Privacy notice
Big Brain Ltd, trading as Proper Blocks · ICO reg. ZC141151 · Last updated 22 August 2026
Who we are
Big Brain Ltd (company number 11209610, registered in England and Wales), trading as Proper Blocks, is the data controller for this website at properblocks.co.uk. We are registered with the Information Commissioner's Office under reference ZC141151. We also build and run the leaseholder portal at dennishouse.properblocks.co.uk, and where that portal holds information about you, we act for the company that manages your block, as set out next.
The current customer block is Dennis House. Dennis House RTM Company Ltd (company number 11620031, registered office Dennis House, Roman Road, London E3 5ER) is the right-to-manage company for that block, and it is the data controller for the personal data about its leaseholders, tenants, and contractors. That is true of the data in the portal and of the records it keeps outside it, such as paper files, board minutes, and correspondence with its professional advisers. For the portal we are its data processor: we hold and handle that data on its written instructions, under the services agreement between us, and we never use it for our own purposes. In plain terms the RTM company decides what is held and why, and we run the system that holds it. You can raise anything in this notice with either of us.
You can contact us at [email protected].
What we collect and why
When you register or are invited, we collect:
- Identity - first name, last name
- Contact - email, mobile number
- Your relationship to the building - your unit, role (leaseholder, tenant, managing agent, contractor), and any notes you supply
- Account security - password (stored as a PBKDF2-SHA256 hash, never plaintext), optional two-factor method, session history, last-login timestamp
- Service-charge transactions - the charges raised against your unit, the payments, refunds, credit notes, and overpayments recorded against them, the dates and amounts, and the running balance shown on your statement
As you use the portal we also log the actions you take (raising issues, uploading documents, posting messages) in an immutable audit log. This is a legal protection for both you and the block - it lets us prove what was done and by whom, if a dispute arises.
Lawful bases
We rely on:
- Legitimate interest for running the portal, supporting the block's management, and keeping an audit trail (Article 6(1)(f) UK GDPR).
- Legal obligation for service-charge accounts, statutory compliance records, and anything that must be retained under the Landlord & Tenant Act 1985 or the Building Safety Act 2022 (Article 6(1)(c)).
- Contract for giving you access to the portal and delivering services associated with your lease (Article 6(1)(b)).
Public registration via the noticeboard QR code
The block has a public QR code that opens a registration page at dennishouse.properblocks.co.uk/register. Anyone passing through Dennis House can use it to ask for an account.
The page asks for your name, email, mobile, and the unit you live in or own. The unit dropdown only shows unit numbers, never the name of the leaseholder. Nothing about the existing residents is revealed before you submit.
When the unit you select has a leaseholder on file with a working email address, that leaseholder is normally sent a one-time link to confirm they recognise you, and the directors take their response into account before granting access. The link works once. Where no leaseholder is on file, or for managing-agent and building-level requests, the directors review and decide the request themselves. They may contact you to verify your identity before granting access.
Registration tokens are stored as a one-way hash; the raw token only ever appears in the email we send. Submissions are rate-limited per IP and the audit log records each request, the leaseholder's decision, and the eventual finalisation.
Who we share data with
We only share your data with:
- The directors of your block's right-to-manage or resident-management company, and (where appointed) its managing agent - to run the block.
- Cloudflare (data processor, UK/EU regions) - to serve the website and portal over the internet, including database and file storage.
- Backblaze (data processor, US, with UK GDPR transfer safeguards) - the block's database is backed up to Backblaze B2 storage so it survives a failure at our main provider. The backup covers everything in the portal, including your name, contact details, unit, charges, and documents. It is encrypted before it leaves us and the key is not shared with Backblaze, so they hold a copy they cannot read.
- Google (Google LLC, US, with UK GDPR transfer safeguards) - the block's email runs on a Gmail mailbox. Email we send you, and email you send the block, is stored in that mailbox, and the portal reads those threads in so the directors can see the correspondence alongside the rest of the record. The content of those emails is therefore held by Google.
- OpenStreetMap and unpkg (US and EU) - the public "Report an issue" page shows a map. It loads the map pictures from OpenStreetMap and the code that draws the map from the unpkg service. Your IP address is shared with both when that page loads; nothing else about you is sent, and neither is used anywhere you are signed in.
- Twilio (data processor, US, with UK GDPR transfer safeguards) - to send SMS one-time codes for two-factor authentication if you choose the SMS option. Only the mobile number you supply is shared.
- Xero (data processor) - since 23 July 2026 we use Xero to keep the block's service-charge accounts. Each charge raised against your unit becomes an invoice in Xero under a contact in your name, so your name, email address, unit, and the amounts charged are shared. Payments and refunds recorded in Xero are read back to build the statement you see in the portal. Xero's own privacy notice sets out where it processes data and the safeguards it applies.
- Anthropic (data processor, US, with UK GDPR transfer safeguards) - the directors can ask the portal to draft the block newsletter for them. When they do, we send the Claude API from Anthropic a summary of the last 30 days of portal records so it can write the draft. That summary can include your unit number, charges raised against your unit, and the subject lines of correspondence with the block. Nothing is sent unless a director asks for a draft. Anthropic does not use data sent through its business API to train its models, and deletes what we send after 30 days.
- Cloudflare Workers AI (data processor, UK/EU regions) - when you photograph a bulky item for a collection booking, or a contractor uploads an insurance or accreditation document, the image is passed to a Cloudflare AI model that reads what is in it so the portal can fill the form in for you. The image is used only to produce that description and is not used to train the model.
- Professional advisers (solicitors, accountants, insurers, brokers) instructed by your block - only where needed for a specific matter.
- Regulators and courts - where we're required to by law.
We do not sell your data and we do not use it for marketing.
How long we keep it
We keep active account data for as long as you have a relationship with the block (lease, tenancy, employment as managing agent or contractor). After that we retain financial and audit records for the periods required by law - typically six years for service-charge accounting, longer for matters that are live or reasonably foreseeable (e.g. Building Safety Act records).
Documents that a director deletes from the portal are held for a 30-day retention period before being permanently deleted from our storage. During that window the directors can restore the document on request. After 30 days the file is gone. The audit log entry recording the deletion is kept indefinitely.
Your rights
Under UK GDPR you have the right to:
- Access the data we hold about you - sign in and use Account → Your data → Download my data, which gives you a file covering your account, the block's record of you, your units, your messages, and anything you have reported. Or email us.
- Correct data that is wrong - email us, or ask a director.
- Ask us to delete data, subject to our legal retention duties - sign in and use Account → Your data → Delete my account, or email us. The directors have one month to reply. Records we must keep, such as six years of service-charge accounting, have your name and contact details removed rather than the record itself destroyed.
- Object to or restrict our processing.
- Complain to the ICO (ico.org.uk) if you think we've got this wrong.
Cookies
We use one strictly-necessary session cookie to keep you signed in. No analytics cookies, no trackers, no third-party cookies. See the cookies page for detail.
Changes
If we change this notice we will update the "Last updated" date above and, for material changes, tell you in the portal.