Privacy Policy
Last Updated: 29 July 2026
This Privacy Policy explains what personal data Approov Limited ("Approov", "we", "us") collects, how we use and share it, and the rights and choices you have. We are committed to data minimisation, transparency, and protecting personal data to the highest global standards, including the UK GDPR and Data Protection Act 2018, the EU GDPR, the Swiss FADP, and applicable US state privacy laws.
We collect business contact information from website visitors and customers to run our business — never to sell. For end users of mobile apps protected by Approov, we act as a data processor on behalf of the app provider: our service is engineered so that we do not know who you are, we do not track individuals, and we never sell personal data or use it to train AI models. Our security and privacy documentation, including our Data Processing Addendum, SOC 2 Type II report, and list of service providers, is available in the Approov Trust Center.
1. Who We Are and Scope
Approov Limited is a company registered in Scotland (No. SC224237) providing mobile app and API security services. Approov Limited is the controller of personal data described in this Policy unless stated otherwise. Data may be shared with Approov Inc., our US subsidiary, for the operational purposes described below.
This Policy applies to:
-
Website visitors — people who visit approov.io, access resources, register for webinars or request demos or trials.
-
Customers and administrative users — organisations that subscribe to the Approov service and the individuals who administer it.
-
End users of protected apps — users of mobile applications that embed the Approov SDK. For end users, Approov acts as a data processor on behalf of the app provider — see Section 3.
- Job applicants — individuals applying for roles at Approov.
2. Personal Data We Collect and Why
A. Website visitors: When you fill in a form, register for a webinar, request a resource, demo or trial, we collect the details you provide: typically name, email address, job title, company and phone number. We also collect website usage data (pages visited, session information, IP address, browser type) through cookies and similar technologies, as described in our Cookie Policy. We use this data to respond to your requests, operate and improve our website, and — subject to your choices in Section 4 — send you relevant communications. Legal bases: consent, and our legitimate interests in operating and promoting our business.
B. Customers and administrative users: When your organisation registers for the Approov service, we collect account and contact information, login credentials, billing details, support requests, and administrative activity logs used to secure customer accounts. Payment card details are collected and processed directly by our payment providers; we do not store or have access to full card numbers. We use this data to provide, secure, bill and support the service and to manage our relationship with your organisation. Legal bases: performance of a contract, legitimate interests, and legal obligations (for example, financial record-keeping).
C. Job applicants: We collect the contact and biographical information you provide (such as your CV, education and employment history). If we make an offer, we may carry out pre-employment checks through a trusted provider, covering right to work, identity, and — where permitted by law — criminal record, education and employment verification. Legal bases: steps prior to entering a contract, legitimate interests, and legal obligations.
We do not knowingly collect special category data (such as health, biometric or political information) unless you volunteer it or the law requires it.
3. End Users of Apps Protected by Approov
Approov is a security service embedded by app providers to verify that requests to their servers come from genuine, untampered instances of their apps. It is engineered on privacy-by-design and data-minimisation principles:
-
We do not know who you are: The Approov service does not collect names, email addresses, account details, precise location, contacts, messages, browsing history or any content from your device.
-
The only personal data processed is your IP address, which is transmitted as an inherent part of internet requests. It is used transiently for security and fraud-prevention purposes and is anonymised using a keyed one-way hash before being written to operational logs, which are retained for no more than 60 days.
-
Everything else is anonymised. App install identifiers are derived from an operating-system identifier that is anonymised before our SDK accesses it, and device integrity signals are processed as pass/fail indicators and cryptographic signatures rather than raw device information.
-
No tracking, no profiling, no ads, no sale, no AI training on personal data. We do not use end-user data to profile individuals, serve advertising, track users across apps or services, and we never sell it or use personal data to train AI or machine-learning models.
-
Processing takes place only in the United Kingdom and the European Economic Area.
-
Anonymised data — which is not personal data — may be retained and used for customer support, billing, security research and improving our threat detection, under contractual safeguards that prohibit any attempt to re-identify individuals.
For end-user data, the provider of the app you are using is the data controller, and Approov processes data on their behalf under our Data Processing Addendum. To exercise privacy rights relating to an app you use, please contact the app provider; because Approov cannot identify individuals, we are generally unable to link any data to you.
4. Marketing Communications and Your Choices
We send marketing communications — such as newsletters, event invitations and product updates — only in accordance with the law of the country you are in:
-
Where confirmed ("double") opt-in is required, such as Germany, Austria and Switzerland, we send a confirmation email when you sign up and add you to our marketing lists only after you confirm.
-
Elsewhere, we rely on your opt-in consent or, for existing business contacts and where permitted (for example under the UK's business-to-business rules), our legitimate interest in communicating with professionals about relevant products.
Every marketing email we send includes an unsubscribe link. You can opt out at any time by using that link or emailing privacy@approov.io; opting out does not affect transactional messages such as invoices, service notices and security alerts. We may use profiling in the form of lead scoring to make our communications more relevant; we do not make any decisions with legal or similarly significant effects by automated means.
5. How We Share Personal Data
We do not sell or rent personal data. We share it only with:
-
Service providers that support our operations — website hosting and analytics, CRM and marketing, meeting and webinar platforms, billing and payment processing, and support/incident management — under contracts that protect your data. Our current list of providers is maintained in the Approov Trust Center. These providers handle business contact and billing data only; they do not receive end-user data from protected apps (see Section 3).
-
Approov group companies — Approov Limited (UK) and Approov Inc. (US) — for the operational purposes described in this Policy.
-
Professional advisers and authorities where required by law, court order, or to protect rights, safety, or investigate fraud, in response to valid requests.
-
A successor entity in connection with a merger, acquisition, financing or sale of assets, in which case this Policy will continue to apply and we will notify you of any change of controller.
-
In aggregated or anonymised form that can no longer identify you, for analytics, research, reporting and service improvement; anonymised data is no longer personal data under the UK GDPR.
6. International Transfers
Approov is headquartered in the UK with an office in the US. Business contact, billing and support data may be processed in the United States and other countries by us and our service providers. End-user data from protected apps is processed only in the UK and EEA, as described in Section 3. Whenever personal data is transferred outside the UK, EEA or Switzerland, we use appropriate safeguards: the UK International Data Transfer Agreement or Addendum, the EU Standard Contractual Clauses (with Swiss adaptations where applicable), or transfers to providers certified under the EU-US, UK and Swiss Data Privacy Framework programs.
7. Security and Retention
We maintain appropriate technical and organisational security measures — including encryption in transit and at rest, access controls, monitoring, and incident response procedures — and hold SOC 2 Type II attestation, available through the Approov Trust Center. Access to personal data is limited to those who need it, under confidentiality obligations.
We retain personal data only as long as necessary for the purposes described in this Policy, including legal, tax and accounting obligations, and then delete or anonymise it. End-user data lifecycles are described in Section 3 and in our Data Processing Addendum. We maintain procedures to detect, respond to and, where legally required, notify individuals and regulators of personal data breaches.
8. Your Rights
Depending on where you live, you have rights to: access the personal data we hold about you; correct inaccurate data; request deletion; object to or restrict certain processing (including any processing based on legitimate interests); receive your data in a portable format; withdraw consent at any time (without affecting prior processing); and opt out of marketing.
To exercise any of these rights, contact privacy@approov.io. We respond within the timeframes required by law (usually one month) and do not charge a fee unless a request is manifestly unfounded or excessive. We may ask for proof of identity. You also have the right to complain to your data protection authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, your national supervisory authority; in Switzerland, the FDPIC.
9. US State Privacy Rights
If you are a resident of California or another US state with a comprehensive privacy law, you have the right to know what personal information we collect, to access, correct and delete it, and not to be discriminated against for exercising your rights. The categories we collect are identifiers and professional information (such as name, business email and job title), commercial information (records of services purchased), and internet activity (interactions with our website). We do not "sell" or "share" personal information as those terms are defined under the CCPA and similar laws, and we do not use or disclose sensitive personal information for purposes requiring a right to limit. We honor opt-out preference signals, such as Global Privacy Control, where required by law. To exercise your rights, or to do so through an authorised agent, contact privacy@approov.io.
10. Children's Privacy
Our website and services are directed at businesses and are not intended for children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact privacy@approov.io and we will delete it.
11. Third-Party Links
Our website contains links to other sites. We are not responsible for their privacy practices and encourage you to review their privacy statements.
12. Changes to This Policy
We may update this Policy from time to time. The current version, with its effective date, will always be posted on this page, and material changes will be highlighted or notified where required by law. Previous versions are available on request.
13. Contact Us
Questions, concerns or requests about this Policy or our privacy practices:
Email: privacy@approov.io Post: Data Protection Officer, Approov Limited, 6 South Charlotte Street, Edinburgh, EH2 4AW, United Kingdom
Phone: +44 131 655 1500
Our security and privacy documentation — including our Data Processing Addendum, SOC 2 Type II report, Service Level Agreement and service provider list — is available in the Approov Trust Center.
Request a Demo
Give us 30 minutes and our security experts will show you how to protect your revenue and business data by deploying Approov to secure your mobile apps.
