Legal
Privacy policy
Effective date: 24 September 2026 · Version 1.0
This Privacy Policy explains how Sefki Huseyin trading as Meskora ("Meskora", "we", "us" or "our"), handles personal information in connection with meskora.com, app.meskora.com, the Meskora mobile apps, demonstrations, sales, support and the Meskora property-operations software service (the "Service").
1. Who we are
Legal operator: Sefki Huseyin, a sole trader in the United Kingdom, trading as Meskora.
Business address: Suite RA01, 195-197 Wood Street, London E17 3NU.
Privacy contact: privacy@meskora.com. General contact: contact@meskora.com.
ICO registration number: ZC255598.
2. When Meskora is controller and when it is processor
We act as a data controller when we decide why and how personal information is used for our own business purposes, including website enquiries, account administration, billing records, security, product improvement, direct sales and legal compliance.
For personal information that a customer uploads to or creates in its Meskora workspace about owners, residents, tenants, guests, contractors, staff or other people ("Customer Content"), the customer will generally be the controller and Meskora will generally act as its processor. We process that Customer Content to provide the Service and in accordance with the customer’s documented instructions and our Data Processing Addendum.
A person’s role may vary by processing activity. This policy does not replace a customer’s own privacy notice to the people whose data the customer places in Meskora.
3. Personal information we may collect
| Category | Examples |
|---|---|
| Account and identity data | Name, business name, role, username, account identifiers, preferred language and authentication information. |
| Contact data | Business email, telephone number, postal address and communication preferences. |
| Subscription and billing data | Plan, unit count, invoices, payment status, transaction references, tax/VAT information and billing contact details. Payment-card details are normally handled by the payment provider rather than stored by Meskora. |
| Usage and device data | IP address, browser/device information, timestamps, login activity, audit events, feature usage and diagnostic information. |
| Sales and support data | Demo requests, correspondence, support tickets, call notes, feedback and attachments you send us. |
| Customer Content | Property, owner, resident, tenant, guest, reservation, maintenance, housekeeping, document, finance, contractor and communication information entered by customers. The precise content is controlled by the customer. |
| Security data | Authentication events, MFA/passkey status, recovery events, administrative actions, access grants and security logs. |
| Cookie/device storage data | Cookie identifiers, consent choices and similar storage/access information as described in our Cookie Notice. |
4. How we collect information
- You provide it directly when you book a demo, create an account, subscribe, contact us, use support or configure the Service.
- Your organisation provides it when an administrator creates your account or adds you to a workspace.
- It is generated automatically when you use the website or Service, for example security and audit logs.
- Customers upload or generate Customer Content in their workspaces.
- Payment, hosting, security, communications and other service providers may provide us with transaction or technical information needed to operate the Service.
- We may obtain business contact information from public business sources for proportionate business-to-business outreach, subject to applicable direct-marketing rules.
5. Why we use personal information and our lawful bases
| Purpose | Typical lawful basis (where Meskora is controller) |
|---|---|
| Provide accounts, subscriptions, demos, support and requested services | Contract; steps at your request before entering a contract. |
| Operate authentication, tenant isolation, audit trails, fraud prevention and platform security | Legitimate interests in protecting customers, users and the Service; legal obligation where applicable. |
| Billing, accounting, tax and business records | Contract; legal obligation; legitimate interests in managing our business. |
| Respond to enquiries and manage customer relationships | Contract / pre-contract steps; legitimate interests. |
| Improve reliability, usability and features using appropriately minimised operational data | Legitimate interests, balanced against users’ rights; consent where required for optional device storage/analytics. |
| Send service messages | Contract and legitimate interests. |
| Send marketing or sales communications | Legitimate interests for appropriate B2B communications, or consent where required. You can opt out at any time. |
| Establish, exercise or defend legal claims and comply with law | Legal obligation and legitimate interests. |
Where we rely on legitimate interests, we consider the necessity of the processing, our interests and the impact on individuals. Where consent is the appropriate basis, you may withdraw it at any time without affecting prior lawful processing.
6. Customer Content and special categories
Meskora is designed for property operations and is not intended to be used as a system for intentionally collecting special-category personal data (such as health, biometric, political or religious information) or criminal-offence data unless the customer has a lawful reason and appropriate safeguards. Customers are responsible for deciding what Customer Content they place in the Service and for providing any required notices and obtaining any required permissions.
7. Sharing personal information
We may share personal information only where necessary with:
- Infrastructure, hosting, storage, content-delivery, security and monitoring providers.
- Payment processors or merchant-of-record providers used to process subscriptions and refunds.
- Email, communications, support, scheduling and customer-relationship providers.
- Professional advisers such as accountants, insurers, auditors and lawyers.
- Authorities, courts or other recipients where required by law or reasonably necessary to protect legal rights, users or the Service.
- A purchaser, investor or successor in connection with a genuine business reorganisation, financing or sale, subject to appropriate confidentiality and data-protection safeguards.
The providers we currently use to run Meskora are: Cloudflare (network security, content delivery and inbound email for meskora.com); SMTP2GO (sending service and account emails); and Expo, Apple and Google (delivering push notifications to the Meskora mobile apps). Meskora's databases, file storage and backups are hosted on infrastructure we operate in the United Kingdom. Our payment provider is identified at checkout and on your invoice. An up-to-date list is available on request from privacy@meskora.com.
8. International transfers
Meskora's databases, file storage and backups are held in the United Kingdom. Some suppliers may process personal information outside the United Kingdom. Where UK transfer rules apply, we use an approved transfer mechanism or another lawful safeguard, such as the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, an adequacy regulation, or another mechanism permitted by law. Customers can request information about the relevant safeguards at privacy@meskora.com.
9. Retention
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and dispute-resolution requirements. Our intended retention approach is:
| Data | Typical retention approach |
|---|---|
| Account and contract records | For the customer relationship and then normally up to 6 years where needed for contract, tax or legal records. |
| Billing/tax records | As required by applicable tax and accounting law, commonly up to 6 years after the relevant period. |
| Support and sales correspondence | Normally up to 24 months after closure or last meaningful contact, unless required longer for an active customer or dispute. |
| Sign-in session records | Deleted 90 days after the session expires. |
| Security logs (sign-in events, IP addresses, device information) | 12 months. |
| Records of Meskora support and administrative access to workspaces | 24 months. |
| Activity history of a customer's own records | For the life of the workspace, then deleted with it. |
| Customer Content after termination | When a contract ends, the workspace becomes read-only and stays available for export for 30 days. The workspace and its Customer Content are then permanently deleted between day 31 and day 60, and we confirm the deletion in writing. Deleted data ages out of our backups by day 90 and is not restored from them except under a legal hold. |
| Marketing suppression records | A minimal suppression record may be kept for as long as needed to honour an opt-out. |
Where records are needed for a security incident, investigation or legal dispute, we place them on hold and keep them until the matter is closed.
10. Security
We use technical and organisational measures designed to protect personal information. The Service is designed around isolated customer workspaces, controlled support access, private file storage, authentication controls and auditable administrative actions. No internet service can guarantee absolute security, and customers must also protect credentials, devices and access permissions.
11. Your rights
Depending on the circumstances, UK data-protection law may give you rights to access, correct, erase or restrict personal information; object to certain processing; receive certain information in portable form; and withdraw consent where consent is used. You also have rights relating to certain solely automated decisions. These rights are subject to legal conditions and exceptions.
If your request concerns Customer Content held in a customer’s workspace, please contact that customer first because it will normally be the controller. We will assist customers with valid rights requests as required by our DPA and law.
To exercise a right concerning information for which Meskora is controller, contact privacy@meskora.com. We may need to verify your identity.
12. Complaints
Please contact us first at privacy@meskora.com so we can try to resolve your concern. You may also complain to the UK Information Commissioner’s Office (ICO) at https://ico.org.uk/make-a-complaint/ or to another competent supervisory authority where applicable.
13. Cookies and similar technologies
Our use of cookies and similar storage/access technologies is described in the Meskora Cookie Notice. We do not set non-essential cookies before obtaining consent where consent is legally required.
14. Children
The Service is intended for organisations and adult business users. It is not directed at children. Customers should not create user accounts for children unless they have a lawful basis, appropriate safeguards and a genuine operational need.
15. Automated decision-making
Meskora does not currently make decisions about individuals that have legal or similarly significant effects based solely on automated processing. If this changes, we will update this notice and provide the information required by law.
16. Changes to this policy
We may update this policy when our services, suppliers or legal obligations change. We will post the revised version with a new effective date and, where changes are material, provide an appropriate notice to affected users or customers.
This Privacy Policy is written in English. Any translation is provided for convenience only; if there is any inconsistency, the English version governs.
17. Contact
Sefki Huseyin trading as Meskora
Suite RA01, 195-197 Wood Street, London E17 3NU
Email: privacy@meskora.com
Website: https://meskora.com