Hapio
JourneyThe student journey platformHubThe operational backboneAssureQuality assurance, by Provisions Plus
FoundersProve your impact, win renewalsOperationsRun the whole operation in one placeMentorsThe next best step for every young personFinanceBilling tracked and export ready
About HapioWho we are and why we built itIn your cornerThe story behind the work
PricingTrustBook a demo
Legal

Privacy Policy

Version 1.0, last updated August 2026

1. Who we are

Hapio is the trading name of People and Purpose Ventures Ltd, a company registered in England and Wales with company number 16642909, registered office at [registered office address], Crowthorne. We build software platforms for alternative provision education settings, including Hapio Journey and Hapio Hub. You can contact us about anything in this policy at hello@hapio.life.

2. The two ways we handle personal data

This distinction matters, so we set it out first.

Data we control. When you visit our website, enquire about our products, attend a demonstration, or deal with us as a client contact, we decide how and why your personal data is used. For that data we are the controller, and this policy describes what we do.

Data we process for our clients. The records held inside our platforms, including records about young people, their families and our clients' staff, belong to the education provisions and organisations that use our software. Those organisations are the controllers of that data. We process it only on their instructions, under a written Data Processing Agreement, and we never use it for our own purposes in identifiable form. If you are a young person, parent or carer and you want to know how your information is handled, or you want to exercise your data protection rights over it, please contact the provision or school that holds your record. We will assist them fully with any such request.

3. Data we collect as controller

We collect and use the following, depending on how you interact with us:

  1. Enquiries and demonstrations: your name, role, organisation, contact details and anything you include in your message, used to respond to you and follow up. Lawful basis: our legitimate interest in responding to business enquiries.
  2. Client relationship and billing contacts: names, roles and contact details of the people our clients nominate for contract, onboarding, support and invoicing purposes. Lawful basis: performance of our contract with the client and our legitimate interest in administering that relationship.
  3. Support and correspondence: emails and messages you send us, used to help you and to keep a record of what was agreed. Lawful basis: legitimate interest, or performance of a contract where you represent a client.
  4. Payment collection: Direct Debit mandates and payments are handled by GoCardless, who act as an independent controller of the payment data they collect under their own privacy notice. We see confirmation of mandate and payment status, not full bank credentials.
  5. Marketing: where we send updates about our products to business contacts, we rely on our legitimate interest in business-to-business marketing, and every message includes a way to opt out. We do not send marketing to individuals in a private capacity without consent.
  6. Website: our website uses only the cookies necessary for it to function. If we introduce analytics or any non-essential cookies, we will update this policy and ask for consent where required.

4. What we never do

We do not sell personal data. We do not share it with third parties for their own marketing. We do not use the records our clients hold in our platforms to train artificial intelligence models, and we never use those records in identifiable form for any purpose of our own. Where our platforms produce sector benchmarks, these are built only from data that has been irreversibly anonymised and aggregated so that no individual, and no single organisation, can be identified.

5. Who we share data with

We use a small number of service providers to run our business and our platforms: hosting and database infrastructure (Supabase, hosted in London, United Kingdom), email delivery (Resend), error monitoring (Sentry, EU data region, with personal data stripped from reports), AI-assisted drafting within the platform (Anthropic, receiving de-identified content only), and payment collection (GoCardless, as an independent controller). Where a provider is outside the UK, transfers are protected by a lawful transfer mechanism such as the UK Addendum to the EU Standard Contractual Clauses or the UK International Data Transfer Agreement. We may also disclose information where the law requires it.

6. How long we keep data

Enquiry correspondence is kept for up to two years from our last contact, so we can pick up where we left off if you come back to us. Client relationship and contract records are kept for the life of the client relationship and for six years afterwards, in line with limitation periods and accounting law. Data we process on behalf of clients is retained and deleted according to their instructions under the Data Processing Agreement, including any extended retention a client instructs to meet safeguarding record-keeping obligations.

7. Security

Our platforms hold sensitive information about children, and we treat that as the defining fact of how we build. Data is hosted in the United Kingdom, encrypted in transit and at rest, protected by database-level tenant isolation so that no client can see another's records, covered by role-based access controls and an audit trail of meaningful actions, and backed up daily with point-in-time recovery. Multi-factor authentication is supported for platform accounts.

8. Your rights

Where we are the controller of your personal data, you have the right to ask for a copy of it, to have it corrected or deleted, to restrict or object to our use of it, and to receive it in a portable format. To exercise any of these rights, email hello@hapio.life and we will respond within one month. You also have the right to complain to the Information Commissioner's Office (ico.org.uk), although we would welcome the chance to resolve any concern with you first.

Where the data in question is a record held in our platforms on behalf of a provision or school, that organisation is the controller: please direct your request to them, and we will support them in responding to you.

9. Children

Our website and our commercial services are directed at organisations, not at children, and we do not knowingly collect personal data from children through our website. Information about young people exists in our platforms only because the provisions and schools we serve place it there as controllers, protected by the measures described in this policy and in our Data Processing Agreement.

10. Changes to this policy

We will update this policy when our practices change, and the current version will always be available on our website with its version number and date. Material changes affecting our clients will also be notified to them directly.

Hapio

The platform family for alternative provision. Built by people who run APs.

Products
JourneyHubAssureBook a demo
For your team
FoundersOperationsMentorsFinance
Company
AboutTrustIn your corner
Legal
Privacy PolicyTerms of UseData protection
hapio.life · © 2026 People and Purpose Ventures Ltd
Hapio is a product of People and Purpose Ventures Ltd, company number 16642909.
Hapio
Products
JourneyThe student journey platformHubThe operational backboneAssureQuality assurance, by Provisions Plus
For your team
FoundersProve your impact, win renewalsOperationsRun the whole operation in one placeMentorsThe next best step for every young personFinanceBilling tracked and export ready
Pricing
About
About HapioWho we are and why we built itIn your cornerThe story behind the work
Trust
Book a demo