Data Processing Agreement
Effective: September 20, 2026·Version 2026-09-20.1
1. Parties and incorporation
This Data Processing Agreement (“DPA”) is part of the Terms of Service (or an executed MSA or Order Form, the “Agreement”) between Apex, Inc. (“Apex”) and the customer identified in the account or Order Form (“Customer”). It takes effect when Customer accepts the Agreement or first uses the Services. A countersigned PDF is available on request at legal@apex.inc.
2. Definitions
- Data Protection Laws means GDPR, UK GDPR, the Swiss FADP, the CCPA / CPRA, and other laws that govern Personal Data in connection with the Services.
- Personal Data, Controller, Processor,Processing, and Data Subject have the meanings in those laws. Under the CPRA, Apex is a “service provider” when it acts as Processor.
- Customer Personal Data means Personal Data in Customer Data that Apex processes on Customer’s behalf.
- Sub-processor means a third party Apex engages to process Customer Personal Data, listed at /legal/sub-processors.
3. Roles
Customer is Controller of Customer Personal Data. Apex is Processor of Customer Personal Data and will process it only on Customer’s documented instructions, including Customer’s configuration of the Services and the licenses in the Terms.
Apex is an independent Controller of:
- Account Data (billing, authentication, support, product telemetry about Customer’s users);
- System Data used to operate, secure, and meter the Services;
- Derived Data produced under the Service Improvement license in the Terms, de-identified as defined there, which is not Customer Personal Data; and
- Data Co-op outputs, only if Customer has enabled the Data Co-op. Enabling the Data Co-op is Customer’s instruction to Apex to act as independent Controller of those de-identified outputs.
Apex will not sell Customer Personal Data or retain, use, or disclose it except as permitted by this DPA and the Agreement. Service Improvement that produces de-identified Derived Data, and the Data Co-op if Customer has enabled it, are documented instructions.
4. Details of processing
- Subject matter: providing the Services.
- Duration: the Agreement term plus the retention periods in the Privacy Policy.
- Nature: collection, storage, organization, structuring, analysis, transmission, erasure.
- Purpose: Customer’s instructions as expressed through the Services, including Service Improvement, and the Data Co-op if enabled.
- Categories of Data Subjects: Customer’s End Users, personnel, and partners.
- Categories of Personal Data: contact data; online and device identifiers; usage, experiment, journey, and communication events; attribution identifiers; partner payout references. Special-category data is not in scope. Customer will not submit it.
5. Customer instructions and warranties
Customer instructs Apex to process Customer Personal Data to provide and improve the Services as described in the Terms. Customer warrants that it has a valid lawful basis and has given Data Subjects the notices required for that processing, including Service Improvement and, if enabled, the Data Co-op. Customer is responsible for its CMP and for the accuracy of consent signals it sends Apex.
6. Confidentiality and personnel
Apex will ensure that persons authorized to process Customer Personal Data are bound by confidentiality and receive privacy and security training appropriate to their role.
7. Security
Apex maintains technical and organizational measures including:
- TLS 1.2+ in transit and encryption at rest for stored workspace data.
- Workspace isolation at the data-store layer (partition keys and authorized queries).
- Least-privilege service access, MFA on administrative access, and centralized security logging.
- Role-based access in the dashboard; structured application logs redact known personal-data and secret fields before emission.
Measures may evolve. They will not materially decrease overall protection during the term.
8. Sub-processors
Customer authorizes Apex to use the Sub-processors at /legal/sub-processors. Apex will impose data-protection terms no less protective than this DPA. Apex remains responsible for Sub-processor performance.
Apex will give at least 30 days’ notice before adding a Sub-processor (email or dashboard, and an update to the public list). Customer may object on reasonable data-protection grounds. If the parties cannot resolve the objection, Customer may terminate the affected Services.
9. International transfers
Customer Personal Data is processed in the United States unless an Order Form specifies another region. For transfers from the EEA, the EU Standard Contractual Clauses Module 2 (Controller to Processor, 2021/914) are incorporated. For the UK, the IDTA addendum is incorporated. Apex is data importer; Customer is data exporter. The Clauses prevail over this DPA on transfer issues. Request a signed package at privacy@apex.inc.
10. Data Subject rights
Apex will assist Customer with requests for access, correction, erasure, portability, and restriction, including self-service export and deletion in the dashboard where available. If Apex receives a request directly, Apex will redirect the Data Subject to Customer unless law requires Apex to respond.
11. Breach notification
Apex will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, at the primary account email. To the extent known at the time, the initial notice will describe the nature of the breach, the categories and approximate number of Data Subjects, likely consequences, and measures taken or proposed. Apex will provide additional information in phases without undue further delay as it becomes available.
12. Return and deletion
On termination, Apex will delete Customer Personal Data within 90 days, except data Apex must retain by law (including tax records for partner payouts, typically 7 years in the United States) and de-identified Derived Data. Customer may request earlier deletion at privacy@apex.inc. Backups age out on a rolling schedule of about 35 days.
13. Audits
On written request, no more than once per year (unless a regulator or a confirmed breach requires more), Apex will provide the then-current third-party audit report covering the Services when one exists. On-site audits require reasonable notice, follow Apex security rules, and are at Customer’s expense. Apex may satisfy an audit request with the report plus written answers.
14. CPRA service-provider terms
Apex will not sell or share Customer Personal Data, or retain, use, or disclose it outside the business purpose of the Agreement, including Service Improvement and the Data Co-op if Customer has enabled it. Apex will not combine Customer Personal Data with personal information from other sources except as permitted for a service provider, or as Derived Data / Co-op outputs that are not personal information. Apex will notify Customer if it determines it can no longer meet these obligations.
15. Order of precedence
An executed MSA or Order Form controls over this DPA. This DPA controls over the Terms on data-protection issues. The SCCs control over this DPA on international transfers.