APEX

Legal

Product Privacy Notice

What personal information APEX collects, how we use and protect it, and the rights you have over it.

Version 1 · Effective July 6, 2026 Incorporated into the Terms of Service →

Draft for the July 6, 2026 launch. This policy is incorporated by reference into the Terms of Service and is being finalized with legal counsel. Items marked finalized at launch will carry committed figures by the Effective Date. Questions: [email protected].

Effective July 6, 2026. This Product Privacy Notice explains how ApexAVCloud LLC ("APEX", "we", "us", or "our"), a Delaware limited liability company with offices at 5009 N Ashland Ave #3E, Chicago, IL 60640 collects and uses personal information in connection with the APEX website and product. It is incorporated by reference into the Terms of Service.

Two roles, two documents. When APEX processes data about its own business, website visitors, and account holders, APEX acts as a controller, and this Notice applies. When APEX processes Customer Data on a customer's behalf to deliver the Services, the customer is the controller and the Data Processing Addendum governs. This Notice does not change a customer's own privacy obligations to its Users and other individuals.

1. Information we collect

1.1. Information you provide. Account and profile details (name, work email, organization, role), demo and contact-form submissions, support communications, and any information you choose to send us.

1.2. Information collected automatically. Basic usage and device information (such as pages viewed, approximate location derived from IP, browser type, and a first-party anonymous identifier used for product analytics). The marketing site uses first-party analytics; the application does not embed third-party advertising trackers.

1.3. Product telemetry. When customers deploy APEX in their environment, the Services collect device, configuration, and event data. To the extent that data identifies individuals, it is Customer Data and is handled under the DPA rather than this Notice.

2. How we use information

To provide, secure, and improve the website and Services; to create and administer accounts; to respond to demo, sales, and support requests; to send service and transactional messages (such as invitations, password resets, and trial reminders); to understand product usage in aggregate; to comply with Law; and to protect the rights, safety, and security of APEX, our customers, and the public.

3. Legal bases (where GDPR/UK GDPR applies)

We rely on: performance of a contract (to provide accounts and the Services you request); legitimate interests (to secure and improve our products and communicate with prospects and customers); consent (where required, for example certain communications); and compliance with legal obligations.

4. How we share information

We share information with subprocessors and service providers who process it on our behalf under contract (see the subprocessor list in the DPA and on the Trust & Security page); with professional advisors; in connection with a corporate transaction (such as a merger or acquisition); and where required by Law or to protect legal rights. We do not sell personal information, and we do not share it for cross-context behavioral advertising.

5. Retention and deletion

We keep personal information for as long as needed for the purposes described here or as required by Law. Workspace data follows the lifecycle described on the Trust & Security page: deletion is available from Settings → Delete Workspace, typically completing within about 7 days for trial workspaces and within about 30 days for paid workspaces, after which only encrypted backups remain and those rotate out by day 30 after deletion.

6. Security

We protect personal information using the measures summarized on the Trust & Security page, including encryption at rest and in transit, per-tenant isolation, role-based access control, and an append-only audit trail. No method of transmission or storage is completely secure, but we work to protect information in line with industry practice.

7. International transfers

We store and process personal information in the United States. Where we receive personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards (such as the Standard Contractual Clauses) as described in the DPA.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. California residents have rights under the CCPA, including the right to know, delete, and correct, and the right not to be discriminated against for exercising those rights. To exercise a right, email [email protected]; we will verify and respond as required by applicable Law. If you are a User of a customer's workspace, please direct requests about Customer Data to that customer (the controller).

9. Children

The website and Services are intended for businesses and are not directed to children, and we do not knowingly collect personal information from children.

10. Contact

Questions or requests: [email protected], or ApexAVCloud LLC, 5009 N Ashland Ave #3E, Chicago, IL 60640.

11. Changes

We may update this Notice from time to time. Material changes take effect as described in the Terms of Service, and we will update the Effective Date above.