← Back

Privacy Policy

1. Who We Are

AptitudeTestUK ("we", "us", "our") operates the website at aptitudetestuk.com and the associated practice platform at app.aptitudetestuk.com. We are the data controller responsible for your personal data.

For any privacy-related queries, contact us at: support@aptitudetestuk.com

2. What Data We Collect

We collect and process the following categories of personal data:

  • Identity data: your name and username.
  • Contact data: your email address.
  • Account data: your password (stored in hashed form), account preferences, and subscription status.
  • Usage data: pages visited, tests completed, scores, time spent, and interaction patterns within the platform.
  • Payment data: billing information processed by our third-party payment provider. We do not store full card numbers.
  • Technical data: IP address, browser type and version, device type, operating system, and referring URLs.
  • Communications data: any messages you send us via email or support channels.

3. How We Collect Data

We collect data in the following ways:

  • Directly from you when you register, subscribe, or contact us.
  • Automatically through cookies and similar tracking technologies when you use the Service.
  • From our payment processor when you complete a transaction.

4. Legal Basis for Processing

Under the UK GDPR, we process your personal data on the following legal bases:

  • Contract performance: to provide the Service you have signed up for, including account management and subscription fulfilment.
  • Legitimate interests: to improve our platform, prevent fraud, ensure security, and send you relevant service updates.
  • Consent: to send you marketing communications where you have opted in. You may withdraw consent at any time.
  • Legal obligation: to comply with applicable laws, including financial record-keeping obligations.

5. How We Use Your Data

We use your personal data to:

  • Create and manage your account.
  • Process payments and manage subscriptions.
  • Deliver and personalise the practice platform experience.
  • Monitor and analyse usage to improve our content and platform.
  • Send transactional emails (account confirmation, receipts, password resets).
  • Send marketing emails where you have consented (you may unsubscribe at any time).
  • Detect, investigate, and prevent fraudulent or unauthorised activity.
  • Comply with legal obligations.

6. Cookies

We use cookies and similar technologies to operate and improve our Service. These include:

  • Essential cookies: required for the platform to function (e.g. session management, login state).
  • Analytics cookies: to understand how users interact with our platform (e.g. pages visited, time on site).
  • Preference cookies: to remember your settings and preferences.

You may control cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of the Service. We will request your consent for non-essential cookies on your first visit.

7. Data Sharing

We do not sell your personal data. We may share your data with trusted third-party service providers who assist us in operating the Service, including:

  • Payment processors (for billing and subscription management).
  • Cloud hosting and infrastructure providers.
  • Analytics platforms (in anonymised or aggregated form where possible).
  • Email delivery providers (for transactional and marketing emails).

All third-party providers are contractually required to handle your data in accordance with UK GDPR and our instructions.

We may also disclose your data where required by law, court order, or to protect the rights and safety of our users or the public.

8. Data Retention

We retain your personal data only for as long as necessary for the purposes described in this policy:

  • Account data is retained for as long as your account is active, plus up to 2 years after account closure.
  • Payment records are retained for 7 years to comply with HMRC requirements.
  • Usage and analytics data may be retained in anonymised form indefinitely.

You may request deletion of your personal data at any time (see Your Rights below).

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include encrypted data transmission (HTTPS), hashed password storage, and restricted internal access to personal data.

No method of internet transmission is 100% secure. While we take all reasonable steps to protect your data, we cannot guarantee absolute security.

10. Children and Young People

Our Service is intended for individuals aged 16 and over. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected data from a child under 16 without parental consent, please contact us at support@aptitudetestuk.com and we will promptly delete it.

11. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

  • Right of access: to request a copy of the personal data we hold about you.
  • Right to rectification: to request correction of inaccurate or incomplete data.
  • Right to erasure: to request deletion of your personal data in certain circumstances.
  • Right to restriction: to request that we limit how we use your data.
  • Right to data portability: to receive your data in a structured, machine-readable format.
  • Right to object: to object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, please contact us at support@aptitudetestuk.com. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

12. International Transfers

Where we use service providers based outside the UK or European Economic Area, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the ICO, to protect your data in accordance with UK GDPR.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Where changes are material, we will notify you by email or via a prominent notice on the Service. 

AptitudeTestUK | UK Armed Forces DAA Practice Tests