ProspectBase
Compliance and privacy

Built for the obligations you already have

Prospecting software touches other people's personal information. In Australia that comes with rules, and a tool that treats them as a checkbox makes them your problem. We build them into the model instead.

Do Not Call

The register restricts a channel, not a door

A listed number means you should not make a cold marketing call to that number. It does not mean you cannot knock, drop or write. ProspectBase says exactly that, keeps the door in your round with the restriction shown as a caveat, and will never suggest adding it to a call list.

The only thing that suppresses a door entirely is the person themselves asking you not to contact them.

Consent

Captured at the moment it is given

Every hand-typed contact carries a reason from a fixed list, the person who entered it, and where relevant the consent method and date. Every hand-typed number is stamped unwashed and advisory at the moment it is written, so it can never be mistaken for a checked one.

Files

The attestation sits on the record

Every source file carries who uploaded it, when, and the attestation they confirmed at the time, with the version of the wording they saw. The compliance decision about a data file is captured at the moment it is made, by the person who made it.

Notifications

No personal information leaves in an email

Outbound notifications are composed from a fixed allow list: campaign name, area, home count, date and a link that requires a session. No owner names, no addresses, no phone numbers, and an automated test enforces it.

Separation

One agency cannot see another

Which agency you are is resolved on the server, checked against your membership and enforced once at a single boundary rather than in hundreds of places. A request for another agency's data fails before it reaches any handler, and every request is audited.

Hosting

Australian, encrypted, and support cannot write

Hosted in Sydney, with every table encrypted under a key we control. Support access to your account is time boxed between one and seventy-two hours, requires a stated reason, and passes read checks only. It can never write to your data.

On surveillance

We record work. We do not track people.

Field software has an obvious temptation and we have declined it. There is no location trail, no live map of where your staff are, no arrival detection and no "find my team". Those features are not on the roadmap.

What is recorded is what coverage genuinely requires: an address, a time, an activity, and the person who logged it. That is enough to answer "has this street been worked" without turning an agency into a monitoring operation, and it is a great deal easier to explain to your team.

Roles
·OwnerEverything, including who else has accessfull
·AdminConfiguration and data, not ownershipfull
·AgentWorks the ground, logs the workstandard
·MemberSees the territory, limited writesstandard
·AuditorReads everything, changes nothingread only
·Walker linkAddresses for one campaign. No owner data reachable at allisolated

What the interface offers and what the server permits are generated from the same rule, so the two cannot drift apart.

Send us your privacy questionnaire

We would rather answer it before you buy than after.