Access boundaries
EnvIQ separates public journeys from authenticated customer workspaces. Platform roles determine which screens and actions a user can access, while database row-level security policies and private storage rules provide an additional data boundary.
Customer organisations are logically separated. Tenant, landlord, housing-provider and platform-administration experiences are designed to expose only information relevant to the authorised role.
Data handling
Authentication, database and file-storage services are provided through controlled server and cloud integrations. Service credentials are kept on the server and must not be exposed to browser code.
Public pages do not provide direct access to private tenant, property, sensor, concern, plan or report records. Security and abuse-prevention controls may use hashed network and user-agent values; hashing is a protective measure and is not anonymisation.
Suppliers and integrations
We assess access needed by hosting, database, authentication, email, sensor and support suppliers and limit integrations to their intended purpose. Customer-specific sensor integrations are enabled only where required for the service.
Supplier locations and transfer safeguards are addressed in customer contracts and our privacy notice. We do not claim all processing is UK-only unless confirmed for the applicable configuration.
Monitoring and incident response
We review service health, access failures and operational errors and investigate suspected misuse or data incidents. Where a personal-data breach requires notification, Mersey Mould Ltd will follow applicable legal and customer-contract duties.
No internet service can promise absolute security. Customers must manage authorised users, use strong unique credentials, remove access that is no longer needed and promptly report suspected compromise.
Report a concern
Send suspected vulnerabilities or incidents to support@enviq.co.uk with the affected page or service and enough detail to investigate safely. Do not access other people’s data, disrupt the service or publish sensitive details while we assess a report.
Formal customer security, processing and subprocessor requirements should be recorded in the applicable written agreement.