Thistle Compliance Short-term let licensing, handled.
0141 241 6195 9am to 4pm, Monday to Friday

Privacy notice

Last updated: 2026-10-05

Ashtad Limited, company number SC571322, registered office 7 Shotts Street, Glasgow G33 4JB, is the data controller for everything described here. Thistle Compliance is a trading name of that company.

If you want to ask about anything on this page, or exercise any of the rights below, email hello@thistlecompliance.co.uk or call 0141 241 6195.

The short version

We hold personal data about four groups of people: visitors to this site, people who contact us, short-term let licence holders we may write to, and the firms we work with.

We market by post only. We do not cold-email and we do not cold-call. If you tell us to stop writing to you, we stop — permanently, with no questions asked.

If you visit this website

The site is hosted by Cloudflare. Like any web host, they process your IP address and request details in order to serve the page and to protect the site from attack. We do not add any analytics, and we do not track you.

We set no cookies of our own. Cloudflare may set a strictly necessary cookie for security and load balancing, which is exempt from the consent requirement. If we ever add analytics, this section and the consent position both have to change first. The current plan is to add none.

Lawful basis: legitimate interests — serving a working, secure website.

If you contact us

Our enquiry form asks for your name and telephone number, and optionally your email address, your council, how many properties you have, your licence expiry date and your message. Only the name and number are required — we telephone you, and the email address is there so we can confirm in writing and so a missed call does not become a missed deadline. The opt-out form asks only for your name and address, because that is all we need to suppress you.

Form submissions are delivered to us by email through Resend, a US-based email provider. We keep enquiries that do not become customers for 12 months, then delete them.

Lawful basis: legitimate interests — answering someone who has asked us a question.

If we write to you about your licence

This is the part that applies to people who have never heard of us. We did not get your details from you.

Where they came from

The public register of short-term let licences that your council must publish under the Civic Government (Scotland) Act 1982 licensing scheme. Those registers contain the licence holder's name, the premises address, the postcode, the licence number and type, its status, and in many councils the expiry date.

For licences held by a company, we may also check Companies House — a public register — to find a business address to write to, rather than writing to a property that is let out to guests.

We do not obtain your email address or your telephone number. The registers do not publish them and we do not go looking.

What we work out from it

We group register entries by holder name to see how many properties the same person or company holds. This matters because our service is aimed at people running several lets rather than someone letting a spare room, and because it tells us whether writing to you is likely to be useful or a nuisance.

That grouping is information no council published — we derived it. A person checks any uncertain match rather than leaving it to software. We think you should know we do it, which is why it is written here.

What we use it for

To write to you, once, by post, telling you when your licence expires and offering to handle the renewal.

Our lawful basis

Legitimate interests, UK GDPR Article 6(1)(f). Our interest is commercial: marketing a compliance service. Your interest is in not missing a statutory deadline that carries a fine of up to £2,500 and the loss of your existing-host status.

The register being public is not, by itself, a lawful basis. We have carried out and documented a Legitimate Interests Assessment covering the purpose, whether the processing is necessary, and the balance between our interests and yours. It is reviewed at least annually. You can ask us for a summary of it and we will send you one.

Because we obtained your data from somewhere other than you, Article 14 of the UK GDPR applies. This notice is how we meet it, together with the privacy information included in the first letter we send you.

If you are a letting agent, property manager or trade contractor

We hold business contact details — name, firm, role, telephone, email — obtained from your own public business listings or given to us directly, so that we can discuss working together.

Lawful basis: legitimate interests — approaching a business about a business matter. Tell us to stop and we will.

If you become a customer

We hold what we need to do the work: your contact details, the properties concerned, licence details, certificates, and the correspondence between us.

Lawful basis: performance of a contract, and legal obligation for the accounting records.

Your absolute right to object

If you object to receiving direct marketing from us, that right is absolute. There is no balancing test, no exceptions, and we do not get to weigh our interests against yours.

Tell us and we will suppress your details immediately and permanently. Here is how — or just call 0141 241 6195 and say so.

We keep a suppression list and screen every mailing against it before it goes out. Suppression means we keep the minimum needed to make sure we never write to you again — your name and address and nothing else. We keep that indefinitely, because deleting it would mean writing to you again by mistake.

Your other rights

You have the right to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, and to object. You can exercise any of them by emailing hello@thistlecompliance.co.uk or calling 0141 241 6195. We will respond within one month.

You can also complain to the Information Commissioner's Office at ico.org.uk or 0303 123 1113. You do not have to come to us first, though we would rather you did so we can put it right.

How long we keep things

Register data about people we have not written to Reviewed annually; deleted when no longer needed for a planned mailing
If we wrote to you and you did not respond Deleted within 24 months of the last letter
Enquiries that do not become customers 12 months
Customer records 6 years after the end of the relationship, for accounting and professional indemnity
Suppression records Indefinitely, so we never contact you again

These are deletion schedules we operate and review, not automatic processes running in the background. If you want your details removed sooner, ask.

Who else sees your data

We do not sell data. We do not share it for anyone else's marketing. There is no other category of recipient.

Data going outside the UK

Resend is based in the United States, so a form submission you send us leaves the UK. Cloudflare operates a global network and may route or cache requests outside the UK.

Both are used under contracts containing the International Data Transfer Addendum to the European Commission's standard contractual clauses, which is the safeguard UK law provides for transfers of this kind.

Changes to this notice

If we change how we use personal data, we change this page first and update the date at the top. If the change is significant and we hold your contact details, we will tell you directly rather than relying on you noticing.