1. Who we are
This website and the Lendora IQ assessment tool (the “Service”) are operated by [Lendora IQ Limited], a company registered in England and Wales under company number [00000000], with its registered office at [registered office address](“Lendora IQ”, “we”, “us”). We are the data controller for the personal data described in this policy.
If you have questions about this policy or how we handle your data, contact us at info@lendoraiq.co.uk.
2. Scope
This policy applies to visitors to our website and to lenders and their staff who use the Service to generate lease energy risk assessments. It is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
3. What data we process
3.1 Data you or your organisation submit
- The trading address or postcode of the property being assessed.
- Optional lease and facility details: tenure status, facility maturity date, lease end date, break date.
- If you contact us directly: your name, work email address, organisation, and the content of your message.
A property address is not, on its own, personal data about an identifiable individual in most cases. Where a trading address corresponds to a sole trader or partnership, it may constitute personal data, and we treat it accordingly.
3.2 Data we retrieve from public sources
To generate an assessment, we query two UK public registers in real time on your behalf:
- The EPC Register (operated by the Department for Energy Security and Net Zero) — non-domestic Energy Performance Certificate data for the matched property.
- Companies House — public company records, which can include the names of directors and persons with significant control. This data is already published by Companies House under its own statutory disclosure regime.
3.3 Technical and security data
We log IP addresses and request timestamps for security, rate-limiting and abuse-prevention purposes. We do not currently use analytics or advertising cookies. If that changes, we will update this policy and, where required by the Privacy and Electronic Communications Regulations (PECR), obtain your consent first.
4. Our lawful basis for processing
- Legitimate interests (Article 6(1)(f) UK GDPR) — to provide the assessment service to lenders carrying out credit risk evaluation, and to secure and improve the Service. We have considered that this processing is proportionate and within the reasonable expectations of businesses using a B2B underwriting tool.
- Performance of a contract (Article 6(1)(b)) — where you are a direct customer, to provide the Service under our agreement with you.
- Legitimate interests — to respond to enquiries you send us.
5. How we use data
- To resolve a submitted address against public property and business records.
- To calculate and return a lease energy risk assessment.
- To store a record of assessments generated, for your audit trail and ours.
- To maintain the security, integrity and availability of the Service.
- To respond to support and sales enquiries.
We do not use submitted data to train third-party AI models, and we do not sell personal data.
6. Who we share data with
- The EPC Register and Companies House — the address or search query you submit is sent to these public APIs to retrieve matching records. No submission is required beyond what is needed to run the search.
- Infrastructure and hosting providers — our database and application hosting providers process data on our behalf under data processing agreements. [Name providers once finalised, e.g. Neon, Vercel/Render.]
- We do not share data with data brokers or for third-party marketing.
7. International transfers
Our infrastructure is intended to be hosted within the UK/EEA. [Confirm actual hosting region(s) before publishing this policy.] If any data is transferred outside the UK, we rely on an adequacy decision or appropriate safeguards such as the UK International Data Transfer Addendum, as required by the UK GDPR.
8. Data retention
We retain assessment records for [retention period, e.g. 6 years] to support your credit file and audit requirements, and our own legal and regulatory obligations. Enquiry correspondence is retained for as long as needed to resolve the matter and for a reasonable period afterwards. We delete or anonymise data once it is no longer needed for these purposes.
9. Security
We apply technical and organisational measures appropriate to the sensitivity of the data we hold, including access controls, rate limiting and encrypted network connections where supported by our infrastructure providers. No system is completely secure, and we cannot guarantee absolute security of information transmitted to us.
10. Your rights
Under UK GDPR, you have the right to:
- Request access to the personal data we hold about you.
- Request correction of inaccurate data.
- Request erasure of your data, in certain circumstances.
- Request restriction of, or object to, our processing.
- Request a portable copy of data you provided to us.
- Lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk, though we would welcome the chance to address your concern directly first.
To exercise any of these rights, contact us at info@lendoraiq.co.uk.
11. Children
The Service is a business-to-business product and is not directed at, or intended for use by, children.
12. Changes to this policy
We may update this policy from time to time. We will post the revised version here with an updated “Last updated” date.