1. Who operates House CRM
HouseCRM is currently operated under the HouseCRM trading name as a private-pilot software platform while the service is being tested prior to formal incorporation and wider commercial launch.
HouseCRM is not yet incorporated. No company registration number or registered office exists at this stage.
For privacy, data-protection or general enquiries, contact enquiries@housecrm.co.uk.
2. Platform participants and responsibilities
House CRM is a multi-tenant software platform used by separate customer estate agencies. Each agency has its own organisation workspace and may give authorised staff access to relevant branches, records and connected services. CRM records may concern applicants, vendors, landlords, tenants, buyers, sellers and other contacts of that agency.
The House CRM platform operator, customer agency and third-party providers may have different data-protection responsibilities depending on the activity. The definitive controller, joint-controller and processor allocation has not been finalised in this draft and requires legal confirmation against the customer contracts and actual processing arrangements.
3. Information House CRM may process
Depending on how an agency uses the service, this may include:
- Estate-agency customer and contact details, requirements, enquiries and communication history.
- Property, valuation, viewing, offer, sales, lettings and progression information.
- Staff account, authentication, role, branch and security-event information.
- Organisation and branch identity, agency branding and authorised staff permissions.
- Identifiers, display names and authorised capabilities for social-media and other third-party accounts connected by a customer agency.
- OAuth access and refresh credentials stored separately for the relevant organisation in encrypted, server-side systems and not intentionally exposed to browser users.
- Agency-approved content, property media, social creative, schedules, publishing jobs and provider receipts.
- Technical information such as device, browser, IP address, request logs, timestamps and essential cookie data.
- Audit evidence needed to record approvals, changes, delivery attempts and provider responses.
4. Why information is used
House CRM may use information to:
- Provide and secure the service and authenticate authorised users.
- Support estate-agency workflows requested by the subscribing organisation.
- Maintain accurate records, prevent duplicate or unauthorised actions and preserve audit history.
- Prepare agency-specific content, approval workflows and schedules using that agency's branding and authorised media.
- Connect with and, when separately enabled and approved, publish to third-party accounts authorised by the relevant customer agency.
- Diagnose faults, monitor service health and respond to support or security incidents.
- Meet legal, regulatory and contractual obligations where they apply.
5. Lawful bases and role allocation
The applicable lawful basis depends on the relationship, processing purpose and party making the decision. It may include performance of a contract, compliance with a legal obligation, legitimate interests or consent where consent is required. The final controller/processor allocation, responsibilities between the platform operator and each customer agency, and activity-specific lawful bases require legal confirmation before Production publication.
6. Customer-controlled connections and publishing
Each customer agency connects and authorises its own Facebook, Instagram, TikTok, LinkedIn or other supported third-party accounts. OAuth connections, encrypted provider credentials, brand and media approvals, publishing jobs and provider receipts are scoped to that organisation and, where applicable, its branch.
Agency staff control which permitted accounts are connected and whether prepared content is approved, scheduled or published. House CRM does not use one customer's credentials, content or social identity for another customer, and one agency must not be able to access or publish through another agency's connection.
7. Service providers and connected platforms
House CRM may rely on hosting, database, authentication, communications and operational service providers. Where a customer agency enables a connection, information may also be exchanged with its selected social network, email provider or property portal, including Meta, TikTok, LinkedIn and property-listing platforms. Each connection is subject to organisation-level authorisation and the third party's terms and privacy practices.
The final list of processors, contractual roles and data locations must be checked against current supplier agreements before this policy is finalised.
8. International processing
Some service providers or connected platforms may process information outside the United Kingdom. The operator must confirm the destinations and transfer safeguards actually used before Production publication. No particular transfer mechanism is asserted by this draft.
9. Retention
Information should be retained only for as long as needed for the relevant service, audit, contractual, legal or regulatory purpose, then securely deleted or anonymised where appropriate. Exact retention periods are intentionally not stated until the operator's retention schedule is approved.
10. Security and tenant isolation
House CRM uses access controls, strict organisation/tenant separation, branch scope where applicable, separate encrypted provider credentials, separate brand/media authority and separate publishing jobs and receipts. These controls are intended to prevent one agency from accessing another agency's records or publishing through another agency's provider connection. No system can guarantee absolute security, and this policy does not claim a certification or security guarantee that has not been independently confirmed.
11. Cookies and technical storage
The authenticated service uses technical storage needed for login, session security and essential operation. Any non-essential analytics or marketing technologies must be separately assessed, disclosed and, where required, placed behind an appropriate consent mechanism before use.
12. Individual rights
Depending on the circumstances and applicable law, individuals may have rights to access, correct, erase or restrict information, object to certain processing, request portability, withdraw consent and complain to a supervisory authority. An estate agency may be the appropriate first contact where it controls the relevant customer record.
To raise a request with the platform operator, contact enquiries@housecrm.co.uk. An individual may instead need to contact the customer estate agency responsible for the relevant record. The operator will need enough information to identify the appropriate organisation and record. The final request-routing, complaints and regulator wording requires counsel confirmation.
13. Changes to this policy
Material changes should be published on this page with an updated effective date. This draft must not be treated as final until the unresolved legal details above are confirmed.