Apexa Ventures

Legal & privacy

Privacy & cookies

Who is responsible

APEXA VENTURE HOLDINGS ESPAÑA, Spain, operating as Apexa Ventures, is the controller for personal data processed to operate this website and respond to business enquiries. This notice concerns this website and related enquiries, not the separate activities of portfolio companies.

What we process and why

When you visit, Netlify, our hosting provider, processes technical request information, which may include your IP address, browser and device information, requested pages, timestamps and security logs. This supports delivery of the website, troubleshooting and protection against abuse. Our legal basis is our legitimate interest in providing a reliable, secure business website (Article 6(1)(f) GDPR).

If you contact us, we process the name, contact details and message you choose to provide to answer your enquiry. Routine business correspondence is processed on the basis of our legitimate interest in responding to enquiries (Article 6(1)(f)). Where you ask us to take steps before entering into a contract with you, Article 6(1)(b) applies. Where a specific legal duty requires processing, Article 6(1)(c) applies. Providing enquiry information is voluntary; without sufficient details we may be unable to respond.

Minimal collection

This website has no contact forms, newsletter registration, checkout, advertising pixels or visitor analytics added by Apexa Ventures. Fonts and images are hosted locally. We do not use this website for automated decisions or profiling with legal or similarly significant effects.

Retention

We delete or anonymise routine business enquiries when the enquiry has been resolved and no further action is required. Where particular records must be retained under a specific legal obligation, only the required records are retained for that obligation’s applicable period, with access restricted. Correspondence that becomes part of a contract or another business relationship is handled under the retention requirements applicable to that relationship.

Technical hosting and security data are retained for the period necessary to deliver and secure the service, subject to Netlify’s applicable service terms and legal obligations. Apexa Ventures does not create an additional archive of visitor traffic logs. The enquiry deletion policy does not override the separate retention rules of a platform you choose to use, such as LinkedIn.

Service providers and international transfers

Netlify and its authorised subprocessors provide hosting and security services. Relevant technical data may be processed outside the European Economic Area, including in the United States. Netlify’s Data Processing Agreement describes the applicable processing terms and international-transfer safeguards, including Standard Contractual Clauses where required. For processing Netlify performs as a controller in its own right, see its Privacy Statement.

Information may also be disclosed where a legal obligation requires it. Following an external link takes you to a separate service with its own privacy practices. If you contact us via LinkedIn, that platform processes the information under its own privacy terms.

Cookies and local storage

The website code does not set cookies or use browser storage, and does not load advertising, analytics or social-media embeds. Links to LinkedIn do not load LinkedIn content unless you follow them. Hosting-level security features may operate separately from the website code. You can manage cookies through your browser settings. If optional tracking is introduced, this notice and the relevant consent controls will be updated before it is enabled.

Your rights

Under the GDPR, subject to its conditions, you may request access, rectification, erasure, restriction or portability of your personal data. You may object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting the lawfulness of earlier processing. To make a request about information shared with us, contact Apexa Ventures through the same channel you used for your enquiry or through our company page. We may request proportionate information to verify your identity.

We respond without undue delay and normally within one month. Where the GDPR permits an extension for complex or numerous requests, we will explain the extension within the first month. You may lodge a complaint with the Agencia Española de Protección de Datos (AEPD), or another competent supervisory authority, including in the EU country where you live or work.

Updates

We may revise this notice when the website or its processing changes. The date above identifies the latest revision.