Legal

Privacy policy

How we handle personal data, both on this website and in the AptaOps platform itself.

Last updated 4 October 2026

Who we are

AptaOps is a training operations platform operated by Selion Technologies. This policy covers aptaops.co.uk and the AptaOps platform we provide to customers.

For anything in this policy, email demo@aptaops.co.uk.

Two different roles

The distinction matters, because it decides who you should be talking to.

  • This website. We are the data controller for the handful of personal data this site involves, which is essentially the contents of any email you send us.
  • The platform. When a training provider runs their business on AptaOps, they are the data controller for the delegates, instructors, staff and company contacts in their system. We are their processor: we hold and process that data on their instructions, under a contract with them. If you have been booked onto a course and want to know what is held about you, ask the training provider who booked you. They can answer, and we will help them do it.

What this website collects

Not much, on purpose. There is no analytics, no advertising, no tracking and no third-party embed on this site.

  • No cookies. The site sets none, which is why there is no cookie banner.
  • Server logs. Our web server records requests in the ordinary way, including IP address, the page requested, timestamp and browser user agent. We use these to keep the site running and secure, and they are deleted on a short rolling cycle.
  • What you email us. If you get in touch about a demo, we keep your message and contact details so we can reply and follow up. Our lawful basis is legitimate interests: you contacted us about our product and we are answering.

What the platform holds

On behalf of our customers, AptaOps holds the records a training operation needs: names and contact details for delegates, instructors and staff, the companies people work for, course attendance and results, certificates and their expiry dates, instructor qualifications and the certificates evidencing them, and the commercial records that go with all of it.

What is held in any given system, and for how long, is set by the customer who runs it. We do not use it for our own purposes, we do not sell it, and we do not use it to train machine-learning models.

The instructor app

The AptaOps app for Android and iOS is for instructors whose training provider runs AptaOps. There's no sign-up in it. The provider creates your account, and they're the data controller for what's in it, just as they are for the rest of their system.

When you use it, the app sends your provider's AptaOps system:

  • Your sign-in. Your username and password, to sign you in. If you ask the app to remember them, they're kept in your phone's secure storage behind your fingerprint or face unlock.
  • What you do in it. Attendance you mark, delegates you add or correct, documents you upload to a course, and qualification requests along with the certificate photo or file you attach.
  • A notification token. On Android, a token from Google's Firebase Cloud Messaging, so your provider's system can send notifications to your phone. You can turn notifications off on the app's profile tab or in your phone's settings.

If the app crashes or hits an error, it sends a crash report to Sentry. That covers the phone model, the operating system and app version, what the app was doing at the time, and an internal account number. It never includes your name, your email address or a screenshot.

The camera is only used when you choose to photograph a certificate. The app doesn't read your location, your contacts or anything else on your phone, and there's no advertising or tracking in it.

Where it is kept

Data is hosted in the United Kingdom. Backups are taken automatically and stored encrypted, separately from the servers they came from and within the UK. Access is limited to the people who need it to run and support the service, over authenticated connections, and what they do is logged.

The one exception is crash reports from the instructor app, which Sentry stores in the EU. UK law treats the EU as giving personal data adequate protection, and the reports carry no names or email addresses.

Who else is involved

We keep the list of suppliers short, and each one only ever sees what it needs to do its job:

  • Microsoft Azure for hosting and encrypted backup storage, in UK regions.
  • Google Workspace or Microsoft 365 for sending email. Where a customer connects their own account, mail goes out through their provider under their own terms, not ours.
  • PayPal where a customer chooses to take payments. They connect their own PayPal account and card details never reach AptaOps.
  • Stripe where a customer chooses to take card payments. They connect their own Stripe account, and the person paying enters their card details on Stripe's own checkout page, so those never reach AptaOps either. Stripe receives the payer's email address, the course name and the booking reference, so the payment can be matched to the right booking.
  • Google Play and the Apple App Store for distributing the instructor app.
  • Google Firebase Cloud Messaging for delivering notifications to the instructor app on Android. Google sees the phone's notification token and the title and text of each notification.
  • Sentry for crash reports from the instructor app, stored in the EU. A report carries an internal account number but no name, email address or screenshot.

We do not share personal data with anyone else, except where the law requires it or where we need to defend a legal claim.

How long we keep things

  • Enquiries and demo correspondence: up to two years after our last contact.
  • Web server logs: a short rolling window, measured in days.
  • Customer data in the platform: for as long as the customer's contract runs. When it ends we return or delete their data on request, and in any case within 90 days, allowing for backups to age out on their own cycle.

Your rights

Under UK data protection law you can ask for a copy of the personal data held about you, ask for it to be corrected or deleted, object to or restrict how it is used, and ask for it in a portable form. You can also withdraw consent where consent is what we relied on.

For anything held in a training provider's AptaOps system, send the request to that provider. For anything we hold as controller, send it to us and we will respond within one month.

If we do not get it right, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first, so we get the chance to fix it.

Changes to this policy

If we change anything material, we will update the date at the top of this page and, for customers, tell you directly.

Back to the home page