Skip to Content

← All policies

DRAFT — for solicitor review; not yet in force.
subprocessors · version 1.0 · effective TBC Permanent link: /policies/subprocessors/1.0

DRAFT — for solicitor review; not yet in force.

Property Inspector — Sub-processor List

1. About this list

1.1 This list identifies the third parties that MBGW Limited (MBGW) uses to process personal data in providing the Property Inspector service (the Service), as required by section 7 of our Data Processing Agreement. It also identifies MBGW's own hosting estate for completeness.

1.2 We will give subscribers at least 30 days' notice by email before adding or replacing a sub-processor, and will publish a new version of this list. Previous versions remain available at [TBC: public policies URL].

1.3 Three kinds of entry appear below:

  • Always used — engaged for every subscriber as part of running the Service.
  • Called from your browser — a provider that the workspace office contacts directly from the user's own browser (for example to load map tiles), rather than through MBGW's servers. The provider therefore sees the user's IP address and browser details as well as the data described in the entry.
  • Only if you connect it — engaged only for a subscriber who chooses to connect that integration in their workspace settings. Connecting the integration is the subscriber's instruction to share the relevant data with the provider; disconnecting it stops further sharing.

2. Hosting (always used)

Provider MBGW Limited — own infrastructure, operated by MBGW
What it does Hosts every component of the Service: subscriber portal, per-workspace office application and database, the API, the mobile-app back end, messaging server, object storage for photographs, documents and reports, backups and exports, and monitoring.
Data processed All subscriber account data and all Customer Data.
Location United Kingdom. [TBC: confirm the physical site address(es) to be disclosed, if any.]
Transfer mechanism Not applicable — data does not leave the UK.

3. Payments (always used)

Provider GoCardless Ltd, Sutton Yard, 65 Goswell Road, London EC1V 7EN
What it does Collects subscription fees by Direct Debit (and, where offered, instant bank payment for the first payment). Holds the Direct Debit mandate and bank account details; MBGW holds only the mandate reference and payment status.
Data processed Subscriber name, email address, billing address, bank account details, payment amounts and dates. Subscriber account data only — no Customer Data.
Location United Kingdom [TBC: confirm any processing in the EEA or elsewhere per GoCardless's current sub-processor disclosure].
Transfer mechanism [TBC: UK adequacy regulations for EEA / GoCardless's standard terms.]
Status [TBC: GoCardless integration is not yet live; this entry takes effect when it is.]

4. Email delivery (always used)

Provider Microsoft Ireland Operations Ltd (Microsoft 365 / Exchange Online, sent via Microsoft Graph)
What it does Sends transactional emails from the Service: account verification, password reset, user invitations, workspace ready and closure notices, and service announcements.
Data processed Recipient name and email address, message content (which may include the subscriber's workspace name and user names).
Location United Kingdom / European Economic Area [TBC: confirm Microsoft 365 tenant data residency].
Transfer mechanism UK adequacy regulations (EEA); Microsoft Products and Services Data Protection Addendum. [TBC]
Note [TBC: whether a separate transactional email provider will be adopted at go-live; if so this entry is replaced with 30 days' notice.]

5. Live traffic and travel-time estimates (always used)

Provider TomTom International B.V., De Ruijterkade 154, 1011 AC Amsterdam, Netherlands
What it does Two features of the team location map in the workspace office. Traffic overlay: supplies live traffic map tiles for the optional traffic overlay; when the overlay is shown, MBGW's office server requests tiles for the map area on screen and passes them to the browser. Travel-time estimate (ETA): while a team is marked as en route to a work order, the office map periodically sends that team's current device position and the work order's site position to TomTom's Matrix Routing service and receives a live-traffic travel time, which is shown next to the team on the map. The ETA request is made by MBGW's office server, not the browser. If no TomTom key is configured, the estimate comes from MBGW's own routing engine and nothing is sent to TomTom.
Data processed Traffic overlay: map tile coordinates (the geographic area being viewed) and the office server's IP address. ETA: the latitude and longitude of the en-route engineer's device and of the destination site, sent as bare coordinate pairs at roughly 20-second intervals while the map is open and a team is en route. No names, identifiers, addresses or other workspace data are included in the request. [TBC: confirm the ETA polling interval and that TomTom does not retain routing coordinates beyond request handling, per its API terms.]
Location European Economic Area.
Transfer mechanism UK adequacy regulations (EEA). [TBC: confirm the applicable TomTom API terms / data processing terms.]

6. Map tiles and address geocoding (always used — called from your browser)

Provider OpenStreetMap Foundation, St John's Innovation Centre, Cowley Road, Cambridge CB4 0WS, United Kingdom (OpenStreetMap tile service and the Nominatim geocoding service)
What it does Base map: the team location map and the site location picker in the workspace office load their base map tiles directly from OpenStreetMap's tile servers into the user's browser. Geocoding: when a user places or drags a site pin on the location picker, the browser asks Nominatim for the address at that point (reverse geocoding); when a user types an address into the picker's search box, the browser sends that text to Nominatim to find matching places. These requests go straight from the browser to the provider; MBGW's servers are not in the path.
Data processed The user's IP address and browser identification; the map area being viewed (tile coordinates); the coordinates of site pins sent for reverse geocoding; address search text typed into the picker. Engineer device positions are plotted by the Service on top of the tiles and are not sent to OpenStreetMap.
Location OpenStreetMap Foundation is a UK company; its tile and geocoding servers are located in the UK and EEA [TBC: confirm from the OSMF privacy policy].
Transfer mechanism OpenStreetMap Foundation's published privacy policy and tile/Nominatim usage policies. [TBC: OSMF does not offer a data processing agreement. Decide whether to (a) treat it as an independent controller of the browser requests and move this entry to section 10, or (b) route tile and geocoding requests through MBGW's servers so that the user's IP address is not exposed.]
Note The map's layer picker also offers alternative base layers that are loaded directly by the browser in the same way: satellite and grey base maps from Esri (Environmental Systems Research Institute, Inc., Redlands, California, USA — ArcGIS Online) and a topographic layer from OpenTopoMap (Germany). They receive the same IP address and tile-area data. [TBC: whether to keep these optional layers at go-live; if kept, each needs its own entry with a transfer mechanism (Esri is outside the UK/EEA).]

7. Google — push notifications (always used) and integrations (only if you connect it)

Provider Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Firebase Cloud Messaging; Google Workspace, Google Drive, Google Calendar, Google sign-in)
What it does Push notifications (always used): the mobile app on every workspace's Android devices receives push notifications through Google's Firebase Cloud Messaging (FCM). The Service sends a message through FCM to wake a device when a record it should have has changed (work orders, teams, engineers, customers, folders, forms, privileges) and when a team-chat message arrives for a device that is offline. Sign-in (only if used): if a user signs in with Google, Google authenticates them and returns their name and email address. Drive (only if connected): PDF reports and customer/site folders are written to the subscriber's own Google Drive. Calendar (only if connected): work orders are synchronised two-way with a calendar per team in the subscriber's own Google account.
Data processed Push notifications: the device's push token, the message type and the identifiers of the records concerned (workspace-scoped references, status and display reference — not the record contents); for chat, the sender's team name, the recipient address and the text of the chat message. [TBC: whether chat message text should be removed from the push payload so that only a wake-up signal passes through Google.] Sign-in: user name and email. Drive: report PDFs (which contain inspection data and may contain personal data of site contacts and engineers), folder names (customer and site names). Calendar: work order title, timing, site address, assigned team. Access tokens for the subscriber's Google account are held encrypted by MBGW.
Location Google processes data globally, including outside the UK and EEA.
Transfer mechanism Google's data processing terms for Firebase and for Workspace / API services, which incorporate the UK Addendum to the EU Standard Contractual Clauses. [TBC: confirm applicable Google terms for Firebase Cloud Messaging and for Workspace; note the subscriber's own Google contract also governs data in their Drive/Calendar.]

8. UK address lookup (always used)

Provider Ideal Postcodes Ltd, United Kingdom [TBC: confirm registered name, company number and address from the Ideal Postcodes terms].
What it does Finds UK postal addresses from a postcode. When a user types a postcode into an address field in the workspace office or the mobile app, the Service's API sends that postcode to Ideal Postcodes and returns the list of matching addresses for the user to pick from. Results are cached in the Service for a period so that the same postcode is not looked up repeatedly. The request is made by MBGW's API server; the provider is not contacted from the browser or the app.
Data processed The postcode entered and the API server's IP address. No names, customer or site identifiers or other workspace data are sent. The returned addresses are public postal address data.
Location United Kingdom [TBC: confirm from the Ideal Postcodes privacy policy].
Transfer mechanism Not applicable if UK-only. [TBC: confirm the applicable Ideal Postcodes API terms / data processing terms.]

9. Microsoft (only if you connect it)

Provider Microsoft Ireland Operations Ltd (Microsoft 365, Microsoft Graph, Microsoft Entra sign-in)
What it does Sign-in: if a user signs in with a Microsoft account, Microsoft authenticates them and returns their name and email address. Files: if the subscriber connects Microsoft 365, PDF reports and folders are written to the subscriber's own SharePoint / OneDrive. Calendar: if the subscriber connects Microsoft 365 calendars, work orders are synchronised two-way with calendars in a shared mailbox in the subscriber's own Microsoft 365 tenant.
Data processed As for the Google Drive and Calendar integrations (section 7), within the subscriber's own Microsoft 365 tenant. Application credentials for the subscriber's tenant are held encrypted by MBGW.
Location Per the subscriber's own Microsoft 365 tenant residency (usually UK or EEA).
Transfer mechanism UK adequacy regulations (EEA); Microsoft Products and Services Data Protection Addendum; the subscriber's own Microsoft contract governs data in their tenant. [TBC]

10. Providers that are not sub-processors

10.1 App stores. The mobile app is distributed through Google Play [TBC: and Apple App Store]. The store operator processes the installing user's data under its own terms as an independent controller; it does not receive Customer Data from the Service.

10.2 Identity providers used only for sign-in (Microsoft, Google) act as independent controllers of the sign-in itself; they are listed above because MBGW also receives data from them.

10.3 Content delivery network. The site location picker in the workspace office loads its address-search add-in script from the unpkg.com content delivery network [TBC: operator and location] directly in the user's browser, which exposes the user's IP address to that network. No workspace data is sent. [TBC: bundle this script with the Service so that no third-party CDN request is made.]

11. Change history

Version Effective date Change
1.0 [TBC] Initial list.

Versions: v1.0 · Integrity: sha256 e96ae54c8bed5bb8