Privacy policy
Effective date: September 23, 2026. We respect your privacy. This page explains what personal data we collect, how we use it, and the choices you have.
1. General information
What this policy covers. This Privacy Policy applies to personal data collected through the Apex Data Labs websites (the “Websites”) and through our AI data services (the “Services”). It does not cover third-party apps, tools or services that connect to our Websites or Services — those have their own privacy policies.
Who is responsible. Apex Data Labs (“Apex”, “we”, “us”, “our”) is responsible for your personal data under this policy.
The laws we follow. We handle personal data in line with the data protection laws that apply to us, such as the EU General Data Protection Regulation (GDPR), the UK GDPR and the California Consumer Privacy Act (CCPA).
Our two roles. Depending on the situation, we act as either a data controller or a data processor:
- Controller: when you give us personal data so you can use our Websites or Services — for example, when you sign a contract with us or send us a message. Here, we decide what data we need and how we use it.
- Processor: when a client sends us material to work on (the “Files”) and those Files include personal data. The client decides what data is in the Files and how it should be handled, and we only follow their instructions. Clients can ask us for a copy of our data processing agreement.
When we ask for consent. Please read this policy before sharing personal data with us. We will ask for your consent before we collect new types of personal data, use it for new purposes, share it with new types of third parties, or make major changes to this policy.
Children. Our Websites and Services are for people aged 18 and over, and we do not knowingly collect data from children. Client Files may sometimes contain data about minors. In that case, the client is responsible for collecting and sharing it lawfully.
Cookies. Our Websites use cookies. Essential cookies keep the site working. Optional cookies help us understand how the site is used, and we only use them if you accept them in our cookie banner. You can also block or delete cookies in your browser settings.
2. Types and purposes of personal data
Only what we need. We collect the smallest amount of personal data we need, and we only use it for the purposes set out in this policy — to run our Websites, deliver our Services, understand and improve our business, and answer your questions.
What we collect, why, and our legal basis:
| When | What we collect | Why we use it | Legal basis |
|---|---|---|---|
| You become a client | Company legal name and address, contact person's name and job title, email, phone | Give you access to the Services, deliver them, send updates, contact you, keep business records | Performing our contract; our legitimate business interests |
| You contact us | Name, email and anything you include in your message | Reply to you and send the information you asked for | Our legitimate business interests; your consent for optional details |
| You visit our Websites | IP address and cookie data | Analyse and improve our Websites, show local content, keep the Websites secure | Our legitimate business interests; your consent for some cookies |
| You join as a contributor | Name, contact details, country, languages, payment details, and samples you choose to provide | Match you with projects and pay you | Performing our contract; your consent for samples |
Staff and contractors. When we hire employees or contractors, we collect what we need to sign contracts, keep records and meet legal duties — for example name, contact details, background check results, government ID or tax numbers and insurance documents for employees, and name and contact details for contractors. Our legal bases are our legitimate business interests and our legal obligations.
Optional information. If you ask for support, join an event, leave feedback or otherwise contact us, you choose what to share. We use it to reply to you, help you, and improve our business.
If you don't provide data. If you don't give us data we ask for, we may not be able to provide a Service, give you full access to the Websites, or reply to you.
Keeping client Files confidential. We take reasonable steps to keep Files confidential and secure. We only open, change, share or delete Files when needed to deliver the Services, enforce our terms, or when the law requires it. Clients are responsible for what their Files contain.
Sensitive data. Files sometimes contain sensitive data — for example about health, religious or political beliefs, ethnic origin, trade union membership or sexual orientation, or biometric data such as faces and voices. Clients are responsible for collecting this lawfully. We process it to perform our contract with the client.
3. Non-personal (technical) data
What we collect. When you use our Websites, we and our analytics providers automatically collect technical data that does not identify you, such as:
- your device type, operating system and browser;
- log files;
- links you follow from our Websites;
- your country;
- other information about how you browse.
Your feedback. If you contact us, we may keep a record of your questions, complaints or comments and our replies. Where we can, we remove details that identify you.
How we use it. We use technical data to:
- understand who visits our Websites;
- see which content and services are popular and useful;
- find and prevent security problems and misuse;
- build new services and features;
- tailor the Websites to your needs.
Combined and anonymised data. If technical data is combined with personal data in a way that identifies you, we treat it as personal data. If data is anonymised so it can no longer identify anyone, it is no longer personal data and we may use it for any business purpose.
4. Service messages and marketing
Service messages. We send important messages when needed — such as service updates, technical or admin notices, and privacy or security information. These are not marketing, so they don't need your consent.
Marketing. We may send newsletters, offers and news about our Services, but only if:
- you have opted in (for example, by signing up for our newsletter); or
- you are already a client and the message is about services closely related to the ones you use.
Opting out. You can stop marketing messages at any time, free of charge, by clicking “unsubscribe” in any email, changing your account settings, or contacting us.
5. How long we keep data
Personal data. We keep personal data only while we need it for the purposes in this policy, or until you ask us to delete it — whichever comes first. After that, we securely delete it unless we have another legal reason to keep it.
Client Files. We keep Files only while we need them to deliver the Services. When the work ends or the client asks, we securely delete them unless we have another legal reason to keep them.
Technical data. We may keep non-personal data for as long as it is useful for the purposes in this policy and our legitimate business interests.
Legal requirements. Some laws (for example accounting rules) require us to keep certain records for a set time. We keep that data for the required period, then delete it.
7. International transfers of personal data
Some of the service providers we use are in other countries, so your personal data may be moved outside the country where you live — for example, outside the European Economic Area (EEA).
When that happens, we make sure your data stays protected. We only transfer it to countries recognised as having adequate data protection, or we sign agreements with the recipient based on approved standard contractual clauses.
8. Security measures
How we protect data. We use organisational and technical measures to protect personal data from loss, misuse, unauthorised access and disclosure. Our security program follows recognised standards such as ISO 27001 and SOC 2. Our measures include:
- secure networks;
- SSL encryption;
- firewalls;
- strong passwords;
- limiting which staff can access personal data;
- anonymising personal data where possible.
Security breaches. No online system is completely secure. We are not responsible for loss or misuse of data caused by events outside our reasonable control. If a serious breach happens, we will take reasonable steps to limit the harm, as the law requires. Our liability is limited as far as the law allows.
9. Your rights
What you can ask for. Subject to legal exceptions, you can ask us to:
- give you a copy of your personal data;
- tell you why we use it;
- correct data that is wrong;
- move your data to another provider;
- delete your data;
- stop or limit how we use your data;
- withdraw consent you have given;
- handle a complaint about your data.
How to ask. Send us your request through our contact form. We may ask you to confirm your identity first. Please allow up to 30 days for us to respond.
Complaints. If you are unhappy with how we handle your data, please contact us first so we can look into it. If you are still not satisfied, you can complain to your local data protection authority.
Data in client Files. For data in client Files, we are only a processor, so we cannot act on these requests ourselves. Please contact the client (the controller). If you contact us, we will pass your request to the client without delay.
10. Term and changes
When this policy applies. This policy applies from the effective date at the top of this page until we replace or update it.
Changes. We may update this policy when laws, rules or industry standards change. We will post the new version here and, if we have your email address, let you know. Where major changes or the law require it, we will ask for your consent.
11. Contact details
If you have questions about this policy or our privacy and security practices, or want to use your rights, contact us at:
- Contact form: Contact us