Legal
Privacy Policy
Effective Date: July 23, 2026 · Last Updated: July 27, 2026
This Privacy Policy explains how Techtum Inc. (“Techtum,” “we,” “us,” or “our”) collects, uses, stores, discloses, and otherwise processes personal information in connection with Apex.
Apex is an artificial-intelligence-powered organizational and sales intelligence platform. References to the “Services” in this Privacy Policy include Apex, Techtum websites and domains, browser extensions, applications, integrations, APIs, support services, and other related services operated by Techtum.
By accessing or using the Services, you acknowledge the practices described in this Privacy Policy.
1. Scope of this Privacy Policy
This Privacy Policy applies to personal information we process in connection with:
- Visitors to Techtum and Apex websites;
- Individuals who create or use Apex accounts;
- Organizations that purchase, administer, or use Apex;
- Employees, contractors, representatives, and other members of customer workspaces;
- Individuals whose information is included in customer-uploaded or synchronized content;
- Business contacts and prospective customers researched or managed through Apex;
- Individuals who communicate with Techtum; and
- Users of Apex browser extensions, integrations, APIs, and related features.
This Privacy Policy does not govern the independent privacy practices of our customers, connected services, public websites, or other third parties.
2. Techtum’s Role
Information Techtum controls
Techtum generally determines the purposes and means of processing information associated with:
- Techtum website visitors;
- Apex account registration;
- Authentication;
- Service administration;
- Billing;
- Customer support;
- Security;
- Service communications; and
- Techtum’s own business operations.
For this information, Techtum generally acts as a data controller, business, or similar responsible entity under applicable privacy laws.
Customer-controlled information
Organizations and individual customers may upload, synchronize, generate, or otherwise process information through Apex. Customers generally determine what information is added to Apex, which integrations are connected, who receives workspace access, and how Apex outputs are used.
For this Customer Content, Techtum generally acts as a processor, service provider, contractor, or similar entity on behalf of the customer.
When a privacy request relates to Customer Content controlled by an Apex customer, we may refer the request to that customer or ask the requester to contact the relevant organization directly.
3. Information We Collect
The information we collect depends on how a person interacts with Apex, which features are used, and which integrations are authorized.
A. Account and profile information
When someone creates or uses an Apex account, we may collect:
- Name;
- Email address;
- Password or other authentication credentials, where applicable;
- Employer or organization;
- Workspace membership;
- User role and permissions;
- Profile information;
- Account preferences;
- Information associated with Google or Microsoft authentication;
- Login and account activity; and
- Additional information a user chooses to add to their profile.
Apex supports password, passwordless, Google, and Microsoft login methods. Firebase provides account-authentication services.
Using Google or Microsoft to authenticate an Apex account does not automatically authorize Apex to synchronize other Google or Microsoft content. Access to connected-service content requires a separate authorization process.
B. Customer Content
Users and customers may enter, upload, synchronize, create, or generate content through Apex, including:
- Documents, PDFs, presentations, spreadsheets, images, and resumes;
- Contact lists, CRM records, sales notes, and meeting notes;
- Emails and email metadata;
- Calendar information and contact information;
- Meeting transcripts and uploaded audio or video files used for transcription;
- Names, email addresses, phone numbers, and professional information;
- Prompts and questions submitted to Apex;
- AI conversations and generated outputs;
- Feedback and support communications; and
- Other information selected by a customer or user.
Customer Content may contain personal information about users, employees, contractors, customers, business contacts, prospects, meeting participants, or other individuals who do not have Apex accounts.
Users and customers are responsible for ensuring that they have the rights, permissions, notices, and lawful authority necessary to provide Customer Content to Apex.
C. Information from connected services
Apex may allow users to connect third-party services, including Google Drive, Gmail, Google Calendar, Microsoft OneDrive, Microsoft Outlook, Microsoft Calendar, Microsoft SharePoint, Salesforce, Slack, Notion, and other customer-authorized services.
Depending on the service, permissions selected, and features used, Apex may access:
- Files and document content;
- File and folder metadata;
- Email bodies, headers, sender and recipient information;
- Calendar events, titles, times, attendees, and meeting links;
- Messages and communication content;
- CRM accounts, contacts, opportunities, and related records;
- Workspace and organization information; and
- Other information selected by the user.
Users initiate synchronization manually by selecting a synchronization function. Apex does not continuously synchronize connected services unless that behavior is clearly presented to and authorized by the user.
Users may select the services, files, folders, records, or categories of content they want to synchronize, depending on the available integration.
D. What Apex retains after synchronization
Apex does not necessarily keep a separate copy of an original cloud-hosted binary file solely because that file was synchronized. Storage behavior depends on the source and feature.
Currently retained after sync or import (when the feature is used):
| Data type | What Apex retains |
|---|---|
| Gmail / Outlook email | Full email text (headers and body, length-capped) stored as document content, plus chunks, embeddings, and related knowledge-graph records |
| Google Drive / OneDrive / SharePoint documents | Extracted document text, metadata, chunks, embeddings, and related knowledge-graph records; binary originals generally remain at the source unless separately uploaded |
| Google / Microsoft calendar | Meeting metadata such as title, time, duration, attendees, and meeting URL; calendar description text is used to detect meeting links and is not stored as a dedicated description field |
| Uploaded files | File content as stored for the workspace, extracted text, chunks, and embeddings |
| Meeting transcripts | Transcript text and related meeting records |
| AI chats and outputs | Prompts, responses, summaries, classifications, embeddings, rankings, and other generated insights |
Not currently retained as a routine sync result:
| Data type | Current practice |
|---|---|
| Email attachments | Not downloaded or stored by current Gmail/Outlook sync connectors |
| Google / Microsoft contacts sync | Contact synchronization is not currently implemented as a product feature |
| Live meeting audio or video | Streamed for real-time processing when a live feature is used; not stored at rest as audio/video |
| Facial expressions, voiceprints, or biometric voice patterns | Not processed or stored |
| Acoustic sentiment analysis | Not performed; any “sentiment” or relationship indicators are text-derived insights, not biometric analysis |
Apex may retain imported content and processed representations derived from connected or uploaded content, including extracted text, metadata, embeddings, summaries, classifications, entities, relationships, knowledge-graph records, search indexes, recommendations, rankings, risks, objections, competitor references, and other generated insights.
These processed representations may remain in Apex until deleted, even if the original connection is later disconnected.
E. Publicly available and third-party professional information
Apex may collect professional or business-related information from public sources where permitted by applicable law and source terms.
This information may include names, professional profile URLs, public LinkedIn profile information, employer, job title, employment history, education, professional interests, general location, public business contact information, public professional activity, company information, and other publicly available professional information.
Sources may include public websites, professional networking platforms, search engines, customer research, customer-uploaded information, CRM records, emails, meetings, public directories, and other lawful public or customer-authorized sources.
Apex may connect this information to a particular customer workspace through metadata.
F. AI outputs and inferred information
Apex uses Customer Content and other authorized information to generate or infer information such as account summaries, contact summaries, organizational relationships, knowledge-graph connections, relevance rankings, account roles, champion or blocker recommendations, relationship indicators, risks, objections, competitor references, text-based sentiment or relationship indicators, suggested actions, employee-account matching recommendations, and other classifications, scores, or recommendations.
These outputs are generated by automated systems and may be incomplete, inaccurate, or based on limited context.
G. Device, log, and usage information
When a person uses the Services, we may automatically collect information such as:
- IP address;
- Browser type, device type, and operating system;
- Approximate location derived from an IP address;
- Login dates and times;
- Pages or features accessed;
- Search and feature activity;
- API activity;
- Error, crash, and performance information;
- Security events and failed login attempts;
- Session identifiers; and
- Other diagnostic or usage information.
What appears in logs and related systems:
- Application and infrastructure logs may include request paths, timing, status codes, IP addresses, user or workspace identifiers, and error messages or stack traces.
- Client-side error reports may include error messages, stack traces, and page URLs, and are sent to Google Cloud Error Reporting.
- Workspace audit logs may record security and usage events. Prompt text and AI output text are written to audit logs only if a workspace administrator enables prompt or output logging. Those settings default to off and redact content when disabled.
- Chat conversations are stored in the Apex database as part of the product experience, separate from audit-log toggles.
- Techtum does not intentionally write OAuth tokens into application logs.
H. Communications
We collect information when a person requests support, contacts Techtum, participates in a product demonstration, applies for a beta program, responds to a survey, provides feedback, communicates with our sales or customer-success teams, or subscribes to updates or marketing communications.
This may include contact information, correspondence, call or meeting information, feedback, and other information voluntarily provided.
I. Billing information
Paid plans are not currently processed through an integrated payment processor in Apex. When paid plans or purchases are offered, we may collect billing contact information, subscription plan, payment status, invoice information, transaction history, tax information, and limited payment-method information supplied by a third-party payment processor.
Complete payment-card information will be processed by a third-party payment processor rather than stored directly by Techtum. The payment processor will be identified in this Privacy Policy or an associated notice when billing is enabled.
J. Cookies and similar technologies
We may use cookies and similar technologies to authenticate users, maintain sessions, secure the Services, remember preferences, prevent fraud, diagnose technical problems, and operate the Services.
Current practice:
- Apex relies primarily on Firebase Authentication session persistence and browser storage such as localStorage or sessionStorage for workspace and interface preferences.
- Techtum does not currently install third-party advertising, analytics, or session-replay cookies such as Google Analytics, Meta Pixel, Hotjar, Mixpanel, or PostHog in the Apex application.
- Essential authentication, security, and hosting cookies may be set by Firebase, Google identity services, or the hosting provider for the website or application.
- Where required by applicable law, we will request consent before using nonessential cookies or similar technologies.
Techtum does not use Customer Content or information obtained from connected Google or Microsoft services for personalized advertising.
4. How We Use Information
We may use information to:
- Provide, operate, and maintain Apex;
- Create and manage accounts and workspaces;
- Authenticate users;
- Manage user roles and permissions;
- Connect and synchronize authorized services;
- Import, organize, index, and search Customer Content;
- Create embeddings and knowledge-graph records;
- Generate AI responses, summaries, recommendations, and insights;
- Match employees, contacts, accounts, documents, and other entities;
- Prepare user-requested actions and workflows;
- Allow users to review and approve actions;
- Provide collaboration and workspace functionality;
- Process transactions and administer subscriptions, when offered;
- Respond to customer-support requests;
- Communicate about accounts, security, billing, and service changes;
- Send marketing communications where permitted;
- Detect, investigate, and prevent fraud, abuse, security incidents, and unauthorized activity;
- Diagnose errors and maintain service reliability;
- Enforce our agreements and policies;
- Comply with applicable laws and legal obligations;
- Establish, exercise, or defend legal claims; and
- Complete a corporate transaction such as a financing, merger, acquisition, reorganization, or sale.
We do not use Customer Content to train Techtum’s generalized or shared artificial-intelligence models.
5. Artificial Intelligence Processing
Apex uses artificial intelligence to respond to user requests and provide features such as search, summarization, classification, recommendations, organizational intelligence, knowledge-graph generation, and meeting assistance.
Information sent for AI processing
When a user invokes an AI feature, Apex may send the AI provider:
- The user’s request;
- Relevant instructions;
- Relevant portions of Customer Content;
- Search results;
- Extracted document content;
- Contact or account information;
- Metadata; and
- Other context necessary to provide the requested result.
Apex does not automatically send a customer’s entire document library, entire inbox, or entire meeting repository to an AI provider merely because an integration has been connected. Relevant portions may be selected and transmitted when needed to fulfill a user’s specific request.
Information submitted for processing is not necessarily anonymized and may include names, business contact information, or other personal information contained in the user’s request or relevant context.
OpenAI retention and model training
Techtum’s primary AI provider is OpenAI. Apex configures covered OpenAI API completion requests with store=False so those requests are opted out of OpenAI’s default storage pipeline.
Techtum:
- Does not use Customer Content to train Techtum’s generalized AI models;
- Does not opt Customer Content into OpenAI model-training programs; and
- Seeks and maintains OpenAI Zero Data Retention (ZDR) for the production organization and covered API endpoints used by Apex, including chat, embeddings, transcription, and real-time meeting features where applicable.
Under an active OpenAI ZDR configuration for covered endpoints, OpenAI is not permitted to retain covered Apex API inputs and outputs after processing. Without organization-level ZDR, OpenAI may retain API inputs and outputs for a limited abuse-monitoring period even when store=False is set. Techtum’s current subprocessor notice describes the applicable configuration.
Optional or alternate AI providers, if enabled for a deployment, may include Azure OpenAI, Anthropic, or Cohere. Those providers process only the data needed for the enabled feature and are listed in Techtum’s subprocessor notice.
Apex may separately store a user’s prompts, conversations, generated outputs, embeddings, and related records within Apex until they are deleted by an authorized user or administrator.
Meeting audio, video, and transcripts
- Live meeting audio may be streamed to OpenAI for real-time transcription or assistance when a user enables a live meeting feature. Live audio is not stored at rest by Apex as an audio or video recording.
- End-of-call or uploaded meeting transcripts may be stored in Apex.
- Uploaded audio or video may be transcribed; Apex retains the resulting text and related records rather than using the media for facial analysis, biometric voice profiling, or emotion recognition.
- Customers are responsible for obtaining any required meeting-recording or transcription notices and consents.
Limited human access
Techtum does not use routine human review of Customer Content to train generalized artificial-intelligence models.
Authorized Techtum personnel may receive limited access to information where necessary to:
- Protect the security of the Services;
- Investigate suspected abuse;
- Comply with law;
- Maintain platform reliability; or
- Address an issue that the customer has expressly authorized Techtum to investigate.
Access is intended to be limited to personnel with a legitimate need. Techtum does not provide a general “login as user” impersonation feature.
Accuracy of AI outputs
AI-generated results may be incomplete, inaccurate, outdated, or misleading. Users are responsible for reviewing outputs before relying on them or taking action. Apex outputs are intended to support human judgment rather than replace it.
6. Automated Recommendations and Actions
Apex may generate recommendations, rankings, classifications, suggested actions, or prepared workflows based on available information.
Users can generally review source evidence, edit generated information, delete generated information, review proposed actions, and decide whether to approve an action.
External or consequential actions require a human user to press an approval or confirmation control before the action is executed.
Apex must not be used as the sole basis for decisions concerning hiring, termination, promotion, compensation, access to employment, credit, housing, insurance, education admissions, or other decisions that produce legal or similarly significant effects on an individual.
Customers are responsible for applying appropriate human review and complying with laws governing employment, profiling, automated decision-making, discrimination, recording, and monitoring.
7. Google API Information
Apex may access Google information only after a user or authorized administrator grants permission.
Apex may use Google API information to import and search selected documents, synchronize selected files and folders, process selected emails, import calendar and meeting information, create summaries and knowledge-graph records, answer user questions, generate requested insights, and provide other user-authorized Apex functionality.
Users can control which supported Google services and information are selected for synchronization.
Apex’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Techtum does not:
- Sell Google user information;
- Provide Google user information to data brokers;
- Use Google user information for advertising;
- Use Google user information to build advertising profiles;
- Use Google user information to determine creditworthiness or lending eligibility; or
- Allow unrestricted human access to Google user information.
Google user information may be disclosed only:
- As necessary to provide or improve user-facing Apex functionality;
- To service providers acting on Techtum’s behalf and subject to appropriate confidentiality and security obligations;
- With the user’s affirmative direction or consent;
- For security purposes;
- As required by applicable law; or
- As part of a corporate transaction subject to appropriate protections.
8. Microsoft and Other Connected-Service Information
Apex may access Microsoft and other third-party information only after a user or authorized administrator grants permission.
Information received from Microsoft, Salesforce, Slack, Notion, or another connected service is used to provide user-authorized Apex functionality, such as synchronization, search, summarization, organizational intelligence, account intelligence, knowledge-graph generation, workflow preparation, and AI-assisted analysis.
Techtum does not sell connected-service information or use Customer Content from connected services for personalized advertising.
Third-party services remain governed by their own terms and privacy policies.
9. Integration Credentials and Nango
Techtum uses Nango to manage certain OAuth connections.
OAuth access and refresh tokens are managed through Nango rather than stored directly in Apex’s primary application database.
According to Techtum’s current configuration:
- OAuth tokens are encrypted;
- Techtum may have limited technical or administrative access through Nango where necessary to operate integrations;
- Tokens are not intentionally written into application logs;
- Workspace administrators may revoke authorized connections; and
- Tokens are deleted when the relevant connection is revoked.
Disconnecting an integration prevents future synchronization. Disconnecting does not necessarily delete information previously imported, generated, indexed, or derived within Apex. Users or authorized administrators can separately delete that information.
10. How Information Is Disclosed
A. Within a workspace
Customer Content may be visible to authorized members of the workspace in which it is stored.
Workspace administrators may:
- Invite or remove users;
- See names and workspace membership;
- See certain account-level or aggregate usage information;
- Manage permissions;
- Revoke integrations;
- Configure retention and audit-logging preferences, where available; and
- Delete workspace content.
Administrators are not provided unrestricted access to a user’s separate personal workspace solely because they administer another workspace.
B. Service providers and subprocessors
We use service providers to operate Apex. Current providers that may process Apex data include:
| Provider | Role |
|---|---|
| Google Cloud Platform | Cloud infrastructure, hosting, storage, logging, and error reporting in the us-central1 region |
| Google Cloud SQL for PostgreSQL, including pgvector | Primary database and vector search |
| Firebase / Google Identity Platform | Authentication |
| Vercel | Frontend website and application hosting |
| Nango | OAuth connections and integration credential management |
| OpenAI | Artificial-intelligence processing, embeddings, transcription, and related AI features |
| Azure OpenAI, Anthropic, or Cohere | Optional alternate or supplemental AI features when enabled |
| Resend | Transactional email, including multi-factor authentication codes |
| Google Gmail API | Limited operational notifications, such as certain beta or contact notifications |
These providers may process information only as necessary to perform services for Techtum, subject to their agreements with us and applicable law.
A current subprocessor list is also maintained with the Services. We may add or change providers as Apex develops. Material changes to how personal information is handled will be reflected in this Privacy Policy or an associated subprocessor notice.
C. At the user’s direction
We may disclose information when a user shares it with another workspace member, connects a third-party service, approves an external action, exports information, sends information through an integration, or otherwise directs Apex to disclose it.
D. Professional advisers
We may provide limited information to attorneys, accountants, auditors, insurers, consultants, and other professional advisers where reasonably necessary.
E. Legal and safety purposes
We may disclose information when we reasonably believe it is necessary to:
- Comply with law, regulation, subpoena, court order, or lawful government request;
- Protect the rights, property, or safety of Techtum, our users, or others;
- Investigate fraud, abuse, security incidents, or unlawful activity;
- Enforce our agreements; or
- Establish, exercise, or defend legal claims.
Where legally permitted, we may notify the affected customer before disclosing Customer Content in response to a legal demand.
F. Corporate transactions
Information may be disclosed or transferred as part of a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar corporate transaction.
Any successor that receives personal information will be required to handle it consistently with applicable law and the commitments made in this Privacy Policy.
G. Techtum personnel access
Authorized Techtum personnel may access production systems and Customer Content only when needed for security, reliability, legal compliance, abuse investigation, or customer-authorized support.
Platform administration capabilities may allow designated Techtum operators to manage users, workspaces, usage, and audit records across tenants. Access is restricted by role, need, and operational controls. Techtum does not copy identifiable production Customer Content into development environments as a routine development practice. Disaster-recovery or backup-restore testing may use controlled restore procedures into isolated environments when necessary.
11. No Sale of Personal Information
Techtum does not:
- Sell personal information;
- Sell Customer Content;
- Sell prospect lists;
- Sell connected-service information;
- Provide personal information to data brokers;
- Share personal information for cross-context behavioral advertising;
- Use Customer Content for advertising; or
- License identifiable customer data for unrelated commercial purposes.
If Techtum materially changes these practices, we will update this Privacy Policy and provide any notice, consent, or opt-out rights required by applicable law before beginning the new practice.
12. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing the Services, maintaining security, resolving disputes, enforcing agreements, and complying with legal obligations.
Retention periods
| Category | Retention |
|---|---|
| Active account information | While the account remains active, and for an appropriate period afterward as needed for security, billing, dispute resolution, or legal compliance |
| Active Customer Content | While the workspace remains active, until an authorized user or administrator deletes it, or until an enabled workspace retention policy deletes eligible content |
| Workspace retention policy | Workspace administrators may enable retention and set a retention period in days. Eligible documents and related derived content older than that period may be deleted by scheduled enforcement |
| Imported content, embeddings, summaries, classifications, graph records, AI chats, and AI outputs | Until separately deleted by an authorized user or administrator, or removed by an applicable retention or workspace-deletion process |
| Disconnected integrations | Future synchronization stops; previously imported or derived information remains until separately deleted |
| OAuth credentials managed through Nango | Deleted when the relevant connection is revoked |
| Security, technical, and audit logs | Retained as needed for security, fraud prevention, troubleshooting, and legal compliance; audit logs are excluded from ordinary content-retention sweeps and are retained for at least seven (7) years |
| Database backups | Encrypted backups are retained according to the backup schedule then in effect, generally at least seven (7) days and commonly about thirty (30) days |
| Billing and transaction records | Retained as needed for tax, accounting, and legal purposes |
| Support communications | Retained as needed to resolve issues and maintain customer-communication records |
| Trial workspaces | Retained while the trial remains active; thereafter handled under inactive or terminated-workspace practices |
| Terminated or deleted workspaces | Customer Content is deleted from production systems when the workspace is deleted or terminated through an authorized deletion process; residual copies may remain in encrypted backups until those backups expire |
Deleted information may remain temporarily in encrypted backups until those backups are overwritten or deleted through routine backup cycles.
We may retain limited information after a deletion request where necessary to comply with law, prevent fraud or abuse, protect security, resolve disputes, enforce agreements, or demonstrate compliance with a request.
What happens technically when content or a workspace is deleted
- Deleting an individual record generally removes that record and related derived data, such as chunks, embeddings, and associated graph artifacts, from the production database.
- Deleting stored files removes associated objects from application storage where those objects are managed by Apex.
- Deleting a personal workspace owned by the requester generally hard-deletes workspace documents, chat history, generated artifacts, memberships, and the workspace record from production systems in the deletion operation.
- Audit-log records associated with a deleted workspace are retained for compliance.
- Company or enterprise workspace termination may require administrator or Techtum-assisted processes depending on the workspace type and agreement.
- Disconnecting an integration does not by itself delete previously imported content.
13. Data Security
Techtum uses administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, destruction, loss, alteration, or disclosure.
Hosting and encryption
- Production backend services are hosted on Google Cloud Platform in the us-central1 region, including Cloud Run and Cloud SQL for PostgreSQL.
- Application file storage uses Google Cloud Storage.
- The Apex web application frontend is hosted on Vercel.
- Authentication is provided by Firebase.
- In transit: data is protected using TLS/HTTPS.
- At rest: database and storage services use Google-managed encryption, currently AES-256 for Cloud SQL and managed encryption for Cloud Storage.
Access to production systems and Customer Content is intended to be limited to authorized personnel with a legitimate operational need.
No security system is completely secure. We cannot guarantee that personal information will never be accessed, used, or disclosed in an unauthorized manner.
Users are responsible for maintaining the security of their account credentials, using appropriate access controls, reviewing workspace membership, protecting connected-service accounts, and notifying us promptly of suspected unauthorized access.
14. User Choices and Controls
Depending on the features available to them, users and administrators may be able to:
- Update account information;
- Select which integrations to connect;
- Select which information to synchronize;
- Revoke integration access;
- Delete imported information;
- Delete uploaded content;
- Edit or delete generated information;
- Export content;
- Remove workspace members;
- Delete eligible workspace content;
- Configure workspace retention and audit-logging preferences;
- Unsubscribe from marketing communications; and
- Request account or workspace deletion.
Account deletion
Users can delete certain content and, where permitted, eligible personal workspaces inside Apex. Apex does not currently provide a fully self-serve control that permanently deletes a user’s Apex identity account from within the product interface.
To delete an Apex user account, contact us using the information in the “Contact Us” section. We will verify the request and delete or deidentify account information except where retention is required for security, legal, billing, or audit purposes.
Unsubscribing from marketing communications does not prevent Techtum from sending necessary service, security, legal, billing, or administrative messages.
15. Privacy Rights
Depending on a person’s location and applicable law, they may have the right to:
- Request access to personal information;
- Request correction of inaccurate information;
- Request deletion;
- Request a portable copy of information;
- Restrict certain processing;
- Object to certain processing;
- Withdraw consent;
- Opt out of certain profiling or targeted advertising;
- Opt out of the sale or sharing of personal information;
- Appeal the denial of a privacy request; and
- Submit a complaint to a data-protection authority.
Techtum does not currently sell personal information or share personal information for cross-context behavioral advertising.
We may need to verify a requester’s identity before completing a request. Authorized agents may submit requests where permitted by law, subject to appropriate verification.
Certain rights are subject to exceptions. For example, we may retain information where necessary to comply with law, maintain security, complete a transaction, exercise legal rights, or fulfill another lawful purpose.
Requests involving customer-controlled information
If Techtum processes information on behalf of an Apex customer, the customer may be responsible for responding to the request.
We may direct the requester to the relevant customer, notify the customer of the request, assist the customer in responding, or take action based on the customer’s lawful instructions.
Requests from non-users
A person who does not have an Apex account but believes information about them appears in Apex may contact us to request access, correction, or deletion.
The requester should provide enough information to help us identify the relevant record and customer workspace. We will not disclose confidential customer information while attempting to locate the record.
16. Legal Bases for Processing
Where European Economic Area, United Kingdom, or similar data-protection laws apply, Techtum may rely on the following legal bases:
Performance of a contract. We process information where necessary to provide Apex, administer accounts, provide requested functionality, and fulfill our contractual obligations.
Legitimate interests. We may process information for legitimate interests such as securing the Services, preventing fraud, maintaining reliability, supporting customers, managing business operations, providing B2B communications, and protecting legal rights. We consider the effect of such processing on affected individuals.
Consent. We may rely on consent for optional integrations, certain cookies, certain marketing communications, recordings or transcription features where consent is required, optional features, and other processing where consent is required. Consent may be withdrawn, although withdrawal does not affect processing already completed lawfully.
Legal obligations. We may process information to comply with tax, accounting, regulatory, judicial, and other legal obligations.
17. International Data Transfers
Techtum is based in Florida, United States.
Production Customer Content is primarily hosted in the United States on Google Cloud Platform in the us-central1 region, with frontend hosting on Vercel and authentication through Firebase. Information may also be processed in other countries where Techtum’s service providers operate. Privacy laws in those countries may differ from the laws of the requester’s country.
Where required by applicable law, Techtum will use an appropriate legal mechanism or contractual protection for international transfers of personal information.
18. Children’s Privacy
Apex is intended only for individuals who are at least 18 years old.
Individuals under 18 may not create or use an Apex account.
Apex is not directed to children under 13, and Techtum does not knowingly collect personal information directly from children under 13 through account registration.
Customer Content may incidentally include information about minors, particularly where a customer works with educational institutions, nonprofit organizations, families, or other populations that include minors. In those circumstances, the customer is responsible for obtaining any required permission, providing legally required notices, and ensuring that its use of Apex complies with applicable law.
If we learn that a person under 18 created an Apex account, we may suspend or delete the account.
A parent or guardian who believes that a child provided personal information directly to Techtum may contact us.
19. Third-Party Services and Links
Apex may contain links to or integrations with third-party services.
Techtum does not control the independent privacy practices of services such as Google, Microsoft, Salesforce, Slack, Notion, LinkedIn, OpenAI, Vercel, Resend, or other third parties.
Users should review the privacy practices of those services before authorizing access or providing information.
Disconnecting a third-party service from Apex does not necessarily delete information already imported or generated within Apex.
20. Changes to This Privacy Policy
We may update this Privacy Policy as Apex develops, our practices change, or legal requirements evolve.
When we update the policy, we will revise the “Last Updated” date.
If a change materially affects how we collect, use, or disclose personal information, we may provide additional notice through the Apex interface, email, a website notice, or another appropriate method.
Where required, we will obtain consent before using previously collected information for a materially different purpose.
21. Contact Us
Questions, concerns, and privacy requests may be submitted to:
Techtum Inc.
Privacy contact: parker@techtum.ai
General and support contact: parker@techtum.ai
Florida, United States
State of incorporation: Florida, United States