Skip to main content
APRAuction Pack Review
TermsPrivacyCookiesSupport

Privacy notice

Your information, explained plainly.

APR may extract and structure information from supplied packs and reports and use it to develop, market, license or sell data products and insights. This notice explains those commercial uses alongside what APR collects, shares and publishes, its use of cookies and cookieless analytics, retention, and your choices.

Effective 6 September 2026 · Last updated 6 September 2026

On this page

  1. Who is responsible for your data
  2. Who this notice covers
  3. Commercial use at a glance
  4. Personal data we collect
  5. Where the data comes from
  6. How and why we use personal data
  7. Sensitive and unnecessary information
  8. Automated processing
  9. Service providers and international processing
  10. Sharing, publication and commercial use
  11. How long we keep data
  12. How we protect data
  13. Cookies, analytics and personalised marketing
  14. Your data-protection rights
  15. Changes to this notice

01

Who is responsible for your data

Oculamor Ltd is the operator of Auction Pack Review and the controller responsible for the personal data described in this notice. It is registered in England and Wales under company number 17011848. Its registered office is 58 Armley Ridge Road, Leeds, LS12 3NP, and its Information Commissioner’s Office registration number is ZC090570.

For privacy questions or to exercise a data-protection right, email support@auctionpackreview.com. Put “Privacy request” in the subject line. Please do not send identity documents until we ask for the minimum evidence needed to verify a request.

02

Who this notice covers

This notice covers personal data relating to:

  • website visitors and people who create or use an account;
  • customers and people who contact support;
  • people whose details appear materially in an auction pack supplied by an authorised customer; and
  • professionals or other contacts a customer identifies in relation to a review.

It does not make APR the controller of information independently held by an auctioneer, solicitor, estate agent, public register or other third party.

03

Commercial use at a glance

APR does more than store files. It may extract, organise, compare and generate structured information from customer-supplied packs and reports. APR may reuse and recycle report content and information derived from uploaded documents to operate and improve the Service and to develop, market, license or sell data products, research, statistics and property or auction insights.

Wherever reasonably possible, commercial datasets and insights will use aggregated, anonymised or non-personal information that does not identify a customer or another person. The fact that information comes from a public or customer-supplied document does not automatically make every further use lawful or remove another person’s privacy or intellectual-property rights.

APR may publish or license a customer pack, report or identifiable extract only where the particular use is clearly explained and APR has the required lawful basis, customer choice, contractual and copyright authority, redaction and safeguards. Where consent is required, it will be requested separately and will not be hidden in general acceptance of this Privacy Notice.

The Terms of service explain ownership of uploaded documents and reports, the customer’s right to use a delivered report, and the licence granted to APR. A customer cannot grant APR rights that the customer does not have.

04

Personal data we collect

Account and contact data

Email address, account identifier, verification status, password hash, account state, support communications, and the version and timestamp of your agreement to the Terms and acknowledgement of this Privacy Notice. We do not store your plain-text password.

Security and service data

Session and CSRF records, request and event timestamps, rate-limit and anti-abuse results, truncated or keyed network/device fingerprints, login and account-security events, and privacy-scrubbed error data.

Auction-pack and review data

Files you are authorised to supply, file metadata and hashes, extracted text and structured facts, evidence locations, review findings, pack versions and report history. Packs may contain names, addresses and other personal data about people who are not the customer.

Order and payment data

Order, price, payment status, provider reference, refund and reconciliation records. Card details are entered with the payment provider and are not intended to be stored by APR.

05

Where the data comes from

Most account, order and support data comes directly from you. Pack data comes from the files an authorised customer supplies. Security and service data is generated when someone interacts with APR and by the providers that protect or operate the Service.

Some pack information may originate from an auctioneer, seller, conveyancer, public authority, public register or other document author. Information being publicly available does not remove our data-protection responsibilities.

06

How and why we use personal data

Provide an account and an ordered review
To register and secure an account, validate supplied files, perform the requested screening, present evidence and deliver and support a report. For the customer, this is normally necessary to take steps at their request and perform the service contract.
Protect APR and its users
To prevent abuse, enforce owner-only access, investigate incidents, protect systems and reconcile delivery. We rely on legitimate interests in operating a secure and reliable service, balanced against the rights of affected people, and on legal obligations where applicable.
Support, complaints and legal rights
To answer requests, correct problems, handle complaints, preserve necessary dispute records and comply with law. The basis depends on the request and may be contract, legal obligation or legitimate interests.
Improve service quality
To test reliability, investigate errors and improve controlled screening methods using data that is minimised, de-identified or generated where reasonably possible.
Develop and commercialise data products
To extract and structure pack and report information; reuse report content and information derived from uploaded documents; identify patterns; produce research, statistics and insights; and develop, market, license or sell commercial data products. APR will assess and document the lawful basis, source rights, necessity, compatibility, transparency, minimisation and safeguards for each use rather than treating this notice as blanket permission.

07

Sensitive and unnecessary information

APR is not designed for customers to submit passwords, payment-card details, identity documents, medical information, biometric data or unrelated special-category or criminal-offence data. Do not include those details in support messages or upload them unless the Service expressly requests and supports them for a stated purpose.

Auction packs can nevertheless contain personal data. We aim to minimise irrelevant details and to show names or other identifiers in a finding only where they are materially needed to explain or evidence it. Signatures, bank details and unrelated personal contact details should not be reproduced in reports.

08

Automated processing

APR uses automated methods to classify documents, extract and compare information and prepare screening findings. The Service does not make a legal decision for you, decide whether you should bid, or determine a person’s legal rights.

Findings may be incomplete or uncertain and should be checked against their cited source documents. You remain responsible for your decision and should obtain appropriate professional advice.

09

Service providers and international processing

APR uses specialist providers to operate the Service, including:

  • Vercel for the customer-facing web application;
  • DigitalOcean for APR’s separately isolated application, database and cache infrastructure in London;
  • Resend for transactional account email;
  • Cloudflare Turnstile for bot and abuse protection;
  • Sentry for privacy-scrubbed error monitoring; and
  • a payment provider when a paid order is offered.

Providers process data only for their stated role and under their applicable contracts. Some provider support, security, routing or subprocessor activity may occur outside the United Kingdom. Where personal data is transferred internationally, APR will use an applicable lawful transfer mechanism and safeguards. We do not claim that every part of the Service is UK-only.

10

Sharing, publication and commercial use

We disclose personal data to the service providers needed to operate APR, to your authorised recipients, and where reasonably necessary to investigate fraud or security incidents, establish or defend legal rights, protect a person from serious harm, or comply with a valid legal obligation or request.

APR may develop, market, license or sell aggregated, anonymised or non-personal data, research and insights derived from the Service, provided the information cannot reasonably identify a customer or another person.

APR may sell or license personal data, or publish an identifiable customer pack, report or extract, only for a specific use that has been explained before it begins and for which APR has established the required lawful basis, recipients, rights, copyright permission, contractual authority, redaction and safeguards. Where consent is the required basis, APR will obtain it through a separate active choice. A general acceptance of this notice does not by itself authorise that use.

A customer may later be offered a separate choice to publish or share a suitably reviewed report. That choice would be optional and would not authorise publication of third-party source documents or personal data that the customer has no right to disclose. We verify requests for disclosure and aim to provide only the information that is necessary and lawful.

11

How long we keep data

We keep personal data only for as long as needed for the purpose for which it was collected, including delivery, security, support, accounting, disputes and legal obligations. Current account-service limits are designed so that:

  • an unverified account expires no later than seven days after registration;
  • an anonymous pending-registration record expires after 24 hours;
  • bounded authentication-request records are retained for up to 30 days; and
  • account-email delivery and provider-event records are retained for up to 90 days unless a shorter link or retry deadline applies.

We keep the email address, password hash and necessary account records while a verified account remains open. If you close the account, we block login and revoke active sessions immediately. We remove or anonymise ordinary active-account data within 30 days unless it is still reasonably needed for security, a complaint, fraud prevention, accounting, a legal claim or another legal obligation.

Limited complaint, fraud, accounting or legal records may be retained for up to six years where relevant. Managed database backups are isolated from ordinary use and cycle out within seven days unless a particular backup must be preserved for an active security incident, dispute or legal obligation.

Files you upload are stored privately and are never published. An upload you do not finish is deleted within 24 hours. A file that fails our safety checks is deleted within 7 days, or immediately if you remove it. Uploaded documents are kept for 6 months from upload so you can view the pages your report relies on, and are deleted sooner if you remove them or close your account.

Your report, the pages it cites and the record of your order are kept for 6 years from delivery so that you can return to them and so that we can deal with any complaint or claim; they are deleted within 30 days if you ask us to erase them and no legal reason requires us to keep them. You can also delete a review yourself from your dashboard at any time. That removes the report, the pages it cites and every document you uploaded for that lot immediately, and it cannot be undone. The record of your order (dates, amounts and identifiers, with none of the report's content) is kept for up to 6 years for accounting and legal purposes. We do not keep separate backups of uploaded files. A specific file may be preserved for longer only where it is needed for an active security incident, dispute or legal obligation.

12

How we protect data

APR uses measures intended to limit access and reduce misuse, including encrypted transport, server-side sessions, CSRF protection, password hashing, email verification, bot protection, rate limits, owner-bound access checks, separate credentials, restricted production services and privacy-scrubbed monitoring.

No online service can guarantee absolute security. If you believe your account, a report link or personal data has been compromised, contact support promptly and avoid including the exposed secret in the message.

13

Cookies, analytics and personalised marketing

APR uses cookies or equivalent browser storage that are necessary to provide and protect the Service. In practice that is a single HttpOnly account session cookie; the CSRF token is held in that session rather than in a separate cookie. Protective providers may also set strictly necessary security cookies. The Cookie Notice lists each one by name, purpose and duration.

APR uses Vercel Web Analytics and Vercel Speed Insights to understand which pages people use and how quickly they load. These are cookieless: they set no cookies and store nothing on your device, they receive only a redacted page address from a fixed list of routes, and they cannot be used to identify you. Because they store nothing on your device, they operate as essential measurement under the Privacy and Electronic Communications Regulations and run on all visits.

APR does not currently use advertising, marketing or personalisation cookies, pixels or similar technologies, and does not create marketing audiences. If that changes, APR will name the tools, providers, purposes and durations in the Cookie Notice and ask for your consent before setting them; APR will not rely on this Privacy Notice alone as consent.

We will not use auction-pack contents, report findings or information about people named in a pack to personalise advertising unless a separate, specific and lawful process is approved and clearly offered before that use begins.

14

Your data-protection rights

Depending on the circumstances, you may have rights to ask for access, correction, erasure, restriction, portability or an objection to processing. A right may not apply in every case, and we may need limited information to verify who is making the request.

Contact support@auctionpackreview.com to make a request. You may also complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint. We would appreciate the opportunity to address the issue first.

15

Changes to this notice

We will publish the current version and effective date. Material changes will be explained clearly and, where appropriate, notified to account holders before they take effect.

A Privacy Notice explains processing; it is not used to describe consent where another lawful basis applies, and an update does not retrospectively change the terms of a completed order.

Auction Pack Review

Information and screening support only. Not legal advice, a report on title, a valuation, a guarantee, or a recommendation to bid.

Operated by Oculamor Ltd, registered in England and Wales under company number 17011848.

Registered office: 58 Armley Ridge Road, Leeds, LS12 3NP. ICO registration ZC090570.

TermsPrivacyCookiesSupportsupport@auctionpackreview.com