Privacy policy

RapidProof — A Trading Name of Orchestrating Identity Limited 

Version 1.0  |  Last updated: 8th July 2026 

 

1. Introduction and Who We Are 

RapidProof is a trading name of Orchestrating Identity Limited, a company incorporated in England and Wales (Company Registration Number: 14263692) with its registered office at  Kings Parade, Lower Coombe Street, Croydon, CR0 1AA (“we”, “us”, “our”, or “RapidProof”). 

We provide a Right to Rent identity verification service used by landlords and letting agents (“Customers”) to verify the right of a prospective or current tenant (“Subjects”) to rent residential property in England, in accordance with the Immigration Act 2014 (as amended). This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when Customers and Subjects use our identity verification services, visit our website, or otherwise interact with us. 

Orchestrating Identity Limited is registered as a data processor with the Information Commissioner’s Office (ICO) under registration reference ZB475194. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Data (Use and Access) Act 2025, and all other applicable data protection legislation. 

2. Personal Data We Collect 

We may collect and process the following categories of personal data, depending on whether you interact with us as a Customer or as a Subject: 

2.1 Contact and Account Data 

  • Customer details: name, email address, telephone number (optional), and postal address, collected via our payment provider (Shopify/Stripe) at the point of purchase 

  • Subject details: name, date of birth, nationality, and email address, provided by the Customer in order to invite the Subject to complete a Verification 

  • Account preferences and communication preferences held with Shopify 

2.2 Identity Verification Data 

  • Identity document data submitted by the Subject for the purposes of completing a Right to Rent check (UK and Irish passport holders only) 

  • Verification status, outcome, and share passcode associated with each Verification 

2.3 Technical and Usage Data 

  • IP address, browser type and version, operating system 

  • Device identifiers and mobile device information 

  • Pages visited, time spent on pages, links clicked 

  • Log-in and access timestamps 

  • Cookies and similar tracking technologies (see our Cookie Policy) 

2.4 Financial Data 

  • Payment card information (processed via our secure payment provider, Shopify/Stripe) 

  • Transaction history relevant to Verifications purchased 

3. How We Collect Your Personal Data 

We collect personal data through the following means: 

  • Directly from the Customer when they register for or use the RapidProof Shopify site, or contact our sales team via rapidproof.co.uk or oidentity.com, to purchase Right to Rent Verifications 

  • Directly from the Subject when they complete the Verification process via the link sent to them, including confirming their willingness to proceed and submitting identity documents 

  • Automatically through use of our website or platform via cookies and tracking technologies 

4. Legal Basis for Processing 

We collect and use your personal data on the following legal bases under UK GDPR: 

  • Legal obligation: As a registered Identity Service Provider (IDSP), we are required to create and retain a record of each Right to Rent Verification, including the Subject’s name, date of birth, nationality, and email address. 

  • Contract performance: Processing is necessary to fulfil the Customer’s purchase of Verification services, including processing orders, inviting Subjects to complete Verifications, and managing accounts. 

  • Legitimate interests: For improving our services, fraud prevention, and ensuring platform security, where these interests are not overridden by your rights. 

  • Consent: Where you have given explicit consent, such as for marketing communications or non-essential cookies. 

  •  

4.a Sub Processors 

OID may engage selected third-party service providers ("Sub Processors) to process personal data on our behalf in order to provide, support and maintain our services. These Sub Processors are required to process personal data only in accordance with our instructions and implement appropriate technical and organisational measures to protect your data. All sub processors are required to comply with applicable data protection legislation. Where personal data is transferred internationally, appropriate safeguards will be implemented. 

If you have any questions please reach out to dpo@oidentity.com where we will review each request on a case-by-case basis. 

 

5. How We Use Personal Data 

5.1 Providing Right to Rent Verification Services 

  • Sending Subjects an invitation and confirmation email to complete a Verification, including relevant terms and conditions 

  • Verifying the identity of the Subject and confirming their Right to Rent in accordance with Home Office requirements 

  • Issuing the Subject with a Verification confirmation pack and share passcode on successful completion 

  • Notifying the Customer once a Verification has been completed and approved 

  • Maintaining the statutory record of the Verification as required of a registered IDSP 

5.2 Business Improvement 

  • Improving and developing our identity verification technology and algorithms 

  • Conducting anonymised statistical analysis and research 

  • Testing and quality assurance of our services 

 

6. Sharing Your Personal Data 

We may share your personal data with the following categories of recipients: 

  • Payment processors and financial institutions, including Shopify and Stripe 

  • Orchestrating Identity Limited for the purposes of processing data for identity verification purposes. 

  • The Customer who purchased the Verification, in the form of Verification status notifications and, where the Subject chooses to share it, the share passcode enabling access to the Verification result 

  • IT service providers, cloud hosting providers, and platform operators 

  • Professional advisors including lawyers, auditors, and accountants 

  • The Home Office and other regulatory bodies, law enforcement agencies, and courts, where we are legally required to do so or where this is necessary to confirm a Right to Rent outcome 

  • A purchaser or successor entity in the event of a merger, acquisition, or sale of business assets 

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions. 

7. International Data Transfers 

We do not transfer, store, or process your personal data outside of the United Kingdom. 

All personal data collected through this website is processed and stored within the same jurisdiction and is not transferred to, accessed from, or processed in any country outside of the United Kingdom. 

If our practices change in the future regarding international data transfers, we will update this Privacy Policy accordingly and ensure appropriate transfer mechanisms are implemented in compliance with UK data protection legislation. 

8. Data Retention 

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, regulatory, accounting, or reporting requirements. Our retention periods are as follows: 

  • Right to Rent Verification records (Subject name, date of birth, nationality, and email address): 30 days following completion of the Verification, as required of a registered Identity Service Provider, after which they are deleted 

  • Identity documents submitted by the Subject: not retained beyond the period required for lawful completion and recording of the check 

  • Financial transaction records: 7 years (as required by HMRC regulations) 

  • Website usage data and cookies: up to 12 months 

  • Marketing consent records: until consent is withdrawn, plus 1 year 

Please note that it is the Customer’s own responsibility, and not RapidProof’s, to retain a record of the Verification result for at least one year after the end of the Subject’s tenancy, or such longer period as may be required by applicable law or Home Office guidance, in order to demonstrate a statutory excuse. 

Where we are required to retain data for longer periods by applicable law or regulation (for example, in connection with legal proceedings or regulatory investigations), we will retain it for only the period required. At the end of the applicable retention period, we will securely delete or anonymise your personal data. 

9. Your Rights Under UK GDPR 

Subject to applicable law and certain conditions and exceptions, you have the following rights in relation to your personal data: 

  • Right of Access (Article 15): To request a copy of the personal data we hold about you (subject access request). 

  • Right to Rectification (Article 16): To request that we correct inaccurate or incomplete personal data. 

  • Right to Erasure (Article 17): To request that we delete your personal data in certain circumstances (the ‘right to be forgotten’). 

  • Right to Restrict Processing (Article 18): To request that we restrict how we use your personal data in certain circumstances. 

  • Right to Data Portability (Article 20): To receive your personal data in a structured, commonly used, machine-readable format. 

  • Right to Object (Article 21): To object to our processing of your personal data based on legitimate interests or for direct marketing purposes. 

  • Right to Withdraw Consent (Article 7(3)): To withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing. 

  • Rights Related to Automated Decision-Making (Article 22): Not to be subject to solely automated decisions that have significant effects on you. 

Please note that some of these rights are not absolute and may be subject to limitations. In particular, our ability to delete Right to Rent Verification records before the end of the applicable retention period may be restricted by legal and regulatory obligations as a registered IDSP. 

To exercise any of your rights, please contact our DPO using the details in Section 14, or via the contact details published on rapidproof.co.uk. We will respond within one month of receiving your request, or within three months where the request is complex or numerous, in which case we will notify you of any extension within the first month. We will not charge a fee for exercising your rights unless requests are manifestly unfounded or excessive. 

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO): 

Information Commissioner’s Office 

Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF 

Helpline: 0303 123 1113  |  Website: www.ico.org.uk 

10. Data Security 

We have implemented appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include but are not limited to: 

  • Orchestrating Identity Limited is ISO 27001 certified 

  • Orchestrating Identity Limited is a certified Identity Service Provider under the UK digital identity and attributes trust framework (DIATF), certificate number DIATF-KIUK-25-42 

  • End-to-end encryption of data in transit using TLS 1.2 or higher 

  • Encryption of data at rest using AES-256 or equivalent standards 

  • Multi-factor authentication for system access 

  • Role-based access controls and the principle of least privilege 

  • Regular penetration testing and security audits 

  • ISO 27001-aligned information security management practices 

  • Staff training and awareness programmes 

  • Incident response and data breach notification procedures 

  • Data Protection Impact Assessments (DPIA) 

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and will report the breach to the ICO within 72 hours of becoming aware of it, as required by UK GDPR Article 33. 

11. Cookies and Similar Technologies 

We use cookies and similar tracking technologies on our website and platform. Cookies are small text files placed on your device to help us provide a better user experience and to understand how our services are used. 

We use the following types of cookies: 

  • Strictly Necessary Cookies: Essential for the operation of our services. These cannot be disabled. 

  • Performance and Analytics Cookies: Help us understand how users interact with our platform (e.g., Google Analytics). These are set only with your consent. 

  • Functional Cookies: Remember your preferences and customise your experience. 

  • Targeting/Marketing Cookies: Used to deliver relevant advertisements. These are only set with your explicit consent. 

You can manage your cookie preferences through our Cookie Consent Manager available on our website. Please refer to our separate Cookie Policy for full details. 

 

12. Children’s Privacy 

Use of our Service as a Subject is restricted to individuals who are at least 18 years of age. Our services are not directed at children under the age of 18 and we do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child, we will take immediate steps to delete such data from our records. 

If you believe that we may have collected personal data from or about a child, please contact our DPO immediately. 

13. Third-Party Links and Services 

Our website and platform may contain links to third-party websites or integrate with third-party services, including Shopify. This Privacy Policy applies only to our own services. We are not responsible for the privacy practices of third parties and encourage you to read the privacy policies of any third-party websites or services you access, including Shopify’s Privacy Policy. 

14. Changes to This Privacy Policy 

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by: 

  • Posting the updated policy on our website with a new effective date 

  • Sending you an email notification (where we hold your email address) 

  • Displaying a prominent notice on our platform 

We encourage you to review this Privacy Policy periodically. Your continued use of our services after the effective date of an updated Privacy Policy constitutes your acceptance of the changes, to the extent permitted by law. Where changes require your consent, we will seek your agreement before the changes take effect. 

 

15. Contact Us and Complaints 

If you have any questions, concerns, or complaints about this Privacy Policy or our data processing practices, please contact us: 

Data Protection Officer 

RapidProof, a trading name of Orchestrating Identity Limited 

150 Borough High St, London SE1 1LB 

Email: dpo@rapidproof.co.uk 

In accordance with the Data (Use and Access) Act 2025, we will formally acknowledge your complaint within 30 days of receipt and work to resolve the matter promptly. You also retain the right to escalate your complaint to the Information Commissioner’s Office (ICO) or with a supervisory authority, in particular in the European Union (or European Economic Area) state where you work, normally live or where any alleged infringement of data protection laws occurred if you remain dissatisfied. 

This Privacy Policy was prepared by Orchestrating Identity Limited and applies to all services offered under the RapidProof trading name.