apokto
Draft — for review before publishing.This is placeholder legal language and has not been reviewed by counsel.

Legal

Privacy Policy

Last updated 30 August 2026

This policy describes how Apokto, Inc. handles personal information collected through the apokto website and in the course of selling and supporting the apokto platform. It does not cover customer data submitted inside a live transaction — that is governed by the applicable order form and our Data Processing Agreement.

1. Scope

This policy applies to personal information we collect from visitors to www.apokto.co, prospective customers who request a briefing or the security package, and individuals we correspond with in the ordinary course of business.

2. Information we collect

We collect information you provide directly, including:

  • contact details submitted through a briefing or security-package request (name, work email, firm and role);
  • the content of messages you send us, for example by email; and
  • basic technical information the site collects automatically, such as browser type and pages visited, as described in our Cookie Policy.

3. How we use information

We use this information to:

  • respond to briefing requests, security-package requests and other inquiries;
  • operate, secure and improve the website;
  • communicate with prospective and current customers about the platform; and
  • meet legal, security and audit obligations.

We do not sell personal information, and we do not use it to serve third-party advertising.

4. Legal bases for processing

Where the UK or EU GDPR applies, we rely on: performance of a contract or steps requested before entering one (for example, responding to a briefing request); our legitimate interests in operating and securing the website and pursuing a sale, balanced against your rights; and, where required, your consent.

5. How we share information

We share personal information with service providers who help us operate the website and respond to inquiries (for example, email delivery), under contractual confidentiality and security obligations. We may also disclose information where required by law, or in connection with a merger, financing or acquisition of our business.

6. Data retention

We keep personal information collected through this website for as long as needed to respond to your inquiry and maintain a record of the relationship, and delete or anonymize it when it is no longer needed for those purposes or for legal compliance.

7. Your rights

Depending on where you live, you may have the right to request access to, correction of, deletion of, or a copy of your personal information, or to object to or restrict certain processing. To exercise a right, contact us using the details below — we will verify the request and respond within the timeframe required by applicable law.

8. Cookies and similar technologies

The website uses a limited number of cookies to operate correctly. See our Cookie Policy for details.

9. Security

We use administrative, technical and physical safeguards designed to protect personal information appropriate to its sensitivity. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. International data transfers

Personal information may be processed in countries other than the one in which you are located. Where required, we use appropriate safeguards, such as standard contractual clauses, to protect information transferred internationally.

11. Children’s privacy

The apokto website and platform are intended for business use and are not directed to children. We do not knowingly collect personal information from children.

12. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by an updated “last updated” date on this page.

13. Contact us

Questions or requests about this policy can be sent to hello@apokto.co.

Questions about this document?

These pages are drafts ahead of legal review. If you need something clarified or want a signed copy for diligence, get in touch.

Contact us

Controls and attestations

SOC 2 Type II
ANNUAL · ON REQUEST
ISO 27001
ISMS CERTIFIED
RFC 3161 timestamping
THIRD-PARTY TSA
WORM object-lock
7-YEAR RETENTION
GDPR · DPA
EU/UK · SUBPROCESSORS
Okta · Entra · Ping
SAML · SCIM
© 2026 APOKTO, INC.SOC 2 TYPE II · ISO 27001 · RFC 3161

Book a briefing

Architecture overview, data-flow diagram and custody specification go to your team before we talk. 45 minutes, on a live deal.

Briefings run 45 minutes on a live deal, not a slide.

Request the security package

SOC 2, ISO 27001, RFC 3161, and the full custody architecture — sent immediately.

Architecture overview, data-flow diagram and custody specification — sent immediately, no call required.