LEGAL
Privacy Notice
Release APX-LGL-V3-DRAFT-2026-07-21 | Last updated July 21, 2026 | Effective date Pending legal approval
This document is prepared for APX launch readiness and should be reviewed by qualified legal/accounting counsel before paid public launch.
# THE APX METHOD™ — Privacy Notice
1. Controller status
APX is expected to act as a controller for customer account, order, LMS, support, recording, and program-delivery data, but counsel must confirm the final role and any licence/permit requirements under Egyptian data-protection law.
2. Data APX may process
| Category | Examples | Purpose |
|---|---|---|
| Account data | name, email, password hash, age confirmation | account creation and security |
| Order/payment metadata | order reference, amount, currency, status, receipt data | sale, access activation, accounting, fraud prevention |
| Program data | enrollment, progress, tasks, feedback, certificate status | service delivery |
| Communication data | support emails, WhatsApp support, LMS messages | support and service communication |
| Session data | attendance, session notes, recording consent, replay links | coaching and quality control |
| Diagnosis data | communication-performance observations | educational assessment only |
| Technical/security data | IP, user agent, logs, audit events | security, fraud prevention, compliance |
| Marketing data | consent, preferences, unsubscribe records | optional marketing where permitted |
3. Lawful bases
The lawful basis must be confirmed by counsel per processing activity. Working categories include contract performance, legal obligation, legitimate interest, consent, claim/defence of legal rights, and court/regulatory compliance.
Consent should only be used where the learner has a genuine choice. Optional marketing, non-essential cookies, service recording where optional, and promotional media use should remain separate from essential service processing.
4. Sensitive data guardrail
APX must avoid collecting medical, mental-health, psychological, neurological, or therapy data. APX Diagnosis must evaluate communication performance, not health or personality disorder status.
5. Providers
APX may use providers for hosting, payment processing, email, video meetings, recordings, analytics, security, and support. The public provider list must name only active, verified providers and must match the vendor/transfer register.
6. International transfers
APX must not treat notice alone as enough for cross-border transfer compliance. Storage locations, provider roles, transfer purposes, safeguards, permits/licences, contracts, subprocessors, and deletion routes must be recorded before launch.
7. Retention
Retention periods must be tied to purpose, legal obligation, accounting requirements, dispute risk, security needs, and deletion capability. Do not promise automatic deletion until tested.
8. Rights requests
Customers may request access, correction, deletion, restriction, withdrawal of consent where applicable, and other rights recognized by mandatory law. APX may need to verify identity proportionately before acting.
9. Breach response
APX must maintain a breach workflow naming the proper authority, responsible owner, decision tree, evidence preservation steps, customer notification criteria, and regulatory clock.
10. Marketing
Transactional service messages are separate from optional marketing. Email/WhatsApp promotions, abandoned-checkout campaigns, referrals, and upsells require separate marketing-law and PDPL confirmation before launch.