Two roles, and which one applies
praeba is a software service for boutique commercial property firms. A firm gives praeba its property documents; praeba reads them, takes the facts stated on their face, and files those facts into the firm's own structured record — its book.
For everything inside a firm's book, the firm is the controller and praeba is the processor. praeba processes that material only on the firm's documented instructions, which are its engagement letter and its Data Processing Agreement. If you are named in a document a firm has given praeba, the firm — not praeba — decides what happens to it, and the firm is who to ask.
praeba decides for its own records: the account and sign-in details of the people at a firm who use the software, and correspondence sent to praeba directly.
The lawful bases for that second category, and the precise wording of the roles above, are part of the legal review this page is under. They are not settled here, and this page will be updated when they are.
What praeba collects, and why
Documents a firm gives it
Someone at the firm puts a file into their workspace — one at a time, or by dragging a whole folder onto the page — or emails it to a private intake address the firm is issued. praeba reads the file, returns the document's type and the facts on its face, and for a lease also a clause-level abstract with a clause or page reference and a confidence score for each field.
Those documents contain personal data: names, contact details and signatures of individuals, signatories, tenants' and landlords' representatives, and the firm's own contacts.
Mail sent to a firm's intake address
praeba watches no inbox. Mail reaches praeba because it was sent or forwarded to praeba's own address — never because praeba went and looked in anyone's mailbox.
A firm is identified by the address the mail arrived at, never by who sent it. The unguessable part of that address is a secret praeba minted and stored on the firm's own record. A sender cannot choose it, and a forged From: line proves nothing and gains nothing — the sender's address is recorded and never consulted.
Every notification of arriving mail is signature-verified before a byte of it is trusted.
A page a firm nominates
There is one thing praeba fetches by itself, and only when a firm asks it to: the availability or listings page the firm nominates. praeba fetches that page, fetches the property pages it links to, and builds the firm's properties and units from what it finds. No document is created by this and nothing is filed against a lease.
Its limits, measured: at most ten index pages, following the page's own pagination, and at most 250 property pages. praeba follows links from the nominated page only. It is not a crawl, and it looks at no other domain. praeba's page reader identifies itself to the sites it fetches.
While automatic refresh is switched on for a workspace, those pages are re-read once a week, on Sunday at 18:00 UTC, and the firm's properties and units are updated from what is found. It touches nothing else — not documents, not deals, not the diary — and reaches nothing the firm did not nominate. Switching it off stops the weekly re-read, takes effect immediately, and praeba will not switch it back on without asking. For pilot firms praeba switches it on during onboarding and tells them it has.
Account and sign-in
The name and email address of each person at a firm who uses the software, and their sign-in events, handled by praeba's identity provider. Every request to the service is authenticated, and a person the firm has marked inactive is refused.
Correspondence
If you write to praeba at the address at the foot of this page, praeba holds that message and its reply.
What praeba does not do
- It watches no folder, no inbox, no calendar and no file store. A folder-watch capability is on the roadmap; it is not built, and it is deliberately absent from praeba's paperwork until it is.
- It does not infer. A field a document does not state comes back empty. praeba does not guess a date, a rent or a party from context, and a field it is unsure of is flagged for a person rather than quietly filled.
- It does not train models on a firm's material. praeba trains no models of its own. The reader is used under its provider's API terms; the exact wording of those terms is being confirmed as part of this review, and this page will cite it once it is.
- It takes no card payments. There is no checkout and no payment surface anywhere in the product, so no payment details are collected or held.
Who else sees it
praeba uses the services below to run the product. Each one is enumerated from praeba's own source code rather than compiled from memory, and each is bound by data protection obligations equivalent to praeba's own.
| Service | What it does | Where |
|---|---|---|
| Netlify, Inc. | Hosting, serverless functions, and the temporary store that holds a document while it is being read | United States |
| Airtable, Inc. | The database that holds the firm's book | United States |
| Clerk, Inc. | Identity and sign-in | United States |
| Anthropic PBC | The reader — the AI service that reads a document and returns its facts, and that reads the pages praeba fetches from a nominated availability page | United States |
| Amazon Web Services EMEA SARL Amazon SES, S3 and SNS |
Receiving a firm's intake mail, holding the raw message in praeba's own storage, and notifying praeba that it has arrived | London (eu-west-2) |
The mail road is the exception, and deliberately so. Intake mail is received in London and praeba's copy of the message is held in praeba's own storage account in London — not in a mailbox belonging to the provider. Amazon Web Services EMEA SARL is established in Luxembourg; the receiving, the storage and the notification are all in London.
The other four are established in the United States, so personal data in a firm's documents transfers to the United States in the course of providing the service. The transfer mechanism is set out in each firm's Data Processing Agreement and is part of this review.
Nothing else is on this list, because nothing else is in the code. In particular Google, Microsoft, Stripe, Make.com and Cal.com are not sub-processors of the service. praeba connects to no mailbox or file store, and there is no payment surface in the product.
How long it is kept
The document itself is not kept
A file given to praeba is held only while it is being read, and is then deleted — whether the read succeeded or failed. There is no exception and no sweep. If a file cannot be read, or cannot even be retrieved, the row in the firm's book says so and the file still goes.
What stays is what was read: the structured facts, filed against the property, unit and lease in the firm's book, with the document's name and the date it was read beside them.
Mail is one step longer, and this is the whole of it
A message sent to a firm's intake address is stored into praeba's own storage account in London. praeba reads it, takes out the attachments, and files each one. The moment at least one attachment has been taken from the message, praeba's stored copy of the message is deleted. The attachment itself then follows the paragraph above — held while it is read, then gone.
The one case where the copy waits, stated rather than smoothed over. If praeba could take nothing at all from a message — no attachment, or every attachment refused or unreadable — the stored copy is not deleted at that moment. It is removed automatically, within 3 days of the message arriving, by an expiry rule on the storage itself. A message that gave praeba nothing is the only kind that lingers, and it lingers in praeba's own account, in London, and for no more than three days.
The book itself
A firm's book is held for as long as praeba provides the service to that firm. On the firm's written request at any time, and on termination, praeba provides the book as a structured export. If the firm additionally asks in writing for deletion, praeba deletes the firm's personal data and the copies under its control within 30 days of that request, except where the law requires it to be kept.
Stated honestly: rows deleted from praeba's database remain recoverable for a limited period in the database provider's own revision history and trash before that provider purges them on its own schedule. praeba does not control that schedule.
Keeping it separate, and what praeba can detect
Every request is authenticated, and the caller's own record resolves to exactly one firm. Reads and writes are scoped by the firm the server resolved — never by anything the caller sent. A caller with no firm is refused.
Said plainly: every firm's records sit in one database, separated by the firm they belong to and enforced on the server. That is logical separation, not a separate database for each firm. praeba says it that way because it is what praeba can prove.
What praeba can detect, honestly stated. Failures and refusals in praeba's own functions are logged, and its authorisation guards refuse and record any request that reaches for another firm's record. praeba does not run a security operations centre, intrusion detection or continuous log monitoring, and depends on the platform providers above to notify it of incidents affecting them. Where praeba processes on a firm's behalf, it notifies that firm of a personal data breach without undue delay.
Your rights
Under UK GDPR you have the right to ask for access to your personal data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable form.
Where the data is in a firm's book, that firm is the controller — the request goes to the firm, and praeba assists the firm in answering it. Where praeba is the controller — its own account records and correspondence — the request comes to praeba directly.
Either way, write to jake@praeba.co.uk and praeba will route it or answer it.
Complaints
If you are not satisfied with how praeba has handled your personal data you can complain to the Information Commissioner's Office, the UK's supervisory authority, at ico.org.uk. praeba would rather hear from you first, but that is your right and not a step you have to take through praeba.
This page itself
This page sets no cookies, stores nothing in your browser, and carries no analytics or tracking of any kind. It loads its typefaces from Google Fonts, which means your browser makes a request to Google and Google receives your IP address in the course of it. That is the only third party this page reaches.