Bellsoph
Privacy Policy
Last updated: 27 September 2026Platform processing unchanged since 1 August 2026Who this notice covers
This notice explains how Bellsoph Property Intelligence (“Bellsoph”, “we” or “us”) handles personal data on the public research website and in the Bellsoph landlord software platform. Contact us through our contact form.
Our role and your landlord's role
We are a controller for account administration, service security, support, billing and public-site data that we decide to collect and use. When a landlord, agent or property business uploads tenant, applicant, guarantor, contractor or property records, that customer normally decides why the information is used and is the controller. Bellsoph acts as its processor and handles that workspace content on its documented instructions. People named in a landlord's workspace should normally contact that landlord first; we will support the landlord in responding.
Information we handle
- Account data, including name, email address, optional phone number, organisation, role and sign-in records.
- Property, owner, tenant, guarantor, tenancy, rent, deposit, compliance, maintenance and contact records.
- Invoices, payment status, expenses, tax classifications and supplier or contractor details.
- Uploaded agreements, certificates, receipts, images and the text or structured fields extracted from them.
- Workspace activity, audit records, support messages, device/browser information and security logs.
- Daily operational totals derived from account, organisation, record, job and allowlisted audit data.
- Optional public-site analytics after a visitor has accepted analytics cookies.
Where information comes from
We receive information from account users, documents they upload, invited team members, authentication providers and the operation of the service. Customers may also add information about tenants and other people who do not have a Bellsoph account. Property lookup can use official or licensed address and energy-performance sources selected by the user.
Why we use it and our lawful bases
- To create accounts and deliver requested platform features: performance of our contract with the account customer.
- To authenticate users, prevent abuse, keep audit records and improve reliability: our legitimate interests in operating a secure service.
- To issue invoices, keep financial records and respond to lawful requests: contract and applicable legal obligations.
- To provide support and service notices: contract and our legitimate interests in supporting customers.
- To run optional public-site analytics: consent, which can be refused or changed at any time.
For customer workspace content, the customer determines and must document its own lawful basis. Uploading sensitive or special-category information is not required for ordinary Bellsoph use and customers should not upload it unless they have a clear lawful reason and appropriate safeguards.
Document extraction and AI assistance
When a user asks Bellsoph to read an agreement, certificate or receipt, the relevant file or extracted text may be sent to the configured document-processing provider. The platform currently supports OpenAI and Google Gemini as configured providers. Outputs can be incomplete or wrong, are marked for review where appropriate and must be checked by a person. Bellsoph does not use these features to make solely automated decisions with legal or similarly significant effects about tenants.
Service providers and international transfers
We use providers for cloud hosting, authentication, database and file storage, transactional email, security scanning, support and optional document processing. The deployed service can include Vercel, Supabase, Resend, Google and OpenAI, depending on the feature and customer configuration. We limit providers to the information needed for their service and use contracts and transfer safeguards required by UK data-protection law where data is processed outside the UK. A customer can request the current sub-processor list and relevant transfer information from support.
Retention, deletion and legal holds
Workspace records are retained while the customer account is active and according to the customer's instructions and agreement. At account closure we provide a reasonable opportunity to export data, then delete or return customer content in line with the applicable contract and backup cycle. We may retain limited billing, security or audit information where it is needed to meet a legal obligation, resolve a dispute, prevent fraud or establish legal claims. A documented legal hold pauses deletion only for the affected records. Customers remain responsible for setting and applying appropriate retention periods for their tenancy and property records.
Security and access
For a plain-language overview of our connection encryption, document access controls and hosting locations, see Security & Privacy.
We use authenticated, organisation-scoped access, role controls, private document storage, audit logging and transport encryption. Customers must keep roles current, limit access to people who need it and avoid sending passwords, API keys or full sensitive documents through ordinary support email. No service can guarantee absolute security; report a suspected incident promptly to support.
Authorised Bellsoph support staff may receive temporary, read-only access to a customer workspace when it is needed to investigate a documented support case. Access is time-limited, protected by multi-factor authentication and recorded in an audit trail. File previews and original downloads are separate, explicit and audited actions.
Cookies and analytics choices
Essential cookies keep sign-in sessions and security controls working. Google Analytics is optional on the public research site, is not loaded until a visitor accepts it, and is not loaded in the private landlord platform. The analytics preference cookie lasts for 180 days. The private platform uses no optional behavioural analytics or product-tracking cookies; Bellsoph does calculate aggregate operational and security measures from service records so we can run the platform safely. Use “Privacy choices” in the site footer to change the public-site decision.
Contacting us and the API waitlist
When you use the contact form or join the API waitlist, we collect the name, email address and any company, role and message you give us, along with the page you sent it from and a protected form of your IP address used only to prevent abuse. We never store the address itself. We use these details to answer you, and for the waitlist, to email you once when the API is available. Our lawful basis is our legitimate interest in responding to enquiries, and your consent for the waitlist email, which you can withdraw at any time by replying to us. We do not sell these details, do not add you to a marketing list, and keep enquiries only as long as we need them to deal with the matter and any follow-up. Messages are delivered to us by email through Resend, our email provider.
Your data-protection rights
Depending on the circumstances, you may have rights to be informed, access personal data, correct it, erase it, restrict its use, receive portable data, object to processing and withdraw consent. Rights are not absolute and a lawful exemption may apply. Email support with enough detail for us to identify the relevant account or customer; we may need to verify identity. If the request concerns a landlord's workspace, we may pass it securely to that customer or assist them as controller.
Complaints and changes
Please contact us first so we can investigate. You can also complain to the UK Information Commissioner's Office at ico.org.uk. We will update this notice when the service or applicable requirements materially change and will provide an appropriate notice for significant changes.