Privacy Policy
Version 2.4 · Effective date: 14 July 2026 · ProSurvey Apps Limited (company no. 17118570), registered in England and Wales.
See also: Terms of Service · Data Processing Agreement · Acceptable Use Policy · Cookie Notice · Sub-processors
1. Who we are
HousingSurvey Pro™ is operated by ProSurvey Apps Limited ("we", "us", "our"), a company registered in England and Wales, company number 17118570.
For any privacy question, or to exercise your rights, use our contact form or email our support address (published on our website). Our company registration record, including our registered office, is publicly searchable on the UK Companies House register under company number 17118570. We respond within one calendar month.
We have not designated a separate named Data Protection Officer: UK GDPR does not require one for a business of our size and processing profile. Privacy enquiries and data-subject requests should be directed to the contact channels above, which we treat as our data-protection contact point.
2. Our two roles — controller and processor
We act in two distinct capacities, and it matters which one applies to a given piece of data:
- Processor — for Tenant/property evidence data captured by our customers (housing associations, councils, and their contractors) and their Authorised Users. Here the customer organisation is the data controller and we are its processor, acting on its documented instructions under our Data Processing Agreement. If you are a resident, occupier or other individual whose data appears in a survey, the housing organisation is your controller — please direct requests to them first (see clause 9).
- Controller — for account, billing, support and website data — the data we need to run our business, provide the Service to our customers, and operate our website.
3. What we process, why, and our lawful basis
3.1 As controller (account, billing, website)
| Data | Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Account data — name, work email, organisation, role | Authentication, access control, providing the Service, support | Contract (Art. 6(1)(b)) |
| Authentication data — password hashes, passkey (WebAuthn) public keys, TOTP secrets, App Check tokens | Securing accounts; two-factor authentication | Legitimate interests (security) (Art. 6(1)(f)) |
| Billing data — customer and subscription identifiers, invoice/PO details, payment terms | Subscription and invoice management. Card details are handled by Stripe and never touch our systems. | Contract; legal obligation (accounting) |
| Support correspondence and contact-form submissions | Responding to you; sales/procurement enquiries; spam review and audit | Legitimate interests |
| Website security (minimal) | Bot protection (Cloudflare Turnstile), security, service integrity | Legitimate interests |
| Marketing/advertising cookies — Meta Pixel (Meta) and LinkedIn Insight Tag (LinkedIn) | Advertising and campaign measurement — understand which marketing brought a visitor to our site. Set only if you accept our cookie-consent banner — see clause 10 and Cookie Notice | Consent (Art. 6(1)(a)) |
| Website analytics — Firebase Analytics / Google Analytics 4 (Google) | Understand website usage and improve the website; also carries a structured technical-error signal (no personal data — see clause 10). Set only if you accept our cookie-consent banner, and only once enabled — see clause 10 and Cookie Notice | Consent (Art. 6(1)(a)) |
| Website performance monitoring — Firebase Performance Monitoring (Google) | Measure website loading speed and technical performance. Set only if you accept our cookie-consent banner, and only once enabled — see clause 10 and Cookie Notice | Consent (Art. 6(1)(a)) |
| Portal/app usage analytics — Firebase Analytics / Google Analytics 4 (Google) | Understand product usage and improve the portal/apps; also carries a structured technical-error signal. Collected automatically (anonymised page/screen views and key actions only; never your Evidence or organisation data) — see clause 10 | Legitimate interests (Art. 6(1)(f)) |
| Mobile app crash reporting — Firebase Crashlytics (Google) | Native crash reports (stack trace, device/OS info, app version) to diagnose and fix app crashes. Not linked to your account identity. Collected automatically, no opt-in toggle — see clause 10 | Legitimate interests (Art. 6(1)(f)) |
| Audit data (who did what, when, in the Service) | Evidence integrity, security, fraud prevention | Contract / legitimate interests |
3.2 As processor (evidence / Tenant Personal Data)
We process the following on our customers' behalf, on their instructions, under the DPA. The customer is the controller and determines the lawful basis (typically a legal obligation or legitimate interests relating to housing standards):
| Data | Notes |
|---|---|
| Property data — addresses, UPRNs, EPC data | Address strings sent to address/EPC lookups (see subprocessors) |
| Environmental readings and observations | Temperature, humidity, condition notes, HHSRS/IAQ inputs |
| Photographs of homes | Special care — see clause 4 |
| Inspection GPS fix | Special care — see clause 4 |
| Surveyor and Authorised-User identifiers | Who captured/edited a record; sealed with it |
| Work orders, deadlines, statutory-stage timestamps | Awaab's Law tracking data |
Records are designed to describe properties, not people. Customers are contractually required (see the Terms and DPA) not to enter tenant personal data, and never special-category data, into free-text or evidence fields, and to minimise any personal data they do enter.
4. Photographs and location — special care
Photographs of homes and a precise GPS fix can be sensitive. Accordingly:
- Photographs are captured to evidence property condition and are content- hashed and sealed with the Evidence Record. They should show building fabric/conditions, not identifiable individuals; customers instruct their surveyors accordingly.
- Location is captured only when a surveyor deliberately captures a GPS fix during an inspection, to geo-stamp the record at the point of capture. There is no background tracking, no movement history, and no advertising use.
As processor, we hold this data for the controlling organisation; requests about it should go to that organisation (clause 9).
5. Where your data lives — UK residency
All platform data (Firestore database, Cloud Storage, Cloud Functions, and authentication) is stored and processed in the Google Cloud London region (europe-west2). Region pinning is enforced in our codebase. Website and portal static assets are code, not customer data, and are served via CDN.
International transfers are limited to what our subprocessors necessarily involve (clause 6); where any transfer outside the UK occurs, it is made under an appropriate safeguard (for example, the UK IDTA/Addendum to the EU Standard Contractual Clauses, or an adequacy decision), as set out per subprocessor on the subprocessors page.
Marketing/advertising cookies, analytics and diagnostics specifically (clause 10, Cookie Notice): Meta Pixel (Meta Platforms Ireland Ltd / Meta Platforms, Inc., both US-headquartered), LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company / LinkedIn Corporation, US-headquartered), Firebase Analytics / Google Analytics 4, Firebase Performance Monitoring and Firebase Crashlytics (each Google Ireland Limited / Google LLC, US-headquartered) each involve a transfer of the relevant data outside the UK when set. The website trackers (Meta Pixel, LinkedIn Insight Tag, Firebase Analytics, Firebase Performance Monitoring) load only if you accept our cookie-consent banner. The portal/app analytics and technical-error reporting, and the mobile apps' Crashlytics crash reporting, are automatic in our signed-in products (legitimate interests — see clauses 3.1 and 10; anonymised usage/diagnostic data only, never your Evidence or organisation data). Each provider relies on its own standard contractual clauses (or equivalent transfer mechanism) as data importer.
6. Subprocessors
We use the following subprocessors. AI providers used for survey-content assistance are the customer's own — see clause 6.1.
| Subprocessor | Purpose | Data / notes |
|---|---|---|
| Google Cloud / Firebase | Hosting, database (Firestore), storage, authentication, Cloud Functions | Core data plane — pinned to europe-west2 (London) |
| Stripe | Card payments and invoicing | Payment card data handled by Stripe (PCI-DSS); we store only customer/subscription identifiers |
| Cloudflare | CDN, DNS, WAF, and Turnstile bot-protection on website forms | Turnstile processes a challenge token/IP for bot detection; minimal, security purpose |
| Google Workspace (SMTP relay) | Sending transactional and notification email (e.g. from a no-reply platform address) | Email metadata and content of platform emails |
| Ordnance Survey / Google Places | Address-to-UPRN resolution and address autocomplete | Address strings only — no tenant personal data |
| EPC register (gov.uk) | Energy-performance lookups for a property | Address/property identifiers only; a public register |
| Google (AI Studio) — public docs assistant only | Powers the public documentation assistant on our website | Only public marketing/documentation content — never Customer Data, Tenant Personal Data, or an auth token |
| Meta (Meta Pixel) | Advertising and campaign measurement on the marketing website | Consent-based — set only if you accept our cookie-consent banner; see clause 10 and Cookie Notice |
| LinkedIn (Insight Tag) | Advertising and campaign measurement on the marketing website | Consent-based — set only if you accept our cookie-consent banner; see clause 10 and Cookie Notice |
| Google (Firebase Analytics / Google Analytics 4) | Website usage analytics (marketing website) and product usage analytics (portal/apps); also carries a structured technical-error signal on each surface | Website: consent-based — set only if you accept our cookie-consent banner. Portal/apps: automatic (legitimate interests, no cookie banner or toggle in a signed-in app); see clause 10 and Cookie Notice |
| Google (Firebase Performance Monitoring) | Website loading-speed and technical-performance measurement (marketing website and portal) | Website: consent-based — set only if you accept our cookie-consent banner. Portal: automatic (legitimate interests); timings and request URLs only, no page content; see clause 10 and Cookie Notice |
| Google (Firebase Crashlytics) | Native crash reporting in the mobile apps | Automatic (legitimate interests) — stack trace, device/OS info, app version; not linked to your account identity; see clause 10 and Cookie Notice |
6.1 Customer-keyed AI providers
If a customer enables advisory AI assistance on survey content, that processing runs on the customer's own AI provider account and API key (for example, Anthropic, Azure OpenAI, OpenAI, Google, or a compatible endpoint the customer configures). The customer's relationship with that AI provider — including the data-processing agreement — is the customer's own. We store the customer's key server-side only, scope its use strictly to that customer, refuse AI actions on finalized records, and fail closed when no key is configured. AI output is advisory and never enters the sealed evidential record automatically.
We give notice of material subprocessor changes as set out in the Data Processing Agreement. The current, up-to-date list is also published on the subprocessors page.
7. Retention
- Finalized Evidence Records are intentionally tamper-evident: no client or API path can edit or delete them, and any change to a sealed record by any means breaks its cryptographic hash chain and is detected automatically. They are retained for the period the controlling organisation sets (default reflects housing-disrepair limitation periods, commonly six years or longer). We do not claim a finalized record can never be altered at the infrastructure layer; we claim any such change cannot be made undetectably (see the Terms of Service, clause 2.4).
- Draft records can be soft-deleted with an audit trail. Soft-deleted drafts leave an audit tombstone; their heavy payload and photos are purged by an automated janitor after a retention window (default around 30 days), while the tombstone/audit record is kept.
- Deleted organisations are purged by an automated sweep after their deletion window (self-service organisation deletion: a 90-day cancellable window; superadmin-initiated deletion: a shorter documented cool-down), subject to records we must legally keep.
- Audit logs are retained with the evidence they protect.
- Account personal data is deleted within 90 days of account closure.
- Accounting/billing records are retained for six years to meet UK accounting-retention requirements, after which they are removed.
- EDI/export artefacts are retained on a rolling window (default around 90 days).
Where UK GDPR erasure rights are engaged for personal data inside Evidence Records, we work with the controller, noting the Article 17(3)(e) exemption (retention for the establishment, exercise or defence of legal claims).
8. Security
TLS in transit and encryption at rest throughout; default-deny access rules with per-organisation isolation; server-authoritative finalization with cryptographic hash chains and append-only audit logs; app attestation (App Check); two-factor authentication (TOTP or passkey); credentials and API keys stored only as salted hashes. We describe our full posture, honestly, on our website's security page.
We do not currently hold SOC 2, ISO/IEC 27001 or Cyber Essentials certification; we operate to those control frameworks and are working towards certification. We make no certification claim unless and until certified.
9. Your rights
Under UK GDPR and the Data Protection Act 2018 you may request access, rectification, erasure, restriction, portability, or object to processing.
- For evidence/tenant data (where we are processor): contact the housing organisation that holds the record — it is your controller. We support that organisation with real, self-service tools: an org-administrator can export all of an organisation's data (as a signed ZIP) and can request full organisation deletion, both without needing a support ticket.
- For account, billing and website data (where we are controller): contact us using the details in clause 1. Any user can delete their own account self-service; their personal data on membership records is redacted, while Evidence Records survive under an opaque identifier (Art. 17(3)(e)).
You have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk. We would appreciate the chance to resolve your concern first.
10. Cookies and similar technologies
We set no advertising or analytics cookies without your consent. Our website uses a cookie-consent banner: strictly-necessary storage — for example authentication/session storage in the portal and app, App Check attestation tokens, and Cloudflare Turnstile for bot protection on forms — is always on, but marketing/advertising and analytics cookies load only if you accept, and you can withdraw that consent at any time via "Manage cookies" in the website footer. The website is configured to set four technologies on consent: Meta Pixel, LinkedIn Insight Tag (advertising and campaign measurement), Firebase Analytics / Google Analytics 4 (website usage analytics plus a structured technical-error signal — unhandled page/script errors, no personal data — when enabled) and Firebase Performance Monitoring (website loading-speed and technical-performance measurement, when enabled) — see clause 6 and the international transfer note in clause 5.
Separately, our portal and mobile apps (signed-in products, where there is no cookie banner) use Firebase Analytics / Google Analytics 4 automatically, to understand product usage — anonymised page/screen views and key actions only, plus the same structured technical-error signal; the portal also uses Firebase Performance Monitoring automatically. There is no opt-in toggle; none of it ever collects your Evidence or organisation data. Our mobile apps additionally use Firebase Crashlytics automatically for native crash reporting — stack trace, device/OS information and app version when the app crashes, not linked to your account identity (we make no setUserId call). Crashlytics exists only in the mobile apps; it has no web equivalent, which is why the website and portal use the performance-monitoring and error-signal tools above instead. We rely on legitimate interests (Art. 6(1)(f)) as the lawful basis for this automatic analytics, error, performance and crash reporting in the signed-in products. If you would prefer we not process this diagnostic/analytics data about your organisation's use of the portal or app, contact support and we will consider a technical opt-out.
The Cookie Notice is the authoritative, up-to-date detail for this clause and will be updated first if any of this changes.
11. Children
The Service is a B2B tool for housing professionals and is not directed at children. We do not knowingly collect personal data about children through our own controller-side processing.
12. Changes
We post changes here with a new version number and effective date. Material changes affecting organisations are notified to organisation administrators.
ProSurvey Apps Limited · registered in England and Wales, company number 17118570 · HousingSurvey Pro™.
Changelog
- v2.4 (14 July 2026) — Full UK-law B2B SaaS suite drafted (W-E1), published live (W-E2/H-LEGAL-PUBLISH). Supersedes the v1.0 short-form page.