Privacy Policy
Last updated: 17 September 2026
This policy explains what personal data Address Lens (addresslens.co.uk) collects, why we collect it, and the choices you have. Address Lens provides UK property dossiers, comparable searches, and neighbourhood evidence.
Who is responsible for your data
The data controller for personal data processed by Address Lens is Milen Pavlov, a sole trader trading as Address Lens, based in the United Kingdom. For anything relating to your personal data — questions, requests or complaints — contact support@addresslens.co.uk.
What we collect
- Account & profile. You may create a password-based account or use an enabled external sign-in provider. For password accounts we store a password hash, not the password itself. For external sign-in we receive the profile fields the provider supplies, such as name, email address, profile picture and provider identifier.
- Usage data. The properties and comparable searches you choose to save to your account. When optional analytics are enabled, we also record privacy-safe usage events (for example, which features are used) to help us improve the service. We do not keep a separate log of every address you look at.
- Reports you generate. When you generate or buy a report, we store a dated snapshot of it — the property address and the evidence shown in the report, and, if you add your own branding, the business name, contact line and logo you supply.
- Offer and negotiation details. If you create an Offer & Negotiation Pack, we store the asking price, your private maximum, priority, buying position, timing flexibility, selected conditions and any condition wording you provide for the same retention period as the report. Your private maximum and strategy remain in the private Pack. The separate agent offer sheet contains only the proposed offer and the buying position, timing and conditions you deliberately selected for agent use; it is not shared automatically.
- Saved Property Expert conversations. We store your questions, generated answers, evidence references and snapshots, AgentFlow run IDs, and usage metadata. They are saved against your signed-in account and property conversation so you can review the evidence Q&A later.
- Connected assistants and investigations. When you connect an approved assistant, we store the client name and identifier, the delegated permissions you grant, an opaque connection record, approval decisions, and the investigation offers and results created for your account. We also keep bounded security and commercial audit facts as described under Retention; they do not contain conversational text or evidence statements.
- Billing. If you subscribe, payments are processed by Stripe. We store your subscription status; we do not store full card details.
- Technical. A secure refresh-token cookie to keep you signed in, plus standard server logs (IP address, user agent) for security and diagnostics.
- Cookie preferences. We store your cookie choices in your browser so the consent banner does not appear on every visit.
How we use it
- To authenticate you and provide the Address Lens service.
- To save and display your comparable searches.
- To generate, store and let you share the reports you create.
- To produce optional AI-assisted summaries when you request them.
- To save and answer the Property Expert evidence questions you choose to submit.
- To operate, secure and audit the connected assistant permissions you choose to grant.
- To manage subscriptions and prevent abuse.
- To send necessary account, security and purchase emails so we can provide and protect the service.
- With your consent, to email you Address Lens product updates and offers. This is optional and separate from accepting our Terms and Privacy Policy. We record your choice, when it was made, where it was collected and the wording version. You can withdraw consent in Account settings, through the unsubscribe option in a product email, or by emailing support@addresslens.co.uk. Withdrawing does not affect your account or necessary service emails, or the lawfulness of processing before withdrawal.
Who we share it with
We share data only with the providers needed to run the service: enabled external sign-in providers, Stripe (payments), Resend (transactional email), Microsoft Azure (hosting and Application Insights), our PDF rendering service, and — only when you request an AI-assisted feature — the AgentFlow processing service and its deployed model provider. Property data is sourced from public datasets including HM Land Registry Price Paid, the EPC Register and the ONS Postcode Directory; see Data sources and licences. We do not sell your personal data.
Connected assistants
An approved third-party assistant can use Address Lens only after you sign in and grant its reviewed delegated permissions. Depending on those permissions and your request, it can submit an ordinary address or postcode, receive candidate display addresses and opaque references, prepare a no-charge investigation offer, and read investigation findings and source evidence. The assistant has its own privacy terms and already knows the query you asked it to send. Address Lens access tokens do not disclose your email address, contact details, property query, UPRN or first-party sign-in session.
Preparing an offer does not buy anything or consume credit. Paid work requires your explicit approval on the Address Lens approval page, where the frozen property, coverage, price or entitlement and material limitations are shown. You can cancel there instead. You can also review each connected assistant in your account and revoke it; revocation ends its delegated access and tokens without signing you out or deleting completed investigation records.
AI processing
Source evidence, report eligibility and fulfilment guardrails, and the core property briefing use fixed rules and recorded data. Some report sections or workflows may include clearly indicated AI-assisted wording when you select it and it is available. For that requested wording, we send only the evidence needed for the wording you requested — not your name or contact details — to our AI service provider, which returns the generated text. The fixed-rule evidence and guardrails continue to work without that optional wording.
Every AgentFlow request — requested wording, comparable-query interpretation, and Buyer Property Expert below — also carries a pseudonymous account identifier and an account-group identifier. These are internal reference codes, not your name, email address or any other contact detail, and the AI provider cannot identify you from them. We send them for run ownership and security: so a request can be attributed for rate limiting, abuse prevention and troubleshooting, and so the work is billed to the right account. They remain personal data under UK GDPR, so we list them here for transparency.
When you submit a Buyer Property Expert question, we send AgentFlow only the minimum bounded context needed for that turn: the current question, a rolling summary, recent messages, and fresh property evidence. We do not resend the full lifetime transcript on every turn, and we do not add your Address Lens account name or contact details to the Property Expert turn contract. Do not include unnecessary personal information in a question.
Property Expert application telemetry records only bounded operational facts such as status, duration, token counts, compaction and citation outcomes. It does not include question text, answer text, prompts, or raw evidence content. Address Lens does not use Property Expert conversation content to train models or improve prompts. Any such use would require separate explicit consent and approved governance. This statement describes Address Lens's use; the deployed model provider's practices must be separately verified before the feature can be enabled.
AI processing services, retention and deletion
Deleting a Property Expert conversation, or closing your account, promptly removes the copies held by Address Lens, including its saved transcript, evidence snapshots, idempotency records and locally held run metadata.
Buyer Property Expert will remain unavailable in production until bounded retention and deletion terms for those separate records, the applicable model provider and subprocessors, and their model-training and prompt-improvement terms have been verified and published in this policy. We do not state a retention duration or promise processor deletion until that evidence exists.
International transfers
Address Lens is operated from the United Kingdom and hosted on Microsoft Azure. Some of the providers we rely on are based outside the UK, or operate support and infrastructure outside it, so your personal data may be transferred abroad. This applies in particular to Stripe (payments), Resend (transactional email), Microsoft Azure (hosting and Application Insights), and the AgentFlow processing service and its deployed model provider when you use an AI-assisted feature.
Where a transfer leaves the UK, we rely on the transfer safeguards recognised under UK GDPR — a UK adequacy decision for the destination country, or the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses in our contract with that provider.
We are completing the per-provider record of hosting locations and safeguards, and will name the specific regions here once each is confirmed. We would rather leave this incomplete than state a location we have not verified. If you need the current position for a particular provider before then, contact us using the details below.
Retention
- Account data — kept while your account is active.
- Reports — a completed report snapshot is kept for 90 days and then automatically deleted. A public share link expires after 30 days (or when the report expires, if sooner) and can be revoked earlier.
- Saved comparable searches and saved properties — kept until you delete them or close your account.
- Saved Property Expert conversations. Each conversation is kept until you delete it, close your account, or a separately published retention policy removes it. The separate AgentFlow boundary is described above.
- Connected assistants and agent audit. A connection is kept until you revoke it or close your account. The query-friendly agent audit projection contains hashed account/client references, granted permissions, fixed operation and approval/credit outcomes, timestamps and a support correlation; it contains no address or evidence text, expires after 90 days, and is removed on account closure where permitted. Authoritative consent, credit, idempotency and purchased-investigation records follow the service's existing legal and account-erasure retention rules.
- Sign-in sessions — expire after around 30 days of inactivity.
- Server logs — standard security and diagnostic logs are kept for a limited period.
You can delete your data at any time — see Data deletion.
Cookies
Essential cookies are required for authentication, account security, and session management. Optional analytics cookies, when enabled, are used only after you consent. They help us understand which searches, reports, and workspace flows need improving. You can clear site data in your browser to reset your choice.
When analytics is enabled, we use Microsoft Azure Application Insights (our hosting provider, acting as our processor) to record privacy-safe usage — pages visited, buttons clicked, and a pseudonymous account identifier — to understand which flows to improve. We do not send your email, name, or property details to analytics, and your approximate location is derived only to city level and not stored as an IP address. You can withdraw analytics consent at any time from "Cookie preferences" in the footer.
Before you answer the cookie banner, we count page visits only. That count records the type of page (for example "a guide page" or "a property page" — never the address, postcode or property you looked at), and a random reference that groups the pages of a single visit so we can see, for instance, that a guide was read before the pricing page. It sets no cookie and stores nothing on your device, and the reference is discarded as soon as you close or reload the page, so it cannot recognise you again, link your visits, or identify you. We do not record your IP address. If you decline analytics, we stop this too — declining means we count nothing at all.
Your rights
Under UK GDPR you can request access to, correction of, or deletion of your personal data. You can also object to or restrict certain processing, and ask for a copy of your data in a portable format. If you can sign in, use Account to close your account. To exercise other rights, use the Data deletion page or email support@addresslens.co.uk. You also have the right to complain to the Information Commissioner, the UK supervisory authority for data protection, if you are unhappy with how we handle your data. We would appreciate the chance to address your concern first.
Contact
Questions about this policy: support@addresslens.co.uk.