APEX SUITE AI
Last Updated: July 27, 2026
This Privacy Policy explains how Apex Suite AI, LLC (“Apex Suite AI,” “we,” “us,” or “our”) collects, uses, shares, and protects information in connection with our software platform, mobile application, website, and related services (collectively, the “Service”).
By using the Service, you agree to the practices described in this Privacy Policy. Use of the Service is also governed by our Terms of Service (“ToS”) and, where applicable, our Data Processing Agreement (“DPA”), both of which are incorporated by reference.
If you are a business customer using Apex Suite AI on behalf of your organization, the DPA governs our processing of Customer Data and takes precedence over this Privacy Policy to the extent of any conflict regarding that data.
Overview of Data Practices. We collect two broad categories of information: (1) Personal Data, which includes account information, communication data, and usage/technical data that identifies or could reasonably identify you; and (2) Customer Data, which is business data you or your organization submits to the Service (such as leads, contacts, and deal information). We retain Personal Data only as long as necessary to provide the Service and fulfill legal obligations, and we retain Customer Data in accordance with your instructions and the DPA. If we transfer data internationally, we rely on approved transfer mechanisms as described in Section 12. For specific retention periods, see Section 8.
1.1 Account Information
We collect account-level information when you create or manage an account, including your name, email address, phone number, company name, job title, billing details, and login credentials.
Retention: Account information is retained for the duration of your active account. Upon account closure, account information is deleted or anonymized within thirty (30) days, unless legal obligations require longer retention (see Section 8).
1.2 Customer Data (Your Business Data)
We collect and process data that you or your organization submit to the Service, such as leads, contacts, communication logs, deal data, notes, files, and other information you upload or generate within the Service (“Customer Data”). Customer Data remains the property of you or your organization, as described in Section 3.
Retention: Customer Data is retained for the duration of your active subscription. Upon termination, Customer Data is handled in accordance with Section 8 and the DPA.
1.3 Usage and Technical Data
We automatically collect information about how you access and use the Service, including:
Retention: Usage and technical data is retained for up to twenty-four (24) months from the date of collection for analytics and service improvement purposes, after which it is deleted or anonymized.
1.4 Communication Data
We collect information contained in messages you send to us, such as support requests, feedback, and other communications (including email, chat, and SMS).
Retention: Communication data is retained for up to thirty-six (36) months from the date of the communication for support, dispute resolution, and service improvement purposes.
1.5 Sensitive Personal Data
We do not intentionally collect or require Sensitive Personal Data (as defined under GDPR Article 9 or CCPA § 1798.140(ae)). However, the nature of the Service allows you to upload data that may contain Sensitive Personal Data. If you choose to upload Sensitive Personal Data, you are responsible for ensuring that a lawful basis exists, appropriate safeguards are in place, and all required consents have been obtained. Please refer to Section 1.4 of the DPA for additional details.
Regardless of whether Sensitive Personal Data is intentionally collected, if such data exists on our servers, we apply the same technical and organizational security measures described in Section 7 to protect it.
1.6 Information from Third-Party Sources
We may receive information about you from third-party integrations you connect to the Service (such as Google Calendar, Calendly, Meta, GoHighLevel, or other calendar, scheduling, CRM, and social media services). The information we receive depends on the permissions you grant and the third party’s policies.
We use the information we collect for the following purposes:
We treat Customer Data as a core asset that must be protected. All Customer Data remains the property of the Customer and is used solely for the purpose of delivering and improving the Service. We implement industry-standard security practices, restrict internal access on a need-to-know basis, and do not sell or share Customer Data with third parties for their own marketing purposes.
Your Rights. You have the right to access, correct, and delete your personal information. For GDPR rights, see Section 10. For CCPA/CPRA rights, see Section 11. To submit any request, contact us at [email protected].
For information about how our sub-processors handle your data, please refer to their privacy policies linked in Section 6.1.
You or your organization retain full ownership of the Customer Data you submit to the Service. Subject to your instructions and this Policy, Apex Suite AI acts as a custodian/processor of Customer Data and uses it only to provide and improve the Service, in accordance with the DPA.
Prohibition on AI/ML Training. Apex Suite AI shall not use Customer Data to train, enhance, improve, or develop any machine learning models, artificial intelligence algorithms, or similar technologies, unless explicitly agreed upon in writing by the Customer.
Data Export Upon Termination. Upon termination of your account or subscription, Apex Suite AI will, upon written request, provide an export of all Customer Data in a standardized, machine-readable format (such as CSV or JSON) within fifteen (15) business days of the request.
Data Deletion Upon Termination. Within thirty (30) days following termination (or following the data export period, if an export is requested), Apex Suite AI will delete or return all Customer Data, including backups, and will certify in writing that all Customer Data has been permanently deleted or returned. Backups and disaster recovery copies may be retained for up to ninety (90) days for business continuity purposes, after which all Customer Data will be permanently deleted or anonymized.
4.1 When We Act as Data Controller
When we collect and process account information, usage data, and communication data about you as a user or account holder, we act as a data controller under GDPR, UK GDPR, and applicable data protection laws. Our legal bases for this processing include:
4.2 When We Act as Data Processor
When we process Customer Data that you or your organization submits to the Service (such as leads, contacts, and deal data), we act as a data processor on behalf of your organization, which is the data controller. In that case, we process Customer Data only in accordance with your organization’s documented instructions, the DPA, and this Policy.
In both roles, Apex Suite AI is obligated to notify the appropriate supervisory authorities and affected users of data breaches in accordance with applicable law (including GDPR Article 33 and Article 34) and the breach notification procedures set forth in the DPA.
We use cookies and similar technologies (such as pixels, tags, web beacons, and local storage) to:
5.1 Types of Cookies We Use
5.2 Third-Party Cookies
Some of our third-party service providers (such as Cloudflare and Meta) may set their own cookies or similar technologies when you use the Service. These cookies are governed by the respective provider’s privacy policy.
5.3 Your Cookie Choices
Where required by applicable law (such as the EU ePrivacy Directive and GDPR), we will obtain your affirmative consent before placing non-essential cookies. Our cookie consent mechanism provides clear options to accept or reject non-essential cookies, including a “Reject All” option that is equally as prominent and accessible as the “Accept All” option. Analytics and Functional cookies are not pre-checked or enabled by default.
You can also control cookies through your browser settings. Most browsers allow you to block or delete cookies. However, disabling certain cookies may impact the functionality of the Service.
We may share information in the following limited circumstances:
6.1 Service Providers and Sub-Processors
We share information with the third-party service providers listed below, who perform services on our behalf. These providers are contractually bound to use information only as necessary to provide their services and are subject to confidentiality and data protection obligations equivalent to those in our DPA.
| Service | Function | Data Shared | Privacy Policy |
| DigitalOcean | Cloud hosting | Customer Data (stored on servers) | https://digitalocean.com/legal/privacy-policy |
| Supabase | Database, authentication | Account data, Customer Data | https://supabase.com/privacy |
| Stripe | Payment processing | Billing details, payment info | https://stripe.com/privacy |
| SendGrid | Transactional email | Email addresses, message content | https://sendgrid.com/policies/privacy |
| Twilio | SMS (standby/ contingency) | Phone numbers, message content (only if activated) | https://twilio.com/legal/privacy |
| GoHighLevel | CRM, automation, SMS/voice | Contact data, leads, workflows, phone numbers | https://gohighlevel.com/privacy-policy |
| Cloudflare | DNS, CDN, security | IP addresses, traffic data | https://cloudflare.com/privacypolicy |
| Meta (Graph API) | Social media integration | Social media post/comment data | https://facebook.com/privacy/policy |
| Google (Calendar API) | Calendar sync, scheduling | Calendar events, scheduling metadata (only with user authorization) | https://policies.google.com/privacy |
| Calendly | Scheduling, booking integration | Booking details, availability, scheduled event data (only with user authorization) | https://calendly.com/privacy |
Additional infrastructure services (Bluehost, WordPress, Elementor, Jetpack) are used for our website but do not process Customer Personal Data. A complete list of all third-party services is maintained in Appendix A of our DPA.
We encourage you to review the privacy policies of our sub-processors linked above to understand how your data may be handled downstream. We conduct periodic reviews of the security practices of our sub-processors and maintain contractual protections including data breach notification requirements and indemnification provisions.
6.2 Legal and Safety
We may disclose information if required by law, regulation, legal process, or governmental request, or when we believe in good faith that disclosure is reasonably necessary to protect the rights, property, or safety of Apex Suite AI, our users, or others.
6.3 Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, or sale of all or a portion of our business, information may be transferred as part of that transaction. We will use reasonable efforts to require the recipient to honor this Privacy Policy and provide notice to affected users no less than thirty (30) days before any such transfer takes effect where required by law. We will implement appropriate safeguards to protect information during any such transfer process.
6.4 No Sale or Sharing for Advertising
We do not sell Personal Data or Customer Data as defined under CCPA § 1798.140(ad). We do not share Personal Data for cross-context behavioral advertising as defined under CPRA § 1798.140(ah).
We implement technical and organizational measures to protect information, including:
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. However, we are committed to protecting data against unauthorized access, use, or disclosure using industry-standard practices.
We retain information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. The following retention periods apply:
We may retain aggregated or de-identified data that does not identify you personally for analytical and service improvement purposes.
Data is not retained indefinitely. If your account is inactive for a period of twenty-four (24) consecutive months with no login activity, we may delete or anonymize your data after providing thirty (30) days’ written notice to the email address associated with your account.
If you would like us to delete personal data we hold about you, you may submit a request by emailing [email protected] with “Data Deletion Request” in the subject line and providing enough information for us to verify your identity and account.
Upon receiving a verified request, we will delete the following categories of data within thirty (30) days, unless we are permitted or required by law to retain certain information:
If you are using Apex Suite AI on behalf of an organization, deletion requests for Customer Data should be directed to your organization as the data controller, who may then instruct us through the process described in Appendix B of the DPA.
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under GDPR and UK GDPR:
To exercise these rights, contact us at [email protected]. We will respond within thirty (30) days (or within the timeframe required by applicable law). If you are using Apex Suite AI on behalf of an organization, some requests may need to be directed to that organization as the data controller.
You also have the right to lodge a complaint with your local supervisory authority (e.g., the Information Commissioner’s Office in the UK, or your EU member state’s data protection authority).
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with specific rights regarding your personal information.
11.1 Categories of Personal Information Collected
The following table describes the categories of personal information we have collected in the preceding 12 months, examples, and the business purposes for collection:
| Category | Examples | Business Purpose |
| Identifiers | Name, email address, phone number, account ID, IP address | Account creation, authentication, service delivery, support |
| Commercial Information | Subscription plan, billing history, payment method (via Stripe) | Payment processing, billing, service provisioning |
| Internet/Network Activity | Browser type, device identifiers, pages visited, session data, clickstream, referral URL | Analytics, service improvement, security monitoring |
| Geolocation Data | Approximate location derived from IP address | Service customization, compliance, fraud detection |
| Professional/Employment Info | Company name, job title, business contact information | Account setup, CRM features, service delivery |
| Inferences | User preferences, feature usage patterns, engagement scores | Service improvement, personalization, product development |
| Sensitive Personal Information | Only if uploaded by Customer (e.g., health data, biometric data) | Processed only per Customer instructions; not intentionally collected |
| Communications Data | Support tickets, chat messages, feedback, emails | Customer support, service improvement, dispute resolution |
11.2 Sources of Personal Information
We collect personal information from the following sources:
11.3 Sale and Sharing of Personal Information
We do not sell your personal information as defined under CCPA § 1798.140(ad).
We do not share your personal information for cross-context behavioral advertising as defined under CPRA § 1798.140(ah).
11.4 Your California Privacy Rights
As a California resident, you have the right to:
11.5 How to Exercise Your Rights
To submit a request, contact us at:
We will verify your identity before processing your request. We will respond within 45 days (with the possibility of a 45-day extension if reasonably necessary). You may also designate an authorized agent to make a request on your behalf; we may require verification of the agent’s authority.
11.6 Financial Incentives
We do not offer financial incentives for the collection, sale, or deletion of personal information.
Our primary infrastructure is located in the United States (DigitalOcean US region). If you access the Service from outside the United States, your information will be transferred to and processed in the United States.
For users in the EEA and United Kingdom, we ensure that international transfers are lawful by relying on:
Additional details regarding international transfer mechanisms are described in Section 2.5 of the DPA.
The Service may integrate with third-party products or services (for example, Meta, GoHighLevel, or other CRM and communication tools). Any data you choose to share with or sync to those services is subject to those providers’ own privacy policies and terms. We are not responsible for the privacy practices of third-party services.
To limit risk, our Data Processing Agreements with third-party integrations include security clauses, data breach notification requirements, and indemnification provisions. We share only the minimum amount of data required for each integration to function and conduct periodic reviews of the security practices of our third-party integrations.
A complete list of all third-party services we use, including those that process Personal Data, is maintained in Appendix A of the DPA and is available upon request at [email protected].
13.1 Google API Services User Data
Apex Suite AI integrates with Google Calendar to provide calendar synchronization, scheduling workflows, reminders, and task management within the Service. This integration requires your explicit authorization through Google’s OAuth consent flow before any data is accessed.
When you connect your Google Calendar account, we access and process the following categories of Google user data:
Google Calendar data is used solely for the purpose of enabling calendar synchronization, scheduling workflows, reminders, and related user-facing calendar features within the Service. We do not use Google user data for any purpose beyond delivering and supporting these calendar-related features.
Apex Suite AI expressly commits that Google user data obtained through Google API Services is:
Apex Suite AI’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You may revoke Apex Suite AI’s access to your Google Calendar data at any time through your Google Account permissions settings (https://myaccount.google.com/permissions). Upon revocation, we will cease accessing your Google Calendar data and will delete any cached Google Calendar data within thirty (30) days.
The Service is not intended for use by children under 18, and we do not knowingly collect personal information from children under 18.
If we learn we have collected personal data from a child under 18 without verified parental consent, we will delete that information as quickly as possible.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at [email protected].
Upon request, we will provide parents or guardians with information regarding the types of data collected (if any) and allow for its permanent deletion.
If you access the Service through our mobile application, the following additional terms apply:
Apex Suite AI shall not be liable for any damages arising from the use of the mobile application, including but not limited to data loss, service interruptions, or device incompatibility, to the fullest extent permitted by applicable law.
If you are a business customer, our Data Processing Agreement (DPA) governs our processing of Customer Data as a data processor on your behalf. The DPA addresses sub-processors, security measures, data subject rights, breach notification, data retention and deletion, international transfers, and audit rights. The DPA is incorporated by reference into the Terms of Service and is available upon request at [email protected].
The DPA includes the following commitments:
In the event of any conflict between this Privacy Policy and the DPA regarding the processing of Customer Data, the DPA shall prevail.
We may update this Privacy Policy from time to time. When we do, we will update the “Last Updated” date at the top of this page. For material changes, we will provide notice via email to the address associated with your account or through in-app notification no less than thirty (30) days before the changes take effect.
If you do not agree with the revised Privacy Policy, you should discontinue use of the Service and close your account before the changes take effect. Your continued use of the Service after the thirty (30) day notice period constitutes your acceptance of the revised Policy.
We encourage you to review this Privacy Policy periodically.
18.1 Governing Law
This Privacy Policy shall be governed by and construed in accordance with the laws of the State of Wyoming, without regard to its conflict of laws principles. Any disputes arising out of or relating to this Privacy Policy shall be resolved in accordance with the Governing Law and Dispute Resolution provisions of our Terms of Service.
18.2 Severability
If any provision of this Privacy Policy is held to be invalid, unlawful, or unenforceable, the remaining provisions shall continue in full force and effect.
18.3 Limitation of Liability
To the fullest extent permitted by applicable law, Apex Suite AI’s total aggregate liability arising out of or relating to this Privacy Policy, whether in contract, tort (including negligence), strict liability, or any other legal or equitable theory, shall not exceed the total fees paid by you to Apex Suite AI in the twelve (12) months preceding the event giving rise to the claim. This limitation applies to all claims, including but not limited to data breaches, unauthorized access, data loss, or any failure to comply with this Privacy Policy, except to the extent such limitation is prohibited by applicable law.
If you have questions about this Privacy Policy, our data practices, or wish to exercise any of your rights, you can contact us at:
Apex Suite AI, LLC
30 N Gould St. Ste N
Sheridan, WY 82801
Email: [email protected]
For GDPR and UK GDPR inquiries, you may also contact your local supervisory authority.
For CCPA/CPRA inquiries, California residents may submit requests as described in Section 11.5.
$
247
.99
Required per business. Covers the onboarding work to get your messaging system properly set up — intake, brand registration submission with the carriers, phone number provisioning, and infrastructure configuration. With new industry compliance requirements taking effect, this setup ensures your system is built to the latest standards from day one.
What’s included:
For individuals and small businesses getting started with compliant messaging.
$
79
.99
per month
Optional: +1 additional campaign for $24.99 / month (max 2 total)
For growing businesses running consistent outreach across multiple messaging use-cases like promotions, reminders, and follow-ups.
$
149
.99
per month
Optional: Up to +2 additional campaigns for $24.99 / month each (max 4 total)
For established businesses with large contact lists and higher message volume that need infrastructure built for scale.
$
299
.99
per month
Optional: Up to +3 additional campaigns for $24.99 / month each (max 6 total)
For individuals and small businesses getting started with compliant messaging.
$
799
.90
per year
Includes 2 months free
Optional: +1 additional campaign for $24.99 / month (max 2 total)
For growing businesses running consistent outreach across multiple messaging use-cases like promotions, reminders, and follow-ups.
$
1,499
.90
per year
Includes 2 months free
Optional: Up to +2 additional campaigns for $24.99 / month each (max 4 total)
For established businesses with large contact lists and higher message volume that need infrastructure built for scale.
$
2,999
.90
per year
Includes 2 months free
Optional: Up to +3 additional campaigns for $24.99 / month each (max 6 total)
Timeline to send:
Your phone number is provisioned quickly. Carrier review for A2P 10DLC takes approximately 1–4 weeks for full approval. However, some registrations may require additional vetting, documentation, or carrier review depending on the nature of the business, messaging use case, industry category, campaign type, or overall compliance requirements — this window is set by US telecom carriers and applies to every messaging platform, not just Apex Suite. Toll-Free verification (when applicable) takes on average 3–7 days. We’ll keep you updated through every step inside your dashboard.
Need more volume? Add a boost anytime. (Purchase in APP)
Your order includes the $247.99 one-time Messaging Infrastructure setup fee. This covers brand registration, phone number provisioning, and full infrastructure configuration.
A few things to know before you confirm