Privacy Policy
Apex Configuration Group Ltd.
Effective Date: June 2025
Next Review Date: June 2027
Who We Are
Apex Configuration Group Ltd. ("Apex", "we", "our", "us") is an IT Service Management consultancy registered in England & Wales (Company No. 15871442). Our registered office is 20 Wenlock Road, London, England, N1 7GU.
We act as the Data Controller for personal data collected through this website.
Information We Collect
We may collect the following types of personal information:
Contact Data: Name, company affiliation, business email address, and telephone number.
Purpose: To respond to enquiries and manage contractual relationships.
Legal Basis: UK GDPR Art. 6(1)(b) — necessary for pre-contractual or contractual purposes.
Usage Data: IP address, browser type, pages accessed, and time spent on our site.
Purpose: Site security and analytics to enhance user experience.
Legal Basis: UK GDPR Art. 6(1)(f) — our legitimate interests in ensuring site security and improving our website.
Marketing Preferences: Opt-in status, newsletter interactions.
Purpose: To send marketing communications tailored to your preferences.
Legal Basis: UK GDPR Art. 6(1)(a) — explicit consent.
We do not intentionally collect sensitive personal data or data from children.
How We Use Your Data
We use your personal data solely for the following purposes:
• To respond effectively to your enquiries and provide tailored proposals.
• To continuously improve our website and user experience through aggregated analytics.
• To send marketing updates, subject to your explicit consent. You may withdraw your consent at any time.
We never sell or rent your personal data.
Cookies & Analytics
We use only essential cookies necessary for site security and functionality.
Data Sharing
Your personal data is securely stored with trusted third parties:
• Microsoft: Provides our website and email hosting, adhering strictly to UK GDPR-compliant Data Processing Agreements (DPA).
No personal data collected through this website leaves the UK or the European Economic Area (EEA).
Data Retention
• Enquiry Emails: Retained for 24 months, then securely deleted.
• Client Contract Files: Stored securely for 7 years as required by HMRC regulations.
• Analytics Logs: Retained for 180 days.
All backups are encrypted and purged automatically on a rolling 35-day schedule.
Your Rights
Under the UK GDPR, you have the right to:
• Request access to, correction, or deletion of your personal data.
• Object to or restrict our processing of your data.
• Withdraw your consent to marketing communications at any time.
• Lodge a complaint with the Information Commissioner's Office (ICO) via www.ico.org.uk.
To exercise these rights, please contact us at privacy@apexconfiguration.com or via our registered postal address. We aim to respond within 30 days.
Security Measures
To protect your data, we implement rigorous security standards:
• Mandatory TLS 1.3 encryption across our entire website.
• Hosting in ISO 27001-certified facilities.
• Strict adherence to the principle of least privilege for all staff.
• Regular security assessments, including quarterly vulnerability scans and annual penetration testing.
Updates to This Policy
We regularly review and update this Privacy Policy to reflect changes in our operations or legal requirements.
We will prominently notify users of significant updates on our homepage.
Previous versions are available upon request.
Contact Us
For any questions regarding this Privacy Policy,
please contact our Data Protection Officer at privacy@apexconfiguration.com.
© 2025 Apex Configuration Group Ltd.
Content protected under UK and EU copyright law. All rights reserved.