Privacy Policy
Version v2026-08 · effective on publication
This policy supersedes all prior versions. The Your data page records the version each user has acknowledged.
Plain-English summary
- Free landlord tools. All Llord tools for landlords are free, forever (STORY-141).
- What we collect. Property addresses, rent details, lease terms, maintenance descriptions, photos, contact details — and, when you switch on overnight triage, tenant maintenance emails — only what each tool needs.
- Where it lives. AWS Sydney — both where your information is stored and where the AI reads it. Resend US (email delivery). Vercel (hosting). Google Places / OpenStreetMap (address autocomplete). Google Analytics US (site usage — never on this page or our Terms page).
- Consents. (1) Use my data for my tools — required. (2) AI processing — required for AI features. (3) Anonymised market-data inclusion — opt-in, default off. (4) Overnight maintenance triage — per property, opt-in, default off.
- Your rights. Access, correct, or delete your data via the dashboard. We action requests within the statutory timeframe.
- Disclaimer. Llord provides tools and information, not legal or financial advice.
1. Who We Are (APP 1 — open and transparent management)
Llord is operated by Cohdit (ABN 35 532 639 253), based in Queensland, Australia. This policy explains how we manage personal information consistent with the Australian Privacy Principles (APPs) under the Privacy Act 1988.
Cohdit may currently fall under the annual-turnover threshold at which the small-business exemption in the Privacy Act 1988 can apply. We do not rely on that exemption. We handle personal information in accordance with the Australian Privacy Principles whether or not the exemption is available to us, and we will keep doing so.
Privacy enquiries: [email protected].
2. Anonymity and Pseudonymity (APP 2)
Where practicable, you may use Llord without identifying yourself. Rent Check, Yield Check, and the STR cap-status preview can be used without an account. Generating a statutory rent-increase notice, sending lease comms, or running maintenance autopilot requires an email address so we can verify ownership and deliver the artefact.
3. Collection of Personal Information (APP 3, APP 5)
We collect only what each tool needs to do its job:
- Contact details: landlord email + name, tenant email + name (when you supply them).
- Property information: address, suburb, postcode, state, bedrooms / bathrooms / parking, property type, land + floor area.
- Rental information: current rent, proposed rent, last increase date, rent-review history, lease term type.
- Maintenance information: issue descriptions, photos uploaded by tenants, vendor quote details.
- Inbound tenant maintenance email: when a landlord turns on overnight triage for a property, tenants can email that property's unique llord.ai maintenance address. We store the sender address, subject, and message content — encrypted (see §8) — for up to 12 months, only when the sender matches a tenant on an active lease for that property.
- Tenant-facing pages: tenants give us information directly on four pages, each reached by a private link we email or text them — the maintenance request form (name, phone, optional email, what is wrong and when they are home, including anything typed into the AI triage chat), the scheduling page (the times they choose and any access note), the sign-off page (whether the job was done properly, and any note), and the tenant lease portal (whether they accept, counter or decline a renewal, any rent they propose or changes they ask for, their notes, and the name they type as their signature).
- Signatures and OTPs: typed name on notices, one-time codes for delivery verification.
- Usage data: wizard step completion events, page views, error reports — for funnel analytics.
- Consent records: what you toggled, when, from which IP and user agent.
We do not knowingly collect personal information from anyone under 18. We do not collect sensitive information (race, religion, health, etc.) except where you choose to include it in a free-text field — in which case it's stored under the same controls as everything else.
4. How We Use Your Information (APP 6)
Primary uses:
- Generate statutory rent-increase notices and renewal offers based on details you supply, and send them when you click Send. We do not send automated follow-ups or reminders about these documents.
- Estimate market rent using publicly available bond data (RTA, NSW Fair Trading) plus AI fallback when no live data exists.
- Triage maintenance requests, match local vendors, and facilitate scheduling.
- Release tenant details to a tradesperson. A tradesperson sees the fault description and the times the tenant is home; they get the tenant's name, contact details and the property address only after the landlord approves the job and the tradesperson takes it on.
- Deliver tools to you and the email recipients you designate.
- Improve the service through aggregate analytics that contain no personal information.
What we are paid for an introduction. Llord is free for landlords. When a tradesperson accepts a job we introduced, that tradesperson pays Llord a flat $65 (including GST). You are never charged it. It does mean we have a financial interest in the introduction, so we tell you every time you are choosing a tradesperson.
Secondary use — anonymised market data. We do not sell a market-data product today, and there is no customer for one. The third consent toggle on the Your data page exists so that, if we ever build one, we already have your position on it. Default is off; we never opt you in, and we will tell you before any such product starts using your records. If — and only if — you turn it on, your records may be passed through our de-identification pipeline: it strips landlord and tenant names, exact street address, and any other direct identifier, hashes retained quasi-identifiers with a server-side pepper, and refuses to emit any cohort smaller than 5 records (k≥5). Withdrawing the consent stops new aggregates including your data from the moment you save the change.
5. Direct Marketing (APP 7)
Transactional emails (notices, scheduling, OTPs, billing receipts) are exempt from marketing rules under the Spam Act 2003 but contain no marketing content. Every marketing email we send carries a one-click unsubscribe link, and one click stops all marketing to that address immediately — we do not wait, and you never need to ask twice. We do not sell your email or share it with third parties for marketing.
6. Cross-Border Disclosure (APP 8)
The AI runs in Australia. When you use AI features (rent reports, lease drafts, maintenance triage, vendor proposals), the relevant text — and, for properties where the landlord has turned on AI Triage with photo consent, tenant-submitted maintenance photos — is read by Anthropic's Claude model running on Amazon Web Services in Sydney (the ap-southeast-2 region), the same place your information is stored. This also covers vendors who set up their AI quoting assistant by uploading price lists, rate cards, documents, or website content — that material is read in Sydney for text extraction and config synthesis, and we retain only the extracted pricing and service patterns, not the original files. Anthropic does not use API inputs to train its models. Until 3 September 2026 this step ran on Anthropic's servers in the United States; it no longer does.
Some other processing does still happen outside Australia. Email delivery uses Resend (US). Application hosting is on Vercel (global edge network). Vercel Blob stores uploaded photos at the nearest region. When you type into a property-address field, the partial address text is sent to our address-autocomplete provider — Google Places (US) — to suggest matches; if that service is unavailable we fall back to OpenStreetMap / Nominatim (operated by the OpenStreetMap Foundation, hosted in the EU/US). Only the address text is sent for lookup — never your name, email, or other identifiers. Card payments from tradespeople paying a lead fee are processed by Stripe (US); Llord never receives or stores card numbers.
Google Analytics 4 (United States) — the pages you visit on llord.ai, plus the general location and device your browser reports. Not used on this page or on our Terms page.
AI processing is gated behind the second consent toggle. Until you grant it, AI tools refuse to run and the dashboard surfaces a soft block pointing back to the Your data page. We take reasonable steps to ensure each provider treats the data consistently with the APPs.
Inbound tenant maintenance emails are AI-processed only for properties where the landlord has switched on overnight maintenance triage and recorded the per-property consent (which names where the AI runs and includes the landlord's warranty that routed content is lawfully obtained). For properties without that consent, inbound messages are stored — encrypted, under §8 — but are never sent to the AI provider.
6a. AI processing detail
Every prompt we send to Anthropic Claude routes through a single internal gateway. Before a prompt leaves our servers:
- PII minimisation. Rent-report prompts carry suburb-level location and rent figures — never your name. Renewal-email prompts carry the names needed to address and sign the email, but never your tenants' email addresses or phone numbers — those are stripped and replaced with placeholders before dispatch, then mail-merged back in by our own code after Claude responds.
- Audit, not retention. We record a one-way hash of each (minimised) prompt plus the time and a non-identifying token — never the prompt text itself. You can see a 7-day summary of AI calls made on your behalf at Your data under “AI services.”
- Retention at Anthropic. We intend to put a zero-data-retention arrangement in place with Anthropic; no such arrangement exists yet. Until it does, prompts sent to Anthropic are handled under Anthropic's standard API data-retention policy — see Anthropic's Privacy Policy. Anthropic does not use API inputs to train its models.
7. Quality and Correction (APP 10, APP 13)
You can correct any field you supplied via the relevant wizard, or by submitting a correction request from the Your data dashboard. Corrections are actioned within the statutory timeframe; you'll receive an email when complete.
If you are a tenant, that dashboard is not yours — it belongs to the landlord who holds the account. Email [email protected] to ask us for a copy or a correction of your information, or to make a privacy complaint. That is the same address as the collection notice on the pages we send you.
8. Security (APP 11)
We protect your information by:
- HTTPS for all traffic; HSTS preload.
- AWS DynamoDB encryption at rest (AWS-managed keys).
- Field-level KMS envelope encryption for the four most-sensitive personal fields: your email, your address, your tenants' names, and your tenants' emails. Each row uses its own data-encryption key, sealed under an AWS KMS customer-managed key in
ap-southeast-2(Sydney). The key policy restricts decrypt operations to the Llord application role only. - Every decrypt is audited. Every time we read one of those four fields — to send you an email, generate a PDF, run an Autopilot cron, or render a dashboard — we log the access (when, what fields, what surface) to a separate audit table. You can see the last 30 days at /account/data under “Where we accessed your data.”
- Analytics never see the protected fields. Aggregate counts (e.g. “rent increases in the last 24 hours”) are computed against a separate analytics plane that stores only opaque HMAC tokens — no email, address, or tenant info. The tokens are minted under a different secret from the operations plane, so the two planes cannot be cross-joined.
- Session cookies are httpOnly and SameSite=Lax; OTPs are short-lived and single-use.
- Rate limits on every public endpoint to deter scraping and abuse.
- No PII in application logs or error trackers; only session IDs and event types.
- Stripe handles all card details — Llord never sees them.
No system is bulletproof. If we discover a data breach affecting your information we will notify you and the OAIC consistent with the Notifiable Data Breaches scheme.
9. Data Retention
Wizard sessions have no automatic deletion date — we keep them until you ask us to delete them under §10. Maintenance requests are retained for 12 months after completion. Inbound tenant maintenance emails are retained for 12 months from receipt, then automatically deleted. Consent records, audit rows, and `legal_actions` rows are retained for at least 7 years for legal-record purposes. Anonymised aggregates (post-de-identification) are retained indefinitely as they are no longer personal information.
10. Your Rights (APP 11, APP 12, APP 13)
You have the right to:
- Access the personal information we hold about you (APP 12).
- Correct inaccurate personal information (APP 13).
- Withdraw consent at any time via the Your data dashboard.
- Request deletion of your personal information (APP 11). We will action deletion within 30 days unless we are required by law to retain a specific record (e.g. a sent statutory notice).
The dashboard is the fastest path. Email [email protected] if you'd prefer to use email.
11. Cookies and Analytics
Llord uses a httpOnly session cookie to maintain wizard state across pages. We use Google Analytics 4 to understand how people move through the site; it is operated by Google in the United States and sets its own cookies — see section 6. We do not sell your information to advertisers. Analytics do not run on this page or on our Terms page.
12. Complaints
If you believe we have breached the Australian Privacy Principles, please contact us first at [email protected]. We will acknowledge within 7 days and respond substantively within 30. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
13. Changes to This Policy
We publish material changes here as a new version with its own effective date; the version in force is shown at the top of this page. The Your data page records the policy version that was in force when you last saved your consent settings. Continued use of Llord after the effective date constitutes acceptance of the updated policy.
14. Contact
For privacy-related questions, corrections, or deletion requests:
Cohdit (ABN 35 532 639 253), Queensland, Australia
[email protected]
Appendix A — APP cross-reference
- APP 1 (open and transparent management) → §1, §13
- APP 2 (anonymity and pseudonymity) → §2
- APP 3, 5 (collection + notification) → §3, §6
- APP 6 (use and disclosure) → §4
- APP 7 (direct marketing) → §5
- APP 8 (cross-border disclosure) → §6
- APP 10, 13 (quality + correction) → §7, §10
- APP 11 (security + retention + deletion) → §8, §9, §10
- APP 12 (access) → §10
This is not legal or financial advice. Verify with a qualified professional.