Apparo Data Protection Policy
Last updated: July 2026
This page sets out how Apparo Learning Ltd (“Apparo”, “we”, “us”) approaches data protection, intended particularly for schools, colleges, employers, and other institutional partners who need assurance on this before engaging with us. For a general explanation of what we collect and why, see our Privacy Policy.
Contents:
1. Who We Are
Apparo Learning Ltd, company number 17330667, registered in England and Wales. Our registered office is Remus House, Coltsfoot Drive, Peterborough, PE2 9BF.
We are registered with the Information Commissioner's Office (ICO).
2. Our Approach
Data protection is not treated as a compliance checkbox at Apparo. Our founder holds current data protection training alongside child safeguarding credentials, reflecting the same care applied to how information is handled as to how learner welfare is protected. In practice, this means:
● Non-essential cookies and analytics tools (Google Analytics 4, Microsoft Clarity) only activate after a visitor gives consent via our cookie banner, verified as correctly blocking these tools until that consent is given.
● All website typography is self-hosted; no visitor data is transferred to third-party font providers.
● Microsoft Clarity's session recording has form-field masking enabled, so nothing typed into our contact form is ever captured in a recording.
● We collect the minimum data needed for any given purpose, and do not sell personal data to third parties.
3. No AI Processing of Learner Data
The Apparo learning platform does not use artificial intelligence to process learner data. This is a deliberate design decision, not a temporary limitation: we chose not to introduce AI-assisted features into a product used by young people, some of whom are under 18, while the relevant regulatory and safeguarding picture continued to develop. If this position changes in future, it will be reflected here and communicated clearly to institutional partners in advance, not introduced quietly.
4. Data Protection Impact Assessment
We have carried out a Data Protection Impact Assessment (DPIA) covering our website, following the Information Commissioner's Office's own seven-step DPIA methodology. That assessment identified the relevant risks arising from our use of analytics and cookies, and the mitigations we have put in place to address them, including the cookie consent controls and font self-hosting described above.
Under UK GDPR, organisations are not required to publish a DPIA in full, and we have chosen not to, since it necessarily contains detailed internal risk reasoning that is more useful to us operationally than to a general reader. A summary is available to institutional partners on request, and the assessment itself can be produced to the ICO if required.
A separate, more detailed DPIA governs the Apparo learning platform, given the more extensive data processing involved in learner accounts and platform use.
5. Data Processing Agreements
Institutional partners who require a Data Processing Agreement (DPA) before sharing data with us, for example as part of a pilot or licence agreement, can request one directly. We will always agree an appropriate DPA before receiving personal data from a partner organisation on a regular basis.
6. Your Rights
Individuals whose data we hold have the right to access, correct, delete, or restrict how we use their personal data, and the right to complain to the ICO. Full detail is available in our Privacy Policy.
7. Contact
Questions about data protection at Apparo, including requests for a DPIA summary or a Data Processing Agreement: support@apparo.uk.
8. Review
This policy is reviewed at least annually, or immediately following any material change to how we process data.
Review Log:
17/07/2026: Policy added to website