Controlled process

Data handling for contractor records

Contractor records can contain commercially sensitive information about customers, sites, equipment, pricing and service history. Installed Revenue uses a scoped process before any live records are accepted.

No live operating records are accepted through the public website or ordinary email.

01

Before transfer

We agree the pilot scope, minimum data fields, responsibilities, access list, retention period and deletion process. Confidentiality and data-processing terms are completed before live records are received.

02

Transfer and access

Before any live records are accepted, a dedicated access-controlled workspace, multi-factor authentication and least-privilege access must be in place. Operating records must not be sent through the public website or ordinary email.

03

Data minimisation

We request only the records needed for the agreed analysis. Where a field is unnecessary, it should be excluded or redacted before transfer.

04

Use of records

Records are used only to perform the agreed service. They are not sold, used for unrelated marketing or combined with another contractor's data.

05

Customer contact

Installed Revenue does not contact a contractor's customers during the audit. Any later communication requires separate written approval, contractor-approved wording and clear responsibility for technical judgments.

06

Retention and deletion

The retention period is agreed for each engagement. At the end of that period, records are returned or deleted as agreed, subject to any limited legal or accounting retention requirement.

07

Contractor responsibilities

The contractor confirms record accuracy, service intervals, pricing, lost-customer status and all engineering, safety and compliance judgments.

08

Incident response

Suspected loss, unauthorised access or disclosure is investigated under a documented incident-response process. Contact: security@installedrevenue.com.