Privacy & Data Protection Policy
Aposto Ltd — this version is dated September 2025.
1 Introduction
1.1 Important information and who we are
Welcome to Aposto Ltd’s Privacy and Data Protection Policy (“Privacy Policy”).
At Aposto Ltd (“we”, “us”, or “our”) we are committed to protecting and respecting your privacy and Personal Data (as defined below) in compliance with the United Kingdom General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and all other mandatory laws and regulations of the United Kingdom.
This Privacy Policy explains how we collect, process and keep your data safe when using our website and/or platform (“Platform”).
We will only use Personal Data in ways that are described in this policy and only ways that are consistent with our obligations and your rights under applicable data protection laws.
By using our website, Platform and any other services provided by us, you consent to the collection and use of data by us as set out in this Privacy Policy.
1.2 Who is your Data Controller and Data Protection Officer
Aposto Ltd is your Data Controller and responsible for your Personal Data.
We have appointed a data protection officer (“DPO”) who is responsible for overseeing questions in relation to this Privacy Policy. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights surrounding your Personal Data please contact the DPO using the details set out below:
- Full name: Catharine Long
- Email address: cathy@aposto.co.uk
- Postal address: C/O Digital House, Baltic Creative, 44 Simpson Street, Liverpool, L1 0AX
1.3 Personal Data we may collect and how we collect it
“Personal Data” means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
1.3.1 Personal Data you provide to us directly
Ways in which you might provide the data to us
This is personal data about you that you give us, which can happen in a wide variety of ways, including by:
- creating an account with us on our Platform;
- uploading information (such as your photo) to our Platform;
- sending us a message through our website or Platform;
- by completing an online form; or
- corresponding with us by e-mail, telephone, SMS or via our customer service tool on our Platform.
What type of data might be included?
The personal data you give us may include but is not limited to:
- your name;
- postal address;
- e-mail address;
- phone number (including mobile number);
- gender (and preferred salutation);
- date of birth;
- your bank details (where necessary for making payments); and
- your image (including photograph and facial recognition, where applicable).
If you are one of our wholesale clients or suppliers, we will process your business contact details and your job role.
We will only ever ask you to give us personal data which we need in order to provide you with the products or services that you have requested from us.
1.3.2 Personal Data we collect or generate about you
When you visit our website, use our Platform or get in touch with us we may collect, generate, store and use certain personal data about you. In some cases we will use cookies to do this, for further information about the cookies we use and how to opt out of such cookies please see our Cookie Policy.
This personal data may include:
- technical information, including: the Internet protocol (IP) address used to connect your computer to the Internet; your login information (if accessing an account with us); browser type and version; time zone setting; browser plug-in types and versions; device types; operating system; time and date of consent and platform; and any phone number used to call our customer service number.
- information about your visit to our website or Platform, including: the full Uniform Resource Locators (URL); clickstream to, through and from our website or Platform (including date and time); products you viewed, searched for or purchased; page response times; download errors; length of visits to certain pages; page interaction information (such as scrolling, clicks, and mouse-overs); and methods used to browse our website or Platform.
We also collect, use and share aggregated data such as module and briefing completion information (“Aggregated Data”) but we do not share this information with third parties. Aggregated Data could be derived from your Personal Data but is not considered Personal Data in law as this data will not directly or indirectly reveal your identity. However, if we combine or connect Aggregated Data with your Personal Data so that it can directly or indirectly identify you, we treat the combined data as Personal Data which will be used in accordance with this Privacy Policy.
We may also aggregate data to enable research or analysis so that we can better understand and serve you and others. For example, we may conduct research on your demographics and usage. Although this aggregated data may be based in part on Personal Data, it does not identify you personally. We may share this type of anonymous data with others, including service providers, our affiliates, agents and current and prospective business partners.
1.3.3 Personal Data captured through facial recognition data
When you attend an event at which we are operating and a facial recognition company is operating, we may also collect any facial recognition data which is captured during your time at the relevant event. We will only process this Personal Data for the purposes of the safety and security of individuals at the event, as detailed below.
1.3.4 Personal Data we receive from other sources
We may also receive Personal Data from other sources, for example from employers (e.g. our clients) of individuals who are signed up to our Platform, or from event hosts or host venues.
2 Legal basis for data collection
There are a number of justifiable reasons under the GDPR that allow collection and processing of Personal Data. The main avenues we rely on are:
- “Consent”: Certain situations allow us to collect your Personal Data, such as when you tick a box that confirms you are happy to receive email newsletters from us, or ‘opt in’ to a service.
- “Contractual Obligations”: We may require certain information from you in order to fulfil our contractual obligations and provide you with the promised service.
- “Legal Compliance”: We’re required by law to collect and process certain types of data, such as fraudulent activity or other illegal actions.
- “Legitimate Interest”: We might need to collect certain information from you to be able to meet our legitimate interests – this covers aspects that can be reasonably expected as part of running our business, that will not have a material impact on your rights, freedom or interests. Examples could be your address, so that we know where to deliver something to, or your name, so that we have a record of who to contact moving forwards.
- “Public Task”: We might need to process Personal Data in order to ensure the safety and security of individuals at public events. Where we do so, we will endeavour to obtain consent for any such processing, however where it is not possible to do so, we will rely on the lawful basis of Public Task.
3 How we use your Personal Data
3.1 Our uses
We will only use your Personal Data when the law allows us to. Set out below is a table containing the different types of Personal Data we collect and the lawful basis for processing that data. Please refer to section 2 for more information on the lawful basis listed in the table below.
Examples provided in the table below are indicative in nature and the purposes for which we use your data may be broader than described but we will never process your data without a legal basis for doing so and it is for a related purpose. For further inquiries please contact our Data Protection Officer.
| Activity | Type of data | Legal justification | Lawful basis for processing data |
|---|---|---|---|
| When a user signs up | Profile / Identity Data | Contractual Obligations | We need to process this data so that we know who is using the service in order to give them appropriate access to the Platform. |
| To send the user information relating to our services | Contact Data | Contractual Obligations | We need to process this data so that we can give access to the Platform, assign events to them, and send them SMS notifications. |
| Assessing availability / suitability of staff in an area | Profile / Identity data, location data | Contractual Obligations, Consent | We need to process this data in order to be able to provide feedback, as part of our services, relating to the availability of staff at an event, and verifying that staff are correctly located in the relevant stadium. |
| Monitoring event attendees | Biometric data | Consent, Public Task, Legal Compliance | In certain scenarios we may utilise facial recognition software for the purposes of ensuring the safety and security of individuals at events. We may also be required to share this Personal Data with third parties where we have a legal obligation to do so (e.g. in a criminal investigation etc.). |
| Access control and event attendance tracking | Biometric data via third party provider, where applicable | Consent, Public Task | We may, from time to time, utilise technology which enables the use of facial recognition for the purposes of controlling access to certain events. Where we do so we will seek your consent unless such technology is being used for the purposes of safety and security at the event. |
| Administrative business purposes | Contact Data, Identity Data | Contractual Obligations, Legitimate Interest | We may need to process your Personal Data for reasons which extend beyond our contractual obligations with you, for example for our own internal administrative reasons. Where we do so we will rely on our legitimate interests for such processing. |
3.2 Change of purpose
We will only use your Personal Data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact our Data Protection Officer.
If we need to use your Personal Data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your Personal Data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
4 Your rights and how you are protected by us
4.1 What control do I have over Aposto Ltd’s use of my Personal Data?
You have the following rights in relation to your personal data:
- Right to access – you have the right to ask us for copies of your personal data;
- Right to rectification – you have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete;
- Right to erasure (“right to be forgotten”) – you have the right to ask us to erase your personal information in certain circumstances;
- Right to data portability – you have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances;
- Right to object to processing – you have the right to object to the processing of your personal information in certain circumstances; and
- Right to restriction of processing – you have the right to ask us to restrict the processing of your personal information in certain circumstances.
You can access information associated with your account by logging into your account that you created with us.
We maintain a structured process to fulfil all data subject requests - including rights to access, rectify, delete, and transfer personal data - without undue delay and at the latest within one calendar month of receipt. Upon receiving a request, dedicated personnel log the inquiry, verify the individual’s identity, and coordinate across systems to execute the action, pausing the statutory deadline until required verification is provided if necessary.
4.2 How does Aposto Ltd protect customers’ Personal Data?
We are concerned with keeping your data secure and protecting it from inappropriate disclosure. We implement a variety of security measures to ensure the security of your Personal Data on our systems, including SSL encryption for all communications. We utilise Google Firebase and their secure systems for storage. The security protocols established by Google are as follows:
All Firebase services have successfully completed the ISO 27001 and SOC 1, SOC 2, and SOC 3 evaluation process, and some have also completed the ISO 27017 and ISO 27018 certification process. Link: https://firebase.google.com/support/privacy/.
Any Personal Data collected by us is only accessible by a limited number of employees who have special access rights to such systems and are bound by obligations of confidentiality. If and when we use subcontractors to store your data, we will not relinquish control of your Personal Data or expose it to security risks that would not have arisen had the data remained in our possession. However, unfortunately no transmission of data over the internet is guaranteed to be completely secure. It may be possible for third parties not under the control of Aposto Ltd to intercept or access transmissions or private communications unlawfully. While we strive to protect your Personal Data, we cannot ensure or warrant the security of any Personal Data you transmit to us. Any such transmission is done at your own risk. If you believe that your interaction with us is no longer secure, please contact us.
Your account information will be protected by a password for your privacy and security. You need to prevent unauthorized access to your account and Personal Data by selecting and protecting your password appropriately and limiting access to your computer or device and by signing off after you have finished accessing your account.
5 Your data and third parties
5.1 Will we share your data with third parties?
We may share Personal Data with third parties including event hosts and event location stakeholders, where necessary. We will only share Personal Data with such third parties where we have a lawful basis to do so, this may include performance of a contract or legitimate interests.
We may also share Personal Data with interested parties in the event that Aposto Ltd anticipates a change in control or the acquisition of all or part of our business or assets or with interested parties in connection with the licensing of our technology.
If Aposto Ltd is sold or makes a sale or transfer, we may, in our sole discretion, transfer, sell or assign your Personal Data to a third party as part of or in connection with that transaction. Upon such transfer, the Privacy Policy of the acquiring entity may govern the further use of your Personal Data. In all other situations your data will still remain protected in accordance with this Privacy Policy (as amended from time to time).
We may share your Personal Data at any time if required for legal reasons or in order to enforce our terms or this Privacy Policy.
6 How long will we retain your data for?
We will only retain your Personal Data for as long as reasonably necessary to fulfil the purposes we collected it for. We may retain your Personal Data for a longer period than usual in order comply with any relevant legal obligation we are required to comply with, in the event of a complaint, or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
Personal Data which is no longer to be retained will be securely and effectively destroyed or permanently erased from our IT systems and we will also require third parties to destroy or erase such personal data where applicable.
In some circumstances we may anonymise your Personal Data so that it can no longer be associated with you. In this case, we may retain such information for a longer period without further notice to you.
7 Age limit for our users
You must not use Aposto Ltd unless you are aged 16 or older. If you are under 16 and you access Aposto Ltd by lying about your age, you must immediately stop using Aposto Ltd. Our software is not intended for children and we do not knowingly collect data relating to children.
8 International transfer of data
Your information may be stored and processed in the UK or other countries or jurisdictions outside the US where Aposto Ltd has facilities. In the event that your information is transferred outside of the UK, we will ensure that appropriate safeguards are implemented for the purposes of guaranteeing the protection of such information.
We are currently storing data in the EU and so, by using Aposto Ltd, you are permitting and consenting to the transfer of information, including Personal Data, outside of the UK.
9 Your right to complain
You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.
Information Commissioner’s OfficeWycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
ICO website: https://www.ico.org.uk
10 Notification of changes and acceptance of policy
We reserve the right to update or amend this privacy policy at any time, including where we intend to further process your personal data for a purpose other than that for which the personal data was collected or where we intend to process new types of personal data. We will place any updates here on this page.
11 Interpretation
All uses of the word “including” mean “including but not limited to” and the enumerated examples are not intended to in any way limit the term which they serve to illustrate. Any email addresses set out in this policy may be used solely for the purpose for which they are stated to be provided, and any unrelated correspondence will be ignored. Unless otherwise required by law, we reserve the right to not respond to emails, even if they relate to a legitimate subject matter for which we have provided an email address. As a matter of common sense, you are more likely to get a reply if your request or question is polite, reasonable and there is no relatively obvious other way to deal with or answer your concern or question (e.g. FAQs, other areas of our website etc.).
Our staff are not authorised to contract on behalf of Aposto Ltd, waive rights or make representations (whether contractual or otherwise). If anything contained in an email from a Aposto Ltd address contradicts anything in this policy, our terms or any official public announcement on our website, or is inconsistent with or amounts to a waiver of any Aposto Ltd rights, the email content will be read down to grant precedence to the latter. The only exception to this is genuine correspondence expressed to be from the Aposto Ltd legal department.
This version is dated September 2025.
