Legal
Privacy Policy
This policy explains what personal data Apexphi collects, why we collect it, and what you can do about it. It covers the Apexphi website at apexphi.com and the My Apexphi client application for iOS and Android.
Last updated 3 September 2026.
Who we are
Apexphi is a Salesforce and digital transformation consultancy. We are the data controller for the personal data described in this policy.
For anything relating to privacy, including requests about your data, contact us at privacy@apexphi.com.
What the My Apexphi application collects
My Apexphi is a private workspace for clients of Apexphi. You create your own sign-in account through Microsoft Entra, which Apexphi operates as its customer identity directory. That account exists solely to access My Apexphi. Apexphi then grants it access to the client workspace you are entitled to see.
Account identity
Your name, email address, and the user identifier created for your account in the Apexphi customer directory when you register. Apexphi separately records which client workspace and role that account may access.
To sign you in and show you only the workspace you are entitled to see.
Profile details
Display name, given name, surname, and an optional profile photo. Names are read from and written back to your directory record when you edit them. Photos are uploaded by you.
To personalize your workspace and show who you are to your delivery team.
Support requests
The summary and description you type when you raise a request, plus your name and email as the reporter.
To create and track the request with your Apexphi delivery team.
Delivery information
Projects, consumption, licensed products, and published reports belonging to your organization. This is your employer's business information rather than your personal data, but it is shown to you through your account.
To provide the service the application exists to deliver.
Technical records
Standard server records such as IP address, timestamp, and request path, generated when the application talks to our servers. For Android notifications, Firebase automatically generates a per-installation identifier and processes the application version and basic device metadata, such as the operating-system version, device model, brand, and form factor. If you enable notifications, Apexphi also receives a device-specific Apple or Firebase push registration token and the device platform. These identifiers are used to deliver notifications to this app installation; they do not give Apexphi access to other content on your device.
To operate the service securely, deliver notifications, and diagnose faults.
What the website collects
You can browse apexphi.com without giving us anything. We only collect personal data if you choose to contact us.
Enquiry details
The name, email address, company, and message you submit through the contact form.
To respond to your enquiry and manage it as a sales lead.
Spam protection signals
Google reCAPTCHA assesses the contact form submission and returns a score to us.
To stop automated abuse of the form.
Technical records
Standard server and hosting logs generated when you load a page.
To operate and secure the site.
What we do not do
We want to be specific about this, because it is unusual:
- Advertising identifiers, ad networks, or any cross-app or cross-site tracking.
- Third-party analytics, product telemetry, or crash-reporting SDKs inside the mobile application.
- Location data, contacts, calendars, microphone, or camera access.
- Biometric data. Face ID and Touch ID on iOS, and biometric authentication on Android, are handled entirely by the operating system. The application only receives a success or failure result and never sees or stores your fingerprint, face scan, or other biometric information.
- Special category data such as health, political, or religious information.
We do not sell your personal data, and we do not share it with anyone for advertising or marketing purposes.
Why we are allowed to use it
Where data protection law requires a legal basis, we rely on the performance of our agreement with you and with the client organization you are associated with, and on our legitimate interest in operating a secure client portal and responding to enquiries. Where we rely on your consent, such as an optional profile photo, you can withdraw it at any time.
Who else processes your data
We use a small number of service providers. They act on our instructions and are not permitted to use your data for their own purposes.
| Provider | Purpose |
|---|---|
| Microsoft | Entra customer identity directory and sign-in |
| Apple | Apple Push Notification service for iOS notifications |
| Atlassian | Jira Service Management, which holds support requests |
| Neon | Managed PostgreSQL database |
| Cloudflare | R2 object storage for reports and images |
| Vercel | Application hosting and content delivery |
| reCAPTCHA on the website contact form and Firebase Cloud Messaging for Android push notifications | |
| Salesforce | CRM that receives website contact enquiries |
What is stored on your device
The mobile application keeps the following in its own private storage. Deleting the application removes all of it.
Sign-in tokens
Stored using secure platform storage managed by the Microsoft Authentication Library, including the iOS Keychain and Android-protected application storage, so you are not asked to sign in every time.
Session cookie
A secure, HTTP-only session cookie issued by our servers after you sign in.
Preferences
The last client workspace you viewed and whether you enabled the biometric lock.
Cached profile photo
Held in the application's private cache, protected by iOS file protection or Android's application sandbox and device encryption.
Downloaded reports
PDF and CSV files you choose to download or export, kept in the application's temporary storage.
Push notification token
Apple Push Notification service or Firebase Cloud Messaging may issue a token for this installation. The app stores the token locally and, after you sign in, sends it to Apexphi so notifications can reach this device. You can disable notification permission at any time in iOS or Android system settings.
How long we keep it
We keep your account and profile data for as long as your account remains active, and delete it when you ask us to close the account. Support requests are retained for as long as we need them to service and audit the engagement. Website enquiries are kept in our CRM until they are no longer commercially relevant. Server logs are kept for a short operational period and then discarded.
How we protect it
All traffic between the application and our servers is encrypted in transit. Sign-in tokens are protected using platform security provided through the Microsoft Authentication Library, cached images are protected by the operating system, and you can enable Face ID or Touch ID on iOS or biometric protection backed by Android Keystore on Android. The biometric unlock is cryptographically bound to the device and the application never receives the underlying biometric data. Access to production data inside Apexphi is limited to staff who need it.
International transfers
Our service providers operate globally, so your data may be processed outside the country where you are based. Where required, we rely on the safeguards those providers offer, including standard contractual clauses.
Your rights
Depending on where you live, you may have the right to:
- Ask for a copy of the personal data we hold about you.
- Ask us to correct information that is wrong or incomplete.
- Ask us to delete your personal data.
- Ask us to restrict or object to how we use it.
- Ask for your data in a portable, machine-readable format.
- Complain to your local data protection authority.
To exercise any of these, email us from your work address at privacy@apexphi.com. We will respond within 30 days.
Deleting your account
You can close your My Apexphi account and delete the personal data held against it at any time from the Legal section of your profile in the application.
In-app deletion removes your Microsoft directory account, Apexphi portal profile and access, and uploaded profile photo, then signs the application out. Microsoft retains a deleted directory account in a recoverable state for up to 30 days before permanently removing it. If you cannot access the application, email privacy@apexphi.com from the address you sign in with, or contact your Apexphi engagement lead.
You can remove your profile photo yourself at any time from the profile screen in the application. We may need to retain a limited set of records, such as support request history, where we have a legal or contractual obligation to do so; we will tell you if that applies to you. Business information belonging to the client organization you worked with is not deleted, because it does not belong to your personal account.
Children
Our website and application are intended for business use by adults. We do not knowingly collect personal data from children.
Changes to this policy
If we change how we handle personal data we will update this page and revise the date above. Material changes affecting the application will also be communicated to your organization.
Contact us
Questions, requests, or complaints about this policy can be sent to privacy@apexphi.com. If you are not satisfied with our response, you may complain to your local data protection authority.