ApexTech Solutions LLC
Effective Date: January 1, 2025
Last Updated: January 1, 2025
1. INTRODUCTION
1.1 General Statement
ApexTech Solutions LLC («we,» «us,» «our,» or the «Company») is committed to protecting the privacy and security of personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you visit our website www.globalretrofit.com (the «Site») and use our related services (collectively, the «Services»).
Registered Office:
ApexTech Solutions LLC
9310 Bellegarde Dr
Charlotte, NC 28277
United States of America
Registered Agent: Ievgen Tymoshenko
Registration Number: SOSID 3154159
1.2 Scope of Application
This Privacy Policy applies to:
- All visitors to our website
- Users registering for information or services
- Potential and current business partners
- Clients and customers of our services
- Newsletter subscribers
- Job applicants
1.3 Consent and Agreement
By accessing or using our Site or Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Site or use our Services.
2. INFORMATION WE COLLECT
2.1 Personal Information
We may collect the following categories of personal information:
Contact Information:
- First and last name
- Business email address
- Phone number (including country code)
- Job title and company name
- Business postal address
- LinkedIn profile URL
Professional Information:
- Company industry and specialization
- Company size and revenue
- Technical expertise and certifications
- Professional experience and background
- Business development objectives
Communication Data:
- Correspondence with us via email, phone, or contact forms
- Recordings of customer service calls (with prior notice)
- Feedback, reviews, and testimonials
- Survey responses
Account Information:
- Username and password (encrypted)
- Account preferences and settings
- Subscription and membership information
- Payment method information (stored by third-party processors)
2.2 Automatically Collected Information
Technical Information:
- Internet Protocol (IP) address
- Browser type and version
- Operating system and device type
- Geographic location (country, state/province, city)
- Browser language preferences
- Screen resolution and device identifiers
Usage Data:
- Pages viewed and time spent on pages
- Clickstream data and navigation patterns
- Date and time of visits
- Referring/exit pages and URLs
- Search queries within our Site
- Downloaded files and content accessed
- Links clicked and features used
Cookies and Similar Technologies:
- HTTP cookies (session and persistent)
- Web beacons and pixel tags
- Local storage and session storage
- Flash cookies and HTML5 storage
- Device fingerprinting data
2.3 Information from Third Parties
Professional Networks:
- LinkedIn profile data (when you connect your account)
- Professional certifications from verification services
- Business contact information from data providers
Public Sources:
- Publicly available company information
- Industry publications and directories
- Conference attendee lists and speaker profiles
- Patent databases and technical publications
Business Partners:
- Referral information from partners
- Joint project collaboration data
- Co-marketing campaign metrics
3. LEGAL BASIS FOR PROCESSING (GDPR/UK GDPR)
For individuals in the European Economic Area (EEA), United Kingdom, and Switzerland, we process personal data based on the following legal grounds:
3.1 Consent (Article 6(1)(a) GDPR)
- Marketing communications and newsletters
- Optional cookies and tracking technologies
- Testimonials and case study participation
- Photography and video content usage
3.2 Contractual Necessity (Article 6(1)(b) GDPR)
- Providing requested Services
- Processing case study submissions
- Managing business partnerships
- Fulfilling contractual obligations
3.3 Legitimate Interests (Article 6(1)(f) GDPR)
- Website functionality and security
- Fraud prevention and detection
- Network and information security
- Analytics and service improvement
- Direct marketing to business contacts (B2B)
3.4 Legal Obligations (Article 6(1)(c) GDPR)
- Tax and accounting requirements
- Regulatory compliance
- Law enforcement requests
- Legal proceedings and dispute resolution
4. HOW WE USE YOUR INFORMATION
4.1 Service Provision
Core Services:
- Processing case study submissions and inquiries
- Providing access to our knowledge library
- Facilitating partner connections and networking
- Delivering technical support and assistance
- Managing user accounts and subscriptions
Business Operations:
- Processing and fulfilling service requests
- Managing business relationships
- Administering partnerships and collaborations
- Coordinating projects and deliverables
- Providing customer service and support
4.2 Communications
Transactional Communications:
- Order confirmations and service updates
- Account notifications and security alerts
- Response to inquiries and support requests
- Legal notices and policy updates
Marketing Communications (with consent):
- Newsletter subscriptions
- Industry insights and white papers
- Event invitations and webinar announcements
- Product updates and new service launches
- Case study and success story highlights
4.3 Analytics and Improvement
Site Optimization:
- Analyzing user behavior and preferences
- A/B testing of features and content
- Identifying technical issues and bugs
- Optimizing site performance and speed
- Improving user experience and navigation
Business Intelligence:
- Market research and trend analysis
- Competitive intelligence gathering
- Service development and innovation
- Strategic planning and forecasting
- ROI and effectiveness measurement
4.4 Security and Fraud Prevention
Security Measures:
- Detecting and preventing unauthorized access
- Monitoring for suspicious activities
- Investigating security incidents
- Protecting against cyber threats
- Ensuring data integrity and availability
Fraud Prevention:
- Verifying identity and credentials
- Detecting fraudulent submissions
- Preventing abuse of services
- Protecting against spam and bots
5. INFORMATION SHARING AND DISCLOSURE
5.1 No Sale of Personal Data
ApexTech Solutions LLC does NOT sell, rent, or trade personal information to third parties for monetary or other valuable consideration.
5.2 Service Providers and Processors
We share personal information with trusted third-party service providers who perform services on our behalf:
Technical Infrastructure:
- Cloud Hosting: Amazon Web Services (AWS), Google Cloud Platform
- Content Delivery: Cloudflare CDN
- Email Services: Google Workspace, SendGrid, Mailchimp
- CRM Systems: HubSpot, Salesforce
- Analytics: Google Analytics, Hotjar
Payment Processing:
- Payment Gateways: Stripe, PayPal
- Note: We do not store complete credit card information on our servers
Marketing and Communications:
- Email Marketing: Mailchimp, SendGrid
- Social Media Management: Hootsuite, Buffer
- Advertising Networks: Google Ads, LinkedIn Ads
All service providers are bound by contractual obligations to:
- Process data only as instructed
- Implement appropriate security measures
- Comply with applicable data protection laws
- Maintain confidentiality
- Delete or return data upon termination
5.3 Business Partners
With Your Explicit Consent:
- Sharing case studies with industry publications
- Joint webinars and co-marketing initiatives
- Partnership opportunities and collaborations
- Referrals to qualified service providers
Business Transfers: In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, personal information may be transferred to the successor entity, subject to:
- Prior notice to affected individuals
- Continuation of privacy protections
- Right to object or delete data (where applicable)
5.4 Legal Requirements and Protection
We may disclose personal information when required by law or to protect our rights:
Legal Obligations:
- Compliance with court orders and subpoenas
- Response to lawful requests from government authorities
- Tax authorities and regulatory agencies
- Law enforcement investigations
- National security requirements
Rights Protection:
- Enforcing our Terms of Service and agreements
- Protecting against legal liability
- Investigating potential violations
- Defending against legal claims
- Protecting safety and security of users
5.5 International Data Transfers
Transfers Outside Your Country: When transferring personal data internationally, we implement appropriate safeguards:
For EU/EEA Data:
- Standard Contractual Clauses (SCCs) approved by European Commission
- Adequacy Decisions for countries with adequate protection
- Binding Corporate Rules (BCRs) where applicable
- Explicit Consent for specific transfers
For UK Data:
- UK Standard Contractual Clauses
- UK adequacy decisions
- International Data Transfer Agreements (IDTA)
For Other Jurisdictions:
- Contractual protections
- Industry standard security measures
- Compliance with local transfer requirements
6. COOKIES AND TRACKING TECHNOLOGIES
6.1 What Are Cookies
Cookies are small text files stored on your device when you visit our Site. They help us provide functionality, remember your preferences, and understand how you use our Services.
6.2 Types of Cookies We Use
Strictly Necessary Cookies (Always Active)
These cookies are essential for the Site to function and cannot be disabled:
| Cookie Name | Purpose | Duration |
|---|---|---|
| session_id | User authentication and security | Session |
| csrf_token | Protection against cross-site request forgery | Session |
| cookie_consent | Records your cookie preferences | 12 months |
| load_balancer | Distributes traffic across servers | Session |
Functional Cookies
These cookies enable enhanced functionality and personalization:
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
| language_pref | ApexTech | Remembers language selection | 12 months |
| region_pref | ApexTech | Remembers geographic preferences | 12 months |
| ui_settings | ApexTech | Stores interface preferences | 6 months |
| recent_searches | ApexTech | Saves recent search queries | 30 days |
Analytics Cookies
These cookies help us understand how visitors use our Site:
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
| _ga | Google Analytics | Distinguishes users | 2 years |
| _gid | Google Analytics | Distinguishes users | 24 hours |
| _gat | Google Analytics | Throttles request rate | 1 minute |
| _hjid | Hotjar | User identification | 365 days |
| _hjIncludedInPageviewSample | Hotjar | Pageview sampling | 30 minutes |
Marketing Cookies
These cookies track visitors across websites to display relevant advertisements:
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
| _fbp | Facebook Pixel tracking | 3 months | |
| li_sugr | LinkedIn Insight Tag | 3 months | |
| IDE | Google Ads tracking | 13 months | |
| NID | Google personalization | 6 months | |
| bcookie | Browser identification | 2 years |
6.3 Cookie Management
Browser Controls: You can control cookies through your browser settings:
- Chrome: Settings → Privacy and Security → Cookies
- Firefox: Options → Privacy & Security → Cookies
- Safari: Preferences → Privacy → Cookies
- Edge: Settings → Privacy & Security → Cookies
Our Cookie Consent Tool: You can manage your cookie preferences using our Cookie Consent Manager at any time by clicking the cookie icon at the bottom of our Site.
Third-Party Opt-Out Tools:
- Google Analytics Opt-out: https://tools.google.com/dlpage/gaoptout
- Network Advertising Initiative: https://optout.networkadvertising.org/
- Digital Advertising Alliance: https://www.aboutads.info/choices/
Impact of Disabling Cookies: Please note that blocking certain cookies may impact functionality:
- Unable to log in or maintain sessions
- Loss of personalized settings
- Inability to complete forms or transactions
- Reduced site performance
6.4 Other Tracking Technologies
Web Beacons (Pixel Tags): Small graphics embedded in web pages or emails to:
- Track email open rates
- Monitor page visits
- Measure campaign effectiveness
Local Storage: HTML5 local storage for:
- Offline functionality
- Performance optimization
- User preference storage
Device Fingerprinting: Collection of device characteristics for:
- Fraud prevention
- Security enhancement
- User identification without cookies
7. YOUR PRIVACY RIGHTS
7.1 Rights Under GDPR (EU/EEA/UK)
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights:
Right of Access (Article 15)
- Request confirmation of data processing
- Obtain a copy of your personal data
- Receive information about processing purposes and recipients
Right to Rectification (Article 16)
- Correct inaccurate personal data
- Complete incomplete personal data
- Update outdated information
Right to Erasure / «Right to be Forgotten» (Article 17)
- Request deletion of personal data when:
- No longer necessary for original purpose
- Consent is withdrawn
- Objection to processing is successful
- Data processed unlawfully
- Legal obligation requires deletion
Right to Restriction of Processing (Article 18)
- Temporarily restrict processing when:
- Accuracy is contested
- Processing is unlawful but you oppose deletion
- We no longer need data but you need it for legal claims
- Objection to processing is pending verification
Right to Data Portability (Article 20)
- Receive personal data in structured, machine-readable format
- Transmit data directly to another controller (where technically feasible)
- Applies to data processed by automated means with consent or contract basis
Right to Object (Article 21)
- Object to processing based on legitimate interests
- Absolute right to object to direct marketing
- Object to profiling and automated decision-making
Right Not to be Subject to Automated Decision-Making (Article 22)
- Protection from decisions based solely on automated processing
- Right to human intervention in significant automated decisions
- Right to contest and explain automated decisions
Right to Lodge a Complaint You have the right to lodge a complaint with a supervisory authority:
- Ireland: Data Protection Commission (DPC)
- UK: Information Commissioner’s Office (ICO)
- Germany: Federal Commissioner for Data Protection
- France: Commission Nationale de l’Informatique et des Libertés (CNIL)
- Your local EU/EEA data protection authority
7.2 Rights Under CCPA/CPRA (California)
California residents have specific rights under the California Consumer Privacy Act:
Right to Know (Section 1798.100)
- Categories of personal information collected
- Specific pieces of personal information
- Sources of personal information
- Business or commercial purposes for collection
- Categories of third parties with whom we share
Right to Delete (Section 1798.105)
- Request deletion of personal information
- Exceptions for legal obligations and legitimate business needs
Right to Opt-Out of Sale (Section 1798.120)
- We do NOT sell personal information
- Right to opt-out if practices change
Right to Non-Discrimination (Section 1798.125)
- Equal service and pricing regardless of privacy rights exercise
- No denial of goods or services
- No different prices or service quality
Right to Correct (CPRA Amendment)
- Request correction of inaccurate personal information
- Effective January 1, 2023
Right to Limit Use of Sensitive Personal Information (CPRA)
- Limit use of sensitive personal information
- Effective January 1, 2023
California «Shine the Light» Law
- Annual disclosure of information sharing for direct marketing purposes
- Request via: privacy@apextechsolutions.com
7.3 Rights Under Other US State Laws
Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA):
- Right to confirm processing
- Right to access personal data
- Right to correct inaccuracies
- Right to delete personal data
- Right to obtain copy of data
- Right to opt out of targeted advertising
- Right to opt out of sale of personal data
- Right to opt out of profiling
7.4 Rights in Other Jurisdictions
Brazil (LGPD):
- Confirmation of processing
- Access to data
- Correction of incomplete, inaccurate, or outdated data
- Anonymization, blocking, or deletion
- Portability to another service provider
- Information about public and private entities with shared data
- Information about possibility of denying consent
- Revocation of consent
Canada (PIPEDA):
- Right to access personal information
- Right to challenge accuracy
- Right to withdraw consent
- Right to file complaint with Privacy Commissioner
Australia (Privacy Act):
- Access to personal information
- Correction of personal information
- Complaint to Office of Australian Information Commissioner (OAIC)
CIS Countries (Russia, Kazakhstan, Belarus, etc.):
- Access to personal data
- Correction or deletion of inaccurate data
- Withdrawal of consent
- Localization requirements compliance (Russia)
8. HOW TO EXERCISE YOUR RIGHTS
8.1 Contact Methods
Email: library@globalretrofit.com
Phone: +1(980)267-8784
Mail:
ApexTech Solutions LLC
Attn: Data Protection Officer
9310 Bellegarde Dr
Charlotte, NC 28277
United States
Online Form: https://www.globalretrofit.com/privacy-request
8.2 Verification Process
To protect your privacy, we must verify your identity before processing requests:
Standard Verification:
- Email confirmation
- Account credentials
- Matching personal information (name, company, phone)
Enhanced Verification (for sensitive requests):
- Government-issued ID (redacted)
- Signed declaration under penalty of perjury (US)
- Notarized request (for high-sensitivity requests)
8.3 Response Timeline
- GDPR: 30 days (extendable by 60 days for complex requests)
- CCPA: 45 days (extendable by 45 days with notice)
- Other US States: 45 days (extendable by reasonable period)
- LGPD (Brazil): 15 days
- General: We strive to respond within 30 days
8.4 Fees
- First request: FREE
- Excessive or manifestly unfounded requests: May charge reasonable administrative fee
- Additional copies: May charge reasonable fee based on administrative costs
9. DATA SECURITY
9.1 Technical Safeguards
Encryption:
- In Transit: TLS 1.3 encryption for all data transmissions
- At Rest: AES-256 encryption for stored data
- Database: Encrypted database storage
- Backups: Encrypted backup systems
Access Controls:
- Multi-factor authentication (MFA) for administrative access
- Role-based access control (RBAC)
- Principle of least privilege
- Regular access reviews and revocations
- VPN requirements for remote access
Network Security:
- Firewalls and intrusion detection/prevention systems (IDS/IPS)
- DDoS protection via Cloudflare
- Network segmentation and isolation
- Regular vulnerability scanning
- Penetration testing (annual)
Application Security:
- Secure coding practices (OWASP Top 10)
- Regular security audits and code reviews
- Web Application Firewall (WAF)
- SQL injection and XSS protection
- CSRF token protection
9.2 Organizational Safeguards
Personnel Security:
- Background checks for employees with data access
- Confidentiality and non-disclosure agreements
- Regular security awareness training (quarterly)
- Incident response training
- Clear roles and responsibilities
Policies and Procedures:
- Information Security Policy
- Incident Response Plan
- Business Continuity and Disaster Recovery Plan
- Data Retention and Destruction Policy
- Third-Party Risk Management Policy
Physical Security:
- Secure data center facilities (AWS/GCP Tier IV)
- Restricted physical access
- Video surveillance
- Environmental controls
- Asset management and tracking
9.3 Monitoring and Logging
Security Monitoring:
- 24/7 security operations center (SOC)
- Real-time threat detection
- Automated alert systems
- Security Information and Event Management (SIEM)
- Log analysis and correlation
Audit Logging:
- Comprehensive audit trails
- User activity logging
- System access logs
- Data modification tracking
- Log retention: 12 months minimum
9.4 Incident Response
Breach Notification: In the event of a data breach, we will:
- Contain: Immediately contain and mitigate the breach
- Assess: Evaluate scope and impact within 72 hours
- Notify Regulators:
- GDPR: Within 72 hours to supervisory authority
- CCPA: Without unreasonable delay
- Other jurisdictions: Per applicable law
- Notify Affected Individuals:
- Without undue delay
- Via email or prominent website notice
- Including nature of breach, data affected, mitigation steps
- Remediate: Implement corrective measures
- Document: Maintain comprehensive incident records
Post-Incident Review:
- Root cause analysis
- Lessons learned documentation
- Process and policy updates
- Additional security measures implementation
10. DATA RETENTION
10.1 Retention Periods
Active Users and Customers:
- Account data: Duration of relationship + 3 years
- Transaction records: 7 years (tax/accounting requirements)
- Communication records: 3 years
- Support tickets: 5 years
Marketing Contacts:
- Newsletter subscribers: Until unsubscribe + 30 days
- Marketing leads: 3 years from last interaction
- Event attendees: 2 years from event date
Business Partners:
- Contract data: Duration of contract + 7 years
- Project documentation: 7 years after completion
- Case study materials: Indefinitely (unless withdrawal requested)
Employment Records:
- Job applications: 2 years
- Employee records: 7 years after termination
Legal and Compliance:
- Legal proceedings: Duration + 7 years
- Compliance records: Per regulatory requirements (typically 7 years)
- Audit logs: 12-36 months
10.2 Retention Criteria
We determine retention periods based on:
- Purpose for which data was collected
- Nature and sensitivity of data
- Legal, regulatory, or contractual obligations
- Business operational needs
- Your preferences and consent
- Industry best practices
10.3 Secure Deletion
Upon expiration of retention period, we:
- Digital Data: Secure deletion using DoD 5220.22-M or NIST 800-88 standards
- Physical Records: Shredding or incineration
- Backup Systems: Overwriting or secure erasure
- Third-Party Storage: Verified deletion certificates
- Anonymization: Conversion to anonymous data for statistical purposes
11. CHILDREN’S PRIVACY
11.1 Age Restrictions
Our Services are intended for business professionals and are NOT directed to individuals under 18 years of age. We do not knowingly collect personal information from children.
Age Verification:
- Users must confirm they are 18+ when registering
- Automated age screening
- Parental consent mechanisms (where required)
11.2 COPPA Compliance (United States)
We comply with the Children’s Online Privacy Protection Act (COPPA):
- Do not knowingly collect information from children under 13
- Do not direct content to children under 13
- No targeted advertising to children under 13
11.3 Discovery of Minor’s Information
If we discover we have collected information from a child under 18:
- Immediate deletion of all collected data
- Notification to parents/guardians (if identifiable)
- System updates to prevent future occurrences
Parents/Guardians: If you believe we have collected information from a minor, contact us immediately at: privacy@apextechsolutions.com
12. INTERNATIONAL DATA TRANSFERS
12.1 Cross-Border Data Flows
As a global business, we may transfer personal data to:
- Our offices and affiliates in different countries
- Service providers and processors worldwide
- Business partners in various jurisdictions
Primary Data Locations:
- United States (primary hosting — AWS US-East)
- European Union (EU regional hosting — AWS Frankfurt)
- Asia-Pacific (regional hosting — AWS Singapore)
12.2 Transfer Mechanisms
For Transfers from EU/EEA:
- Standard Contractual Clauses (SCCs) — EU Commission Decision 2021/914
- Adequacy Decisions — For countries deemed adequate by EU Commission
- Binding Corporate Rules — When applicable
- Derogations — Article 49 GDPR (explicit consent, contract necessity)
For Transfers from UK:
- UK International Data Transfer Agreement (IDTA)
- UK Standard Contractual Clauses
- UK Adequacy Regulations
For Transfers from Switzerland:
- Swiss-approved Standard Contractual Clauses
- Swiss Federal Data Protection Act compliance
12.3 Transfer Impact Assessments
We conduct Transfer Impact Assessments (TIAs) to evaluate:
- Legal framework in destination country
- Supplementary measures needed
- Alternative transfer mechanisms
- Risks to data subjects
12.4 Data Localization Requirements
Russia:
- Personal data of Russian citizens stored and processed on servers located in Russia
- Cross-border transfer notifications to Roskomnadzor
China:
- Compliance with Personal Information Protection Law (PIPL)
- Critical Information Infrastructure (CII) data localization
Other Jurisdictions:
- Compliance with local data residency requirements
- Regional data storage where mandated
13. THIRD-PARTY LINKS AND SERVICES
13.1 External Links
Our Site may contain links to third-party websites, applications, or services not operated by us:
Disclaimer:
- We are NOT responsible for privacy practices of third parties
- This Privacy Policy does NOT apply to third-party sites
- We do NOT endorse or make representations about third-party services
Recommendation:
- Review privacy policies of any third-party sites you visit
- Exercise caution when providing personal information
- Understand data practices before engaging
13.2 Social Media Integration
Social Media Plugins: Our Site includes social media features from:
- LinkedIn (share buttons, company page embeds)
- Twitter/X (share buttons, embedded tweets)
- Facebook (share buttons, page plugins)
- YouTube (embedded videos)
Data Collection: These features may:
- Collect your IP address and page visits
- Set cookies to enable proper functionality
- Are governed by the privacy policy of the providing company
Your Controls:
- Browser cookie settings
- Social media privacy settings
- Opt-out tools provided by platforms
13.3 Third-Party Analytics
Google Analytics:
- Tracking code on our Site
- Collects anonymized usage data
- Subject to Google’s privacy policy
- Opt-out: https://tools.google.com/dlpage/gaoptout
Hotjar:
- Heatmaps and session recordings
- User behavior analysis
- Anonymized data collection
- Opt-out: https://www.hotjar.com/policies/do-not-track/
14. DO NOT TRACK SIGNALS
14.1 DNT Disclosure
Currently, our Site does not respond to Do Not Track (DNT) browser signals or similar mechanisms due to:
- Lack of industry-wide standard for DNT interpretation
- Technical limitations in current implementation
- Reliance on third-party analytics that may not honor DNT
14.2 Alternative Privacy Controls
Instead, we offer:
- Cookie Consent Manager — Granular control over cookie categories
- Privacy Settings — Account-level privacy preferences
- Opt-Out Links — Direct opt-out for marketing communications
- Browser Controls — Standard cookie management through browsers
14.3 Future Developments
We are monitoring developments in:
- Global Privacy Control (GPC) standard
- DNT industry consensus
- Regulatory guidance on browser signals
We may implement DNT response mechanisms as standards evolve.
15. CALIFORNIA-SPECIFIC DISCLOSURES
15.1 «Shine the Light» Law
Under California Civil Code Section 1798.83, California residents may request:
- Information about personal information disclosed to third parties for direct marketing
- Names and addresses of third parties receiving information
- Annual request limit: One per calendar year
Request Process: Email: california-privacy@apextechsolutions.com
Subject Line: «California Shine the Light Request»
Our Disclosure: We do NOT share personal information with third parties for their direct marketing purposes.
15.2 CCPA/CPRA Metrics (Annual Disclosure)
In compliance with CCPA Section 1798.100(d), we provide the following metrics for the preceding 12 months:
Privacy Requests Received:
- Right to Know: [X] requests
- Right to Delete: [X] requests
- Right to Correct: [X] requests
- Right to Opt-Out: [X] requests (Note: We don’t sell data)
Response Metrics:
- Median response time: [X] days
- Requests granted (in whole or part): [X]%
- Requests denied: [X]%
- Average days to respond: [X] days
Categories of Personal Information Collected: (See Section 2 of this Privacy Policy)
Business/Commercial Purposes: (See Section 4 of this Privacy Policy)
Categories Disclosed: (See Section 5 of this Privacy Policy)
16. EUROPEAN UNION SPECIFIC PROVISIONS
16.1 Data Protection Officer
For GDPR compliance, we have appointed a Data Protection Officer:
EU Data Protection Officer:
Email: library@globalretrofit.com
Phone: +1(980)267-8784
16.2 EU Representative
For individuals in the EU/EEA, our EU representative is:
ApexTech Solutions LLC
9310 Bellegarde Dr
Charlotte, NC 28277
Email: library@globalretrofit.com
16.3 Supervisory Authority
Our lead supervisory authority is:
Irish Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
Phone: +353 (0)761 104 800
Website: www.dataprotection.ie
16.4 Data Processing Records
We maintain records of processing activities per Article 30 GDPR, including:
- Purposes of processing
- Categories of data subjects and personal data
- Categories of recipients
- International transfers
- Retention periods
- Security measures
17. UNITED KINGDOM SPECIFIC PROVISIONS
17.1 UK Representative
For UK data subjects, our UK representative is:
ApexTech Solutions LLC
9310 Bellegarde Dr
Charlotte, NC 28277
Email: library@globalretrofit.com
17.2 ICO Registration
We are registered with the UK Information Commissioner’s Office:
- ICO Registration Number: [XXXXXXXX]
- Registration Status: Active
- Next Renewal: [Date]
17.3 UK Supervisory Authority
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
United Kingdom
Phone: +44 (0) 303 123 1113
Website: www.ico.org.uk
18. UPDATES TO THIS PRIVACY POLICY
18.1 Modification Rights
We reserve the right to modify this Privacy Policy at any time to reflect:
- Changes in our data practices
- New legal or regulatory requirements
- Technological developments
- Business operational changes
- Feedback from data protection authorities
18.2 Notice of Changes
Material Changes: We will notify you of material changes through:
- Email notification to registered users
- Prominent notice on our homepage
- Pop-up notification on Site
- 30 days advance notice before effective date
Non-Material Changes:
- Updated «Last Updated» date
- Posted on Privacy Policy page
- Effective immediately upon posting
18.3 Version History
We maintain a version history of Privacy Policy changes:
- Version 1.0 — Effective: January 1, 2025 — Initial publication
- Future versions will be archived and accessible
18.4 Continued Use Constitutes Acceptance
Your continued use of our Services after modifications constitutes acceptance of the updated Privacy Policy. If you do not agree with changes, you must:
- Discontinue use of Services
- Request deletion of your account and data
- Contact us with concerns
19. CONTACT INFORMATION
19.1 General Privacy Inquiries
Privacy Team:
Email: library@globalretrofit.com
Phone: +1(980)267-8784
Response Time: 5-8 business days
19.2 Data Protection Officer
Ievgen Tymoshenko
Data Protection Officer
ApexTech Solutions LLC
9310 Bellegarde Dr
Charlotte, NC 28277
United States
Email:library@globalretrofit.com
Phone: +1(980)267-8784
19.3 Regional Contact Points
North America:
Email:library@globalretrofit.com
Phone: +1(980)267-8784
Europe:
Email:library@globalretrofit.com
Phone: +1(980)267-8784
Asia-Pacific:
Email:library@globalretrofit.com
Phone: +1(980)267-8784
19.4 Complaint or Concern
If you have a complaint about our privacy practices:
Step 1: Contact our Privacy Team (above)
Step 2: Escalate to Data Protection Officer if unresolved
Step 3: File complaint with relevant supervisory authority:
- EU/EEA: Local Data Protection Authority
- UK: Information Commissioner’s Office (ICO)
- California: California Attorney General
- Other US States: State Attorney General
- Canada: Privacy Commissioner of Canada
- Australia: Office of Australian Information Commissioner
20. SPECIAL PROVISIONS FOR SPECIFIC JURISDICTIONS
20.1 CIS Countries (Russia, Belarus, Kazakhstan)
Russia:
- Compliance with Federal Law No. 152-FZ «On Personal Data»
- Cross-border transfer notifications to Roskomnadzor
- Data localization for Russian citizens’ data
- Operator’s registry inclusion
Kazakhstan:
- Law «On Personal Data and Its Protection» compliance
- Data protection principles adherence
- Cross-border transfer requirements
Belarus:
- Law «On Information, Informatization and Protection of Information»
- Personal data protection measures
20.2 Brazil (LGPD)
- Compliance with Lei Geral de Proteção de Dados (LGPD)
- Legal basis for processing clearly identified
- Data subject rights honored within 15 days
- ANPD (National Data Protection Authority) notification procedures
20.3 Canada (PIPEDA)
- Personal Information Protection and Electronic Documents Act compliance
- Consent mechanisms per PIPEDA guidelines
- Privacy Commissioner of Canada complaint procedures
- Provincial privacy law compliance (Quebec, BC, Alberta)
20.4 Australia (Privacy Act)
- Australian Privacy Principles (APPs) compliance
- Notification of Eligible Data Breaches scheme
- OAIC (Office of Australian Information Commissioner) coordination
- Cross-border disclosure requirements
20.5 Singapore (PDPA)
- Personal Data Protection Act compliance
- Do Not Call Registry compliance
- PDPC (Personal Data Protection Commission) guidelines
- Data breach notification within 72 hours
21. ACCESSIBILITY
This Privacy Policy is designed to be accessible to all individuals:
Alternative Formats:
- Large print version: Available upon request
- Screen reader compatible HTML version
- PDF version for download
- Plain language summary available
Request Alternative Format: Email: accessibility@apextechsolutions.com
22. LANGUAGE
This Privacy Policy is provided in English as the primary language. Translations may be available for convenience:
Available Translations:
- Spanish (Español)
- German (Deutsch)
- French (Français)
- Russian (Русский)
- Chinese (中文)
Conflicts: In case of conflicts between English version and translations, the English version prevails.
23. ENTIRE AGREEMENT
This Privacy Policy, together with our Terms of Service, constitutes the entire agreement between you and ApexTech Solutions LLC regarding privacy practices and supersedes all prior agreements and understandings.
Last Updated: January 1, 2025
Effective Date: January 1, 2025
Version: 1.0
Document Control:
- Owner: Data Protection Officer
- Review Cycle: Annual (or as required by law)
- Next Review Date: January 1, 2026
- Approval: Legal Department, Executive Management
