PlaceBuilder
PlaceBuilder is the smartest way to engage communities in local decision making. It helps the built environment sector maximise inclusivity, streamline community insight and boost productivity with AI.
With a range of engagement tools, data analytics and quick setup, PlaceBuilder is the ideal engagement solution for the public sector.
Features
- Easy-to-use, fully responsive platform for higher engagement rates
- Map surveys with geofenced interactive map
- Quick polls and long form surveys
- Quick edit with drag and drop controls and project templates
- Customisable website with unlimited content
- Customisable branding: colours, logo, images, content
- Dashboard with content editor and live engagement activity
- Over 30 analytics and artificial intelligence (AI) generated insights
- Complete data export including map files
Benefits
- Maximise engagement: up to 7x more engagement than online surveys
- Flexible toolkit for all your consultations
- Quick start templates for planning, transport, net zero, behaviour, policy
- Statistically robust insights to help you close the feedback loop
- Streamline consultations to boost productivity across the organisation
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 7 0 6 3 8 7 2 1 0 0 1 7 1 4
Contact
THE FUTURE FOX LTD
Bobbi Taylor
Telephone: 02080580584
Email: hello@thefuturefox.com
About your service
- Service categories
-
Applications
Content workflow and management
- Capture
Content services
- Content Sharing and Collaboration Applications
Persuasive content management
- Website Software
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No
- System requirements
-
- Internet connection
- Web browser
User support
- Email or online ticketing support
- Yes
- Support response times
- Assistance requests logged and initiated within 1 business day. Response to question within 48 hours Monday-Friday.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- The web chat has been tested with users using assistive technologies, including screen readers and keyboard-only navigation, to ensure basic accessibility and usability. We continue to review accessibility as part of ongoing improvements and welcome feedback from users.
- Onsite support
- Yes, at extra cost
- Support levels
- Access email, phone and webchat support during office hours via the help button. Assistance requests logged and initiated within 4 working hours. All requests are handled via a Customer Success Manager with input from the technical team where required. Addition support can be agreed upon based on support requirements as outlined in the Pricing Document, using day rates.
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
We provide an on-boarding meeting, online training, user documentation, and best practise and templates.
A dedicated Customer Success Manager leads the support throughout the contract. The Customer Success Manager will arrange further support from the technical team if required by the contrac - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
- Users with the relevant permission level can export all project data from the dashboard at any time. When the contract ends, the Customer Success Manager will lead the Exit Plan which includes full data extraction on the customer's behalf.
- End-of-contract process
-
At the end of the contract the customers will have the option to request an extension of the service (for a supplementary fee) with a minimum 30 days notice.
Should the contract not be extended, the Customer Success Manager will deliver an agreed Exit Plan for successful offboarding.
The microsite content will stay active and externally visible for a minimum of 48 months.
A phone interview will be organised with the client to assess the quality of the service provided and to identify areas of improvement.
All personal and pseudo-anonymised data will be deleted in line with our Privacy Policy. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- PlaceBuilder is a fully responsive web application. There is no difference in functionality when using different devices. Layout is optimised for screen size.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Administrators access PlaceBuilder through a secure, web-based user interface using a standard web browser. Users adjust controls and input content and images to configure their consultations and analyses.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- PlaceBuilder has been tested with users using assistive technologies, including screen readers and keyboard-only navigation, to ensure accessibility and usability, and WCAG compliance. We continue to review accessibility as part of ongoing improvements and welcome feedback from users.
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Administrators with editor permission level can use their dashboard to customise:
Branding, colours and logo
Content and imagery, and alt text
Fonts, style, margins
Embedded content eg video, data maps etc
Map position and zoom
Feature configuration (turn on and off features like geotagging, demographic survey, polls etc)
Number of engagement projects
Status of engagement projects (live / launch / close) and dates
URLs and links
Menu items and navigation
User permissions and access
Site password
Scaling
- Independence of resources
- The service is designed to be distributed across multiple machines.Most of the static content is served up through a Content Delivery Network to speed up loading times
Analytics
- Service usage metrics
- Yes
- Metrics types
-
User sessions, unique responses, total responses, locations, socio demographic statistics, satisfaction levels, survey / map responses with segmentation and heatmaps.
Administrator logs contain logins, reports downloaded, activities performed. - Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Approved adminstrators can download the data from each project in the dashboard at any time.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XLSX
- CSV
- Shape file (GIS data)
- DOCX
- PNG
- Data import formats
- Other
- Other data import formats
-
- Shape files/KML for map data
- PNG
- JPEG
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.9% service availability, measured monthly, excluding planned maintenance. If availability falls below this level, customers may be eligible for a pro-rata service credit or refund, as set out in the Terms and Conditions. The service is designed for resilience using distributed cloud infrastructure. Planned or unplanned outages are communicated to users via email alerts, with updates provided until service is restored.
- Approach to resilience
- PlaceBuilder is designed for resilience using cloud-based infrastructure hosted in UK data centres operated by a third-party provider. The service uses distributed processing across multiple machines, managed backups, and monitored capacity to reduce the impact of component failure. Data centres provide built-in resilience including redundant power, networking and physical security controls. Detailed architecture and resilience information is available on request.
- Outage reporting
- Service outages are reported to users via email alerts. Notifications are sent when an outage is identified, with follow-up updates provided until the service is restored.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- Access to management interfaces is protected using strong authentication, including multi-factor authentication (MFA). Passwords are stored in encrypted form. Role-based access control (RBAC) is used to restrict access to data and project types based on user roles, with access rights reviewed on a quarterly basis. Administrative access and user actions are logged and auditable by authorised administrators. Support channels are access-controlled, encrypted, and logged to prevent unauthorised access.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Our security governance follows ISO/IEC 27001 principles and is embedded across the organisation. Security policies, including a Cyber Security Policy and Data Breach Policy, are reviewed on a quarterly basis, with oversight and accountability held by the CEO. Security is integrated into product design, development and ongoing operations, and applied across people, process and technology, including staff onboarding, training and compliance with security requirements.
- Information security policies and processes
- Our information security policies and processes are designed to minimise risk and protect customer data. The CEO holds overall responsibility for information security and policy compliance. Adherence to policies is reviewed on a quarterly basis, with actions tracked and addressed as required. Controls include strong password management, use of password managers, multi-factor authentication, role-based access controls, and device security. Staff are required to follow security policies as part of onboarding and ongoing operations. We are Cyber Essentials Plus certified and registered with the ICO.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We use source control (Git) to track all service components throughout their lifecycle. Changes are proposed, reviewed and approved by the Technical Lead and CEO before implementation. Changes are developed and tested in a staging environment using automated testing before release to production. Each change is assessed against a technical risk register, including potential security impacts, to ensure risks are understood and managed prior to deployment.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We operate a risk-based vulnerability management process aligned with Cyber Essentials Plus controls. Potential threats are identified through automated vulnerability testing, dependency monitoring, and review of system changes. Vulnerabilities are prioritised by severity and potential impact. Critical vulnerabilities are assessed and contained within 4 hours, including deploying hotfixes where required, followed by investigation and remedial actions. Software packages and operating systems are kept up to date. Threat intelligence is sourced from cloud service providers, operating system vendors, dependency security advisories, and security update notifications.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We operate protective monitoring to identify potential security compromises using system alerts, monitoring logs, and automated indicators of suspicious activity. Alerts are reviewed by authorised staff, who assess events using log data and other diagnostic information. Where a potential compromise is identified, incidents are handled in line with our Incident Management Policy, which defines roles and responsibilities across containment and recovery, investigation and risk assessment, notification, and evaluation and response. Incidents are prioritised within 4 hours, with high-priority incidents addressed immediately.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Users can report incidents to us at any time through their account manager or the Help button, by email, phone or in person. These are logged and initiated within 4 working hours. Administrators are informed regularly of progress, according to severity. Once the incident is dealt with, an incident report is filed and provided to the relevant parties by email. Data breach incidents are managed following our Data Breach policy. Our Incident management policy covers 4 steps with roles and responsibilities: Containment and recovery,Investigation and risk assessment,Notification, Evaluation and response.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Branded template site in private view
- Link to free trial
- https://www.thefuturefox.com/book-a-demo
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2.5%
- Between £500,001 and £1,000,000
- 3.5%
- Between £1,000,001 and £2,500,000
- 4%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 52d17229-aed0-47dd-b1cf-756f1b517f89
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- C4c66f73-9f67-4136-9490-e4accfb7b1e1
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
-