Data Processing Agreement

Effective Date June 30, 2026
Last Updated July 26, 2026
Review Cycle Every 12 Months

This Data Processing Agreement ("DPA") forms part of the agreement between Apex Thunder ("Apex Thunder", "we", "our", or "us") and the Customer ("Customer", "you", or "your") whenever Apex Thunder processes Personal Data on behalf of the Customer in the capacity of a Data Processor under applicable Data Protection Laws. This DPA sets out the respective rights and obligations of the parties regarding the processing, security, confidentiality, and protection of Personal Data in connection with the Services and is intended to satisfy the requirements of the European Union General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and other applicable data protection laws where relevant.

Purpose of this Agreement

The purpose of this Data Processing Agreement is to establish the legal framework governing the processing of Personal Data by Apex Thunder solely to the extent Apex Thunder acts as a Data Processor while providing hosting, cloud infrastructure, managed services, technical support, and other related Services. This Agreement defines the responsibilities of both parties, establishes appropriate safeguards for Personal Data, and documents the measures implemented to facilitate compliance with applicable Data Protection Laws.

Nothing in this DPA shall be interpreted as expanding the scope of the Services, creating additional contractual obligations beyond those expressly required by applicable Data Protection Laws, or limiting any rights, exclusions, or limitations of liability set forth in the Apex Thunder Terms of Service or other applicable agreements between the parties.

This DPA supplements the Apex Thunder Terms of Service and Privacy Policy. In the event of any conflict relating solely to the processing of Personal Data where Apex Thunder acts as a Data Processor, the provisions of this DPA shall prevail only to the extent required by applicable Data Protection Laws. For all other matters, the Terms of Service shall remain in full force and effect.

Scope of Application

This Agreement applies only where, and only for so long as, Apex Thunder processes Personal Data on behalf of the Customer as a Data Processor in connection with the applicable Services. It does not apply where Apex Thunder processes Personal Data as an independent Data Controller for its own legitimate business purposes, including but not limited to account administration, billing, payment processing, fraud prevention, security monitoring, legal compliance, abuse prevention, customer support administration, or other purposes described in the Apex Thunder Privacy Policy.

This DPA applies automatically to all eligible Services unless the parties have executed a separate written data processing agreement governing the relevant Services, in which case that agreement shall control solely with respect to those Services.

The Customer acknowledges that the nature of the Services may require the Customer to determine whether Personal Data is uploaded, stored, transmitted, or otherwise processed through the Services, and remains solely responsible for ensuring that such processing is lawful and authorized under applicable Data Protection Laws.

1. Definitions

Unless otherwise defined in this Agreement, the Apex Thunder Terms of Service, or applicable Data Protection Laws, the following terms shall have the meanings set forth below. These definitions shall be interpreted consistently with the GDPR and other applicable Data Protection Laws and, where applicable, shall include any amendments, replacements, or successor legislation.

1.1 Applicable Data Protection Laws

"Applicable Data Protection Laws" means the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, the United Kingdom Data Protection Act 2018, and any other applicable privacy, data protection, cybersecurity, or electronic communications legislation governing the Processing of Personal Data by either party, as amended, replaced, or superseded from time to time.

1.2 Personal Data

"Personal Data" means any information relating to an identified or identifiable natural person as defined under Applicable Data Protection Laws, including any information that directly or indirectly identifies an individual.

1.3 Data Subject

"Data Subject" means an identified or identifiable natural person whose Personal Data is processed.

1.4 Controller

"Controller" means the natural or legal person, public authority, agency, or other body which alone or jointly determines the purposes and means of the Processing of Personal Data.

1.5 Processor

"Processor" means the natural or legal person, public authority, agency, or other body which Processes Personal Data on behalf of the Controller.

1.6 Processing

"Processing" or "Process" means any operation or set of operations performed on Personal Data, whether by automated or non-automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, making available, alignment, combination, restriction, erasure, or destruction.

1.7 Authorized Subprocessor

"Authorized Subprocessor" means a third-party service provider engaged by Apex Thunder to Process Personal Data on behalf of the Customer solely for the purpose of providing or supporting the Services and subject to appropriate contractual data protection obligations.

1.8 Personal Data Breach

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Personal Data transmitted, stored, or otherwise Processed.

1.9 Services

"Services" means any hosting, cloud infrastructure, virtual private server (VPS), dedicated server, managed service, technical support, website-related service, software, platform, feature, or other product or service made available by Apex Thunder under the applicable service agreement, including any updates, enhancements, or successor offerings.

1.10 Customer

"Customer" means the individual or legal entity that has entered into a valid agreement with Apex Thunder for the provision of Services and, where applicable, acts as the Controller of the Personal Data Processed under this Agreement.

1.11 Apex Thunder

"Apex Thunder" means the service provider offering the Services under the applicable agreement and, where applicable, acting as the Processor of Personal Data on behalf of the Customer.

1.12 Agreement

"Agreement" means this Data Processing Agreement together with the applicable Terms of Service, Privacy Policy, and any other contractual documents expressly incorporated by reference. Except where Applicable Data Protection Laws require otherwise, this DPA supplements, and does not replace or invalidate, the parties' primary service agreement.

2. Roles of the Parties

The parties acknowledge that their respective roles concerning the Processing of Personal Data depend upon the nature of the Services provided and the specific Processing activities performed. This Agreement applies only where Apex Thunder Processes Personal Data on behalf of the Customer as a Processor and does not alter the parties' respective responsibilities under Applicable Data Protection Laws.

2.1 Customer as Data Controller

Unless otherwise expressly agreed in writing, the Customer acts as the Controller and remains solely responsible for determining the purposes, legal basis, and means of Processing Personal Data. The Customer further represents and warrants that it has all necessary rights, permissions, notices, and lawful bases required under Applicable Data Protection Laws to Process Personal Data through the Services.

2.2 Apex Thunder as Data Processor

Where Apex Thunder Processes Personal Data solely on behalf of the Customer in connection with the Services, Apex Thunder acts as a Processor and shall Process Personal Data only in accordance with the Customer's documented instructions, this Agreement, the applicable service agreement, and Applicable Data Protection Laws, unless otherwise required by applicable law.

2.3 Independent Controller Activities

Apex Thunder acts as an independent Controller for Processing activities undertaken for its own legitimate business purposes or to comply with legal obligations. Such activities include, without limitation, customer account administration, identity verification, billing, payment processing, fraud prevention, abuse prevention, cybersecurity, service monitoring, logging, legal compliance, responding to lawful requests from competent authorities, maintaining business records, enforcing contractual rights, and protecting the security, availability, and integrity of the Services.

2.4 Customer Instructions

The Customer is solely responsible for the legality, accuracy, and completeness of any instructions provided to Apex Thunder relating to the Processing of Personal Data. Apex Thunder is not responsible for independently verifying whether the Customer's instructions comply with Applicable Data Protection Laws and reserves the right to refuse, suspend, or decline to implement any instruction that it reasonably believes may violate applicable law, compromise the security or integrity of the Services, or expose Apex Thunder or any third party to legal or regulatory risk.

2.5 No Monitoring Obligation

Unless expressly required by Applicable Data Protection Laws or agreed in writing, Apex Thunder has no obligation to monitor, investigate, validate, or determine the nature, content, legality, or accuracy of Personal Data uploaded, stored, transmitted, or otherwise Processed by or on behalf of the Customer through the Services.

2.6 No Transfer of Ownership

Nothing in this Agreement transfers ownership of Personal Data to Apex Thunder. Except where Apex Thunder acts as an independent Controller for its own lawful purposes, all rights, title, and interests in Personal Data remain with the Customer or the applicable Data Subject, as determined under Applicable Data Protection Laws.

3. Processing of Personal Data

Apex Thunder shall Process Personal Data only to the extent reasonably necessary to provide, maintain, secure, support, and improve the Services, perform its contractual obligations, comply with Applicable Data Protection Laws, and fulfill other lawful obligations arising under the applicable service agreement. Processing shall be carried out only in accordance with this Agreement, the Customer's documented instructions where applicable, and Applicable Data Protection Laws.

3.1 Processing Instructions

Apex Thunder shall Process Personal Data only on the documented instructions of the Customer, including instructions reasonably inferred from the Customer's configuration, administration, deployment, and ordinary use of the Services, unless Processing is required by Applicable Data Protection Laws. Where legally permitted, Apex Thunder may notify the Customer before carrying out any Processing required by law that is inconsistent with the Customer's instructions. Apex Thunder reserves the right to refuse, suspend, or decline any instruction that it reasonably believes is unlawful, technically infeasible, or would compromise the security, integrity, or availability of the Services.

3.2 Purpose Limitation

Apex Thunder shall not Process Customer Personal Data for purposes incompatible with providing the Services. Except where required by law or expressly authorized by the Customer, Apex Thunder will not sell Customer Personal Data or use it for targeted advertising, commercial profiling, or unrelated marketing activities. Nothing in this Agreement restricts Apex Thunder from using aggregated, anonymized, or de-identified information that no longer constitutes Personal Data under Applicable Data Protection Laws.

3.3 Nature of Processing

Depending upon the Services used by the Customer, Processing activities may include collection, recording, organization, structuring, storage, retrieval, consultation, transmission, hosting, caching, backup, replication, migration, restoration, technical support, troubleshooting, deletion, destruction, and other Processing operations reasonably necessary for the provision, maintenance, protection, or improvement of the Services. Such Processing may be performed through automated or manual means where appropriate.

3.4 Categories of Personal Data

The categories of Personal Data Processed depend upon the Customer's use of the Services and may include account information, contact information, billing information, authentication credentials, technical identifiers, IP addresses, support communications, website content, application data, system logs, metadata, and any other Personal Data intentionally submitted, transmitted, stored, or otherwise Processed by or on behalf of the Customer through the Services.

3.5 Categories of Data Subjects

Personal Data Processed under this Agreement may relate to the Customer, the Customer's employees, contractors, authorized users, website visitors, application users, clients, suppliers, business contacts, prospective customers, or any other individuals whose Personal Data is Processed through the Services under the Customer's direction.

3.6 Duration of Processing

Apex Thunder shall Process Personal Data only for the duration necessary to provide the applicable Services, comply with documented Customer instructions, satisfy Applicable Data Protection Laws, fulfill legitimate legal obligations, resolve disputes, enforce contractual rights, or meet documented retention requirements. Upon termination of the applicable Services, Personal Data shall be retained, returned, or deleted in accordance with Section 11 of this Agreement and the Apex Thunder data retention practices.

4. Customer Responsibilities

The Customer remains solely responsible for the Personal Data submitted to or processed through the Services and for ensuring that such Processing complies with Applicable Data Protection Laws. Nothing in this Agreement transfers the Customer's legal responsibilities as the Controller or relieves the Customer of its independent compliance obligations.

4.1 Lawful Basis for Processing

The Customer represents and warrants that it has established and shall maintain a valid legal basis for the Processing of all Personal Data submitted to the Services, including where required obtaining valid consent or relying upon another lawful basis under Applicable Data Protection Laws.

4.2 Accuracy and Legality of Personal Data

The Customer is solely responsible for the accuracy, quality, integrity, legality, and reliability of all Personal Data uploaded, transmitted, stored, or otherwise Processed through the Services. Apex Thunder has no obligation to verify, monitor, investigate, or determine whether Personal Data has been lawfully collected or Processed by the Customer.

4.3 Customer Instructions

The Customer shall provide only lawful, complete, and accurate instructions regarding the Processing of Personal Data. The Customer acknowledges that Apex Thunder may rely upon such instructions without independently assessing their legality and may refuse, suspend, or decline any instruction reasonably believed to violate Applicable Data Protection Laws, applicable regulations, court orders, contractual obligations, or the security and integrity of the Services.

4.4 Security Responsibilities

The Customer is solely responsible for maintaining appropriate administrative, organizational, and technical safeguards within its own environment, including without limitation user access controls, authentication credentials, endpoint security, encryption where appropriate, application security, software updates, backups, API integrations, and any systems connected to or interacting with the Services.

4.5 Sensitive Personal Data

Unless expressly supported by the applicable Service and permitted under Applicable Data Protection Laws, the Customer shall not intentionally Process or instruct Apex Thunder to Process special categories of Personal Data, biometric data, genetic data, criminal conviction data, or any other sensitive information requiring enhanced legal protections. The Customer assumes full responsibility for any such Processing initiated by or on its behalf.

4.6 Compliance with Applicable Laws

The Customer remains solely responsible for complying with all Applicable Data Protection Laws and any other laws, regulations, or industry-specific requirements governing the collection, use, disclosure, transfer, retention, or deletion of Personal Data, including providing legally required privacy notices and responding to requests from Data Subjects where applicable.

4.7 International Transfers Initiated by the Customer

Where the Customer instructs or enables the international transfer of Personal Data through the Services, the Customer is solely responsible for ensuring that such transfers comply with Applicable Data Protection Laws and that all required transfer mechanisms, assessments, notices, or authorizations have been implemented before initiating the transfer.

4.8 Indemnification for Customer Processing

To the fullest extent permitted by applicable law, the Customer shall defend, indemnify, and hold harmless Apex Thunder, its affiliates, personnel, contractors, and service providers from and against any claims, investigations, administrative proceedings, regulatory actions, damages, liabilities, penalties, fines, costs, or expenses arising from the Customer's breach of this Agreement, unlawful Processing of Personal Data, invalid Processing instructions, or failure to comply with Applicable Data Protection Laws, except to the extent directly caused by Apex Thunder's proven breach of this Agreement or Applicable Data Protection Laws.

5. Confidentiality

Apex Thunder maintains appropriate confidentiality safeguards designed to protect Personal Data processed on behalf of Customers. Access to Personal Data is restricted to authorized personnel and Authorized Subprocessors who require such access to perform their legitimate duties in connection with the Services and who are subject to appropriate confidentiality obligations.

5.1 Confidentiality Obligations

Apex Thunder shall take commercially reasonable measures to ensure that any person authorized to Process Personal Data is bound by contractual, statutory, or professional duties of confidentiality or is otherwise subject to an appropriate legal obligation of confidentiality before being granted access to such Personal Data.

5.2 Restricted Access

Access to Personal Data shall be limited to personnel and Authorized Subprocessors whose access is reasonably necessary to provide, maintain, secure, support, or improve the Services, comply with legal obligations, investigate abuse or security incidents, or otherwise fulfill legitimate business purposes consistent with this Agreement and Applicable Data Protection Laws.

5.3 Need-to-Know Principle

Apex Thunder applies the principle of least privilege and need-to-know access where reasonably appropriate, taking into account the nature of the Services, operational requirements, security considerations, and applicable legal obligations.

5.4 Permitted Disclosures

Nothing in this Agreement prevents Apex Thunder from disclosing Personal Data where such disclosure is required by Applicable Data Protection Laws, other applicable laws, binding court orders, lawful governmental requests, regulatory requirements, or to protect the rights, property, security, or legal interests of Apex Thunder, its Customers, users, or third parties, provided such disclosure is made only to the extent legally permitted or required.

5.5 Survival of Confidentiality

The confidentiality obligations described in this Section shall survive the termination or expiration of the applicable Services for so long as Apex Thunder retains Personal Data in accordance with this Agreement, Applicable Data Protection Laws, or other applicable legal obligations.

6. Technical & Organizational Security Measures

Apex Thunder implements and maintains commercially reasonable technical and organizational security measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, unauthorized access, and other forms of unlawful Processing. Such measures are selected having regard to the nature of the Services, the risks associated with the Processing, available technology, implementation costs, industry practices, and Applicable Data Protection Laws. No security program, product, infrastructure, or technology can guarantee absolute security or prevent every security incident.

6.1 Technical & Organizational Measures

Apex Thunder maintains administrative, physical, technical, and organizational safeguards intended to preserve the confidentiality, integrity, availability, and resilience of systems used to Process Personal Data. Security measures are periodically reviewed and may be modified, enhanced, replaced, or updated to address evolving threats, operational requirements, technological developments, and changes in Applicable Data Protection Laws.

6.2 Access Controls

Apex Thunder implements access management procedures intended to limit access to Personal Data to authorized personnel whose access is reasonably necessary to perform their assigned responsibilities. Access permissions are managed using the principles of least privilege and role-based access where reasonably appropriate.

6.3 Encryption & Secure Communications

Where commercially reasonable, technically feasible, and appropriate for the applicable Services, Apex Thunder utilizes encryption, secure communication protocols, certificate management, and other protective technologies designed to safeguard Personal Data during transmission and, where applicable, while at rest. The specific technologies employed may change over time without prior notice.

6.4 Infrastructure Security

Apex Thunder maintains layered security controls intended to protect its infrastructure, including networks, compute resources, virtualization platforms, storage systems, management systems, and supporting services. Depending on the applicable Service, these controls may include network segmentation, firewalls, traffic filtering, denial-of-service mitigation, malware protection, intrusion detection or prevention technologies, vulnerability management, and other appropriate safeguards.

6.5 Monitoring & Logging

Apex Thunder may monitor, record, and analyze operational events, security events, authentication activity, system logs, and other technical information for purposes including service operation, security monitoring, abuse prevention, incident response, troubleshooting, legal compliance, and protection of the Services. Logs may be retained for periods determined by operational, security, contractual, or legal requirements.

6.6 Business Continuity & Resilience

Apex Thunder maintains commercially reasonable business continuity, disaster recovery, backup, and operational resilience procedures appropriate for the Services offered. Recovery capabilities, backup frequency, retention periods, redundancy, and restoration objectives may vary depending upon the applicable Service, service plan, infrastructure, technical limitations, and operational requirements.

6.7 Shared Security Responsibility

Security is a shared responsibility. While Apex Thunder implements security measures for the infrastructure and Services under its control, the Customer remains solely responsible for securing its own applications, operating systems, software, authentication credentials, encryption keys, devices, network configurations, third-party integrations, user permissions, and any content or Personal Data under the Customer's control.

6.8 Continuous Security Improvements

Apex Thunder may modify, replace, enhance, or discontinue specific security controls, technologies, vendors, or operational procedures at any time where reasonably necessary to improve security, maintain service availability, comply with Applicable Data Protection Laws, address emerging threats, respond to newly identified vulnerabilities, or support operational requirements, provided that such changes do not materially reduce the overall level of protection appropriate for the applicable Services.

7. Authorized Subprocessors

In order to provide, operate, maintain, secure, support, and improve the Services, Apex Thunder may engage carefully selected affiliates and third-party service providers ("Authorized Subprocessors") to Process Personal Data on behalf of the Customer where reasonably necessary. Apex Thunder requires Authorized Subprocessors to protect Personal Data through appropriate contractual, technical, and organizational safeguards consistent with Applicable Data Protection Laws.

7.1 Appointment of Authorized Subprocessors

Apex Thunder may appoint Authorized Subprocessors to provide infrastructure, cloud services, data center operations, payment processing, customer communications, monitoring, backup, security, technical support, software platforms, or other services reasonably necessary for the operation and delivery of the Services. Apex Thunder selects Authorized Subprocessors using reasonable commercial, operational, technical, security, and compliance considerations.

7.2 Contractual Safeguards

Apex Thunder requires Authorized Subprocessors that Process Personal Data on its behalf to be subject to written contractual obligations that are reasonably designed to protect Personal Data, maintain appropriate confidentiality, implement appropriate technical and organizational measures, and Process Personal Data only as necessary for the services they provide, to the extent required by Applicable Data Protection Laws.

7.3 General Customer Authorization

By entering into this Agreement, the Customer provides Apex Thunder with a general authorization to engage, replace, remove, or change Authorized Subprocessors where reasonably necessary for the provision, maintenance, security, operation, or improvement of the Services.

7.4 Changes to Authorized Subprocessors

Apex Thunder may appoint, replace, consolidate, remove, or otherwise modify its Authorized Subprocessors at any time to address operational, technical, commercial, legal, security, availability, or business requirements. Where required by Applicable Data Protection Laws, Apex Thunder will implement any legally required safeguards relating to such changes.

7.5 International Processing

Where an Authorized Subprocessor Processes Personal Data in a country different from that in which the Personal Data originated, Apex Thunder shall implement transfer mechanisms or safeguards required by Applicable Data Protection Laws where such safeguards are legally required.

7.6 Responsibility for Authorized Subprocessors

Apex Thunder remains responsible for its own obligations under this Agreement to the extent required by Applicable Data Protection Laws. Nothing in this Section shall be interpreted as creating strict liability for the independent acts or omissions of an Authorized Subprocessor beyond the responsibility imposed upon Apex Thunder by Applicable Data Protection Laws or the applicable service agreements.

7.7 Customer-Selected Third-Party Services

This Section applies only to Authorized Subprocessors engaged by Apex Thunder. It does not apply to third-party products, services, software, plugins, APIs, integrations, applications, marketplaces, or providers independently selected, installed, configured, or used by the Customer. The Customer remains solely responsible for evaluating the privacy, security, legality, and compliance of such independent third-party services.

8. International Data Transfers

The provision of the Services may require Personal Data to be Processed in jurisdictions other than the country in which the Personal Data was originally collected. Where international transfers of Personal Data occur and Applicable Data Protection Laws require specific safeguards, Apex Thunder shall implement transfer mechanisms or other legally recognized safeguards to the extent required by applicable law.

8.1 International Processing

Depending on the Services selected by the Customer, Personal Data may be Processed by Apex Thunder, its affiliates, Authorized Subprocessors, infrastructure providers, or other service providers located in multiple jurisdictions where reasonably necessary for the provision, operation, maintenance, support, security, resilience, or improvement of the Services.

8.2 Transfer Safeguards

Where Applicable Data Protection Laws require safeguards for international transfers, Apex Thunder may rely upon adequacy decisions, Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA), the UK Addendum to the SCCs, binding contractual commitments, certifications, or any other transfer mechanism recognized under Applicable Data Protection Laws, as appropriate for the relevant transfer.

8.3 Transfers to Authorized Subprocessors

Where Personal Data is Processed by an Authorized Subprocessor in another jurisdiction, Apex Thunder shall require such Authorized Subprocessor to implement transfer safeguards where required by Applicable Data Protection Laws and to Process Personal Data only for the purposes authorized under this Agreement.

8.4 Customer Responsibilities

The Customer acknowledges that the use of globally distributed infrastructure, cloud platforms, content delivery networks, security services, backup systems, communications providers, or other technical resources may involve international transfers of Personal Data. The Customer remains solely responsible for determining whether its own legal or regulatory obligations require specific data residency, localization, transfer documentation, risk assessments, notices, or other compliance measures before using the Services.

8.5 Government & Law Enforcement Requests

Where Apex Thunder receives a legally binding request from a court, governmental authority, regulator, or law enforcement agency for access to Personal Data, Apex Thunder may disclose the requested information to the extent required by applicable law. Where legally permitted and reasonably practicable, Apex Thunder may notify the Customer before making such disclosure. Nothing in this Agreement requires Apex Thunder to provide notice where prohibited by law, court order, confidentiality obligation, or other legally binding restriction.

8.6 Changes to Transfer Mechanisms

Apex Thunder may modify, replace, supplement, or update its international transfer mechanisms, contractual safeguards, operational practices, or supporting documentation at any time where reasonably necessary to reflect changes in Applicable Data Protection Laws, regulatory guidance, judicial decisions, technological developments, or operational requirements.

9. Assistance with Data Subject Requests

Where Apex Thunder Processes Personal Data solely on behalf of the Customer as a Processor, Apex Thunder shall provide commercially reasonable assistance to the Customer in responding to Data Subject requests only to the extent required by Applicable Data Protection Laws, taking into account the nature of the Processing, the functionality of the Services, and the information available to Apex Thunder.

9.1 Customer Responsibility

The Customer, as Controller, remains solely responsible for receiving, assessing, responding to, and documenting Data Subject requests, including determining whether a request should be granted, refused, restricted, or otherwise addressed under Applicable Data Protection Laws.

9.2 Assistance by Apex Thunder

Upon receiving a valid written request from the Customer, Apex Thunder may provide commercially reasonable assistance using available technical and organizational measures to help the Customer comply with its obligations relating to Data Subject requests, to the extent required by Applicable Data Protection Laws and subject to the capabilities of the applicable Services.

9.3 Requests Received Directly

If Apex Thunder receives a request directly from a Data Subject relating to Personal Data Processed solely on behalf of the Customer, Apex Thunder may decline to respond substantively and may instead refer the requester to the Customer. Where legally permitted and reasonably practicable, Apex Thunder may notify the Customer of such request.

9.4 Identity Verification

Apex Thunder may require sufficient information to verify the identity, authority, and legitimacy of any requester before taking any action involving Personal Data. Apex Thunder shall not be responsible for delays resulting from incomplete, inaccurate, fraudulent, or unverifiable requests.

9.5 Limitations of Assistance

Apex Thunder shall not be required to provide assistance where doing so would violate Applicable Data Protection Laws, other applicable laws, court orders, contractual obligations, confidentiality obligations, legal privilege, security requirements, or the rights and freedoms of other persons. Apex Thunder may also decline requests that are technically infeasible, manifestly unfounded, excessive, repetitive, or disproportionate.

9.6 Service Limitations

The Customer acknowledges that the nature of hosting and cloud infrastructure services may limit Apex Thunder's ability to identify, isolate, modify, retrieve, or delete specific Personal Data where such actions are not technically feasible, would adversely affect the security, integrity, or operation of the Services, or would impact Personal Data belonging to other customers.

9.7 Costs of Assistance

Where responding to Customer requests requires substantial manual effort, restoration of archived information, custom engineering, dedicated technical resources, legal review, or other extraordinary operational activities beyond the standard functionality of the Services, Apex Thunder reserves the right to charge reasonable fees or recover its reasonable costs to the extent permitted by the applicable service agreement and Applicable Data Protection Laws.

10. Personal Data Breach Notification

Apex Thunder maintains incident response procedures designed to identify, investigate, assess, contain, mitigate, and remediate actual or suspected Personal Data Breaches affecting Personal Data Processed under this Agreement. Where Apex Thunder acts as a Processor, it shall notify the Customer of a confirmed Personal Data Breach without undue delay to the extent required by Applicable Data Protection Laws.

10.1 Incident Detection & Response

Apex Thunder maintains commercially reasonable monitoring, detection, investigation, escalation, containment, recovery, and incident response procedures designed to address security incidents that may affect the confidentiality, integrity, or availability of Personal Data Processed through the Services.

10.2 Customer Notification

Where Apex Thunder becomes aware of a confirmed Personal Data Breach affecting Personal Data Processed on behalf of the Customer, Apex Thunder shall notify the Customer without undue delay to the extent required by Applicable Data Protection Laws. Initial notifications may be based upon information reasonably available at the time and may be supplemented as additional information becomes available during the investigation.

10.3 Information Provided

To the extent reasonably available, breach notifications may include a description of the nature of the Personal Data Breach, the categories of affected Personal Data, the likely consequences, corrective actions taken or proposed, recommended mitigation steps, and other information reasonably necessary to assist the Customer in meeting its legal obligations.

10.4 Customer Responsibilities

The Customer remains solely responsible for determining whether any Personal Data Breach must be reported to supervisory authorities, affected Data Subjects, customers, business partners, regulators, or any other third party, except where Apex Thunder is separately required by Applicable Data Protection Laws to provide such notification.

10.5 Cooperation

Subject to the nature of the Services and the information reasonably available, Apex Thunder may provide commercially reasonable cooperation to assist the Customer in investigating a confirmed Personal Data Breach and in fulfilling obligations imposed by Applicable Data Protection Laws, provided that such assistance does not materially interfere with Apex Thunder's operations, security, legal obligations, or the rights of other customers.

10.6 Incident Mitigation

Following identification of a confirmed Personal Data Breach, Apex Thunder may implement commercially reasonable containment, remediation, recovery, corrective, and preventive measures appropriate to the circumstances of the incident, taking into account the nature of the Services, operational requirements, and Applicable Data Protection Laws.

10.7 No Admission of Liability

Any notification, investigation, communication, remediation effort, or other action undertaken by Apex Thunder in connection with a Personal Data Breach shall not constitute an admission of liability, negligence, fault, regulatory non-compliance, contractual breach, or legal responsibility. Such actions are undertaken solely for security, operational, contractual, or legal compliance purposes.

11. Data Retention & Deletion

Apex Thunder retains Personal Data only for as long as reasonably necessary to provide the Services, perform contractual obligations, maintain security, comply with Applicable Data Protection Laws, protect legitimate business interests, resolve disputes, enforce contractual rights, and satisfy regulatory or legal requirements. Following termination of the applicable Services, Personal Data shall be retained, returned, deleted, anonymized, or otherwise disposed of in accordance with this Agreement, the applicable Service terms, operational requirements, and Applicable Data Protection Laws.

11.1 Retention During the Services

Apex Thunder may retain Personal Data for as long as reasonably necessary to provide, operate, secure, maintain, support, troubleshoot, back up, restore, monitor, improve, or otherwise administer the Services, and to fulfill contractual, operational, legal, regulatory, accounting, fraud prevention, security, and compliance obligations.

11.2 Customer Responsibility

The Customer is solely responsible for determining its own data retention requirements and for exporting, downloading, migrating, or otherwise retrieving Customer Data before any suspension, expiration, cancellation, or termination of the applicable Services. Apex Thunder shall not be responsible for any inability to recover Customer Data after the expiration of any applicable retention period or after deletion has occurred in accordance with this Agreement.

11.3 Return or Deletion of Personal Data

Subject to the functionality of the applicable Services, technical feasibility, Applicable Data Protection Laws, and any applicable retention requirements, Apex Thunder may return, enable the Customer to retrieve, delete, anonymize, or otherwise dispose of Personal Data following termination of the Services. Apex Thunder shall have no obligation to retain Customer Data beyond any applicable retention period unless otherwise required by law or expressly agreed in writing.

11.4 Backup & Disaster Recovery Systems

Personal Data contained within backup media, disaster recovery systems, archived storage, snapshots, replicas, or other resilience mechanisms may remain until such media is overwritten, rotated, expired, or securely destroyed through normal operational lifecycle processes. During this period, such data shall remain subject to the confidentiality and security safeguards applicable to backup systems.

11.5 Legal & Operational Retention

Apex Thunder may retain Personal Data where reasonably necessary to comply with Applicable Data Protection Laws, tax or accounting obligations, court orders, regulatory requirements, lawful governmental requests, fraud prevention, security investigations, abuse prevention, dispute resolution, insurance requirements, audit obligations, or the establishment, exercise, or defense of legal claims.

11.6 Secure Deletion

Where Personal Data is deleted, Apex Thunder shall use commercially reasonable methods appropriate to the applicable storage technology and operational environment to render the data inaccessible or securely remove it, taking into account technical limitations, backup architecture, and applicable industry practices. Immediate or irreversible deletion from all storage media is not guaranteed.

11.7 Survival of Obligations

Any obligations relating to confidentiality, lawful retention, security, regulatory compliance, dispute resolution, audit, indemnification, limitation of liability, or the establishment, exercise, or defense of legal claims shall survive the termination or expiration of this Agreement to the extent permitted by applicable law.

12. Audits & Compliance

Apex Thunder maintains internal policies, procedures, technical safeguards, and operational practices designed to support compliance with Applicable Data Protection Laws. Subject to this Agreement, Apex Thunder may make available information reasonably necessary to demonstrate its compliance as a Processor while protecting the security, confidentiality, availability, integrity, trade secrets, proprietary information, and the rights of Apex Thunder, its Customers, and third parties.

12.1 Demonstrating Compliance

Upon reasonable written request, Apex Thunder may provide documentation, security information, compliance statements, questionnaires, certifications, policies, summaries, or other evidence reasonably sufficient to demonstrate compliance with the obligations applicable under this Agreement, provided that such disclosure does not compromise security, confidentiality, legal obligations, trade secrets, or the rights of other Customers or third parties.

12.2 Audit Requests

Where Applicable Data Protection Laws grant the Customer audit rights, any audit shall be subject to reasonable prior written notice, mutually agreed scope, scheduling, duration, confidentiality obligations, and reasonable operational limitations. Audits shall be conducted in a manner that minimizes disruption to Apex Thunder's business operations, personnel, infrastructure, systems, security, and other Customers.

12.3 Alternative Evidence

Apex Thunder may satisfy audit or inspection requests by providing existing audit reports, compliance certifications, independent assessments, security documentation, standardized questionnaires, penetration testing summaries, or other comparable evidence where such documentation reasonably demonstrates compliance, thereby avoiding or limiting the need for direct inspections.

12.4 Audit Restrictions

Nothing in this Agreement grants the Customer unrestricted access to Apex Thunder's facilities, source code, production environments, internal systems, vulnerability assessments, penetration testing results, security configurations, personnel, confidential business information, trade secrets, or information relating to other Customers or third parties. Apex Thunder may reasonably refuse, postpone, supervise, restrict, or terminate any audit activity that could compromise security, availability, legal compliance, confidentiality, or operational stability.

12.5 Costs of Audits

Unless otherwise required by Applicable Data Protection Laws or expressly agreed in writing, the Customer shall bear its own costs associated with any audit or inspection. Where an audit requires substantial legal review, engineering resources, dedicated personnel, custom documentation, technical assistance, or extraordinary operational effort from Apex Thunder, Apex Thunder reserves the right to recover its reasonable costs to the extent permitted by applicable law.

12.6 Regulatory Cooperation

Apex Thunder may cooperate with competent supervisory authorities, courts, regulators, or other governmental bodies to the extent required by Applicable Data Protection Laws. Where legally permitted and reasonably practicable, Apex Thunder may notify the Customer before disclosing Customer-related information.

12.7 Continuous Compliance

Apex Thunder may periodically review, update, improve, or modify its privacy, security, operational, and compliance practices to reflect changes in Applicable Data Protection Laws, regulatory guidance, industry standards, emerging threats, technological developments, and operational requirements.

13. Liability, Indemnification & Limitation of Liability

Each party remains independently responsible for complying with the obligations applicable to its respective role under Applicable Data Protection Laws. Except where mandatory law expressly provides otherwise, this Agreement does not expand, create, reduce, or modify any liability, remedy, exclusion of damages, limitation of liability, allocation of risk, or indemnification obligation contained in the applicable Terms of Service or any other governing agreement between the parties.

13.1 Customer Responsibility

The Customer remains solely responsible for determining the lawful basis for Processing Personal Data, providing required privacy notices, obtaining any required consents or other legal authorizations, responding to Data Subject requests, ensuring the legality, accuracy, integrity, and quality of Customer Data, and complying with all obligations applicable to a Controller under Applicable Data Protection Laws.

13.2 Apex Thunder Responsibility

Where Apex Thunder acts as a Processor, Apex Thunder shall perform its obligations under this Agreement only to the extent required by Applicable Data Protection Laws, the applicable Service agreement, and the Customer's documented instructions, except where Processing is otherwise required by law.

13.3 Independent Compliance

Each party is independently responsible for its own compliance with Applicable Data Protection Laws. Neither party shall be liable for the acts, omissions, instructions, decisions, or legal non-compliance of the other party except to the extent liability is imposed by mandatory law.

13.4 Indemnification

Any indemnification obligations relating to the Services or the Processing of Personal Data shall be governed exclusively by the applicable Terms of Service or other written agreement between the parties. Nothing in this Agreement creates any additional or independent indemnification obligation except where expressly required by mandatory law.

13.5 Limitation of Liability

To the maximum extent permitted by Applicable Data Protection Laws, any limitation of liability, exclusion of damages, disclaimer, allocation of risk, remedy limitation, or liability cap contained in the applicable Terms of Service shall apply equally to this Agreement. Nothing in this Agreement shall be interpreted as expanding Apex Thunder's liability beyond that expressly provided under the governing Service agreement or mandatory law.

13.6 Force Majeure

Neither party shall be responsible for delays or failures in performing obligations under this Agreement resulting from events beyond its reasonable control, including natural disasters, armed conflicts, terrorism, cyber warfare, widespread Internet failures, telecommunications failures, utility outages, governmental actions, epidemics, pandemics, labor disputes, failures of third-party infrastructure providers, or other force majeure events, except where liability cannot legally be excluded.

13.7 Survival

Any provisions relating to confidentiality, security, lawful retention, limitation of liability, indemnification, dispute resolution, governing law, regulatory cooperation, audit rights, and any obligations intended by their nature to survive shall continue after the termination or expiration of this Agreement to the extent permitted by Applicable Data Protection Laws.

14. Changes to this Agreement

Apex Thunder may amend, revise, supplement, replace, or otherwise modify this Data Processing Agreement from time to time to reflect changes in Applicable Data Protection Laws, regulatory guidance, judicial decisions, industry standards, security practices, technological developments, operational requirements, business practices, or the Services provided. The most recently published version of this Agreement supersedes all previous versions unless expressly stated otherwise.

14.1 Right to Modify

Apex Thunder reserves the right to modify this Agreement whenever reasonably necessary to maintain legal compliance, improve privacy or security practices, introduce new Services or processing activities, respond to operational or technical developments, address emerging threats, or satisfy regulatory or contractual requirements.

14.2 Effective Date

Unless otherwise stated, amendments to this Agreement shall become effective on the Effective Date specified in the updated version. To the maximum extent permitted by Applicable Data Protection Laws, continued access to or use of the Services after the Effective Date constitutes acceptance of the revised Agreement.

14.3 Notice of Material Changes

Where required by Applicable Data Protection Laws or where Apex Thunder determines that a modification materially affects this Agreement, Apex Thunder may provide notice through the Client Area, email, website announcements, or other reasonable communication channels. Failure by the Customer to receive, access, review, or acknowledge such notice shall not, by itself, affect the validity or enforceability of the revised Agreement where notice has been provided in a commercially reasonable manner or where no notice is required by law.

14.4 Legal & Regulatory Changes

Apex Thunder may implement immediate or time-sensitive modifications where reasonably necessary to comply with Applicable Data Protection Laws, regulatory guidance, court decisions, legally recognized transfer mechanisms, security requirements, or other legal obligations. Such modifications may take effect without prior notice where immediate implementation is reasonably necessary or required by law.

14.5 Customer Review

The Customer is responsible for periodically reviewing this Agreement to remain informed of revisions affecting the Processing of Personal Data. The current version of this Agreement shall be made available through the Apex Thunder Legal Center.

14.6 Relationship with Other Agreements

This Data Processing Agreement forms part of and should be read together with the applicable Terms of Service, Privacy Policy, Security Policy, Cookie Policy, and other applicable legal documentation published by Apex Thunder. In the event of a conflict relating specifically to the Processing of Personal Data, this Agreement shall prevail only to the extent required by Applicable Data Protection Laws.

15. Contact Information

If you have questions regarding this Data Processing Agreement, require information relating to Apex Thunder's Processing of Personal Data, or need assistance concerning privacy or data protection matters, you may contact Apex Thunder through the official support channels made available for your account or through the Apex Thunder Legal Center. Requests will be reviewed and handled to the extent required by Applicable Data Protection Laws, this Agreement, and the applicable Service agreement.

Privacy & Data Protection

Questions relating to this Agreement, the Processing of Personal Data, international data transfers, or other privacy-related matters may be submitted through the official support channels or Client Area for appropriate review by the relevant personnel.

Customer Requests

Customers seeking assistance regarding Personal Data Processed through the Services should submit requests through the Client Area or other authorized support channels. Apex Thunder may request additional information where reasonably necessary to verify the identity or authority of the requester before taking action.

Regulatory & Legal Inquiries

Competent supervisory authorities, regulators, courts, or other legally authorized entities may communicate with Apex Thunder regarding matters relating to this Agreement through the appropriate contact methods designated by Apex Thunder. Responses will be provided where required by Applicable Data Protection Laws or other applicable legal obligations.

Security & Incident Reporting

If you become aware of a suspected security incident or unauthorized access that may affect Personal Data Processed through the Services, you should notify Apex Thunder without undue delay through the official support or security reporting channels so the matter may be assessed in accordance with applicable incident response procedures.

Frequently Asked Questions

The following frequently asked questions provide additional guidance regarding the application of this Data Processing Agreement, the respective responsibilities of Apex Thunder and its Customers, and the protection of Personal Data under Applicable Data Protection Laws.

What is a Data Processing Agreement ("DPA")?

A Data Processing Agreement ("DPA") is a legally binding agreement that governs how a Data Processor Processes Personal Data on behalf of a Data Controller. It defines the respective responsibilities of the parties and establishes contractual safeguards required under Applicable Data Protection Laws, including the GDPR where applicable.

When does this Agreement apply?

This Agreement applies whenever Apex Thunder Processes Personal Data solely on behalf of a Customer in connection with the Services in the capacity of a Data Processor. It supplements the applicable Terms of Service and other legal documentation where relevant.

Is Apex Thunder always a Data Processor?

No. Depending on the Processing activity, Apex Thunder may act either as a Data Processor or as an independent Data Controller. For example, hosting Customer content is generally performed as a Processor, while billing, fraud prevention, account administration, legal compliance, abuse prevention, and certain security operations are generally performed as an independent Controller.

Does Apex Thunder comply with Applicable Data Protection Laws?

Apex Thunder maintains administrative, technical, and organizational measures designed to support compliance with Applicable Data Protection Laws, including the GDPR, UK GDPR, and other applicable privacy laws where they apply to the Services and the relevant Processing activities. Nothing in this Agreement shall be interpreted as a representation or warranty that every Customer's use of the Services independently complies with such laws.

Does Apex Thunder use Subprocessors?

Yes. Apex Thunder may engage carefully selected authorized Subprocessors where reasonably necessary to provide, maintain, secure, support, or improve the Services. Authorized Subprocessors are contractually required to maintain appropriate privacy, confidentiality, and security obligations consistent with this Agreement and Applicable Data Protection Laws.

Can Personal Data be transferred internationally?

Yes. Depending on the Services used, Personal Data may be Processed in different countries. Where required by Applicable Data Protection Laws, Apex Thunder implements appropriate transfer mechanisms and safeguards recognized under applicable law, including where appropriate, Standard Contractual Clauses (SCCs), adequacy decisions, the UK International Data Transfer Agreement (IDTA), or other legally recognized transfer mechanisms.

How are Personal Data Breaches handled?

Apex Thunder maintains incident response procedures designed to detect, investigate, contain, mitigate, and remediate confirmed Personal Data Breaches. Where required by Applicable Data Protection Laws, affected Customers will be notified without undue delay after Apex Thunder becomes aware of a confirmed Personal Data Breach affecting Personal Data Processed on their behalf. Any such notification shall not constitute an admission of liability or regulatory non-compliance.

What happens to Personal Data when Services are terminated?

Subject to Applicable Data Protection Laws, the applicable Service Agreement, contractual obligations, and legitimate legal retention requirements, Apex Thunder will return or securely delete Personal Data where applicable. Certain information may remain within backup systems until normal retention cycles are completed or where continued retention is required or permitted by law.

Can Customers request information about Apex Thunder's compliance?

Subject to this Agreement, Applicable Data Protection Laws, confidentiality obligations, security requirements, and the protection of other Customers, Apex Thunder may make available information reasonably necessary to demonstrate compliance with its obligations as a Data Processor. Apex Thunder may satisfy such requests through existing documentation, compliance certifications, audit reports, questionnaires, or other reasonable evidence where appropriate instead of permitting direct audits.

Does this Agreement replace the Privacy Policy?

No. This Data Processing Agreement supplements, but does not replace, the applicable Terms of Service, Privacy Policy, Security Policy, Cookie Policy, or other legal documentation published by Apex Thunder. Each document serves a distinct legal purpose and should be read together where applicable.

Will this Agreement change in the future?

Yes. Apex Thunder may amend this Agreement from time to time to reflect changes in Applicable Data Protection Laws, regulatory guidance, security practices, industry standards, operational requirements, technological developments, or the Services. The latest published version will supersede previous versions and will be made available through the Apex Thunder Legal Center.

Who should I contact regarding privacy or GDPR matters?

Requests relating to this Agreement, Personal Data Processing, privacy matters, or Applicable Data Protection Laws may be submitted through Apex Thunder's authorized support channels or Client Area. Requests will be handled to the extent required by Applicable Data Protection Laws, this Agreement, and the applicable Service Agreement.

Is Apex Thunder a Data Controller or a Data Processor?

It depends on the specific Processing activity. Apex Thunder generally acts as a Data Processor when Processing Personal Data solely on behalf of a Customer in connection with the Services. Apex Thunder may also act as an independent Data Controller for limited Processing activities relating to account administration, billing, fraud prevention, security, abuse prevention, legal compliance, and other legitimate business purposes.

Does Apex Thunder appoint a Data Protection Officer (DPO)?

Where Applicable Data Protection Laws require the appointment of a Data Protection Officer ("DPO") or another designated privacy representative, Apex Thunder will comply with those legal requirements. Where no such appointment is legally required, privacy and data protection matters are handled through Apex Thunder's authorized support and operational channels.

Can I request deletion of my Personal Data?

Requests relating to the deletion of Personal Data are handled in accordance with Applicable Data Protection Laws, this Agreement, and the applicable Service Agreement. Certain information may be retained where required or permitted for legal, regulatory, accounting, fraud prevention, security, dispute resolution, the establishment, exercise, or defense of legal claims, or other legitimate purposes permitted by law.

Are backups deleted immediately after Service termination?

No. Personal Data contained within backup systems may remain until the applicable backup media is overwritten, rotated, or securely deleted through the normal backup lifecycle. During this period, such data remains subject to the security, confidentiality, and access controls described in this Agreement.

Can government authorities request access to Personal Data?

Apex Thunder may disclose Personal Data only where required by a legally binding court order, subpoena, lawful governmental request, or other applicable legal process. Where legally permitted, Apex Thunder may notify the affected Customer before making such disclosure and shall disclose only the information legally required.

Does Apex Thunder sell Customer Personal Data?

No. Apex Thunder does not sell Customer Personal Data and does not use Customer Personal Data for advertising, profiling, or unrelated marketing purposes except where expressly authorized by the Customer or required by Applicable Data Protection Laws.

Can Customers audit Apex Thunder?

Audit rights, where available under Applicable Data Protection Laws, are subject to the limitations set forth in this Agreement. Apex Thunder may satisfy audit requests by providing existing audit reports, security documentation, compliance certifications, questionnaires, or other reasonable evidence where appropriate. Any audit must be conducted upon reasonable prior notice, during normal business hours, in a manner that does not unreasonably interfere with Apex Thunder's operations or expose confidential information, trade secrets, security controls, or the rights of other Customers.

Is Customer Data encrypted?

Apex Thunder implements encryption and other technical safeguards where appropriate and reasonably practicable, taking into account the nature of the Services, current technology, operational requirements, and applicable security risks. The specific security measures implemented may vary depending on the Services provided and the underlying infrastructure.

Does this Agreement create additional legal rights?

No. This Agreement supplements the applicable Terms of Service and other governing agreements. Except where required by Applicable Data Protection Laws, it does not create additional warranties, guarantees, remedies, indemnification obligations, or legal rights beyond those expressly provided by applicable law or the applicable Service Agreement.

Who is responsible for the Personal Data stored in my account?

The Customer remains solely responsible for the legality, accuracy, integrity, and security of the Personal Data submitted to or stored through the Services. As the Data Controller, the Customer is responsible for determining the purposes and legal basis for Processing such Personal Data, except where Apex Thunder acts as an independent Data Controller for its own legitimate business purposes.

Does Apex Thunder monitor Customer Data?

Apex Thunder does not routinely access or review Customer Data except where reasonably necessary to provide, secure, maintain, troubleshoot, or support the Services, investigate suspected abuse, comply with applicable legal obligations, respond to Customer-authorized support requests, or otherwise as permitted under the applicable Service Agreement and Applicable Data Protection Laws.

Can I choose where my data is stored?

Data storage and Processing locations depend on the Services selected, the infrastructure used, and operational requirements. Certain Services may allow Customers to select or request a preferred hosting location where such options are offered. The use of globally distributed infrastructure or authorized Subprocessors may nevertheless require limited cross-border Processing as described in this Agreement.

What happens if a provision of this Agreement becomes invalid?

If any provision of this Agreement is determined to be invalid, unlawful, or unenforceable by a competent authority, the remaining provisions shall continue in full force and effect to the maximum extent permitted by Applicable Data Protection Laws. The invalid provision shall be interpreted or replaced, where appropriate, in a manner that most closely reflects its original legal intent.

Can Apex Thunder verify that Customers have obtained lawful consent?

No. The Customer, as the Data Controller, is solely responsible for ensuring that an appropriate legal basis exists for Processing Personal Data, including obtaining any required consents, providing applicable privacy notices, and complying with Applicable Data Protection Laws. Apex Thunder does not independently verify the legality of Customer-submitted Personal Data except where required by law.

Who can access Personal Data at Apex Thunder?

Access to Personal Data is restricted to authorized personnel and authorized Subprocessors who require such access to perform their assigned responsibilities. Such access is granted on a need-to-know basis, is subject to appropriate confidentiality obligations, and is protected by administrative, technical, and organizational security measures designed to prevent unauthorized access or disclosure.