Legal
Privacy notice
RepairClock is operated by Gauthier Matherat trading as Repairclock, 15 acol road flat 3 London NW63AA-UK (“we”). This notice explains how we handle personal data when you visit our website and when your organisation uses RepairClock. Contact: you@bygauthier.com.
Two roles
Your account data (your name, email, password hash, billing details, how you use the product): we are the controller.
Case data your organisation records (tenant and landlord names and contact details, property addresses, case notes, photos, letters): your organisation is the controller and we act as its processor, processing it only to provide the service on your instructions. Our Data Processing Addendum forms part of the terms.
What we collect and why
- Account and organisation details — to provide the service (contract).
- Billing information — handled by Stripe; we never see full card numbers (contract, legal obligation).
- Product usage events (e.g. “case created”) — to improve the product and support you (legitimate interests). Demo-workspace activity is flagged and excluded.
- Security logs and rate-limiting data — to protect the service (legitimate interests).
- Marketing-site analytics — anonymous counts of page and tool use (legitimate interests).
Sub-processors
We use a small number of providers to run RepairClock. Depending on configuration these are:
- Hosting and database (e.g. Vercel, a managed Postgres provider) — application hosting and storage.
- Resend — sending transactional email (letters to tenants, approval links, reminders).
- Stripe — subscription billing.
- Anthropic — only when your workspace uses “Improve with AI” on a letter. Tenant names, addresses, landlord and investigator names are removed before the text is sent; the AI suggestion is a draft you review.
- PostHog (EU) — product analytics, if enabled.
Where a provider processes data outside the UK, we rely on UK adequacy regulations or the International Data Transfer Addendum.
Retention
We keep account and case data while your subscription is active. When you close your workspace we delete it within 30 days, except where we must keep records (such as invoices) by law. Demo workspaces are deleted automatically after 24 hours.
Security
Passwords are hashed (bcrypt). Sessions use random tokens stored only as hashes. Uploaded files are fingerprinted (SHA-256) and served only to signed-in members of the workspace. Landlord approval links are single-purpose, expire, and are stored only as hashes.
Your rights
You can ask for access to, correction or deletion of your personal data, object to or restrict processing, and ask for portability. If your data is in a workspace run by a letting agent or landlord, contact them first — they control that data. You can complain to the Information Commissioner's Office (ico.org.uk).
Last updated: October 2026.