Skip to main content
ZAAPTO

United Kingdom GDPR and Data Protection Act 2018

Privacy notice

How ZAAPTO LTD handles personal data: on this website, in correspondence, during an engagement, and in any application the company publishes.

Effective 7 August 2026 Version 1.0 ZAAPTO LTD, company number 16938315

1. Who this notice is from

This notice is published by ZAAPTO LTD, a private company limited by shares, registered in England and Wales with company number 16938315, registered office 4 Wix Road, Basingstoke, England, RG24 9ZF. "ZAAPTO", "we" and "us" mean that company.

Every data protection matter, including a request to exercise a right, goes to contact@zaapto.uk, or by post to the registered office.

1.1 Data protection officer

ZAAPTO has not appointed a Data Protection Officer. Article 37 requires one only for a public authority, or where core activities involve large scale monitoring or large scale processing of special category or criminal offence data, none of which applies here. Responsibility sits with the company's officers.

1.2 Registration with the ICO

[TO CONFIRM: whether ZAAPTO LTD must pay the ICO data protection fee under the Data Protection (Charges and Information) Regulations 2018 and, if so, the registration number] No number is stated until one exists. Your rights apply either way.

1.3 Representatives

ZAAPTO LTD is a United Kingdom company, so no Article 27 UK representative is required. [TO CONFIRM: whether an EU representative is required under Article 27 of the EU GDPR]

2. Controller and processor

The law separates the organisation that decides why and how personal data is processed, the controller, from the one that processes it on those instructions, the processor. ZAAPTO is both, for different data, and this notice keeps them apart because your route to enforce a right differs.

2.1 Where ZAAPTO is the controller

For data it collects for its own purposes: website visitors, people who write to the enquiry address, contacts at a client or supplier, and the records the company must keep to run itself. ZAAPTO sets the purpose, the lawful basis and the retention period, and answers requests directly.

2.2 Where ZAAPTO is the processor

During an engagement, ZAAPTO builds software inside a client's own systems, where the personal data belongs to the client's world: their staff, the people they sell to, their suppliers. The client decides why it exists and ZAAPTO acts only on documented instructions.

If your data sits in a client's system, contact that client to exercise a right. If you contact us, we say promptly that we are the processor, pass the request to the controller where we can identify them, and tell you so.

2.3 Written terms

Where ZAAPTO acts as processor, a written agreement carrying the terms required by Article 28(3) is in place before processing begins: subject matter and duration, categories of data and data subjects, confidentiality, Article 32 security, sub-processor approval, assistance with rights, deletion or return at the end, and the client's right to audit.

3. What this notice covers

The website at zaapto.uk, email correspondence with ZAAPTO, the administration of engagements, and any application ZAAPTO publishes on the Apple App Store, Google Play or an equivalent channel.

Position as at the effective date. ZAAPTO LTD has published no application on any store. Sections 22 and 23 are written in advance, so the position can be read before a download exists, and they bind any application the company publishes under its own name.

It does not cover other organisations' sites, or a client's systems, which their own notice governs.

4. Which role applies where

Every processing section carries a role marker, repeated here in one place.

Role that applies to each processing section
SectionSubject matterRole of ZAAPTOWho answers a rights request
5Website visitorsControllerZAAPTO LTD
6Enquiries and correspondenceControllerZAAPTO LTD
7Client and supplier recordsControllerZAAPTO LTD
8Work inside client systemsProcessorThe client, as controller
22, 23Applications published by ZAAPTOControllerZAAPTO LTD

Wide tables scroll sideways.

5. Website visitors

Role: controller

This site is a set of static files. No login, no account, no form, no analytics, no advertising code. What follows exists because a browser asked a server for a file.

Data inventory: website visitors
CategoryExample fieldsSourcePurposeLawful basisRetentionRecipients
Request and connection data IP address, timestamp, file requested, HTTP status, user agent, referring page, country derived from IP, bot score Your browser, automatically Delivering the page, keeping the site available, blocking attack and automated abuse Article 6(1)(f). Interest: keeping a published website available and defending the domain against attack, see section 9 The hosting provider's own log period, measured in days. ZAAPTO keeps no copy Cloudflare, Inc.
Font request data IP address, user agent, referring page, sent when your browser fetches the two typefaces Your browser, automatically Displaying the site in the typefaces it is set in Article 6(1)(f). Interest: presenting a legible published document, see section 9 Not retained by ZAAPTO. Google's own retention applies Google LLC, Google Ireland Limited

ZAAPTO keeps no server logs and profiles no visitor. A content blocker will stop your browser contacting Google for the typefaces, and the site stays readable in the faces on your device.

6. Enquiries and correspondence

Role: controller

Every contact action here opens your own email client addressed to contact@zaapto.uk. You send from your own email service and it arrives in a mailbox operated for ZAAPTO. No form, no capture script, no lead service.

Data inventory: enquiries and correspondence
CategoryExample fieldsSourcePurposeLawful basisRetentionRecipients
Identity and contact details Name, email address, organisation, job title, telephone if given You Knowing who is writing and replying to them Article 6(1)(f) for a general enquiry, interest: operating a correspondence address, section 9. Article 6(1)(b), steps at your request before a contract, once specific work is discussed 12 months from the last message, unless work follows Email hosting provider, section 12
Message content Your description of a process, systems in use, constraints, attachments You Understanding the request, deciding whether ZAAPTO can help, replying Article 6(1)(f) or 6(1)(b), as above 12 months from the last message Email hosting provider, section 12
Message metadata Headers, mail server records, timestamps, spam scoring Generated in transit Delivering mail and filtering unsolicited mail Article 6(1)(f). Interest: operating a working mailbox, see section 9 12 months from the last message Email hosting provider, section 12

6.1 Other people named in your message

If your message contains personal data about somebody else, ZAAPTO becomes its controller on receipt, on the same terms as the thread. Please keep it minimal: a role is usually enough.

6.2 What not to send

No credentials, passwords, API keys or tokens. No special category data. No extracts of records about other people. Real data and access are arranged in your own systems under a written agreement.

7. Client and supplier records

Role: controller

When an engagement proceeds, ZAAPTO keeps its own record of the contract and the money. The individuals are named contacts.

Data inventory: client and supplier administration
CategoryExample fieldsSourcePurposeLawful basisRetentionRecipients
Contract contacts Name, role, work email and telephone, signature on an engagement letter The organisation Agreeing, performing and evidencing a contract Article 6(1)(b) where the individual contracts personally, otherwise Article 6(1)(f), interest: administering a contract with an organisation, section 9 6 years from the end of the contract Accountant, advisers if a dispute arises
Billing and payment records Invoice, purchase order reference, amounts, dates, remittance details The organisation, and the bank Invoicing, collecting payment, bookkeeping, accounts and tax returns Article 6(1)(c), legal obligation, sections 386 and 388 Companies Act 2006 and Schedule 11 Value Added Tax Act 1994 where applicable. Article 6(1)(b) for taking payment 6 years from the end of the financial year Accountant, bank, HM Revenue and Customs on a lawful request
Engagement correspondence Email and notes on scope, changes, acceptance and handover Both parties Running the work and evidencing what was agreed Article 6(1)(b) and 6(1)(f). Interest: being able to bring or defend a claim in the limitation period, see section 9 6 years from the end of the contract Email hosting provider, advisers if a dispute arises
Access records Which account had access to which system, granted when, revoked when Created by ZAAPTO Controlling access and later evidencing it Article 6(1)(f). Interest: demonstrating that access was scoped and removed, see section 9 6 years from the end of the contract The client, on request

8. Work inside client systems

Role: processor

The work described elsewhere is software built inside systems the client owns. Where it reads, moves or writes personal data, ZAAPTO does so on the client's documented instructions.

Data inventory: processing carried out for a client
CategoryExample fieldsSourcePurposeLawful basisRetentionRecipients
Records handled by an automation Whatever the specification moves, for example a customer name, a job status, a document reference The client's systems Performing the function set out in the written specification Chosen by the client as controller. ZAAPTO selects no basis for this data Set by the client in its own systems Only the systems named in the specification
Diagnostic extracts A small sample of real records, where a fault cannot be reproduced with invented data The client, deliberately provided Diagnosing one specific defect Chosen by the client, on its documented instruction Deleted on closure of the defect, and within 30 days regardless Nobody outside ZAAPTO

8.1 Working copies

No client personal data leaves the client's systems by default. Where an extract is genuinely necessary it is requested in writing, kept to the smallest sample that answers the question, held where the client agrees, and deleted on closure, with a note in the access records in section 7.

8.2 Unlawful instructions

If an instruction appears to infringe data protection law, ZAAPTO says so in writing before acting, as Article 28(3) requires.

8.3 End of engagement

At the end, ZAAPTO deletes or returns personal data processed on the client's behalf, at the client's election. The client revokes ZAAPTO's access, and ZAAPTO confirms in writing when it believes all of it is gone.

9. Legitimate interests, named

Role: controller

Article 6(1)(f) requires the interest to be identified rather than gestured at. Each is balanced against the rights and freedoms of the people concerned.

Legitimate interests relied on, and the balancing
ProcessingThe interest, namedWhy it does not override your rights
Serving pages, and hosting layer logs Keeping a published website available and defending the domain against automated attack Limited to what a web request contains, no profiling, held for days
Serving typefaces from Google's font hosts Presenting a legible document consistently across devices No account and no identifier set here, and it is stated so you can block it
Reading and answering enquiry email Operating a correspondence address so a person who writes gets an answer It is what you chose to send, used only to reply, deleted after 12 months
Holding contract records for six years Bringing or defending a claim inside the limitation period in section 5 of the Limitation Act 1980 A fixed period, no other use, disclosed only to advisers in a dispute
Access grant and revocation records Showing a client or a regulator that access was scoped and later removed An account name and two dates, protecting the people whose data is in those systems
Writing to a company's named representative Administering a contract with an organisation, which happens through a person Work contact data in a work context

You may object at any time. Section 16.7 explains how.

10. Special category and criminal offence data

Role: controller in 10.1, processor in 10.2

10.1 As controller

ZAAPTO has no purpose requiring data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to identify a person, health, sex life or sexual orientation. No Article 9 condition and no Schedule 1 condition of the Data Protection Act 2018 is relied on, because no such data is processed for the company's own purposes.

If it arrives unsolicited in an email it is used for nothing and removed once noticed, unless removal would destroy a record we must keep. ZAAPTO processes no Article 10 criminal offence data and runs no records checks.

10.2 As processor

A client's systems may hold special category data. Where an engagement would touch it, three things apply without exception: the client states the data and its Article 9 condition, and its Schedule 1 condition where required, in the data processing agreement before work starts; the client holds the appropriate policy document required by paragraph 5 of Part 4 of Schedule 1 where its condition requires one; and the specification states where that data flows. If those cannot be stated, the work is declined.

11. Children

Role: controller

This site and the company's services are for businesses, not children. ZAAPTO does not knowingly collect personal data from anybody under 18. Any application it publishes will be age rated honestly and will not sit in a children's category unless built to the ICO's Age Appropriate Design Code. A child's data collected unintentionally is deleted.

12. Recipients and sub-processors

Role: controller for the company's own suppliers, processor where a sub-processor serves a client

Data here goes only to these recipients, for the purpose stated. ZAAPTO does not sell personal data, share it for anyone else's marketing, or use it to train a model.

Named recipients and processors
RecipientFunctionData reaching themRelationshipLocation
Cloudflare, Inc. Hosting and content delivery for zaapto.uk, and attack protection Request and connection data, section 5 Processor to ZAAPTO Global edge network, including outside the UK. See section 13
Google LLC and Google Ireland Limited Serving the two typefaces from fonts.googleapis.com and fonts.gstatic.com Your IP address and browser details, sent by your browser Independent controller of its own logs. ZAAPTO receives none of it United States and elsewhere. See section 13
Email hosting provider Receiving, storing and sending mail for zaapto.uk Everything in an enquiry or engagement email, with attachments and headers Processor to ZAAPTO [TO CONFIRM: the provider operating the zaapto.uk mailboxes, its legal entity and country of processing]
Accountant Bookkeeping, statutory accounts, tax filings Billing and payment records, section 7 Processor for bookkeeping, independent controller for its own professional duties [TO CONFIRM: the accounting firm engaged and its country of processing]
Banking provider Receiving and making payments Name, amount, payment reference Independent controller under its own regulatory duties [TO CONFIRM: the bank holding the ZAAPTO LTD business account]
Professional advisers Legal or accountancy advice, only if a dispute or regulatory matter arises Only records relevant to that matter Independent controllers, bound by professional confidentiality United Kingdom
Public authorities Disclosure required by law, to HM Revenue and Customs, a court or the Information Commissioner Only what the lawful request covers Recipients under a legal obligation, Article 6(1)(c) United Kingdom

12.1 Sub-processors during an engagement

As processor, ZAAPTO engages no sub-processor without the client's prior written authorisation under Article 28(2), and where that authorisation is general the client is told of any addition in advance and may object. Most engagements involve none.

13. International transfers

Role: controller, and processor where client data is involved

A restricted transfer is personal data sent outside the United Kingdom. Chapter V allows one only under a listed safeguard.

13.1 Adequacy

Transfers to countries covered by United Kingdom adequacy regulations, which include the European Economic Area, are made under Article 45, and need no further safeguard while those regulations stand.

13.2 The IDTA and the UK Addendum

Elsewhere, ZAAPTO relies on Article 46, using either the International Data Transfer Agreement issued by the Information Commissioner or the International Data Transfer Addendum to the European Commission's standard contractual clauses. Both are approved United Kingdom mechanisms.

13.3 Transfer risk assessment

Before relying on either, ZAAPTO assesses the destination's law and practice, the sensitivity of the data, and whether the safeguard would work. If it would not, the transfer is not made.

13.4 The transfers that actually occur

Restricted transfers and the safeguard for each
TransferDataDestinationSafeguard
Website delivery Request and connection data, section 5 Cloudflare's global network, which may serve a request from outside the UK Article 46, the Addendum to the EU standard contractual clauses in the provider's data processing terms, with a transfer risk assessment
Typeface delivery IP address and browser details, section 5 Google's font hosts, including servers in the United States Article 46 as operated by Google. Your browser makes the request, so ZAAPTO is not the exporter and states this row for completeness
Email hosting Correspondence, sections 6 and 7 [TO CONFIRM: country of processing for the zaapto.uk mailboxes] UK or EEA processing is preferred. Otherwise Article 46 with the IDTA or the Addendum, with a transfer risk assessment
Client engagements Client personal data Wherever the client's systems already are The client is the exporter and decides. ZAAPTO moves client data to a new country only on written instruction

A copy of any safeguard relied on can be requested, redacted where commercially confidential.

14. Retention

Role: controller

Data is kept only while there is a reason, and the reason is given, because a period without one is a guess.

Retention periods and the reason for each
RecordPeriodCounted fromReason
Hosting request logsThe provider's own period, days rather than monthsThe request They exist to detect attack and diagnose availability, both short lived questions. ZAAPTO keeps no copy
Enquiries that lead to no work12 monthsThe last message in the thread Long enough to answer a follow up, short enough that an abandoned idea does not sit indefinitely
Contracts and engagement correspondence6 yearsThe end of the contract The limitation period for a simple contract, section 5 of the Limitation Act 1980, so a claim can be brought or defended
Accounting records, invoices, payments6 yearsThe end of the financial year Statutory. Section 388 of the Companies Act 2006 requires accounting records to be preserved, HM Revenue and Customs requires company tax records for six years, and Schedule 11 to the Value Added Tax Act 1994 requires six years for VAT records if the company registers
Access grant and revocation records6 yearsThe end of the engagement Evidence of how the contract was performed, kept with it
Diagnostic extracts of client dataUntil the defect closes, 30 days at mostProvision of the extract It answers one question and has no purpose afterwards
Data protection requests and our responses3 yearsClosure of the request Accountability under Article 5(2), so we can show how a request was handled if the Information Commissioner asks
Personal data breach records6 yearsThe date of the record Article 33(5) requires a record of every breach with no fixed period. Six years aligns it with the limitation period
Suppression record after deletionIndefinite, minimalCompletion of the deletion So the deletion is honoured and can be evidenced. It holds the minimum needed for that, see section 23.4

At the end of a period records are deleted or, where a backup cannot be edited, put beyond use and deleted as it cycles. Anything restored is subject to the same periods.

15. Security, and what we do not claim

Role: controller and processor

Article 32 requires measures appropriate to the risk. These are applied: named accounts with multi factor authentication; access into a client system requested per system, scoped and revoked at the end; credentials in dedicated secret storage rather than documents or messages; no copying of personal data out of client systems except as section 8.1 allows; and a static website with no database to compromise.

What is not claimed. ZAAPTO LTD does not hold ISO 27001 certification, a SOC 2 report or Cyber Essentials certification, and will not represent otherwise. Nothing here is a third party attestation. These are commitments about how the company arranges its work, and a client is entitled to write them into the engagement contract, where they become enforceable.

16. Your rights

Role: controller. Where ZAAPTO is a processor, section 2.2 says who to contact

Every right below is exercised the same way: write to contact@zaapto.uk, or to the registered office. No particular wording is needed and there is no charge.

16.1 Timing

A request is answered without undue delay and within one month of receipt, as Article 12(3) requires, counted from the day after receipt or after identity is verified. Complex or repeated requests may be extended by up to two further months, and we tell you inside the first month that it applies and why.

16.2 Verifying who you are

Article 12(6) allows us to ask what is necessary to confirm identity where there is reasonable doubt. Writing from an address already in the correspondence is usually enough. If not, we ask for the minimum extra information and discard it once identity is settled. We will not ask for a passport to answer a question about an email thread.

16.3 Access, Article 15

You may ask whether we hold personal data about you and, if so, for a copy with the purposes, categories, recipients, retention period, the source if it was not you, and your other rights. Where a copy would reveal another person's data, that part is redacted unless they consent, as paragraph 16 of Schedule 2 to the Data Protection Act 2018 permits.

16.4 Rectification, Article 16

You may have inaccurate data corrected and incomplete data completed. Where the record is of something you told us, correction means adding the correct version rather than rewriting the original. Recipients in section 12 are told, unless that is impossible or disproportionate, as Article 19 requires.

16.5 Erasure, Article 17

You may ask for deletion where data is no longer necessary, where consent is withdrawn and no other basis applies, where you object with no overriding ground, or where processing was unlawful. It is not absolute: it does not apply where processing is necessary for a legal obligation, which is why accounting records stay until the statutory period ends, or for legal claims, which is why contract records run to the limitation period. Where a request cannot be granted in full we say which records are kept and under which exemption.

16.6 Restriction, Article 18

You may ask us to stop using data while a question about it is resolved, such as a challenge to its accuracy. It is then stored but not otherwise used, except with your consent or for legal claims, and we tell you before a restriction is lifted.

16.7 Objection, Article 21

You may object at any time to processing based on legitimate interests, all of which section 9 lists. We stop unless we can demonstrate compelling legitimate grounds overriding your rights and freedoms, or the processing is for legal claims. An objection to direct marketing is absolute and immediate, and ZAAPTO carries out none.

16.8 Portability, Article 20

Where automated processing is based on consent or a contract, you may ask for the data you provided in a structured, commonly used, machine readable format, and ask us to send it to another controller where feasible. Most data held here is correspondence under legitimate interests or a legal obligation, which falls outside this right.

16.9 Withdrawing consent, Article 7(3)

Where processing relies on consent you may withdraw it at any time, as easily as it was given, without affecting the lawfulness of what came before. Nothing in sections 5 to 8 relies on consent.

16.10 Automated decisions, Article 22

You have the right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects. ZAAPTO makes none, see section 19.

16.11 When a request can be refused

A request may be refused, or a reasonable fee charged, where it is manifestly unfounded or excessive under Article 12(5). It may be refused in part where an exemption in Schedule 2 to the Data Protection Act 2018 applies, such as legal professional privilege. Any refusal comes within one month, says which ground applies to which records, and tells you that you may complain to the Information Commissioner and seek a judicial remedy. Refusal is never silent.

17. Complaints and the ICO

Role: controller

If you are unhappy with how we have handled your data or your request, tell us first at contact@zaapto.uk, which is usually quicker. That is not a precondition and does not affect your right to complain.

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk/make-a-complaint

You also have the right to an effective judicial remedy under Articles 78 and 79, and to compensation under Article 82 for damage suffered through an infringement.

18. Personal data breaches

Role: controller in 18.2 and 18.3, processor in 18.4

A personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Losing access counts, not only somebody else gaining it. Report a suspected one to contact@zaapto.uk.

18.1 Detection and containment

On becoming aware of a suspected breach we contain it, establish what data and who is affected, and record the moment awareness began, because every later deadline runs from it.

18.2 Notifying the Information Commissioner, Article 33

Where ZAAPTO is controller and a breach is likely to result in a risk to people's rights and freedoms, it is reported to the Information Commissioner without undue delay and, where feasible, within 72 hours of becoming aware. A later report carries the reasons for the delay. Where a breach is judged unlikely to result in a risk it is not reported, and that reasoning is written down at the time. A report covers the nature of the breach, the categories and approximate numbers affected, the likely consequences, the measures taken and a contact point.

18.3 Notifying you, Article 34

Where a breach is likely to result in a high risk to your rights and freedoms you are told without undue delay, in plain language, with the nature of the breach, the likely consequences, the measures taken and a contact point. Notice is not required where the data was unintelligible to anyone unauthorised, where later measures removed the high risk, or where individual notice would take disproportionate effort, when a public communication is made instead.

18.4 Where ZAAPTO is the processor, Article 33(2)

Where a breach affects data processed on a client's behalf, ZAAPTO notifies that client without undue delay, with what they need for their own assessment and their own 72 hour deadline. Whether to notify the Information Commissioner or affected individuals is the client's decision as controller, and ZAAPTO assists under Article 28(3)(f).

18.5 The record, Article 33(5)

Every breach is recorded whether or not it is reportable, with the facts, its effects and the remedial action. Section 14 gives the retention period.

19. Automated decisions and profiling

Role: controller

ZAAPTO makes no decisions about individuals based solely on automated processing producing legal or similarly significant effects, and profiles nobody. Enquiries are read by a person, and nothing here scores or ranks a visitor.

Automations built for a client may apply rules to records. Whether a rule is a decision within Article 22 is a question for the client as controller, raised at the scope stage whenever a specification describes a rule deciding something about a person rather than a task.

20. Marketing and electronic communications

Role: controller

ZAAPTO operates no mailing list, sends no marketing email and makes no marketing calls. Writing to the enquiry address adds you to nothing, so there is nothing to unsubscribe from. Any message that looks like marketing from a zaapto.uk address should be reported to us.

If a mailing list is ever introduced it will run under the Privacy and Electronic Communications Regulations 2003: consent by positive action, the regulation 22(3) existing customer exception used only where it genuinely applies, a working unsubscribe in every message, and this section rewritten first.

21. Cookies and similar technologies

Role: controller

This site sets no analytics, advertising or personalisation cookies and stores nothing in local or session storage. The full position, including what the hosting platform may set and why no banner appears, is in the cookie statement.

Regulation 6 of the Privacy and Electronic Communications Regulations 2003 requires consent for storing or accessing information on a device, except where strictly necessary for a service the user requested. The cookie statement explains why that exception applies here.

22. Applications published by ZAAPTO

Role: controller

As at the effective date, ZAAPTO LTD has published no application on the Apple App Store, on Google Play or anywhere else. This section states the terms binding any application it publishes under its own name. [TO CONFIRM: name, platforms and store listing identifiers of the first application, once one exists]

22.1 The governing rule

An application published by ZAAPTO will not collect personal data unnecessary for a function the user asked for, and will say what a function needs as it asks.

22.2 Permissions

This is the complete set of device permissions any ZAAPTO application may request. One not listed will not be requested, and a future need changes this table before that release.

Permissions, purpose, consequence of declining, and how to revoke
PermissionPurposeRequired or optionalIf you declineRevoke on iOSRevoke on Android
Notifications Telling you a job you started has finished or failed Optional Everything works. You check status in the application instead Settings, Notifications, the application, turn off Allow Notifications Settings, Apps, the application, Notifications, turn off
Camera Capturing a document or a code when you choose that instead of picking a file Optional Capture is unavailable. You can still attach an existing file Settings, Privacy and Security, Camera, off for the application Settings, Apps, the application, Permissions, Camera, Do not allow
Photos and files Attaching a file you select to the record you are working on Optional No attachments from the device. Every other function is unaffected Settings, Privacy and Security, Photos, None or Limited for the application Settings, Apps, the application, Permissions, Photos and videos or Files, Do not allow
Device biometrics Unlocking the application locally if you switch that option on Optional It unlocks with your account credentials instead, and no biometric data reaches ZAAPTO, since the check is on the device Settings, Face ID and Passcode, Other Apps, off for the application Settings, Apps, the application, Permissions, Biometrics, or turn the option off in the application
Location Not requestedn/an/an/an/a
Contacts, calendar, microphone, health, motion Not requestedn/an/an/an/a
App Tracking Transparency, iOS Not requested, no tracking as Apple defines it, see 22.4 n/an/a Settings, Privacy and Security, Tracking, where you can refuse every application's request n/a

Declining an optional permission is never met with a repeated prompt. A function that needs one explains itself and links to the setting.

22.3 Data an application would process

Account data, the sign in address and any name you give, under Article 6(1)(b) as necessary for the service you asked for. Content data, what you put in, under Article 6(1)(b). Diagnostic data, crash and error records, under Article 6(1)(f), the interest being keeping installed software working. Anything further needs your consent under regulation 6 of the Privacy and Electronic Communications Regulations 2003 and can be refused without losing a function.

22.4 App Tracking Transparency, iOS

Apple defines tracking as linking user or device data from an application with data from other companies' applications, websites or offline properties for targeted advertising or measurement, or sharing it with a data broker. ZAAPTO does none of that: no advertising software development kit, no data broker, so no App Tracking Transparency prompt appears. If that changed, the prompt would appear, this notice would be updated first, and refusing would remove no function.

22.5 Google Play Data Safety

A Play listing's Data Safety section must describe the same collection, sharing and security practices as this notice, so any ZAAPTO declaration will match sections 22.3 and 22.4. If a store declaration and this notice differ, tell us and we will correct whichever is wrong and say which it was.

22.6 The stores as recipients

Apple and Google run the distribution and payment platforms and are independent controllers of what they collect there. ZAAPTO receives only what a developer receives: aggregate sales and crash information and the fact of a subscription, not your payment details.

23. Account and data deletion

Role: controller

Both stores require an application with account creation to offer a deletion route, including one reachable from outside it. Both below will exist for any ZAAPTO application with accounts.

23.1 In the application

Settings, then Account, then Delete account. The screen states what will be deleted, what is retained and for how long, and asks once. It does not route you into a support conversation.

23.2 By email

Write to contact@zaapto.uk from the account address with "account deletion" in the subject. If you have lost that address we ask for other information sufficient to establish the account is yours, under section 16.2.

23.3 What happens, and when

The request is acknowledged within three working days. Deletion completes within 30 days of verification and you are told when it is done, covering the account record, your content, diagnostic records linked to it and device tokens. Backups are put beyond use at once and deleted as they cycle.

23.4 What is kept afterwards, and why

Minimal records retained after account deletion
RecordContentsPeriodReason
Transaction recordsAmount, date, store order reference. Not your content6 years from the end of the financial yearLegal obligation, Article 6(1)(c), company accounting and tax records, section 14
Suppression recordA one way hash of the account identifier and the deletion dateIndefiniteSo the deletion is honoured and can be evidenced, Article 5(2). It cannot recreate the account or contact you
Legal holdOnly records covered by a live claim or regulatory matterUntil the matter endsArticle 17(3)(e), establishment, exercise or defence of legal claims

23.5 Deleting content without deleting the account

You may ask for specific content to be deleted while keeping the account, at the same address. Section 16.5 governs the answer.

24. Changes to this notice

This notice carries a version number and effective date, and both change when it does. A change that materially affects how personal data is used, a new recipient, a new purpose or a longer retention period, is made before the processing it describes begins.

Superseded versions are kept and can be requested at contact@zaapto.uk. This notice is governed by the law of England and Wales.