Privacy & Consent (UK GDPR)
Effective Date: January 1, 2026
This Privacy & Consent Notice explains how APPIFIED LABS LTD (“we”, “our”, “us”) collects, uses, and protects personal data when providing tenant referencing, identity and compliance checks (the “Service”) via our website and WhatsApp. By using the Service, you agree to the terms below.
1. Who we are
APPIFIED LABS LTD
Registered Address: 82 A James Carter Road, Mildenhall, Suffolk, England, IP28 7DE
Email: privacy@mychecksai.com
Under UK GDPR, we may act as a Data Processor for landlords/agents who initiate checks, and as a Data Controller where applicants or referees submit information directly to us (e.g., WhatsApp Flows or our web forms).
2. What information we collect
Depending on the check type, we may collect:
- Applicants (tenants/guarantors): name, date of birth, email, phone/WhatsApp ID, address history, employment details, referee details, identity/right-to-rent related data, and responses submitted via WhatsApp or web forms.
- Referees (employers/landlords/personal refs): name, email/phone, relationship to applicant, and reference responses.
- Landlords/agents: name, email/phone, WhatsApp ID, organisation/project context, usage logs, and billing events.
3. How we use your information
We use personal data to:
- Run tenant referencing, identity, and compliance checks requested by landlords/agents
- Contact referees only where the applicant has permission
- Send WhatsApp updates relating to a check (invitations, reminders, progress/status updates)
- Provide results to the requesting landlord/agent
- Maintain audit logs and prevent fraud/misuse
- Comply with applicable legal and regulatory obligations
4. Consent & referee permissions (important)
When an applicant provides referee details, the applicant confirms they have informed their referees and have explicit permission for us to contact them as part of the check.
Referee reminder tip: We may show a reminder such as:
“Tip: Please let your referee know we’ll be contacting them shortly — it helps speed things up.”
5. Lawful basis (UK GDPR)
We process personal data using one or more of the following lawful bases:
- Consent (e.g. WhatsApp Flow submission, optional marketing opt-in)
- Contract (to provide the Service requested)
- Legitimate interests (fraud prevention, service security, audit logs)
- Legal obligation (where applicable for compliance-related checks)
6. Data retention
We keep data only as long as necessary for the Service, dispute handling, and legal compliance. Typical retention periods:
- Referencing and compliance data: up to 6 years
- WhatsApp message logs: up to 12 months
- Free demo/trial checks: up to 90 days (unless converted to a paid account)
- Marketing consent records: until consent is withdrawn
7. Marketing vs transactional messages (and STOP)
Transactional messages are messages required to run a check (e.g. invites, reminders, status updates). Marketing messages are optional and only sent if you opt in.
You can opt out of marketing at any time by replying STOP. Opting out of marketing does not stop essential transactional messages relating to active checks.
8. Third-party processors
We use third-party processors to deliver the Service. Data is hosted and managed in the EU. Our processors include:
- Meta (Facebook/WhatsApp): WhatsApp messaging and flows
- Twilio: WhatsApp message delivery and status callbacks
- Stripe: payments and billing
- Yoti: identity verification
- Hetzner: application hosting (EU)
- Amazon S3: file storage (EU region)
9. Yoti identity checks (disclosure)
To help establish identity, we use Yoti to perform identity verification. When you submit an ID document, Yoti extracts data such as name and date of birth. If you are asked to submit a selfie, Yoti uses technology to check the selfie is of a real person and matches the photo on the ID document. Yoti sends us the results of the checks.
Yoti retains data for their operational period and deletes it in line with their retention practices. We retain identity check results in accordance with the retention section above.
10. Data security
We use appropriate technical and organisational safeguards to protect personal data, including access controls and secure storage. No method of transmission or storage is 100% secure, but we work to maintain industry-standard protections.
11. Your rights
Under UK GDPR you may have the right to:
- Request access to your personal data
- Request correction of inaccurate data
- Request deletion (where legally permissible)
- Object to or restrict processing in certain cases
- Withdraw consent at any time (where processing is based on consent)
To exercise your rights, contact: privacy@mychecksai.com
12. Contact
Email: privacy@mychecksai.com
Support: support@mychecksai.com
Billing: billing@mychecksai.com
Address: 82 A James Carter Road, Mildenhall, Suffolk, England, IP28 7DE