We use cookies to keep the site working and, with your consent, to personalise advertising. See our Cookie Policy for details.
Last updated: August 2026
Entity: HomeFeed AI Limited
Address: Stylus House, London Road, Bracknell, Berkshire RG12 2UT
Data protection contact: privacy@home-feed.co.uk
This Data Processing Agreement ("DPA") forms part of the Terms of Service between HomeFeed AI Limited ("HomeFeed", "Processor") and the Business User ("Controller"). By creating a HomeFeed account and agreeing to the Terms of Service, the Business User agrees to this DPA.
In this DPA:
"Controller" means the Business User — the estate agent that has created a HomeFeed account.
"Processor" means HomeFeed AI Limited, which processes Personal Data on behalf of the Controller.
"Personal Data" means any information relating to an identified or identifiable natural person processed under this DPA.
"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
"Data Subject" means the individual to whom Personal Data relates — in HomeFeed's context, typically an End User (a lead).
"Sub-processor" means any third party engaged by HomeFeed to process Personal Data on behalf of the Controller.
"UK GDPR" means the UK General Data Protection Regulation as retained in UK law by the European Union (Withdrawal) Act 2018.
"Applicable Law" means UK GDPR, the Data Protection Act 2018, and any other applicable data protection legislation.
HomeFeed processes lead Personal Data on behalf of the Controller for the purpose of providing the HomeFeed platform and Services, including running lead generation advertising campaigns, capturing and storing leads, displaying and organising those leads for the Controller and its authorised staff, and providing platform functionality that helps the Controller use its own data for its property marketing and lead-management purposes. HomeFeed does not process Controller lead data for HomeFeed's own independent marketing or commercial purposes.
The processing activities carried out by HomeFeed on behalf of the Controller include:
Collection and storage of lead data submitted via HomeFeed-hosted landing pages and Facebook/Instagram native lead forms
Display of lead data to the Controller and their authorised staff within the HomeFeed platform
Deletion of individual lead records at the Controller's instruction, using the deletion function in the platform
Export of lead data by the Controller, using the export function in the platform
Technical support and maintenance activities involving access to the Controller's account
The Personal Data processed may include:
Name, email address, and phone number of End Users (leads)
Property preferences and search criteria
Whether the End User is a buyer, seller, or tenant
Valuation request details
Any other information submitted by an End User via a lead form
Where the Controller has configured a Meta Pixel on its landing pages, and the visitor has consented to targeting and advertising cookies: the visitor's IP address, browser and device information, and the page viewed. Section 4.10 explains how this data is treated.
The data subjects are End Users — members of the public who have responded to a property advertisement, submitted a lead form, or visited a landing page, in connection with the Controller's HomeFeed campaign.
HomeFeed will process Personal Data for the duration of the Controller's HomeFeed account. Section 4.8 sets out what happens to Personal Data on termination.
The Controller agrees to:
Comply with all Applicable Law in respect of the Personal Data it collects and shares with HomeFeed
Ensure it has a lawful basis for processing End User data and for sharing it with HomeFeed as Processor
Provide End Users with appropriate privacy information at the point of data collection, including details of HomeFeed's role as a data processor
Ensure that any instructions given to HomeFeed in respect of Personal Data comply with Applicable Law
Not instruct HomeFeed to process Personal Data in a manner that would cause HomeFeed to breach Applicable Law
HomeFeed will process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law. HomeFeed will inform the Controller if it believes an instruction infringes Applicable Law.
HomeFeed will ensure that persons authorised to process Personal Data are subject to appropriate confidentiality obligations.
HomeFeed will implement appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing, accidental loss, destruction, or damage, appropriate to the risk involved. These measures include:
Encryption of data in transit, enforced by HTTP Strict Transport Security across the whole service
Encryption of data at rest, provided by our database and storage supplier
Row-level access controls in the database and role-based permissions in the application, so that a user of one agency cannot read another agency's data
Logging of HomeFeed staff access to Business User accounts, as described in section 4.4
Periodic internal security review
Staff training on data protection
Authorised HomeFeed personnel have the technical ability to access the Controller's account where reasonably necessary to provide the Services. HomeFeed staff do not routinely access the Controller's account or Personal Data. Actual staff access is limited to circumstances where it is reasonably necessary to provide support, training, troubleshooting, or related assistance to that Controller.
Access is off by default and is granted by the Controller. Each capability below is enabled only where the Controller's account owner has expressly granted that specific permission in the account's permission settings. Where a permission has not been granted, access is refused. Subject to that grant, the capabilities are:
Reading and viewing account data, including campaign information and account settings. Access to lead records is a separate permission that is not granted by default.
Deleting listings within the account
Granting or removing user roles, including the owner role, and removing staff members from the account
Reading the account's connected Facebook and Instagram page permissions
Publishing to the account's connected Facebook and Instagram pages, and actions affecting the account's advertising
Where the Controller has granted the permission to publish or to act on advertising, HomeFeed staff will not post to connected Facebook or Instagram pages, or take action against the Controller's ad budget, without the Controller's explicit prior consent. This is an organisational commitment.
HomeFeed maintains a log of staff access to Business User accounts, which the Controller may read from within the platform. The log records access mediated by the platform's support-access checks from 10 June 2026 onwards. It is a record of that access rather than a complete record of every read, and the platform reports this limitation alongside the log itself.
HomeFeed staff will not access or use Controller Personal Data for HomeFeed's own independent marketing or commercial purposes.
The Controller provides general authorisation for HomeFeed to engage sub-processors to assist in delivering the Services. HomeFeed's current sub-processors are:
Supabase — database, authentication and file storage. Receives all data held by the platform. Data is held at rest in the United Kingdom (AWS eu-west-2, London); the supplier is US-incorporated, so its support access is covered by its own data processing terms.
Vercel — application hosting, serverless functions and content delivery. Receives all data in transit through the application. Application functions run in London; platform logging and operational dashboards are in the United States.
Stripe — subscription billing and payment processing. Receives the Controller's billing details and subscription state. It receives no lead data. Stripe is an independent controller in respect of payment data.
Resend — transactional and lead-notification email delivery (US). Receives lead name, email, phone, enquiry text and property address.
OpenAI — advertising copy, listing prose and features, extraction of property details from a listing page retrieved at the Controller's instruction, and buyer research (US). Receives property and listing content. It does not receive lead contact details.
Tavily — retrieval of a property listing page from a URL supplied by the Controller, and area market-data search (US). Receives the listing URL, its page content, and search queries containing an area or postcode.
Meta Platforms Ireland Limited — campaign publishing to Facebook and Instagram, retrieval of leads from native lead forms, and the landing-page pixel. See section 4.10 and section 7.
brand.dev — looks up an agency's branding from its domain during onboarding (US). Receives the agency domain. It receives no lead data.
Ideal Postcodes (postcodes.io) — converts a property or branch postcode to coordinates for map display and advertising targeting. Receives a postcode only. The request is made by our servers, so no End User IP address is disclosed.
HomeFeed will notify the Controller of any intended changes to sub-processors by written notice to the Controller's account email address, and will provide the current list on request to privacy@home-feed.co.uk. Controllers may object to new sub-processors within 14 days of notification. HomeFeed will ensure sub-processors are bound by data protection obligations equivalent to those in this DPA.
HomeFeed will assist the Controller in responding to requests from Data Subjects exercising their rights under Applicable Law, including requests to access, rectify, erase, or restrict processing of their Personal Data. Where a Data Subject submits a deletion request directly to HomeFeed, HomeFeed will process that request and notify the Controller.
HomeFeed will provide reasonable assistance to the Controller in carrying out data protection impact assessments and prior consultations with supervisory authorities where required by Applicable Law.
The Controller may delete individual lead records at any time from within the platform, and may export a complete copy of its account at any time using the platform's export function — the account record, its branches, properties, listings, social posts, campaigns and leads. Staff accounts and outstanding invitations are included as non-identifying references only, and media files are referenced rather than embedded. The export is self-service and does not require a request to HomeFeed, and it is the return limb of the return-or-delete undertaking in this section.
On the Controller's written request to privacy@home-feed.co.uk, HomeFeed will delete the Personal Data processed under this DPA. HomeFeed will confirm deletion in writing on request.
Termination of the Controller's subscription ends the Controller's access to the Services. It does not by itself delete the Personal Data. The Controller should export any data it wishes to retain, and make a deletion request, before or at termination.
The following records are retained after deletion, as a compliance record, and are not covered by the above:
These records identify the account and the member of staff or visitor concerned, and the action taken. They do not contain End User contact details.
HomeFeed will provide the Controller with all information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits and inspections by the Controller or their appointed auditor, subject to reasonable notice and conditions of confidentiality.
Where the Controller has configured a Meta Pixel identifier on its HomeFeed-hosted landing pages, and a visitor to one of those pages consents to targeting and advertising cookies, the page loads Meta's tracking script and reports the page view to Meta Platforms Ireland Limited. Meta receives the visitor's IP address, browser and device information, and the page viewed, and sets the _fbp and fr cookies. Where the visitor does not consent, the script is not loaded, nothing is sent, and neither cookie is set.
For that collection and transmission, HomeFeed and Meta act as joint data controllers rather than as processor and sub-processor. Meta's own subsequent use of the data is governed by its own terms, and it may transfer the data to the United States. This is described for End Users in the Cookie Policy and the Privacy Policy.
Configuring a pixel is the Controller's decision. The Controller is responsible for ensuring it has a lawful basis for the resulting processing of its landing-page visitors' data.
Some of HomeFeed's sub-processors process Personal Data outside the UK or European Economic Area:
HomeFeed will ensure that any such transfer is carried out in accordance with Applicable Law, including by relying on UK International Data Transfer Agreements (IDTAs), Standard Contractual Clauses (SCCs), adequacy regulations, or other appropriate safeguards.
Transfers of data between HomeFeed and Meta's platforms are additionally governed by Meta's Platform Terms (Sections 10A, 10B, and 10C).
In the event of a Personal Data breach affecting Personal Data processed under this DPA, HomeFeed will notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach, where feasible. HomeFeed will provide the Controller with sufficient information to enable the Controller to meet any obligations to notify the relevant supervisory authority and affected Data Subjects. Where the breach involves Meta Platform Data, HomeFeed will also notify Meta in accordance with Meta's Platform Terms.
Where Personal Data processed under this DPA includes data that originated from Facebook or Instagram native lead forms ("Meta Platform Data"), such data is subject to additional obligations under Meta's Platform Terms. HomeFeed processes Meta Platform Data as a Tech Provider solely on behalf of and at the direction of the Controller. HomeFeed will not use Meta Platform Data for its own purposes and will delete it in accordance with Meta's Platform Terms. The Controller acknowledges that their use of Meta's platforms through HomeFeed is subject to Meta's Platform Terms.
This section concerns data HomeFeed retrieves from Meta. Section 4.10 concerns landing-page visitor data HomeFeed sends to Meta, which is a separate arrangement with a different controllership.
This DPA shall be governed by and construed in accordance with the laws of England and Wales. The courts of England and Wales shall have exclusive jurisdiction.
For any queries relating to this DPA, please contact:
HomeFeed AI Limited
Stylus House, London Road, Bracknell, Berkshire RG12 2UT
Privacy and data protection: privacy@home-feed.co.uk
By creating a HomeFeed account and agreeing to the Terms of Service, the Business User confirms they have read and agree to this Data Processing Agreement.