Privacy Policy
Last updated: July 2026 · Version 1.1
1. Who we are, and our two roles
Lytom Housing is operated by Lytom ("we", "us", "our"). Contact: support@lytom.app. ICO registration reference: ZC189749.
We act in two distinct capacities:
- Data controller for the account data of the officers who use the app (your name, work email address, job title, and your posts on the community forum).
- Data processor for the case data your council records in the app (property addresses, landlord and tenant details, inspection findings, notices, penalties, correspondence, photographs and files). Your council is the data controller for this information and determines why and how it is processed. We process it only to provide the service, on the council's instructions, and never for our own purposes.
2. What data is processed
Account data (we are the controller):
- Name, work email address, job title and qualifications (as entered by you)
- Password (stored only as a secure hash by Firebase Authentication; we never see it)
- Organisation (council) name and your permission level within it
- Community forum posts and replies, which carry your name and council
Case data (your council is the controller):
- Property records, inspection findings, hazard assessments and schedules of works
- Landlord, agent and tenant names, addresses and contact details
- Notices, civil penalties, letters, case logs and diary entries
- Photographs and files uploaded to a case
3. How data is used
- To provide the Lytom Housing service to your council
- To generate the documents you ask the app to produce
- To provide AI drafting assistance when, and only when, an officer requests it (see section 5)
- To respond to support requests
- To secure the service and investigate misuse
- To comply with legal obligations
We do not sell data. We do not use case data for advertising, profiling, analytics or training AI models. We do not access case data except where necessary to provide support that the council has requested, or to investigate a security incident.
4. Legal basis
Legitimate interests (officers' account data): creating and administering accounts, providing access to the service, responding to support requests, and securing the service and preventing misuse. Individual officers may not be party to Lytom's agreement with the council, so this basis reflects how the service operates.
The council's own lawful basis (case data): case data is processed by councils in the exercise of their statutory housing enforcement functions (public task). Each council is responsible for its own lawful basis, privacy notices and data protection impact assessments for that data; we support these with the information in this policy.
5. AI drafting assistance
Some features can draft or tidy text using an AI model (OpenAI's API). This happens only when an officer presses an AI button - nothing is sent to the AI provider automatically. When used, the relevant case details (for example the hazards found, recipient names and the property address) are sent to OpenAI to produce the draft.
- OpenAI does not use data submitted via its API to train its models.
- API data is retained by OpenAI for up to 30 days for abuse monitoring, then deleted.
- Every AI draft is presented to the officer for review before it can be used; the officer remains responsible for its accuracy (see our Terms of Use).
Councils that do not wish to use AI assistance can simply not use the AI buttons; all documents can be written manually.
6. Sub-processors and data location
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Google Cloud / Firebase | Authentication, database, file storage, hosting | All account and case data | Database and files stored in London (europe-west2) |
| OpenAI | AI drafting, only when requested by an officer | The case details relevant to the requested draft | USA (EU-US Data Privacy Framework; API data not used for training; deleted within 30 days) |
We will inform councils before adding or changing sub-processors.
7. The community forum
The in-app community forum is shared across every council using Lytom Housing. Posts and replies display your name and council and are visible to all signed-in users at any council. Do not post personal data about tenants, landlords or identifiable cases. You can delete your own posts at any time, and content can be reported to us for removal.
8. Data retention
- Case data is retained for as long as the council's service agreement is active, and is deleted on the council's written instruction or at the end of the agreement.
- Account data is deleted when your account is deleted or your council leaves the service.
- Councils control their own retention of enforcement records within the app and should apply their own retention schedules.
9. Data security
- Encryption in transit (HTTPS/TLS) and at rest (Google Cloud encryption)
- Server-side security rules isolate each council's case data and are designed to prevent access by users from another council
- Role-based access controls configured by each council's account owner
- An immutable case log providing an audit trail of case activity
- Passwords hashed by Firebase Authentication; email verification required
10. Data breaches
If we become aware of a personal data breach affecting a council's data, we will notify the affected council without undue delay and, where reasonably practicable, within 24 hours, providing the information the council needs to meet its own obligations to the ICO and to data subjects.
11. Your rights (UK GDPR)
- Access: request a copy of your personal data
- Rectification: correct inaccurate data
- Erasure: request deletion of your data
- Portability: receive your data in a portable format
- Object / restrict: object to or restrict certain processing
For your account data, email support@lytom.app and we will respond within 30 days. For case data, requests should go to the council concerned (as controller); we will assist the council with available self-service exports, deletion and, where requested, a standard electronic export containing structured machine-readable data and uploaded files. We do not provide bespoke export formats or migration into another system.
12. Complaints
You have the right to complain to the Information Commissioner's Office (ICO): ico.org.uk · 0303 123 1113.
13. Changes to this policy
We may update this policy from time to time. Significant changes will be notified in the app or by email. The version and date at the top of this page always reflect the current policy.
14. Contact
Email: support@lytom.app. We aim to respond to all enquiries within 48 hours.