Privacy & contact
This notice covers the current invitation-based property-research workspace. Updated 30 September 2026.
Who is responsible
SVG ASSOCIATES LTD is the controller for this workspace. We are registered in England and Wales, company number 17391911, with ICO registration ZC241701.
Registered office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ.
For service enquiries or privacy requests, email stefano@svgassociates.co.uk.
What we collect and why
We use property labels, coordinates and the selected buyer, seller, estate agent, solicitor or platform administrator role to organise requested research. We collect published planning observations and linked official document text, and retain their source URLs, content hashes, timestamps and research outcomes. Public sources can contain information about owners, applicants, neighbours and professionals; public availability does not remove their privacy rights.
You can add authorised document text and a document name. The current form saves text rather than the original file. Case contacts, administrative authority, correspondence, supplied transaction facts and search-request receipts are also stored for the case. Identity, bank, medical and unrelated personal information are not needed for this research workflow. There is no automatic personal-data redaction.
Our lawful basis for proportionate public-source research, keeping its evidence and protecting workspace access is legitimate interests under UK GDPR Article 6(1)(f). These interests are responding to the property enquiry, maintaining an accurate source trail and preventing unauthorised access. We limit the information to the case purpose rather than using it for marketing or a general people-search service.
Access, cookies and security
Each client invitation is linked to a workspace. Client workspaces are separate unless the platform administrator deliberately shares an existing workspace. Access can permit case work or viewing only. Founder administrators manage invitations and can select company or client workspaces. We store invitation labels, roles, expiry, revocation and credential digests, and check workspace permissions against stored sessions.
A necessary session cookie keeps you signed in for up to eight hours. Session and request-validation data protect access; temporary network-address counters limit abusive requests. Application request logs record route, method and status rather than document text or access tokens. Hosting providers also process ordinary infrastructure and network logs. We do not use advertising or analytics cookies on these pages.
Research sources and model review
Public research requests go to the government's Planning Data and public energy-certificate services and the currently supported official sources, including linked council and Historic England material. Source services receive the requested coordinates or document URL and normal request metadata.
When a model review is attempted, bounded case context and selected source and document text can be sent to the configured model provider. That can include text you added: uploads are not automatically anonymised or excluded from review. The selected model provider is reported in the workspace. The launch configuration uses the OpenAI API; the earlier Neon AI Gateway route returned an account-not-enabled error. A provider setting alone does not establish that a model review succeeded. Missing or failed review is shown explicitly in the case.
Available reviews produce cited findings and proposals. Model proposals are not automatically executed. Authorised administrative correspondence uses fixed templates and recorded contacts; when email delivery is enabled, recipients and the configured email service receive the message and delivery metadata. The workspace does not sign documents or make decisions to exchange or complete a transaction. Public-source gaps remain visible. A connected search supplier can receive the requested property address, title reference and exact quoted-price authorisation; no supplier quote or paid order is claimed when provider access is unavailable.
Hosting and international processing
Render runs the application in Frankfurt, Germany. Neon stores the operational database in AWS US East (Ohio), United States. Model requests use the configured provider API. The previous Neon AI Gateway route used its US region; OpenAI processing and retention depend on the actual API account and applicable terms. Provider support and subprocessors can process information in other locations; Frankfurt application hosting does not mean that all processing stays in Germany.
Render, Neon and OpenAI publish data-processing terms and international-transfer provisions, including standard contractual clauses and a UK Addendum where applicable. Account-specific transfer arrangements, model-provider retention and training terms, and the complete provider backup retention period have not yet been verified for this workspace. We cannot promise UK-only processing, zero model retention or immediate deletion from every provider copy. Contact us for the current provider and transfer information.
Retention and deletion
Cases expire 90 days after creation. Expired cases become inaccessible, and the running worker deletes the case and its documents, evidence, jobs and reviews. You can delete a case earlier from its overview. The 90-day period is the current working retention setting, not a statutory requirement.
Invitation access expires after the chosen period; access and security records can remain after expiry or revocation, and their retention longstop is not yet established. Downloaded reports remain wherever you save them. Provider logs, backups, restored copies and model requests can have separate retention periods; deletion from the live database does not prove their immediate erasure. The exact provider backup longstop and reconciliation of earlier case deletions after a restore remain unresolved.
Your rights
You can request access, correction, deletion or restriction of your personal information and object to legitimate-interest processing. Data portability and other rights apply where their legal conditions are met. Contact stefano@svgassociates.co.uk with enough information to identify the relevant case or source; do not send an access token or unnecessary identity documents.
You can also complain to the Information Commissioner's Office. If you choose to contact us by email, we use the message and reply address to handle that enquiry.