Privacy Policy
Last updated: 22 August 2026
Website and platform privacy information. Effective: 22 August 2026. This Policy explains how Levered AI Ltd uses personal data when people visit marklet.io, contact us, create or use an account, receive support or use Marklet. It also explains the important distinction between data Marklet controls and workspace data it processes for customers.
1. Who we are
Levered AI Ltd (company number 17149630), registered in England and Wales and trading as Marklet, has its registered office at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF. Its ICO registration number is ZC199153.
For account, authentication, billing, security, support, website, public legal-update monitoring and business-administration data, Marklet is usually the controller. For personal data in customer Workspaces, the customer organisation ordinarily decides why and how it is processed, and Marklet acts as its processor or sub-processor. Questions about Workspace content should usually be directed first to the relevant RMC, RTM company, residents' association or managing agent.
Data protection contact: privacy@marklet.io.
2. Who this Policy applies to
This Policy applies to website visitors, prospective and current customer contacts, account administrators, Authorised Users, support contacts, people identified in public legislation or tribunal-decision sources used for legal updates, and other people whose data Marklet uses as controller. It also gives general information about people whose personal data a customer records in a Workspace even where they have no account or direct relationship with Marklet, including former leaseholders, residents, individual payees and estate accountants. Marklet is a business service and is not directed to children.
3. Personal data we collect
Account and identity data
name, work email, organisation, role, account identifier, one-time authentication and session information, invitations and account status
Customer and building data
organisation, estate and building details, plan, units, professional credentials declared for plan eligibility and customer contacts
Billing data
billing contact, plan, invoice, payment status, tax and transaction references; Stripe normally holds full payment credentials
Support and communications
messages, calls, enquiries, feedback, attachments and records of support or legal notices
Device, usage and security
IP address, browser and device type, timestamps, session information, audit and security events, feature usage, error and diagnostic data
Website analytics
page or interaction information and coarse location (country and town). No visitor identifier is created, and neither the IP address nor the browser details a device sends are retained for this analytics purpose
Marketing preferences
newsletter or product-update preferences, opt-outs and engagement records, if marketing is used
Signup verification
where self-serve signup is used: the signer's declared role, a verification record including a hashed network identifier, the result of a Companies House officer-name check, and a record of which document versions were accepted
Public legal-update data
legislation and tribunal references, decision dates, residential addresses appearing in feed titles, tribunal and panel-member names, decision text, source links and Marklet's classifications and summaries; decision text may contain other names and factual information about people involved in a case
Workspace membership and professional-contact data
current and former leaseholder or resident names, email addresses, roles, unit associations and occupancy periods; estate accountant names and email addresses recorded for year-end workflows; individual payee details; and other third-party contact or role information entered by a customer
Workspace content
issues, emails, comments, photographs, leases, invoices, service-charge records, bank account details where a payee is an individual, meetings, documents, building-safety material and other content supplied or generated for a customer
4. How we obtain personal data
We collect data directly from the person or customer; from use of the website and Service; from organisations that invite or authorise a user; through connected accounting, Companies House, email and notification services; from public registers and sources; and from suppliers that help us authenticate users, provide infrastructure, prevent bots, deliver messages, process AI features and collect subscription payments.
For legal updates, Marklet polls public legislation and tribunal-decision feeds each day. Feed titles may contain residential addresses and panel-member names. Those titles and abstracts are classified automatically; where an item is taken forward, the full public decision text is read to produce a summary. Marklet does not obtain reliable contact details for every person named in these sources.
Because these sources concern many people and do not ordinarily provide contact details, giving this information individually to every person would generally be impossible or involve disproportionate effort. Marklet publishes this Policy as a proportionate transparency measure and applies minimisation, retention and rights-handling safeguards. This does not affect an individual's ability to contact Marklet or exercise applicable rights.
Workspace content may include personal data about current and former residents or leaseholders, directors, individual payees, estate accountants, contractors, complainants, correspondents and others who have no account or direct relationship with Marklet. That information is obtained indirectly when the customer records it in the Service. The customer, as controller, is responsible for providing any privacy information required by Article 14 of the UK GDPR and for ensuring that it is entitled to place and retain the data in the Service. This Policy provides supplementary information about Marklet's processing role but does not replace the customer's own privacy notice.
5. Why we use controller data and our lawful bases
Provide accounts and the Service
Contract; and legitimate interests in providing a business service to users acting for customers
Authenticate users and manage permissions
Contract; legitimate interests in secure account administration
Bill customers and keep financial records
Contract; legal obligation; legitimate interests in collecting debts and preventing fraud
Security, fraud and service integrity
Legitimate interests; legal obligation where applicable
Support, enquiries and service messages
Contract; legitimate interests in customer service and administration
Operate, troubleshoot and improve Marklet
Legitimate interests in developing a reliable and useful service, using data proportionately and with safeguards
Monitor and summarise legal developments
Legitimate interests in keeping Marklet's statutory workflows and legal information current and helping business users identify relevant changes, subject to minimisation, source verification and a legitimate-interests balancing test applied to this processing
Website measurement
Legitimate interests in understanding website use through proportionate, cookieless analytics
Legal claims and compliance
Legal obligation; legitimate interests in protecting rights, handling claims and cooperating with authorities
Marketing
Consent where required; otherwise legitimate interests where business-to-business marketing is permitted, always with an opt-out
Where we rely on legitimate interests, we consider the purpose, necessity and effect on individuals and use safeguards such as minimisation, access controls and opt-outs where appropriate.
6. Workspace content: Marklet as processor
Marklet processes personal data in a Workspace on the customer's documented instructions to provide hosting, search, communication, workflow, export, support, AI and other selected functions. The Marklet Data Processing Agreement governs that processing. The customer determines its lawful bases, transparency, retention and access decisions.
A managing agent may use Marklet as a processor for an RMC or RTM company, in which case Marklet may be a sub-processor. The legal role depends on the actual management and instruction chain.
7. Special category and sensitive information
(a) Marklet does not ordinarily request special category data, but health, disability, racial or ethnic origin, religion, trade-union, sexual-life or other sensitive information may appear incidentally in emails, free text or uploaded documents.
(b) Where a customer deliberately stores person-centred fire-risk assessments, evacuation statements or similar resident fire-safety material, it must use the designated resident fire-safety category.
(c) That category restricts visibility to directors and managing agents, excludes the material from search and AI features, removes the uploader's filename and records each opening in the customer audit trail.
(d) Ordinary Marklet administrator access is removed for those documents. Exceptional support access requires a named person, a stated reason, one building and a time-limited break-glass grant recorded in the customer audit trail.
(e) These controls reduce exposure but do not alter the customer's responsibility to identify an Article 6 lawful basis, an Article 9 condition and any Data Protection Act 2018 Schedule 1 requirements, and to store no more data than necessary.
8. AI features
(a) Relevant Customer Data is sent to Anthropic to provide requested AI functions such as summaries, categorisation, invoice extraction, Ask Mark and lease analysis.
(b) Customer Data is not used by Marklet to train third-party foundation models.
(c) Resident fire-safety documents in the designated category are withheld from AI features.
(d) AI outputs are assistive and can be overridden. Marklet does not make solely automated decisions that produce legal or similarly significant effects for individuals.
(e) Ask Mark conversation history is stored in the user's browser rather than on Marklet's servers, although individual prompts and relevant Workspace content are processed to produce each response.
(f) For legal updates, the title and published abstract of each new decision or instrument are sent to Anthropic in the United States for automated classification. Where an item is taken forward, the full public decision text is separately sent to Anthropic to be summarised; that step is started by a Marklet administrator rather than automatically. Anthropic retains API content for up to 30 days under its standard terms. Marklet limits the resulting update to information relevant to the legal development and does not use that processing to make decisions about the people named in a case.
10. International transfers
Some providers or their support operations are located outside the United Kingdom. In particular, Anthropic processes AI inputs and full public tribunal decisions in the United States. Where a restricted transfer occurs, Marklet uses an adequacy regulation where available or an appropriate safeguard such as the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum. Where Marklet relies on an appropriate safeguard, it completes and documents the required data protection test (also commonly called a transfer risk assessment) and adopts supplementary measures where required. The precise mechanism depends on the recipient, the processing covered and the current provider contract. A copy of relevant safeguards may be requested from privacy@marklet.io, subject to lawful redactions.
11. How long we keep personal data
Account and support records
for the customer relationship and afterwards for as long as reasonably needed for support, security, legal claims and business records
Billing and tax records
normally six years after the relevant financial period or transaction, and longer if required for a dispute or legal obligation
Workspace data
while the relevant Workspace exists and until the customer deletes it or instructs return or deletion under the DPA
Unit occupancy and membership history
a former leaseholder's or resident's name, email address, role, unit association and period remain in the unit history after their membership or access is removed and may be included in a period statement generated as a PDF for conveyancing. The history is retained for the life of the unit record unless the customer, as controller, lawfully corrects or deletes it or instructs Marklet to do so
Uploaded documents
not automatically deleted; retained while the Workspace exists unless the customer deletes them
Resident fire-safety documents
review prompts are issued for material not opened for 12 months; the customer records that it remains needed or deletes it; Marklet does not automatically purge it because Marklet may not know when the underlying need ends
Backups
deleted data may remain in restricted daily backups for up to seven days and is then overwritten
Audit trail
append-only audit records may survive deletion of the record described to preserve security and evidential integrity; summaries can contain names entered by the customer and are minimised where reasonably practicable
Public legal-update data
source metadata, classifications, summaries and short verified quotations are kept while relevant to maintaining the legal-update service. Full decision text is not stored: the public document is re-read from its source each time it is processed. A copy may be held for up to 30 days by Marklet's AI provider under that provider's own terms
Marketing records
until opt-out, then suppression details are retained to respect the opt-out
Where an erasure request concerns billing data, Marklet will delete or redact records it controls only to the extent that erasure applies; financial and tax records are normally retained for six years as stated above. Where appropriate, Marklet will submit a redaction request to Stripe. Stripe generally cannot action redaction of transaction data until at least 90 days after the transaction and may retain information for its own legal, regulatory, fraud-prevention or other lawful purposes. Marklet cannot require Stripe to erase data that Stripe retains in its own capacity.
These periods may be shortened or extended where required by law, litigation, security, fraud prevention or the controller's lawful instructions. Customers must export records they are legally required to keep before ending or deleting a Workspace.
12. Security
Marklet uses measures appropriate to the service and risks, including passwordless authentication, role-based access, configurable permissions, customer-level separation, encryption of stored files and email bodies using customer-specific keys, audit records, restricted administrator access, backups and documented internal security review. Deleting a building destroys its customer-specific encryption key, making encrypted files and email bodies unreadable.
Marklet achieved Cyber Essentials certification at the basic tier on 4 August 2026. This does not mean that Marklet holds Cyber Essentials Plus or has undergone penetration testing or an accredited security audit.
No online service can guarantee absolute security. Users must protect their email accounts, devices and access links, use appropriate permissions and report suspected misuse to hello@marklet.io.
13. Your rights
Depending on the circumstances, individuals may have rights to access, correct, erase or restrict personal data; object to processing based on legitimate interests or direct marketing; receive portable data; withdraw consent; and complain to a supervisory authority. These rights are subject to legal conditions and exemptions.
A person named in a public legal source may contact privacy@marklet.io even if they are not a Marklet user. Marklet will verify identity where necessary, make reasonable and proportionate searches, consider any request or objection case by case, and correct, restrict, erase or de-index controller data where the legal conditions are met. The right to erasure is not absolute; Marklet may retain limited information where itcan demonstrate overriding legitimate grounds for continuing to process, or where another exception in Article 17(3) applies, and will explain any refusal and the right to complain to the ICO.
For other Marklet controller data, contact privacy@marklet.io. For Workspace content, contact the relevant RMC, RTM company, residents' association or managing agent first; Marklet will assist that customer in accordance with the DPA. Removal of a person's membership or account access does not by itself erase an accurate historical record of their association with a unit. The customer must assess any request to correct, restrict or erase that history under Data Protection Law, including whether retention remains necessary for property administration, conveyancing, legal obligations or legal claims. We may need information to verify identity and locate the data.
14. Marketing and service messages
Operational messages about accounts, security, billing, Workspaces and changes to the Service are not marketing and may be necessary to provide the Service. If Marklet sends newsletters, offers or other promotional messages, recipients can opt out through the message or by contacting privacy@marklet.io. Opting out of marketing does not stop necessary service messages.
15. Cookies and device storage
Marklet uses authentication and session storage, user-selected interface preferences, a service worker anda service worker that caches application assets and, for a signed-in user, recently fetched Workspace data and any changes made while offline, all cleared on sign-out, per-device push-notification subscriptions, a local cache that may hold recently viewed Workspace data until sign-out, and Cloudflare Turnstile for bot protection. Website analytics does not store or read information on the device. The Cookie Policy explains these technologies, their duration and why Marklet does not presently display a consent banner. Users should sign out on shared or unmanaged devices to clear locally cached Workspace data.
16. Complaints
Please contact privacy@marklet.io first so we can try to resolve the issue. Individuals may also complain to the Information Commissioner's Office at ico.org.uk or by using the contact details published by the ICO. If another organisation controls the Workspace data, it remains responsible for responding to the complaint.
17. Changes to this Policy
We may update this Policy to reflect changes to Marklet, law or our suppliers. We will publish the new version and update the date above. Where a change materially affects how we use controller data, we will provide additional notice where appropriate.