Privacy & Data Processing Policy


Last updated: 12 August 2026

This Privacy & Data Processing Policy explains how The Apply Group Ltd collects, uses, shares, stores and protects personal data across the websites, platforms and services covered by this Policy.

1. Who We Are

The services covered by this Policy are operated by:

The Apply Group Ltd
Company No. 12938105
ICO Registration No. ZB327179
124 City Road
London EC1V 2NX
United Kingdom

Privacy enquiries: privacy@theapplygroup.com


2. Definitions and Services Covered

In this Policy:

“TAG”, “we”, “us” and “our” mean The Apply Group Ltd.

“Covered Services” means the websites, applications and digital services operated by TAG that are covered by this Policy, including:

“ApplyPal” includes ApplyPal.io, app.ApplyPal.io, Institution-specific ApplyPal environments and ApplyPal widgets.

“ApplyFor Services” means ApplyForMedicine.com, ApplyForUniversity.com and ApplyForInternships.com.

“Institution” means a university, college, school, pathway provider, educational organisation, charity, internship provider, widening-participation organisation or other organisation using ApplyPal.

“Ambassador” means a student, former student, alumnus, intern, employee or other authorised person communicating with prospective students or other users through ApplyPal.

“Personal Data”, “Data Controller”, “Data Processor” and “Data Subject” have the meanings given to them under applicable data-protection legislation.

ReferPool

ReferPool.io is also operated by The Apply Group Ltd but is a separate service with a distinct recruitment and career-networking purpose.

ReferPool may maintain additional or product-specific privacy information.

Where a user moves from a Covered Service to ReferPool, the provisions in section 22 of this Policy apply.


3. Scope of Processing

This Policy applies to personal data processed in connection with activities including:


4. When TAG Is the Data Controller

TAG acts as Data Controller where TAG determines why and how personal data is processed.

This generally includes processing connected with:


5. When an Institution Is the Data Controller

ApplyPal may also operate as technology provided to an Institution.

Where an Institution determines why personal data is processed through its ApplyPal environment, the Institution will normally be the Data Controller and TAG will normally act as its Data Processor.

This may include:

The Institution’s own privacy notice may therefore also apply.

Where required, TAG and the Institution will enter into a Data Processing Agreement governing this processing.

Even where TAG acts primarily as Processor, TAG may separately act as Controller for limited purposes such as:


6. Personal Data We May Collect

The information we process depends on which Covered Service you use.

Identity and Contact Information

This may include:

Education and Application Information

Depending on the service, this may include:

Career and Internship Information

Where relevant to ApplyForInternships or related functionality, we may process:

Ambassador Information

Where you act as an Ambassador, information may include:

Some Ambassador information is intentionally visible to prospective students or other authorised users.


7. Conversation and Communication Data

ApplyPal facilitates communication between prospective students, applicants, Ambassadors and Institutions.

We may therefore process:

Authorised Institution personnel may have access to conversations within their ApplyPal environment for purposes including:

ApplyPal should therefore not be treated as an end-to-end private messaging service in which only the two conversation participants can ever access a message.


8. Usage, Engagement and Analytics Data

Depending on the Covered Service, we may process:


9. Applicant Engagement and High-Intent Signals

ApplyPal may help Institutions identify patterns suggesting that a prospective student is particularly engaged.

This can include activity such as:

These may be displayed as engagement or high-intent indicators.

They:

The Institution remains responsible for how it uses such information.


10. Technical and Security Data

We may process:


11. How We Obtain Personal Data

We may receive information:


12. Children and Users Under 18

Some Covered Services are intended for prospective students and may be used by people under 18.

ApplyPal may also be used in widening-participation programmes involving Year 12, Year 13 and other younger users.

ApplyPal is generally intended for users aged 13 or over, unless an appropriate alternative legal and safeguarding framework applies.

Where children or young people use our services, relevant safeguards may include:

We do not use children’s personal data for behavioural advertising.


13. Special Category and Sensitive Personal Data

Our services do not normally require users to provide Special Category Personal Data.

However, communications or programme activity may occasionally reveal matters such as:

Users should avoid providing sensitive information unless relevant and appropriate.

Where TAG processes such information solely as Processor, the Institution is responsible for establishing the appropriate lawful basis and additional legal condition.

Where TAG acts as Controller, we will process Special Category Personal Data only where an appropriate lawful basis and additional legal condition apply.

Information may also be processed where necessary to:


14. Why We Use Personal Data

Depending on the service, we may use personal data to:


15. Lawful Bases

Where TAG acts as Data Controller, the lawful basis depends on the processing.

We may rely on:

Contract

Where processing is necessary to provide a service you request or perform an agreement with you.

Legitimate Interests

Where reasonably necessary for legitimate interests including:

provided those interests are not overridden by your rights and interests.

Legal Obligation

Where processing is required by law.

Consent

Where consent is required, including for certain:

You may withdraw consent at any time.

Vital Interests

Where necessary in exceptional circumstances to protect life or physical safety.

Where TAG acts solely as Processor for an Institution, the Institution determines the relevant lawful basis.


16. Artificial Intelligence and Automated Tools

ApplyPal may use AI or automated tools to assist with functions including:

Automated content may be:

An automated flag does not necessarily mean that a user has breached Platform rules.

Human review may be used where appropriate.

Where an external AI provider processes personal data on TAG’s behalf, appropriate contractual, security and international-transfer arrangements will apply.

We seek to minimise the personal data supplied to external AI services.

ApplyPal does not use AI to make final university admissions decisions or automatically accept or reject applicants.


17. Safeguarding and Moderation

ApplyPal may analyse or review communications to identify matters including:

Authorised TAG or Institution personnel may review flagged information where appropriate.

Serious safeguarding issues may be escalated where necessary and lawful.


18. LinkedIn and Other Social-Media APIs

Some TAG services, particularly ApplyPal, may allow users to connect with or publish content to third-party social-media services using authorised APIs.

These services may include LinkedIn and, where enabled, other social-media platforms.

Social-media authentication and connections

Where you voluntarily connect a social-media account, TAG may receive information permitted by that platform and authorised by you.

Depending on the integration and permissions granted, this may include:

Access credentials and tokens used to operate an authorised API integration are protected and are not intended to be publicly displayed.

Publishing and sharing

Where a feature allows you to post or share content through an authorised social-media API, information processed may include:

TAG will not publish to your personal social-media account merely because a sharing option is displayed.

Publication requires the relevant user action or prior authorisation for the particular feature.

Engagement information

Where a social-media API makes this information available and the necessary permission has been granted, TAG may receive information about interaction with published content, such as:

We only process information made available under the relevant API permissions and for purposes connected with the feature being used.

Private messages and social-media inboxes

Unless a separate feature clearly tells you otherwise and obtains the necessary permission, TAG does not access your private social-media inbox or direct messages merely because you connect a social-media account.

Third-party responsibility

When content is published to LinkedIn or another social-media service, that platform independently processes the content under its own privacy terms.

Deleting information from TAG does not necessarily delete a post or other information already published on the third-party platform.

You may also be able to revoke an integration through your social-media account settings.


19. Hotjar and User-Experience Analytics

TAG uses Hotjar, a Contentsquare service, on Covered Services where enabled to help understand how visitors interact with our websites and services.

Hotjar may provide:

Hotjar is used to improve user experience and is not used by TAG for behavioural advertising.

Where legally required, Hotjar is treated as an optional analytics technology and does not operate until the appropriate consent has been given.

Hotjar suppresses user keystroke information by default. Areas containing private conversations, sensitive data or sensitive user-generated information should also be excluded or suppressed from session capture.


20. Our Processors, Sub-Processors and Service Providers

TAG uses third parties where necessary to operate the Covered Services.

Whether a provider is a Processor to TAG or a Sub-Processor depends on whether TAG itself is acting as Controller or as Processor for an Institution.

Where TAG acts as Processor, it only appoints Sub-Processors subject to appropriate contractual data-protection obligations and applicable Institution authorisation.

DigitalOcean

Service: Cloud database and infrastructure

Use: ApplyPal primary production database and supporting infrastructure.

Primary ApplyPal database location: London, United Kingdom

Personal data may include:

DigitalOcean acts as a Sub-Processor where it hosts Institution-controlled ApplyPal data on behalf of TAG.

Resend – Plus Five Five, Inc.

Service: Transactional email infrastructure

Resend may be used for:

Personal data may include:

Resend’s primary processing operations are in the United States. Appropriate international-transfer safeguards are used where required.

Hotjar / Contentsquare

Service: User-experience analytics

Personal data may include:

Hotjar/Contentsquare uses European infrastructure for relevant European customer data and may use authorised affiliates and service providers for support and related functions.

Hotjar acts as a Processor to TAG for TAG-controlled analytics and may act as a Sub-Processor where it processes Institution-controlled data in an ApplyPal environment.

Hotjar is consent-gated where required.

Additional Providers

TAG may appoint additional infrastructure, communications, AI, security or technical providers as its services develop.

Where a new provider processes personal data:

Institutions requiring further information about current Sub-Processors may contact: privacy@theapplygroup.com


21. International Transfers

Although ApplyPal’s primary production database is hosted in London, some service providers may process or access limited information outside the UK.

Where a restricted international transfer occurs, TAG uses an appropriate mechanism where required, which may include:

Supplementary safeguards may also be used where appropriate.


22. ApplyPal and ReferPool

ReferPool.io is another service operated by The Apply Group Ltd.

Common ownership does not mean that personal data collected through ApplyPal or another Covered Service is automatically repurposed for ReferPool.

No automatic ReferPool account

Using ApplyPal, ApplyForMedicine, ApplyForUniversity or ApplyForInternships does not by itself create a ReferPool account.

Links to ReferPool

A Covered Service may contain links or calls to action that direct a user to ReferPool.

Opening ReferPool does not by itself transfer private ApplyPal account information, conversations or Institution records.

Optional transfer

A user may be offered the opportunity to continue a career or employability journey through ReferPool.

Before personal data is transferred specifically for this purpose, the relevant user should be informed of:

Information transferred following an appropriate user action may include:

ReferPool’s applicable privacy information then applies to subsequent ReferPool processing.

Information not transferred by default

TAG does not automatically transfer from ApplyPal to ReferPool:

Institution-controlled data

Where TAG holds personal data solely as Processor for an Institution, that information is not repurposed for ReferPool unless:

ReferPool is not an ApplyPal Sub-Processor simply because it is operated by the same legal company.


23. Sharing Personal Data

Personal data may be shared with:

Institutions

Where relevant to an Institution’s ApplyPal environment.

Other authorised users

Where information is intentionally published or communicated to them.

Processors and Sub-Processors

As described in section 20.

Social-media platforms

Where you deliberately use an authorised social-sharing or integration feature.

Professional advisers

Including lawyers, auditors, accountants and insurers where reasonably necessary.

Authorities

Where disclosure is required by law, valid legal process, safeguarding need or protection of legal rights.

Corporate transaction participants

Under appropriate confidentiality and data-protection safeguards where relevant to an investment, financing, merger, restructuring or sale.

TAG does not sell Covered Service users’ personal data to data brokers or third parties for their own advertising purposes.


24. Security

TAG maintains technical and organisational measures designed to protect personal data.

Measures may include:

No online system can provide an absolute guarantee of security.


25. Personal Data Breaches

TAG maintains processes for investigating and responding to suspected personal-data breaches.

Where TAG acts as Processor, the relevant Institution will be notified in accordance with applicable law and contractual obligations.

Where TAG acts as Controller, TAG will assess whether notification to the Information Commissioner’s Office or affected individuals is legally required.


26. Retention

We retain personal data for no longer than reasonably necessary for the relevant purpose.

Retention depends on matters including:

Where TAG acts as Processor, data will be deleted or returned in accordance with the relevant Institution’s instructions and Data Processing Agreement, subject to lawful retention requirements.

When personal data is no longer required, it will be deleted, anonymised or otherwise removed from ordinary operational use.


27. Cookies

TAG uses cookies and similar technologies for purposes including:

For more information, see the The Apply Group Cookie Policy.


28. Your Rights

Depending on applicable law and the circumstances, you may have rights including:

These rights are subject to applicable legal conditions and exemptions.

Institution-controlled data

Where an Institution is Controller, you should normally make your request directly to that Institution.

TAG will assist the Institution where required.

TAG-controlled data

Contact: privacy@theapplygroup.com

We may verify your identity before fulfilling a request.


29. Marketing

Operational service messages are separate from marketing.

TAG may send business or marketing communications where permitted by law.

Where consent is required, we will obtain it.

You may unsubscribe through the mechanism provided in a communication or by contacting: privacy@theapplygroup.com


30. Third-Party Websites

Covered Services may contain links to independent third-party websites.

Those organisations are responsible for their own processing and their own privacy notices apply when you use their services.


31. Changes to This Policy

We may update this Policy to reflect:

The current revision date will appear at the top of the Policy.

Material changes will be brought to users’ or Institutions’ attention where appropriate.


32. Complaints and Contact

Privacy questions and complaints can be sent to:

The Apply Group Ltd
Company No. 12938105
ICO Registration No. ZB327179
124 City Road
London EC1V 2NX
United Kingdom

privacy@theapplygroup.com

You also have the right to complain to the:

Information Commissioner’s Office (ICO)

or another competent supervisory authority where applicable.

We take peer-to-peer to
a whole new level.

School

University

Scholarship

Internship

Mentor

Tutors

Coach

Alumni

Career

Job

Peers

School

University

Scholarship

Internship

Mentor

Tutors

Coach

Alumni

Career

Job

Peers

School

University

Scholarship

Internship

Mentor

Tutors

Coach

Alumni

Career

Job

Peers

School

University

Scholarship

Internship

Mentor

Tutors

Coach

Alumni

Career

Job

Peers

Reach Us

©2026 The Apply Group Ltd. All Rights Reserved.

ApplyPal