SMS authentication / security codes
Effective date: 22 September 2026
1. Purpose of this page
This page explains how SJR Data uses SMS for staff login two-factor authentication (security codes), who may receive those messages, and how opt-in and opt-out work. It is provided as a clear public statement of our transactional SMS practice for authorised portal users.
Separately, administrators may opt in to WebAuthn / passkeys (for example Touch ID or Windows Hello) as an additional way to complete two-factor authentication after password sign-in. SMS and authenticator-app codes remain available as backup. Passkeys are not required for officers.
2. Who receives SMS security codes
SMS one-time security codes are sent only to authorised staff users of the SJR Data housing analytics / arrears portal who have SMS two-factor authentication enabled on their account.
- Messages are not sent to housing residents, tenants or the general public for login or marketing.
- SJR Data does not use these security-code SMS as promotional or marketing messages.
- Only UK mobile numbers in +44 format are accepted for SMS 2FA.
3. How you opt in (account creation and profile)
Receiving SMS security codes is tied to staff account setup and login security, not to a separate marketing signup:
- When an administrator creates a staff user account, they may collect a Contact Phone number and select SMS under Two-F.A Method.
-
Staff users may also maintain their number on My Profile under
Phone number (UK
+44format) and manage Two-factor authentication, including switching to SMS where a valid phone is held. - When SMS 2FA is enabled for an account, SJR Data sends a one-time security code by SMS during login so the user can complete authentication.
4. Consent / acceptance
By being issued an SJR Data staff account with a mobile number for SMS two-factor authentication, and/or by using SMS 2FA at login, the user accepts receiving transactional security-code SMS from SJR Data for account authentication purposes only.
5. Message type and example
Messages are transactional security codes / account login only. They are short one-time passcodes used solely to verify the signed-in user.
Example body style:
SJR-Data security code: 123456
6. Opt-out
You can reply STOP to a security-code SMS. Mobile carriers and Twilio typically treat STOP as an opt-out from further messages from that sender.
The SJR Data application does not currently implement its own in-app STOP reply handler. To stop SMS security codes for your account, contact simon@sjrdata.com or ask an administrator to disable SMS two-factor authentication on your user account (for example by switching you to Authenticator 2FA or removing SMS as your method).
7. Related policies
8. Contact
Questions about SMS authentication or this notice: simon@sjrdata.com.
© 2026 Clear Arrears Limited, trading as SJR Data.
Registered in England & Wales, company no. 09455934.
Registered office: 1 Park Road, Hampton Wick, Kingston upon Thames, Surrey, KT1 4AS.