Legal
Security & data protection
Last updated: April 2026
Housing data is sensitive — tenants' addresses, vulnerabilities, financial circumstances. Here's how we look after it.
Where your data is stored
All customer data is stored in UK-based data centres operated by tier-1 providers, with data residency in the United Kingdom only.
Encryption
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Database back-ups are encrypted and stored in a separate region.
Certifications
CHICS holds Cyber Essentials certification, our hosting providers are ISO 27001 certified, and we provide a signed Data Processing Agreement (DPA) on request.
Access control
Role-based access control with least-privilege defaults, MFA on all admin accounts, and a tamper-evident audit log for every change to tenancy data.
Vulnerability disclosure
If you believe you have found a security vulnerability, please report it to support@chics.co.uk. We aim to acknowledge within one working day.
Sub-processors
A current list of sub-processors and their purpose is provided to customers and updated whenever we make a change.
This page is provided in good faith as a starting point — please have your DPO or legal counsel review it before publishing publicly.