Skip to content

Aptem Website and Marketing Privacy Policy

1. Introduction 

This Data Privacy Policy explains how Aptem Limited (“we”, “us” or “our”) collect, use, store, and protect personal data that we process as a data controller as part of our business operations in the United Kingdom.

This includes data relating to our customers, prospective customers, partners, and individuals who interact with us.  

This specifically includes, but is not limited to: 

  • Personal data relating to customers, prospective customers, and business contacts 

  • Information collected through sales activities, including meetings, calls, demos, and correspondence 

  • Data obtained via marketing activities, including website forms, events, newsletters, and campaigns 

  • Personal data processed through customer relationship management (CRM) systems and similar business tools 

  • Records of communications and interactions, including emails, call recordings (where applicable), and support enquiries 

  • Personal data collected through our website, including cookies and analytics (where we act as controller) 

This policy governs how we collect, use, store, and protect personal data for these purposes.  

This policy does not cover personal data processed by customers within our Aptem platform or services, where we act as a data processor. That is addressed in a separate Processor Aptem Service Privacy Policy / Data Processing Agreement (DPA). 

This policy does not cover personal data relating to current or former Aptem employees or contractors. That is addressed separately in the Employee Privacy Notice, available in the Aptem Employee Handbook. 

2. Who we are / company information 

For the purposes of applicable data protection laws, including the UK GDPR and the Data Protection Act 2018, the data controller responsible for your personal data is: 

Legal Entity: Aptem Limited 
Registered Address: Eagle House, 167 City Road, London, EC1V 1NR 
Telephone Number Details: 020 7870 1000 

Email address: hello@aptem.co.uk 

 We are registered with the Information Commissioners Office; our registration number is: Z1900970. 

Data Protection Officer 

We have appointed a Data Protection Officer (DPO) who is responsible for overseeing compliance with data protection law. You can contact the DPO at: 

Contact Name: Sarah Griffiths 

Email: dpo@aptem.co.uk  

3. Applicable laws and regulations 

We process personal data in accordance with applicable UK data protection laws, including: 

  • UK General Data Protection Regulation (UK GDPR) 

  • Data Protection Act 2018 

  • Data Use and Access Act 2025 (DUAA) 

  • Privacy and Electronic Communications Regulations (PECR) (for cookies and marketing communications) 

  • Relevant international standards such as ISO/IEC 27001 (Information Security Management) 

4. Categories of personal data we collect 

We collect and process personal data as a data controller from our customers and prospects, our business communications, and visitors and users of our website. The categories of personal data we collect include: 

  • Customer and prospect data – Name, job title, and company name; business contact details (email, phone number, address); account and billing information; records of communications (emails, calls, meeting notes); and marketing preferences and engagement history. 

  • Website and technical data – IP address and device identifiers, browser type and usage data, and cookies and tracking technologies (see Section 15). 

  • Call and interaction data – Call recordings (where applicable), customer support tickets and correspondence, and sales and onboarding interactions. 

  • Recruitment and job application data – Name, contact details, CV, covering letter, employment history, qualifications, references, and any other information you choose to include in a job application. 

5. Special category data 

We do not generally seek to collect or process special category personal data (such as data concerning health, racial or ethnic origin, religious beliefs, or trade union membership) as part of our controller activities as outlined in this privacy policy.  

Special category data may occasionally be present within the information you choose to provide us, for example: 

  • Information voluntarily included in a CV, covering letter, or job application (such as details of a disability where relevant to a request for reasonable adjustments); 

  • Health information shared with us in connection with visiting our premises or attending an event.  

Where we hold such data, we only use it for the specific purpose for which it was provided (for example, arranging reasonable adjustments during recruitment) and do not use it for any other purpose. We rely on the following conditions under Article 9 UK GDPR for processing this data: explicit consent, or where processing is necessary for the establishment, exercise, or defence of legal claims, or for reasons of substantial public interest in accordance with the Data Protection Act 2018. 

6. Source of personal data 

Personal data is collected from a range of sources when acting as a data controller, including customers and prospective customers, business communications, and visitors to and users of the website. 

These sources include: 

  • Directly from individuals, for example when a form is completed, information is requested, or contact is made  

  • An individual’s employer or organisation, where contact details are shared in a business context  

  • Website forms, including enquiries, downloads, and newsletter sign-ups  

  • Event registrations, such as webinars, conferences, or other industry events  

  • The CRM system, where personal data is recorded and managed as part of sales, marketing, and customer relationship activities 

  • Publicly available professional sources, such as company websites or professional networking platforms (e.g. LinkedIn), where appropriate  

  • Referrals or business partners, where details are shared in a professional context  

  • Job applications, submitted directly by candidates or via recruitment platforms/agencies 

Where personal data is obtained from third-party or public sources, it is only used in accordance with applicable data protection laws and legitimate business interests, and individuals are provided with relevant information about the processing where required. 

7. Purposes of processing 

We process personal data for the following purposes: 

  • Managing customer relationships and accounts 

    To establish and maintain business relationships, including onboarding customers, administering accounts, managing contracts, processing payments, and maintaining accurate records of contacts and interactions throughout the customer lifecycle. 

  • Providing information about our products and services 

    To respond to enquiries, provide product demonstrations, share relevant documentation, and communicate updates about our offerings that are relevant to customers or prospective customers. 

  • Sales, marketing, and business development 

    To identify potential customers, manage sales pipelines, conduct outreach, send marketing communications (where permitted), organise events, and analyse engagement to improve the effectiveness of our marketing and growth strategies. 

  • Customer support and service improvement 

    To provide technical and customer support, respond to queries or issues, maintain support records, and analyse interactions (including calls and tickets) to improve service quality, user experience, and operational performance. 

  • Legal, regulatory, and compliance obligations 

    To comply with applicable laws and regulations, including data protection requirements, financial record-keeping, audit obligations, and responding to lawful requests from regulators or authorities. 

Where we process special category data, we do so only where the law allows, as explained in Section 5. 

  • Security monitoring and fraud prevention 

    To protect our systems and users by monitoring for suspicious activity, preventing fraud or misuse, maintaining system integrity, and ensuring the confidentiality, availability, and resilience of our infrastructure. 

  • Recruitment and hiring 

To assess candidates’ suitability for roles, manage the recruitment process, and communicate with applicants about their application. 

8. Legal bases for processing 

We rely on the following lawful bases under UK GDPR: 

  • Contractual necessity – to perform contracts with customers, or prior to entering into a contract of employment 

  • Legitimate interests – for business operations, marketing (where permitted), and service improvement 

  • Consent – for certain marketing communications and cookies 

  • Legal obligation – where processing is required by law  

9. Data sharing and disclosure 

We may share personal data with trusted third parties, including the sub-processors as listed in our published Aptem Sub-Processors page, where necessary for the purposes set out in this policy, including but not limited to: 

  • Service providers and suppliers who process personal data on our behalf in order to support our internal business operations (e.g., CRM providers, communication platforms, IT and hosting services) 

  • Professional advisors (legal, financial, compliance) 

  • Regulatory authorities where required by law 

  • Employees, contractors, or personnel located in countries outside the UK/EEA, where access to personal data is necessary for business operations and subject to appropriate safeguards 

Where third parties process personal data on our behalf (including sub-processors), we have appropriate contractual arrangements in place to ensure that they act only on our documented instructions. These third parties are required to handle personal data securely, not to use it for their own purposes, not to disclose it further without authorisation, and to retain it only for as long as necessary in accordance with contractual obligations and applicable data protection laws. 

10. Location  

We operate a predominantly cloud-based environment for our IT systems, infrastructure, and service delivery functions. Under our current sub-processor arrangements, our core hosting services are mainly located in the United Kingdom, with certain ancillary services provided from both the United Kingdom (UK) and the European Economic Area (EEA).  

As a UK-based data controller, we handle personal data in compliance with the UK GDPR and the Data Protection Act 2018. Personal data is stored within secure, cloud-based environments and is predominantly hosted and processed in the United Kingdom, and where relevant, within the European Economic Area (EEA). 

We do not typically transfer personal data outside the United Kingdom or the EEA unless this is necessary for specific sub-processors or service providers to perform their functions, such as delivering services, providing remote support, or enabling approved features. In such cases, limited access to or processing of personal data may occur outside the United Kingdom and the EEA, including in the United States, and is subject to appropriate safeguards, such as the ICO’s International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with a data protection test (formerly known as transfer risk assessment), confirming an appropriate level of protection at the destination. 

Details of the locations for data processing by our sub-processors are available in the Aptem Sub-Processor Schedule available at this link. 

11. Data retention 

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, regulatory, accounting, or reporting requirements. 

Recruitment data for unsuccessful candidates is retained for 6 months following the closure of the recruitment process, to allow Aptem to respond to any queries or claims arising from the process, after which it is securely deleted. With consent, Aptem may retain a candidate’s details for longer for the purpose of consideration for future vacancies. 

Marketing website data 
Personal data collected through our marketing website (such as contact forms, newsletter sign-ups, and analytics data) is retained for as long as necessary to respond to inquiries, maintain ongoing communications, and improve our marketing efforts. Typically: 

  • Marketing communications data is retained until you withdraw consent or unsubscribe, after which we may retain minimal records to demonstrate compliance with applicable laws.  

  • Analytics and cookie data are retained in accordance with our cookie policy and applicable consent preferences.   

Operational data (Controller activities) 
Where we act as a data controller for operational purposes (such as customer success, billing, and customer support), we retain personal data for the duration of the business relationship and thereafter as required to: 

  • Comply with legal and regulatory obligations (e.g., tax, financial reporting, and audit requirements).  

  • Resolve disputes and enforce our agreements.  

  • Maintain appropriate business and financial records.   

Retention periods may vary depending on the nature of the data, contractual obligations and the applicable legal requirements. 

Data deletion and anonymisation 
When personal data is no longer required, we will securely delete or anonymise it in accordance with our data retention policies and applicable laws. 

 Review of retention periods 
We regularly review our retention practices to ensure that personal data is not kept longer than necessary and remains aligned with legal, regulatory, and business requirements. 

12. Data subject rights 

Where we process personal data, related to marketing and other controller activities, individuals have rights under applicable data protection laws. We are committed to respecting and facilitating the exercise of these rights in line with recognised data protection principles and good practice (including those reflected in PECR-aligned frameworks). 

Subject to certain legal limitations, you have the following rights in relation to your personal data: 

  • Right of access – You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data, along with relevant information about how it is used.  

  • Right to rectification – You may request that we correct or complete any inaccurate or incomplete personal data we hold about you.  

  • Right to erasure – You may request the deletion of your personal data where there is no lawful reason for us to continue processing it.  

  • Right to restrict processing – You may request that we limit the way we use your personal data in certain circumstances.  

  • Right to object to processing – You have the right to object to our processing of your personal data where we rely on legitimate interests. 

    In particular, you have an absolute right to object to the use of your personal data for direct marketing purposes. Where you exercise this right, we will stop processing your data for such purposes without delay.  

  • Right to data portability – Where applicable, you may request that we provide your personal data in a structured, commonly used, and machine-readable format, or transfer it to another controller.  

  • Right to withdraw consent – Where we rely on consent (for example, for certain marketing communications), you may withdraw your consent at any time. This will not affect the lawfulness of processing carried out before consent was withdrawn.  

  • Right to complain – You have the right to make a data protection complaint directly to us about how we handle your personal data, and we will investigate and respond to it in accordance with the process set out in Section 18. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) if you believe your data protection rights have been infringed. More information is available at: https://ico.org.uk/. 

We may need to verify your identity before responding to your request to ensure the security of your personal data. 

13. Automated decision-making 

Aptem may use automated decision-making technologies, including algorithmic tools and systems, in limited and proportionate circumstances to support our business operations, such as improving our services, personalising user experiences, and managing customer interactions.  

Any use of automated decision-making will comply with applicable data protection laws and will include appropriate safeguards to protect your rights and freedoms. Where required, this includes the availability of human review or intervention. 

We will only use automated processing where it is necessary, lawful, and fair. We are committed to transparency and will inform you where such processing is used, particularly where decisions may have a legal or similarly significant effect on you. 

14. Use of Artificial Intelligence (AI) 

Aptem may use Artificial Intelligence (AI) tools in a limited and proportionate manner to support our business operations, including enhancing customer service, improving website functionality, and increasing administrative efficiency. 

AI tools are used to support, and not replace, human decision-making. Appropriate human oversight is applied, and outputs generated by AI are reviewed where necessary to ensure accuracy, relevance, and fairness. 

Where AI involves the processing of personal data, we ensure there is a valid lawful basis and that appropriate safeguards are implemented. These safeguards include measures to: 

  • minimise the amount of personal data processed; 

  • monitor and mitigate risks of bias or inaccuracy; 

  • ensure data quality and relevance; 

  • protect individuals’ rights and freedoms; 

  • ensure personal data is not used to train AI models; 

  • apply appropriate data retention controls, ensuring that personal data processed by AI tools is retained only for as long as necessary and in line with our data retention policies. 

We also seek to ensure that any third-party AI providers we use process personal data in accordance with our instructions and applicable data protection laws, including implementing appropriate technical and organisational measures to safeguard such data. 

We also conduct risk assessments, including data protection impact assessments where required, to evaluate and address any potential risks associated with the use of AI technologies. 

We remain committed to using AI responsibly and in line with applicable legal and regulatory requirements, including data protection laws and recognised best practices. 

Further information on how Aptem uses and implements AI is available in the Aptem AI Use and Governance Charter, which is available to customers and prospects through our Trust Centre. 

15. UK cookies law 

We use cookies and similar technologies on our marketing website to support core functionality, understand how visitors use our site, and improve user experience. Our use of cookies complies with the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR). 

Types of cookies we use 

  • Strictly necessary cookies – required for the website to function (e.g. security, load balancing, session management). These do not require consent.  

  • Analytics and performance cookies – help us understand how visitors interact with our site, such as pages visited, time spent, and navigation behaviour, so we can improve performance and usability.  

  • Third-party cookies – set by services we use to support the website, listed below. 

Cookie Purpose Type
Google Analytics Understand how visitors use and navigate the website Analytics
Hotjar Understand visitor behaviour and improve usability Analytics
LinkedIn Analytics Track interactions between LinkedIn page and website Analytics/Marketing
Vimeo Capture views of video content Functional

Managing cookies 

Where cookies are not strictly necessary, they are only set with your consent. You can manage or withdraw your consent at any time using the Manage Cookies link at the bottom of our website, or through your browser settings.  More general information on cookies is available at https://www.aboutcookies.org/. 

We regularly review our use of cookies to ensure ongoing compliance with data protection requirements and best practice. 

16. Aptem Trust Centre 

As part of our ongoing commitment to data privacy and information security, the Aptem Trust Centre provides customers with access to resources that support audits, compliance assessments, and security-related enquiries. The Trust Centre is available at https://trust.aptem.co.uk/. 

17. How to raise a question 

If you have any questions, comments, or requests regarding this notice or our use of your personal data, you may contact us at any time. We will respond in accordance with applicable data protection legislation, including the UK GDPR, the Data Protection Act 2018, and the Data Use and Access Act 2025. 

Please contact us by email at dpo@aptem.co.uk or write to us at the address below: 

Data Protection Officer 
Aptem Ltd 
Eagle House 
167 City Road 
London 
EC1V 1NR 

United Kingdom 

18. How to raise a complaint 

If you are dissatisfied with how we handle your personal data, you have the right to raise a data protection complaint directly with us. We will consider and respond to all complaints in accordance with our data protection obligations. 

When you raise a complaint with us, we will: 

  • Acknowledge receipt of your complaint within 2 working days 

  • Respond within 10 working days once all information is received  

  • Escalate to the COO if you are unsatisfied, acknowledged within 10 working days, responded to within 15 working days 

  • Investigate your complaint appropriately, taking into account its nature and circumstances 

  • Keep you informed of progress where the investigation takes time to resolve 

  • Respond to you in plain, accessible language, without undue delay, including confirming the outcome and any action taken 

You can contact us by email at complaints@aptem.co.uk or write to us at the address below: 

Data Protection Officer 
Aptem Ltd 
Eagle House 
167 City Road 
London 
EC1V 1NR 

United Kingdom 

You also have the right to lodge a complaint with the UK’s supervisory authority for data protection issues, the Information Commissioner’s Office (ICO), whether or not you have raised it with us first. Further information is available at: https://www.ico.org.uk 

19. Changes to this Privacy Policy 

This Privacy Policy is reviewed on a regular basis and may be updated from time to time to reflect changes in legal, regulatory, or operational requirements, as well as updates to our services or data processing activities. 

Any changes will be published on this page, and where appropriate, we will take reasonable steps to notify you of significant updates. 

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Last reviewed: 21 August 2026.