Applicable to SaaS platform services (data processor)
1. Introduction
This Privacy Policy explains how Aptem Limited ("we", "us", or "our") processes personal data when providing our Software-as-a-Service (SaaS) platform (comprising Aptem Apprentice, Aptem Employ, Aptem Assess, and Aptem Skills) (the "Services") to our customers. This Privacy Policy should be read alongside, and considered together with, the contractual documentation in place between Aptem and the customer.
In the context of providing our Services to customers, we act as a data processor, processing personal data solely on behalf of and under the instructions of our customers (the "Data Controllers").
2. Scope
This Policy applies to personal data processed by us in our role as a data processor in connection with the Services. It does not apply to personal data we process as a data controller for our own business purposes (such as account management, billing, or marketing), which is addressed separately in Aptem Website and Marketing Privacy Policy.
This Privacy Policy forms part of, and should be read alongside, the other contractual documents governing your subscription with Aptem, including the Master Services Agreement (or equivalent agreement) and its Schedules. In the event of any conflict, that agreement takes precedence.
3. Who We Are / Company Information
For the purposes of applicable data protection laws, including the UK GDPR and the Data Protection Act 2018, Aptem acts as a data processor on behalf of our customers, who act as the data controller for the personal data processed through the Software. Aptem's details as data processor are:
Legal Entity: Aptem Limited
Registered Address: Eagle House, 167 City Road, London, EC1V 1NR
Telephone Number Tel: 020 7870 1000
Data subjects should direct any queries or requests regarding their personal data to the relevant data controller (their training provider or employer), who remains responsible for determining how their personal data is used.
We are registered with the Information Commissioners Office; our registration number is: Z1900970.
Data Protection Officer
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing compliance with data protection law. You can contact the DPO at:
Contact Name: Sarah Griffiths
Email: dpo@aptem.co.uk
4. Applicable Laws and Regulations
We process personal data in accordance with applicable UK data protection laws, including:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Data Use and Access Act 2025 (DUAA)
- Privacy and Electronic Communications Regulations (PECR) (for cookies and marketing communications)
- Relevant international standards such as ISO/IEC 27001 (Information Security Management)
5. Role and Responsibilities
When acting as a data processor, we:
- Process personal data only on documented instructions from our customers
- Do not determine the purposes or legal basis for processing
- Do not control how personal data is ultimately used by the data controller
Our customers, as Data Controllers, are responsible for:
- Determining the purposes and legal basis of processing
- Providing appropriate privacy notices to data subjects
- Responding to data subject rights requests
6. Nature of Processing
As a SaaS provider, we process personal data on our customers' behalf through our cloud-based software platform. Processing is primarily automated, with limited Aptem human access occurring only where necessary for software development, support, and maintenance activities. This includes:
- Hosting and storage of data
- Processing and transmission of data within the platform
- Providing functionality requested by the customer
- Maintaining service performance and security
The specific categories of personal data, data subjects, and processing details are determined by our customers and defined in the data processing terms of our Master Services Agreement with them.
7. Data Security
We implement appropriate technical and organisational measures to protect personal data, in line with our obligations under the UK GDPR, the Data Protection Act 2018, and our accreditations to ISO 27001 and Cyber Essentials Plus. These measures include, but are not limited to:
- Encryption in transit and, where applicable, at rest
- Access controls based on least privilege principles
- Monitoring, logging, and security testing
- Incident detection and response procedures
We maintain our ISO 27001 and Cyber Essentials Plus accreditations through regular internal and external audits, and review our security measures on an ongoing basis to reflect changes in risk, technology, and regulatory requirements.
8. Sub-processors
We engage third-party service providers ("Sub-processors") to support delivery of the Services, such as cloud hosting, infrastructure, and specific platform functionality. Sub-processors are selected on the basis of their ability to fulfil the relevant business requirements, including their suitability to provide the required services and meet Aptem’s operational needs. As part of the selection and due diligence process, consideration is also given to the sub-processor’s data protection and security practices to ensure that these are appropriate to the nature of the services provided and the data involved. The assessment of data protection and security practices therefore forms an important part of the overall due diligence process but is not the primary basis for selecting a sub-processor.
Each Sub-processor is bound by a written contract imposing data protection obligations that are materially equivalent to those we owe our customers, including a requirement to implement appropriate technical and organisational measures to protect personal data.
We remain responsible for our Sub-processors' compliance with these obligations and for any processing they carry out on our behalf.
Where we intend to appoint a new Sub-processor, we will update our published list. Customers may subscribe to notifications via this page and have the right to object to a new Sub-processor in accordance with the terms of their Master Services Agreement.
A current list of Sub-processors is available at: Aptem Sub Processors.
9. International Data Transfers
Personal data submitted to the Aptem Software on behalf of our customers is hosted and processed using Microsoft Azure infrastructure located in the UK. Certain functions of the service are supported by other sub-processors, some of which are located in the EEA or the US, as set out in our sub-processor list. We only transfer personal data outside the UK or EEA where this is necessary to allow an authorised sub-processor to access or process the data in order to provide our services, or where we have the customer’s prior written consent. Where such a transfer takes place, it is protected by legal safeguards.
A current list of our sub-processors, including their locations, is available under section 8, and customers can sign up for notifications of any changes in line with our data processing terms.
10. Assistance to Data Controllers
We assist our customers, taking into account the nature of processing and the information available to us, in fulfilling their obligations under applicable data protection laws, including:
- Data subject requests - supporting responses to data subject access requests and other data subject rights requests, including providing relevant data extracts or enabling data export directly through the Software
- Security and breach obligations - assisting with obligations relating to the security of processing and notification of personal data breaches
- Data protection impact assessments (DPIAs) - providing information reasonably required for our customers to carry out DPIAs relating to their use of the Services
- Regulatory consultation - assisting with any prior consultation with the relevant supervisory authority, where required
- Complaints handling - supporting our customers in responding to complaints raised by data subjects regarding the processing of their personal data
Where fulfilling a request requires material time or resource beyond what is reasonably included as part of the Services, we may charge for that assistance at our standard rates, except where the need for that assistance arises from our own breach of our obligations.
We will promptly comply with any lawful instruction from a customer regarding Customer Personal Data, including a request to provide the customer with a copy of that data, subject to the customer's cost obligations under their Master Services Agreement.
Data subjects should direct any requests regarding their personal data to the relevant Data Controller (their training provider or employer), who remains responsible for determining how their request is handled and for responding to the data subject directly.
As a data processor, we owe our data protection obligations primarily to our customers rather than directly to data subjects. Where a law gives data subjects specific rights, such as the right to complain introduced by the Data (Use and Access) Act 2025, these are exercised against the relevant Data Controller. We will, however, support our customers in responding to such matters where relevant and appropriate.
11. Data Retention
We retain personal data only for as long as necessary to provide the Services and in accordance with our customers' documented instructions, unless otherwise required by law.
On termination of a customer's agreement with us, we will either:
- Promptly destroy or erase all copies of that customer's personal data in our possession; or
- At the customer's request, made within a defined period after termination and at the customer's expense, return a complete copy of their personal data before destroying or erasing our remaining copies.
Where prompt destruction or erasure is not practical, for example, copies held for backup purposes and not in active use, the personal data will be retained only until our next scheduled deletion or destruction cycle for that data.
Further detail on retention and termination is set out in the data processing terms of our Master Services Agreement with each customer.
12. Personal Data Breaches
In the event of a personal data breach affecting personal data we process on a customer's behalf, we will notify the relevant customer in accordance with the timescales and notification obligations set out in our service agreement with that customer.
Where available, our notification will typically include (this list is not exhaustive):
- A description of the nature of the breach, including if known, the cause
- The remedial action taken
- The likely consequences of the breach
As data controller, the customer is responsible for meeting its own notification obligations to supervisory authorities and affected data subjects under applicable data protection laws. We will cooperate with our customers and provide reasonable assistance to help them meet these obligations.
13. Confidentiality
We ensure that all personnel including permanent, and contractors, who have access to or process personal data on our customers' behalf are subject to confidentiality obligations with respect to that data.
These obligations continue to apply for as long as the personal data remains confidential, and extend to any Sub-processors we engage, who are contractually required to impose materially equivalent confidentiality obligations on their own personnel.
Access to personal data is limited to personnel who require it to perform their role, in line with the access controls described in Section 7 (Data Security). Personnel with access to personal data are permitted to process it only in accordance with our customers' instructions and not for any other purpose, unless required to do so by applicable data protection law.
Access rights are granted on the basis of role and business need, are subject to periodic review, and workflows are implemented to revoke promptly when no longer required, such as on a change of role or termination of employment or engagement, in accordance with the access control principles set out and managed under our ISO 27001-certified Information Security Management System.
14. Audits and Compliance
We publish security certifications, policies, and standard due diligence documentation via the Aptem Trust Centre at https://trust.aptem.co.uk/.
We support audits and inspections by a customer or their designated auditor to verify our compliance, conducted on reasonable notice and in a manner that minimises disruption to our business. We also maintain accurate records demonstrating our compliance with applicable data protection laws, which we make available to customers on request.
Further detail on audit rights and any applicable limitations is set out in the data processing terms of our Master Services Agreement with each customer.
15. Changes to This Privacy Policy
This Privacy Policy is reviewed on a regular basis and may be updated from time to time to reflect changes in legal, regulatory, or operational requirements, as well as updates to our services or data processing activities.
Any changes will be published on this page, and where appropriate, we will take reasonable steps to notify you of significant updates.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.
16. Contact Information
For questions about this Privacy Policy or our role as a data processor, please contact:
Aptem Limited
Eagle House, 167 City Road, London, EC1V 1NR
Telephone Number Tel: 020 7870 1000
Email address: privacy@aptem.co.uk
Last reviewed: 21st August 2026
Version: 2.0