This Privacy Policy explains how Apexa AI Labs (“Apexa”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects personal data when you visit apexaailabs.com, contact us, or use our software, AI, automation, and related services. We designed this Policy to meet the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, together with guidance from the Information Commissioner's Office (ICO).
1. Who we are (data controller)
Apexa AI Labs is a London-based AI and custom software company serving businesses across the UK, USA, and, where agreed, international clients.
For personal data processed through this website and our client engagements, Apexa AI Labs is the data controller unless a written agreement states that we act only as a processor on behalf of a client.
- Legal name (trading): Apexa AI Labs
- Headquarters: London, United Kingdom
- Email (privacy & data requests): info@apexaailabs.com
- WhatsApp business contact: +44 7449 703113
- Website: https://apexaailabs.com
2. Scope of this Policy
This Policy applies to personal data processed in connection with our website, marketing communications, discovery calls, proposals, contracts, support channels, demos, and products we operate. It does not cover third-party websites or services that we do not control, even if linked from our site.
Where we provide software or AI systems to a business customer, that customer typically decides the purposes of processing end-user or employee data inside their environment. In those cases, our processing is governed by the customer agreement and applicable data processing terms.
3. Personal data we collect
We collect only what is reasonably necessary for the stated purpose (data minimization).
A. Identity & contact data
- Name, job title, company name, city/country
- Email address, phone/WhatsApp number
- Preferred language (Arabic / English)
B. Business enquiry & project data
- Industry, operational pain points, and requirements you share
- Meeting notes, proposals, statements of work, and correspondence
- Billing and contracting details needed to perform the engagement
C. Technical & usage data
- IP address, browser type, device/OS signals, approximate location derived from IP
- Pages visited, referring URL, timestamps, and interaction events
- Cookie and similar technology identifiers (see Cookie Policy)
D. Communications
- Messages sent via forms, email, WhatsApp, or chat widgets
- Support tickets and call summaries when you request assistance
4. Sensitive personal data
We do not intentionally collect special category personal data (as defined under UK GDPR) through our public website. Please do not submit health, biometric, religious, criminal, or similarly sensitive data unless we expressly request it under a written engagement with appropriate safeguards.
If a client engagement requires processing sensitive data inside a custom system, we will document the lawful basis, purpose limitation, access controls, and security measures in the contract.
5. How we obtain data
- Directly from you (forms, email, WhatsApp, calls, meetings)
- Automatically via cookies and similar technologies when you use our website
- From your organization when it designates you as a contact
- From publicly available business sources or referrals, where lawful
6. Why we process personal data (purposes)
We process personal data for transparent, specific purposes, including:
- Responding to enquiries and providing consultations
- Preparing proposals, contracts, and delivering services
- Operating, securing, and improving our website and products
- Sending service-related notices and, where permitted, marketing updates
- Analytics to understand demand and improve content (with appropriate consent/controls where required)
- Complying with UK law, responding to lawful requests, and protecting our legal rights
- Preventing fraud, abuse, and security incidents
7. Legal bases (UK GDPR)
Depending on the context, we rely on one or more of the following bases recognized under the UK GDPR:
- Consent — where you opt in (for example, non-essential cookies or certain marketing)
- Contractual necessity — to take steps at your request before a contract or to perform a contract
- Legitimate interest — improving services, securing systems, and B2B relationship management, balanced against your rights
- Legal obligation — where UK or other applicable law requires retention or disclosure
Where consent is the basis, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
9. Cross-border transfers
As a UK-based provider, we prefer processing and hosting arrangements that support UK data considerations. Some tools (for example global cloud or analytics providers) may involve transfer or remote access outside the UK.
Where personal data is transferred outside the UK, we take steps consistent with UK GDPR and ICO guidance — including assessing the destination, using contractual safeguards such as the UK's International Data Transfer Agreement, and applying technical and organizational measures appropriate to the risk.
10. Retention
We keep personal data only as long as needed for the purposes above, including:
- Enquiry records: typically up to 24 months after last meaningful contact, unless a longer period is needed for a live opportunity or dispute
- Contract and billing records: for the engagement term plus periods required by UK commercial/tax rules
- Website logs and security records: for shorter operational windows unless investigating an incident
- Marketing preferences: until you unsubscribe or we delete inactive contacts
When retention ends, we delete or irreversibly anonymize data where feasible.
11. Security measures
We apply technical and organizational measures appropriate to the nature of the data and processing risk, including access controls, encryption in transit where standard, least-privilege practices, vendor diligence, and staff awareness. No method of transmission or storage is 100% secure; we work to reduce risk continuously and to respond promptly to incidents.
If a personal data breach occurs that requires notification under UK GDPR or related rules, we will notify the ICO and affected individuals as required.
12. Your rights under UK GDPR
Subject to legal exceptions, you may request to:
- Be informed about processing of your personal data
- Access your personal data
- Request correction of inaccurate or incomplete data
- Request destruction of data no longer needed (subject to lawful retention)
- Withdraw consent where processing is consent-based
- Object to certain processing in circumstances provided by law
- Lodge a complaint with the Information Commissioner's Office (ICO)
To exercise rights, email info@apexaailabs.com with the subject “Data Protection Request”. We may need to verify your identity before responding. We aim to respond within the timeframes required by applicable law.
13. Children
Our website and services are directed to businesses and professionals. We do not knowingly collect personal data from children. If you believe a child provided data to us, contact us and we will take appropriate steps to delete it.
14. AI systems and automated processing
Apexa builds and deploys AI agents, chatbots, voice systems, and analytics for clients. When those systems process personal data:
- Client-controlled deployments typically treat the client as controller and Apexa as processor under contract
- We design for purpose limitation, human oversight options, and secure configuration
- We do not use your private project data to train public models unless a written agreement expressly allows it
15. Changes to this Policy
We may update this Privacy Policy to reflect legal, technical, or business changes. The “Last updated” date will change when we publish a revision. Material changes may be highlighted on the website or communicated to active clients where appropriate.
Contact for privacy matters
Apexa AI Labs — London, United Kingdom. Email: info@apexaailabs.com. WhatsApp: +44 7449 703113. For data subject requests, please include enough detail for us to locate your records.
Contact us