Aplos Data LLC. Privacy Policy

Effective Date: May 7, 2026

1. Aplos Data LLC. Privacy Policy

At Aplos Data LLC., we are committed to protecting your privacy and handling your personal data with transparency, care, and in compliance with applicable data protection laws worldwide. This Privacy Policy explains how Aplos Data LLC. (“we,” “us,” or “our”) collects, uses, shares, and protects personal data when you interact with our website, services, and business operations.

This policy applies to all individuals who visit our website, engage with our services, communicate with us, or whose personal data we process in connection with our business. We recognize that privacy is a fundamental right, and we have designed our practices to respect your privacy while enabling us to deliver world-class services to our global clients.

By accessing our website or using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our website or services. We regularly review and update this Privacy Policy to reflect changes in our practices, technology, legal requirements, and business operations.

Scope of This Policy: This Privacy Policy covers personal data processed by Aplos Data LLC., as a data controller. When we provide services and process personal data on behalf of our clients as a data processor, our processing is governed by separate data processing agreements with those clients.

Language Versions: This Privacy Policy may be available in multiple languages. In the event of any inconsistency between language versions, the English version shall prevail, except where local law requires otherwise.

2. What is Personal Data at Aplos Data LLC.?

Personal data means any information that relates to an identified or identifiable individual. At Aplos Data LLC., this includes identity information such as your name, username, title, date of birth, gender, and photograph. We collect contact information including email address, postal address, telephone number, and mobile number. Professional information encompasses your job title, company name, business address, work email, professional qualifications, work history, areas of expertise, and business interests.

When you create accounts with us, we collect account information including username, password, security questions and answers, preferences, and account settings. Financial information includes payment card details, bank account information, billing address, transaction history, and credit information when you purchase our services. We collect technical information such as IP address, browser type and version, device type and identifier, operating system, and other technology details from devices used to access our services.

Location data may include precise or approximate geographic location collected through your device, IP address, or information you provide. We collect usage information about how you use our website, products, and services, including pages visited, time spent, links clicked, and interaction patterns. Communication information includes records of your communications with us through emails, letters, phone calls, video conferences, chat messages, and meeting notes.

We maintain marketing information about your preferences for receiving communications and your engagement with our marketing materials. When providing services, we may collect technical and system data including system logs, performance data, network configuration, and diagnostic information from client systems. Audio and visual information includes voice recordings, video recordings from meetings or events, photographs, and video surveillance footage from our facilities.

In limited circumstances, such as for secure facility access or authentication purposes, we may collect biometric data including fingerprints, facial recognition data, or voice prints, but only with your explicit consent and in compliance with applicable biometric privacy laws. We may also process special categories of sensitive personal information such as health information for insurance or accommodation purposes, background check information for security clearance or employment, and other sensitive data only with your explicit consent or where legally permitted, implementing enhanced security measures for such data.

3. Your Privacy Rights at Aplos Data LLC.

Aplos Data LLC. respects your rights regarding your personal data. Depending on your location and applicable law, you may have various rights concerning your personal information.

Universal Rights: You have the right to access the personal data we hold about you and receive information about how we process it, including the categories of data, purposes of processing, recipients, and retention periods. You may request that we correct inaccurate or incomplete personal data. In certain circumstances, you may request that we delete your personal data, such as when it is no longer necessary for the purposes for which it was collected, you withdraw consent and there is no other legal basis for processing, you object to processing and there are no overriding legitimate grounds, the data has been unlawfully processed, or deletion is required by legal obligation.

You may request that we restrict the processing of your personal data in certain situations, such as when you contest its accuracy or object to our processing. Where technically feasible and legally required, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller. You may object to our processing of your personal data based on legitimate interests or for direct marketing purposes, and we will cease processing unless we have compelling legitimate grounds that override your interests.

Where we process your personal data based on consent, you may withdraw your consent at any time, though this will not affect the lawfulness of processing before withdrawal. You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects, unless such processing is necessary for contract performance, authorized by law, or based on your explicit consent.

You also have the right to lodge a complaint with a supervisory authority in your jurisdiction if you believe our processing violates applicable data protection laws.

Additional Rights for U.S. Residents: If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act. These include the right to know what personal information we collect, use, disclose, sell, or share, the right to delete personal information, the right to correct inaccurate personal information, and the right to opt-out of the sale or sharing of personal information for cross-context behavioural advertising. You have the right to limit use of sensitive personal information and the right to non-discrimination for exercising your privacy rights.

We do not sell personal information for monetary consideration. To opt-out of any sale or sharing as defined under California law, email privacy@aplosdata.com with “Opt-Out” in the subject line. We honor Global Privacy Control signals. California residents may also request information about personal information disclosed to third parties for direct marketing purposes under California’s Shine the Light law.

Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws have similar rights, including rights to access, delete, correct, data portability, and opt-out of targeted advertising and profiling.

Additional Rights for EEA, UK, and Swiss Residents: Residents of the European Economic Area, United Kingdom, and Switzerland have rights under GDPR, UK GDPR, and Swiss data protection law, including all rights listed above, plus enhanced rights regarding automated decision-making and profiling, and the right to lodge a complaint with your local supervisory authority.

How to Exercise Your Rights: To exercise any of these rights, please contact us using the information provided in Section 12 of this Privacy Policy. We will respond to your request within the timeframe required by applicable law, typically within thirty days or forty-five days for California requests. We may need to verify your identity before processing your request to ensure the security of your personal data. You may designate an authorized agent to make requests on your behalf by providing proof of authorization. We do not charge fees for most requests unless they are manifestly unfounded, excessive, or repetitive. If you are dissatisfied with our response, you may appeal by contacting our Data Protection Officer at dpo@aplosdata.com.

4. Personal Data Aplos Data LLC. Collects from You

We collect personal data directly from you through various interactions with our business, website, and services.

Website Visits: When you visit our website, we automatically collect technical information through cookies and similar technologies to understand how visitors use our site and improve user experience. This includes your IP address and approximate geographic location, browser type and version, language settings, device type, operating system, and screen resolution. We track which pages you visit, how much time you spend on each page, and the navigation paths you take through our site. We also collect information about the referring website or source that brought you to our site, the date and time of your access, and clickstream data showing your interaction patterns with our website features and content.

Contact Forms and Inquiries: When you submit contact forms, request information or consultations, or sign up for our newsletters, we collect the information you provide including your name, contact information, company name, job title, email address, and phone number. We collect the content of your message and details of your inquiry, your preferred contact method and time, and your areas of interest or service needs to ensure we provide relevant information and connect you with appropriate specialists within our organization.

Service Engagement: When you engage our services, we collect detailed information necessary to deliver services effectively and meet your business objectives. This includes comprehensive information about your business requirements and objectives, technical specifications and system information about your current technology environment, detailed project information including timelines, milestones, and deliverables, relevant business information and context about your organization, industry, competitive environment, and strategic priorities, information about project stakeholders and their roles, budget constraints and available resources, and performance metrics and success criteria.

Account Registration: If you create an account on our client portal or other platforms we provide, we collect registration information necessary to establish and secure your account, including your chosen username and securely hashed password, email address, profile information such as name, job title, company affiliation, and optional profile photo, security questions and answers, account preferences and settings, and two-factor authentication information such as mobile phone number or authentication app configuration if you enable this enhanced security feature.

Events and Webinars: When you register for or attend our events, webinars, conferences, or training sessions, we collect information necessary to facilitate your participation including registration information, attendance records and participation data, questions you ask and feedback you provide, networking preferences if our events include networking components, and for in-person events, information about dietary restrictions or accessibility needs. We also collect any information you voluntarily share during participation in discussions, workshops, or interactive sessions.

Job Applications: If you apply for employment with Aplos Data LLC., we collect information necessary to evaluate your qualifications and suitability for the position, including all information contained in your curriculum vitae or resume and cover letter, application forms and questionnaires, references and their contact information, interview notes and assessments, work samples or portfolio materials, and with your consent, background check results which may include verification of employment history, education credentials, criminal records where permitted by law, and professional qualifications and certifications.

Communications: We collect and retain information from your various communications with us to maintain a record of our interactions and ensure we can respond effectively to your needs. This includes the content of emails and other correspondence, phone call recordings for quality assurance, training, compliance, and record-keeping purposes where we notify you and obtain consent as required by law, information from video conferences and virtual meetings including recordings, chat messages, and shared files, notes and summaries from in-person meetings documenting discussions, decisions, and action items, and the content of interactions through social media platforms including messages, comments, and posts.

Surveys and Feedback: When you participate in surveys, provide feedback, or engage in market research activities we conduct, we collect your responses to survey questions and opinions, satisfaction ratings regarding your experience with our services, suggestions and comments, and demographic information such as your industry, company size, role, or geographic location which helps us analyze survey results and understand different perspectives.

Payment Information: When you purchase our services, we collect information necessary to process payments and maintain financial records, including billing name and address, payment card details including card number, expiration date, and security code which are processed through secure third-party payment processors certified as compliant with the Payment Card Industry Data Security Standard. For wire transfers and ACH payments, we collect bank account information. We maintain records of transaction history and invoices documenting all financial transactions, which we retain in accordance with tax and accounting requirements.

Client Portal and Platform Usage: If you use our client portals, collaboration platforms, or proprietary tools, we collect information about your usage including login information and access logs, files you upload and download, content of collaboration and communication within the platform, features you use and how you configure preferences, and details of support tickets or help requests you submit.

Location Data: We may collect location information through several means including precise location data through GPS signals from your device with your explicit permission, approximate location information derived from your IP address, location information you provide directly in communications with us, and check-ins at our facilities or event venues.

Video Surveillance: We operate video surveillance systems in our offices and facilities for security purposes. Video surveillance is conducted in common areas such as building entrances, lobbies, hallways, and parking areas. We post clear signage in areas where video surveillance is in operation. Surveillance footage is retained for a limited period, typically thirty to ninety days, unless needed for security investigations or legal purposes, and access is restricted to authorized security personnel and management.

Call and Meeting Recordings: We may record phone calls, video conferences, and meetings for quality assurance, training, compliance, and record-keeping purposes. Where required by law, we notify you before recording begins and obtain your consent. Recordings are retained in accordance with our data retention policies and are accessible only to authorized personnel who have a legitimate business need to access them.

5. Personal Data Aplos Data LLC. Receives from Other Sources

In addition to data collected directly from you, we may receive personal data from third-party sources to supplement our understanding of our clients and prospects, verify information, and conduct business development activities.

Business Partners and Clients: We receive contact and professional information from our business partners and strategic alliances who collaborate with us on projects or refer potential clients to our services. When clients engage us for projects involving your organization, they may provide us with your contact information and relevant background about your role and responsibilities. We participate in joint ventures and consortium arrangements where partner organizations share information about team members and stakeholders, and subcontractors and vendors we work with may share information about their personnel or contacts relevant to our collaborative work.

Public Sources: We collect information from publicly available sources to research potential clients, understand industry trends, and stay informed about relevant developments. This includes company websites, professional networking platforms such as LinkedIn where professionals choose to share publicly available profile information including work history, skills, and expertise, business directories and databases, public records and government registries, news articles, press releases, and media coverage, industry publications and conference proceedings, and academic publications and research papers.

Data Brokers and Marketing Partners: We may obtain contact information and business intelligence from reputable data brokers and list providers that compile business contact information from various public and proprietary sources. We work with marketing partners and lead generation services that identify companies and individuals who have expressed interest in our services, and we purchase research and reports from industry research firms. Trade show and event organizers may provide attendee lists to sponsors and exhibitors when we participate in industry events, typically including names, job titles, companies, and contact information for individuals who consented to having their information shared.

Referrals: We receive information through referrals from individuals who are satisfied with our services and refer colleagues or business associates, providing us with contact information and context about the referral. Colleagues or business associates of our existing clients may recommend individuals within their network, professional contacts may suggest collaboration opportunities, and former employees or alumni sometimes make introductions to their current colleagues or employers.

Social Media Platforms: When you interact with our social media pages on platforms such as LinkedIn, Twitter, or Facebook, we may receive information from those platforms in accordance with their privacy policies and your privacy settings. This may include profile information you have chosen to make public, your interactions with our content such as likes, shares, and comments, messages you send to our business pages, and demographic and interest information about our followers in aggregated form. The information we receive from social media platforms is governed by those platforms’ privacy policies and your privacy settings on those platforms.

Service Providers: Third-party service providers who support our business operations may share information with us as part of providing their services. Event organizers provide attendee lists when we sponsor or exhibit at conferences and trade shows subject to attendees’ consent preferences. Technology vendors that provide analytics, customer relationship management, or marketing automation platforms may share usage data and engagement metrics. Research firms that conduct market studies on our behalf share results which may include contact information for participants who consented to follow-up. Collaboration and productivity tools we use may provide information about how our clients and partners interact with content we share through those platforms.

Background Check Providers: For employment purposes or when security clearances are required for certain projects, we may receive information from background check services and screening companies. These providers conduct various checks and verifications on our behalf including credit reporting, professional verification services, educational institutions verifying degrees and attendance, and former employers providing references and verifying employment dates. All background checks are conducted in compliance with applicable laws, including the Fair Credit Reporting Act in the United States, and only with appropriate consent from the individual being screened.

Government and Regulatory Bodies: In some cases, we receive information from government agencies and regulatory bodies in the course of our business operations, including law enforcement agencies in connection with investigations, courts in connection with legal proceedings, sanctions screening and watch list databases maintained by governments to ensure compliance with trade restrictions and anti-money laundering regulations, and professional licensing boards regarding the status of professional licenses.

Credit and Financial Information Providers: For significant business relationships, particularly when extending credit terms or entering into substantial contracts, we may obtain credit and financial information from specialized providers such as Dun & Bradstreet, Experian Business, or Equifax Business. These reports include business credit scores and ratings, financial background information, payment history, and public financial records that help us assess the financial stability and creditworthiness of potential business partners and make informed decisions about credit terms and payment arrangements.

Third-Party Data Compliance: We only use third-party sources that comply with applicable data protection laws and have lawful bases for collecting and sharing the information they provide to us. We conduct due diligence on significant data providers to verify their compliance practices and data quality, and we require our data providers to warrant that they comply with applicable privacy laws and have the right to share the data with us for our intended purposes. If we become aware that a third-party source has provided us with data in violation of applicable laws or without proper authorization, we will cease using that source and delete the improperly obtained data.

6. Aplos Data LLC.’s Use of Personal Data

Aplos Data LLC. uses personal data for various legitimate business purposes. The specific purposes depend on the nature of our relationship with you and the legal basis for processing.

Service Delivery and Contract Performance: The primary purpose for which we collect and use personal data is to deliver services to our clients and fulfill our contractual obligations. When a client engages us for a project, we use personal data to understand their requirements, design appropriate solutions, and implement our recommendations. We manage client projects by tracking progress, coordinating with stakeholders, managing timelines and deliverables, and ensuring we meet our commitments. We provide technical support and assistance, implement solutions and recommendations, conduct research and analysis for client projects, and create deliverables, reports, and documentation. Managing project teams and resources, communicating about project status, and processing payments and invoicing all require us to process personal data in ways that are necessary to fulfill our contractual obligations and deliver high-quality services.

Client Relationship Management: Beyond specific project delivery, we use personal data to build and maintain ongoing business relationships with our clients. We invest in understanding client needs and requirements for both current and potential future engagements. This requires maintaining information about client organizations, key contacts, business challenges, technology environments, and strategic priorities. We manage client accounts and contacts, provide customer service and support, respond to inquiries and requests, schedule meetings and consultations, follow up on proposals and opportunities, and manage client portals and collaboration platforms.

Business Operations and Administration: Like any organization, we use personal data for various business operations and administrative functions necessary to run our company effectively. This includes operating and managing our business, accounting and financial management, human resources and employee management, facility management and security, IT systems administration and support, records management and archiving, business continuity and disaster recovery planning, and quality assurance and performance monitoring.

Marketing and Business Development: We use personal data to promote our services and capabilities to potential clients and maintain awareness among existing clients of our full range of offerings. This includes promoting our services, sending marketing communications and newsletters with clear opt-out mechanisms, conducting market research and analysis, identifying potential clients and opportunities, managing leads and sales pipelines, attending and organizing events and webinars, creating and distributing thought leadership content, building brand awareness and reputation, and personalizing marketing messages based on recipient interests, industry, role, and past interactions to ensure our communications are relevant and valuable.

Website and Digital Services: We use personal data to operate and maintain our website and provide digital services to visitors and users. This includes operating the website, providing interactive features and functionality, personalizing your website experience, analyzing website usage and performance, improving website design and user experience, troubleshooting technical issues, preventing fraud and security threats, and administering user accounts and portals.

Employment and Human Resources: We process substantial personal data in connection with recruiting, hiring, and managing our employees. This includes recruiting and hiring employees, managing employee records and benefits, payroll and compensation administration, performance management and reviews, training and professional development, internal communications, workplace safety and security, and employee relations and engagement activities.

Legal Compliance and Protection: We use personal data as necessary to comply with legal obligations and protect our legal rights and interests. This includes complying with legal obligations and regulations, responding to legal requests and court orders, protecting our legal rights and interests, preventing, detecting, and investigating fraud, enforcing our terms of service and contracts, managing disputes and litigation, conducting internal audits and investigations, and maintaining compliance programs.

Research and Innovation: We use personal data to develop new services and solutions, improve our methodologies, and advance the state of our business.This includes developing new services and solutions, conducting research and development, testing and improving our methodologies, analyzing industry trends and best practices, creating intellectual property such as frameworks, tools, and methodologies, and participating in academic and industry research.

Artificial Intelligence and Automated Processing: We may use artificial intelligence, machine learning, and automated processing technologies to enhance our services, improve efficiency, and deliver better outcomes for our clients. In service delivery, we may use AI tools to analyze large volumes of data, identify patterns, detect anomalies, generate insights, and optimize solutions, though all AI-generated content is carefully reviewed and validated by our professional staff. We may use AI for data analysis to process large datasets, identify patterns and trends, make predictions, and derive insights that inform our recommendations. We may deploy AI-powered chatbots and virtual assistants on our website to provide immediate responses to common questions, clearly identified as automated systems with options to interact with human representatives. For recruitment, we may use AI tools to support our hiring process, though all AI-assisted decisions are subject to human review and oversight, and we do not make employment decisions based solely on automated processing. In marketing, we use AI to personalize website content, optimize campaigns, predict customer preferences, and segment audiences for targeted communications.

When we use AI technologies that process your personal data, we implement important safeguards including appropriate human oversight and intervention in decision-making, safeguards to prevent discriminatory or biased outcomes, regular audits of AI systems for fairness and accuracy, and transparency about when AI is being used in decisions that significantly affect you. You have the right to request human review of automated decisions that significantly affect you and the right to object to automated decision-making in certain circumstances. We do not use your personal data to train third-party AI models without your explicit consent. When we use third-party AI services, we ensure these providers have appropriate data protection measures in place and require contractual commitments that they do not use your data for their own purposes beyond providing services to us.

Profiling and Business Intelligence: We may create profiles of clients, prospects, and website visitors by combining data from various sources to better understand and serve our business relationships. These profiles help us understand business needs and preferences, identify potential service opportunities, conduct market segmentation and analysis, predict business trends and requirements, and optimize our service delivery. Our profiling activities are based on business and professional information rather than sensitive personal characteristics. You have the right to object to profiling activities, and you also have the right to request human review of any decisions based on profiling that significantly affect you.

Legal Bases for Processing: We process personal data based on one or more of the following legal bases. We process based on consent in situations where you have agreed to receive marketing communications, participate in surveys, accept our use of cookies beyond those strictly necessary, consent to our processing of sensitive personal information, or agree to recording of calls or meetings. When we rely on consent, you have the right to withdraw it at any time. We process personal data when necessary to perform our contractual obligations to you or to take steps at your request before entering into a contract, including delivering services, processing payments, providing customer support, and implementing pre-contractual measures. We process personal data when we have legitimate business interests that are not overridden by your rights and interests, such as operating and improving our business, marketing our services, preventing fraud and maintaining security, supporting business development, and improving our services. Before relying on legitimate interests, we conduct balancing tests to ensure our interests do not override your fundamental rights and freedoms, and you have the right to object to such processing. We process personal data when necessary to comply with legal requirements such as tax and accounting obligations, regulatory requirements, employment law requirements, responding to valid legal requests, and maintaining records as required by law. In rare cases, we may process personal data when necessary to protect someone’s life or physical safety or when necessary for tasks carried out in the public interest.

7. Aplos Data LLC.’s Sharing of Personal Data

Aplos Data LLC. may share your personal data with third parties in specific circumstances and subject to appropriate safeguards. We do not sell personal data for monetary consideration, and we share data only when necessary for legitimate business purposes or when required by law.

Service Providers and Processors: We engage third-party service providers who process personal data on our behalf to support our business operations. These service providers act as data processors under our instruction and are contractually obligated to protect your data and use it only for the purposes we specify. We conduct due diligence before engaging service providers and monitor their performance on an ongoing basis. Technology and infrastructure providers include cloud hosting and storage providers such as Amazon Web Services, Microsoft Azure, and Google Cloud, IT support and managed services providers, software-as-a-service platforms for various business functions, database and data warehouse providers, cybersecurity and threat detection services, and backup and disaster recovery services. Communication and collaboration tools include email service providers, video conferencing platforms such as Zoom and Microsoft Teams, collaboration and project management tools, customer relationship management systems, and communication platforms and messaging services. Marketing and analytics providers include marketing automation platforms, email marketing services, web analytics providers such as Google Analytics, advertising platforms and networks, social media management tools, market research and survey platforms, and event management and webinar platforms. Professional services include legal advisors and law firms, accounting and auditing firms, business consultants and advisors, insurance providers and brokers, and financial advisors. Administrative services include payment processors and merchant services that maintain PCI DSS compliance, payroll and benefits administrators, recruitment and staffing agencies, background check providers, document management and archiving services, and translation and localization services.

Business Partners and Collaborators: We sometimes share personal data with business partners in connection with collaborative business activities. For joint projects and engagements, we may work with other consulting firms or technology providers to deliver comprehensive solutions to clients, sharing information necessary for partners to perform their role. Strategic alliances and partnerships with complementary service providers may involve sharing information about mutual clients or prospects to provide integrated services. Subcontracting arrangements occur when we engage specialists to perform specific aspects of client projects under our direction. Consortium or team-based service delivery for large engagements may involve multiple firms working together, requiring coordination and information sharing. Co-marketing initiatives with partners may involve sharing information about joint offerings or events. Research collaborations with academic institutions or industry organizations may involve sharing data for research purposes, typically in anonymized or aggregated form.

Clients: When we provide services as a data processor on behalf of clients, we may share personal data with those clients as data controllers. In these situations, the client determines the purposes and means of processing, and the client’s privacy policy governs their use of such data.

Corporate Transactions: In the event of a merger, acquisition, sale of assets, bankruptcy, or other corporate transaction, personal data may be among the assets transferred or reviewed. We may disclose personal data to potential buyers, investors, or advisors under strict confidentiality obligations during due diligence processes. If a transaction is completed, personal data may be transferred to successor entities who will assume our rights and obligations regarding that data. We will notify affected individuals of material changes to data processing resulting from business transitions where required by law.

Legal and Regulatory Authorities: We may disclose personal data to law enforcement agencies and government authorities, regulatory bodies and supervisory authorities, courts and tribunals, tax authorities, and other public authorities when required or permitted by law. We disclose data when required by law or legal process, when necessary to comply with legal obligations, when requested through valid legal process such as subpoenas or court orders, when necessary to protect our legal rights or interests, when necessary to prevent or investigate fraud or security threats, and when necessary to protect the safety or rights of individuals. We carefully review all legal requests to ensure they are legally valid and appropriately scoped. Where permitted by law, we will notify affected individuals of legal requests for their data unless prohibited by law or unless notification would undermine the purpose of the request.

Professional Advisors: We share personal data with professional advisors who assist us with legal, financial, insurance, and business matters, including lawyers and legal counsel, accountants and auditors, insurance advisors and underwriters, business consultants, and financial advisors. These professionals are bound by confidentiality obligations and professional ethics rules that require them to protect the confidentiality of information they receive.

Protection of Rights and Safety: We may disclose personal data when we believe in good faith that disclosure is necessary to protect our legal rights, property, or safety, to protect the rights, property, or safety of our clients, employees, or others, to prevent or investigate fraud, security threats, or illegal activities, to enforce our terms of service or contracts, or to respond to emergencies involving danger to persons or property.

With Your Consent: We may share your personal data with third parties when you have given explicit consent for such sharing, such as when you agree to have your contact information shared with event sponsors, when you connect your account with third-party services that require data sharing, when you participate in joint marketing initiatives, or when you request that we facilitate introductions or referrals. When we seek your consent for data sharing, we clearly explain what data will be shared, with whom, and for what purposes. You can withdraw consent for future sharing at any time.

Anonymized and Aggregated Data: We may share anonymized or aggregated data that does not identify you personally with business partners and clients, research institutions, industry organizations, and the public through reports and publications. This anonymous data is not considered personal data under applicable privacy laws and may be used for any lawful business purpose. We implement appropriate techniques to ensure that anonymized data cannot be re-identified and linked back to individuals.

Third-Party Websites and Services: Our website may contain links to third-party websites, services, or applications that are not operated by Aplos Data LLC.. When you click on these links, you leave our website and this Privacy Policy no longer applies. We are not responsible for the privacy practices of third parties. When we integrate third-party services into our website or services, we select providers with strong privacy practices, though their use of your data is governed by their own privacy policies.

No Sale of Personal Data: We do not sell personal information for monetary consideration. Under some U.S. state privacy laws, “sale” or “sharing” may be defined broadly to include certain data sharing for advertising purposes. To the extent any of our data sharing practices constitute a “sale” or “sharing” under these broad definitions, you have the right to opt out by contacting us at privacy@aplosdata.com with “Opt-Out” in the subject line.

International Transfers: Some of the third parties with whom we share data are located outside your country or region, which may involve transferring your personal data internationally. International data transfers are addressed in detail in Section 11 of this Privacy Policy.

8. Protection of Personal Data at Aplos Data LLC.

Aplos Data LLC. is committed to protecting your personal data through robust security measures, policies, and practices. We implement technical, organizational, and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration, and destruction.

Technical Security Measures: We use industry-standard encryption to protect data at all stages of processing and storage. Data in transit is encrypted using Transport Layer Security and Secure Sockets Layer protocols. Data at rest is encrypted using strong encryption algorithms that meet or exceed industry standards. We apply additional layers of encryption to particularly sensitive data such as authentication credentials, financial information, and confidential client data. We maintain secure key management practices to ensure encryption keys are properly protected, rotated regularly, and accessible only to authorized personnel and systems.

We implement strict access controls to ensure that only authorized individuals can access personal data, and only to the extent necessary for their legitimate job functions. Our role-based access control system assigns permissions based on job function and responsibility. We follow the principle of least privilege, granting the minimum level of access necessary for each role. Multi-factor authentication is required for access to sensitive systems and data. We enforce strong password policies and automatically lock accounts after failed login attempts. We conduct regular access reviews to ensure permissions remain appropriate, and when employees change positions or leave the organization, access is promptly modified or revoked. All access to personal data is logged and auditable.

We protect our network infrastructure through multiple layers of defense including enterprise-grade firewalls, intrusion detection and prevention systems, network segmentation and isolation, secure virtual private networks for remote access, rigorous patching and update schedules, vulnerability scanning and penetration testing, and distributed denial of service protection and mitigation capabilities.

We secure our applications and software through comprehensive security practices throughout the development lifecycle. Our secure software development lifecycle incorporates security considerations from initial design through deployment and maintenance.

We conduct regular security code reviews, use web application firewalls, validate and sanitize all input from users and external systems, and address the most common and critical web application vulnerabilities identified in the OWASP Top Ten list. We conduct regular security testing and assessments of our applications.

We protect devices and endpoints used to access our systems and data through comprehensive endpoint security measures including antivirus and anti-malware software, endpoint detection and response solutions, full-disk encryption for all devices containing or accessing personal data, mobile device management solutions, secure configuration standards, and regular security patches and updates.

We implement data loss prevention measures to prevent unauthorized disclosure or exfiltration of personal data. Our DLP systems monitor data transfers and movements across our network, email systems, cloud services, and endpoints. We implement controls on the use of removable media, monitor email and file transfer activities for sensitive data, classify and label sensitive data, and automatically enforce DLP policies across systems.

Security Monitoring and Operations: We maintain comprehensive security monitoring through continuous oversight of our systems and networks. Our security operations center monitors for suspicious activities, security incidents, and potential threats around the clock.

We collect and analyze security logs from all critical systems, maintaining detailed records of system access, data transfers, and security events. We have implemented automated alerting systems that notify our security team of potential security incidents in real time, enabling rapid response to emerging threats.

Backup and Recovery: We maintain robust backup and disaster recovery capabilities to ensure business continuity and data protection. Our systems perform regular automated backups of critical data, with backups stored in geographically diverse locations to protect against regional disasters. We regularly test our backup and recovery procedures to ensure they function properly when needed. In the event of a system failure or data loss incident, we can restore data from secure backups to minimize disruption and data loss.

Incident Response: We maintain a comprehensive incident response program to address security incidents promptly and effectively. Our incident response team is trained to identify, contain, investigate, and remediate security incidents. We have documented incident response procedures that define roles, responsibilities, and escalation paths. When a security incident occurs, we follow established protocols to contain the threat, assess the impact, notify affected parties as required by law, and implement corrective measures to prevent recurrence.

Organizational Security Measures: We have established comprehensive policies and procedures governing the handling of personal data throughout its lifecycle. All employees and contractors are required to comply with our privacy and security policies as a condition of their engagement with Aplos Data LLC.. All personnel receive comprehensive privacy and data protection training upon joining the organization and participate in annual refresher training thereafter. Employees who regularly handle personal data receive specialized training appropriate to their roles. We conduct appropriate background checks on employees and contractors who will have access to personal data or sensitive systems. All employees, contractors, and third parties with access to personal data are bound by confidentiality obligations.

We carefully select and manage third-party service providers who process personal data on our behalf. Before engaging a service provider, we conduct due diligence to assess their privacy and security practices. We require service providers to enter into written agreements that include appropriate data protection terms, security requirements, and confidentiality obligations. We adhere to the principle of data minimization, collecting and retaining only the personal data that is necessary for specific, legitimate purposes. We incorporate privacy considerations into the design and development of new systems, services, and business processes through our privacy by design approach. We conduct Privacy Impact Assessments for new services, products, or technologies that may pose risks to personal data.

We conduct regular internal audits and reviews of our privacy and security practices to ensure compliance with our policies and applicable laws. Our Data Protection Officer is responsible for monitoring compliance with data protection laws, advising on privacy matters, and serving as a point of contact for data protection authorities and individuals. We have established a privacy council comprising senior leaders from legal, security, information technology, and business functions that oversees privacy strategy and compliance.

Physical Security Measures: Our offices and data centers are protected by physical security controls designed to prevent unauthorized access, including perimeter security, access control systems requiring authentication for entry, video surveillance in common areas and entry points, visitor management and escort procedures, and security personnel where appropriate. Physical documents and media containing personal data are stored in locked cabinets or secure storage areas with restricted access. When personal data is no longer needed, we dispose of it securely through shredding physical documents and securely wiping or physically destroying electronic media. We enforce clean desk and clear screen policies to minimize the risk of unauthorized access to personal data.

Data Retention and Deletion: We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Our retention periods vary depending on the type of data and the purposes for which it is processed. Client project data is retained for the duration of the engagement plus seven years for legal and audit purposes. Marketing communications data is retained until you unsubscribe or request deletion. Website analytics data is retained for twenty-six months. Job application data is retained for two years after the recruitment process concludes unless you request earlier deletion. Financial records are retained for seven years in accordance with tax and accounting requirements. Security logs are retained for twelve months. Employee records are retained in accordance with employment law requirements.

When retention periods expire, we securely delete or anonymize personal data unless we are required or permitted to retain it longer for legal, regulatory, or legitimate business purposes. We use automated systems to enforce our data retention policies, including automatically deleting data when retention periods expire, archiving inactive data to secure storage, purging temporary files and logs, and removing outdated marketing contacts.

Data Breach Response: Despite our robust security measures, no system is completely immune to security incidents. In the event of a data breach that poses a risk to your rights and freedoms, we have established procedures to respond promptly and effectively. If we experience a data breach, we will notify affected individuals within seventy-two hours of becoming aware of the breach, or as required by applicable law, which may vary by jurisdiction. Our notification will provide information about the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, the measures we are taking to address the breach, and guidance on protective measures you can take. We will notify relevant supervisory authorities as required by law. We maintain cyber insurance coverage to help manage the financial impact of data breaches and provide resources for breach response.

Third-Party Security: When we engage third-party service providers who process personal data on our behalf, we require them to implement appropriate technical and organizational measures to protect personal data. Our agreements with service providers include security requirements, audit rights, and breach notification obligations. We periodically assess the security practices of our service providers through questionnaires, certifications review, and audits where appropriate.

Continuous Improvement: We recognize that privacy and security threats evolve continuously, and we are committed to continuously improving our security posture. We monitor emerging threats and vulnerabilities, evaluate new security technologies and best practices, participate in information sharing with industry peers and security communities, and update our security measures to address evolving risks.

9. Cookies and Other Technologies

Aplos Data LLC. uses cookies, web beacons, pixels, and similar tracking technologies on our website to enhance user experience, analyze usage patterns, and support our marketing activities.

What Are Cookies? Cookies are small text files that are placed on your device when you visit a website. Cookies allow websites to recognize your device, remember your preferences, and provide functionality. Session cookies are temporary and are deleted when you close your browser. Persistent cookies remain on your device for a set period or until you delete them. First-party cookies are set by the website you are visiting, while third-party cookies are set by other parties such as analytics providers or advertisers.

How We Use Cookies: We use cookies and similar technologies for several purposes. Strictly necessary cookies are essential for our website to function properly and enable core functionality such as security, network management, and accessibility. These cookies do not store any personally identifiable information and cannot be disabled. Performance and analytics cookies collect information about how visitors use our website, such as which pages are visited most often and how long visitors spend on each page. We use analytics services such as Google Analytics to collect and process this information, which we use to improve how our website works. Functionality cookies allow our website to remember choices you make, such as your language preference or customized settings, and provide enhanced, more personal features. Targeting and advertising cookies are used to deliver advertisements that are relevant to you and your interests. They may track your browsing activity across different websites to build a profile of your interests. Social media cookies are set by social media platforms such as LinkedIn, Twitter, and Facebook when you interact with features from these platforms on our website.

Other Tracking Technologies: In addition to cookies, we use web beacons and pixels, which are small graphic images embedded in web pages or emails that allow us to track whether you have viewed a particular web page or email message. We may use local storage technologies such as HTML5 local storage and browser caching to store content and preferences on your device. We may collect information about your device, browser, and settings to create a unique identifier or “fingerprint” for your device to help detect fraud and improve security. We may use technologies that recognize when you access our services from multiple devices to provide a consistent experience across devices.

How to Control Cookies: You have several options to control or limit how cookies and similar technologies are used. Most web browsers allow you to control cookies through their settings. You can typically set your browser to refuse all cookies, accept only certain cookies, or notify you when a cookie is set. Please note that if you disable or refuse cookies, some parts of our website may become inaccessible or not function properly. You can opt out of interest-based advertising from participating companies through relevant industry opt-out tools.

We honor Global Privacy Control signals where required by law. Global Privacy Control is a browser setting that allows you to indicate your privacy preferences regarding the sale or sharing of your personal data. Mobile devices typically provide settings to limit tracking and advertising through device settings. Some browsers offer a “Do Not Track” feature, though our website does not respond to Do Not Track signals at this time. However, we do honor Global Privacy Control signals where required by law.

Cookie Consent Management: When you first visit our website, we present you with a cookie consent banner that explains our use of cookies and allows you to make choices about which categories of cookies you wish to accept. You can change your cookie preferences at any time by clicking the “Cookie Settings” link in our website footer or by accessing our privacy preference center.

Third-Party Cookies: We allow certain third parties to set cookies through our website to provide services to us or to deliver advertisements, including analytics providers such as Google Analytics, advertising networks and platforms, social media platforms, content delivery networks, and customer service and chat providers. These third parties have their own privacy policies governing their use of cookies and the data they collect. We conduct due diligence on third-party cookie providers to ensure they have appropriate privacy and security practices in place.

10. Transfer of Personal Data Between Countries

Aplos Data LLC. is headquartered in Ohio, United States, and operates globally. We provide services to clients worldwide and engage service providers located in various countries. As a result, your personal data may be transferred to, stored in, and processed in countries other than your country of residence, including the United States and other countries where we or our service providers operate.

Different countries have different data protection laws, and some countries may not provide the same level of protection for personal data as your home country. When we transfer personal data internationally, we implement appropriate safeguards to protect your data in accordance with applicable laws.

Legal Mechanisms for International Transfers: We rely on several legal mechanisms to transfer personal data internationally. We transfer personal data to countries that have been deemed by the European Commission, UK government, or Swiss authorities to provide an adequate level of data protection. For transfers to countries without an adequacy decision, we use Standard Contractual Clauses approved by the European Commission, UK authorities, or other relevant authorities. These are standardized contractual terms that provide appropriate safeguards for personal data transferred internationally. For transfers from the European Union to the United States, we may rely on the EU-U.S. Data Privacy Framework where we or our service providers are certified under this framework. Similarly, we may rely on the UK Extension to the EU-U.S. Data Privacy Framework for transfers from the United Kingdom and the Swiss-U.S. Data Privacy Framework for transfers from Switzerland. Where applicable, we may implement Binding Corporate Rules. In limited circumstances where other transfer mechanisms are not available, we may rely on specific derogations permitted by law, such as when the transfer is necessary for the performance of a contract with you or based on your explicit consent after being informed of the risks.

Additional Safeguards: Beyond legal transfer mechanisms, we implement additional technical and organizational safeguards when transferring personal data internationally, including encryption of data during transmission and at rest, access controls limiting who can access transferred data, contractual obligations requiring recipients to protect data appropriately, regular audits and assessments of international data recipients, and data minimization to transfer only necessary data.

Data Localization Requirements: Certain countries require that personal data of their residents be stored locally or have restrictions on international transfers. Where we operate in such jurisdictions, we comply with local data localization requirements.

Your Rights Regarding International Transfers: You have the right to obtain information about the safeguards we have implemented for international transfers of your personal data.

You may request a copy of the Standard Contractual Clauses or other transfer mechanisms we have implemented by contacting us at privacy@aplosdata.com. If you have concerns about how your personal data is transferred or processed internationally, you have the right to lodge a complaint with your local data protection authority.

11. Our Companywide Commitment to Your Privacy

At Aplos Data LLC., privacy is not just a legal obligation but a core value that guides how we conduct business. We have embedded privacy considerations throughout our organization and operations.

Privacy Governance Structure: We maintain a comprehensive privacy governance structure to oversee our data protection program. Our Data Protection Officer is responsible for monitoring compliance with data protection laws, advising on privacy matters, conducting privacy impact assessments, serving as a point of contact for data protection authorities and individuals, and overseeing privacy training and awareness programs.

Privacy Training and Culture: We invest significantly in privacy training and awareness to ensure all personnel understand their responsibilities regarding personal data protection. All personnel receive initial privacy and data protection training upon joining the organization covering data protection principles, security best practices, incident reporting procedures, and regulatory requirements. Annual refresher training keeps personnel updated on new developments. Employees who regularly handle personal data receive role-specific training appropriate to their responsibilities. We conduct regular security awareness campaigns throughout the year to keep privacy and security top of mind.

Privacy by Design and Default: We incorporate privacy considerations into the design and development of new systems, services, and business processes from the outset. Our privacy by design approach includes conducting Privacy Impact Assessments before implementing new initiatives, implementing data minimization in system design, building in strong access controls and encryption, providing privacy-protective default settings, and enabling user control over personal data.

Accountability and Documentation: We maintain comprehensive documentation of our privacy compliance program to demonstrate accountability and facilitate oversight. This documentation includes records of processing activities, Privacy Impact Assessments, data protection policies and procedures, training records, vendor due diligence documentation, incident response logs, audit reports, and data processing agreements. This documentation is available to supervisory authorities upon request and to individuals where legally required.

Continuous Improvement: We are committed to continuously improving our privacy practices to address evolving threats, technologies, and expectations. Our continuous improvement efforts include regular privacy audits and assessments, monitoring regulatory developments and emerging best practices, participating in industry forums and privacy organizations, soliciting feedback from clients, employees, and stakeholders, implementing new privacy-enhancing technologies, and updating policies and procedures to reflect lessons learned.

Transparency and Communication: We believe in transparency about our privacy practices and are committed to clear communication with individuals about how we handle personal data. We provide this comprehensive Privacy Policy in clear, plain language. We communicate material changes to our privacy practices through website notifications, email communications, and updates to this Privacy Policy. We maintain open channels of communication for privacy inquiries and requests and respond promptly.

Ethical Data Use: Beyond legal compliance, we are committed to ethical use of personal data. Our ethical principles include respecting individual dignity and autonomy, using data only for legitimate, transparent purposes, avoiding discriminatory or biased data practices, protecting vulnerable populations, considering societal impacts of our data practices, and being accountable for our decisions and actions. We carefully consider the ethical implications of new technologies and data practices, particularly in areas such as artificial intelligence, automated decision-making, and profiling.

Privacy in Client Services: When we provide services to clients, we extend our privacy commitments to the personal data we process on their behalf. As a trusted advisor, we help clients develop and implement privacy-compliant systems and processes. We provide guidance on privacy best practices, data protection requirements, and privacy-enhancing technologies. We recognize that trust is the foundation of our client relationships, and we work diligently to earn and maintain that trust through exemplary privacy practices.

12. Privacy Questions

We are committed to addressing your privacy questions, concerns, and requests promptly and professionally.

Contact Information:

For general privacy inquiries, email privacy@aplosdata.com.

For matters requiring the Data Protection Officer, who oversees our privacy program and can assist with privacy questions, complaints, and data subject rights requests, email dpo@aplosdata.com.

To exercise your privacy rights, including rights to access, correct, delete, or port your personal data, please submit your request to privacy@aplosdata.com with “Data Subject Access Request” or “Privacy Rights Request” in the subject line.

If you believe you have discovered a security vulnerability or wish to report a security incident, please contact security@aplosdata.com. We maintain responsible disclosure procedures for security researchers and will respond promptly to legitimate security reports.

Appeals: If you are dissatisfied with our response to your privacy request, you have the right to appeal. To submit an appeal, contact our Data Protection Officer at dpo@aplosdata.com with “Privacy Request Appeal” in the subject line. Please include your original request, our response, and the reasons you are appealing. We will review your appeal and respond within the timeframe required by applicable law, typically within thirty to sixty days depending on jurisdiction.

Supervisory Authorities: You have the right to lodge a complaint with a data protection supervisory authority if you believe our processing of your personal data violates applicable law.

Updates to This Privacy Policy: We review and update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, and business operations. The “Effective Date” and “Last Reviewed” date at the top of this policy indicate when it was last updated. When we make material changes to this Privacy Policy, we will notify affected individuals through one or more of the following methods: posting a prominent notice on our website, sending an email notification to registered users, providing in-app notifications where applicable, or direct communication for significant changes affecting your rights. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your privacy. Your continued use of our website and services after changes to this Privacy Policy constitutes your acceptance of the updated policy. We maintain previous versions of this Privacy Policy for reference. If you would like to review a previous version, please contact us at privacy@aplosdata.com.

Severability: If any provision of this Privacy Policy is found to be invalid, illegal, or unenforceable in any jurisdiction, such invalidity, illegality, or unenforceability shall not affect the remaining provisions or the validity, legality, or enforceability of such provision in any other jurisdiction. The remaining provisions will continue in full force and effect.

Interpretation: This Privacy Policy should be read in conjunction with our Terms of Service and any other agreements you have with Aplos Data LLC.. In the event of any conflict between this Privacy Policy and our Terms of Service, this Privacy Policy shall prevail with respect to privacy matters. Headings in this Privacy Policy are for convenience only and do not affect the interpretation of any provision.

Governing Law: This Privacy Policy and our privacy practices are governed by applicable data protection laws in the jurisdictions where we operate, including but not limited to the General Data Protection Regulation for individuals in the European Economic Area, the UK GDPR and Data Protection Act 2018 for individuals in the United Kingdom, the California Consumer Privacy Act and California Privacy Rights Act for California residents, and other applicable U.S. state and federal privacy laws. To the extent not governed by specific data protection laws, this Privacy Policy shall be governed by the laws of the State of Ohio, United States, without regard to its conflict of law provisions.

Thank You: Thank you for taking the time to read our Privacy Policy and for trusting Aplos Data LLC. with your personal data. We take this responsibility seriously and are committed to protecting your privacy while delivering exceptional services. If you have any questions, concerns, or feedback about this Privacy Policy or our privacy practices, please contact us at privacy@aplosdata.com. We are here to help and look forward to hearing from you.

End of Privacy Policy