EvidenceTrail Trust file

Data processing and cookies posture

A procurement-facing summary for UK social-landlord pilot review. It explains the current prototype processor posture, cookies position, and the evidence still required before production contracting.

This page is not legal advice, not a signed Data Processing Agreement, not a full customer privacy notice, and not a completed DPIA.

Phase 2 update

Phase 2 announced for Oct 2026: see what changes.

Buyer decision summary

Suitable as a technical annex for customer legal and DPO review, not a signed DPA, completed DPIA, tenant privacy notice, or transfer assessment.

EvidenceTrail is positioned for UK social-landlord procurement review, while Awaab's Law legal-scope wording remains limited to the England social rented sector.

1. Treat as technical input

Use this page with the DPA/DPIA annex as review material, not signed legal terms or a customer privacy notice.

2. Confirm controller choices

Customer legal/DPO owners still decide lawful basis, retention, rights handling, transfers, and tenant privacy information.

3. Keep analytics server-side

Public-page measurement is server-side and privacy safe. Marketing cookies, browser tracking storage, or preference profiles still need consent and preference controls before launch.

Current posture

Processor role

EvidenceTrail is intended to support social landlords as a processor for tenant, property, evidence, repair, complaint, and contractor records during a customer-approved pilot.

Contract status

Article 28 terms still need customer legal approval. The current materials are technical and procurement inputs, not signed contract terms.

Cookies posture

Prototype public pages do not set non-essential analytics or marketing cookies. Server-side Plausible events run in null mode unless environment keys are configured. If non-essential storage or tracking is added later, consent and preference controls must be implemented before launch.

Product data field map

This field map is generated from current product model field groups for DPA/DPIA review. It is a technical review aid, not a completed Record of Processing Activities, signed processing schedule, customer privacy notice, or legal advice.

Current product field groups for privacy review
Model Fields Data category Purpose Controller decision Production gap
AwaabCaseorganisation_id, case_id, property_reference, tenant_referenceCase, property, organisation, and tenant referencesLink imported repair or complaint records to the correct organisation, property, and tenant reference for evidence-pack review.Customer controller confirms reference formats, lawful basis, privacy notice coverage, and whether tenant references may be processed in pilot.Customer-approved data schedule, retention, return, and deletion evidence.
AwaabCaseawareness_at, route, reported_issue, confirmed_hazardHazard triage and statutory-clock contextSurface operational clock visibility, triage route, and source issue wording without making legal compliance conclusions.Customer legal/domain owner confirms scope, special-category risk, and tenant privacy information before live data use.Legal/DPO review of live issue descriptions and statutory-scope wording.
AwaabCaseinvestigation_concluded_at, written_summary_sent_at, relevant_safety_work_completed_at, supplementary_work_started_at, alternative_accommodation_offered_atRepair lifecycle timestamps and review milestonesBuild a source-cited operational timeline for internal review, evidence gaps, and pilot readouts.Customer confirms source systems, retention period, evidence owners, and whether dates can be shared with reviewers.Signed processing instructions for source-system exports and reviewers.
EvidenceEventoccurred_at, event_type, summary, source, actor, external_referenceEvidence timeline entries and source referencesRecord evidence provenance, event type, actor/source reference, and review notes for case packs.Customer decides source permissions, redaction needs, evidence upload rules, and subject-rights handling.Customer-approved evidence-source policy, redaction workflow, and DSR process.

Article 28 evidence still required

Processor contract readiness checklist
Area Current prototype evidence Production gap
Documented instructions Product scope and evidence workflows are described for pilot review. Signed customer instructions and processing schedule are not approved.
Confidentiality and security Trust centre and procurement pack document prototype controls. Approved contractual security measures and staff confidentiality process.
Subprocessors No production subprocessors have been appointed. Approved subprocessor schedule, objection process, and residency evidence.
Rights, breach, and DPIA assistance Internal DSR report, redaction, disclosure-manifest, and incident drafts exist. Customer-approved assistance commitments, notice timings, and legal workflow.
Deletion and return Prototype evidence-pack and privacy-review surfaces describe limitations. Reversible lifecycle policy, export/return procedure, and deletion evidence.

Privacy information status

This product page does not replace the customer's privacy notice to tenants, residents, staff, contractors, or complainants. Pilot customers still need to decide controller purposes, lawful basis, retention, recipients, international transfers, rights handling, and contact details for their own privacy information.

Customer controller decisions still required

The customer legal/DPO owner should confirm lawful basis and tenant privacy information, retention schedule and deletion/return instructions, subprocessor approvals and international transfer assessment, and subject-rights and breach-assistance workflow before production use.