GDPR & Compliance
Status: Draft Owner: @bilal @deen Last Updated: 2026-02-15
GDPR Requirements
Personal Data Held
| Table | Fields | Lawful Basis |
|---|---|---|
users | email, full_name, phone | Contract (user signed up) |
tenants | name, phone, email | Legitimate interest (landlord’s tenant) |
vendors | name, phone, email | Contract (vendor relationship) |
conversations | message content, phone | Legitimate interest + consent |
messages | content, media_url | Legitimate interest + consent |
Data Subject Rights
| Right | Implementation | Status |
|---|---|---|
| Right to access | Export tenant data on request | Not implemented |
| Right to erasure | Delete/anonymise tenant data | Soft delete exists, full erasure TBD |
| Right to rectification | Update personal data | Via dashboard |
| Right to portability | Export in machine-readable format | Not implemented |
Deletion Flow
Contact: gdpr@ehq.tech (not yet set up — see Domain & Email Setup)
Process (to be implemented):
- Receive deletion request
- Verify identity
- Anonymise tenant record (replace PII with
[REDACTED]) - Retain anonymised conversation data for regulatory compliance
- Confirm deletion to requester within 30 days
Data Retention
| Data | Full | Summary | Metadata |
|---|---|---|---|
| Conversations | 1 year | 3 years | 7 years |
| Audio recordings | 1 year | N/A | 7 years |
| Media attachments | 1 year | N/A | 7 years |
Consent
| Channel | Method |
|---|---|
| Voice | ”This call may be recorded…” at start |
| First message includes consent notice | |
| Chat | Consent in onboarding / first interaction |
UK Housing Regulations
Compliance documents tracked per property:
- Gas Safety Certificate (annual)
- EPC (10 years)
- EICR (5 years)
- HMO License (5 years)
- Fire Risk Assessment
- Legionella Assessment
Envo tracks expiry dates and alerts landlords before documents expire (30-day default).
Security Compliance (Future)
- SOC2 readiness (Drata/Immuta)
- OWASP scanning
- Penetration testing
- Privacy policy for ehq.tech
- Terms of service
See also: Security, Data Model