Data Processing Agreement
Version 2.4 · Effective date: 14 July 2026 · ProSurvey Apps Limited (company no. 17118570), registered in England and Wales.
See also: Terms of Service · Privacy Policy · Acceptable Use Policy · Cookie Notice · Sub-processors
This Data Processing Agreement forms part of the agreement (the "Agreement", i.e. the Terms of Service) between ProSurvey Apps Limited (company number 17118570, England and Wales) ("Processor", "we", "us") and the customer organisation ("Controller", "you") for the HousingSurvey Pro Service. It governs our processing of Tenant Personal Data and any other personal data we process on your behalf. Where we process personal data as a controller (account, billing, website data), our Privacy Policy applies instead.
Terms defined in the Terms of Service have the same meaning here. "UK Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and any successor or related legislation, as amended.
1. Roles and scope
1.1 You are the controller and we are the processor in respect of the personal data described in Annex 1. Where you are yourself a processor for a further controller (for example, a contractor acting for a landlord), you appoint us as your sub-processor and warrant you have authority to do so.
1.2 We process personal data only for the purpose of providing the Service and only as described in this DPA and Annex 1.
2. Processing on documented instructions
2.1 We process personal data only on your documented instructions, including those in the Agreement, this DPA, your configuration and use of the Service, and any further written instructions you give — unless required to do otherwise by law (in which case we will inform you, unless legally prohibited).
2.2 We will inform you if, in our opinion, an instruction infringes UK Data Protection Law. We are not obliged to act on an instruction that would.
3. Confidentiality
We ensure that personnel authorised to process personal data are bound by appropriate confidentiality obligations and access personal data only as needed to perform the Service.
4. Security (technical and organisational measures)
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, costs, and the nature, scope, context and purposes of processing. Our measures are set out in Annex 2 and are kept under review. We do not currently hold SOC 2, ISO/IEC 27001 or Cyber Essentials certification; we operate to those frameworks and are working towards certification.
5. Sub-processors
5.1 You provide general authorisation for us to engage the sub-processors listed in Annex 3 for the processing described.
5.2 We impose data-protection obligations on each sub-processor that are, in substance, no less protective than those in this DPA, and remain responsible to you for each sub-processor's performance.
5.3 We will give you at least 30 days' prior notice of any intended addition or replacement of a sub-processor (by updating the subprocessors page and, where you have subscribed, notifying your organisation administrators), giving you a reasonable opportunity to object on reasonable data-protection grounds. If we cannot resolve a reasonable objection, you may terminate the affected Service as your sole remedy.
6. Data-subject rights
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures — including the Service's self-service export and deletion tools — to fulfil your obligation to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection). If we receive a request directly, we will not respond to it ourselves (except to direct the individual to you) and will pass it to you promptly.
7. Assistance with obligations
We assist you, taking into account the nature of processing and the information available to us, with: security of processing (Art. 32); personal-data-breach notification and communication (Arts. 33–34); data-protection impact assessments (Art. 35); and prior consultation (Art. 36).
8. Personal-data breaches
We notify you without undue delay after becoming aware of a personal-data breach affecting personal data we process for you, and provide the information you reasonably need to meet your own notification obligations.
9. Deletion or return
On termination of the Service, and at your choice, we delete or return the personal data we process for you and delete existing copies, unless UK Data Protection Law (or another law to which we are subject) requires storage. The Service provides self-service export (for return) throughout the term and for the post-termination export window, and self-service/scheduled deletion, as described in the Terms of Service (clause 10.4) and Privacy Policy (clause 7). Retention of audit and accounting records, and of tamper-evident evidence for its configured retention period, is as described there.
10. Audits and information
We make available to you the information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. We may satisfy this by providing our security documentation, security-questionnaire responses, and (once obtained) certification/attestation reports, and by reasonable, scoped, confidential audits at reasonable frequency and cost. Our default position is documentation-first (security documentation and questionnaire responses, supplemented by certification/attestation reports once obtained), with a scoped on-site or remote audit step available for cause, on reasonable notice.
11. International transfers
We process the data plane in the UK (europe-west2, London). Any transfer of personal data outside the UK arising from a sub-processor is made under an appropriate transfer mechanism — that sub-processor's UK IDTA/Addendum to the EU Standard Contractual Clauses (or equivalent), or an applicable adequacy decision, as set out per sub-processor in Annex 3 and on the subprocessors page. We will not transfer personal data outside the UK other than as described there without an appropriate safeguard.
12. Liability
Liability under this DPA is subject to the limitations and exclusions in the Agreement (Terms of Service, clause 12), except to the extent UK Data Protection Law requires otherwise.
13. Precedence and general
13.1 In the event of conflict between this DPA and the rest of the Agreement on a data-protection matter, this DPA prevails.
13.2 This DPA is governed by the law of England and Wales, consistent with the Agreement.
Annex 1 — Description of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the HousingSurvey Pro damp & mould evidence platform |
| Duration | The term of the Agreement, plus the post-termination export/retention windows described in the Terms and Privacy Policy |
| Nature and purpose | Capture, storage, hash-chaining, transmission and export of property-condition evidence and related work-management data, on the Controller's behalf |
| Types of personal data | Property addresses/UPRNs; environmental readings and observations; photographs of properties; inspection GPS coordinates; surveyor/Authorised-User identifiers; work-order and statutory-deadline data. The Service is designed to describe properties, not people; the Controller is required not to enter special-category data and to minimise personal data |
| Categories of data subjects | Residents/occupiers and other individuals connected to a property (only to the extent the Controller enters such data); the Controller's own staff and contractors (as Authorised Users) |
| Special-category data | Not to be processed; the Controller undertakes not to enter it |
| Frequency | Continuous, for the duration of the Service |
Annex 2 — Technical and organisational measures (drawn from the real security posture)
- UK data residency: Firestore, Cloud Storage, Cloud Functions and authentication pinned to Google Cloud europe-west2 (London), enforced in code.
- Access control: default-deny Firestore/Storage rules; per-organisation isolation; role-based access (owner/org-admin/manager/coordinator/finance/ viewer/surveyor); contractor access only via explicit landlord grants; server-side custom claims minted only by controlled functions; SSO/SCIM on eligible plans.
- Authentication: TOTP and phishing-resistant WebAuthn passkeys are available and required by the apps for relevant roles; platform-superadmin rules/callables verify current second-factor proof server-side. Equivalent server-side step-up is not yet universal for ordinary manager/org-admin actions. Passwords are held by Identity Platform; high-entropy API/SCIM bearer tokens are stored only as SHA-256 digests and shown once.
- Evidence integrity: server-authoritative finalization (timestamp set by a function, never a device clock); per-property SHA-256 hash chaining with a nightly integrity verifier that flags (never alters) mismatches and raises audit/notification events; append-only, hash-chained audit log per organisation; signed evidence bundles independently verifiable by a third party.
- Encryption: TLS in transit; encryption at rest (managed by the cloud platform) throughout.
- Application security: app attestation (App Check); upload restrictions (images only, size-capped) enforced by Storage rules; signed webhooks (HMAC-SHA256); rate-limited, audited API access.
- Per-tenant AI isolation: survey-content AI runs only on the Controller's own key, scoped strictly to that Controller; no shared platform AI account; refused on finalized records; fails closed when unconfigured.
- Logging and monitoring: Cloud logging on functions; append-only audit trail; nightly chain-verification run records.
- Backups/continuity: production Firestore has seven-day point-in-time recovery (PITR) plus daily backups retained for 98 days. Evidence Storage has object versioning, 14-day soft delete and a nightly mirror to a separate versioned Archive bucket in London. The same-region backup protects object/ bucket loss while preserving UK residency, but does not cover a whole-London- region outage. See the compliance mapping for current recovery-test gaps. These controls are separate from the cryptographic integrity guarantee, which does not depend on backups.
This annex reflects our current engineered security posture and is kept under review as controls land. We do not represent an in-progress control as complete, and we add no certification claim until one is actually held.
Annex 3 — Sub-processors
| Sub-processor | Role | Location / residency |
|---|---|---|
| Google Cloud / Firebase | Core hosting, database, storage, auth, functions | UK (europe-west2, London) for the data plane |
| Stripe | Payments and invoicing | UK/EU and US-headquartered; card data is out of our scope entirely (Stripe is PCI-DSS certified). Any transfer outside the UK is under Stripe's standard contractual clauses (or equivalent transfer mechanism) |
| Cloudflare | CDN, DNS, WAF, Turnstile bot protection | Global CDN network, US-headquartered; any transfer outside the UK is under Cloudflare's standard contractual clauses (or equivalent transfer mechanism) |
| Google Workspace (SMTP) | Transactional/notification email | US-headquartered (Google LLC) / Ireland (Google Ireland Ltd); any transfer outside the UK is under Google's standard contractual clauses (or equivalent transfer mechanism) |
| Ordnance Survey / Google Places | Address lookup (address strings only) | Ordnance Survey: UK. Google Places: US-headquartered; any transfer outside the UK is under Google's standard contractual clauses (or equivalent transfer mechanism) |
| EPC register (gov.uk) | Public energy-performance lookup | UK |
| Google (AI Studio) — public docs assistant only | Public website documentation assistant; no Customer/Tenant data | US-headquartered; touches only public marketing/documentation content, never personal data |
| Customer-keyed AI providers (Anthropic / Azure OpenAI / OpenAI / Google / BYO endpoint) | Advisory survey-content AI — the Controller's own account and DPA | Determined by the Controller's arrangement with its chosen provider — this is a sub-processor of the Controller's own choosing, not ours, listed here for transparency |
The full, current version of this table — kept up to date as sub-processors change — is published on the subprocessors page, which this Annex 3 mirrors.
ProSurvey Apps Limited · registered in England and Wales, company number 17118570 · HousingSurvey Pro™.
Changelog
- v2.4 (14 July 2026) — Full UK-law B2B SaaS suite drafted (W-E1), published live (W-E2/H-LEGAL-PUBLISH). Supersedes the v1.0 short-form page.