Data Protection & GDPR
ProSurvey Apps Limited (company no. 17118570) · Trust & Security Handbook
Audience: data protection officers, security reviewers, procurement. This page states how HousingSurvey Pro handles personal data under UK GDPR and the Data Protection Act 2018. Items not yet implemented are marked planned or in progress — this page does not claim capabilities the platform does not yet have. Tracked on our internal roadmap.
Roles
- The customer organisation (housing association / contractor) is the data controller for the personal data it processes in the platform (tenant/resident details captured during surveys, its own staff accounts).
- HousingSurvey Pro is the data processor, acting on the controller's documented instructions. The published Data Processing Agreement governs this relationship, subject to any customer procurement/countersignature process.
What personal data is processed
| Category | Examples | Basis |
|---|---|---|
| Property & occupancy | address, UPRN, tenure; resident-reported damp/mould | controller's statutory housing duties |
| Survey evidence | photos, readings, surveyor observations, GPS at capture | controller instruction |
| Staff/surveyor accounts | name, email or tenant username, role, accreditations | contract / legitimate interest |
| Audit & security logs | who did what, when; sign-in events | legal obligation / legitimate interest |
The platform is designed to minimise resident personal data: it records property condition and evidence, not resident profiles.
Data subject rights
Requests are handled under a documented DSAR procedure: for tenant/property data we act as processor and assist the customer (controller), who owns the request; for account/billing data we are controller and respond directly. The tooling behind each right:
- Right of access / portability — full-organisation and subject export. Admins can export an organisation's data in a machine-readable form, including all report versions, not just the latest. The signed ZIP also includes work orders, properties, members, audit/billing data and a photo manifest; the export is audited.
- Right to erasure — authorised, audited company-data deletion with a confirmation + cooldown, extending the existing organisation suspend/delete lifecycle. Personal-account deletion, a cancellable organisation-deletion window and automated purge paths are implemented. Erasure is reconciled with the evidence-retention obligation below.
- Rectification — because sealed evidence is immutable, corrections are made as a new report version linked to the original (see the versioning model); the original is retained as the contemporaneous record.
Retention & the evidence tension
Housing damp-and-mould evidence may need to be retained for regulatory, ombudsman, or litigation purposes. HousingSurvey Pro reconciles this with erasure by:
- keeping sealed evidence immutable and hash-chained for its retention period (set by the controller's schedule);
- supporting erasure at the organisation level (offboarding) with audit;
- treating corrections as new versions rather than destructive edits.
Scheduled janitors enforce configured draft and organisation deletion windows and the EDI artefact retention limit. A customer-admin per-organisation evidence-retention setting remains planned; contractual retention text must not be confused with a shipping per-tenant configuration control.
Security of processing (Art. 32)
Summarised here; full detail in Security & data architecture:
- encryption in transit (TLS) and at rest (managed);
- tenant isolation enforced in server-side security rules;
- role baselines plus server-evaluated per-member module levels from None to Module admin; tenant, owner, sealed-record and field-assignment boundaries cannot be overridden;
- tamper-evident, hash-chained evidence with a quarantine + audit response;
- customer-controlled, advisory-only AI (no shared key; fails closed);
- remote logout — an admin can revoke a surveyor's sessions/tokens;
- immutable audit events for privileged and destructive actions.
International transfers & sub-processors
Primary hosting and the evidence backup are London (europe-west2). Subprocessors and any international-transfer position are published in the Subprocessor Register. Customer-supplied AI keys mean AI processing occurs under the customer's own provider agreement.
Breach response
Evidence-tamper detections follow a documented internal procedure that mandates disclosure over concealment and preserves original bytes. The DPA commits us to notify controllers without undue delay and assist with UK GDPR Arts.33–34, and a general incident-response plan (severity model, response lifecycle, and the processor/controller breach-notification duties including the ICO 72-hour threshold) is now documented. The tabletop exercise needed to evidence repeatable 72-hour support is still outstanding, so that support is partially implemented, not claimed complete.
Status: living document. Export, deletion, the DPA and subprocessor register are implemented/published, and an Art. 30 Record of Processing Activities plus a DSAR-handling procedure are now maintained. The per-organisation evidence-retention control and the incident-response tabletop exercise remain open.