This policy explains how Apoynt (apoynt.co.uk) handles personal data under UK GDPR and the Data Protection Act 2018.
Apoynt is the controller for accounts on apoynt.co.uk. Each business that uses Apoynt is the controller for its own customer bookings. We act as their processor for that data.
Account names and emails, booking details, payment references (not full card numbers), support messages, and basic device logs needed to run the site.
To provide the service, take payment for plans, send booking messages the business has enabled, keep the platform secure, and meet UK law.
Account data while the account is open and for up to 24 months after closure unless the law requires longer. Booking records follow the business that created them.
You can ask for a copy of your data, corrections, deletion, or to object to some uses. Write to hello@apoynt.co.uk. You can also complain to the ICO at ico.org.uk.
We use hosting, email and payment providers (such as PayPal or Stripe when a business connects them). They only process data on our or the business’s instructions.
Everyone must be busy right now, but they will get your message.