Protected by design
Your property records, held with care.
Sensitive financial, tenancy and property records deserve more than a vague promise. Tendmere combines protected connections, encrypted recovery, dedicated EU infrastructure and accountable privacy controls.
TLS + encrypted backups
Data protection
EU data centres
Data residency (UK-adequate)
UK GDPR controls
Privacy programme
FCA-authorised partner
Open Banking setup
Security measures
How we protect your data
Encryption in transit
All data transmitted between your device and our servers is encrypted using TLS 1.3, the latest transport security protocol.
Encrypted recovery
Database backups and recovery key material are encrypted with AES-256 before retention or off-server transfer.
Dedicated EU hosting
Core application, authentication, file, and database services run on dedicated EU-hosted infrastructure controlled by Tendmere. Carefully selected subprocessors are governed by documented data-protection safeguards.
UK GDPR controls
Tendmere is designed and operated to support UK GDPR and Data Protection Act 2018 obligations, including access, correction, portability, and deletion requests.
Accountable privacy programme
Privacy requests, processor records, access controls, incident handling, and retention decisions are managed under our documented data-protection programme.
FCA-authorised Open Banking partner
When Open Banking is enabled, it will use a provider authorised and regulated by the Financial Conduct Authority, with read-only access only. Live bank feeds remain gated by partner credentials.
No credential storage
We never see or store your bank login credentials. When Open Banking is enabled, the connection is handled entirely by our FCA-regulated partner — Tendmere only receives read-only transaction data.
Regular backups
Automated daily encrypted backups, off-server retention, and disposable restore drills protect recovery from hardware failures and incidents.
Access controls
Row-level security ensures you can only access your own data. Multi-factor authentication available for all accounts.
Audit logging
All significant actions are logged with timestamps for accountability and compliance audit trails.
Vulnerability monitoring
Continuous dependency scanning and security monitoring to identify and patch vulnerabilities before they become threats.
Data portability
Use the available CSV and PDF exports, or request a complete copy through our privacy data-request process. There are no exit fees.
Our promise
Data handling principles
Minimise collection
We only collect data necessary to provide the service. No tracking beyond essential analytics.
Never sell
Your data is never sold, rented, or shared with third parties for marketing. Period.
Protect every route
Connections use TLS; database backups and recovery key material are AES-256 encrypted before retention or off-server transfer.
Control data routes
Core services stay on dedicated EU infrastructure. We assess subprocessor locations and put the required UK data-protection safeguards in place.
Let you leave
Use available CSV exports or request a complete copy or account deletion through our privacy data-request process.
Be transparent
Our privacy policy is written in plain English. No legalese walls. No hidden clauses.
FAQ
Security questions
Found a vulnerability?
We welcome responsible disclosure. Email us and we’ll acknowledge your report promptly.
Your data is safe. Start managing.
Review Tendmere's current transport, storage, access-control and EU-hosting posture for the controlled web beta.
No credit card required · Controlled web beta for 1-2 properties
