Privacy & Data Protection Policy
Last updated: 21 September 2026. This policy is provided by WWY Ltd and should be read alongside your organisation's own privacy documentation. It will be reviewed and updated following legal review.
Who we are
WWY Insight is operated by WWY Ltd ("WWY", "we", "us"). WWY provides the platform to client organisations so they can run quality-assurance audits of residential surveying reports. For the audit content a client organisation uploads, that organisation is normally the data controller and WWY acts as the data processor; WWY is the controller for its own account administration and billing records.
What data we hold
- Account details — name, work email address, organisation and role of authorised users.
- Uploaded documents — site notes, draft surveying reports, photograph schedules and comparable-evidence files uploaded for auditing. These may contain property addresses and limited personal details of property occupants or surveyors.
- Audit results — criteria outcomes, evidence quotations, reviewer decisions, scores and final reports produced by the platform.
- Activity records — an audit trail of significant actions (sign-ins, uploads, decisions, deletions) recording who did what and when, without document content.
How your data is protected
- Encryption in transit and at rest — all connections use HTTPS/TLS, and data stored by the platform is encrypted at rest by our hosting infrastructure.
- Strict separation between organisations — every audit, document and result is tied to its owning organisation and is enforced by server-side access controls on every request. A user of one client organisation cannot see another organisation's data, or WWY's own records.
- Least-privilege access — users only receive the permissions their role requires, granted individually by an administrator. There are no shared or anonymous accounts.
- Server-side authorisation — every sensitive action (viewing, uploading, reviewing, deleting) is checked on the server, not just hidden on screen.
- No training on client documents — uploaded documents are used only to perform the requested audit analysis; they are not used to train AI models.
- Data minimisation — only the information needed for each stage is processed and retained; extracted evidence is limited to the checks being performed.
- Accountability — an append-only activity log records administrative and audit actions so access and changes can be reviewed.
Document retention and deletion
Source documents (site notes, draft reports and comparable-evidence files) are treated as temporary working material:
- Once an audit is finalised, source documents are automatically and permanently deleted after two weeks. This period gives surveyors time to query or challenge an audit result, and each client organisation can set a shorter or longer window (up to 90 days). The business audit record — criteria results, scores, reviewer decisions and the final report — is retained separately.
- When an audit is finalised, personal data held in the retained audit record and its extracted evidence is automatically masked: email addresses, telephone numbers, full postcodes (reduced to the postcode district) and named occupiers, owners, applicants or tenants are removed, along with lender and case reference numbers. Property addresses are reduced to town and postcode district. Surveyor names, dates, results and scores are deliberately retained so audits remain meaningful and comparable. Masking is based on recognised patterns, so a bare name written into free prose may occasionally remain; WWY super administrators can re-run masking on request.
- Page images generated for on-screen viewing are deleted with the source documents; only the minimum photographic metadata (presence and labels) is kept in the audit record.
- Client administrators can delete an unfinalised audit themselves at any time; WWY super administrators can permanently delete audits, reports, client organisations and user accounts, which removes the associated stored files and records. A minimal deletion record (audit number, type, client and time) is kept in the activity log without any document content.
Your rights
Under UK data protection law, individuals have the right to request access to, correction of, export of, or deletion of their personal data, and to object to or restrict certain processing. Requests relating to audit content should be made to the client organisation that carried out the audit in the first instance; WWY will assist the organisation in responding. Statutory and contractual records are not deleted automatically where there is a lawful obligation to retain them.
Sub-processors and hosting
The platform is built and hosted on the Lovable platform, with database, authentication and file storage provided through Lovable Cloud, and document analysis performed via the Lovable AI gateway. These providers process data only to deliver the service and under their own security and data-processing terms. Data is hosted within professionally managed cloud infrastructure; WWY can provide further detail on hosting arrangements on request.
Contact
For privacy questions, data requests or to report a security concern, contact WWY Ltd at info@wwy-ltd.co.uk. You also have the right to raise a concern with the Information Commissioner's Office (ICO).
See also our cookie policy.