Security at Rentalize
Rentalize stores platform data in EU data centres and processes personal data for you under a published GDPR Data Processing Agreement. Personal data is never used to train AI models, every AI action is logged and waits for your approval, and you choose the AI engine. ISO 27001 certification is in progress: we do not hold the certificate yet. Our controls follow ISO 27018 and ISO 27701 guidance, and we are not certified to either.
- EU data storagePrimary hosting on Amazon Web Services in an EU region, backups in a second EU member state.
- No AI training on personal dataTenant data is queried per request and never used to train AI models.
- ISO 27001: in progressNot certified yet. ISO 27018 and 27701 aligned, not certified.
- 99.5% availability commitmentPer month from go-live, in our published Service Level Agreement.
Where is Rentalize data stored?
Rentalize platform data is stored in EU data centres. Our Data Processing Agreement names the location of processing as the European Union, with primary hosting on Amazon Web Services in an EU region and backups held in a second EU member state. Encryption keys are held in the European Union through the hosting provider's managed key service.
There are no transfers of personal data outside the European Economic Area in the ordinary course. If one were ever needed, the DPA allows it only on an adequacy decision or the European Commission's Standard Contractual Clauses, with a transfer impact assessment, and we must tell you in advance. Remote support access from outside the EEA counts as a transfer under the same clause.
One thing to know about AI. If you run Talia, our AI colleague, on a hosted engine, the prompts it needs are processed by that provider. A self-hosted model keeps AI processing inside your own infrastructure. Your platform data is stored in the EU either way.
How does Rentalize handle GDPR?
You are the controller of your tenant, landlord and contractor data, and Rentalize is your processor under Article 28 of the GDPR. The terms are in our Data Processing Agreement, which is published and applies automatically as part of the subscription, so most customers need nothing more. If your organisation requires an executed Article 28 agreement, the same text is signed as an annex to your order, and a signed copy is available on request.
What the DPA commits us to, in plain terms:
- We notify you of a personal data breach within 48 hours of becoming aware of it, with an initial notification within 24 hours where it is likely to be high risk. Both are shorter than the 72 hours GDPR gives you as controller.
- We give you at least 30 days' written notice before adding or replacing a sub-processor, and you can object.
- You can export your data in open, machine readable formats at any time, at no charge.
- At the end of your contract we return or delete your data at your election, and certify deletion in writing.
The DPA also covers audits, data subject requests and sub-processors. Read it in full at rentalize.com/legal/dpa, alongside our privacy policy.
Is tenant data used to train AI models?
No. Tenant names, rent amounts and compliance records are never used to train AI models. When you ask Talia a question, she queries your live data for that request, returns the answer and discards it. What she remembers about your preferences is encrypted at rest, in line with GDPR Article 32, and PPS numbers, bank details and passwords are not stored in that memory. Multi-tenant isolation is enforced at every tool call, so the assistant only ever sees your own company's data.
The contract says the same. Clause 4.5 of our DPA prohibits us from using personal data to train any machine learning model. The one permitted use of data derived from the platform is irreversibly anonymised, aggregated statistics for product improvement and benchmarking under clause 5, from which no tenant, landlord, contractor or customer can be identified. You can opt out of that clause at any time, in writing, at no charge.
Which AI engine does Rentalize use?
Your choice. Rentalize AI can run on Anthropic, OpenAI, Google Gemini, or a self-hosted local model inside your own infrastructure, and the provider and model are set by your account administrator. Most property software ties you to the vendor's own assistant. We do not, because housing bodies and local authorities often need data to stay within a named jurisdiction or on their own systems.
Your platform data is stored in the EU either way. When you choose a hosted engine, the prompts Talia needs are processed by that provider. A self-hosted model keeps that processing on infrastructure you control. Administrators also set a daily token budget and how long conversations are retained, from 30 days to indefinitely. More detail is on the Talia and AI page.
AI audit trail, permission modes and the EU AI Act
Talia can take actions, not only answer questions, so every write is gated. When she creates a task, logs a payment, sends an SMS or updates a ticket, she shows a preview of exactly what will change, and nothing happens until someone clicks Confirm. Permission modes control what the assistant is allowed to do.
Every question and every action is logged per user and per company, elevated administrators can review sessions, and the retention period is yours to set. Across the platform, actions are timestamped and attributable to a named user, with role-based access, granular permissions and segregation of duties.
That record matters from 2 August 2026, when EU AI Act deployer duties apply to firms using AI on tenant-facing decisions. The logs are what an evaluator asks for, and they already exist for every AI action taken in Rentalize.
Is Rentalize ISO 27001 certified?
Not yet. ISO 27001 certification is in progress, and we do not hold the certificate today. We would rather say that plainly than have you find out at the security questionnaire stage.
ISO 27001
Information security management. We are working towards certification to the international standard for protecting the confidentiality, integrity and availability of data.
ISO 27018
Protection of personal data in the cloud. Our controls follow its guidance. We are not certified to it.
ISO 27701
Privacy information management. Our privacy controls follow its guidance, which extends ISO 27001 with controls aligned to GDPR. We are not certified to it.
If your procurement requires a certificate by a set date, ask us for the current status before you decide.
Access control, encryption and backups
The technical and organisational measures we maintain are set out in Annex A of the Data Processing Agreement, which does not allow us to reduce the overall level of security during your contract. They include:
- Role-based access control on the principle of least privilege, with multi-factor authentication required for all administrative and privileged access.
- Encryption in transit using TLS 1.2 or above, and encryption at rest for databases, object storage and backups.
- Encrypted daily backups, retained for at least 30 days and held within the European Union, with restoration tested at least quarterly.
- Separate production, staging and development environments, with no live personal data in development.
- Independent penetration testing at least annually, with findings tracked to closure.
The full list, including monitoring, incident response and supplier checks, is in the DPA itself.
What uptime does Rentalize commit to?
Our Service Level Agreement commits to platform availability of 99.5 per cent in each month from your go-live date, with service credits if we miss it. Availability is measured by automated monitoring that runs independently of the platform, polling from outside the hosting environment, so the monthly figure is not compiled by hand. One service level applies to every commercial customer.
The platform has held up where it counts. Rentalize Select has processed more than 6,000 applications with zero downtime through intake peaks, including a single week of 4,600.
Security FAQ
Does Rentalize sign a Data Processing Agreement?
Yes. Our Data Processing Agreement is published at rentalize.com/legal/dpa and applies automatically as part of the subscription. Where an organisation requires an executed Article 28 agreement, the same text is signed as an annex to the order form, and a signed copy is available on request.
Is Rentalize data stored in the EU?
Yes. Platform data is stored in EU data centres: primary hosting on Amazon Web Services in an EU region, with backups in a second EU member state. If you run Talia on a hosted AI engine, the prompts it needs are processed by that provider; a self-hosted model keeps AI processing in your own infrastructure.
Is Rentalize ISO 27001 certified?
Not yet. ISO 27001 certification is in progress and we do not hold the certificate. Our controls follow ISO 27018 and ISO 27701 guidance, and we are not certified to either standard.
Is tenant data used to train AI?
No. Personal data is never used to train AI models, and clause 4.5 of our Data Processing Agreement prohibits it. Only irreversibly anonymised, aggregated statistics may be used for product improvement and benchmarking, and you can opt out of that at any time at no charge.
Can we choose which AI model Rentalize uses?
Yes. Your account administrator chooses Anthropic, OpenAI, Google Gemini, or a self-hosted model inside your own infrastructure. Every AI action shows a preview and waits for confirmation, and every question and action is logged per user and per company.
How quickly would we be told about a data breach?
Within 48 hours of us becoming aware of it, with an initial notification within 24 hours where the breach is likely to be high risk to the people affected. Both are shorter than the 72 hours GDPR gives a controller, so you keep time to assess and notify.
Working through a security questionnaire?
Book a 45-minute demo and bring your questions, or ask us to call you first. The documents procurement teams usually ask for are linked below.