Privacy Policy
Version 1.4 · Effective date: 12 September 2026 · Governing law: Scotland
Scope
This Policy explains how AppGantry handles personal data in connection with its business website and mobile service offerings. It distinguishes data for which AppGantry is controller from Customer Content processed on a customer's instructions.
1 Who we are
AppGantry Ltd is a company registered in Scotland (SC892971) with registered office at 5 South Charlotte Street, Edinburgh, EH2 4AN, United Kingdom. In this Policy, "AppGantry", "we", "us" and "our" refer to AppGantry Ltd. For UK data-protection law, AppGantry is controller of the account, service-operation, security, billing and relationship data described below.
Contact the Data Protection Officer, AppGantry Ltd at contact@appgantry.com. The same address may be used for privacy enquiries and rights requests.
2 Our role and the customer's role
AppGantry acts as controller for records it creates or determines are necessary to operate the Service, including account and authentication data, memberships and roles, tester identities, the device registry, download and session telemetry, audit events, metering, billing, support and security records. This remains so where those records relate to Customer users or testers.
AppGantry acts as processor only for Customer Content: Build binaries and their contents, Customer-authored filenames, release notes and descriptions, distribution lists or content supplied by Customer, and narrowly necessary metadata processed solely on Customer's instructions. The customer normally acts as controller for that processing, which is governed by our Data Processing Agreement. A recipient identifier is processor data when it appears in a Customer-supplied distribution list or other Customer Content; account, invitation, membership, device and download records that AppGantry creates and maintains about that person are controller records. Copies of the DPA and related policies are supplied with applicable service materials or available from contact@appgantry.com. We do not inspect or reuse Build binaries except as needed to provide, secure, support and operate the Service or comply with law.
3 Personal data, purposes and lawful bases
| Category and examples | Purpose | UK GDPR lawful basis |
| Identity and contact: name, email, invite addresses, employer or organisation links | Create accounts; administer memberships, roles, invitations, support and notices | Contract; legitimate interests in operating a B2B service |
| Authentication and security: password hash, MFA/TOTP status, passkeys, recovery data, token hashes, session records | Authenticate users; prevent misuse; investigate and respond to security events | Contract; legitimate interests; legal obligation where applicable |
| Organisation administration: organisation and project memberships, roles, tester identities, invitation and provenance links | Provide and administer the Service; control access; maintain operational records and support users | Contract; legitimate interests |
| Device and provisioning data: iOS device UDID, device name, model and operating system | Register and manage authorised test devices and provisioning workflows | Contract; legitimate interests |
| Technical and activity data: coarse subnet/IP and network metadata, user-agent, session and download activity, audit events | Deliver downloads; secure, troubleshoot and audit the Service; prevent abuse | Legitimate interests; contract; legal obligation where applicable |
| Usage and metering: hosted storage retained, uploaded and downloaded/distributed bytes, plan and feature use | Measure consumption, apply spend caps and credit, manage Plans and improve operations | Contract; legitimate interests |
| Credit, billing and transaction records | Administer credit, purchases, refunds, accounting and tax with Paddle | Contract; legal obligation; legitimate interests |
| Customer-directed integration credentials: encrypted or sealed credentials for App Store Connect, Google Play, Microsoft Intune or Enterprise BYOSA | Operate the connection selected by Customer and send or store data at Customer's direction | Contract |
| Support, privacy and legal correspondence | Answer enquiries, resolve issues, manage data-subject requests and establish legal claims | Contract; legal obligation; legitimate interests |
| Marketing choices and business contact details | Send consented marketing and limited relevant B2B communications; record opt-outs | Consent; legitimate interests, with a right to object |
Where we rely on legitimate interests, those interests include operating and securing a business service, administering customer relationships, improving reliability, preventing fraud and communicating relevant B2B information. We balance those interests against individual rights. Where consent applies, it may be withdrawn at any time without affecting earlier processing.
4 Sources
We receive data directly from users, customer administrators and invite senders; automatically from browsers, devices and use of the Service; from Customer's configured identity, application store, device-management or storage systems; and from service providers such as Paddle where needed to reconcile subscriptions, payments, refunds or fraud controls.
5 Sharing and recipients
We disclose personal data only where needed to provide and protect the Service, complete a transaction, comply with law, establish or defend claims, or complete a corporate transaction with appropriate confidentiality protections. Recipients include authorised customer administrators, professional advisers, public authorities where legally required, and the providers in our Subprocessor List.
Confirmed providers include Microsoft Azure, Paddle, SMTP2GO, Brevo (Sendinblue), bunny.net, Sentry EU, PostHog EU for server-side feature flags, and hCaptcha where enabled. Paddle may be an independent controller for payment, fraud, tax and legal duties.
Where Customer configures App Store Connect, Google Play, Microsoft Intune or Enterprise BYOSA, AppGantry sends or stores data using Customer credentials at Customer's direction. Apple device provisioning may transmit a device identifier, name, model and operating-system information. These Customer-selected providers are recipients for that activity, not AppGantry-appointed subprocessors. BYOSA stores Build artifacts in Customer's own Microsoft Azure tenant while AppGantry retains operational metadata and encrypted or sealed access configuration.
We do not sell personal data or use it for cross-context behavioural advertising. We do not currently use browser analytics or advertising trackers. PostHog is used for server-side feature flags, not browser analytics capture.
6 International processing
Personal data may be processed in the United Kingdom, European Economic Area and other locations where AppGantry or its providers operate. Where UK data-protection law restricts a transfer, we use an applicable lawful mechanism, such as an adequacy regulation or approved contractual safeguards, and supplementary measures where appropriate. Provider-specific information is available in the Subprocessor List or on request.
7 Retention
We retain personal data only for as long as reasonably needed for the purposes described, then delete, anonymise or restrict it unless law requires longer retention.
| Record | Typical period | Notes |
| Build artifacts | Intended defaults: Team 30 days; Business 12 months; Enterprise custom | Scheduled automatic expiry applies only where enabled and configured; otherwise Customer deletion or other lifecycle events govern. Hosted prepaid credit-exhaustion reclamation is active. Enterprise BYOSA storage follows Customer's Azure settings. |
| Audit records | Customer-determined; tier defaults are Team 90 days, Business 365 days, Enterprise 730 days | Defaults apply where no different supported setting is agreed or configured; they are not fixed minimums or absolute caps, and remain subject to legal/security preservation. |
| Organisation deletion requested by an authorised administrator | Immediate and irreversible | Customer must first retrieve required Builds and request any needed processor-data copy. Cancellation of a paid subscription does not itself delete the organisation. |
| Developer Account deletion request | 30-day cancellation/recovery window | The request locks the Account. Hard deletion occurs when the deletion process runs after the window, subject to sole-administrator safeguards and lawful retention. |
| Expired trial organisation | 30-day trial grace period | Access may be restored by activation during the grace period. Automatic post-trial organisation deletion is deployment/configuration dependent. |
| Hosted prepaid Builds after credit exhaustion | 30-day reclamation period | Credit-exhaustion Build reclamation is active and distinct from trial expiry and organisation deletion. |
| Individual personal-data export archive | 7 days | The personal-data export download link expires after seven days; it is not an organisation Customer Content or Build-binary export. |
| Customer-directed integration credentials | Connection lifecycle | Encrypted or sealed credentials are removed when the connection, project or organisation is deleted, subject to protected backup rotation and lawful preservation. |
| Usage and metering records | 2 years | Supports service measurement, billing and disputes. |
| Credit, payment and accounting records | Applicable statutory periods | Retained as required for accounting, tax, payment and dispute obligations. |
| Download activity and network metadata | No current automated age-based expiry | Records may remain for the life of the download-event record. A 24-month maximum is planned but is not yet enforced. |
| Azure Log Analytics | 30 days | Operational telemetry retention. |
| Error and performance reports | Provider-configured | Retention follows the configured Sentry provider settings; AppGantry's intended maximum is 90 days. |
| Billing, tax, security and rights-request records | As legally or operationally required | May be restricted or pseudonymised rather than immediately erased. |
8 Security
We use technical and organisational measures appropriate to the service and risk, including TLS in transit, Azure encryption at rest, Argon2 password hashing, hashed tokens, scoped and revocable personal access tokens, MFA/TOTP, recovery codes, passkeys, tenant authorisation, separation of public and administrative surfaces, managed identities, Key Vault, logging, redaction, backups and recovery measures. Business and Enterprise support SSO/SAML. No internet service can eliminate all risk. Our Security Overview provides further non-contractual detail.
9 Your rights
Subject to conditions and exemptions in law, individuals may request access, correction, erasure, restriction, portability, or objection to processing. They may withdraw consent and may object at any time to direct marketing. Where AppGantry processes Customer Content only for a customer, we may refer the request to that customer and assist it as processor.
To exercise a right, email contact@appgantry.com. We may need to verify identity and authority. You may complain to the UK Information Commissioner's Office at ico.org.uk, or another competent supervisory authority.
10 United States state privacy rights
Where applicable US state privacy law applies, residents may request to know or access the categories and specific pieces of personal data we hold, and may request deletion or correction. They may opt out of sale, sharing or processing for cross-context behavioural advertising, and will not be discriminated against for exercising a right. An authorised agent may submit a request where permitted; we may verify the resident, the agent's authority and the request. Residents may appeal a denied request where applicable by replying to our decision.
The categories of personal data and recipients are disclosed above. AppGantry does not sell or share personal data for cross-context behavioural advertising and does not use browser advertising trackers. We honour Global Privacy Control as a rejection of optional cookies. Our Do Not Sell or Share notice provides an additional rights route; residents may also exercise rights directly by emailing contact@appgantry.com.
11 Marketing
We send optional marketing where consent has been given and provide an unsubscribe method. We may also send limited, relevant B2B marketing where legitimate interests permit, taking account of role, relationship and reasonable expectations. Every such message provides an opt-out. Service, security and legal notices are not marketing.
12 Cookies and similar technologies
Our Cookie Policy describes first-party consent and session cookies and conditional Paddle.js and hCaptcha storage. It is supplied with applicable service materials or available from contact@appgantry.com. We currently use no browser analytics or advertising tracking. If optional analytics is introduced, it will be consent-gated where required.
13 Automated decisions, children and business use
We do not make solely automated decisions about individuals that produce legal or similarly significant effects. The Service is for business and professional customers. Users must be at least 18; the Service is not directed to children.
14 Changes and contact
We may update this Policy to reflect legal, service or provider changes. We will identify the version and effective date and give reasonable notice of material changes by email or in the Service where appropriate.
AppGantry Ltd ยท SC892971
5 South Charlotte Street, Edinburgh, EH2 4AN, United Kingdom
Data Protection Officer, AppGantry Ltd: contact@appgantry.com
Questions about this document? support@appgantry.com.