Data Processing Addendum

Last updated: August 2026 · Version: 1.0

This Addendum forms part of the Terms of service between you ("Customer") and CJ Normandie Ltd ("HMOJo", "we", "us"). It applies whenever we process personal data on your behalf, and it is required by Article 28 of the UK GDPR. You do not need to sign it — accepting the Terms of service accepts this Addendum.

In plain terms: when you put your tenants' details into HMOJo, you are the one deciding what happens to that data and you are answerable for it. We are your supplier. This document sets out what we will and will not do with it, and what we owe you.


1. Definitions

"Data Protection Law" means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, as amended.

"Customer Personal Data" means personal data that we process on your behalf through HMOJo — principally data about your tenants, applicants, guarantors, occupants and contractors.

"controller", "processor", "data subject", "personal data", "processing" and "personal data breach" have the meanings given in the UK GDPR.

"Sub-processor" means a third party engaged by us to process Customer Personal Data.


2. Roles

You are the controller of Customer Personal Data. We are your processor.

You are responsible for: having a lawful basis for the processing; giving data subjects the information they are entitled to; the accuracy and lawfulness of what you put into HMOJo; and responding to data subjects. We will help you with the last of these under section 8.

We are separately a controller for account holder data — see the Privacy notice. This Addendum does not apply to that data.


3. Our instructions

We will process Customer Personal Data only:

(a) on your documented instructions, which are: the Terms of service, this Addendum, the configuration and use of the product by you and your users, and any further written instruction you give that we agree to; and

(b) where required by law, in which case we will tell you first unless the law prevents us.

We will not sell Customer Personal Data, use it for our own marketing, or use it to train any AI model — ours or a third party's.

We may use aggregated and fully anonymised statistics derived from use of the service to operate and improve it, provided no individual can be identified.

If we consider an instruction infringes Data Protection Law, we will tell you.


4. Details of the processing

Subject matter: provision of the HMOJo HMO compliance and property management service.

Duration: for as long as your account is open, plus the 90-day retention period in section 11.

Nature and purpose: hosting, storage, organisation, retrieval, display, AI-assisted extraction of information from documents, transmission of invitation and notification emails, and deletion.

Categories of data subject: tenants, prospective tenants and applicants, guarantors, occupants, emergency contacts, contractors and tradespeople, and any other individual whose data you enter.

Categories of personal data:

  • identity and contact data — name, email, phone, date of birth
  • tenancy data — room, dates, tenancy documents, deposit scheme references
  • identity documents — passports, biometric residence permits, share codes and other Right to Rent evidence. Not processed during the beta programme. HMOJo does not accept these during beta and Customers are contractually prohibited from uploading them
  • inventory and check-in records, including photographs of rooms and their contents
  • maintenance and issue reports submitted by tenants
  • correspondence within the platform

Special category data: not required by the service and not intentionally collected. You must not upload special category or criminal offence data unless you have a lawful condition under Article 9 or 10 UK GDPR and appropriate policy documentation. If it appears incidentally — for example in a maintenance report mentioning a health condition — we will process it under the same terms.

Automated decision-making: none. HMOJo does not score, rank, approve or reject any individual, and does not carry out referencing or credit checks.


5. Confidentiality

We ensure that anyone authorised to process Customer Personal Data is bound by confidentiality obligations, is trained appropriately, and has access only where needed.


6. Security

We implement appropriate technical and organisational measures under Article 32, including:

  • encryption of data in transit and at rest
  • row-level access controls so each account's data is logically isolated
  • role-based access to production systems, limited to personnel who require it
  • authentication controls, including passwordless invitation links for tenant users
  • logging and monitoring
  • regular backups
  • vendor selection and review on security grounds
  • a documented process for detecting and responding to incidents

We may update these measures, provided the level of protection is not reduced. A current summary is at Security.


7. Sub-processors

You give general authorisation for us to engage Sub-processors. Every Sub-processor is bound by a written contract imposing data protection obligations no less protective than this Addendum, and we remain fully liable to you for their performance.

Current Sub-processors — name, purpose and processing region — are listed at /legal/subprocessors and are available on request from privacy@HMOJo.co.uk.

We will give you at least 30 days' notice before adding or replacing a Sub-processor. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the service without penalty and receive a refund of any fees paid in advance for it.


8. Assisting you with data subjects

If we receive a request from a data subject relating to Customer Personal Data, we will not respond to it substantively — we will forward it to you promptly and tell the individual to contact you, as controller.

Taking into account the nature of the processing, we will provide reasonable assistance, by appropriate technical and organisational measures, to help you respond to requests to access, rectify, erase, restrict, port or object. In practice most of this you can do yourself directly in the product.


9. Personal data breaches

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.

Our notification will describe, so far as we know it: what happened, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.

We will assist you with your own obligations to notify the ICO and affected individuals. Deciding whether to notify is yours — you are the controller.


10. DPIAs and prior consultation

We will provide reasonable assistance with data protection impact assessments and any prior consultation with the ICO, taking into account the nature of the processing and the information available to us.


11. Deletion and return

You can export Customer Personal Data at any time from the product.

On termination of your account, we retain Customer Personal Data for 90 days and then delete it permanently, unless the law requires us to keep it. Backups are overwritten on our normal cycle, which may extend deletion from backup media by up to a further 30 days; data in backups remains protected by this Addendum until deleted.

You are responsible for exporting anything you are legally required to keep before the 90-day period ends. Note that Right to Rent evidence is not held in HMOJo during the beta — you must continue to retain those records yourself, for the period required by immigration law.


12. Audit

On reasonable written request, and no more than once in any 12-month period unless required by a regulator or following a breach, we will provide the information reasonably necessary to demonstrate compliance with this Addendum — including our security documentation and any relevant third-party certifications or reports held by our Sub-processors.

Where that information is genuinely insufficient, you may audit us, or appoint an independent auditor bound by confidentiality, on 30 days' notice, during business hours, without unreasonable disruption, and at your cost.


13. International transfers

We process Customer Personal Data in the United Kingdom and the European Economic Area only.

We will not transfer Customer Personal Data outside the UK and EEA without either your prior written consent or an appropriate transfer mechanism recognised under Data Protection Law (such as the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses), and we will update the Sub-processor list before doing so.


14. Your warranties

You warrant that:

(a) you have a lawful basis for all processing you instruct;

(b) you have provided data subjects with the information required by Articles 13 and 14 — our Tenant privacy notice helps but does not replace your own notice;

(c) you have a valid Article 9 or 10 condition for any special category or criminal offence data you upload;

(d) you will not instruct us to do anything that would put either of us in breach of Data Protection Law.


15. Liability and precedence

Each party's liability under this Addendum is subject to the limitations and exclusions in section 17 of the Terms of service, except where Data Protection Law does not permit it.

If this Addendum conflicts with the Terms of service, this Addendum prevails in relation to the processing of Customer Personal Data.


16. Term

This Addendum takes effect when you accept the Terms of service and continues until we have deleted all Customer Personal Data in accordance with section 11.


Questions: privacy@HMOJo.co.uk