Legal
Privacy policy
How Appright Ltd collects, uses and protects personal data.
Last updated 26 September 2026
1. Who we are
Appright (“Appright”, “we”, “us”, “our”) provides business-to-business software for UK trade and field-service businesses (bespoke apps for each customer), together with an internal app for Appright staff and a public marketing website.
We trade as Appright. The legal entity is Appright Ltd / APPRIGHT LTD (company number 17477022), registered in England and Wales.
Privacy contact: hello@appright.co.uk
Formal notices: 405 Ford Green Road, Stoke-On-Trent, England, ST6 8LX (registered office; company number 17477022).
2. Scope of this policy
This policy covers personal data processed in connection with:
| Surface | Description |
|---|---|
| Marketing website | Public pages (e.g. Home, Services, About, Contact/enquiry) and related lead/enquiry handling |
| Internal staff app | Appright’s own internal app for running the business (Appright staff only; customers do not log in) |
| Customer apps | The apps we build and run for our customers’ businesses |
| Client websites | Websites we build and run for our clients, including their enquiry forms |
| Artificial intelligence (AI) marketing service | Marketing we plan, draft and publish for clients on their connected social media and advertising accounts, and the enquiry forms and tools (for example, a postcode checker) we build for them |
It does not cover special-category data or children’s data. Appright’s products are intended for business-to-business use.
How we handle personal data in our artificial intelligence (AI) marketing service is explained in sections 3, 4.3, 5.1, 6, 8 and 10.
3. Controller and processor
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, our role depends on the data:
| Data | Role |
|---|---|
| Marketing site leads / enquiries | Appright is the controller |
| Staff accounts in our internal app and related internal records | Appright is the controller |
| Appright’s own account, login, billing-contact and platform administration records | Appright is the controller |
| Operational data in customer apps (jobs, sites, contacts, timesheets, photos, BACS/invoicing details held for the customer, and similar Customer Data) | The customer is the controller; Appright is the processor (acting on the customer’s documented instructions, typically under customer terms and a data processing agreement) |
| Websites we build and run for clients, including enquiries submitted through their forms | The client is the controller; Appright is the processor (acting on the client’s instructions) |
| AI marketing service: content and adverts we draft and publish on a client’s connected social media and advertising accounts, and enquiries collected through the client’s forms and tools | The client is the controller; Appright is the processor (acting on the client’s instructions) |
Ownership. Each customer owns its Customer Data. Appright owns the software, apps, websites and tools we build and run (the product), and provides them to customers under our customer terms. When a customer leaves, we provide an export of their data on request (see section 8).
Where Appright acts as processor, this policy summarises our approach for transparency; the customer’s own privacy notice and our Data Processing Agreement (DPA) govern that processing.
4. What we collect
4.1 Data we may process as controller
Depending on how you interact with us, this may include:
- Enquiry / lead data from the website contact form (e.g. name, business name, email, telephone, message content)
- Account and login data for Appright staff and (where applicable) customer administrators (e.g. name, email, sign-in details, whether extra sign-in security is set up)
- Billing / commercial contact details for Appright’s relationship with the customer business
- Communications with us (email, phone notes) relating to sales, onboarding or support
- Limited technical / security logs (e.g. login events, IP address, device/browser information) for security and service integrity
4.2 Data we may process as processor (Customer Data)
When a customer uses one of their apps, they (or their authorised users) may submit ordinary business operational data such as:
- Business contact details (customers, sites, key contacts)
- Job / site / schedule data
- Timesheets and related workforce operational records
- Photos and uploaded files (e.g. job photos, receipts where features are enabled)
- BACS or other bank details used for customer invoicing (held for the customer’s business purposes)
We do not hold payment card data.
We do not intentionally collect special-category personal data or children’s data through these products. Customers must not upload such data unless a documented lawful basis and DPA cover exist.
4.3 Data collected through the AI marketing service (on behalf of clients)
When we run marketing for a client, the enquiry forms and tools we build for them (for example, a postcode checker) may collect:
- Names and contact details (such as email address and telephone number)
- Postcode or area, and the details of the enquiry
- Whether the person has agreed to receive marketing emails or text messages
- Basic information about which campaign or advert led to the enquiry
We collect this for the client, who is the controller. The client’s own privacy notice also applies.
We do not use personal data to decide who sees our clients’ adverts. Where we target by location, we use area-level open data (for example, published statistics for postcode areas), which does not identify individuals.
5. Purposes and lawful bases
| Purpose | Lawful basis |
|---|---|
| Respond to website enquiries / leads; pursue business sales conversations | Legitimate interests (growing and managing our business) and/or steps prior to entering a contract |
| Provide and administer the Services under a customer contract (including onboarding, support and invoicing of the customer) | Performance of a contract |
| Operate staff accounts in our internal app; secure sign-in (passkeys / authenticator apps) | Legitimate interests (running and securing our business) and/or contract with staff/contractors as applicable |
| Process Customer Data in customer apps on the customer’s instructions | As processor: processing necessary to perform the customer contract / documented instructions; the customer is responsible for its own lawful basis as controller |
| Security, fraud prevention, abuse detection, backups | Legitimate interests (protecting systems, customers and Appright) |
| Legal / regulatory compliance (e.g. tax, responding to lawful requests) | Legal obligation and/or legitimate interests |
| Marketing to business contacts (if any beyond transactional messages) | Legitimate interests and/or consent where required |
Where we rely on legitimate interests, we balance those interests against individuals’ rights.
5.1 AI marketing service
When we collect enquiries through a client’s forms and tools, we do so on the client’s behalf. The lawful bases we expect to apply are:
- Marketing emails and text messages: consent. We only send them to people who have opted in, and every message explains how to opt out.
- Following up an enquiry the person made (for example, replying to a request for a quote or a visit): legitimate interests.
Nothing is published on a client’s social media or advertising accounts until the client has approved it.
6. Sharing and sub-processors
We do not sell personal data.
We may share personal data with:
- Directors and authorised Appright staff who need it to operate the business
- Sub-processors that host or support the Services (see below)
- Professional advisers (e.g. solicitor, accountant, insurer/broker) under confidentiality
- Authorities where required by law
Sub-processors and infrastructure
| Type of provider | Role | Status |
|---|---|---|
| Cloud hosting and database providers | Hosting our apps and websites, databases, storage for photos and files, and secure connections | Live; may involve processing outside the UK |
| Artificial intelligence (AI) service providers (such as large language model providers) | Artificial intelligence (AI) features where enabled, such as reading receipts, filling in job sheets, and drafting quotes, invoices and reports (the images, notes and job details needed for the feature, and the extracted fields) | Live where the feature is used; may involve processing outside the UK |
| Source code hosting provider | Storing our source code and running automated checks only; not used to store customer data | Code only |
| Social media publishing provider (such as a social media scheduling service) | Publishing approved posts and adverts to a client’s connected social media accounts, and reading basic performance figures | Used only where we provide the AI marketing service |
Passkey providers (the companies behind the sign-in on your phone or computer) are part of the user’s own device sign-in setup, not Appright sub-processors of Customer Data in the ordinary sense.
Our sub-processors process personal data under written contracts, with appropriate safeguards in place, including for any transfer of personal data outside the UK. A current list of sub-processors is available on request from hello@appright.co.uk, and is also maintained as described in the customer DPA.
Advertising platforms and conversion tracking
When we run adverts for a client on advertising platforms (such as Meta, Google or LinkedIn), the platform decides which individuals see each advert. The platforms do this under their own privacy policies, and we do not give them personal data to choose who sees an advert.
Where the client chooses to turn it on, conversion tracking passes enquiry events (for example, that a form was submitted after someone saw an advert) back to the advertising platform, so the client can see which adverts work. The platform handles that information under its own privacy policy.
7. International transfers
Some of our cloud hosting and artificial intelligence (AI) service providers may process personal data outside the UK. Where that happens, we make sure appropriate safeguards are in place, such as UK-approved contract terms or an adequacy decision, as required by UK data protection law.
We plan to move production hosting to the European Union (EU) once migration is complete. Until then, we do not claim UK-only or EU-only data residency.
8. Retention
We keep personal data only as long as needed for the purposes above, subject to legal and contractual requirements.
| Category | Retention approach |
|---|---|
| Marketing leads / enquiries | Retained while actively pursuing the enquiry or as needed for records; then deleted or anonymised |
| Enquiries collected through the AI marketing service | Kept for the period agreed with the client (the controller), then deleted or returned to the client |
| Staff / account / login records | For the life of the account relationship, plus a period after closure for security and audit |
| Customer Data (processor) | Per the customer contract / DPA: generally for the term of the Services, then returned or deleted within agreed windows |
Client offboarding and deletion
When a client leaves, we archive their app, disable logins, provide an export on request, and delete data after the applicable retention period.
Audit logs (signatures and logins)
Appright retains audit logs of signatures and logins (who, when, IP address and device, document hash and version).
9. Security
We apply technical and organisational measures appropriate to business software provided as an online service, including:
- TLS / HTTPS in transit (including HSTS where configured)
- Provider encryption at rest on database and object storage (as offered by the hosting/storage provider)
- Passwords hashed (scrypt)
- Authenticator app secrets encrypted (AES-256-GCM, a strong industry-standard method)
- Appright staff: passkeys required to sign in, with an authenticator app as the fallback (no text-message, email-code or push-only sign-in checks). Customer app users: extra sign-in security is optional (recommended), with passkeys and authenticator apps offered.
We do not claim bring-your-own-key (BYOK) encryption; field-level encryption of photos, BACS details or other ordinary personal data; or that extra sign-in security equals encryption of Customer Data at rest.
Access to our internal app is limited to authorised Appright staff. Customers remain responsible for managing their own app users and their sign-in security, as supported by the product.
10. Your rights (UK GDPR)
Depending on your circumstances and our role (controller or processor), you may have rights to:
- Access your personal data
- Rectification of inaccurate data
- Erasure (“right to be forgotten”) in certain cases
- Restriction of processing in certain cases
- Data portability in certain cases
- Object to processing based on legitimate interests (and to direct marketing)
- Withdraw consent where processing is based on consent
- Complain to the Information Commissioner’s Office (ICO) — ico.org.uk
Marketing: you can opt out of marketing emails or text messages at any time, using the link or instructions in the message or by contacting us. You also have the right to object to direct marketing at any time, and we (or our client) will stop.
Where Appright is the processor, please contact the relevant customer (the controller) in the first instance for rights requests about operational data in their app; we will assist the customer as required by the DPA.
To exercise your rights where Appright is the controller, contact us at hello@appright.co.uk. We may need to verify your identity.
11. Cookies (website)
The marketing website may use cookies or similar technologies as needed for basic operation and, if introduced later, analytics or preferences. Essential cookies may be required for the site to function. Non-essential cookies (if any) will be described here and, where required, controlled via a consent mechanism.
12. Children’s data
Our Services and website are aimed at businesses and business contacts. We do not knowingly target or collect personal data from children.
13. Changes to this policy
We may update this privacy policy from time to time. The “last updated” date at the top will be revised. Material changes affecting customers will be communicated as appropriate (e.g. notice in-app, email to administrators, or an updated website posting).
14. Contact
Privacy questions and rights requests: hello@appright.co.uk
Formal written notices: Appright Ltd, 405 Ford Green Road, Stoke-On-Trent, England, ST6 8LX (registered office; company number 17477022).
15. Governing law
This privacy policy is governed by the laws of England and Wales. Disputes relating to it will be subject to the exclusive jurisdiction of the courts of England and Wales, subject to any mandatory rights that cannot be excluded.