Last updated: March 2026

1. Who We Are

The Heron Residents Association ("we", "us", "our") is the residents association for The Heron, 5 Moor Lane, London, EC2Y 9BB. We operate the website at heronleaseholders.com for the benefit of residents and leaseholders.

For data protection queries, contact us at admin@heronleaseholders.com.

2. What Data We Collect

We collect and process the following personal data:

  • Email address — required to identify you and send login links.
  • Name — optional, used to personalise your experience.
  • Flat number — optional, used to identify your residency.
  • Last login date — recorded when you log in to the portal.

3. How We Use Your Data

We use your personal data solely to:

  • Verify your eligibility as a resident or leaseholder.
  • Send you secure, passwordless login links by email.
  • Provide access to residents-only content and services.

We do not use your data for marketing, share it with third parties, or sell it.

4. Legal Basis for Processing

We process your personal data on the basis of legitimate interests (Article 6(1)(f) UK GDPR) — specifically, the legitimate interest of the residents association in maintaining a secure, members-only portal for communication and governance purposes.

5. Data Storage and Security

Your data is stored in a secure database on a server based in the United Kingdom. Access to the database is restricted to authorised administrators of The Heron Residents Association. We use HTTPS for all data in transit.

Login is handled via time-limited email links. We do not store passwords.

6. How Long We Keep Your Data

We retain your personal data for as long as you remain a resident or leaseholder at The Heron, or until you request its deletion. If you move and are removed from the residents list, your data will be deactivated and may be deleted upon request.

7. Third-Party Services

We use the following third-party services which may process your data:

  • Resend (resend.com) — used to deliver login emails. Your email address is transmitted to Resend for this purpose. See Resend's Privacy Policy.

8. Your Rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten").
  • Restrict or object to processing.
  • Data portability — receive your data in a portable format.

To exercise any of these rights, please contact us at admin@heronleaseholders.com.

9. Cookies

We use a single session cookie to keep you logged in. This cookie is strictly necessary for the operation of the portal and does not track you across other websites. No third-party tracking or advertising cookies are used.

10. Complaints

If you have concerns about how we handle your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.