Strictly Private & Confidential | September 2026
Data Processing Schedule
Standard personal data processing for APEXE3 clients
Document status | Standard client-facing document |
Version | 2.0 – September 2026 |
Provider | APEXE3 (branded APEX:E3) |
Scope | Personal data processing carried out by APEXE3 on behalf of clients in connection with APEXE3 products, platforms and services |
Purpose and scope. This Data Processing Schedule provides a standard description of how APEXE3 processes personal data on behalf of its clients. It is designed to be shared across APEXE3 clients and is not limited to a particular product, deployment model, industry or use case. It applies where APEXE3 acts as a processor, or performs an equivalent service-provider role under applicable data-protection law. The exact personal data processed will depend on the services used, client configuration and the information supplied by or on behalf of the client.
1. Details of processing
1.1 The details of the processing of personal data carried out by APEXE3 as processor for a client are set out below.
Subject matter, nature and purpose of processing
To provide, host, operate, configure, administer, maintain and support APEXE3 products, platforms and services.
To receive, store, retrieve, organise, analyse, transform, classify, enrich, structure, display, transmit and otherwise process client-provided data as necessary to deliver requested functionality, workflows, integrations, APIs and outputs.
To store, retrieve and update details of client administrators, support contacts and authorised users for authentication, access control, user and role administration, service operation and support.
To process personal data contained in files, documents, records, prompts, messages, datasets, forms or other materials supplied by or on behalf of a client in order to perform client-directed use cases and make outputs available to authorised users or connected systems.
To create and retain operational, security, audit, usage and diagnostic records reasonably necessary to secure, monitor, troubleshoot, support and administer the services.
To perform backup, recovery, resilience and business-continuity activities where APEXE3 manages the relevant environment or service component.
To facilitate approved integrations, secure data exchange and interoperability with systems selected by the client.
Where AI, machine-learning or large-language-model functionality is used, to process the information reasonably required to perform the client-requested AI operation through the configured model environment or service.
To generate anonymised or aggregated information for security, reliability, service improvement and product development where that information no longer identifies an individual or client.
Duration of processing
For as long as APEXE3 provides the relevant services to the client and for any limited period reasonably required to complete support, return, deletion, security, backup rotation or service-closure activities.
Personal data is not retained longer than necessary for the purposes for which it is processed, subject to applicable legal, regulatory, security and backup-retention requirements.
Where a client gives specific documented retention or deletion instructions, APEXE3 will apply them where technically feasible and lawful.
Types of personal data
The precise personal data processed is determined by the client and the services used. It may include:
Identity and contact data: names, business contact details, telephone numbers, email addresses, signatures, job titles and organisational information.
User and account data: usernames, account identifiers, user roles, permissions, authentication information, SSO identifiers and other account-management information.
Technical and security data: IP addresses, network and connection information, device or browser information, session identifiers, timestamps, authentication events, audit logs and system-usage records.
Professional and employment data: employer, role, profession, employment information, qualifications, certifications and professional affiliations where supplied by the client.
Business and transactional data: information contained in client files, documents, records, forms, prompts, messages or datasets, which may include financial, commercial, identification, scheduling, location or other information selected by the client.
Support and administration data: client support contacts, support-ticket content, correspondence, screenshots, logs and technical information supplied for troubleshooting or administration.
Derived data and outputs: extracted fields, metadata, classifications, summaries, analyses and other generated outputs where these relate to an identified or identifiable individual.
Special-category personal data and criminal-conviction data are not required as a standard service feature. If a client chooses to submit such data, APEXE3 will process it only as necessary to provide the requested service, on the client's documented instructions and subject to applicable law.
Categories of data subjects
Authorised users, system administrators, helpdesk contacts, support contacts, employees, officers, agents, temporary workers and contractors of the client or related organisations.
Employees, officers, agents, contractors, customers, prospective customers, suppliers, counterparties, advisers and other individuals whose information is included in data supplied by a client.
Individuals identified or described in files, documents, records, forms, datasets, prompts, messages or other content processed through APEXE3 services.
Members of the public or other individuals whose personal data is incidentally included in client-provided content.
2. Processor obligations
2.1 APEXE3 acknowledges that personal data processed on behalf of a client remains under the control of that client. When acting as processor, APEXE3 shall:
2.1.1 process personal data only on documented instructions from the client, including instructions provided through the configuration and use of the services and through authorised support or administration requests, unless APEXE3 is required to process the personal data by applicable law. Where legally permitted, APEXE3 will inform the client of that requirement before processing;
2.1.2 ensure that persons authorised to process personal data have committed themselves to confidentiality or are subject to an appropriate statutory, professional or contractual duty of confidentiality;
2.1.3 taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risks to individuals, maintain appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk, including the controls described in section 3 of this Schedule;
2.1.4 take reasonable steps to ensure that any person acting under APEXE3's authority who has access to personal data processes it only on the client's documented instructions, unless required to do otherwise by applicable law;
2.1.5 use subprocessors where reasonably necessary to provide or support the services. APEXE3 will apply appropriate due diligence, require suitable written data-protection and confidentiality obligations, and provide reasonable notice of material additions or replacements to subprocessors where required by applicable law;
2.1.6 where APEXE3 engages a subprocessor to carry out processing activities on behalf of a client, impose data-protection obligations that provide a materially equivalent level of protection to the obligations applicable to APEXE3, to the extent required by applicable law;
2.1.7 taking into account the nature of the processing, assist the client through appropriate technical and organisational measures, insofar as reasonably possible, in responding to requests from data subjects exercising rights under applicable data-protection law;
2.1.8 taking into account the nature of the processing and the information available to APEXE3, provide reasonable assistance to the client with obligations concerning security of processing, personal-data-breach notifications, data-protection impact assessments and consultation with a competent supervisory authority where required;
2.1.9 notify the client without undue delay after becoming aware of a personal data breach affecting personal data processed by APEXE3 on the client's behalf, and provide information reasonably available to APEXE3 to support the client's assessment and notification obligations;
2.1.10 at the client's choice, return, delete or otherwise put beyond use personal data when it is no longer required to provide the relevant services, and delete existing copies unless applicable law requires continued storage. Backup copies will be removed in accordance with normal backup-retention and rotation processes;
2.1.11 make available information reasonably necessary to demonstrate compliance with the processor obligations described in this Schedule and cooperate with reasonable assurance or audit requests. Audits will ordinarily be limited to once per calendar year, on reasonable written notice, unless a competent regulator requires otherwise or a material personal data breach justifies additional review. APEXE3 may use current certifications, independent assurance reports, security documentation, questionnaires or other appropriate evidence where these provide sufficient assurance;
2.1.12 inform the client if, in APEXE3's opinion, a documented processing instruction infringes applicable data-protection law, unless applicable law prohibits APEXE3 from doing so; and
2.1.13 ensure that restricted international transfers of personal data initiated by APEXE3 are made using a lawful transfer mechanism where required. Such mechanisms may include adequacy regulations or decisions, approved standard contractual clauses and applicable UK addenda, the UK Extension to the EU-US Data Privacy Framework, the EU-US Data Privacy Framework, or another legally valid mechanism. Access to a service by an authorised user located outside the United Kingdom or EEA at the client's direction will not, by itself, be treated as a transfer initiated by APEXE3.
3. Technical and organisational measures
APEXE3 maintains a risk-based security programme designed to protect personal data processed on behalf of clients. The specific controls used may vary according to the service, deployment model, hosting environment, integrations and client configuration. Core control areas include:
Control area | APEXE3 approach | Data-protection relevance |
Governance & confidentiality | Access to client personal data is limited to authorised personnel with a legitimate business need. Personnel with access are subject to confidentiality obligations and security policies. | Reduces risk of unauthorised disclosure or use. |
Identity & access control | User, administrator and privileged access is controlled through authentication, roles, permissions and least-privilege principles. Enterprise identity controls such as SSO and MFA may be supported where relevant. | Restricts personal data and administration functions to authorised identities. |
Segregation & network security | Client environments and data are logically separated as appropriate to the service architecture. Network boundaries, routing controls and restricted service exposure are used to reduce unnecessary access paths. | Helps prevent cross-client access and limits the attack surface. |
Encryption & secure transport | Appropriate encryption and secure transport controls are used to protect data in transit and, where applicable to the service or hosting model, at rest. | Protects personal data during transmission and storage. |
Secure data exchange | APIs, application interfaces, secure file-transfer mechanisms and approved integrations use authentication and access controls appropriate to the integration. | Controls how personal data enters and leaves APEXE3-managed service boundaries. |
Logging & monitoring | Operational, authentication, access, usage and security events may be logged and monitored for security, availability, troubleshooting, support and audit purposes. | Supports detection, investigation, accountability and service integrity. |
Vulnerability & patch management | APEXE3 applies risk-based vulnerability management, security updates and patching to APEXE3-managed components and prioritises remediation according to severity and exposure. | Reduces exposure to known security weaknesses. |
Secure development & change management | Changes to APEXE3-managed software and infrastructure are subject to controlled development, review, testing and deployment practices appropriate to the change. | Reduces the risk of introducing security or privacy defects. |
Backup, resilience & recovery | Where APEXE3 manages the relevant environment, backup and recovery controls may cover application data, configuration, databases, client content and generated outputs, subject to the service design and retention policy. | Supports availability, integrity and recovery while keeping backup copies protected. |
Incident management | Security events are triaged, investigated, contained and remediated through documented operational processes, with escalation and client notification where personal data is affected. | Supports timely response to personal data breaches and security incidents. |
Retention & deletion | Personal data is retained only for as long as required for the service purpose, legal or security needs, and normal backup rotation. Client-directed deletion is applied where technically feasible and lawful. | Supports storage limitation and secure service closure. |
Subprocessor management | Material service providers that may process client personal data are subject to appropriate due diligence, confidentiality and data-protection obligations. | Extends relevant protections to the processing supply chain. |
AI / model processing | Where AI or machine-learning functionality is used, only information reasonably necessary for the requested operation is provided to the configured model component. The model arrangement may vary by service and deployment. | Limits personal data used in AI processing to the client-directed use case. |
Data minimisation | APEXE3 designs and operates services to process only the information reasonably necessary to deliver configured functionality, while clients control the content they submit. | Supports purpose limitation and data minimisation. |
4. Client responsibilities
Clients remain responsible for determining the purposes and lawful basis of their processing and for the personal data they choose to provide to APEXE3. In particular:
Clients should ensure personal data supplied to APEXE3 is lawfully obtained and may lawfully be processed for the instructed purpose.
Clients should provide any privacy information required to individuals and respond to data-subject requests where the client acts as controller, with APEXE3 providing reasonable processor assistance as described above.
Clients should configure and manage users, roles, identity-provider controls, integrations and access permissions in accordance with their own security policies and least-privilege principles.
Clients should limit personal data supplied to APEXE3 to information reasonably required for the relevant use case and should avoid intentionally submitting special-category or criminal-conviction data unless necessary and lawful.
Clients are responsible for the accuracy, quality and completeness of the personal data and instructions they provide.
5. General
5.1 This Schedule is APEXE3's standard client-facing description of its personal-data processing practices when acting as processor. It is intended for use across APEXE3 clients, services and supported deployment models.
5.2 References to personal data, processor, controller, data subject, personal data breach and similar concepts have the meanings given to them under the data-protection laws applicable to the relevant processing.
5.3 APEXE3 may update this Schedule from time to time to reflect changes to its services, subprocessors, security practices or applicable law. Updates will not intentionally result in a material reduction in the overall level of protection provided for client personal data.
Document note: This document is intentionally product-neutral and client-neutral so that it can be shared as APEXE3's standard Data Processing Schedule across its client base.
