Privacy policy

How Appright Ltd collects, uses and protects personal data.

Last updated 26 September 2026

Trading name: Appright
Legal entity: Appright Ltd (APPRIGHT LTD)
Company number: 17477022
Registered office: 405 Ford Green Road, Stoke-On-Trent, England, ST6 8LX
Governing law: England and Wales

1. Who we are

Appright (“Appright”, “we”, “us”, “our”) provides business-to-business software for UK trade and field-service businesses (bespoke apps for each customer), together with an internal app for Appright staff and a public marketing website.

We trade as Appright. The legal entity is Appright Ltd / APPRIGHT LTD (company number 17477022), registered in England and Wales.

Privacy contact: hello@appright.co.uk

Formal notices: 405 Ford Green Road, Stoke-On-Trent, England, ST6 8LX (registered office; company number 17477022).

2. Scope of this policy

This policy covers personal data processed in connection with:

SurfaceDescription
Marketing websitePublic pages (e.g. Home, Services, About, Contact/enquiry) and related lead/enquiry handling
Internal staff appAppright’s own internal app for running the business (Appright staff only; customers do not log in)
Customer appsThe apps we build and run for our customers’ businesses
Client websitesWebsites we build and run for our clients, including their enquiry forms
Artificial intelligence (AI) marketing serviceMarketing we plan, draft and publish for clients on their connected social media and advertising accounts, and the enquiry forms and tools (for example, a postcode checker) we build for them

It does not cover special-category data or children’s data. Appright’s products are intended for business-to-business use.

How we handle personal data in our artificial intelligence (AI) marketing service is explained in sections 3, 4.3, 5.1, 6, 8 and 10.

3. Controller and processor

Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, our role depends on the data:

DataRole
Marketing site leads / enquiriesAppright is the controller
Staff accounts in our internal app and related internal recordsAppright is the controller
Appright’s own account, login, billing-contact and platform administration recordsAppright is the controller
Operational data in customer apps (jobs, sites, contacts, timesheets, photos, BACS/invoicing details held for the customer, and similar Customer Data)The customer is the controller; Appright is the processor (acting on the customer’s documented instructions, typically under customer terms and a data processing agreement)
Websites we build and run for clients, including enquiries submitted through their formsThe client is the controller; Appright is the processor (acting on the client’s instructions)
AI marketing service: content and adverts we draft and publish on a client’s connected social media and advertising accounts, and enquiries collected through the client’s forms and toolsThe client is the controller; Appright is the processor (acting on the client’s instructions)

Ownership. Each customer owns its Customer Data. Appright owns the software, apps, websites and tools we build and run (the product), and provides them to customers under our customer terms. When a customer leaves, we provide an export of their data on request (see section 8).

Where Appright acts as processor, this policy summarises our approach for transparency; the customer’s own privacy notice and our Data Processing Agreement (DPA) govern that processing.

4. What we collect

4.1 Data we may process as controller

Depending on how you interact with us, this may include:

  • Enquiry / lead data from the website contact form (e.g. name, business name, email, telephone, message content)
  • Account and login data for Appright staff and (where applicable) customer administrators (e.g. name, email, sign-in details, whether extra sign-in security is set up)
  • Billing / commercial contact details for Appright’s relationship with the customer business
  • Communications with us (email, phone notes) relating to sales, onboarding or support
  • Limited technical / security logs (e.g. login events, IP address, device/browser information) for security and service integrity

4.2 Data we may process as processor (Customer Data)

When a customer uses one of their apps, they (or their authorised users) may submit ordinary business operational data such as:

  • Business contact details (customers, sites, key contacts)
  • Job / site / schedule data
  • Timesheets and related workforce operational records
  • Photos and uploaded files (e.g. job photos, receipts where features are enabled)
  • BACS or other bank details used for customer invoicing (held for the customer’s business purposes)

We do not hold payment card data.

We do not intentionally collect special-category personal data or children’s data through these products. Customers must not upload such data unless a documented lawful basis and DPA cover exist.

4.3 Data collected through the AI marketing service (on behalf of clients)

When we run marketing for a client, the enquiry forms and tools we build for them (for example, a postcode checker) may collect:

  • Names and contact details (such as email address and telephone number)
  • Postcode or area, and the details of the enquiry
  • Whether the person has agreed to receive marketing emails or text messages
  • Basic information about which campaign or advert led to the enquiry

We collect this for the client, who is the controller. The client’s own privacy notice also applies.

We do not use personal data to decide who sees our clients’ adverts. Where we target by location, we use area-level open data (for example, published statistics for postcode areas), which does not identify individuals.

5. Purposes and lawful bases

PurposeLawful basis
Respond to website enquiries / leads; pursue business sales conversationsLegitimate interests (growing and managing our business) and/or steps prior to entering a contract
Provide and administer the Services under a customer contract (including onboarding, support and invoicing of the customer)Performance of a contract
Operate staff accounts in our internal app; secure sign-in (passkeys / authenticator apps)Legitimate interests (running and securing our business) and/or contract with staff/contractors as applicable
Process Customer Data in customer apps on the customer’s instructionsAs processor: processing necessary to perform the customer contract / documented instructions; the customer is responsible for its own lawful basis as controller
Security, fraud prevention, abuse detection, backupsLegitimate interests (protecting systems, customers and Appright)
Legal / regulatory compliance (e.g. tax, responding to lawful requests)Legal obligation and/or legitimate interests
Marketing to business contacts (if any beyond transactional messages)Legitimate interests and/or consent where required

Where we rely on legitimate interests, we balance those interests against individuals’ rights.

5.1 AI marketing service

When we collect enquiries through a client’s forms and tools, we do so on the client’s behalf. The lawful bases we expect to apply are:

  • Marketing emails and text messages: consent. We only send them to people who have opted in, and every message explains how to opt out.
  • Following up an enquiry the person made (for example, replying to a request for a quote or a visit): legitimate interests.

Nothing is published on a client’s social media or advertising accounts until the client has approved it.

6. Sharing and sub-processors

We do not sell personal data.

We may share personal data with:

  • Directors and authorised Appright staff who need it to operate the business
  • Sub-processors that host or support the Services (see below)
  • Professional advisers (e.g. solicitor, accountant, insurer/broker) under confidentiality
  • Authorities where required by law

Sub-processors and infrastructure

Type of providerRoleStatus
Cloud hosting and database providersHosting our apps and websites, databases, storage for photos and files, and secure connectionsLive; may involve processing outside the UK
Artificial intelligence (AI) service providers (such as large language model providers)Artificial intelligence (AI) features where enabled, such as reading receipts, filling in job sheets, and drafting quotes, invoices and reports (the images, notes and job details needed for the feature, and the extracted fields)Live where the feature is used; may involve processing outside the UK
Source code hosting providerStoring our source code and running automated checks only; not used to store customer dataCode only
Social media publishing provider (such as a social media scheduling service)Publishing approved posts and adverts to a client’s connected social media accounts, and reading basic performance figuresUsed only where we provide the AI marketing service

Passkey providers (the companies behind the sign-in on your phone or computer) are part of the user’s own device sign-in setup, not Appright sub-processors of Customer Data in the ordinary sense.

Our sub-processors process personal data under written contracts, with appropriate safeguards in place, including for any transfer of personal data outside the UK. A current list of sub-processors is available on request from hello@appright.co.uk, and is also maintained as described in the customer DPA.

Advertising platforms and conversion tracking

When we run adverts for a client on advertising platforms (such as Meta, Google or LinkedIn), the platform decides which individuals see each advert. The platforms do this under their own privacy policies, and we do not give them personal data to choose who sees an advert.

Where the client chooses to turn it on, conversion tracking passes enquiry events (for example, that a form was submitted after someone saw an advert) back to the advertising platform, so the client can see which adverts work. The platform handles that information under its own privacy policy.

7. International transfers

Some of our cloud hosting and artificial intelligence (AI) service providers may process personal data outside the UK. Where that happens, we make sure appropriate safeguards are in place, such as UK-approved contract terms or an adequacy decision, as required by UK data protection law.

We plan to move production hosting to the European Union (EU) once migration is complete. Until then, we do not claim UK-only or EU-only data residency.

8. Retention

We keep personal data only as long as needed for the purposes above, subject to legal and contractual requirements.

CategoryRetention approach
Marketing leads / enquiriesRetained while actively pursuing the enquiry or as needed for records; then deleted or anonymised
Enquiries collected through the AI marketing serviceKept for the period agreed with the client (the controller), then deleted or returned to the client
Staff / account / login recordsFor the life of the account relationship, plus a period after closure for security and audit
Customer Data (processor)Per the customer contract / DPA: generally for the term of the Services, then returned or deleted within agreed windows

Client offboarding and deletion

When a client leaves, we archive their app, disable logins, provide an export on request, and delete data after the applicable retention period.

Audit logs (signatures and logins)

Appright retains audit logs of signatures and logins (who, when, IP address and device, document hash and version).

9. Security

We apply technical and organisational measures appropriate to business software provided as an online service, including:

  • TLS / HTTPS in transit (including HSTS where configured)
  • Provider encryption at rest on database and object storage (as offered by the hosting/storage provider)
  • Passwords hashed (scrypt)
  • Authenticator app secrets encrypted (AES-256-GCM, a strong industry-standard method)
  • Appright staff: passkeys required to sign in, with an authenticator app as the fallback (no text-message, email-code or push-only sign-in checks). Customer app users: extra sign-in security is optional (recommended), with passkeys and authenticator apps offered.

We do not claim bring-your-own-key (BYOK) encryption; field-level encryption of photos, BACS details or other ordinary personal data; or that extra sign-in security equals encryption of Customer Data at rest.

Access to our internal app is limited to authorised Appright staff. Customers remain responsible for managing their own app users and their sign-in security, as supported by the product.

10. Your rights (UK GDPR)

Depending on your circumstances and our role (controller or processor), you may have rights to:

  • Access your personal data
  • Rectification of inaccurate data
  • Erasure (“right to be forgotten”) in certain cases
  • Restriction of processing in certain cases
  • Data portability in certain cases
  • Object to processing based on legitimate interests (and to direct marketing)
  • Withdraw consent where processing is based on consent
  • Complain to the Information Commissioner’s Office (ICO) — ico.org.uk

Marketing: you can opt out of marketing emails or text messages at any time, using the link or instructions in the message or by contacting us. You also have the right to object to direct marketing at any time, and we (or our client) will stop.

Where Appright is the processor, please contact the relevant customer (the controller) in the first instance for rights requests about operational data in their app; we will assist the customer as required by the DPA.

To exercise your rights where Appright is the controller, contact us at hello@appright.co.uk. We may need to verify your identity.

11. Cookies (website)

The marketing website may use cookies or similar technologies as needed for basic operation and, if introduced later, analytics or preferences. Essential cookies may be required for the site to function. Non-essential cookies (if any) will be described here and, where required, controlled via a consent mechanism.

12. Children’s data

Our Services and website are aimed at businesses and business contacts. We do not knowingly target or collect personal data from children.

13. Changes to this policy

We may update this privacy policy from time to time. The “last updated” date at the top will be revised. Material changes affecting customers will be communicated as appropriate (e.g. notice in-app, email to administrators, or an updated website posting).

14. Contact

Privacy questions and rights requests: hello@appright.co.uk

Formal written notices: Appright Ltd, 405 Ford Green Road, Stoke-On-Trent, England, ST6 8LX (registered office; company number 17477022).

15. Governing law

This privacy policy is governed by the laws of England and Wales. Disputes relating to it will be subject to the exclusive jurisdiction of the courts of England and Wales, subject to any mandatory rights that cannot be excluded.