United Kingdom GDPR and Data Protection Act 2018
Privacy notice
How ZAAPTO LTD handles personal data: on this website, in correspondence, during an engagement, and in any application the company publishes.
Effective 7 August 2026 Version 1.0 ZAAPTO LTD, company number 16938315
1. Who this notice is from
This notice is published by ZAAPTO LTD, a private company limited by shares, registered in England and Wales with company number 16938315, registered office 4 Wix Road, Basingstoke, England, RG24 9ZF. "ZAAPTO", "we" and "us" mean that company.
Every data protection matter, including a request to exercise a right, goes to [email protected], or by post to the registered office.
1.1 Data protection officer
ZAAPTO has not appointed a Data Protection Officer. Article 37 requires one only for a public authority, or where core activities involve large scale monitoring or large scale processing of special category or criminal offence data, none of which applies here. Responsibility sits with the company's officers.
1.2 Registration with the ICO
[TO CONFIRM: whether ZAAPTO LTD must pay the ICO data protection fee under the Data Protection (Charges and Information) Regulations 2018 and, if so, the registration number] No number is stated until one exists. Your rights apply either way.
1.3 Representatives
ZAAPTO LTD is a United Kingdom company, so no Article 27 UK representative is required. [TO CONFIRM: whether an EU representative is required under Article 27 of the EU GDPR]
2. Controller and processor
The law separates the organisation that decides why and how personal data is processed, the controller, from the one that processes it on those instructions, the processor. ZAAPTO is both, for different data, and this notice keeps them apart because your route to enforce a right differs.
2.1 Where ZAAPTO is the controller
For data it collects for its own purposes: website visitors, people who write to the enquiry address, contacts at a client or supplier, and the records the company must keep to run itself. ZAAPTO sets the purpose, the lawful basis and the retention period, and answers requests directly.
2.2 Where ZAAPTO is the processor
During an engagement, ZAAPTO builds software inside a client's own systems, where the personal data belongs to the client's world: their staff, the people they sell to, their suppliers. The client decides why it exists and ZAAPTO acts only on documented instructions.
If your data sits in a client's system, contact that client to exercise a right. If you contact us, we say promptly that we are the processor, pass the request to the controller where we can identify them, and tell you so.
2.3 Written terms
Where ZAAPTO acts as processor, a written agreement carrying the terms required by Article 28(3) is in place before processing begins: subject matter and duration, categories of data and data subjects, confidentiality, Article 32 security, sub-processor approval, assistance with rights, deletion or return at the end, and the client's right to audit.
3. What this notice covers
The website at zaapto.uk, email correspondence with ZAAPTO, the administration of engagements, and any application ZAAPTO publishes on the Apple App Store, Google Play or an equivalent channel.
Position as at the effective date. ZAAPTO LTD has published no application on any store. Sections 22 and 23 are written in advance, so the position can be read before a download exists, and they bind any application the company publishes under its own name.
It does not cover other organisations' sites, or a client's systems, which their own notice governs.
4. Which role applies where
Every processing section carries a role marker, repeated here in one place.
| Section | Subject matter | Role of ZAAPTO | Who answers a rights request |
|---|---|---|---|
| 5 | Website visitors | Controller | ZAAPTO LTD |
| 6 | Enquiries and correspondence | Controller | ZAAPTO LTD |
| 7 | Client and supplier records | Controller | ZAAPTO LTD |
| 8 | Work inside client systems | Processor | The client, as controller |
| 22, 23 | Applications published by ZAAPTO | Controller | ZAAPTO LTD |
Wide tables scroll sideways.
5. Website visitors
Role: controller
This site is a set of static files. No login, no account, no form, no analytics, no advertising code. What follows exists because a browser asked a server for a file.
| Category | Example fields | Source | Purpose | Lawful basis | Retention | Recipients |
|---|---|---|---|---|---|---|
| Request and connection data | IP address, timestamp, file requested, HTTP status, user agent, referring page, country derived from IP, bot score | Your browser, automatically | Delivering the page, keeping the site available, blocking attack and automated abuse | Article 6(1)(f). Interest: keeping a published website available and defending the domain against attack, see section 9 | The hosting provider's own log period, measured in days. ZAAPTO keeps no copy | Cloudflare, Inc. |
| Font request data | IP address, user agent, referring page, sent when your browser fetches the two typefaces | Your browser, automatically | Displaying the site in the typefaces it is set in | Article 6(1)(f). Interest: presenting a legible published document, see section 9 | Not retained by ZAAPTO. Google's own retention applies | Google LLC, Google Ireland Limited |
ZAAPTO keeps no server logs and profiles no visitor. A content blocker will stop your browser contacting Google for the typefaces, and the site stays readable in the faces on your device.
6. Enquiries and correspondence
Role: controller
Every contact action here opens your own email client addressed to [email protected]. You send from your own email service and it arrives in a mailbox operated for ZAAPTO. No form, no capture script, no lead service.
| Category | Example fields | Source | Purpose | Lawful basis | Retention | Recipients |
|---|---|---|---|---|---|---|
| Identity and contact details | Name, email address, organisation, job title, telephone if given | You | Knowing who is writing and replying to them | Article 6(1)(f) for a general enquiry, interest: operating a correspondence address, section 9. Article 6(1)(b), steps at your request before a contract, once specific work is discussed | 12 months from the last message, unless work follows | Email hosting provider, section 12 |
| Message content | Your description of a process, systems in use, constraints, attachments | You | Understanding the request, deciding whether ZAAPTO can help, replying | Article 6(1)(f) or 6(1)(b), as above | 12 months from the last message | Email hosting provider, section 12 |
| Message metadata | Headers, mail server records, timestamps, spam scoring | Generated in transit | Delivering mail and filtering unsolicited mail | Article 6(1)(f). Interest: operating a working mailbox, see section 9 | 12 months from the last message | Email hosting provider, section 12 |
6.1 Other people named in your message
If your message contains personal data about somebody else, ZAAPTO becomes its controller on receipt, on the same terms as the thread. Please keep it minimal: a role is usually enough.
6.2 What not to send
No credentials, passwords, API keys or tokens. No special category data. No extracts of records about other people. Real data and access are arranged in your own systems under a written agreement.
7. Client and supplier records
Role: controller
When an engagement proceeds, ZAAPTO keeps its own record of the contract and the money. The individuals are named contacts.
| Category | Example fields | Source | Purpose | Lawful basis | Retention | Recipients |
|---|---|---|---|---|---|---|
| Contract contacts | Name, role, work email and telephone, signature on an engagement letter | The organisation | Agreeing, performing and evidencing a contract | Article 6(1)(b) where the individual contracts personally, otherwise Article 6(1)(f), interest: administering a contract with an organisation, section 9 | 6 years from the end of the contract | Accountant, advisers if a dispute arises |
| Billing and payment records | Invoice, purchase order reference, amounts, dates, remittance details | The organisation, and the bank | Invoicing, collecting payment, bookkeeping, accounts and tax returns | Article 6(1)(c), legal obligation, sections 386 and 388 Companies Act 2006 and Schedule 11 Value Added Tax Act 1994 where applicable. Article 6(1)(b) for taking payment | 6 years from the end of the financial year | Accountant, bank, HM Revenue and Customs on a lawful request |
| Engagement correspondence | Email and notes on scope, changes, acceptance and handover | Both parties | Running the work and evidencing what was agreed | Article 6(1)(b) and 6(1)(f). Interest: being able to bring or defend a claim in the limitation period, see section 9 | 6 years from the end of the contract | Email hosting provider, advisers if a dispute arises |
| Access records | Which account had access to which system, granted when, revoked when | Created by ZAAPTO | Controlling access and later evidencing it | Article 6(1)(f). Interest: demonstrating that access was scoped and removed, see section 9 | 6 years from the end of the contract | The client, on request |
8. Work inside client systems
Role: processor
The work described elsewhere is software built inside systems the client owns. Where it reads, moves or writes personal data, ZAAPTO does so on the client's documented instructions.
| Category | Example fields | Source | Purpose | Lawful basis | Retention | Recipients |
|---|---|---|---|---|---|---|
| Records handled by an automation | Whatever the specification moves, for example a customer name, a job status, a document reference | The client's systems | Performing the function set out in the written specification | Chosen by the client as controller. ZAAPTO selects no basis for this data | Set by the client in its own systems | Only the systems named in the specification |
| Diagnostic extracts | A small sample of real records, where a fault cannot be reproduced with invented data | The client, deliberately provided | Diagnosing one specific defect | Chosen by the client, on its documented instruction | Deleted on closure of the defect, and within 30 days regardless | Nobody outside ZAAPTO |
8.1 Working copies
No client personal data leaves the client's systems by default. Where an extract is genuinely necessary it is requested in writing, kept to the smallest sample that answers the question, held where the client agrees, and deleted on closure, with a note in the access records in section 7.
8.2 Unlawful instructions
If an instruction appears to infringe data protection law, ZAAPTO says so in writing before acting, as Article 28(3) requires.
8.3 End of engagement
At the end, ZAAPTO deletes or returns personal data processed on the client's behalf, at the client's election. The client revokes ZAAPTO's access, and ZAAPTO confirms in writing when it believes all of it is gone.
9. Legitimate interests, named
Role: controller
Article 6(1)(f) requires the interest to be identified rather than gestured at. Each is balanced against the rights and freedoms of the people concerned.
| Processing | The interest, named | Why it does not override your rights |
|---|---|---|
| Serving pages, and hosting layer logs | Keeping a published website available and defending the domain against automated attack | Limited to what a web request contains, no profiling, held for days |
| Serving typefaces from Google's font hosts | Presenting a legible document consistently across devices | No account and no identifier set here, and it is stated so you can block it |
| Reading and answering enquiry email | Operating a correspondence address so a person who writes gets an answer | It is what you chose to send, used only to reply, deleted after 12 months |
| Holding contract records for six years | Bringing or defending a claim inside the limitation period in section 5 of the Limitation Act 1980 | A fixed period, no other use, disclosed only to advisers in a dispute |
| Access grant and revocation records | Showing a client or a regulator that access was scoped and later removed | An account name and two dates, protecting the people whose data is in those systems |
| Writing to a company's named representative | Administering a contract with an organisation, which happens through a person | Work contact data in a work context |
You may object at any time. Section 16.7 explains how.
10. Special category and criminal offence data
Role: controller in 10.1, processor in 10.2
10.1 As controller
ZAAPTO has no purpose requiring data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to identify a person, health, sex life or sexual orientation. No Article 9 condition and no Schedule 1 condition of the Data Protection Act 2018 is relied on, because no such data is processed for the company's own purposes.
If it arrives unsolicited in an email it is used for nothing and removed once noticed, unless removal would destroy a record we must keep. ZAAPTO processes no Article 10 criminal offence data and runs no records checks.
10.2 As processor
A client's systems may hold special category data. Where an engagement would touch it, three things apply without exception: the client states the data and its Article 9 condition, and its Schedule 1 condition where required, in the data processing agreement before work starts; the client holds the appropriate policy document required by paragraph 5 of Part 4 of Schedule 1 where its condition requires one; and the specification states where that data flows. If those cannot be stated, the work is declined.
11. Children
Role: controller
This site and the company's services are for businesses, not children. ZAAPTO does not knowingly collect personal data from anybody under 18. Any application it publishes will be age rated honestly and will not sit in a children's category unless built to the ICO's Age Appropriate Design Code. A child's data collected unintentionally is deleted.
12. Recipients and sub-processors
Role: controller for the company's own suppliers, processor where a sub-processor serves a client
Data here goes only to these recipients, for the purpose stated. ZAAPTO does not sell personal data, share it for anyone else's marketing, or use it to train a model.
| Recipient | Function | Data reaching them | Relationship | Location |
|---|---|---|---|---|
| Cloudflare, Inc. | Hosting and content delivery for zaapto.uk, and attack protection | Request and connection data, section 5 | Processor to ZAAPTO | Global edge network, including outside the UK. See section 13 |
| Google LLC and Google Ireland Limited | Serving the two typefaces from fonts.googleapis.com and fonts.gstatic.com | Your IP address and browser details, sent by your browser | Independent controller of its own logs. ZAAPTO receives none of it | United States and elsewhere. See section 13 |
| Email hosting provider | Receiving, storing and sending mail for zaapto.uk | Everything in an enquiry or engagement email, with attachments and headers | Processor to ZAAPTO | [TO CONFIRM: the provider operating the zaapto.uk mailboxes, its legal entity and country of processing] |
| Accountant | Bookkeeping, statutory accounts, tax filings | Billing and payment records, section 7 | Processor for bookkeeping, independent controller for its own professional duties | [TO CONFIRM: the accounting firm engaged and its country of processing] |
| Banking provider | Receiving and making payments | Name, amount, payment reference | Independent controller under its own regulatory duties | [TO CONFIRM: the bank holding the ZAAPTO LTD business account] |
| Professional advisers | Legal or accountancy advice, only if a dispute or regulatory matter arises | Only records relevant to that matter | Independent controllers, bound by professional confidentiality | United Kingdom |
| Public authorities | Disclosure required by law, to HM Revenue and Customs, a court or the Information Commissioner | Only what the lawful request covers | Recipients under a legal obligation, Article 6(1)(c) | United Kingdom |
12.1 Sub-processors during an engagement
As processor, ZAAPTO engages no sub-processor without the client's prior written authorisation under Article 28(2), and where that authorisation is general the client is told of any addition in advance and may object. Most engagements involve none.
13. International transfers
Role: controller, and processor where client data is involved
A restricted transfer is personal data sent outside the United Kingdom. Chapter V allows one only under a listed safeguard.
13.1 Adequacy
Transfers to countries covered by United Kingdom adequacy regulations, which include the European Economic Area, are made under Article 45, and need no further safeguard while those regulations stand.
13.2 The IDTA and the UK Addendum
Elsewhere, ZAAPTO relies on Article 46, using either the International Data Transfer Agreement issued by the Information Commissioner or the International Data Transfer Addendum to the European Commission's standard contractual clauses. Both are approved United Kingdom mechanisms.
13.3 Transfer risk assessment
Before relying on either, ZAAPTO assesses the destination's law and practice, the sensitivity of the data, and whether the safeguard would work. If it would not, the transfer is not made.
13.4 The transfers that actually occur
| Transfer | Data | Destination | Safeguard |
|---|---|---|---|
| Website delivery | Request and connection data, section 5 | Cloudflare's global network, which may serve a request from outside the UK | Article 46, the Addendum to the EU standard contractual clauses in the provider's data processing terms, with a transfer risk assessment |
| Typeface delivery | IP address and browser details, section 5 | Google's font hosts, including servers in the United States | Article 46 as operated by Google. Your browser makes the request, so ZAAPTO is not the exporter and states this row for completeness |
| Email hosting | Correspondence, sections 6 and 7 | [TO CONFIRM: country of processing for the zaapto.uk mailboxes] | UK or EEA processing is preferred. Otherwise Article 46 with the IDTA or the Addendum, with a transfer risk assessment |
| Client engagements | Client personal data | Wherever the client's systems already are | The client is the exporter and decides. ZAAPTO moves client data to a new country only on written instruction |
A copy of any safeguard relied on can be requested, redacted where commercially confidential.
14. Retention
Role: controller
Data is kept only while there is a reason, and the reason is given, because a period without one is a guess.
| Record | Period | Counted from | Reason |
|---|---|---|---|
| Hosting request logs | The provider's own period, days rather than months | The request | They exist to detect attack and diagnose availability, both short lived questions. ZAAPTO keeps no copy |
| Enquiries that lead to no work | 12 months | The last message in the thread | Long enough to answer a follow up, short enough that an abandoned idea does not sit indefinitely |
| Contracts and engagement correspondence | 6 years | The end of the contract | The limitation period for a simple contract, section 5 of the Limitation Act 1980, so a claim can be brought or defended |
| Accounting records, invoices, payments | 6 years | The end of the financial year | Statutory. Section 388 of the Companies Act 2006 requires accounting records to be preserved, HM Revenue and Customs requires company tax records for six years, and Schedule 11 to the Value Added Tax Act 1994 requires six years for VAT records if the company registers |
| Access grant and revocation records | 6 years | The end of the engagement | Evidence of how the contract was performed, kept with it |
| Diagnostic extracts of client data | Until the defect closes, 30 days at most | Provision of the extract | It answers one question and has no purpose afterwards |
| Data protection requests and our responses | 3 years | Closure of the request | Accountability under Article 5(2), so we can show how a request was handled if the Information Commissioner asks |
| Personal data breach records | 6 years | The date of the record | Article 33(5) requires a record of every breach with no fixed period. Six years aligns it with the limitation period |
| Suppression record after deletion | Indefinite, minimal | Completion of the deletion | So the deletion is honoured and can be evidenced. It holds the minimum needed for that, see section 23.4 |
At the end of a period records are deleted or, where a backup cannot be edited, put beyond use and deleted as it cycles. Anything restored is subject to the same periods.
15. Security, and what we do not claim
Role: controller and processor
Article 32 requires measures appropriate to the risk. These are applied: named accounts with multi factor authentication; access into a client system requested per system, scoped and revoked at the end; credentials in dedicated secret storage rather than documents or messages; no copying of personal data out of client systems except as section 8.1 allows; and a static website with no database to compromise.
What is not claimed. ZAAPTO LTD does not hold ISO 27001 certification, a SOC 2 report or Cyber Essentials certification, and will not represent otherwise. Nothing here is a third party attestation. These are commitments about how the company arranges its work, and a client is entitled to write them into the engagement contract, where they become enforceable.
16. Your rights
Role: controller. Where ZAAPTO is a processor, section 2.2 says who to contact
Every right below is exercised the same way: write to [email protected], or to the registered office. No particular wording is needed and there is no charge.
16.1 Timing
A request is answered without undue delay and within one month of receipt, as Article 12(3) requires, counted from the day after receipt or after identity is verified. Complex or repeated requests may be extended by up to two further months, and we tell you inside the first month that it applies and why.
16.2 Verifying who you are
Article 12(6) allows us to ask what is necessary to confirm identity where there is reasonable doubt. Writing from an address already in the correspondence is usually enough. If not, we ask for the minimum extra information and discard it once identity is settled. We will not ask for a passport to answer a question about an email thread.
16.3 Access, Article 15
You may ask whether we hold personal data about you and, if so, for a copy with the purposes, categories, recipients, retention period, the source if it was not you, and your other rights. Where a copy would reveal another person's data, that part is redacted unless they consent, as paragraph 16 of Schedule 2 to the Data Protection Act 2018 permits.
16.4 Rectification, Article 16
You may have inaccurate data corrected and incomplete data completed. Where the record is of something you told us, correction means adding the correct version rather than rewriting the original. Recipients in section 12 are told, unless that is impossible or disproportionate, as Article 19 requires.
16.5 Erasure, Article 17
You may ask for deletion where data is no longer necessary, where consent is withdrawn and no other basis applies, where you object with no overriding ground, or where processing was unlawful. It is not absolute: it does not apply where processing is necessary for a legal obligation, which is why accounting records stay until the statutory period ends, or for legal claims, which is why contract records run to the limitation period. Where a request cannot be granted in full we say which records are kept and under which exemption.
16.6 Restriction, Article 18
You may ask us to stop using data while a question about it is resolved, such as a challenge to its accuracy. It is then stored but not otherwise used, except with your consent or for legal claims, and we tell you before a restriction is lifted.
16.7 Objection, Article 21
You may object at any time to processing based on legitimate interests, all of which section 9 lists. We stop unless we can demonstrate compelling legitimate grounds overriding your rights and freedoms, or the processing is for legal claims. An objection to direct marketing is absolute and immediate, and ZAAPTO carries out none.
16.8 Portability, Article 20
Where automated processing is based on consent or a contract, you may ask for the data you provided in a structured, commonly used, machine readable format, and ask us to send it to another controller where feasible. Most data held here is correspondence under legitimate interests or a legal obligation, which falls outside this right.
16.9 Withdrawing consent, Article 7(3)
Where processing relies on consent you may withdraw it at any time, as easily as it was given, without affecting the lawfulness of what came before. Nothing in sections 5 to 8 relies on consent.
16.10 Automated decisions, Article 22
You have the right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects. ZAAPTO makes none, see section 19.
16.11 When a request can be refused
A request may be refused, or a reasonable fee charged, where it is manifestly unfounded or excessive under Article 12(5). It may be refused in part where an exemption in Schedule 2 to the Data Protection Act 2018 applies, such as legal professional privilege. Any refusal comes within one month, says which ground applies to which records, and tells you that you may complain to the Information Commissioner and seek a judicial remedy. Refusal is never silent.
17. Complaints and the ICO
Role: controller
If you are unhappy with how we have handled your data or your request, tell us first at [email protected], which is usually quicker. That is not a precondition and does not affect your right to complain.
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk/make-a-complaint
You also have the right to an effective judicial remedy under Articles 78 and 79, and to compensation under Article 82 for damage suffered through an infringement.
18. Personal data breaches
Role: controller in 18.2 and 18.3, processor in 18.4
A personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Losing access counts, not only somebody else gaining it. Report a suspected one to [email protected].
18.1 Detection and containment
On becoming aware of a suspected breach we contain it, establish what data and who is affected, and record the moment awareness began, because every later deadline runs from it.
18.2 Notifying the Information Commissioner, Article 33
Where ZAAPTO is controller and a breach is likely to result in a risk to people's rights and freedoms, it is reported to the Information Commissioner without undue delay and, where feasible, within 72 hours of becoming aware. A later report carries the reasons for the delay. Where a breach is judged unlikely to result in a risk it is not reported, and that reasoning is written down at the time. A report covers the nature of the breach, the categories and approximate numbers affected, the likely consequences, the measures taken and a contact point.
18.3 Notifying you, Article 34
Where a breach is likely to result in a high risk to your rights and freedoms you are told without undue delay, in plain language, with the nature of the breach, the likely consequences, the measures taken and a contact point. Notice is not required where the data was unintelligible to anyone unauthorised, where later measures removed the high risk, or where individual notice would take disproportionate effort, when a public communication is made instead.
18.4 Where ZAAPTO is the processor, Article 33(2)
Where a breach affects data processed on a client's behalf, ZAAPTO notifies that client without undue delay, with what they need for their own assessment and their own 72 hour deadline. Whether to notify the Information Commissioner or affected individuals is the client's decision as controller, and ZAAPTO assists under Article 28(3)(f).
18.5 The record, Article 33(5)
Every breach is recorded whether or not it is reportable, with the facts, its effects and the remedial action. Section 14 gives the retention period.
19. Automated decisions and profiling
Role: controller
ZAAPTO makes no decisions about individuals based solely on automated processing producing legal or similarly significant effects, and profiles nobody. Enquiries are read by a person, and nothing here scores or ranks a visitor.
Automations built for a client may apply rules to records. Whether a rule is a decision within Article 22 is a question for the client as controller, raised at the scope stage whenever a specification describes a rule deciding something about a person rather than a task.
20. Marketing and electronic communications
Role: controller
ZAAPTO operates no mailing list, sends no marketing email and makes no marketing calls. Writing to the enquiry address adds you to nothing, so there is nothing to unsubscribe from. Any message that looks like marketing from a zaapto.uk address should be reported to us.
If a mailing list is ever introduced it will run under the Privacy and Electronic Communications Regulations 2003: consent by positive action, the regulation 22(3) existing customer exception used only where it genuinely applies, a working unsubscribe in every message, and this section rewritten first.
21. Cookies and similar technologies
Role: controller
This site sets no analytics, advertising or personalisation cookies and stores nothing in local or session storage. The full position, including what the hosting platform may set and why no banner appears, is in the cookie statement.
Regulation 6 of the Privacy and Electronic Communications Regulations 2003 requires consent for storing or accessing information on a device, except where strictly necessary for a service the user requested. The cookie statement explains why that exception applies here.
22. Applications published by ZAAPTO
Role: controller
As at the effective date, ZAAPTO LTD has published no application on the Apple App Store, on Google Play or anywhere else. This section states the terms binding any application it publishes under its own name. [TO CONFIRM: name, platforms and store listing identifiers of the first application, once one exists]
22.1 The governing rule
An application published by ZAAPTO will not collect personal data unnecessary for a function the user asked for, and will say what a function needs as it asks.
22.2 Permissions
This is the complete set of device permissions any ZAAPTO application may request. One not listed will not be requested, and a future need changes this table before that release.
| Permission | Purpose | Required or optional | If you decline | Revoke on iOS | Revoke on Android |
|---|---|---|---|---|---|
| Notifications | Telling you a job you started has finished or failed | Optional | Everything works. You check status in the application instead | Settings, Notifications, the application, turn off Allow Notifications | Settings, Apps, the application, Notifications, turn off |
| Camera | Capturing a document or a code when you choose that instead of picking a file | Optional | Capture is unavailable. You can still attach an existing file | Settings, Privacy and Security, Camera, off for the application | Settings, Apps, the application, Permissions, Camera, Do not allow |
| Photos and files | Attaching a file you select to the record you are working on | Optional | No attachments from the device. Every other function is unaffected | Settings, Privacy and Security, Photos, None or Limited for the application | Settings, Apps, the application, Permissions, Photos and videos or Files, Do not allow |
| Device biometrics | Unlocking the application locally if you switch that option on | Optional | It unlocks with your account credentials instead, and no biometric data reaches ZAAPTO, since the check is on the device | Settings, Face ID and Passcode, Other Apps, off for the application | Settings, Apps, the application, Permissions, Biometrics, or turn the option off in the application |
| Location | Not requested | n/a | n/a | n/a | n/a |
| Contacts, calendar, microphone, health, motion | Not requested | n/a | n/a | n/a | n/a |
| App Tracking Transparency, iOS | Not requested, no tracking as Apple defines it, see 22.4 | n/a | n/a | Settings, Privacy and Security, Tracking, where you can refuse every application's request | n/a |
Declining an optional permission is never met with a repeated prompt. A function that needs one explains itself and links to the setting.
22.3 Data an application would process
Account data, the sign in address and any name you give, under Article 6(1)(b) as necessary for the service you asked for. Content data, what you put in, under Article 6(1)(b). Diagnostic data, crash and error records, under Article 6(1)(f), the interest being keeping installed software working. Anything further needs your consent under regulation 6 of the Privacy and Electronic Communications Regulations 2003 and can be refused without losing a function.
22.4 App Tracking Transparency, iOS
Apple defines tracking as linking user or device data from an application with data from other companies' applications, websites or offline properties for targeted advertising or measurement, or sharing it with a data broker. ZAAPTO does none of that: no advertising software development kit, no data broker, so no App Tracking Transparency prompt appears. If that changed, the prompt would appear, this notice would be updated first, and refusing would remove no function.
22.5 Google Play Data Safety
A Play listing's Data Safety section must describe the same collection, sharing and security practices as this notice, so any ZAAPTO declaration will match sections 22.3 and 22.4. If a store declaration and this notice differ, tell us and we will correct whichever is wrong and say which it was.
22.6 The stores as recipients
Apple and Google run the distribution and payment platforms and are independent controllers of what they collect there. ZAAPTO receives only what a developer receives: aggregate sales and crash information and the fact of a subscription, not your payment details.
23. Account and data deletion
Role: controller
Both stores require an application with account creation to offer a deletion route, including one reachable from outside it. Both below will exist for any ZAAPTO application with accounts.
23.1 In the application
Settings, then Account, then Delete account. The screen states what will be deleted, what is retained and for how long, and asks once. It does not route you into a support conversation.
23.2 By email
Write to [email protected] from the account address with "account deletion" in the subject. If you have lost that address we ask for other information sufficient to establish the account is yours, under section 16.2.
23.3 What happens, and when
The request is acknowledged within three working days. Deletion completes within 30 days of verification and you are told when it is done, covering the account record, your content, diagnostic records linked to it and device tokens. Backups are put beyond use at once and deleted as they cycle.
23.4 What is kept afterwards, and why
| Record | Contents | Period | Reason |
|---|---|---|---|
| Transaction records | Amount, date, store order reference. Not your content | 6 years from the end of the financial year | Legal obligation, Article 6(1)(c), company accounting and tax records, section 14 |
| Suppression record | A one way hash of the account identifier and the deletion date | Indefinite | So the deletion is honoured and can be evidenced, Article 5(2). It cannot recreate the account or contact you |
| Legal hold | Only records covered by a live claim or regulatory matter | Until the matter ends | Article 17(3)(e), establishment, exercise or defence of legal claims |
23.5 Deleting content without deleting the account
You may ask for specific content to be deleted while keeping the account, at the same address. Section 16.5 governs the answer.
24. Changes to this notice
This notice carries a version number and effective date, and both change when it does. A change that materially affects how personal data is used, a new recipient, a new purpose or a longer retention period, is made before the processing it describes begins.
Superseded versions are kept and can be requested at [email protected]. This notice is governed by the law of England and Wales.