Last updated: 11 February 2026
This policy explains how MainDesk collects, uses, stores, and protects your personal data in compliance with UK GDPR and the Data Protection Act 2018.
MainDesk ("we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our platform at maindesk.co.uk (the "Service").
We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy applies to all users of our Service, including administrators, staff members, and any other individuals who access or use the platform.
Please read this Privacy Policy carefully. By using our Service, you acknowledge that you have read, understood, and agree to the collection and use of your information as described in this policy. If you do not agree with our policies and practices, please do not use our Service.
MainDesk operates the platform at maindesk.co.uk and provides HMO operations and compliance software for supported housing providers in the United Kingdom. We are a data controller for the purposes of UK GDPR, meaning we determine the purposes and means of processing your personal data.
Our registered business address and contact details are provided in Section 14 of this policy. When we refer to "we", "us", or "our" in this policy, we mean MainDesk.
We collect and process various categories of personal data to provide and improve our Service. The types of information we collect depend on how you interact with our platform. We collect this information directly from you when you register, use the Service, or contact us, and automatically through your use of the platform.
We collect the following personal identification information:
We collect information related to your account and platform usage:
We collect operational data that you create or upload through the Service:
Note: When you process tenant data through our Service, you act as a data controller and are responsible for ensuring you have appropriate legal basis and consent for processing that data.
We automatically collect technical information when you use our Service:
In some cases, you may upload or create content that contains special category personal data (such as health information in support logs). We process this data only as necessary to provide the Service and in accordance with your instructions. You are responsible for ensuring you have appropriate legal basis for processing special category data.
We use your personal data for the following specific purposes:
Under UK GDPR, we must have a lawful basis for processing your personal data. We process your data under the following legal bases:
We process your personal data to perform our contract with you and provide the services you have requested. This includes:
We process your data to comply with our legal obligations, including:
We process your data based on our legitimate interests, balanced against your rights and freedoms:
You have the right to object to processing based on legitimate interests (see Section 11).
Where we rely on consent, we will:
We typically seek consent for: marketing communications, non-essential cookies, and optional features.
We implement comprehensive technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction:
In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours and inform affected users without undue delay, in accordance with UK GDPR requirements.
We retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy, unless a longer retention period is required or permitted by law. Our retention periods are based on:
When data is no longer needed, we securely delete or anonymise it in accordance with our data retention policies. Anonymised data (which cannot identify individuals) may be retained indefinitely for statistical and analytical purposes.
You may request deletion of your data at any time (subject to legal obligations). See Section 11 for information about your right to erasure.
We do not sell your personal data. We may share your data with the following categories of third parties, only as necessary to provide the Service:
We work with trusted third-party service providers who help us operate the platform:
All service providers are contractually bound to protect your data and use it only for specified purposes.
We may disclose your data if required by law or to:
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the new entity. We will notify you of any such change and ensure your data continues to be protected in accordance with this policy.
We Never:
Your data is primarily stored and processed within the United Kingdom. However, some of our service providers may be located outside the UK. When we transfer your personal data outside the UK, we ensure appropriate safeguards are in place to protect your data in accordance with UK GDPR requirements.
If you would like more information about the specific safeguards we use for international transfers, please contact us using the details in Section 14.
We use cookies and similar tracking technologies to enhance your experience on our platform. Cookies are small text files stored on your device when you visit our website.
These cookies are necessary for the platform to function and cannot be disabled:
These cookies help us understand how you use the platform (you can opt out):
These cookies remember your preferences (you can opt out):
You can manage cookie preferences through your browser settings. Most browsers allow you to refuse or delete cookies. However, disabling essential cookies may affect platform functionality. For more information about managing cookies, visit allaboutcookies.org.
Under UK GDPR, you have several rights regarding your personal data. You can exercise these rights at any time by contacting us at hello@maindesk.co.uk. We will respond to your request within one month (or inform you if we need more time).
You have the right to request a copy of the personal data we hold about you, including information about how we process it. We will provide this in a commonly used, machine-readable format.
You can request correction of inaccurate or incomplete personal data. You can also update much of your information directly through your account settings.
You can request deletion of your personal data in certain circumstances, such as when:
Note: We may not be able to delete data if we have a legal obligation to retain it.
You can request that we limit how we process your data in certain circumstances, such as when you contest the accuracy of the data or object to processing while we consider your objection.
You can object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
You can request a copy of your data in a structured, commonly used, machine-readable format. This applies to data you have provided and which we process based on consent or contract.
Where processing is based on consent, you can withdraw consent at any time. This will not affect the lawfulness of processing before withdrawal.
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe we have not handled your personal data correctly. Visit ico.org.uk for more information.
How to Exercise Your Rights: To exercise any of these rights, please email us at hello@maindesk.co.uk with "Data Protection Request" in the subject line. We may need to verify your identity before processing your request.
MainDesk is not intended for use by children under the age of 16. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at hello@maindesk.co.uk, and we will delete such information.
If you are under 16, please do not use our Service or provide any personal data to us. If we become aware that we have collected data from someone under 16, we will take steps to delete that information promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational, legal, or regulatory reasons. We will notify you of any material changes by:
We encourage you to review this policy periodically to stay informed about how we protect your data. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy. If you do not agree to the changes, you may close your account or stop using the Service.
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact us:
MainDesk
Email: hello@maindesk.co.uk
Website: maindesk.co.uk
For data protection enquiries, please include "Data Protection" in your subject line to ensure your message is handled promptly.
If you have concerns about how we process your personal data, you can also contact the Information Commissioner's Office (ICO), the UK's data protection regulator:
ICO Website: ico.org.uk
ICO Helpline: 0303 123 1113