Gatha Privacy Policy

Last updated: 14th July 2026

Version: 1.3

Thanks for using Gatha. This Privacy Policy explains what personal data we collect when you use the Gatha app and website, why we collect it, how we look after it, and the rights you have over it.

We have tried to write this in plain English. If anything is unclear, contact us using the details in Section 17 and we will explain it properly.


1. Who we are

Gatha is a trading name of UK Homes Network Ltd, a company registered in England and Wales (company number 15316798).

UK Homes Network Ltd 5 Stubbs Grove, Coventry, West Midlands, CV2 3GD Email: [email protected] or [email protected] Telephone: 07751 589563

UK Homes Network Ltd is the data controller for the personal data described in this policy. That means we decide why and how your personal data is processed.

We are registered with the Information Commissioner's Office (ICO) as a data controller. Registration number: ZB644160.

This policy covers:

  • the Gatha mobile app (iOS)

  • the Gatha web app at app.gatha.uk

  • the Gatha marketing website at gatha.uk

2. The laws we follow

We process your personal data in accordance with:

  • the UK General Data Protection Regulation (UK GDPR)

  • the Data Protection Act 2018

  • the Privacy and Electronic Communications Regulations (PECR), which govern cookies and electronic marketing

Where we operate features covered by the Online Safety Act 2023 (user-to-user content such as posts, comments and messages), we also maintain the safety, reporting and moderation measures described in Section 12.

3. What Gatha is for

Gatha is a professional networking platform for people working in and around UK property and trades: developers, investors, agents, lenders, trades professionals and service providers. The data we collect exists to run that community, keep it safe, and provide the features you sign up for.

4. The personal data we collect

We only collect data you give us directly or data generated by your use of Gatha. We do not buy data about you from third parties or scrape it from other platforms.

4.1 Account data

When you register we collect:

  • Email address: used to create and secure your account, verify your email, reset your password, and send you service messages.

  • Name or username: shown on your profile and attached to your posts and comments so other members know who they are talking to. You do not have to use your legal name, though we encourage it in a professional community.

  • Password: stored only in securely hashed form through our authentication provider. We never see or store your password in plain text.

  • Phone number (optional): you may choose to add a phone number to your account. This is entirely optional and you can use Gatha fully without providing one.

4.2 Profile data

You can choose to add:

  • a profile photo

  • your trade or profession and your role

  • your location and the first half of your postcode (your "postcode area", for example "M1" or "SW1"), which we use to show you relevant local members, content and job opportunities. This is optional: you can opt out of providing a postcode during onboarding, and you can remove it at any time in your profile settings. We never ask for your full postcode or street address.

  • other profile details such as a bio, company name or links

Profile data is visible to other members as part of your public profile. Only add what you are comfortable sharing.

4.3 Content you create

  • Posts and comments are visible to other members and should be treated as public within the community. Do not post personal information you would not want widely seen.

  • Direct and group messages are private between you and the recipients. We do not read them in the normal course of business. We may access specific messages only where needed to investigate a safety report, suspected abuse or a legal obligation (see Section 12).

4.4 Technical and usage data

  • Device and connection data: IP address, device type, operating system and app version, used for security, fraud prevention and making the app work on your device. We may derive an approximate location (country or city) from your IP address for security purposes.

  • Push notifications: push notifications are not enabled in the current version of the Gatha app, and we do not currently collect device push tokens. If we introduce push notifications in a future release, we will collect a unique device token that allows us to send notifications to your device, and we will update this policy before doing so. You will always be asked for permission first, and you will be able to turn notifications off at any time in your device settings.

  • Usage events: we record actions such as logins, screens visited and features used in our own first-party analytics system, stored in our own database. No third-party analytics company receives this data. We use it to understand which parts of Gatha are used, fix problems and improve the product. On the web, where this involves cookies or similar technologies stored on your device, we only set them with your consent (see Section 15).

  • Crash and error data: if the app or website encounters an error, technical details about the error, your device and your session are sent to our error monitoring provider (Sentry) so we can diagnose and fix the problem. This includes your account identifier and your IP address, so that we can identify which account and session an error relates to.

4.5 Payment data

If you subscribe to a paid product such as Gatha Verified:

  • On iOS, payment is taken by Apple through your App Store account. Subscription status is managed through our subscription provider (RevenueCat). We receive confirmation of your subscription status, not your payment details.

  • On the web, payment is processed by Stripe, a PCI-DSS compliant payment processor. Your card details go directly to Stripe.

We never see or store your card numbers ourselves, on any platform. We hold only the records we need to know what you have subscribed to, manage your membership and meet our accounting obligations.

4.6 Data we do not collect

At present we do not collect:

  • identity documents or formal ID verification data

  • your device's GPS or precise location. The Gatha app does not request location permission and cannot access your device's location.

  • special category data as defined in Article 9 UK GDPR (such as health data, racial or ethnic origin, political opinions or religious beliefs), unless you voluntarily include such information in content you post, which we neither request nor require

If we introduce identity or professional verification in future, Section 14 explains how we will handle that.

5. Why we process your data and our lawful bases

UK GDPR requires a lawful basis for every use of your personal data. Ours are:

Creating and running your account, and delivering the core features of Gatha Data involved: account, profile, content. Lawful basis: Contract (Article 6(1)(b)), processing necessary to provide the service you signed up for.

Processing subscriptions and payments Data involved: payment and subscription records. Lawful basis: Contract, plus legal obligation (Article 6(1)(c)) for tax and accounting records.

Keeping Gatha secure: preventing fraud, abuse and malicious access Data involved: IP address, device data, security logs. Lawful basis: Legitimate interests (Article 6(1)(f)), protecting our members and platform.

Fixing crashes and errors Data involved: crash and error data. Lawful basis: Legitimate interests, maintaining a working, reliable service.

Understanding how Gatha is used and improving it Data involved: first-party usage events. Lawful basis: Legitimate interests, product improvement using data we hold in our own systems.

Moderating content, handling reports and complying with online safety duties Data involved: content, reports, related account data. Lawful basis: Legitimate interests and legal obligation.

Sending you service messages (verification, password resets, important notices) Data involved: email address. Lawful basis: Contract. These messages are part of running your account and cannot be opted out of while you hold an account.

Sending you marketing or community update emails Data involved: email address. Lawful basis: Consent (Article 6(1)(a)), only where you have opted in. You can withdraw at any time via the unsubscribe link or your settings.

Sharing your individual data with lenders, agents or other partners Data involved: see Section 6. Lawful basis: Consent, explicit opt-in only.

Where we rely on legitimate interests, we have carried out a balancing assessment to make sure our interests do not override your rights. You can object to any legitimate interests processing (see Section 10).

6. Insights, reports and data sharing with partners

We want to be upfront about this section because it is the part of our business model that involves your data beyond simply running the app.

6.1 Aggregated and anonymised insights

We produce market insight reports for organisations in the property industry, such as lenders and agents. These reports are built from aggregated data: for example, trends in activity by region, profession mix, or demand patterns.

Before any data is used in these reports, we apply recognised anonymisation and aggregation techniques designed to prevent identification of any individual, including minimum group size thresholds so that figures relating to small groups are suppressed rather than published. We assess our approach against the ICO's anonymisation guidance, including the risk of identification by combining our figures with other available information.

If a dataset could still reasonably be traced back to an individual, we treat it as pseudonymised personal data. Pseudonymised data is only ever shared under Section 6.2 with your consent, never under this section.

We have carried out a data protection impact assessment (DPIA) covering our insight and data sharing activities.

6.2 Individual-level sharing with partners

In some cases, partners may wish to connect with individual members, and members may benefit from that: for example, an investor who wants to hear from development finance lenders.

We will only share your individual profile or activity data with a partner where you have given explicit opt-in consent, and that consent works as follows:

  • You will always be told exactly who receives your data. At the point you give consent, we will name the specific partner organisation, or where consent covers a category, we will define that category precisely (for example, "regulated UK bridging and development finance lenders who are current Gatha partners, listed at gatha.uk/partners") and maintain a public, up-to-date list of the organisations in it. We will not rely on broad descriptions such as "lenders and agents".

  • You will be told exactly what is shared and why: the specific data fields, the purpose, and what the partner is permitted to do with them.

  • Nothing is shared unless you actively opt in. Consent is never pre-ticked, bundled into signup, or a condition of using Gatha.

  • If a partner will contact you with marketing, your consent will specifically and separately cover receiving marketing communications from that partner, as required by the Privacy and Electronic Communications Regulations.

  • You can withdraw consent at any time in your settings or by contacting us, and we will stop sharing from that point. Withdrawing consent never affects your ordinary use of Gatha.

What happens once a partner receives your data. The partner becomes an independent data controller of the data they receive, and their own privacy policy governs their use of it. Before sharing anything, we put a data sharing agreement in place with each partner, consistent with the ICO's Data Sharing Code of Practice, restricting their use of your data to the purposes you consented to and requiring them to honour your data protection rights.

If you correct or delete your data. Where you exercise your rights of rectification or erasure over data we have already shared under this section, we will notify each partner who received it, as required by Article 19 UK GDPR, so they can update or delete their copy.

We do not sell your personal data to third parties outside this consent-based arrangement, and we never share your private messages with partners.

6.3 Members joining from UK Homes Network

If your account is being migrated from the UK Homes Network app, nothing in Section 6.2 applies to you automatically. Specifically:

  • your data will not be shared with any partner under Section 6.2 unless and until you give the explicit opt-in consent described above, after migration

  • the promises made to you under the UK Homes Network privacy policy about not selling or giving away your personal data continue to be honoured unless you actively choose otherwise

  • before migration you will receive advance notice explaining the move to Gatha, what changes, and how to delete your account before the migration takes place if you prefer not to move across

7. Who processes data on our behalf

We use a small number of carefully chosen service providers (processors and sub-processors) to run Gatha. Each is bound by a data processing agreement and may only use your data on our instructions.

Supabase (EU) Our core backend: database, authentication, file storage and realtime features. Hosted in the EU.

Hostinger (UK/EU) Hosting for our web application.

Cloudflare (global network, see Section 8) Content delivery and security for our websites and media.

Sentry (USA, see Section 8) Crash and error monitoring.

Brevo (EU) Sending transactional emails such as verification, password resets and notifications, and marketing emails where you have opted in.

RevenueCat (USA, see Section 8) Subscription management for in-app purchases on iOS.

Stripe (USA, see Section 8) Payment processing for web subscriptions. Stripe handles your card data directly and is PCI-DSS compliant.

Apple (global) App distribution and payment processing through the App Store.

We may add media hosting or content delivery providers (for example, for video storage) or substitute a provider above with an equivalent one offering the same or better protections. The current, authoritative list of our sub-processors is always available at gatha.uk/sub-processors and material changes will be reflected in an updated version of this policy.

8. International transfers

Most of your data is stored in the UK and EU. Some providers process data in the United States or across global networks: currently Sentry, RevenueCat and Stripe (USA), and Cloudflare (a global network including US locations). For each of these transfers, we ensure one of the following safeguards is in place:

  • the provider is certified under the EU-US Data Privacy Framework and its UK Extension (the UK-US Data Bridge), or

  • we have Standard Contractual Clauses with the UK International Data Transfer Addendum (or the ICO's International Data Transfer Agreement) in place with the provider

We carry out and keep on record a transfer risk assessment for each transfer relying on contractual safeguards. These mechanisms give your data legally enforceable protection equivalent to UK standards. You can ask us for more detail on the safeguard applying to any specific provider using the contact details in Section 17.

9. How long we keep your data

  • Account and profile data: kept while your account is active. When you delete your account, we delete or anonymise your personal data within 30 days, except where we must keep specific records for legal reasons.

  • Encrypted backups: deleted data may persist in our encrypted database backups for up to 35 days after deletion before those backups cycle out. Backups are not used for any purpose other than disaster recovery.

  • Content: posts and comments are deleted or fully anonymised when you delete your account or the individual content. Messages you sent may remain visible to recipients, in the same way an email you sent remains in the recipient's inbox.

  • Payment and subscription records: kept for 6 years to meet HMRC and accounting requirements.

  • Security logs: kept for up to 12 months.

  • Crash and error data: retained by our monitoring provider for a rolling period of up to 90 days.

  • Moderation records: reports and enforcement records are kept for up to 2 years after account deletion where necessary for safety and to prevent banned users returning, or for up to 6 years where connected to actual or anticipated legal claims.

10. Your rights

Under UK GDPR you have the right to:

  1. Be informed about how we use your data (this policy)

  2. Access a copy of the personal data we hold about you

  3. Rectify inaccurate or incomplete data

  4. Erasure: ask us to delete your data (this applies in most circumstances, though there are legal exceptions)

  5. Restrict processing in certain situations

  6. Data portability: receive your data in a structured, machine-readable format

  7. Object to processing based on legitimate interests, and to any direct marketing (marketing objections are absolute and we will always stop)

  8. Withdraw consent at any time, where consent is our lawful basis, without affecting the lawfulness of what was done before withdrawal

  9. Not be subject to solely automated decisions with legal or similarly significant effects. We do not currently make any such decisions about you.

To exercise any right, contact us using Section 17. We will respond within one month. We do not charge for requests unless they are manifestly unfounded or excessive. If you are unhappy with our response, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to resolve your concern first.

11. Deleting your account

You can delete your account at any time:

  • In the app: Settings, then Privacy & Data, then Delete Account

  • On the web: app.gatha.uk/account/delete

  • By email: contact us using Section 17 and we will action it for you

Deletion is permanent and immediate. It removes your profile, your posts and comments, your messages, your projects, your uploaded media, and your login credentials. Your account cannot be recovered or logged back into. Some records are retained where the law requires it, as set out in Section 9.

Active paid subscriptions taken through Apple must also be cancelled separately in your App Store subscription settings (iPhone Settings, then your name, then Subscriptions), as Apple controls that billing relationship. Deleting your Gatha account does not cancel an Apple subscription, and Apple will continue to charge you until you cancel it there.

12. Community safety, moderation and the Online Safety Act

Gatha hosts user-generated content, and we take our duties to keep the community safe seriously. From launch:

  • Community Guidelines set out what is and is not acceptable

  • Every post, comment, profile, job listing, project and message can be reported in-app. Reports can be filed under the categories Spam, Harassment, Inappropriate, or Misinformation.

  • You can block any member. Blocking works in both directions: neither of you will see the other's posts, comments, projects or profile, and neither of you can send messages to the other. Blocking also removes any existing connection between you. You can review and undo your blocks at any time in Settings, then Security & Privacy, then Blocked Users.

  • Reports are reviewed by our moderation team, and we may remove content, restrict features, suspend or ban accounts

  • We may access otherwise private content (such as a reported message) where necessary to investigate a report, protect members or comply with the law

  • We maintain a complaints process for both the person reporting and the person reported

We may disclose personal data to law enforcement or regulators where we are legally required to, or where necessary to protect someone from serious harm.

13. Children

Gatha is a professional platform for people working in the UK property and trades industries and is not intended for anyone under 18. We do not knowingly collect personal data from under-18s. We have assessed the likelihood of the service being accessed by children in line with the Online Safety Act 2023 and the ICO's Age Appropriate Design Code, and we keep that assessment under review.

If you believe someone under 18 is using Gatha, contact us immediately (Section 17) and we will investigate and remove the account where appropriate.

14. Future changes to verification

We may in future introduce identity or professional verification features (for example, verifying trade accreditations or professional status). If we do:

  • we will update this policy before launching the feature, explaining exactly what data is collected, who processes it, and on what lawful basis

  • verification will introduce new data categories only with clear notice to you

  • if any special category data were ever involved, we would identify an appropriate Article 9 condition and tell you before collecting it

You will never be enrolled into a verification process silently.

For clarity: Gatha Verified, our premium membership, is a paid subscription tier and does not involve identity or credential verification. Our Terms of Service explain exactly what Gatha Verified includes.

15. Cookies and similar technologies

The Gatha mobile app does not use cookies.

Our website and web app use a small number of cookies and similar technologies:

  • Strictly necessary: keeping you logged in, security and fraud prevention (including Cloudflare security cookies). These do not require consent.

  • Analytics and preferences: only set with your consent via our cookie banner, where used.

You can manage cookies through our cookie settings and your browser. A full cookie list is available at gatha.uk/cookies.

16. Security and data breaches

We use appropriate technical and organisational measures to protect your data, including encryption in transit and at rest, hashed passwords, access controls, EU-hosted infrastructure and the safeguards described in Section 8.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the ICO within 72 hours as required, and we will tell you directly without undue delay where the risk to you is high.

You are responsible for keeping your own login credentials secure. Use a strong, unique password and contact us immediately if you believe your account has been compromised.

17. Contact us

For any questions about this policy, your data, or to exercise your rights:

UK Homes Network Ltd (trading as Gatha) 5 Stubbs Grove, Coventry, West Midlands, CV2 3GD Email: [email protected] (general support and data requests) Email: [email protected] (data protection requests) Telephone: 07751 589563

18. Changes to this policy

We may update this policy from time to time, for example when we add features or change providers. The date at the top shows the latest version. For material changes, we will notify you in the app or by email before the changes take effect, and where the change involves a new use of your data requiring consent, we will ask for it.