How Washscope should handle property and personal data.
The product uses public property context, modelled environmental information and information supplied by homeowners and professionals. The production service should collect the minimum personal information needed for each workflow and clearly separate public property facts from private customer records.
Information collected
Account and contact details, property addresses, maintenance preferences, quote and booking records, provider business information, messages, payment status, site evidence, approximate or precise location when a field workflow requires it, and device or security logs.
Why it is used
To build and improve a property record, estimate condition, match and verify professionals, produce quotes, coordinate bookings, process payments, resolve disputes, protect the atlas and comply with legal obligations. A production collection notice should identify which fields are required and what happens if they are not supplied.
Disclosure
Homeowner identity and exact property data should only be disclosed to a professional when needed for an accepted workflow. Payment and infrastructure vendors should receive only the information required to provide their service. Overseas disclosure and hosting locations must be documented before launch.
Location and property intelligence
Route and arrival location should be purpose-limited, time-limited and visible to the user. Raw atlas scores, bulk property intelligence and unrestricted address lists should not be delivered to provider devices. Access should be audited.
Retention, access and correction
Records should be retained only as long as needed for the disclosed purpose, legal obligations, disputes and security. Users need a route to request access to and correction of their personal information. Draft onboarding data saved in this prototype remains on the current device until cleared.
Security
Production controls should include authenticated accounts, tenant isolation, encryption in transit, private object storage, short-lived media links, least-privilege access, audit logs, incident response and tested deletion procedures.