1. Who we are
Fundsure Ltd, registered in England and Wales (Company number 12804657). Registered address: 3rd Floor, 45 Albemarle Street, Mayfair, London, W1S 4JL.
ICO registration: ZB012773. Trading as PRS Shield at prs-shield.co.uk. Contact: support@prs-shield.co.uk
2. What data we collect
- Account data: name, email address, phone number
- Property data: addresses, certificate expiry dates, EPC ratings
- Tenant data: name, date of birth, nationality, email, phone number
- Compliance check data: AML screening results, Right to Rent verification outcomes, sanctions check reports
- Payment data: processed by Stripe — we do not store card details
- Usage data: login times, actions taken (maintained as part of the immutable audit trail)
3. Why we collect it (lawful basis)
- Legal obligation: HMRC AML supervision requires us to conduct and retain compliance records for a minimum of 5 years
- Contract: to deliver the PRS Shield service you have subscribed to
- Legitimate interests: fraud prevention and service improvement
4. How long we keep it
Minimum 5 years from the date of each compliance record, as required by HMRC AML regulations. Account data is retained for the duration of your subscription plus 5 years.
All data is stored on Supabase's SOC 2 Type 2 audited infrastructure. Documents and compliance records are encrypted at rest and in transit. Supabase undergoes independent annual SOC 2 audits covering security, availability, and confidentiality controls.
5. Who we share it with
- SmartSearch (Landmark Information Group): sanctions screening and digital identity verification. SmartSearch is certified against the UK Government's Digital Identity and Attributes Trust Framework (DIATF) and listed on the official DVS Register maintained by the Office for Digital Identities and Attributes (OfDIA)
- Stripe: payment processing
- BoldSign: e-signature services
- Supabase (DigitalOcean infrastructure, EU region): secure database and file storage hosting. SOC 2 Type 2 certified.
- Resend: transactional email delivery
- HMRC: as required by our AML supervision obligations
- National Crime Agency: if a Suspicious Activity Report is required
We do not sell your data to third parties.
6. Your rights (GDPR)
You have the right to access, rectification, erasure (subject to legal retention obligations), restriction, portability, and objection. To exercise any of these rights, contact support@prs-shield.co.uk.
You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
7. Cookies
See our Cookie Policy for details on how we use cookies.
8. Changes to this policy
We may update this policy from time to time. The latest version will always be available at this page. Last updated: March 2026.