Privacy Policy
Apex Systematic is committed to protecting your personal data. This Privacy Policy explains what data we collect, how we use it, and your rights under GDPR and applicable Spanish data protection law (Ley Orgánica 3/2018, LOPDGDD).
1. Who We Are
Apex Systematic is a sole trader operating under Spanish law, trading as JORGE RIVERO, NIF: 04298371Q. We provide AI workflow automation services to professional services firms, self-employed professionals, and small businesses, with a particular focus on clients based in the United Kingdom.
For data protection purposes, we are the data controller of your personal data. You can contact us via the contact form on our website.
2. Data We Collect
- Name and email address when you submit our contact form or book a call
- Professional information you voluntarily share (job title, company, sector)
- Information about your workflows and business processes shared during an audit or engagement
- Technical data such as IP address, browser type, and pages visited via website analytics
- Payment and billing information processed via Stripe
- Call recordings or transcripts where you have consented to these as part of a demo or discovery call
3. How We Use Your Data
- To respond to your enquiry and provide the services you request
- To manage our business relationship with you
- To send project-related communications and updates
- To improve our website using anonymised analytics data
- To comply with our legal and accounting obligations
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
4. Legal Basis for Processing
- Contract — processing necessary to perform services you have engaged us for
- Legitimate interests — to respond to enquiries and improve our services
- Legal obligation — where required by Spanish or EU law
- Consent — for analytics cookies and any other use where you have explicitly agreed
5. International Transfers
Many of our clients are based in the United Kingdom. The UK has been granted adequacy status by the European Commission, meaning personal data may be transferred there without additional safeguards. Where data is transferred to other third countries (e.g. the United States, via tools such as Google or OpenAI), we rely on Standard Contractual Clauses or equivalent mechanisms as required by GDPR.
6. Data Retention
Enquiry data is retained for 12 months. Client engagement data is retained for 5 years for accounting and legal purposes in accordance with Spanish law. You may request deletion at any time, subject to those legal obligations.
7. Third-Party Processors
We use the following third-party tools that may process your data on our behalf:
- Stripe — payment processing
- Brevo — email communications
- Make — workflow automation infrastructure
- Google (Analytics, Tag Manager, Workspace) — analytics and business tools
- OpenAI / AI providers — AI processing within automation workflows
- Vapi — AI voice agent functionality
- Cal.com — appointment scheduling
- CookieYes — cookie consent management
- Airtable / Notion — project and client data management (used selectively)
Each processor is bound by a data processing agreement and is only permitted to use your data for the purposes we specify.
8. Your Rights
Under GDPR you have the right to access, correct, erase, object to, or restrict the processing of your personal data, as well as the right to data portability. To exercise any of these rights, please contact us. We will respond within 30 days.
You also have the right to lodge a complaint with the Spanish Data Protection Authority (Agencia Española de Protección de Datos — AEPD) at www.aepd.es.
9. Data Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. All data is transmitted over encrypted connections (HTTPS). Access to client data is restricted on a need-to-know basis.
10. Changes
We may update this policy periodically. The latest version will always be available on this page with the date of last revision shown above.
11. Contact
For any privacy-related queries, please contact us.