What is a Data Processing Agreement ("DPA")?
A Data Processing Agreement ("DPA") is a legally binding agreement that governs how a Data Processor Processes Personal Data on behalf of a Data Controller. It defines the respective responsibilities of the parties and establishes contractual safeguards required under Applicable Data Protection Laws, including the GDPR where applicable.
When does this Agreement apply?
This Agreement applies whenever Apex Thunder Processes Personal Data solely on behalf of a Customer in connection with the Services in the capacity of a Data Processor. It supplements the applicable Terms of Service and other legal documentation where relevant.
Is Apex Thunder always a Data Processor?
No. Depending on the Processing activity, Apex Thunder may act either as a Data Processor or as an independent Data Controller. For example, hosting Customer content is generally performed as a Processor, while billing, fraud prevention, account administration, legal compliance, abuse prevention, and certain security operations are generally performed as an independent Controller.
Does Apex Thunder comply with Applicable Data Protection Laws?
Apex Thunder maintains administrative, technical, and organizational measures designed to support compliance with Applicable Data Protection Laws, including the GDPR, UK GDPR, and other applicable privacy laws where they apply to the Services and the relevant Processing activities. Nothing in this Agreement shall be interpreted as a representation or warranty that every Customer's use of the Services independently complies with such laws.
Does Apex Thunder use Subprocessors?
Yes. Apex Thunder may engage carefully selected authorized Subprocessors where reasonably necessary to provide, maintain, secure, support, or improve the Services. Authorized Subprocessors are contractually required to maintain appropriate privacy, confidentiality, and security obligations consistent with this Agreement and Applicable Data Protection Laws.
Can Personal Data be transferred internationally?
Yes. Depending on the Services used, Personal Data may be Processed in different countries. Where required by Applicable Data Protection Laws, Apex Thunder implements appropriate transfer mechanisms and safeguards recognized under applicable law, including where appropriate, Standard Contractual Clauses (SCCs), adequacy decisions, the UK International Data Transfer Agreement (IDTA), or other legally recognized transfer mechanisms.
How are Personal Data Breaches handled?
Apex Thunder maintains incident response procedures designed to detect, investigate, contain, mitigate, and remediate confirmed Personal Data Breaches. Where required by Applicable Data Protection Laws, affected Customers will be notified without undue delay after Apex Thunder becomes aware of a confirmed Personal Data Breach affecting Personal Data Processed on their behalf. Any such notification shall not constitute an admission of liability or regulatory non-compliance.
What happens to Personal Data when Services are terminated?
Subject to Applicable Data Protection Laws, the applicable Service Agreement, contractual obligations, and legitimate legal retention requirements, Apex Thunder will return or securely delete Personal Data where applicable. Certain information may remain within backup systems until normal retention cycles are completed or where continued retention is required or permitted by law.
Can Customers request information about Apex Thunder's compliance?
Subject to this Agreement, Applicable Data Protection Laws, confidentiality obligations, security requirements, and the protection of other Customers, Apex Thunder may make available information reasonably necessary to demonstrate compliance with its obligations as a Data Processor. Apex Thunder may satisfy such requests through existing documentation, compliance certifications, audit reports, questionnaires, or other reasonable evidence where appropriate instead of permitting direct audits.
Does this Agreement replace the Privacy Policy?
No. This Data Processing Agreement supplements, but does not replace, the applicable Terms of Service, Privacy Policy, Security Policy, Cookie Policy, or other legal documentation published by Apex Thunder. Each document serves a distinct legal purpose and should be read together where applicable.
Will this Agreement change in the future?
Yes. Apex Thunder may amend this Agreement from time to time to reflect changes in Applicable Data Protection Laws, regulatory guidance, security practices, industry standards, operational requirements, technological developments, or the Services. The latest published version will supersede previous versions and will be made available through the Apex Thunder Legal Center.
Who should I contact regarding privacy or GDPR matters?
Requests relating to this Agreement, Personal Data Processing, privacy matters, or Applicable Data Protection Laws may be submitted through Apex Thunder's authorized support channels or Client Area. Requests will be handled to the extent required by Applicable Data Protection Laws, this Agreement, and the applicable Service Agreement.
Is Apex Thunder a Data Controller or a Data Processor?
It depends on the specific Processing activity. Apex Thunder generally acts as a Data Processor when Processing Personal Data solely on behalf of a Customer in connection with the Services. Apex Thunder may also act as an independent Data Controller for limited Processing activities relating to account administration, billing, fraud prevention, security, abuse prevention, legal compliance, and other legitimate business purposes.
Does Apex Thunder appoint a Data Protection Officer (DPO)?
Where Applicable Data Protection Laws require the appointment of a Data Protection Officer ("DPO") or another designated privacy representative, Apex Thunder will comply with those legal requirements. Where no such appointment is legally required, privacy and data protection matters are handled through Apex Thunder's authorized support and operational channels.
Can I request deletion of my Personal Data?
Requests relating to the deletion of Personal Data are handled in accordance with Applicable Data Protection Laws, this Agreement, and the applicable Service Agreement. Certain information may be retained where required or permitted for legal, regulatory, accounting, fraud prevention, security, dispute resolution, the establishment, exercise, or defense of legal claims, or other legitimate purposes permitted by law.
Are backups deleted immediately after Service termination?
No. Personal Data contained within backup systems may remain until the applicable backup media is overwritten, rotated, or securely deleted through the normal backup lifecycle. During this period, such data remains subject to the security, confidentiality, and access controls described in this Agreement.
Can government authorities request access to Personal Data?
Apex Thunder may disclose Personal Data only where required by a legally binding court order, subpoena, lawful governmental request, or other applicable legal process. Where legally permitted, Apex Thunder may notify the affected Customer before making such disclosure and shall disclose only the information legally required.
Does Apex Thunder sell Customer Personal Data?
No. Apex Thunder does not sell Customer Personal Data and does not use Customer Personal Data for advertising, profiling, or unrelated marketing purposes except where expressly authorized by the Customer or required by Applicable Data Protection Laws.
Can Customers audit Apex Thunder?
Audit rights, where available under Applicable Data Protection Laws, are subject to the limitations set forth in this Agreement. Apex Thunder may satisfy audit requests by providing existing audit reports, security documentation, compliance certifications, questionnaires, or other reasonable evidence where appropriate. Any audit must be conducted upon reasonable prior notice, during normal business hours, in a manner that does not unreasonably interfere with Apex Thunder's operations or expose confidential information, trade secrets, security controls, or the rights of other Customers.
Is Customer Data encrypted?
Apex Thunder implements encryption and other technical safeguards where appropriate and reasonably practicable, taking into account the nature of the Services, current technology, operational requirements, and applicable security risks. The specific security measures implemented may vary depending on the Services provided and the underlying infrastructure.
Does this Agreement create additional legal rights?
No. This Agreement supplements the applicable Terms of Service and other governing agreements. Except where required by Applicable Data Protection Laws, it does not create additional warranties, guarantees, remedies, indemnification obligations, or legal rights beyond those expressly provided by applicable law or the applicable Service Agreement.
Who is responsible for the Personal Data stored in my account?
The Customer remains solely responsible for the legality, accuracy, integrity, and security of the Personal Data submitted to or stored through the Services. As the Data Controller, the Customer is responsible for determining the purposes and legal basis for Processing such Personal Data, except where Apex Thunder acts as an independent Data Controller for its own legitimate business purposes.
Does Apex Thunder monitor Customer Data?
Apex Thunder does not routinely access or review Customer Data except where reasonably necessary to provide, secure, maintain, troubleshoot, or support the Services, investigate suspected abuse, comply with applicable legal obligations, respond to Customer-authorized support requests, or otherwise as permitted under the applicable Service Agreement and Applicable Data Protection Laws.
Can I choose where my data is stored?
Data storage and Processing locations depend on the Services selected, the infrastructure used, and operational requirements. Certain Services may allow Customers to select or request a preferred hosting location where such options are offered. The use of globally distributed infrastructure or authorized Subprocessors may nevertheless require limited cross-border Processing as described in this Agreement.
What happens if a provision of this Agreement becomes invalid?
If any provision of this Agreement is determined to be invalid, unlawful, or unenforceable by a competent authority, the remaining provisions shall continue in full force and effect to the maximum extent permitted by Applicable Data Protection Laws. The invalid provision shall be interpreted or replaced, where appropriate, in a manner that most closely reflects its original legal intent.
Can Apex Thunder verify that Customers have obtained lawful consent?
No. The Customer, as the Data Controller, is solely responsible for ensuring that an appropriate legal basis exists for Processing Personal Data, including obtaining any required consents, providing applicable privacy notices, and complying with Applicable Data Protection Laws. Apex Thunder does not independently verify the legality of Customer-submitted Personal Data except where required by law.
Who can access Personal Data at Apex Thunder?
Access to Personal Data is restricted to authorized personnel and authorized Subprocessors who require such access to perform their assigned responsibilities. Such access is granted on a need-to-know basis, is subject to appropriate confidentiality obligations, and is protected by administrative, technical, and organizational security measures designed to prevent unauthorized access or disclosure.