SECURITY AND DATA

Security and data protection at ProspectOS

This page explains the account controls, campaign safeguards and supporting legal information available to agencies using ProspectOS.

Section 1

Security and control overview

Account access controls

User access can be configured according to assigned roles and branches, subject to the permissions available on the account.

Branch and postcode scope

Available controls help agencies organise access and activity around assigned branches and selected postcodes.

Recorded platform activity

Supported campaign, approval, wallet and platform activity can be recorded for operational review.

Payment information

Current payment providers and their purposes are identified on the ProspectOS Subprocessors page.

Supplier transparency

The Subprocessors page identifies suppliers used to provide specific parts of the ProspectOS service.

Data protection information

Our Privacy Policy and Data Processing Agreement explain relevant processing information and responsibilities.

Section 2

Account roles and branch controls

ProspectOS is designed around role and branch based access. The controls available to each customer depend on current product configuration and the permissions assigned to each user.

Enterprise Admin

Intended for agency level administration across authorised branches and account settings.

Branch Admin

Intended for operational and administrative activity within an assigned branch.

Standard User

Intended for operational product use within an assigned branch without agency subscription or purchasing authority.

View Only

Intended for reading permitted information without sending campaigns or changing account settings.

Disabled access

Access can be removed when a user leaves or changes role while relevant account records may be retained.

Activity records

Supported activity records can help authorised users review relevant platform actions.

Section 3

Campaign controls and recorded activity

ProspectOS includes configurable controls intended to help agencies review how campaign activity is scoped, approved, funded and recorded.

Postcode scope checks

Campaign activity can be checked against the postcodes available to the relevant branch.

Own listing checks

Configured controls can help identify properties already associated with the branch before a send.

Duplicate activity checks

Available rules can reduce unintended repeat activity within the configured period.

Wallet checks

Campaign activity that requires credits can be checked against the available balance before dispatch.

Spend controls

Configured limits can help branches manage campaign spending.

Automation review

Eligible automation activity can be placed into a review queue before dispatch.

Send history

Recorded send history can provide available destination, timing and campaign context.

Approval history

Recorded review decisions can provide additional context for authorised users.

Section 4

Data protection information and responsibilities

Customers are responsible for deciding how they use ProspectOS for their own prospecting activity. This includes identifying an appropriate lawful basis, providing required privacy information, handling objections and applying the rules relevant to each communication channel. ProspectOS responsibilities are described in the Privacy Policy and, where applicable, the Data Processing Agreement. This page is not legal advice.

Section 5

Infrastructure and supplier information

ProspectOS uses external services to operate different parts of the platform. Current suppliers and their purposes are listed on the Subprocessors page. Further technical information may be available during an appropriate customer security review.

Cloud infrastructure
Connection security
Access management
Operational logging
Backup and recovery
Payment services
Print and postage services
Property and data services
Website analytics
Section 6

Customer security responsibilities

Security is a shared responsibility. Customers should configure their account carefully and apply appropriate controls to information used or exported from ProspectOS.

Use a unique and strong password
Remove access when a user leaves
Apply the minimum permissions needed
Keep exported information appropriately protected
Review campaign content and targeting before dispatch
Report suspected security issues promptly

Ask ProspectOS about security and data

For questions about account controls, data processing or suppliers, or to report a suspected security issue, email ProspectOS. Do not include passwords, payment details or unnecessary personal data.

Email hello@prospectos.co.uk