Apollo Data Processing Agreement
Last updated: 3 July 2026
This Data Processing Agreement (DPA) forms part of the agreement between APOLLOUI LTD (Apollo, Processor, we, us, our) and the customer organisation that registers for or uses the Apollo platform (Customer, Tenant, Controller, you, your).
It applies where Apollo processes Personal Data on your behalf as a processor under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This DPA supplements the Apollo Terms and Conditions (Terms). If there is a conflict between this DPA and the Terms regarding processor obligations and Personal Data processed on your instructions, this DPA prevails for that subject matter unless a separate signed agreement expressly overrides it.
Out of scope: Personal Data for which Apollo acts as an independent controller (for example Apollo’s own account administration, subscription billing with you, marketing to you, website operations, and platform security logs relating to Apollo’s relationship with you) is described in our Privacy Policy and is not covered by this DPA.
Related documents:
- Terms and Conditions
- Privacy Policy
- Cookie Policy — Apollo controller website cookies; cross-reference only
- Disclaimer — platform scope and limits; cross-reference only
1. Introduction and relationship to Terms
1.1 By using the Apollo platform as a Tenant, you instruct Apollo to process Personal Data contained in your tenant workspace and related features (including the client portal where you expose data to your clients) solely to provide the Platform as described in the Terms and this DPA.
1.2 This DPA incorporates UK GDPR Article 28-style processor commitments. It applies to the extent required by applicable UK data protection law.
1.3 Order of documents (see also section 20):
- Signed enterprise or Provider agreement (if any) — prevails for its subject matter;
- This DPA — processor processing of Tenant Personal Data;
- Terms — general platform contract;
- Privacy Policy — Apollo controller transparency (not a substitute for this DPA).
1.4 Capitalised terms not defined in this DPA have the meaning given in the Terms or UK GDPR.
2. Definitions
| Term | Meaning |
|---|---|
| Apollo Platform / Platform | The Apollo software-as-a-service platform, including workspace tools, client portal, APIs, and related services described in the Terms. |
| Authorised User | A person you permit to access the Platform under your tenant (for example OWNER, ADMIN, STAFF, EDITOR, COLLABORATOR, CLIENT portal users). |
| Client | Your customer (for example an estate agent or property professional) whose data you manage in Apollo. |
| Client Content | Content and data you upload or generate about clients, jobs, orders, and deliverables. |
| Controller | The entity that determines the purposes and means of processing Personal Data — you, for Tenant Personal Data. |
| Data Protection Laws | UK GDPR, the Data Protection Act 2018, and applicable UK privacy and electronic communications law. |
| Data Subject | An identified or identifiable individual whose Personal Data is processed. |
| DPA | This Data Processing Agreement. |
| Personal Data | Information relating to an identified or identifiable individual, as defined in UK GDPR. |
| Personal Data Breach | A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data. |
| Processing | Any operation performed on Personal Data (including collection, storage, use, disclosure, deletion). |
| Processor | An entity that processes Personal Data on behalf of the Controller — Apollo, for Tenant Personal Data. |
| Subprocessor | A third party engaged by Apollo to process Personal Data on our behalf. |
| Tenant Personal Data | Personal Data processed by Apollo on your behalf in providing the Platform, as described in Annex 1. |
| Terms | The Apollo Terms and Conditions. |
3. Scope and application
3.1 This DPA applies to Apollo’s Processing of Tenant Personal Data when you use the Platform as a Tenant.
3.2 This DPA does not apply to:
(a) Personal Data for which Apollo is a Controller (see Privacy Policy), including without limitation:
- your organisation’s Apollo subscription billing relationship with us (Stripe billing metadata held by Apollo as controller);
- marketing to prospective customers or early-access registrants on Apollo-controlled lists (for example Mailchimp register-interest, where you are not the controller of that list);
- website visitor data on Apollo marketing pages (subject to Cookie Policy);
- support requests submitted to Apollo about the Platform as a product (where Apollo is controller for that intake);
(b) Personal Data you process outside the Platform;
(c) Third-party services you connect or use independently (except where Apollo processes data on your behalf through an integrated Subprocessor solely to deliver the Platform).
3.3 Client portal dual role. Client portal users may have:
- Tenant Personal Data (controlled by you, processed by Apollo under this DPA); and
- Apollo account data (controlled by Apollo, described in the Privacy Policy).
3.4 Invitations and platform email. Where Apollo sends secure invitation or account-setup emails on your instruction, Apollo processes invitee Personal Data to deliver the Platform. The lawful basis and privacy notice for invitees in their relationship with you remain your responsibility as Controller.
3.5 If you require a signed copy of this DPA, contact hello@apolloui.co.uk.
4. Roles of the parties
4.1 You are the Controller of Tenant Personal Data. You determine why and how that Personal Data is processed in your business (clients, staff, orders, property jobs, invoicing, deliverables, and related workflows).
4.2 Apollo is the Processor of Tenant Personal Data. We process it only on your documented instructions as set out in the Terms, this DPA, and your use of the Platform’s functionality (which constitutes instructions for the features you enable).
4.3 You acknowledge that Apollo does not control your client relationships, pricing, service quality, or compliance with sector rules — you do.
4.4 Nothing in this DPA makes Apollo a joint controller of Tenant Personal Data unless required by law and explicitly agreed in writing.
5. Subject matter, duration, nature and purpose of processing
5.1 Subject matter: Provision of the Apollo SaaS platform to your property photography or related property media business.
5.2 Duration: For the period you maintain an active tenant workspace and Authorised Users access the Platform under the Terms, plus any post-termination retention period described in section 17 and Annex 1.
5.3 Nature of processing: Collection, storage, organisation, retrieval, use, disclosure by transmission, alignment, restriction, erasure, destruction, backup, and security monitoring — limited to what is necessary to operate the Platform.
5.4 Purpose of processing:
- hosting, storing, displaying, transmitting, backing up, securing, and operating Tenant Personal Data;
- enabling diary/workflow, CRM (clients/branches/contacts), orders, production, messaging, invoicing, pricing, file delivery, and client portal access;
- enforcing role-based access, tenant isolation, and audit/event logging;
- providing support and incident response relating to the Platform;
- complying with legal obligations applicable to Apollo as Processor.
5.5 Apollo will not use Tenant Personal Data for its own marketing, sell Tenant Personal Data, or use it to build advertising profiles.
6. Categories of personal data
Tenant Personal Data may include the categories below (depending on what you and your Authorised Users upload or generate):
| Category | Examples |
|---|---|
| Tenant user account and membership data | Names, email addresses, roles, profile fields (for example display name, phone), membership status, permission overrides |
| CRM — clients, branches, contacts | Client/branch names, billing email and address, agent/contact names and emails, portal linkage identifiers |
| Orders, diary and property/job data | Property addresses, postcodes, access notes, on-site contact name/phone/email, scheduling, assignments |
| Staff, editor and collaborator operational data | Staff directory entries, availability, service capabilities, and operational compensation/payment-status metadata where used |
| Messages and notes | In-app order messages, threads, operational notes and reminders stored in the Platform |
| Invoices and payment metadata (tenant side) | Client billing context, amounts, due dates, settlement status; payment record metadata — not full payment card numbers |
| Uploaded files and media | Photographs, video, floorplans, documents, previews, deliverables — file contents and metadata; may include images of people and property interiors |
| Client portal exposure | Subset of the above that you configure as visible to client portal users for a selected client/branch context |
| Audit and event metadata | Order events, workflow logs, user IDs, timestamps, event types |
7. Categories of data subjects
Data Subjects may include:
- your owners, administrators, staff, editors, and collaborators;
- your clients and their branch contacts;
- client portal users you invite or link;
- property occupants, agents, and on-site contacts named on orders;
- individuals who may appear in uploaded media;
- any other individuals whose Personal Data you or your Authorised Users enter into the Platform.
8. Controller instructions
8.1 You instruct Apollo to process Tenant Personal Data to provide the Platform in accordance with:
- the Terms;
- this DPA;
- your configuration and use of features (including invitations, CRM records, orders, portal access, invoicing, and file uploads); and
- documented written instructions you send to hello@apolloui.co.uk that are consistent with the Platform’s functionality.
8.2 Apollo will inform you if, in our opinion, an instruction infringes Data Protection Laws. Apollo may refuse or suspend Processing required to comply with law.
8.3 You are responsible for instructions given by your Authorised Users through the Platform within the permissions you grant.
8.4 Apollo may process Tenant Personal Data as necessary to maintain security, prevent abuse, and enforce the Terms (for example investigating cross-tenant access attempts), to the extent permitted by Data Protection Laws as Processor or as required by law.
9. Processor obligations
Apollo shall:
9.1 process Tenant Personal Data only on documented instructions from you, unless required by law (in which case we will inform you unless prohibited);
9.2 ensure persons authorised to process Tenant Personal Data are bound by confidentiality obligations;
9.3 implement appropriate technical and organisational measures under section 11 and Annex 2;
9.4 respect the conditions for engaging Subprocessors under section 12;
9.5 assist you with Data Subject rights and security/breach/DPIA requests under sections 14–16, considering the nature of processing and information available to us;
9.6 at your choice, delete or return Tenant Personal Data at end of services under section 17, subject to legal retention;
9.7 make available information reasonably necessary to demonstrate compliance with Article 28 UK GDPR obligations, subject to section 18;
9.8 notify you without undue delay if we become aware of a Personal Data Breach affecting Tenant Personal Data under section 16.
10. Confidentiality
10.1 Apollo shall treat Tenant Personal Data as confidential and not disclose it except:
- as necessary to provide the Platform;
- to Subprocessors under section 12;
- as you instruct through the Platform;
- as required by law or valid legal process; or
- with your prior written consent.
10.2 Apollo personnel and contractors with access to Tenant Personal Data are subject to confidentiality obligations appropriate to their role.
11. Security measures
11.1 Apollo implements appropriate technical and organisational measures for a B2B SaaS platform of this kind, having regard to the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing.
11.2 Measures in place or designed in the Platform include those listed in Annex 2. They are described at a high level; we do not represent that they meet any particular certification (for example ISO 27001 or SOC 2) unless explicitly agreed in writing.
11.3 No absolute security. You acknowledge that no system is completely secure. You must maintain strong credentials, manage Authorised User access, and notify us promptly at hello@apolloui.co.uk if you suspect compromise of your tenant or accounts.
11.4 You are responsible for configuration choices that affect security (for example portal scope, download gates, user roles, and what you upload).
12. Subprocessors
12.1 You provide general written authorisation for Apollo to engage Subprocessors to process Tenant Personal Data, subject to this section.
12.2 Apollo shall:
- maintain an up-to-date list of Subprocessors in Annex 3 (and update the published list when Subprocessors change materially);
- impose data protection terms on Subprocessors that are substantially similar to the protections in this DPA, to the extent applicable;
- remain liable to you for Subprocessor performance of obligations under Article 28 UK GDPR, unless applicable law provides otherwise.
12.3 Changes to Subprocessors. Apollo will inform you of intended additions or replacements of Subprocessors by updating Annex 3 / the published subprocessor list and, where practicable, notifying account holders by email or in-product notice. You may object on reasonable grounds relating to data protection within 14 days of notice. If we cannot reasonably accommodate the objection, you may terminate the affected services in accordance with the Terms.
12.4 Excluded from Subprocessor processing of Tenant Personal Data (Apollo as separate controller):
- Mailchimp — Mailchimp is currently used for Apollo-controlled early-access/marketing lists and the consent-gated website popup. It is not used for routine tenant workspace processing unless Apollo later enables a tenant feature that uses Mailchimp and updates this DPA/subprocessor list;
- Stripe (Apollo subscription) — billing for your Apollo subscription is Apollo controller processing, not Tenant Personal Data processing under this DPA.
12.5 Stripe Connect (tenant–client payments). Where tenant-client payment features are enabled, Stripe may process payment data as your payment provider for client transactions. Tenant invoice/payment metadata in Apollo remains Tenant Personal Data. Connect onboarding status and identifiers stored in Apollo are processed to deliver the feature.
13. International transfers
13.1 Tenant Personal Data may be processed in the United Kingdom and in other countries where Apollo or Subprocessors operate.
13.2 Apollo does not warrant that all Tenant Personal Data is stored only in the UK unless and until we have verified and documented provider regions.
13.3 Where Tenant Personal Data is transferred outside the UK and UK GDPR requires safeguards, Apollo will ensure appropriate safeguards under UK data protection law, which may include UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), Addendum to EU Standard Contractual Clauses, or another valid transfer mechanism.
13.4 Annex 3 notes known providers. Personal data may be processed in the UK, EEA and other countries where Apollo or Subprocessors operate. Updated transfer information may be provided on request at hello@apolloui.co.uk.
14. Assistance with data subject rights
14.1 You are primarily responsible for responding to Data Subjects (your clients, staff, contacts) whose Personal Data you control in the Platform.
14.2 Taking into account the nature of the processing, Apollo will assist you by appropriate technical and organisational measures, insofar as this is possible, for you to fulfil your obligation to respond to Data Subject requests to exercise rights under UK GDPR (access, rectification, erasure, restriction, portability, objection).
14.3 How assistance works (as implemented today):
- You may export or access Tenant Personal Data through Platform features where available, or request assistance at hello@apolloui.co.uk;
- Self-service full export and automated DSAR tooling may be limited; assistance may be manual within reasonable timelines;
- Requests relating to an individual’s Apollo login account (not tenant-controlled CRM content) may be handled by Apollo as Controller under the Privacy Policy — we will help route requests where unclear.
14.4 Apollo may charge reasonable fees for manifestly unfounded or excessive requests, or request reimbursement for disproportionate effort, where permitted by law.
14.5 Client portal users should normally contact you first for tenant-controlled data; see Privacy Policy section 21.
15. Assistance with security, breach notifications and DPIAs
15.1 Apollo will provide reasonable assistance to you with:
- security of processing (considering Annex 2 measures);
- data protection impact assessments (DPIAs) where required, based on information about the Platform we reasonably possess;
- prior consultation with the ICO where required,
when you request assistance at hello@apolloui.co.uk and the request relates to Tenant Personal Data processed under this DPA.
15.2 Apollo does not provide legal advice. You remain responsible for your DPIAs and regulatory consultations for your use of the Platform.
16. Personal data breach handling
16.1 Apollo will notify you without undue delay after becoming aware of a Personal Data Breach affecting Tenant Personal Data, with information reasonably available to allow you to meet your controller obligations (including ICO notification where required).
16.2 Notification will be sent to the email address associated with your tenant OWNER, billing contact, or another breach/security contact you designate in writing.
16.3 Apollo will use reasonable efforts to investigate, mitigate, and remediate breaches within our control.
16.4 Apollo’s notification does not constitute an admission of fault or liability.
16.5 You are responsible for notifying affected Data Subjects and the ICO where you are required to do so as Controller.
17. Return or deletion of data at end of services
17.1 Upon termination or expiry of your subscription or tenant workspace in accordance with the Terms, you may export Tenant Personal Data using available Platform features or by requesting assistance at hello@apolloui.co.uk before deletion.
17.2 Retention after termination. We generally retain Tenant Personal Data for a limited period after closure or cancellation to allow recovery and export, after which it may be deleted or anonymised unless we need to retain it for legal, billing, security, or dispute reasons (in which case data will be isolated and protected). Deletion may be handled manually and is not necessarily automated.
17.3 Backups. Deleted data may persist in encrypted backups for a limited period before overwrite.
17.4 Legal retention. Apollo may retain minimal records (for example audit logs or billing evidence) where required by law, even after Tenant Personal Data is deleted.
17.5 Upon your written request within the export window, Apollo will use reasonable efforts to return Tenant Personal Data in a commonly used format where technically feasible, or delete it, unless law requires retention.
18. Audits and information
18.1 Apollo will make available information reasonably necessary to demonstrate compliance with Article 28 UK GDPR obligations, which may include:
- this DPA and Annexes;
- summaries of security measures (Annex 2);
- Subprocessor list (Annex 3);
- responses to reasonable security questionnaires for B2B SaaS.
18.2 On-site audits are not included by default. If UK GDPR requires an audit and information is insufficient, you may request an audit no more than once per 12 months (unless mandated by a supervisory authority or following a material breach), subject to:
- 30 days’ prior written notice;
- confidentiality and security restrictions;
- scope limited to Tenant Personal Data and relevant controls;
- conducted during business hours without unreasonable disruption;
- you bearing your costs and reimbursing Apollo’s reasonable costs unless the audit reveals material non-compliance by Apollo.
18.3 Apollo may provide standard security documentation in lieu of on-site audit where sufficient.
19. Controller responsibilities
You shall:
19.1 ensure you have a lawful basis under Data Protection Laws for all Tenant Personal Data you upload or generate and for instructions to Apollo;
19.2 provide privacy information to your clients, staff, and other Data Subjects as required (including client portal users);
19.3 ensure Authorised Users comply with the Terms and applicable law;
19.4 configure roles, portal scope, and delivery controls appropriately;
19.5 not upload unlawful, excessive, or special-category data unless you have a valid condition and safeguards;
19.6 respond to Data Subject requests for tenant-controlled data promptly;
19.7 notify Apollo if you become aware of a Personal Data Breach affecting the Platform or your tenant;
19.8 not request Processing that infringes Data Protection Laws.
20. Liability and order of precedence
20.1 Limitation of liability in the Terms applies to claims arising under or in connection with this DPA, except where Data Protection Laws prohibit limitation.
20.2 Order of precedence:
- Signed written agreement between the parties specifically addressing data protection (if any);
- This DPA (Tenant Personal Data processor processing);
- Terms;
- Privacy Policy and Cookie Policy (transparency for Apollo controller processing — not expanding processor obligations).
20.3 Nothing in this DPA excludes liability that cannot be excluded under applicable law (including Data Protection Laws where applicable to Apollo).
21. Changes to this DPA
21.1 Apollo may update this DPA to reflect changes in law, Subprocessors, security measures, or the Platform.
21.2 Material changes will be notified by updating the published DPA and, where appropriate, email to tenant owners or in-product notice. Continued use of the Platform after the effective date of changes constitutes acceptance where permitted by law and the Terms.
21.3 If you object to a material change on reasonable data protection grounds, contact hello@apolloui.co.uk within 14 days to discuss alternatives or termination under the Terms.
22. Contact
Processor: APOLLOUI LTD
Email: hello@apolloui.co.uk
Post: 38 Mercer Avenue, Ebbsfleet Valley, Swanscombe, England, DA10 1BR
Privacy contact: hello@apolloui.co.uk
For Data Subject requests relating to tenant-controlled data, Data Subjects should contact you (the Controller) in the first instance. For Apollo account data, see the Privacy Policy.
Annex 1 — Processing details
| Field | Details |
|---|---|
| Controller | The Customer / Tenant organisation using Apollo |
| Processor | APOLLOUI LTD (17093007) |
| Subject matter | Provision of the Apollo SaaS platform |
| Duration | Term of the Terms/subscription plus post-termination limited retention for recovery/export |
| Nature and purpose | Hosting, storage, transmission, backup, security, and operation of tenant workspace features (CRM, orders, diary, production, messaging, invoicing, pricing, media delivery, client portal) |
| Categories of Personal Data | As section 6 |
| Categories of Data Subjects | As section 7 |
| Controller instructions | Terms, this DPA, Platform configuration and use, written instructions to hello@apolloui.co.uk |
| Frequency of processing | Continuous during subscription while features are used |
| Storage location | Google Firebase / Cloud Storage and related infrastructure; may involve Subprocessors in the UK, EEA and other regions (Annex 3) |
Annex 2 — Technical and organisational measures
Apollo applies measures appropriate to risk, including the following as implemented or designed in the Platform (non-exhaustive):
Access control and authentication
- Firebase Authentication for user identity (email/password and optional Google sign-in);
- httpOnly session cookie (
__session) bridge with server-side verification before granting session; - Role-based access control (RBAC) — membership roles (for example OWNER, ADMIN, STAFF, EDITOR, CLIENT) with server-side enforcement;
- Tenant isolation — application logic and Firestore security rules designed to prevent cross-tenant access using composite membership identifiers;
- Fail-closed behaviour when membership, role, or tenant context is missing or invalid;
- Least-privilege expectation for Apollo operator access to production systems.
Data protection in transit and at rest
- HTTPS/TLS for data in transit to the application;
- Cloud provider encryption for data at rest in Firebase/GCP services (per Google’s platform defaults).
Invitations and secrets
- Secure invitation tokens stored as hashes only (
tokenHash), not raw tokens in database; - Environment secrets for API keys and service credentials (not exposed in client bundles);
- Transactional invite email via Amazon SES when configured, with delivery logging.
File and media access
- Tenant-scoped storage paths in Firebase / Cloud Storage;
- Signed URLs with time-limited TTL for downloads where implemented;
- Client portal and role gates for deliverable access.
Monitoring, logging and resilience
- Order events and operational audit metadata in Firestore where implemented;
- Stripe webhook ledger for billing integrity (Apollo subscription — controller data);
- Hosting and application logging via Vercel and cloud providers;
- Backups / disaster recovery dependent on Google Cloud and operational procedures.
Organisational measures
- Confidentiality expectations for personnel with access;
- Incident response and breach notification procedures;
- Vendor review for Subprocessors listed in Annex 3.
Not claimed: ISO 27001, SOC 2, or other formal certifications unless separately documented.
Annex 3 — Subprocessors
The following Subprocessors may process Tenant Personal Data on Apollo’s behalf.
Stripe (subscription billing) is listed below for transparency. Apollo subscription billing is generally Apollo controller processing, not Tenant Personal Data under this DPA.
| Subprocessor | Processing activity | Tenant Personal Data? |
|---|---|---|
| Google Firebase / Google Cloud | Authentication, Firestore database, Cloud Storage, Cloud Functions | Yes — primary storage and processing of tenant workspace data |
| Vercel | Application hosting, CDN, serverless execution, request logs | Yes — transient processing and logs |
| Amazon Web Services (Amazon SES) | Transactional email (invitations, platform email when configured) | Yes — recipient email and message content for delivery |
| Stripe | Apollo subscription billing (your subscription to Apollo) | Generally no — listed for transparency; Apollo acts as controller for subscription billing metadata |
| Stripe Connect | Tenant–client payment processing where features are enabled | Limited — payment metadata in tenant invoices; Stripe as tenant’s payment provider |
| Google (OAuth) | Optional Google sign-in for user authentication | Yes — authentication identifiers for Authorised Users |
Not Subprocessors for Tenant Personal Data (Apollo as controller or separate relationship):
| Provider | Role |
|---|---|
| Mailchimp | Apollo early-access/marketing lists and consent-gated website popup — not tenant workspace storage |
| Mailchimp (external register-interest link) | Data you submit directly to Mailchimp on their site |
Not currently active (do not process Tenant Personal Data until enabled and listed):
- Xero or other accounting exports;
- Tenant operational email fan-out for orders/invoices (not live as described in product docs);
- Third-party analytics on marketing site.
Apollo will update this Annex when Subprocessors change.
Related documents: Terms and Conditions · Privacy Policy · Cookie Policy · Disclaimer
