Security and Incidents
Last updated: 25 September 2026
Contents
- 1. About this page
- 2. Service status
- 3. How we respond to incidents
- 4. Personal-data breaches
- 5. Reporting a security concern
- 6. How we protect data
- 7. Where data is held
- 8. Contact us
1. About this page
This page explains how ProConvey Limited (company number 13905278) tells customers about service incidents and personal-data breaches, how to report a security concern, and the main ways we protect data. For customers with a ProConvey licence agreement, that agreement sets out our commitments; this page summarises them.
2. Service status
Service status and incident updates are published at https://proconvey.betteruptime.com/ (components: Application, Sign in, Partner API, Quote requests). This page is the customer incident channel. There is no 24/7 telephone on-call.
Each component is checked automatically. If a component goes down, the status page shows it and posts an update without anyone needing to act. We also post updates for problems the checks cannot see, such as a feature that is slow or a supplier outage, and for planned maintenance. You can subscribe to updates on the status page.
3. How we respond to incidents
Our monitoring alerts a named first responder by email and push notification. If an alert is not acknowledged within 15 minutes, the whole team is alerted. For serious incidents we also email affected customers.
Schedule 2 of our licence agreement provides:
The Licensor shall use reasonable endeavours to respond to reported critical system outages within 4 business hours and to resolve or provide a workaround within 1 business day.
4. Personal-data breaches
If a personal-data breach affects data a customer firm has put into the platform, we notify the firm without undue delay, and in any event within the period in its licence agreement (24 hours under our standard terms). We tell the firm what happened, what data and how many people are affected, the likely consequences and what we are doing, and we help the firm meet its own obligations. We do not contact the Information Commissioner's Office or the firm's clients about the firm's data without first consulting the firm, unless the law requires it.
If a breach affects personal data that ProConvey controls and it must be reported, we report it to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of it, and we tell the people affected where the law requires.
5. Reporting a security concern
If you think you have found a security weakness in ProConvey, or that an account or data has been misused, email support@proconvey.co.uk straight away with as much detail as you can. Please do not try to test or exploit the weakness further; our Acceptable Use Policy does not allow testing without our written permission. For concerns about personal data, contact our Data Protection Officer: Christopher Scantlebury, chris.scantlebury@proconvey.co.uk
6. How we protect data
- The case database and its backups are encrypted at rest, and traffic to the platform uses HTTPS.
- Access is role-based, and each user has their own sign-in.
- Staff users can turn on an authenticator app for their ProConvey sign-in. It is optional and not required. Clients are not asked to use multi-factor authentication.
- New confidential documents are stored privately and opened through short-lived signed links after an access check. Some older document links remain publicly reachable. Listing photos, logos and letterhead images are public.
- Database: Aurora continuous point-in-time recovery (recovery point about 5 minutes) and daily encrypted snapshots kept for 35 days, in London only. There is no copy in a second region. Client documents are stored in Vercel Blob (Amazon S3 durability). ProConvey does not keep a separate copy of documents, so there is no ProConvey recovery point for documents. Better Stack and 1Password are not backups; 1Password is the credential store.
- ProConvey holds Hiscox cyber and data insurance with a limit of £2,000,000 and Hiscox professional indemnity insurance with a limit of £1,000,000, both in force to 25 February 2027.
7. Where data is held
The conveyancing case database, its backups and transactional email are hosted in the United Kingdom (AWS London, eu-west-2). Application compute runs in London (Vercel lhr1). Better Stack log and uptime telemetry is processed in the EU (Germany). Clerk (identity: names, email addresses, phone numbers, credentials and sessions), Knock (notification recipient details and content) and Sentry (error and session data) process personal data in the United States under UK transfer safeguards (the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses and, where the supplier is certified, the UK–US data bridge). Clerk and Knock offer no EU region. The storage region of Vercel Blob, which holds client documents, is to be confirmed. Other suppliers that receive personal data, and their locations, are listed in the sub-processor register.
8. Contact us
Security and service issues: support@proconvey.co.uk
Data Protection Officer: Christopher Scantlebury, chris.scantlebury@proconvey.co.uk
ProConvey Limited is registered in England and Wales, company number 13905278, registered office 45 Fitzroy Street, London, England, W1T 6EB.