PRIVACY POLICY

ApexTech Solutions LLC

Effective Date: January 1, 2025
Last Updated: January 1, 2025


1. INTRODUCTION

1.1 General Statement

ApexTech Solutions LLC («we,» «us,» «our,» or the «Company») is committed to protecting the privacy and security of personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you visit our website www.globalretrofit.com (the «Site») and use our related services (collectively, the «Services»).

Registered Office:

ApexTech Solutions LLC
9310 Bellegarde Dr
Charlotte, NC 28277
United States of America

Registered Agent: Ievgen Tymoshenko
Registration Number: SOSID 3154159

1.2 Scope of Application

This Privacy Policy applies to:

  • All visitors to our website
  • Users registering for information or services
  • Potential and current business partners
  • Clients and customers of our services
  • Newsletter subscribers
  • Job applicants

By accessing or using our Site or Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Site or use our Services.


2. INFORMATION WE COLLECT

2.1 Personal Information

We may collect the following categories of personal information:

Contact Information:

  • First and last name
  • Business email address
  • Phone number (including country code)
  • Job title and company name
  • Business postal address
  • LinkedIn profile URL

Professional Information:

  • Company industry and specialization
  • Company size and revenue
  • Technical expertise and certifications
  • Professional experience and background
  • Business development objectives

Communication Data:

  • Correspondence with us via email, phone, or contact forms
  • Recordings of customer service calls (with prior notice)
  • Feedback, reviews, and testimonials
  • Survey responses

Account Information:

  • Username and password (encrypted)
  • Account preferences and settings
  • Subscription and membership information
  • Payment method information (stored by third-party processors)

2.2 Automatically Collected Information

Technical Information:

  • Internet Protocol (IP) address
  • Browser type and version
  • Operating system and device type
  • Geographic location (country, state/province, city)
  • Browser language preferences
  • Screen resolution and device identifiers

Usage Data:

  • Pages viewed and time spent on pages
  • Clickstream data and navigation patterns
  • Date and time of visits
  • Referring/exit pages and URLs
  • Search queries within our Site
  • Downloaded files and content accessed
  • Links clicked and features used

Cookies and Similar Technologies:

  • HTTP cookies (session and persistent)
  • Web beacons and pixel tags
  • Local storage and session storage
  • Flash cookies and HTML5 storage
  • Device fingerprinting data

2.3 Information from Third Parties

Professional Networks:

  • LinkedIn profile data (when you connect your account)
  • Professional certifications from verification services
  • Business contact information from data providers

Public Sources:

  • Publicly available company information
  • Industry publications and directories
  • Conference attendee lists and speaker profiles
  • Patent databases and technical publications

Business Partners:

  • Referral information from partners
  • Joint project collaboration data
  • Co-marketing campaign metrics

3. LEGAL BASIS FOR PROCESSING (GDPR/UK GDPR)

For individuals in the European Economic Area (EEA), United Kingdom, and Switzerland, we process personal data based on the following legal grounds:

3.1 Consent (Article 6(1)(a) GDPR)

  • Marketing communications and newsletters
  • Optional cookies and tracking technologies
  • Testimonials and case study participation
  • Photography and video content usage

3.2 Contractual Necessity (Article 6(1)(b) GDPR)

  • Providing requested Services
  • Processing case study submissions
  • Managing business partnerships
  • Fulfilling contractual obligations

3.3 Legitimate Interests (Article 6(1)(f) GDPR)

  • Website functionality and security
  • Fraud prevention and detection
  • Network and information security
  • Analytics and service improvement
  • Direct marketing to business contacts (B2B)

3.4 Legal Obligations (Article 6(1)(c) GDPR)

  • Tax and accounting requirements
  • Regulatory compliance
  • Law enforcement requests
  • Legal proceedings and dispute resolution

4. HOW WE USE YOUR INFORMATION

4.1 Service Provision

Core Services:

  • Processing case study submissions and inquiries
  • Providing access to our knowledge library
  • Facilitating partner connections and networking
  • Delivering technical support and assistance
  • Managing user accounts and subscriptions

Business Operations:

  • Processing and fulfilling service requests
  • Managing business relationships
  • Administering partnerships and collaborations
  • Coordinating projects and deliverables
  • Providing customer service and support

4.2 Communications

Transactional Communications:

  • Order confirmations and service updates
  • Account notifications and security alerts
  • Response to inquiries and support requests
  • Legal notices and policy updates

Marketing Communications (with consent):

  • Newsletter subscriptions
  • Industry insights and white papers
  • Event invitations and webinar announcements
  • Product updates and new service launches
  • Case study and success story highlights

4.3 Analytics and Improvement

Site Optimization:

  • Analyzing user behavior and preferences
  • A/B testing of features and content
  • Identifying technical issues and bugs
  • Optimizing site performance and speed
  • Improving user experience and navigation

Business Intelligence:

  • Market research and trend analysis
  • Competitive intelligence gathering
  • Service development and innovation
  • Strategic planning and forecasting
  • ROI and effectiveness measurement

4.4 Security and Fraud Prevention

Security Measures:

  • Detecting and preventing unauthorized access
  • Monitoring for suspicious activities
  • Investigating security incidents
  • Protecting against cyber threats
  • Ensuring data integrity and availability

Fraud Prevention:

  • Verifying identity and credentials
  • Detecting fraudulent submissions
  • Preventing abuse of services
  • Protecting against spam and bots

5. INFORMATION SHARING AND DISCLOSURE

5.1 No Sale of Personal Data

ApexTech Solutions LLC does NOT sell, rent, or trade personal information to third parties for monetary or other valuable consideration.

5.2 Service Providers and Processors

We share personal information with trusted third-party service providers who perform services on our behalf:

Technical Infrastructure:

  • Cloud Hosting: Amazon Web Services (AWS), Google Cloud Platform
  • Content Delivery: Cloudflare CDN
  • Email Services: Google Workspace, SendGrid, Mailchimp
  • CRM Systems: HubSpot, Salesforce
  • Analytics: Google Analytics, Hotjar

Payment Processing:

  • Payment Gateways: Stripe, PayPal
  • Note: We do not store complete credit card information on our servers

Marketing and Communications:

  • Email Marketing: Mailchimp, SendGrid
  • Social Media Management: Hootsuite, Buffer
  • Advertising Networks: Google Ads, LinkedIn Ads

All service providers are bound by contractual obligations to:

  • Process data only as instructed
  • Implement appropriate security measures
  • Comply with applicable data protection laws
  • Maintain confidentiality
  • Delete or return data upon termination

5.3 Business Partners

With Your Explicit Consent:

  • Sharing case studies with industry publications
  • Joint webinars and co-marketing initiatives
  • Partnership opportunities and collaborations
  • Referrals to qualified service providers

Business Transfers: In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, personal information may be transferred to the successor entity, subject to:

  • Prior notice to affected individuals
  • Continuation of privacy protections
  • Right to object or delete data (where applicable)

We may disclose personal information when required by law or to protect our rights:

Legal Obligations:

  • Compliance with court orders and subpoenas
  • Response to lawful requests from government authorities
  • Tax authorities and regulatory agencies
  • Law enforcement investigations
  • National security requirements

Rights Protection:

  • Enforcing our Terms of Service and agreements
  • Protecting against legal liability
  • Investigating potential violations
  • Defending against legal claims
  • Protecting safety and security of users

5.5 International Data Transfers

Transfers Outside Your Country: When transferring personal data internationally, we implement appropriate safeguards:

For EU/EEA Data:

  • Standard Contractual Clauses (SCCs) approved by European Commission
  • Adequacy Decisions for countries with adequate protection
  • Binding Corporate Rules (BCRs) where applicable
  • Explicit Consent for specific transfers

For UK Data:

  • UK Standard Contractual Clauses
  • UK adequacy decisions
  • International Data Transfer Agreements (IDTA)

For Other Jurisdictions:

  • Contractual protections
  • Industry standard security measures
  • Compliance with local transfer requirements

6. COOKIES AND TRACKING TECHNOLOGIES

6.1 What Are Cookies

Cookies are small text files stored on your device when you visit our Site. They help us provide functionality, remember your preferences, and understand how you use our Services.

6.2 Types of Cookies We Use

Strictly Necessary Cookies (Always Active)

These cookies are essential for the Site to function and cannot be disabled:

Cookie Name Purpose Duration
session_id User authentication and security Session
csrf_token Protection against cross-site request forgery Session
cookie_consent Records your cookie preferences 12 months
load_balancer Distributes traffic across servers Session

Functional Cookies

These cookies enable enhanced functionality and personalization:

Cookie Name Provider Purpose Duration
language_pref ApexTech Remembers language selection 12 months
region_pref ApexTech Remembers geographic preferences 12 months
ui_settings ApexTech Stores interface preferences 6 months
recent_searches ApexTech Saves recent search queries 30 days

Analytics Cookies

These cookies help us understand how visitors use our Site:

Cookie Name Provider Purpose Duration
_ga Google Analytics Distinguishes users 2 years
_gid Google Analytics Distinguishes users 24 hours
_gat Google Analytics Throttles request rate 1 minute
_hjid Hotjar User identification 365 days
_hjIncludedInPageviewSample Hotjar Pageview sampling 30 minutes

Marketing Cookies

These cookies track visitors across websites to display relevant advertisements:

Cookie Name Provider Purpose Duration
_fbp Facebook Facebook Pixel tracking 3 months
li_sugr LinkedIn LinkedIn Insight Tag 3 months
IDE Google Google Ads tracking 13 months
NID Google Google personalization 6 months
bcookie LinkedIn Browser identification 2 years

Browser Controls: You can control cookies through your browser settings:

  • Chrome: Settings → Privacy and Security → Cookies
  • Firefox: Options → Privacy & Security → Cookies
  • Safari: Preferences → Privacy → Cookies
  • Edge: Settings → Privacy & Security → Cookies

Our Cookie Consent Tool: You can manage your cookie preferences using our Cookie Consent Manager at any time by clicking the cookie icon at the bottom of our Site.

Third-Party Opt-Out Tools:

Impact of Disabling Cookies: Please note that blocking certain cookies may impact functionality:

  • Unable to log in or maintain sessions
  • Loss of personalized settings
  • Inability to complete forms or transactions
  • Reduced site performance

6.4 Other Tracking Technologies

Web Beacons (Pixel Tags): Small graphics embedded in web pages or emails to:

  • Track email open rates
  • Monitor page visits
  • Measure campaign effectiveness

Local Storage: HTML5 local storage for:

  • Offline functionality
  • Performance optimization
  • User preference storage

Device Fingerprinting: Collection of device characteristics for:

  • Fraud prevention
  • Security enhancement
  • User identification without cookies

7. YOUR PRIVACY RIGHTS

7.1 Rights Under GDPR (EU/EEA/UK)

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights:

Right of Access (Article 15)

  • Request confirmation of data processing
  • Obtain a copy of your personal data
  • Receive information about processing purposes and recipients

Right to Rectification (Article 16)

  • Correct inaccurate personal data
  • Complete incomplete personal data
  • Update outdated information

Right to Erasure / «Right to be Forgotten» (Article 17)

  • Request deletion of personal data when:
    • No longer necessary for original purpose
    • Consent is withdrawn
    • Objection to processing is successful
    • Data processed unlawfully
    • Legal obligation requires deletion

Right to Restriction of Processing (Article 18)

  • Temporarily restrict processing when:
    • Accuracy is contested
    • Processing is unlawful but you oppose deletion
    • We no longer need data but you need it for legal claims
    • Objection to processing is pending verification

Right to Data Portability (Article 20)

  • Receive personal data in structured, machine-readable format
  • Transmit data directly to another controller (where technically feasible)
  • Applies to data processed by automated means with consent or contract basis

Right to Object (Article 21)

  • Object to processing based on legitimate interests
  • Absolute right to object to direct marketing
  • Object to profiling and automated decision-making

Right Not to be Subject to Automated Decision-Making (Article 22)

  • Protection from decisions based solely on automated processing
  • Right to human intervention in significant automated decisions
  • Right to contest and explain automated decisions

Right to Lodge a Complaint You have the right to lodge a complaint with a supervisory authority:

  • Ireland: Data Protection Commission (DPC)
  • UK: Information Commissioner’s Office (ICO)
  • Germany: Federal Commissioner for Data Protection
  • France: Commission Nationale de l’Informatique et des Libertés (CNIL)
  • Your local EU/EEA data protection authority

7.2 Rights Under CCPA/CPRA (California)

California residents have specific rights under the California Consumer Privacy Act:

Right to Know (Section 1798.100)

  • Categories of personal information collected
  • Specific pieces of personal information
  • Sources of personal information
  • Business or commercial purposes for collection
  • Categories of third parties with whom we share

Right to Delete (Section 1798.105)

  • Request deletion of personal information
  • Exceptions for legal obligations and legitimate business needs

Right to Opt-Out of Sale (Section 1798.120)

  • We do NOT sell personal information
  • Right to opt-out if practices change

Right to Non-Discrimination (Section 1798.125)

  • Equal service and pricing regardless of privacy rights exercise
  • No denial of goods or services
  • No different prices or service quality

Right to Correct (CPRA Amendment)

  • Request correction of inaccurate personal information
  • Effective January 1, 2023

Right to Limit Use of Sensitive Personal Information (CPRA)

  • Limit use of sensitive personal information
  • Effective January 1, 2023

California «Shine the Light» Law

  • Annual disclosure of information sharing for direct marketing purposes
  • Request via: privacy@apextechsolutions.com

7.3 Rights Under Other US State Laws

Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA):

  • Right to confirm processing
  • Right to access personal data
  • Right to correct inaccuracies
  • Right to delete personal data
  • Right to obtain copy of data
  • Right to opt out of targeted advertising
  • Right to opt out of sale of personal data
  • Right to opt out of profiling

7.4 Rights in Other Jurisdictions

Brazil (LGPD):

  • Confirmation of processing
  • Access to data
  • Correction of incomplete, inaccurate, or outdated data
  • Anonymization, blocking, or deletion
  • Portability to another service provider
  • Information about public and private entities with shared data
  • Information about possibility of denying consent
  • Revocation of consent

Canada (PIPEDA):

  • Right to access personal information
  • Right to challenge accuracy
  • Right to withdraw consent
  • Right to file complaint with Privacy Commissioner

Australia (Privacy Act):

  • Access to personal information
  • Correction of personal information
  • Complaint to Office of Australian Information Commissioner (OAIC)

CIS Countries (Russia, Kazakhstan, Belarus, etc.):

  • Access to personal data
  • Correction or deletion of inaccurate data
  • Withdrawal of consent
  • Localization requirements compliance (Russia)

8. HOW TO EXERCISE YOUR RIGHTS

8.1 Contact Methods

Email: library@globalretrofit.com
Phone: +1(980)267-8784
Mail:

ApexTech Solutions LLC
Attn: Data Protection Officer
9310 Bellegarde Dr
Charlotte, NC 28277
United States

Online Form: https://www.globalretrofit.com/privacy-request

8.2 Verification Process

To protect your privacy, we must verify your identity before processing requests:

Standard Verification:

  • Email confirmation
  • Account credentials
  • Matching personal information (name, company, phone)

Enhanced Verification (for sensitive requests):

  • Government-issued ID (redacted)
  • Signed declaration under penalty of perjury (US)
  • Notarized request (for high-sensitivity requests)

8.3 Response Timeline

  • GDPR: 30 days (extendable by 60 days for complex requests)
  • CCPA: 45 days (extendable by 45 days with notice)
  • Other US States: 45 days (extendable by reasonable period)
  • LGPD (Brazil): 15 days
  • General: We strive to respond within 30 days

8.4 Fees

  • First request: FREE
  • Excessive or manifestly unfounded requests: May charge reasonable administrative fee
  • Additional copies: May charge reasonable fee based on administrative costs

9. DATA SECURITY

9.1 Technical Safeguards

Encryption:

  • In Transit: TLS 1.3 encryption for all data transmissions
  • At Rest: AES-256 encryption for stored data
  • Database: Encrypted database storage
  • Backups: Encrypted backup systems

Access Controls:

  • Multi-factor authentication (MFA) for administrative access
  • Role-based access control (RBAC)
  • Principle of least privilege
  • Regular access reviews and revocations
  • VPN requirements for remote access

Network Security:

  • Firewalls and intrusion detection/prevention systems (IDS/IPS)
  • DDoS protection via Cloudflare
  • Network segmentation and isolation
  • Regular vulnerability scanning
  • Penetration testing (annual)

Application Security:

  • Secure coding practices (OWASP Top 10)
  • Regular security audits and code reviews
  • Web Application Firewall (WAF)
  • SQL injection and XSS protection
  • CSRF token protection

9.2 Organizational Safeguards

Personnel Security:

  • Background checks for employees with data access
  • Confidentiality and non-disclosure agreements
  • Regular security awareness training (quarterly)
  • Incident response training
  • Clear roles and responsibilities

Policies and Procedures:

  • Information Security Policy
  • Incident Response Plan
  • Business Continuity and Disaster Recovery Plan
  • Data Retention and Destruction Policy
  • Third-Party Risk Management Policy

Physical Security:

  • Secure data center facilities (AWS/GCP Tier IV)
  • Restricted physical access
  • Video surveillance
  • Environmental controls
  • Asset management and tracking

9.3 Monitoring and Logging

Security Monitoring:

  • 24/7 security operations center (SOC)
  • Real-time threat detection
  • Automated alert systems
  • Security Information and Event Management (SIEM)
  • Log analysis and correlation

Audit Logging:

  • Comprehensive audit trails
  • User activity logging
  • System access logs
  • Data modification tracking
  • Log retention: 12 months minimum

9.4 Incident Response

Breach Notification: In the event of a data breach, we will:

  • Contain: Immediately contain and mitigate the breach
  • Assess: Evaluate scope and impact within 72 hours
  • Notify Regulators:
    • GDPR: Within 72 hours to supervisory authority
    • CCPA: Without unreasonable delay
    • Other jurisdictions: Per applicable law
  • Notify Affected Individuals:
    • Without undue delay
    • Via email or prominent website notice
    • Including nature of breach, data affected, mitigation steps
  • Remediate: Implement corrective measures
  • Document: Maintain comprehensive incident records

Post-Incident Review:

  • Root cause analysis
  • Lessons learned documentation
  • Process and policy updates
  • Additional security measures implementation

10. DATA RETENTION

10.1 Retention Periods

Active Users and Customers:

  • Account data: Duration of relationship + 3 years
  • Transaction records: 7 years (tax/accounting requirements)
  • Communication records: 3 years
  • Support tickets: 5 years

Marketing Contacts:

  • Newsletter subscribers: Until unsubscribe + 30 days
  • Marketing leads: 3 years from last interaction
  • Event attendees: 2 years from event date

Business Partners:

  • Contract data: Duration of contract + 7 years
  • Project documentation: 7 years after completion
  • Case study materials: Indefinitely (unless withdrawal requested)

Employment Records:

  • Job applications: 2 years
  • Employee records: 7 years after termination

Legal and Compliance:

  • Legal proceedings: Duration + 7 years
  • Compliance records: Per regulatory requirements (typically 7 years)
  • Audit logs: 12-36 months

10.2 Retention Criteria

We determine retention periods based on:

  • Purpose for which data was collected
  • Nature and sensitivity of data
  • Legal, regulatory, or contractual obligations
  • Business operational needs
  • Your preferences and consent
  • Industry best practices

10.3 Secure Deletion

Upon expiration of retention period, we:

  • Digital Data: Secure deletion using DoD 5220.22-M or NIST 800-88 standards
  • Physical Records: Shredding or incineration
  • Backup Systems: Overwriting or secure erasure
  • Third-Party Storage: Verified deletion certificates
  • Anonymization: Conversion to anonymous data for statistical purposes

11. CHILDREN’S PRIVACY

11.1 Age Restrictions

Our Services are intended for business professionals and are NOT directed to individuals under 18 years of age. We do not knowingly collect personal information from children.

Age Verification:

  • Users must confirm they are 18+ when registering
  • Automated age screening
  • Parental consent mechanisms (where required)

11.2 COPPA Compliance (United States)

We comply with the Children’s Online Privacy Protection Act (COPPA):

  • Do not knowingly collect information from children under 13
  • Do not direct content to children under 13
  • No targeted advertising to children under 13

11.3 Discovery of Minor’s Information

If we discover we have collected information from a child under 18:

  • Immediate deletion of all collected data
  • Notification to parents/guardians (if identifiable)
  • System updates to prevent future occurrences

Parents/Guardians: If you believe we have collected information from a minor, contact us immediately at: privacy@apextechsolutions.com


12. INTERNATIONAL DATA TRANSFERS

12.1 Cross-Border Data Flows

As a global business, we may transfer personal data to:

  • Our offices and affiliates in different countries
  • Service providers and processors worldwide
  • Business partners in various jurisdictions

Primary Data Locations:

  • United States (primary hosting — AWS US-East)
  • European Union (EU regional hosting — AWS Frankfurt)
  • Asia-Pacific (regional hosting — AWS Singapore)

12.2 Transfer Mechanisms

For Transfers from EU/EEA:

  • Standard Contractual Clauses (SCCs) — EU Commission Decision 2021/914
  • Adequacy Decisions — For countries deemed adequate by EU Commission
  • Binding Corporate Rules — When applicable
  • Derogations — Article 49 GDPR (explicit consent, contract necessity)

For Transfers from UK:

  • UK International Data Transfer Agreement (IDTA)
  • UK Standard Contractual Clauses
  • UK Adequacy Regulations

For Transfers from Switzerland:

  • Swiss-approved Standard Contractual Clauses
  • Swiss Federal Data Protection Act compliance

12.3 Transfer Impact Assessments

We conduct Transfer Impact Assessments (TIAs) to evaluate:

  • Legal framework in destination country
  • Supplementary measures needed
  • Alternative transfer mechanisms
  • Risks to data subjects

12.4 Data Localization Requirements

Russia:

  • Personal data of Russian citizens stored and processed on servers located in Russia
  • Cross-border transfer notifications to Roskomnadzor

China:

  • Compliance with Personal Information Protection Law (PIPL)
  • Critical Information Infrastructure (CII) data localization

Other Jurisdictions:

  • Compliance with local data residency requirements
  • Regional data storage where mandated

13. THIRD-PARTY LINKS AND SERVICES

Our Site may contain links to third-party websites, applications, or services not operated by us:

Disclaimer:

  • We are NOT responsible for privacy practices of third parties
  • This Privacy Policy does NOT apply to third-party sites
  • We do NOT endorse or make representations about third-party services

Recommendation:

  • Review privacy policies of any third-party sites you visit
  • Exercise caution when providing personal information
  • Understand data practices before engaging

13.2 Social Media Integration

Social Media Plugins: Our Site includes social media features from:

  • LinkedIn (share buttons, company page embeds)
  • Twitter/X (share buttons, embedded tweets)
  • Facebook (share buttons, page plugins)
  • YouTube (embedded videos)

Data Collection: These features may:

  • Collect your IP address and page visits
  • Set cookies to enable proper functionality
  • Are governed by the privacy policy of the providing company

Your Controls:

  • Browser cookie settings
  • Social media privacy settings
  • Opt-out tools provided by platforms

13.3 Third-Party Analytics

Google Analytics:

Hotjar:


14. DO NOT TRACK SIGNALS

14.1 DNT Disclosure

Currently, our Site does not respond to Do Not Track (DNT) browser signals or similar mechanisms due to:

  • Lack of industry-wide standard for DNT interpretation
  • Technical limitations in current implementation
  • Reliance on third-party analytics that may not honor DNT

14.2 Alternative Privacy Controls

Instead, we offer:

  • Cookie Consent Manager — Granular control over cookie categories
  • Privacy Settings — Account-level privacy preferences
  • Opt-Out Links — Direct opt-out for marketing communications
  • Browser Controls — Standard cookie management through browsers

14.3 Future Developments

We are monitoring developments in:

  • Global Privacy Control (GPC) standard
  • DNT industry consensus
  • Regulatory guidance on browser signals

We may implement DNT response mechanisms as standards evolve.


15. CALIFORNIA-SPECIFIC DISCLOSURES

15.1 «Shine the Light» Law

Under California Civil Code Section 1798.83, California residents may request:

  • Information about personal information disclosed to third parties for direct marketing
  • Names and addresses of third parties receiving information
  • Annual request limit: One per calendar year

Request Process: Email: california-privacy@apextechsolutions.com
Subject Line: «California Shine the Light Request»

Our Disclosure: We do NOT share personal information with third parties for their direct marketing purposes.

15.2 CCPA/CPRA Metrics (Annual Disclosure)

In compliance with CCPA Section 1798.100(d), we provide the following metrics for the preceding 12 months:

Privacy Requests Received:

  • Right to Know: [X] requests
  • Right to Delete: [X] requests
  • Right to Correct: [X] requests
  • Right to Opt-Out: [X] requests (Note: We don’t sell data)

Response Metrics:

  • Median response time: [X] days
  • Requests granted (in whole or part): [X]%
  • Requests denied: [X]%
  • Average days to respond: [X] days

Categories of Personal Information Collected: (See Section 2 of this Privacy Policy)

Business/Commercial Purposes: (See Section 4 of this Privacy Policy)

Categories Disclosed: (See Section 5 of this Privacy Policy)


16. EUROPEAN UNION SPECIFIC PROVISIONS

16.1 Data Protection Officer

For GDPR compliance, we have appointed a Data Protection Officer:

EU Data Protection Officer:

Email: library@globalretrofit.com
Phone: +1(980)267-8784 

16.2 EU Representative

For individuals in the EU/EEA, our EU representative is:

ApexTech Solutions LLC
9310 Bellegarde Dr
Charlotte, NC 28277
Email: library@globalretrofit.com 

16.3 Supervisory Authority

Our lead supervisory authority is:

Irish Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
Phone: +353 (0)761 104 800
Website: www.dataprotection.ie

16.4 Data Processing Records

We maintain records of processing activities per Article 30 GDPR, including:

  • Purposes of processing
  • Categories of data subjects and personal data
  • Categories of recipients
  • International transfers
  • Retention periods
  • Security measures

17. UNITED KINGDOM SPECIFIC PROVISIONS

17.1 UK Representative

For UK data subjects, our UK representative is:

ApexTech Solutions LLC
9310 Bellegarde Dr
Charlotte, NC 28277
Email: library@globalretrofit.com 

17.2 ICO Registration

We are registered with the UK Information Commissioner’s Office:

  • ICO Registration Number: [XXXXXXXX]
  • Registration Status: Active
  • Next Renewal: [Date]

17.3 UK Supervisory Authority

Information Commissioner's Office (ICO)
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
United Kingdom
Phone: +44 (0) 303 123 1113
Website: www.ico.org.uk

18. UPDATES TO THIS PRIVACY POLICY

18.1 Modification Rights

We reserve the right to modify this Privacy Policy at any time to reflect:

  • Changes in our data practices
  • New legal or regulatory requirements
  • Technological developments
  • Business operational changes
  • Feedback from data protection authorities

18.2 Notice of Changes

Material Changes: We will notify you of material changes through:

  • Email notification to registered users
  • Prominent notice on our homepage
  • Pop-up notification on Site
  • 30 days advance notice before effective date

Non-Material Changes:

  • Updated «Last Updated» date
  • Posted on Privacy Policy page
  • Effective immediately upon posting

18.3 Version History

We maintain a version history of Privacy Policy changes:

  • Version 1.0 — Effective: January 1, 2025 — Initial publication
  • Future versions will be archived and accessible

18.4 Continued Use Constitutes Acceptance

Your continued use of our Services after modifications constitutes acceptance of the updated Privacy Policy. If you do not agree with changes, you must:

  • Discontinue use of Services
  • Request deletion of your account and data
  • Contact us with concerns

19. CONTACT INFORMATION

19.1 General Privacy Inquiries

Privacy Team:

Email: library@globalretrofit.com 
Phone: +1(980)267-8784
Response Time: 5-8 business days

19.2 Data Protection Officer

Ievgen Tymoshenko
Data Protection Officer
ApexTech Solutions LLC
9310 Bellegarde Dr
Charlotte, NC 28277
United States

Email:library@globalretrofit.com 
Phone: +1(980)267-8784

19.3 Regional Contact Points

North America:

Email:library@globalretrofit.com 
Phone: +1(980)267-8784

Europe:

Email:library@globalretrofit.com 
Phone: +1(980)267-8784

Asia-Pacific:

Email:library@globalretrofit.com 
Phone: +1(980)267-8784

19.4 Complaint or Concern

If you have a complaint about our privacy practices:

Step 1: Contact our Privacy Team (above)
Step 2: Escalate to Data Protection Officer if unresolved
Step 3: File complaint with relevant supervisory authority:

  • EU/EEA: Local Data Protection Authority
  • UK: Information Commissioner’s Office (ICO)
  • California: California Attorney General
  • Other US States: State Attorney General
  • Canada: Privacy Commissioner of Canada
  • Australia: Office of Australian Information Commissioner

20. SPECIAL PROVISIONS FOR SPECIFIC JURISDICTIONS

20.1 CIS Countries (Russia, Belarus, Kazakhstan)

Russia:

  • Compliance with Federal Law No. 152-FZ «On Personal Data»
  • Cross-border transfer notifications to Roskomnadzor
  • Data localization for Russian citizens’ data
  • Operator’s registry inclusion

Kazakhstan:

  • Law «On Personal Data and Its Protection» compliance
  • Data protection principles adherence
  • Cross-border transfer requirements

Belarus:

  • Law «On Information, Informatization and Protection of Information»
  • Personal data protection measures

20.2 Brazil (LGPD)

  • Compliance with Lei Geral de Proteção de Dados (LGPD)
  • Legal basis for processing clearly identified
  • Data subject rights honored within 15 days
  • ANPD (National Data Protection Authority) notification procedures

20.3 Canada (PIPEDA)

  • Personal Information Protection and Electronic Documents Act compliance
  • Consent mechanisms per PIPEDA guidelines
  • Privacy Commissioner of Canada complaint procedures
  • Provincial privacy law compliance (Quebec, BC, Alberta)

20.4 Australia (Privacy Act)

  • Australian Privacy Principles (APPs) compliance
  • Notification of Eligible Data Breaches scheme
  • OAIC (Office of Australian Information Commissioner) coordination
  • Cross-border disclosure requirements

20.5 Singapore (PDPA)

  • Personal Data Protection Act compliance
  • Do Not Call Registry compliance
  • PDPC (Personal Data Protection Commission) guidelines
  • Data breach notification within 72 hours

21. ACCESSIBILITY

This Privacy Policy is designed to be accessible to all individuals:

Alternative Formats:

  • Large print version: Available upon request
  • Screen reader compatible HTML version
  • PDF version for download
  • Plain language summary available

Request Alternative Format: Email: accessibility@apextechsolutions.com


22. LANGUAGE

This Privacy Policy is provided in English as the primary language. Translations may be available for convenience:

Available Translations:

  • Spanish (Español)
  • German (Deutsch)
  • French (Français)
  • Russian (Русский)
  • Chinese (中文)

Conflicts: In case of conflicts between English version and translations, the English version prevails.


23. ENTIRE AGREEMENT

This Privacy Policy, together with our Terms of Service, constitutes the entire agreement between you and ApexTech Solutions LLC regarding privacy practices and supersedes all prior agreements and understandings.


Last Updated: January 1, 2025
Effective Date: January 1, 2025
Version: 1.0

Document Control:

  • Owner: Data Protection Officer
  • Review Cycle: Annual (or as required by law)
  • Next Review Date: January 1, 2026
  • Approval: Legal Department, Executive Management