Compliance & assurance · AVM
Data Protection
The Property Valuation API uses property identity, characteristics and a valuation date. Data-protection responsibilities depend on the information supplied, the processing purpose and the decisions made with the result.
Property Information
Keep requests limited to information needed for the valuation. Use request references for your own record identifiers and keep borrower names, income, bank details and sensitive personal information out of property fields.
Addresses and property identifiers can relate to identifiable people in context. Treat the information accordingly and restrict its use to the agreed purpose. See ICO guidance on personal information.
Access and Input Transparency
API access requires an authorised key and the relevant permissions. Stored property attributes are applied when requested, eligible and permitted. Responses identify the stored values used, ignored inputs and derived values.
These features support controlled access and a record of how a request was resolved. Establish the lawful basis for processing personal information separately, including where stored property attributes are used.
Processing and Retention Arrangements
Before processing personal information, establish the parties' controller or processor roles, purposes, lawful basis, retention periods, security responsibilities and individual-rights procedures. Include appropriate contractual terms for a processor relationship and assess international transfers where relevant. See ICO guidance on controllers and processors.
For your deployment, confirm:
- The information submitted, the permitted purpose and each party's responsibilities.
- The hosting and processing locations, service providers and safeguards for any restricted international transfers.
- Retention and deletion arrangements for requests, results, service logs, identity records, backups and provider-held copies.
- Contacts and procedures for individual-rights requests, access removal and incident communication.
Asynchronous job status and results have a seven-day retrieval window, as described in Batch and Asynchronous Jobs. This is an API availability window, rather than a deletion schedule for every copy of the information. Confirm the wider retention arrangements in the applicable processing terms.
Website Enquiries and Pilot Registration
Valtaic Ltd is the controller of information collected through its website enquiries and pilot-interest list. The website Privacy Policy covers those activities, including contact information, website measurement and individual rights.
The website's pilot-list retention period applies to registrations. Customer API processing, provider arrangements and retention are covered separately by the terms for the relevant service.
Decisions Affecting Individuals
An automated property estimate is one input to a wider decision process. Where personal information is used for a solely automated significant decision, assess the applicable safeguards, including information about the decision, representations, human intervention and contestability. Special-category information requires additional consideration. See the ICO summary of automated decision-making safeguards.
The deploying organisation implements these procedures in its decision workflow. The API's evidence and referral outputs can support the review.
Assess whether a data protection impact assessment is required before high-risk processing begins, and document risks, mitigations and review triggers. See ICO DPIA guidance.
Contact hello@valtaic.io to discuss the data-handling arrangements for your deployment.