Privacy Policy
How we collect, use, and protect your personal data.
Last updated: 17 March 2026
1. Introduction
Apexiar ("we", "our", "us") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website (apexiar.co.uk) or use our services.
We are a data controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you have any questions about this policy or our data practices, please contact us at info@apexiar.co.uk.
2. Information We Collect
We may collect and process the following categories of personal data:
Information you provide directly
- Contact information — name, email address, company name, and phone number when you submit a form or contact us.
- Account information — details provided when creating an account to access our platform.
- Communication data — any correspondence you send to us, including support requests and feedback.
Information collected automatically
- Usage data — pages visited, time spent on pages, click patterns, and navigation paths.
- Technical data — IP address, browser type and version, operating system, device type, and screen resolution.
- Cookie data — information collected through cookies and similar tracking technologies (see our Cookie Policy for details).
3. How We Use Your Information
We use your personal data for the following purposes:
- To provide our services — processing your enquiries, managing your account, and delivering the products you have requested.
- To communicate with you — responding to your contact form submissions, sending service updates, and providing customer support.
- To improve our website — analysing usage patterns to enhance user experience, performance, and content.
- To ensure security — detecting, preventing, and addressing technical issues, fraud, and security threats.
- To comply with legal obligations — meeting regulatory, legal, and compliance requirements.
4. Legal Basis for Processing
Under UK GDPR, we process your personal data on the following legal bases:
- Consent — where you have given clear consent for us to process your personal data for a specific purpose (e.g. marketing communications).
- Contractual necessity — where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract.
- Legitimate interests — where processing is necessary for our legitimate business interests, provided these are not overridden by your rights (e.g. improving our services, website analytics).
- Legal obligation — where processing is necessary to comply with a legal obligation.
5. Data Sharing
We do not sell your personal data. We may share your information with:
- Service providers — trusted third parties who assist us in operating our website and services (e.g. hosting providers, email services, analytics platforms). These providers are contractually bound to protect your data.
- Legal authorities — where required by law, regulation, legal process, or enforceable governmental request.
- Business transfers — in connection with a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction.
6. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements.
Contact form submissions are retained for up to 24 months. Account data is retained for the duration of your account and for 12 months after closure. Analytics data is anonymised after 26 months.
7. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate or incomplete data.
- Right to erasure — request deletion of your personal data in certain circumstances.
- Right to restriction — request that we restrict the processing of your data.
- Right to data portability — request a copy of your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, please contact us at info@apexiar.co.uk. We will respond to your request within one month.
8. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS/SSL) and at rest.
- Role-based access controls and authentication.
- Regular security assessments and monitoring.
- Secure data centres with physical access controls.
9. International Transfers
Your personal data may be transferred to and processed in countries outside the United Kingdom. Where such transfers occur, we ensure that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the ICO, to protect your data in accordance with UK GDPR.
10. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites. We encourage you to read the privacy policy of every website you visit.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically.
12. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
- Email: info@apexiar.co.uk
- Website: apexiar.co.uk/contact
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data protection rights have been violated.
