Who is responsible for your data
Oculamor Ltd is the operator of Auction Pack Review and the controller responsible for the personal data described in this notice. It is registered in England and Wales under company number 17011848. Its registered office is 58 Armley Ridge Road, Leeds, LS12 3NP, and its Information Commissioner’s Office registration number is ZC090570.
For privacy questions or to exercise a data-protection right, email support@auctionpackreview.com. Put “Privacy request” in the subject line. Please do not send identity documents until we ask for the minimum evidence needed to verify a request.
Who this notice covers
This notice covers personal data relating to:
- website visitors and people who create or use an account;
- customers and people who contact support;
- people whose details appear materially in an auction pack supplied by an authorised customer; and
- professionals or other contacts a customer identifies in relation to a review.
It does not make APR the controller of information independently held by an auctioneer, solicitor, estate agent, public register or other third party.
Commercial use at a glance
APR does more than store files. It may extract, organise, compare and generate structured information from customer-supplied packs and reports. APR may reuse and recycle report content and information derived from uploaded documents to operate and improve the Service and to develop, market, license or sell data products, research, statistics and property or auction insights.
Wherever reasonably possible, commercial datasets and insights will use aggregated, anonymised or non-personal information that does not identify a customer or another person. The fact that information comes from a public or customer-supplied document does not automatically make every further use lawful or remove another person’s privacy or intellectual-property rights.
APR may publish or license a customer pack, report or identifiable extract only where the particular use is clearly explained and APR has the required lawful basis, customer choice, contractual and copyright authority, redaction and safeguards. Where consent is required, it will be requested separately and will not be hidden in general acceptance of this Privacy Notice.
The Terms of service explain ownership of uploaded documents and reports, the customer’s right to use a delivered report, and the licence granted to APR. A customer cannot grant APR rights that the customer does not have.
Personal data we collect
Account and contact data
Email address, account identifier, verification status, password hash, account state, support communications, and the version and timestamp of your agreement to the Terms and acknowledgement of this Privacy Notice. We do not store your plain-text password.
Security and service data
Session and CSRF records, request and event timestamps, rate-limit and anti-abuse results, truncated or keyed network/device fingerprints, login and account-security events, and privacy-scrubbed error data.
Auction-pack and review data
Files you are authorised to supply, file metadata and hashes, extracted text and structured facts, evidence locations, review findings, pack versions and report history. Packs may contain names, addresses and other personal data about people who are not the customer.
Order and payment data
Order, price, payment status, provider reference, refund and reconciliation records. Card details are entered with the payment provider and are not intended to be stored by APR.
Where the data comes from
Most account, order and support data comes directly from you. Pack data comes from the files an authorised customer supplies. Security and service data is generated when someone interacts with APR and by the providers that protect or operate the Service.
Some pack information may originate from an auctioneer, seller, conveyancer, public authority, public register or other document author. Information being publicly available does not remove our data-protection responsibilities.
How and why we use personal data
- Provide an account and an ordered review
- To register and secure an account, validate supplied files, perform the requested screening, present evidence and deliver and support a report. For the customer, this is normally necessary to take steps at their request and perform the service contract.
- Protect APR and its users
- To prevent abuse, enforce owner-only access, investigate incidents, protect systems and reconcile delivery. We rely on legitimate interests in operating a secure and reliable service, balanced against the rights of affected people, and on legal obligations where applicable.
- Support, complaints and legal rights
- To answer requests, correct problems, handle complaints, preserve necessary dispute records and comply with law. The basis depends on the request and may be contract, legal obligation or legitimate interests.
- Improve service quality
- To test reliability, investigate errors and improve controlled screening methods using data that is minimised, de-identified or generated where reasonably possible.
- Develop and commercialise data products
- To extract and structure pack and report information; reuse report content and information derived from uploaded documents; identify patterns; produce research, statistics and insights; and develop, market, license or sell commercial data products. APR will assess and document the lawful basis, source rights, necessity, compatibility, transparency, minimisation and safeguards for each use rather than treating this notice as blanket permission.
Sensitive and unnecessary information
APR is not designed for customers to submit passwords, payment-card details, identity documents, medical information, biometric data or unrelated special-category or criminal-offence data. Do not include those details in support messages or upload them unless the Service expressly requests and supports them for a stated purpose.
Auction packs can nevertheless contain personal data. We aim to minimise irrelevant details and to show names or other identifiers in a finding only where they are materially needed to explain or evidence it. Signatures, bank details and unrelated personal contact details should not be reproduced in reports.
Automated processing
APR uses automated methods to classify documents, extract and compare information and prepare screening findings. The Service does not make a legal decision for you, decide whether you should bid, or determine a person’s legal rights.
Findings may be incomplete or uncertain and should be checked against their cited source documents. You remain responsible for your decision and should obtain appropriate professional advice.
Service providers and international processing
APR uses specialist providers to operate the Service, including:
- Vercel for the customer-facing web application;
- DigitalOcean for APR’s separately isolated application, database and cache infrastructure in London;
- Resend for transactional account email;
- Cloudflare Turnstile for bot and abuse protection;
- Sentry for privacy-scrubbed error monitoring; and
- a payment provider when a paid order is offered.
Providers process data only for their stated role and under their applicable contracts. Some provider support, security, routing or subprocessor activity may occur outside the United Kingdom. Where personal data is transferred internationally, APR will use an applicable lawful transfer mechanism and safeguards. We do not claim that every part of the Service is UK-only.
How long we keep data
We keep personal data only for as long as needed for the purpose for which it was collected, including delivery, security, support, accounting, disputes and legal obligations. Current account-service limits are designed so that:
- an unverified account expires no later than seven days after registration;
- an anonymous pending-registration record expires after 24 hours;
- bounded authentication-request records are retained for up to 30 days; and
- account-email delivery and provider-event records are retained for up to 90 days unless a shorter link or retry deadline applies.
We keep the email address, password hash and necessary account records while a verified account remains open. If you close the account, we block login and revoke active sessions immediately. We remove or anonymise ordinary active-account data within 30 days unless it is still reasonably needed for security, a complaint, fraud prevention, accounting, a legal claim or another legal obligation.
Limited complaint, fraud, accounting or legal records may be retained for up to six years where relevant. Managed database backups are isolated from ordinary use and cycle out within seven days unless a particular backup must be preserved for an active security incident, dispute or legal obligation.
Files you upload are stored privately and are never published. An upload you do not finish is deleted within 24 hours. A file that fails our safety checks is deleted within 7 days, or immediately if you remove it. Uploaded documents are kept for 6 months from upload so you can view the pages your report relies on, and are deleted sooner if you remove them or close your account.
Your report, the pages it cites and the record of your order are kept for 6 years from delivery so that you can return to them and so that we can deal with any complaint or claim; they are deleted within 30 days if you ask us to erase them and no legal reason requires us to keep them. You can also delete a review yourself from your dashboard at any time. That removes the report, the pages it cites and every document you uploaded for that lot immediately, and it cannot be undone. The record of your order (dates, amounts and identifiers, with none of the report's content) is kept for up to 6 years for accounting and legal purposes. We do not keep separate backups of uploaded files. A specific file may be preserved for longer only where it is needed for an active security incident, dispute or legal obligation.
How we protect data
APR uses measures intended to limit access and reduce misuse, including encrypted transport, server-side sessions, CSRF protection, password hashing, email verification, bot protection, rate limits, owner-bound access checks, separate credentials, restricted production services and privacy-scrubbed monitoring.
No online service can guarantee absolute security. If you believe your account, a report link or personal data has been compromised, contact support promptly and avoid including the exposed secret in the message.
Your data-protection rights
Depending on the circumstances, you may have rights to ask for access, correction, erasure, restriction, portability or an objection to processing. A right may not apply in every case, and we may need limited information to verify who is making the request.
Contact support@auctionpackreview.com to make a request. You may also complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint. We would appreciate the opportunity to address the issue first.
Changes to this notice
We will publish the current version and effective date. Material changes will be explained clearly and, where appropriate, notified to account holders before they take effect.
A Privacy Notice explains processing; it is not used to describe consent where another lawful basis applies, and an update does not retrospectively change the terms of a completed order.