Skip to content
Legal

Privacy Policy

This policy explains what personal data Apex Reporting collects, why we collect it, how long we keep it and the choices available to you. It covers both our website and the Apex Reporting application.

Effective date: [Date to be confirmed]

Initial draft. This document is an initial draft prepared for review. It is not legal advice and must be reviewed and approved by a qualified legal professional before publication or reliance. Items shown in square brackets are placeholders awaiting confirmation.

01Who we are

Apex Reporting (“we”, “us”) provides AI-assisted condition reporting software for small and medium-sized businesses. For the purposes of UK data protection law, we act as a data controller in relation to account and website data, and as a data processor in relation to inspection content that customers upload on behalf of their own clients.

Registered entity: [Legal entity name to be confirmed]. Registered address: [Address to be confirmed].

02Data we collect

We collect the following categories of information:

  • Account data: name, work email address, company name, business type, team size and password credentials.
  • Inspection content: photographs, annotations, condition ratings, notes, asset identifiers and generated report documents.
  • Usage data: pages visited, features used, device and browser type, approximate location derived from IP address and diagnostic logs.
  • Communications: enquiries, demo requests, newsletter sign-ups and support correspondence.
  • Billing data: plan selection and billing contact details. Card details are handled by our payment provider and are not stored by us.

03How we use your data

  • To create and administer your account and workspace.
  • To generate, store and deliver condition reports you create.
  • To provide AI-assisted drafting of condition descriptions, which you review and approve before a report is issued.
  • To provide customer support and respond to your enquiries.
  • To maintain security, prevent misuse and diagnose technical faults.
  • To improve the product, including analysing aggregated, non-identifying usage patterns.
  • To send service messages, and marketing emails only where you have opted in.

05AI processing of inspection content

Where AI-assisted features are enabled, photographs and related inspection details may be processed by an AI model provider in order to draft suggested descriptions. Suggestions are always presented for human review, and the inspector remains responsible for the final content of a report.

We contractually require AI processing partners to handle content only for the purpose of producing the requested output. [Current AI processing partners and regions to be confirmed.]

06Sharing and disclosure

We do not sell personal data. We share data only with service providers who help us operate the platform, including hosting, storage, email delivery, payment processing, analytics and AI processing. Each is bound by contractual confidentiality and security obligations.

We may disclose data where required by law, to enforce our terms, or in connection with a business transfer, in which case you will be notified.

07International transfers

Where data is transferred outside the UK or EEA, we rely on adequacy regulations or appropriate safeguards such as the International Data Transfer Agreement or Standard Contractual Clauses. [Hosting and processing regions to be confirmed.]

08Data retention

Inspection content and reports are retained for as long as your account remains active, so that records stay available for dispute resolution. Retention periods for each data category will be confirmed and published here.

Following account closure we delete or anonymise data within [retention period to be confirmed], except where we must retain records for legal or accounting purposes.

09Security

We apply technical and organisational measures appropriate to the sensitivity of the data we handle, including encryption in transit, access controls, role-based permissions, audit logging and regular backups.

No system can be guaranteed completely secure. If a personal data breach occurs that is likely to affect your rights, we will notify you and the relevant supervisory authority as required.

10Your rights

Subject to conditions, you may request access to your data, correction of inaccurate data, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. You may also withdraw marketing consent at any time.

To exercise a right, contact us using the details below. You have the right to complain to the Information Commissioner’s Office if you are unhappy with how we have handled your data.

11Cookies

We use essential cookies to keep you signed in and to maintain security. Analytics and preference cookies are used only where permitted by you. A detailed cookie list will be published alongside our cookie controls. [Cookie inventory to be confirmed.]

12Changes and contact

We may update this policy as the service develops. Material changes will be communicated by email or in-product notice, and the effective date above will be revised.

Privacy enquiries: [privacy contact email to be confirmed]. General enquiries can be sent through our contact section.