Version 1.0, last updated August 2026
Hapio is the trading name of People and Purpose Ventures Ltd, a company registered in England and Wales with company number 16642909, registered office at [registered office address], Crowthorne. We build software platforms for alternative provision education settings, including Hapio Journey and Hapio Hub. You can contact us about anything in this policy at hello@hapio.life.
This distinction matters, so we set it out first.
Data we control. When you visit our website, enquire about our products, attend a demonstration, or deal with us as a client contact, we decide how and why your personal data is used. For that data we are the controller, and this policy describes what we do.
Data we process for our clients. The records held inside our platforms, including records about young people, their families and our clients' staff, belong to the education provisions and organisations that use our software. Those organisations are the controllers of that data. We process it only on their instructions, under a written Data Processing Agreement, and we never use it for our own purposes in identifiable form. If you are a young person, parent or carer and you want to know how your information is handled, or you want to exercise your data protection rights over it, please contact the provision or school that holds your record. We will assist them fully with any such request.
We collect and use the following, depending on how you interact with us:
We do not sell personal data. We do not share it with third parties for their own marketing. We do not use the records our clients hold in our platforms to train artificial intelligence models, and we never use those records in identifiable form for any purpose of our own. Where our platforms produce sector benchmarks, these are built only from data that has been irreversibly anonymised and aggregated so that no individual, and no single organisation, can be identified.
We use a small number of service providers to run our business and our platforms: hosting and database infrastructure (Supabase, hosted in London, United Kingdom), email delivery (Resend), error monitoring (Sentry, EU data region, with personal data stripped from reports), AI-assisted drafting within the platform (Anthropic, receiving de-identified content only), and payment collection (GoCardless, as an independent controller). Where a provider is outside the UK, transfers are protected by a lawful transfer mechanism such as the UK Addendum to the EU Standard Contractual Clauses or the UK International Data Transfer Agreement. We may also disclose information where the law requires it.
Enquiry correspondence is kept for up to two years from our last contact, so we can pick up where we left off if you come back to us. Client relationship and contract records are kept for the life of the client relationship and for six years afterwards, in line with limitation periods and accounting law. Data we process on behalf of clients is retained and deleted according to their instructions under the Data Processing Agreement, including any extended retention a client instructs to meet safeguarding record-keeping obligations.
Our platforms hold sensitive information about children, and we treat that as the defining fact of how we build. Data is hosted in the United Kingdom, encrypted in transit and at rest, protected by database-level tenant isolation so that no client can see another's records, covered by role-based access controls and an audit trail of meaningful actions, and backed up daily with point-in-time recovery. Multi-factor authentication is supported for platform accounts.
Where we are the controller of your personal data, you have the right to ask for a copy of it, to have it corrected or deleted, to restrict or object to our use of it, and to receive it in a portable format. To exercise any of these rights, email hello@hapio.life and we will respond within one month. You also have the right to complain to the Information Commissioner's Office (ico.org.uk), although we would welcome the chance to resolve any concern with you first.
Where the data in question is a record held in our platforms on behalf of a provision or school, that organisation is the controller: please direct your request to them, and we will support them in responding to you.
Our website and our commercial services are directed at organisations, not at children, and we do not knowingly collect personal data from children through our website. Information about young people exists in our platforms only because the provisions and schools we serve place it there as controllers, protected by the measures described in this policy and in our Data Processing Agreement.
We will update this policy when our practices change, and the current version will always be available on our website with its version number and date. Material changes affecting our clients will also be notified to them directly.