Data & Privacy

Your data, handled with care

Plain-English answers to how Roost collects, stores, protects, and eventually removes your data — no jargon, no ambiguity.

Last updated: June 2026  ·  Morado Limited, registered in England & Wales

Encrypted everywhere

All documents and personal data are encrypted at rest and in transit, using AWS KMS-managed keys.

Never auto-deleted

We never silently delete your data. When the retention period ends, we ask you what to do — you decide.

UK GDPR compliant

Roost is built from the ground up under UK data protection law. Your rights are built in, not bolted on.

The data Roost holds about you

We only collect data that's needed to run the platform. There's no advertising, no data brokering, and no selling your information to third parties.


Data retention periods

Retention periods are tied to the tenancy lifecycle — not to when data was uploaded. This is intentional: a gas safety certificate uploaded on day one of a tenancy should stay accessible for the same period as everything else from that tenancy.

Data type Retention period Clock starts
Documents, messages & issues Tenancy duration + 6 years From the date the tenancy formally ended
Archived property data 6 years From the later of tenancy end date or archive date
Notifications 12 months From the date each notification was created
Account data Until you request deletion

We never auto-delete. When the retention period for a property expires, we email you and ask whether you'd like the data permanently removed or kept on file. You make that call — we don't make it for you. This is a deliberate product decision, not a legal minimum.

The 6-year period reflects the UK Limitation Act 1980, under which contractual disputes can be brought for up to six years after the event. Keeping tenancy documents for this window protects both landlords and tenants.


What happens when a property is archived

When a landlord archives a property (typically after a sale or at the end of a tenancy), the following happens immediately:


Encryption & security

Roost is hosted on AWS in the UK (London region, eu-west-2). Security is layered across every part of the stack.

Encryption at rest

All documents (S3) and database records (PostgreSQL) are encrypted using AWS KMS customer-managed keys. Roost controls the keys — not AWS.

Encryption in transit

All connections between your browser and Roost use TLS (HTTPS). Data is never transmitted unencrypted.

Authentication

Login is handled by AWS Cognito with mandatory multi-factor authentication (MFA). We don't store passwords ourselves.

Document access

Documents are never served directly. The platform generates short-lived, time-limited presigned URLs — so access is always authenticated and auditable.


Who can see what

Access to data within Roost is strictly role-based. Landlords and tenants only see data for properties they're connected to.


Your UK GDPR rights

Under UK data protection law, you have the following rights. To exercise any of them, email us at privacy@wearemorado.com.

Access

Request a copy of all personal data we hold about you.

Rectification

Ask us to correct inaccurate or incomplete personal data.

Erasure

Request deletion of your data, subject to legal retention obligations.

Portability

Receive your data in a structured, machine-readable format.

Restriction

Ask us to restrict processing of your data in certain circumstances.

Objection

Object to processing where we rely on legitimate interests as the lawful basis.

If you're not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) — the UK's independent data protection authority — at ico.org.uk.


What we don't do

Questions about your data?

Reach us directly. We aim to respond to all data-related queries within 5 working days.

Email privacy@wearemorado.com