Privacy Policy
1. Introduction
1.1 Apolast is committed to protecting the privacy and security of personal data processed in connection with its B2B relationships and services.
1.2 This Privacy Policy describes how Apolast, acting as data controller for certain activities, collects, uses and protects personal data, and explains the on‑premise, “Private AI / Zero Data Retention” nature of the Apolast Software.
2. Scope
2.1 This Privacy Policy applies to personal data relating to:
- a) representatives of Customers, prospective customers, system integrators, suppliers, investors and other business partners;
- b) visitors to Apolast’s websites and recipients of Apolast’s marketing communications;
- c) individuals whose data may be included in limited telemetry or support logs transmitted to Apolast when optional remote support or analytics are enabled.
2.2 This Privacy Policy does not apply to Customer end‑user data or proprietary source code processed solely within Customer’s infrastructure by the on‑premise Software, where Apolast has no access and does not act as controller or processor.
3. Identity of the Controller and Contact Details
3.1 For the activities covered by this Privacy Policy, Apolast (ТОВ) and/or the relevant holding or contracting entity identified in the applicable contract acts as data controller within the meaning of GDPR.
3.2 Contact details for privacy inquiries, including our Data Protection Officer (where required) and support team, can be reached directly via email at contact@apolast.com.
4. Categories of Personal Data
4.1 Apolast may collect and process the following categories of personal data about business contacts:
- a) Identification data: name, position, employer, professional role.
- b) Contact data: business email address, business phone number, postal address, preferred language.
- c) Contract and billing data: invoicing details, tax IDs, payment history, contract metadata.
- d) Communication data: contents of emails, support tickets, meeting notes, feedback and surveys.
- e) Website and marketing data: IP address, device and browser information, cookies and similar identifiers, usage data, preferences, interactions with marketing campaigns.
- f) Telemetry and support data (if enabled): technical logs, error codes, performance metrics and configuration parameters related to Software operation, designed to minimize inclusion of proprietary code or directly identifiable end‑user data.
4.2 Apolast does not intentionally collect special categories of personal data (e.g. health data) in the course of normal B2B activities.
5. Sources of Personal Data
5.1 Personal data is obtained from:
- a) direct interactions (emails, meetings, calls, events);
- b) forms and interfaces on Apolast websites or product portals;
- c) Customer or partner onboarding processes;
- d) optional telemetry and support channels when configured to send data to Apolast;
- e) publicly available business data (e.g. professional networks) where permitted by law.
6. On‑Premise “Private AI” and Zero Data Retention
6.1 The Apolast Software is deployed on‑premise and processes Customer Codebase and related data entirely within Customer’s environment; by default, Customer’s proprietary code and end‑user personal data are not transmitted to Apolast‑controlled servers or public cloud LLMs.
6.2 Apolast follows a “Private AI” and “Zero Data Retention” strategy:
- a) Apolast does not use Customer Codebase or end‑user data to train public LLMs;
- b) Apolast does not routinely store Customer’s application data on its own systems;
- c) any data temporarily accessed for support or troubleshooting is strictly limited, used only for the specific purpose, and deleted or anonymised afterwards.
7. Purposes and Legal Bases
7.1 Apolast processes personal data for the following purposes and legal bases under GDPR:
- a) Contract performance (Art. 6(1)(b) GDPR): managing pre‑contractual discussions, entering into and performing B2B contracts, issuing invoices, delivering Services.
- b) Legal obligations (Art. 6(1)(c) GDPR): complying with accounting, tax, sanctions and regulatory requirements.
- c) Legitimate interests (Art. 6(1)(f) GDPR):
- managing and expanding business relationships;
- ensuring cybersecurity and service integrity;
- improving and supporting the Software (subject to telemetry minimisation);
- defending legal claims and maintaining evidence.
- d) Consent (Art. 6(1)(a) GDPR): for certain marketing communications or optional telemetry where required; consent may be withdrawn at any time.
7.2 Apolast applies GDPR principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability to all relevant processing activities.
8. Relation to DORA and NIS2 Compliance Tooling
8.1 Customers may deploy Apolast as part of internal compliance frameworks under DORA, for example to maintain IT asset inventories, dependency mapping and resilience testing capabilities.
8.2 Customers may use SBOM generation and asset visibility features to support NIS2 supply‑chain security obligations, vendor risk assessments and documentation.
8.3 Apolast does not determine Customer’s purposes for processing end‑user data within Customer’s environment; Customers remain responsible for their own data protection frameworks, notices and role definitions (controller/processor).
9. Data Sharing and Recipients
9.1 Apolast may share personal data, on a need‑to‑know basis, with:
- a) Apolast group companies and holding entities for internal administration and contract fulfillment;
- b) System Integrators and implementation partners engaged by Customer or Apolast to deliver projects, subject to contractual confidentiality and data protection obligations;
- c) professional advisers (lawyers, auditors, accountants);
- d) providers of infrastructure, CRM, communications, ticketing and analytics tools used by Apolast;
- e) competent authorities, regulators or courts, where required by law.
9.2 Apolast does not sell personal data and does not use Customer Codebase or end‑user data to train public LLMs.
10. International Transfers
10.1 Where personal data is transferred outside the European Economic Area, Apolast will implement appropriate safeguards such as:
- a) adequacy decisions under Art. 45 GDPR;
- b) standard contractual clauses (SCCs) or equivalent instruments;
- c) supplementary technical and organisational measures where required.
10.2 Specific transfer mechanisms may be described in the DPA and relevant contract schedules.
11. Data Retention
11.1 Apolast retains personal data only for as long as necessary for the purposes for which it was collected, taking into account:
- a) contractual obligations and limitations periods;
- b) statutory retention requirements (e.g. accounting and tax);
- c) the need to preserve evidence for legal claims.
11.2 After expiry of the retention period, personal data is deleted or irreversibly anonymised, unless further retention is required by law.
12. Data Subject Rights
12.1 Under GDPR and applicable data protection laws, individuals whose personal data Apolast processes may have the following rights (subject to conditions):
- a) right to be informed;
- b) right of access;
- c) right to rectification;
- d) right to erasure;
- e) right to restriction of processing;
- f) right to data portability;
- g) right to object to processing based on legitimate interests or direct marketing;
- h) rights related to automated decision‑making and profiling, where applicable.
12.2 Requests to exercise these rights can be submitted directly via email at contact@apolast.com. Apolast will respond within the time limits set by law, typically one month.
13. Security Measures
13.1 Apolast implements appropriate technical and organisational measures to protect personal data, including:
- a) role‑based access controls;
- b) secure development and deployment practices;
- c) encryption in transit and at rest where proportionate;
- d) logging and monitoring of security‑relevant events;
- e) staff training and confidentiality undertakings.
13.2 For Customers subject to DORA and NIS2, Apolast’s contractual commitments and documentation can assist in vendor and supply‑chain risk assessments.
14. Cookies and Online Tracking
14.1 Apolast’s websites may use cookies and similar technologies to:
- a) enable core site functionality and security;
- b) collect aggregate analytics and performance data;
- c) support limited marketing activities.
14.2 Where required by law, consent will be obtained via a cookie banner or preference center, and users can manage cookie settings or use browser controls to block or delete cookies.
15. Changes to this Privacy Policy
15.1 Apolast may update this Privacy Policy to reflect changes in laws, services or processing activities. The current version will be published on Apolast’s website with the effective date indicated.
15.2 Where changes are significant, Apolast may notify Customers via appropriate channels (e.g. email or customer portals).
16. Contact and Complaints
16.1 For questions about this Privacy Policy or Apolast’s data protection practices, individuals may contact Apolast directly at contact@apolast.com.
16.2 Data subjects have the right to lodge a complaint with their local data protection authority if they believe their rights have been infringed.