Privacy policy

This policy explains how Apoynt (apoynt.co.uk) handles personal data under UK GDPR and the Data Protection Act 2018.

Who we are

Apoynt is the controller for accounts on apoynt.co.uk. Each business that uses Apoynt is the controller for its own customer bookings. We act as their processor for that data.

What we collect

Account names and emails, booking details, payment references (not full card numbers), support messages, and basic device logs needed to run the site.

Why we use it

To provide the service, take payment for plans, send booking messages the business has enabled, keep the platform secure, and meet UK law.

How long we keep it

Account data while the account is open and for up to 24 months after closure unless the law requires longer. Booking records follow the business that created them.

Your rights

You can ask for a copy of your data, corrections, deletion, or to object to some uses. Write to hello@apoynt.co.uk. You can also complain to the ICO at ico.org.uk.

Processors

We use hosting, email and payment providers (such as PayPal or Stripe when a business connects them). They only process data on our or the business’s instructions.