Legal
Data Processing Agreement
The mutual obligations concerning personal data processed by Apex on behalf of the customer.
Last updated: September 1, 2026
1. Purpose
This Data Processing Agreement (DPA) governs the parties' obligations regarding personal data processed by Apex on behalf of the customer. Enterprise and Pro customers can sign this agreement from the dashboard.
2. Parties and Roles
Under this agreement, the customer acts as the "data controller" and Apex acts as the "data processor" processing data according to the customer's instructions.
3. Scope of Processing
- Categories of data processed: end-user data processed through the customer's application
- Purpose of processing: solely to provide the service and follow customer instructions
- Processing period: during the term of the agreement and for the legally required retention period after termination
4. Subprocessors
Apex works with a limited number of subprocessors to provide the service; the current list is available upon request. Customers are notified before a new subprocessor is added.
5. Security Measures
All measures listed on security.html, including encryption, access controls, and regular audits, also apply under this agreement.
6. Data Breach Notification
When a security incident affecting personal data is detected, the customer is notified without undue delay and within the period required by law.
7. Audit Rights
Customers may, with reasonable notice, audit Apex's compliance with this agreement or request independent audit reports.