Skip to Content

← All policies

DRAFT — for solicitor review; not yet in force.
privacy · version 1.0 · major · effective TBC Permanent link: /policies/privacy/1.0

DRAFT — for solicitor review; not yet in force.

Property Inspector — Privacy Notice

1. Introduction

1.1 This notice explains how MBGW Limited (MBGW, we, us) uses personal data in connection with the Property Inspector service (the Service), the subscriber portal and our website. It is written to meet the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1.2 MBGW Limited is registered in England and Wales (company number [TBC]; registered office [TBC]). Our Information Commissioner's Office registration number is [TBC: ICO registration number]. You can contact us about data protection at [TBC: privacy contact email]. [TBC: whether a Data Protection Officer is appointed; none is required to be by default.]

2. Our two roles

2.1 We act as a controller for personal data about our subscribers and the people who deal with us directly: the person who registers a subscriber account, billing contacts, and visitors to our website. This notice covers that processing.

2.2 We act as a processor for the data that our subscribers and their users put into their workspaces — their customers, sites, inspections, photographs, work orders, chat messages and so on (Customer Data). Our subscriber is the controller of that data and decides why and how it is used. We process it only on the subscriber's instructions under our Data Processing Agreement. If you are a customer, employee or contractor of one of our subscribers and want to exercise your rights over data held in their workspace, please contact that subscriber; we will help them respond.

3. Personal data we collect as controller

3.1 Subscriber account data. When you register and check out we collect your name, email address, password (held by our identity broker as a salted hash, never in clear text), the plan you choose, whether you subscribe as an individual or a business, company name, company number and VAT number, billing address, telephone number and your workspace names.

3.2 Payment data. Direct Debit mandates are set up with our payment provider, GoCardless. Bank account details are entered on and held by GoCardless; we hold only the mandate reference, payment status and history. [TBC: confirm nothing else is retained once GoCardless is live.]

3.3 Sign-in data. If you sign in with a Microsoft or Google account, we receive your name, email address and the account identifier from that provider. We record sign-in events, failed attempts and lockouts.

3.4 Agreement records. When you accept a version of our Terms or policies we record the document code and version, the date and time, your IP address, your browser identification and where it was presented (checkout, re-acceptance or the portal).

3.5 Support and correspondence. Emails, support requests and notes of calls.

3.6 Usage and technical data. Server logs, error reports, request identifiers and performance traces from the web office, portal, API and mobile app (see section 7). These may include IP addresses, device model and operating system version, app version and user identifiers.

3.7 Website data. Cookies and similar data as described in the Cookie Policy.

4. Why we use it and our lawful bases

Purpose Lawful basis (UK GDPR Article 6)
Creating and managing your account, providing the Service, collecting payment Performance of a contract
Provisioning workspaces, sending service emails (verification, password reset, workspace ready, closure notices) Performance of a contract
Recording your acceptance of our terms and policies Legal obligation and legitimate interests (evidencing the contract)
Security: authentication, lockout, rate limiting, fraud and abuse prevention, audit logs Legitimate interests (protecting the Service and subscribers) and legal obligation
Operating, monitoring and improving the Service (logs, traces, error reports) Legitimate interests (running a reliable service)
Accounting, tax and regulatory records Legal obligation
Responding to support requests and correspondence Performance of a contract and legitimate interests
Telling you about material changes to the Service or our terms Performance of a contract and legal obligation
Marketing about our own similar services to business contacts Legitimate interests; you can opt out at any time [TBC: whether any marketing is planned; individuals only with consent under PECR]

4.2 We do not sell personal data, and we do not use it for automated decision-making that produces legal or similarly significant effects.

5. Who we share it with

5.1 Service providers (sub-processors). We use a small number of suppliers to run the Service. They are listed, with what they do and where they process data, in our Sub-processor List. In summary: GoCardless (payments); Microsoft (email delivery and, where a subscriber chooses to connect it, Microsoft 365 integration); Google (Firebase Cloud Messaging, which delivers push notifications to the mobile app in every workspace, and — only where a subscriber chooses to connect them — Google Workspace, Drive or Calendar); TomTom (live traffic tiles and, while a team is en route to a job, travel-time estimates from the team's device position); the OpenStreetMap Foundation (base map tiles and address geocoding, requested directly from the office user's browser); Ideal Postcodes (UK postcode address lookup); and our own UK hosting estate.

5.2 Identity providers. If you sign in with Microsoft or Google, those providers process your sign-in under their own privacy notices.

5.3 Professional advisers, insurers and authorities. Where necessary to obtain advice, to comply with law, or to establish, exercise or defend legal claims.

5.4 A buyer of our business. If MBGW or the Service is sold or transferred, the successor may receive personal data on the same terms as this notice.

6. Where data is held and international transfers

6.1 The Service is hosted on infrastructure that MBGW operates in the United Kingdom. Subscriber account data, Customer Data, backups and exports are stored there.

6.2 Some of our suppliers process data outside the UK. Where they do, we rely on the UK adequacy regulations (for example for the European Economic Area) or on the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses. [TBC: confirm transfer mechanism for each supplier in the Sub-processor List.] Details are in the Sub-processor List.

7. Logs, telemetry and the mobile app

7.1 To operate the Service reliably we collect diagnostic telemetry (logs, traces and metrics) from our servers, the web office and the mobile app. Telemetry includes request identifiers, timings, error messages, app and device version, and the user and workspace identifier that made the request. It is stored on our UK estate and retained for [TBC: telemetry retention period].

7.2 The mobile app processes the device's location to show engineers' positions on the team location map in the workspace office and to attach locations to jobs. Location is collected only while a user is signed in and [TBC: only while a job is in progress / during working hours as configured by the subscriber]. This location data is Customer Data controlled by the subscriber; we hold it as processor. While a team is marked as en route to a work order, the office map sends that team's current device coordinates and the destination site coordinates (as bare coordinate pairs, without names or identifiers) to TomTom to estimate travel time; see the Sub-processor List. [TBC: confirm exact location-collection triggers and retention.]

7.3 The app may request access to the camera and photo library (to capture inspection photographs), storage (to keep forms available offline) and notifications. Photographs are Customer Data. Push notifications to Android devices are delivered through Google's Firebase Cloud Messaging; the notification carries the device's push token, the type of change and the identifiers of the records concerned, and for team chat the sender's team name and the message text. See the Sub-processor List.

8. How long we keep it

8.1 Subscriber account data: for the life of your subscription and for [TBC: e.g. 6 years] afterwards, to meet our accounting and legal obligations and to evidence the contract.

8.2 Agreement records: for [TBC: e.g. 6 years] after the subscription ends.

8.3 Payment records: [TBC: e.g. 6 years] after the transaction, as required by tax law.

8.4 Logs and telemetry: [TBC: telemetry retention period].

8.5 Customer Data, backups and exports: as set out in the Data Retention and Backup Policy, which forms part of our contract with the subscriber.

9. Your rights

9.1 Under the UK GDPR you have the right to: access the personal data we hold about you; have inaccurate data corrected; have data erased in certain circumstances; restrict or object to processing in certain circumstances; receive data you provided to us in a portable format; and withdraw consent where consent is the basis for processing.

9.2 To exercise a right, contact us at [TBC: privacy contact email]. We will respond within one month, which we may extend by two further months for complex requests. We may ask you to verify your identity.

9.3 If you are dissatisfied with how we handle your data you may complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113). We would welcome the chance to resolve your concern first.

10. Security

10.1 We protect personal data with the measures described in our Security Overview, including per-workspace isolation, encryption in transit, single sign-on, access controls and encrypted, signed backups. No system is perfectly secure; if we become aware of a personal data breach that affects you, we will tell you and the ICO as the law requires.

11. Children

11.1 The Service is for businesses and adults. We do not knowingly collect personal data from anyone under 18 as a subscriber. Customer Data may contain personal data about individuals of any age at the subscriber's direction, and the subscriber is responsible for that as controller.

12. Changes to this notice

12.1 Each version of this notice is numbered and published with its effective date at [TBC: public policies URL]. We will tell subscribers by email about material changes and ask them to acknowledge the new version in the subscriber portal.


Versions: v1.0 · Integrity: sha256 44c22473c556fe56