Last updated: 12 August 2026
This Privacy & Data Processing Policy explains how The Apply Group Ltd collects, uses, shares, stores and protects personal data across the websites, platforms and services covered by this Policy.
The services covered by this Policy are operated by:
The Apply Group Ltd
Company No. 12938105
ICO Registration No. ZB327179
124 City Road
London EC1V 2NX
United Kingdom
Privacy enquiries:
In this Policy:
“TAG”, “we”, “us” and “our” mean The Apply Group Ltd.
“Covered Services” means the websites, applications and digital services operated by TAG that are covered by this Policy, including:
“ApplyPal” includes ApplyPal.io, app.ApplyPal.io, Institution-specific ApplyPal environments and ApplyPal widgets.
“ApplyFor Services” means ApplyForMedicine.com, ApplyForUniversity.com and ApplyForInternships.com.
“Institution” means a university, college, school, pathway provider, educational organisation, charity, internship provider, widening-participation organisation or other organisation using ApplyPal.
“Ambassador” means a student, former student, alumnus, intern, employee or other authorised person communicating with prospective students or other users through ApplyPal.
“Personal Data”, “Data Controller”, “Data Processor” and “Data Subject” have the meanings given to them under applicable data-protection legislation.
ReferPool.io is also operated by The Apply Group Ltd but is a separate service with a distinct recruitment and career-networking purpose.
ReferPool may maintain additional or product-specific privacy information.
Where a user moves from a Covered Service to ReferPool, the provisions in section 22 of this Policy apply.
This Policy applies to personal data processed in connection with activities including:
TAG acts as Data Controller where TAG determines why and how personal data is processed.
This generally includes processing connected with:
ApplyPal may also operate as technology provided to an Institution.
Where an Institution determines why personal data is processed through its ApplyPal environment, the Institution will normally be the Data Controller and TAG will normally act as its Data Processor.
This may include:
The Institution’s own privacy notice may therefore also apply.
Where required, TAG and the Institution will enter into a Data Processing Agreement governing this processing.
Even where TAG acts primarily as Processor, TAG may separately act as Controller for limited purposes such as:
The information we process depends on which Covered Service you use.
This may include:
Depending on the service, this may include:
Where relevant to ApplyForInternships or related functionality, we may process:
Where you act as an Ambassador, information may include:
Some Ambassador information is intentionally visible to prospective students or other authorised users.
ApplyPal facilitates communication between prospective students, applicants, Ambassadors and Institutions.
We may therefore process:
Authorised Institution personnel may have access to conversations within their ApplyPal environment for purposes including:
ApplyPal should therefore not be treated as an end-to-end private messaging service in which only the two conversation participants can ever access a message.
Depending on the Covered Service, we may process:
ApplyPal may help Institutions identify patterns suggesting that a prospective student is particularly engaged.
This can include activity such as:
These may be displayed as engagement or high-intent indicators.
They:
The Institution remains responsible for how it uses such information.
We may process:
We may receive information:
Some Covered Services are intended for prospective students and may be used by people under 18.
ApplyPal may also be used in widening-participation programmes involving Year 12, Year 13 and other younger users.
ApplyPal is generally intended for users aged 13 or over, unless an appropriate alternative legal and safeguarding framework applies.
Where children or young people use our services, relevant safeguards may include:
We do not use children’s personal data for behavioural advertising.
Our services do not normally require users to provide Special Category Personal Data.
However, communications or programme activity may occasionally reveal matters such as:
Users should avoid providing sensitive information unless relevant and appropriate.
Where TAG processes such information solely as Processor, the Institution is responsible for establishing the appropriate lawful basis and additional legal condition.
Where TAG acts as Controller, we will process Special Category Personal Data only where an appropriate lawful basis and additional legal condition apply.
Information may also be processed where necessary to:
Depending on the service, we may use personal data to:
Where TAG acts as Data Controller, the lawful basis depends on the processing.
We may rely on:
Where processing is necessary to provide a service you request or perform an agreement with you.
Where reasonably necessary for legitimate interests including:
provided those interests are not overridden by your rights and interests.
Where processing is required by law.
Where consent is required, including for certain:
You may withdraw consent at any time.
Where necessary in exceptional circumstances to protect life or physical safety.
Where TAG acts solely as Processor for an Institution, the Institution determines the relevant lawful basis.
ApplyPal may use AI or automated tools to assist with functions including:
Automated content may be:
An automated flag does not necessarily mean that a user has breached Platform rules.
Human review may be used where appropriate.
Where an external AI provider processes personal data on TAG’s behalf, appropriate contractual, security and international-transfer arrangements will apply.
We seek to minimise the personal data supplied to external AI services.
ApplyPal does not use AI to make final university admissions decisions or automatically accept or reject applicants.
ApplyPal may analyse or review communications to identify matters including:
Authorised TAG or Institution personnel may review flagged information where appropriate.
Serious safeguarding issues may be escalated where necessary and lawful.
Some TAG services, particularly ApplyPal, may allow users to connect with or publish content to third-party social-media services using authorised APIs.
These services may include LinkedIn and, where enabled, other social-media platforms.
Where you voluntarily connect a social-media account, TAG may receive information permitted by that platform and authorised by you.
Depending on the integration and permissions granted, this may include:
Access credentials and tokens used to operate an authorised API integration are protected and are not intended to be publicly displayed.
Where a feature allows you to post or share content through an authorised social-media API, information processed may include:
TAG will not publish to your personal social-media account merely because a sharing option is displayed.
Publication requires the relevant user action or prior authorisation for the particular feature.
Where a social-media API makes this information available and the necessary permission has been granted, TAG may receive information about interaction with published content, such as:
We only process information made available under the relevant API permissions and for purposes connected with the feature being used.
Unless a separate feature clearly tells you otherwise and obtains the necessary permission, TAG does not access your private social-media inbox or direct messages merely because you connect a social-media account.
When content is published to LinkedIn or another social-media service, that platform independently processes the content under its own privacy terms.
Deleting information from TAG does not necessarily delete a post or other information already published on the third-party platform.
You may also be able to revoke an integration through your social-media account settings.
TAG uses Hotjar, a Contentsquare service, on Covered Services where enabled to help understand how visitors interact with our websites and services.
Hotjar may provide:
Hotjar is used to improve user experience and is not used by TAG for behavioural advertising.
Where legally required, Hotjar is treated as an optional analytics technology and does not operate until the appropriate consent has been given.
Hotjar suppresses user keystroke information by default. Areas containing private conversations, sensitive data or sensitive user-generated information should also be excluded or suppressed from session capture.
TAG uses third parties where necessary to operate the Covered Services.
Whether a provider is a Processor to TAG or a Sub-Processor depends on whether TAG itself is acting as Controller or as Processor for an Institution.
Where TAG acts as Processor, it only appoints Sub-Processors subject to appropriate contractual data-protection obligations and applicable Institution authorisation.
Service: Cloud database and infrastructure
Use: ApplyPal primary production database and supporting infrastructure.
Primary ApplyPal database location: London, United Kingdom
Personal data may include:
DigitalOcean acts as a Sub-Processor where it hosts Institution-controlled ApplyPal data on behalf of TAG.
Service: Transactional email infrastructure
Resend may be used for:
Personal data may include:
Resend’s primary processing operations are in the United States. Appropriate international-transfer safeguards are used where required.
Service: User-experience analytics
Personal data may include:
Hotjar/Contentsquare uses European infrastructure for relevant European customer data and may use authorised affiliates and service providers for support and related functions.
Hotjar acts as a Processor to TAG for TAG-controlled analytics and may act as a Sub-Processor where it processes Institution-controlled data in an ApplyPal environment.
Hotjar is consent-gated where required.
TAG may appoint additional infrastructure, communications, AI, security or technical providers as its services develop.
Where a new provider processes personal data:
Institutions requiring further information about current Sub-Processors may contact:
Although ApplyPal’s primary production database is hosted in London, some service providers may process or access limited information outside the UK.
Where a restricted international transfer occurs, TAG uses an appropriate mechanism where required, which may include:
Supplementary safeguards may also be used where appropriate.
ReferPool.io is another service operated by The Apply Group Ltd.
Common ownership does not mean that personal data collected through ApplyPal or another Covered Service is automatically repurposed for ReferPool.
Using ApplyPal, ApplyForMedicine, ApplyForUniversity or ApplyForInternships does not by itself create a ReferPool account.
A Covered Service may contain links or calls to action that direct a user to ReferPool.
Opening ReferPool does not by itself transfer private ApplyPal account information, conversations or Institution records.
A user may be offered the opportunity to continue a career or employability journey through ReferPool.
Before personal data is transferred specifically for this purpose, the relevant user should be informed of:
Information transferred following an appropriate user action may include:
ReferPool’s applicable privacy information then applies to subsequent ReferPool processing.
TAG does not automatically transfer from ApplyPal to ReferPool:
Where TAG holds personal data solely as Processor for an Institution, that information is not repurposed for ReferPool unless:
ReferPool is not an ApplyPal Sub-Processor simply because it is operated by the same legal company.
Personal data may be shared with:
Where relevant to an Institution’s ApplyPal environment.
Where information is intentionally published or communicated to them.
As described in section 20.
Where you deliberately use an authorised social-sharing or integration feature.
Including lawyers, auditors, accountants and insurers where reasonably necessary.
Where disclosure is required by law, valid legal process, safeguarding need or protection of legal rights.
Under appropriate confidentiality and data-protection safeguards where relevant to an investment, financing, merger, restructuring or sale.
TAG does not sell Covered Service users’ personal data to data brokers or third parties for their own advertising purposes.
TAG maintains technical and organisational measures designed to protect personal data.
Measures may include:
No online system can provide an absolute guarantee of security.
TAG maintains processes for investigating and responding to suspected personal-data breaches.
Where TAG acts as Processor, the relevant Institution will be notified in accordance with applicable law and contractual obligations.
Where TAG acts as Controller, TAG will assess whether notification to the Information Commissioner’s Office or affected individuals is legally required.
We retain personal data for no longer than reasonably necessary for the relevant purpose.
Retention depends on matters including:
Where TAG acts as Processor, data will be deleted or returned in accordance with the relevant Institution’s instructions and Data Processing Agreement, subject to lawful retention requirements.
When personal data is no longer required, it will be deleted, anonymised or otherwise removed from ordinary operational use.
TAG uses cookies and similar technologies for purposes including:
For more information, see the The Apply Group Cookie Policy.
Depending on applicable law and the circumstances, you may have rights including:
These rights are subject to applicable legal conditions and exemptions.
Where an Institution is Controller, you should normally make your request directly to that Institution.
TAG will assist the Institution where required.
Contact:
We may verify your identity before fulfilling a request.
Operational service messages are separate from marketing.
TAG may send business or marketing communications where permitted by law.
Where consent is required, we will obtain it.
You may unsubscribe through the mechanism provided in a communication or by contacting:
Covered Services may contain links to independent third-party websites.
Those organisations are responsible for their own processing and their own privacy notices apply when you use their services.
We may update this Policy to reflect:
The current revision date will appear at the top of the Policy.
Material changes will be brought to users’ or Institutions’ attention where appropriate.
Privacy questions and complaints can be sent to:
The Apply Group Ltd
Company No. 12938105
ICO Registration No. ZB327179
124 City Road
London EC1V 2NX
United Kingdom
You also have the right to complain to the:
Information Commissioner’s Office (ICO)
or another competent supervisory authority where applicable.
We take peer-to-peer to
a whole new level.