Privacy Policy
What personal data we collect, why we hold it, who we share it with, and the rights you have over it.
Last updated 30 July 2026
Who we are
ActiveManage Ltd (company number 10448163) is a software company registered in England and Wales, with its registered office at ActiveManage Ltd., Enterprise Centre, David Lane, Basford, Nottingham, NG6 0JU. We build and operate the ActiveManage low-code platform and deliver bespoke applications on it.
We are registered with the Information Commissioner's Office under registration number ZA880120. For anything in this policy, contact us at info@activemanage.co.uk.
The two roles we play
This matters more than anything else in this policy, because it determines who is answerable to you.
When you browse this website, send us an enquiry, or become our customer, we decide why and how your data is used. We are the controller, and this policy governs.
When our customers run applications on the ActiveManage platform, they decide what data goes in and why. They are the controller; we are the processor acting on their documented instructions. If you are a patient of an NHS trust, an employee of a retailer, or a service user of any organisation that runs on ActiveManage, your relationship is with that organisation, and their privacy notice — not this one — tells you how your data is handled.
If you believe an organisation is holding your data in an ActiveManage application and you want to exercise your rights over it, approach that organisation directly. If you cannot identify them, contact us and we will pass your request to the relevant customer — we cannot act on their data ourselves without their instruction.
What we collect as controller
| What | Where it comes from | Why |
|---|---|---|
| Name, email address, company name, area of interest and your message | The contact form on this site | To answer your enquiry and, if it goes further, to scope and quote the work |
| Business contact details, correspondence and contract records | You, during a sales or delivery relationship | To perform our contract with you and keep proper business records |
| Account identifiers, sign-in events and audit records | Your use of a platform tenant we administer for you | To operate, secure and support the service |
| IP address, browser and device information, pages viewed, approximate location | Automatically, via Google Analytics | To understand how the site is used and improve it |
| Server and application logs, including IP address and request details | Automatically, on our infrastructure | Security monitoring, fault diagnosis and abuse prevention |
We do not ask for special category data through this website, and we would rather you did not put any into the contact form. We do not run credit checks, buy marketing lists, or build profiles about you from third-party sources.
Our lawful bases
| Purpose | Lawful basis |
|---|---|
| Responding to an enquiry you send us | Legitimate interests — you asked us to get in touch, and answering is what you would expect |
| Delivering a project or operating a tenant for a customer | Performance of a contract |
| Keeping accounting, tax and contractual records | Legal obligation |
| Securing our systems and investigating misuse | Legitimate interests — running a service that is not compromised |
| Analytics cookies and similar technologies | Consent (see the Cookie Policy) |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and you can object at any time using the contact details above.
Who we share it with
We do not sell personal data, and we do not share it for anyone else's marketing. We keep our supply chain deliberately short. Every organisation below is contracted under a data processing agreement and subject to our ongoing security review.
| Sub-processor | What they do for us | Where |
|---|---|---|
| Amazon Web Services | Compute, storage, networking and backups | eu-west-2 (London) |
| Stripe | Payment processing — card details are tokenised and we never store the card number | UK / EU / US |
| Website analytics, and — where a customer application enables them — Maps, reCAPTCHA and advertising | US, under the UK extension to the EU–US Data Privacy Framework |
We will also disclose data where the law requires it, to establish or defend legal claims, or to a buyer if the business is sold — in which case this policy continues to apply until you are told otherwise.
International transfers
Customer application data is hosted in the United Kingdom by default, in the AWS London region. EU or US hosting is available on request where a customer needs it.
Some of our own suppliers process limited data outside the UK. Where they do, we rely on the UK extension to the EU–US Data Privacy Framework, or on the International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.
How long we keep it
| Data | Retention |
|---|---|
| Enquiries that do not become customers | 24 months from last contact, then deleted |
| Customer contract and correspondence records | Duration of the contract plus 6 years, for limitation and tax purposes |
| Accounting records | 6 years from the end of the accounting period, as required by law |
| Security and access logs | Typically 12 months, longer where an investigation requires it |
| Analytics data | As configured in Google Analytics — currently 14 months |
| Customer application data we process | As instructed by the customer; returned or deleted on termination |
Your rights
Where we are the controller, you have the right to:
- Be told what we hold about you, and get a copy of it
- Have inaccurate data corrected
- Have data erased, where we have no continuing basis to keep it
- Restrict how we use it while a dispute is resolved
- Receive data you gave us in a portable, machine-readable form
- Object to processing we base on legitimate interests, including any direct marketing
- Withdraw consent at any time, where consent is what we relied on
Email info@activemanage.co.uk and we will respond within one month. There is no charge unless a request is manifestly unfounded or excessive. If you are unhappy with our response you can complain to the Information Commissioner's Office at ico.org.uk — though we would appreciate the chance to put it right first.
How we protect it
Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Access is role-based and default-deny, granted to vetted UK-based staff only where a job requires it, and every change is written to a tamper-evident audit trail. We hold Cyber Essentials certification, submit to the NHS Data Security and Protection Toolkit annually, map our controls to ISO 27001 Annex A, and commission CREST-certified penetration testing on every major release.
No system is perfectly secure. If we suffer a breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and tell you directly where the risk is high.
Children
This website and our sales process are aimed at businesses, not children, and we do not knowingly collect data from anyone under 18 through them. Customer applications built on the platform sometimes do serve children — in those cases the customer is the controller and is responsible for the appropriate safeguards and age-verification measures.
Changes
We update this policy when what we do changes. The date at the top is the version in force. Where a change materially affects you, we will tell customers directly rather than relying on you to re-read this page.