Skip to content
Our Stairwell
Overview
Features
All featuresExplore the shared workspaceMeetings and governanceKeep agendas, papers, attendance, proxies, minutes, decisions, and company records connected.Building recordsTrack works, quotes, certificates, insurance, assets, contractors, and the evidence behind each decision.Service charge recordsConnect demands, payments, credits, bills, funds, bank activity, reports, and unit ledgers.Document librarySearch file contents, filter by source, follow documents back to their records, and share evidence with control.Resident communicationPublish announcements, run discussions and polls, coordinate dates, and keep residents pointed to the right record.Resident accessConnect residents to units and roles while keeping finance, governance, and sensitive records appropriately controlled.Setup and prioritiesUse guided setup, dashboard priorities, invitations, notifications, controlled sharing, and exports to keep work moving.
How it worksPricingContactSupport
Sign in
Start free trial
Menu
OverviewFeaturesHow it worksPricingContactSupportSign inStart free trial

Privacy information

Privacy Notice

Pre-release draft · Version 2026-09-05

How Our Stairwell uses personal information and how people can exercise their data-protection rights.

Legal and privacy
Privacy noticeCookies & storageSubscription termsData processingAcceptable useSupport & service levelsSubprocessorsSecurity measures

These documents are being prepared for launch. Our Stairwell Ltd has not yet been incorporated. Customer subscriptions will open only after incorporation and completion of the supplier details and launch terms. This draft does not offer a subscription from an existing limited company.

Our Stairwell Ltd has not yet been incorporated and there are no customer subscriptions. Before incorporation, the individual operating Our Stairwell is responsible for personal information used for website enquiries and other pre-launch activities. The operator's full identity and contact address must be completed in this notice before public use. Contact [email protected]. Before customers join, this notice will identify the incorporated company and its contact details for activities where it decides why and how personal information is used. No statutory data protection officer has been appointed; this mailbox is the privacy contact.

1. Scope and our different roles

This notice covers visitors to our websites; prospective customers and their contacts; customer administrators and billing contacts; account holders and invited users; people who contact support; people who open an invitation or public sale-pack link; contractors and professional advisers; and other people whose information we use for our own business purposes.

A customer association normally decides why resident, owner, tenant, building, governance, finance, contractor and workspace records are used. It is the controller for those records and we operate the platform as its processor, under the Data Processing Agreement. If your question is about information in an association workspace, contact the association first. We will help it answer requests.

We act as a separate controller when we decide to use information for our website and enquiries, contracting, account and service administration, billing, fraud and misuse prevention, security, support operations, legal compliance, complaints and legal claims. Support content about a customer's residents or records may still be processed on that customer's instructions even though we control the limited ticket, security and service-management records around it.

2. Information we receive

Depending on how you interact with us, we may receive:

  • name, email address, postal address, telephone number, role, organisation and unit relationship;
  • account, authentication, invitation, permission and profile identifiers;
  • customer setup, contract acceptance, authority, plan, billing and payment-status information;
  • messages, support correspondence, attachments, feedback and complaint information;
  • public sale-pack link details and records of link views or downloads;
  • IP address, browser and device details, request identifiers, timestamps, security events and audit records;
  • information a customer or another authorised user enters about you in its workspace; and
  • other information you choose to give us or that is needed to deal with a request.

We receive information directly from you; from the customer association and its authorised users; from identity, email, payment and integration providers; and, where relevant, from public registers such as Companies House. If another person provides your information, the relevant customer should also give you its own privacy information.

Please do not put special-category information, criminal-offence information or unnecessary information about other people into a contact or support message. Customer workspace content may contain such information only where the customer has decided it is necessary and lawful.

3. Why we use information and our lawful bases

PurposeTypical informationLawful basis when we are controller
Answer enquiries, arrange demonstrations and take requested pre-contract stepsContact details, role, organisation, unit count and messageSteps at your request before a contract and our legitimate interests in responding and developing customer relationships
Set up and administer customers, accounts, subscriptions, contracts and paymentsIdentity, organisation, authority, acceptance, billing contact, plan and payment statusContract where you are the contracting individual; otherwise our and the customer's legitimate interests in performing the business contract; legal obligation for tax and accounting records
Authenticate users, control access, protect the service and investigate misuse or incidentsAccount identifiers, roles, IP, device, browser, request, event and audit informationOur and customers' legitimate interests in providing a secure service, and compliance with legal security obligations
Provide support, diagnose faults and improve service reliabilityContact details, ticket content, relevant account context and diagnostic informationContract or legitimate interests in supporting and improving the service; legal obligation where a request concerns data-protection rights
Handle privacy requests, complaints, disputes and legal claimsIdentity, request, evidence, correspondence and outcomeLegal obligation and legitimate interests in establishing, exercising or defending legal claims
Send genuinely optional direct marketingName, business contact details, preferences and suppression statusConsent where electronic-marketing law requires it; otherwise legitimate interests after the required balancing assessment. You may object at any time

Where we process customer workspace information only on the association's instructions, its lawful basis applies rather than one chosen by us. You are not generally required by law to give us information, but required form, account, contract or payment details are needed to provide the requested service. If they are not provided, we may be unable to respond, create an account or supply the service.

4. Contact forms, invitations and public links

The contact form sends the details you enter to our support system. We and Cloudflare use your IP address, a short-lived Turnstile token and browser signals to distinguish people from bots and rate-limit misuse. Turnstile tokens expire after five minutes. Contacting us does not by itself add you to a marketing list.

Invitation pages use the invitation code, email address, account details and security information to validate and accept an invitation. Invitation links normally expire after 30 days. Public sale-pack pages use the access token and record limited view, download, IP, browser and audit information to protect the link and give the customer an access record. Public sale-pack links expire no later than 30 days after creation unless revoked sooner. The customer association is normally controller for the invitation, sale-pack content and viewer details.

5. Cookies and similar technology

We currently use only storage and access technology needed to authenticate users, preserve security, prevent fraud or technical faults, remember an action you request, and provide features you choose to use. We do not currently load advertising technology, optional audience analytics or browser session replay. Our Cookies and Storage Notice identifies the technology currently in use, its purpose and normal duration. If our use changes, we will update that notice and provide the consent or objection control required by law before enabling the new technology.

6. Who receives information

We disclose information only as needed to:

  • the relevant customer association and its authorised users;
  • hosting, content-delivery, security, authentication, storage, search, support, email, monitoring and backup providers;
  • payment providers and customer-selected accounting or calendar integrations;
  • professional advisers, insurers, auditors and prospective purchasers under appropriate confidentiality controls; and
  • regulators, courts, law-enforcement bodies or other recipients where disclosure is required or legally justified.

Important providers and their functions are listed on our Subprocessor List. GoCardless and some customer-selected integrations may act as independent controllers under their own privacy notices. We do not sell personal information.

7. International transfers

Our core production hosting is intended to be in the United Kingdom, but providers including Cloudflare, Resend, Google and OpenAI may process information in the United States or other countries. Where a restricted transfer requires a safeguard, we use an applicable UK adequacy regulation, the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or another lawful mechanism. We assess the transfer and use supplementary security measures where appropriate. Contact us for information about a relevant safeguard.

8. How long we keep information

RecordNormal retention
Uncompleted onboarding draftUp to 90 days after it was last saved
Contact and sales enquiryUntil resolved and normally up to 24 months after the last meaningful contact; longer if it becomes a customer, complaint or legal record
Support ticketNormally up to 24 months after closure; material contract, security, complaint or legal correspondence may be kept for up to six years
Contract acceptance, invoice, payment and tax recordNormally six years after the end of the customer relationship or relevant accounting period
Central operational logsNormally three days; separately retained error or incident evidence may be kept for up to 90 days or longer while an investigation or claim requires it
Live customer workspaceFor ordinary paid or trial access and normally 90 days after that access ends following voluntary cancellation; for qualifying non-payment, normally 90 days from the payment failure or mandate loss, subject to the customer contract and instructions
Protected backups and restricted compliance archiveUntil the applicable backup deletion cycle; selected records may be retained for up to six years where a documented legal, tax, accounting, regulatory or claims purpose requires them
Marketing suppression recordMinimal contact and objection details for as long as needed to honour the objection

We may keep a record longer where a legal hold, active dispute, regulator or law requires it, and may delete it sooner when it is no longer needed. Customer associations set retention for workspace content; after live deletion, backup copies are put beyond ordinary use until their deletion cycle. A six-year archive is not intended to include an entire workspace by default: only records justified by the specific legal or business-record purpose should be selected.

9. Your rights

Depending on the circumstances and lawful basis, you may ask for access to your information, correction, erasure, restriction, or portability; object to processing based on legitimate interests or to direct marketing; and withdraw consent without affecting earlier processing. You also have rights concerning decisions made solely by automated means that have legal or similarly significant effects.

We use automated security checks to validate requests and rate-limit suspected misuse. They may temporarily reject or delay a request, but we do not use solely automated decisions that produce legal or similarly significant effects. Contact [email protected] to exercise a right. We may need proportionate information to confirm your identity. If the information is controlled by a customer association, we will normally refer the request to that association and assist it.

10. Data-protection complaints

You may make a data-protection complaint in plain language by emailing [email protected]. Tell us what happened, which information or right is involved, the outcome you want and any relevant dates or evidence. We will acknowledge a data-protection complaint within 30 days, make appropriate enquiries, keep you informed about progress and tell you the outcome without undue delay.

You may also complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, telephone 0303 123 1113, or write to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would appreciate the opportunity to address the issue first, but you do not have to contact us before seeking regulatory assistance.

11. Changes to this notice

We will update this notice when our identity, services, providers or processing materially changes. When a limited company takes over the business, this notice must be updated to name the company, company number and registered office, explain any transfer of existing records and identify the effective date. Material changes will be brought to affected people’s attention where appropriate.

Our Stairwell

Block management software for UK resident-led buildings.

Explore
FeaturesPricingHow it worksContactSupportLegal