1. Data Controller
Walther Field is operated by the platform provider. For the purposes of the UK GDPR and the Data Protection Act 2018, the operating company is the Data Controller for account and platform data.
Surveying companies that use the platform to manage their own client information act as independent Data Controllers for the personal data they enter (client names, addresses, and contact details). This policy covers both the platform's own data collection and describes how surveying company data is handled.
Data Controller contact details:
Walther Group Ltd
Contact email: walther118@outlook.com
ICO registration number: [to be registered]
2. Personal data we collect
We collect the following categories of personal data:
- Account data: Company name, contact name, contact email, and contact phone number provided when requesting access to the platform.
- User data: Name and email address of invited surveyors and administrators, managed through the platform's authentication system.
- Client data: Names, addresses, and contact details of clients entered by surveying companies when creating surveys. This is entered and controlled by the surveying company, not the platform.
- Survey data: Site names, addresses, descriptions, surveyor names, survey dates, building details, room descriptions, sample locations, material descriptions, and associated photographs.
- Photos: Site, building, room, and sample photographs uploaded during surveys.
3. How we use your data and lawful basis
We process personal data under the following lawful bases:
- Contract (Article 6(1)(b)): To provide and manage the asbestos surveying platform service for registered companies and their users.
- Legitimate interests (Article 6(1)(f)): To operate, secure, and improve the platform, including account administration, billing, and technical support.
- Legal obligation (Article 6(1)(c)): To comply with legal and regulatory requirements, including record-keeping obligations relevant to asbestos surveying.
- Consent (Article 6(1)(a)): For any optional communications or features where consent is required. Consent can be withdrawn at any time.
We do not use personal data for automated decision-making or profiling.
4. Who we share data with
We do not sell personal data to third parties. We do not share personal data with advertising networks, analytics platforms, or external marketing services.
Personal data is shared only in the following circumstances:
- Cloud hosting provider: Data is stored on secure cloud infrastructure provided by the platform's hosting service. This provider processes data solely on our instructions under a written data processing agreement.
- Authentication provider: Email and password authentication, and optional Google sign-in, are handled by the platform's authentication service. Google receives only the authentication request — not your survey or client data.
- Legal compliance: Where required by law, court order, or regulatory authority, we may disclose data to the extent necessary.
Surveying companies' client data is visible only to that company's authorised users and administrators. Other companies cannot access it.
5. Data retention
We retain personal data only for as long as necessary:
- Account data: Retained for the duration of the company's subscription and for up to 6 years after termination for legal, tax, and contract record purposes.
- Survey data and photos: Retained for the duration of the subscription. Surveying companies are responsible for determining appropriate retention periods for their client data, taking into account legal and insurance requirements (typically 6 years for asbestos survey records).
- Client contact data: Retained while the client relationship is active. Surveying companies can delete client records at any time using the data erasure tools in the platform.
When data is no longer needed, it is securely deleted or anonymised.
6. Security measures
We implement appropriate technical and organisational measures to protect personal data:
- Encryption in transit: All data is transmitted over HTTPS (TLS encryption).
- Access control: The platform is invite-only. No public access to any survey data is possible without authentication.
- Company-level isolation: Each surveying company's data is isolated at the database level. One company cannot see another company's surveys, clients, or samples.
- Role-based access: Administrators and surveyors have different permission levels. Only administrators can manage company settings and user access.
- Secure authentication: Passwords are hashed and managed by the platform's authentication service. Optional Google sign-in is available.
- Regular security scanning: The platform runs automated security scans to identify and address vulnerabilities.
Device data: When surveyors work offline, data is cached locally on their device. We recommend that devices used for survey work have a passcode or biometric lock enabled to protect data if the device is lost or stolen.
7. Your rights under UK GDPR
You have the following rights regarding your personal data:
- Right of access: You can request a copy of the personal data we hold about you.
- Right to rectification: You can ask us to correct inaccurate or incomplete data.
- Right to erasure: You can ask us to delete your personal data when it is no longer needed or if you withdraw consent.
- Right to restrict processing: You can ask us to limit how we use your data in certain circumstances.
- Right to data portability: You can request your data in a structured, machine-readable format.
- Right to object: You can object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent: Where processing is based on consent, you can withdraw it at any time.
To exercise any of these rights, contact us using the details in Section 1.
8. International data transfers
Data is stored on cloud infrastructure that may process data outside the UK. Where this occurs, appropriate safeguards are in place, including standard contractual clauses and the UK International Data Transfer Agreement, to ensure your data is protected to UK GDPR standards.
9. Data breach response
In the event of a personal data breach, we follow a documented breach response process. Where a breach is likely to result in a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.
A detailed breach response procedure is available to platform administrators within the application.
10. Changes to this policy
We may update this privacy policy from time to time. The date at the top of this page indicates when it was last updated. We will notify users of significant changes through the platform.
11. Complaints
If you have a concern about how we handle your personal data, please contact us first using the details in Section 1. You also have the right to complain to the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Phone: 0303 123 1113
Website: ico.org.uk