Terms of Service
ApexCM Construction Management
This Privacy Policy (“Privacy Policy”) describes how ApexCM LLC, doing business as ApexCM (Apex Construction Management) (“ApexCM,” “Company,” “we,” “us,” or “our”), collects, uses, processes, stores, discloses, and otherwise handles information in connection with the ApexCM construction management platform, our website, web application, mobile applications, customer and vendor portals, subscription services, communications, and related products and services (collectively, the “Services”).
ApexCM is a cloud-based construction management software platform designed to help contractors and construction businesses manage projects, customers, estimates and proposals, invoices and payments, expenses and receipts, documents, contracts, change orders, workforce activities, reports, and related construction-management operations. The Services may also include artificial-intelligence-assisted functionality, including receipt categorization and floor-plan analysis.
This Privacy Policy applies to information we process through the Services. It also explains certain choices and rights that may be available to you.
By accessing or using the Services, you acknowledge that you have read this Privacy Policy. Where applicable law requires consent for particular processing, we will request that consent separately.
1. SCOPE OF THIS PRIVACY POLICY
This Privacy Policy applies to information processed through ApexCM, including information associated with:
- ApexCM account holders;
- contractors and construction companies using ApexCM;
- workspace owners, administrators, managers, supervisors, employees, project members, and other authorized users;
- customers and prospective customers of ApexCM users;
- employees, workers, subcontractors, vendors, and other individuals whose information an ApexCM customer enters into the Services;
- visitors to ApexCM websites and portals;
- individuals accessing estimate, payment, change-order, vendor, subcontractor, or other portal links;
- individuals communicating with ApexCM; and
- users of any future ApexCM mobile application.
This Privacy Policy does not govern third-party websites, applications, or services that operate independently from ApexCM, even when those services are accessible through a link or integration within ApexCM. Third-party providers maintain their own privacy practices and policies.
2. APEXCM'S ROLE WHEN PROCESSING CUSTOMER DATA
ApexCM customers may enter information about their own customers, employees, workers, subcontractors, vendors, and other individuals into the Services. The platform currently supports this type of third-party data, including names, contact details, project information, payment-related information, signatures, workforce information, and other construction-management records.
Depending on the circumstances and applicable law, an ApexCM business customer may act as the controller, “business,” or similar responsible party for personal information that it submits to ApexCM, while ApexCM may act as a processor, “service provider,” or similar party processing that information on the customer's behalf.
Each ApexCM customer is responsible for determining whether it has the necessary authority, notices, permissions, consents, and other lawful grounds to collect information from third parties and provide that information to ApexCM.
If your personal information was submitted to ApexCM by a contractor, employer, construction company, or another ApexCM customer, you may need to contact that organization directly to exercise certain rights concerning that information. Where legally required and technically appropriate, ApexCM may assist its customers in responding to valid privacy requests.
3. INFORMATION WE COLLECT AND PROCESS
Depending on how you interact with ApexCM and which features you use, we may process the following categories of information.
3.1 Account and Identity Information
We may process information used to create, maintain, authenticate, and administer an ApexCM account, including:
- full name;
- email address;
- telephone number;
- account role;
- workspace membership;
- account and user identifiers;
- authentication-related information;
- current workspace;
- application preferences; and
- account settings.
ApexCM currently uses Base44-managed authentication and account functionality.
3.2 Business and Company Information
ApexCM may process information about a user's business or organization, including:
- legal or business name;
- company or trade name;
- business logo;
- business address;
- telephone number;
- email address;
- website;
- tax identification information or EIN where entered;
- industry;
- company size;
- workspace configuration; and
- other business-profile information.
This information may be used to operate workspaces and may appear on estimates, invoices, reports, PDFs, communications, or other business documents generated through ApexCM.
3.3 Customer and Contact Information
ApexCM users may provide information concerning their customers and prospective customers, including:
- names;
- email addresses;
- telephone numbers;
- physical or project addresses;
- project information;
- estimates and proposals;
- payment requests;
- invoice information;
- change orders;
- communications;
- approvals;
- signatures; and
- related customer records.
ApexCM generally receives this information from the business using the Services rather than directly from the individual concerned.
3.4 Project and Construction Information
We may process project-related information such as:
- project names;
- job-site addresses;
- project descriptions;
- budgets;
- project dates;
- cost codes;
- labor information;
- material information;
- notes;
- documents;
- drawings;
- estimates;
- project status;
- completion information;
- change orders;
- contracts;
- milestones; and
- related construction records.
3.5 Estimates, Proposals and Invoice Information
ApexCM may process information necessary to create and manage estimates, proposals, invoices, and payment requests, including:
- line items;
- quantities;
- pricing;
- totals;
- taxes;
- milestones;
- terms;
- scope information;
- approval status;
- customer comments;
- payment status;
- supporting documents; and
- generated PDFs.
The Services include customer-facing estimate and payment functionality.
3.6 Payment and Subscription Information
ApexCM uses Stripe for subscription billing and certain payment-related functionality.
Depending on the transaction, ApexCM may process or store:
- billing email;
- Stripe customer ID;
- Stripe subscription ID;
- Stripe Checkout session identifiers;
- Stripe payment-related identifiers;
- subscription plan;
- subscription status;
- billing interval;
- billing-period information;
- masked payment-card information made available by Stripe, such as card brand, last four digits, and expiration date;
- invoice and billing-history information; and
- transaction status.
ApexCM does not store raw payment-card numbers or card security codes (CVC/CVV) in its application database. Raw card information is handled by Stripe.
Stripe's processing of personal information is also governed by Stripe's own privacy documentation and contractual terms.
3.7 Expense and Receipt Information
When users use ApexCM's receipt and expense functionality, we may process:
- receipt images;
- vendor names;
- merchant information;
- item descriptions;
- amounts;
- dates;
- expense categories;
- barcodes;
- purchase-order information;
- job numbers;
- expense notes; and
- categorization results.
Receipt images and related information may be stored through Base44-managed file storage.
3.8 Documents, Images and Files
Users may upload documents or images to ApexCM, including:
- project documents;
- receipt images;
- estimate scope documents;
- floor-plan drawings;
- architectural drawings;
- check images;
- proof-of-payment images;
- logos;
- PDFs; and
- other documents necessary to use the Services.
Users should avoid uploading unnecessary sensitive personal information.
The current implementation uses Base44 file-storage functionality, and the audit indicates that certain uploaded files may be accessible through URL-based storage. Users should therefore avoid sharing file URLs with unauthorized persons.
3.9 Workforce and Team Information
Businesses using workforce functionality may provide information concerning employees, team members, workers, subcontractors, or other personnel, including:
- names;
- email addresses;
- telephone numbers;
- roles;
- hourly rates;
- pay type;
- tax-form type;
- timesheet information;
- hours worked;
- project labor information;
- workspace membership; and
- related workforce information.
Customers are responsible for ensuring that they are authorized to provide workforce information to ApexCM and to use such information through the Services.
3.10 Signatures, Approvals and Acknowledgments
Certain ApexCM workflows may record:
- typed signatures;
- approval decisions;
- terms acceptance;
- date and time of acceptance;
- approved terms snapshots;
- acknowledgment records;
- IP addresses;
- device information; and
- related activity information.
These records may be maintained to document a transaction, approval, authorization, or other business activity.
3.11 Device, Browser, IP and Technical Information
ApexCM may process technical information such as:
- IP address;
- user agent;
- browser information;
- device information;
- server-request information;
- authentication information;
- activity records; and
- diagnostic or security logs.
Certain public portal approval processes specifically record IP and device information for audit and acknowledgment purposes.
3.12 Communications
If you communicate through or with ApexCM, we may process:
- email addresses;
- telephone numbers;
- email content;
- SMS content;
- estimate links;
- support requests;
- customer communications;
- attachments; and
- related communication records.
ApexCM currently uses third-party providers for certain email and SMS functionality.
3.13 Information Received Through Integrations
Where enabled by an ApexCM customer, information may be exchanged with connected third-party services, including accounting systems or other owner-configured integrations.
The information exchanged depends on the integration and may include project, worker, timesheet, user, membership, and other operational information.
4. HOW WE COLLECT INFORMATION
We may obtain information:
Directly from you, such as when you register, create a workspace, configure your business profile, subscribe, upload a document, contact us, or use ApexCM.
From an ApexCM customer, such as when a contractor enters information about a customer, employee, worker, subcontractor, or vendor.
Automatically through use of the Services, such as certain device, browser, IP, authentication, activity, or diagnostic information.
From service providers, such as Stripe providing subscription and payment-status information.
From integrations, where a customer authorizes or configures information exchange with another service.
From public portal activity, such as when a customer reviews or approves an estimate, responds to a change order, or interacts with a payment request.
5. HOW WE USE INFORMATION
Subject to applicable law, ApexCM may use information to:
- provide and operate the Services;
- create and administer accounts;
- authenticate users;
- maintain workspaces;
- manage roles and permissions;
- provide project-management functionality;
- create estimates and proposals;
- generate invoices and payment requests;
- process subscription transactions;
- maintain subscription entitlements;
- manage billing history;
- facilitate customer payments;
- manage expenses and receipts;
- perform receipt categorization;
- analyze floor plans where requested;
- provide AI-assisted functionality;
- create and manage contracts and change orders;
- support customer portals;
- send transactional emails;
- send SMS notifications where enabled;
- manage workers and timesheets;
- produce reports and analytics;
- generate PDFs and other documents;
- synchronize information with customer-authorized integrations;
- respond to customer-support inquiries;
- prevent abuse and unauthorized activity;
- enforce account permissions;
- maintain audit records;
- diagnose technical issues;
- maintain and improve functionality;
- administer subscriptions;
- comply with applicable laws and lawful requests;
- establish, exercise, or defend legal claims;
- enforce agreements and policies; and
- protect ApexCM, our customers, users, and others.
6. ARTIFICIAL INTELLIGENCE AND AUTOMATED PROCESSING
ApexCM includes or may make available artificial-intelligence-assisted functionality.
6.1 Receipt Categorization
Receipt categorization currently uses Base44's InvokeLLM functionality. Information such as vendor names, item descriptions, amounts, and workspace category names may be submitted for categorization.
According to the current system implementation reviewed for this Policy, receipt categorization sends extracted/textual receipt information rather than the receipt image itself.
ApexCM may retain categorization history, including suggested categories, final categories, confidence information, and corrections, to support the functionality.
6.2 Floor-Plan Analysis
ApexCM's floor-plan analysis functionality may transmit uploaded architectural or construction drawing images, together with user-provided notes or prompts, through Base44's AI functionality to an AI model provided by Anthropic.
The resulting analysis may include information such as:
- room information;
- takeoff information;
- scope information;
- cost summaries; and
- construction-analysis results.
The current implementation identifies Anthropic Claude as the AI model used for floor-plan analysis.
6.3 AI-Generated Information Is Not Guaranteed
Artificial-intelligence systems may generate incomplete, inaccurate, outdated, misleading, or otherwise incorrect results.
Users should independently review and verify AI-generated:
- estimates;
- quantities;
- measurements;
- takeoffs;
- categories;
- line items;
- recommendations;
- cost calculations;
- project information; and
- other generated output
before relying upon such information for business, contractual, financial, safety, engineering, architectural, legal, tax, or construction decisions.
ApexCM's AI functionality is intended to assist users and is not a substitute for qualified professional judgment.
6.4 AI Retention
The current application audit did not identify an application-level AI retention period. Retention by underlying AI or infrastructure providers may be governed by their respective contractual terms and privacy practices.
We will not represent that AI providers immediately delete submitted information unless that practice has been independently confirmed.
7. HOW WE DISCLOSE INFORMATION
We may disclose information as reasonably necessary to operate ApexCM and for the purposes described in this Policy.
7.1 Base44
ApexCM is built using Base44 infrastructure and services. Base44 may process application data in connection with:
- hosting;
- databases;
- authentication;
- server-side functions;
- file storage;
- application infrastructure;
- AI/LLM gateway functionality; and
- other platform functionality.
Base44 is therefore a core infrastructure provider for ApexCM.
7.2 Stripe
We disclose information to Stripe as necessary for:
- subscription billing;
- Checkout;
- payment processing;
- payment-method management;
- billing history;
- invoices;
- certain one-time purchases;
- connected payment functionality where enabled; and
- fraud prevention and payment security.
Stripe directly processes card information submitted through Stripe-hosted payment interfaces.
7.3 Email Providers
ApexCM uses Resend and/or Base44 email functionality for transactional communications.
Information disclosed for email delivery may include:
- recipient email address;
- sender information;
- reply-to information;
- subject lines;
- email body;
- customer information included in the communication; and
- attachments such as estimates, PDFs, or scope documents.
7.4 Twilio
Where SMS functionality is enabled, ApexCM may use Twilio to send transactional text messages.
Information provided to Twilio may include:
- telephone numbers;
- message content; and
- links associated with estimates or other communications.
7.5 Anthropic and AI Providers
Where AI functionality is used, relevant information may be transmitted through Base44's AI infrastructure to underlying AI providers.
For floor-plan analysis, this may include architectural drawing images and related prompts sent for processing by Anthropic's Claude model.
7.6 Google Services
ApexCM may use Google Places functionality for address autocomplete. Address search information may therefore be processed by Google or an associated provider.
Other Google-based AI/web-context functionality may be available through Base44 where specifically used.
7.7 Customer-Configured Accounting Integrations
Where an ApexCM customer enables an accounting or external webhook integration, ApexCM may transmit information to the destination configured by that customer.
The customer is responsible for its selection, configuration, authorization, and use of such external integrations.
7.8 Other Users Within Your Organization
Information may be accessible to authorized members of your workspace according to their roles and permissions.
Workspace owners and administrators may have broader access than other users.
7.9 Customer and Vendor Portals
Certain information may be made available through tokenized links for purposes such as:
- estimate review;
- estimate approval;
- payment requests;
- change-order approval;
- clarification responses;
- vendor interactions; and
- subcontractor interactions.
The system audit indicates that certain customer portal tokens expire, including 30-day expiration periods for specified estimate/payment tokens.
Recipients are responsible for protecting portal links against unauthorized access.
7.10 Legal and Safety Disclosures
We may disclose information if we reasonably believe disclosure is necessary to:
- comply with applicable law;
- comply with a court order, subpoena, warrant, or lawful governmental request;
- protect the rights, property, or safety of ApexCM, our users, customers, or others;
- investigate suspected fraud, security incidents, or abuse;
- enforce agreements;
- establish or defend legal claims; or
- prevent potentially unlawful activity.
Where permitted and appropriate, we may challenge requests that we believe are unlawful or overly broad.
7.11 Corporate Transactions
If ApexCM is involved in a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, reorganization, or similar corporate transaction, information may be disclosed to relevant parties as part of that transaction, subject to applicable law.
8. WE DO NOT SELL PERSONAL INFORMATION FOR MONEY
ApexCM's reviewed implementation does not contain advertising pixels or advertising SDKs such as Facebook Pixel, Google Analytics, Mixpanel, Segment, or AdSense.
Based on the current operation of the Services, ApexCM does not sell personal information to third parties for monetary consideration.
If our practices materially change, we will update this Privacy Policy and provide any notices or choices required by applicable law.
This statement should not be interpreted more broadly than applicable privacy law defines the terms “sell,” “share,” “targeted advertising,” or similar concepts.
9. COOKIES, LOCAL STORAGE AND SIMILAR TECHNOLOGIES
The ApexCM application may use browser storage and technologies necessary for authentication, application functionality, preferences, security, and payment processing.
The reviewed application uses local storage for certain application preferences and technical functions, including theme/accent preferences, build/cache information, and native-app detection.
The application audit did not identify an ApexCM advertising pixel or dedicated advertising tracker.
Base44 may use platform-managed authentication/session technologies, and Stripe may use cookies and similar technologies when users interact with Stripe-hosted payment functionality.
Where required by applicable law, ApexCM may provide additional cookie notices or consent mechanisms.
10. DATA SECURITY
ApexCM uses technical and organizational functionality intended to help protect information and restrict unauthorized access.
The current system includes:
- workspace-level access controls;
- row-level security;
- user roles and permissions;
- backend authentication checks;
- service-role restrictions for system operations;
- audit logs;
- API security controls;
- input sanitization in identified functionality;
- backup/restore functionality; and
- security-management functionality.
The platform includes roles such as owner, administrator, manager, supervisor, employee, and project member.
However, no method of electronic transmission, cloud storage, authentication, or information-security system can be guaranteed to be completely secure.
Accordingly, ApexCM cannot guarantee that unauthorized persons will never defeat security measures or gain access to information.
Users are responsible for:
- maintaining the confidentiality of their account credentials;
- using strong and unique passwords;
- limiting access to authorized personnel;
- appropriately configuring roles and permissions;
- securing devices used to access ApexCM;
- promptly notifying ApexCM of suspected unauthorized access; and
- protecting public/tokenized links shared with customers or third parties.
ApexCM will not claim specific certifications, encryption-at-rest standards, or infrastructure guarantees unless those representations have been verified with the applicable infrastructure provider. The system audit specifically identifies Base44 infrastructure encryption and hosting details as matters requiring provider confirmation.
11. DATA RETENTION
We retain information for as long as reasonably necessary to:
- provide the Services;
- maintain an active account;
- perform requested business functions;
- comply with contractual obligations;
- maintain appropriate business and transaction records;
- resolve disputes;
- prevent fraud or abuse;
- enforce agreements;
- satisfy applicable legal, accounting, tax, or regulatory obligations; and
- establish, exercise, or defend legal claims.
The current ApexCM implementation does not establish a universal automatic time-based deletion period for all categories of information.
Subscription cancellation does not automatically delete customer data. Data may remain associated with the account after cancellation unless it is deleted through available account/data deletion functionality or otherwise removed in accordance with our practices and applicable law.
Certain information may remain for longer periods where necessary for legitimate business or legal purposes.
Information may also persist temporarily in backups, logs, archives, third-party systems, or other technical systems after deletion from active application records.
Third parties such as Stripe may independently retain transaction and customer records according to their legal obligations and privacy policies.
12. ACCOUNT AND DATA DELETION
ApexCM currently provides account-deletion functionality.
The implementation distinguishes between workspace owners and members. Owner deletion may delete owned workspace data, while member deletion may remove personal records and anonymize certain references where information must remain within a shared workspace.
Deletion may not immediately or automatically remove:
- information that another ApexCM customer independently controls;
- legally required records;
- transaction information retained by Stripe or another payment processor;
- records necessary to prevent fraud or enforce agreements;
- information contained in backups;
- information already transmitted to third parties at the user's direction;
- information retained by third-party processors under their independent obligations; or
- de-identified or anonymized information that can no longer reasonably identify an individual.
Where applicable law provides additional deletion rights, users may contact us using the method specified below.
13. SUBSCRIPTION CANCELLATION IS DIFFERENT FROM DATA DELETION
Canceling a paid ApexCM subscription does not automatically constitute a request to delete an account or its data.
The current system is designed to preserve account data following subscription cancellation while paid functionality may become restricted after the applicable subscription period ends.
Users who wish to delete their data should use the available account-deletion functionality or submit a privacy request, as applicable.
14. DATA ACCURACY
Users are responsible for maintaining accurate information in ApexCM, particularly information concerning:
- customers;
- projects;
- employees;
- workers;
- estimates;
- invoices;
- payment records;
- tax information;
- construction information;
- addresses; and
- uploaded documentation.
ApexCM may rely on information supplied by users and is not responsible for independently verifying every piece of information entered into the Services.
15. PRIVACY RIGHTS
Depending on where you reside and the laws applicable to your information, you may have certain privacy rights.
These may include the right to request:
- confirmation of whether we process your personal information;
- access to personal information;
- correction of inaccurate information;
- deletion of personal information;
- a copy of certain information;
- restriction of certain processing;
- withdrawal of consent where processing is based on consent;
- objection to certain processing;
- portability of certain information; and
- information about categories of information collected and disclosed.
Not every right applies in every jurisdiction or circumstance.
We may need to verify your identity before fulfilling a request. We may also request information reasonably necessary to verify that you are authorized to make a request on behalf of another individual.
We may deny or limit a request where permitted by law, including where an exception applies.
16. INFORMATION CONTROLLED BY AN APEXCM CUSTOMER
If you are a customer, employee, subcontractor, worker, or other individual whose information was entered into ApexCM by a construction company or contractor, that business may control your information.
In those circumstances, you should generally submit your privacy request directly to the business that collected your information.
If we receive a request concerning information controlled by an ApexCM customer, we may refer the request to that customer or assist the customer where required by applicable law.
17. U.S. STATE PRIVACY RIGHTS
Residents of certain U.S. states may have additional rights under applicable comprehensive privacy laws.
Depending on applicable law and whether statutory thresholds are met, these rights may include:
- right to know/access;
- right to correct;
- right to delete;
- right to obtain a portable copy;
- right to opt out of certain sales, sharing, targeted advertising, or profiling;
- right to appeal certain privacy-request decisions; and
- right not to receive unlawful discriminatory treatment for exercising privacy rights.
ApexCM will process valid requests according to applicable law.
Because privacy laws and applicability thresholds vary by state and may change over time, the availability of a particular right depends on the circumstances.
18. VIRGINIA PRIVACY RIGHTS
Because ApexCM LLC operates in Virginia, Virginia residents may have rights under the Virginia Consumer Data Protection Act where that law applies to ApexCM and the particular processing activity.
Applicable rights may include requests to:
- confirm whether personal data is being processed;
- access personal data;
- correct inaccuracies;
- delete qualifying personal data;
- obtain a portable copy of qualifying personal data; and
- opt out of certain processing involving targeted advertising, sale of personal data, or qualifying profiling.
Rights under Virginia law are subject to statutory definitions, thresholds, exceptions, and limitations.
If a request is denied and applicable law provides an appeal right, the requester may submit an appeal through the privacy contact method identified below.
19. CALIFORNIA PRIVACY NOTICE
If California privacy law applies to ApexCM and a particular individual or processing activity, California residents may have additional rights concerning their personal information.
Depending on applicability, those rights may include:
- knowing categories and specific pieces of personal information collected;
- knowing categories of sources;
- knowing purposes for collection/use;
- knowing categories of third parties receiving information;
- requesting deletion;
- requesting correction;
- obtaining information concerning sale or sharing;
- opting out of qualifying sale or sharing;
- limiting certain uses of sensitive personal information where applicable; and
- protection against unlawful discrimination for exercising privacy rights.
The reviewed ApexCM implementation does not contain advertising trackers and ApexCM does not currently sell personal information for monetary consideration.
Whether a particular disclosure constitutes “sharing” or “sale” under California law depends on the statutory definitions and circumstances.
20. INTERNATIONAL USERS
ApexCM is currently primarily U.S.-oriented, including U.S.-dollar pricing, but the application does not currently contain an explicit technical geographic restriction.
If you access ApexCM from outside the United States, your information may be processed in jurisdictions different from your country of residence, including through service providers used to operate the Services.
Privacy and data-protection laws in those jurisdictions may differ from those in your home country.
Where legally required, ApexCM will use appropriate mechanisms for international transfers.
ApexCM does not currently make a specific representation in this Policy concerning the precise Base44 data-center location because that infrastructure-level fact has not yet been verified.
21. CHILDREN'S PRIVACY
ApexCM is a business-oriented construction management service and is not designed or intended for children.
Before publication, ApexCM should insert and legally confirm its minimum permitted user age here: [MINIMUM AGE].
We do not knowingly intend to collect personal information directly from children through independent ApexCM accounts.
If we learn that information was collected from a child in circumstances prohibited by applicable law, we will take appropriate steps to address the information, which may include deletion.
ApexCM business customers are responsible for ensuring that any information they submit concerning minors is collected and processed lawfully and only where necessary.
22. EMAIL AND SMS COMMUNICATIONS
ApexCM may send transactional communications necessary to operate the Services, including:
- account communications;
- estimate notifications;
- invoice/payment communications;
- approval notifications;
- clarification requests;
- project-related communications;
- security notices;
- subscription/billing communications; and
- other service-related notices.
Where SMS functionality is enabled, messages may be delivered through Twilio.
Transactional communications may be necessary for the operation of requested Services and may not always be subject to marketing opt-out mechanisms.
If ApexCM introduces marketing email or SMS campaigns, it will provide legally required consent and opt-out mechanisms where applicable.
23. CUSTOMER PORTAL SECURITY
Certain ApexCM functionality permits recipients to access information through tokenized links without creating a full ApexCM account.
These links may be used for:
- estimates;
- approvals;
- payment requests;
- change orders;
- clarification workflows;
- vendor functions; and
- subcontractor functions.
Users should treat such links as confidential.
Anyone who obtains a valid portal link may potentially be able to access information available through that link until the link expires, is revoked, or otherwise becomes invalid.
ApexCM customers are responsible for sending portal links only to intended recipients and for notifying ApexCM if they believe a link has been compromised.
24. THIRD-PARTY LINKS AND SERVICES
The Services may contain links to or integrations with third-party websites, applications, payment processors, or services.
ApexCM does not control the independent privacy practices of third parties.
When you leave ApexCM or intentionally interact with a third-party service, the third party's privacy policy and terms may apply.
Users should review third-party privacy policies before providing information directly to those providers.
25. BUSINESS CUSTOMER RESPONSIBILITIES
Businesses using ApexCM are responsible for their own privacy and data-protection obligations.
Without limiting any contractual requirements, ApexCM customers are responsible for:
- providing required privacy notices to their customers and personnel;
- obtaining necessary permissions and consents;
- having a lawful basis to process information;
- entering information into ApexCM only when authorized;
- configuring user permissions appropriately;
- protecting login credentials;
- protecting portal links;
- ensuring uploaded information is appropriate and lawful;
- complying with employment and workforce privacy laws;
- complying with communications and SMS laws;
- determining whether AI processing is appropriate for information they submit;
- complying with applicable record-retention obligations; and
- responding to privacy requests where they act as the responsible controller/business.
26. SENSITIVE AND HIGH-RISK INFORMATION
Unless a particular ApexCM feature expressly requires it, users should not upload or enter unnecessary highly sensitive information.
Users should exercise particular caution with information such as:
- Social Security numbers;
- government identification numbers;
- passwords belonging to third-party services;
- complete payment-card numbers;
- card security codes;
- bank login credentials;
- protected medical information;
- biometric information;
- highly sensitive employee records; or
- other information unnecessary for construction-management purposes.
The availability of a text field, document upload, or other feature does not mean ApexCM requests or requires users to upload sensitive information.
27. LEGAL COMPLIANCE AND GOVERNMENT REQUESTS
ApexCM may preserve, access, or disclose information where reasonably necessary to comply with applicable legal obligations or valid legal process.
Where legally permitted, ApexCM may evaluate governmental or third-party requests for information and may reject, narrow, or challenge requests that appear invalid, unlawful, or overly broad.
We may preserve information in response to a valid legal preservation request even if the information would otherwise have been deleted under ordinary practices.
28. DATA BREACHES AND SECURITY INCIDENTS
If ApexCM becomes aware of a security incident involving personal information, we may investigate, mitigate, remediate, and provide legally required notices to affected individuals, customers, regulators, or other parties.
The timing and content of any notification will depend on applicable law and the circumstances of the incident.
Nothing in this Privacy Policy constitutes a guarantee that a security incident will never occur.
29. DE-IDENTIFIED AND AGGREGATED INFORMATION
Where permitted by law, ApexCM may create or use aggregated, statistical, or de-identified information that does not reasonably identify an individual.
We may use such information for purposes such as:
- improving the Services;
- understanding product usage;
- capacity planning;
- troubleshooting;
- security;
- product development; and
- business analysis.
Where information is treated as legally de-identified data, ApexCM will not intentionally attempt to re-identify it except where permitted by law for purposes such as evaluating whether de-identification processes are effective.
30. CHANGES TO OUR BUSINESS
If ApexCM undergoes a merger, acquisition, financing, reorganization, sale, bankruptcy, transfer of assets, or similar transaction, personal information may be transferred or disclosed as part of that transaction.
Any successor may continue processing information subject to this Privacy Policy unless users are provided with a different notice as required by law.
31. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy periodically to reflect:
- changes to ApexCM;
- new functionality;
- new integrations;
- changes to service providers;
- changes in our data practices;
- security developments;
- regulatory requirements; or
- changes in applicable law.
When we update this Privacy Policy, we will update the “Last Updated” date.
Where required by applicable law, we may provide additional notice of material changes or request consent before applying certain changes.
Users are encouraged to periodically review the current Privacy Policy.
32. CONTACTING APEXCM ABOUT PRIVACY
Questions, requests, or concerns regarding this Privacy Policy or ApexCM's privacy practices may be directed to:
ApexCM LLC
ApexCM (Apex Construction Management)
Website: apexcm.pro
Privacy Email: [INSERT PRIVACY EMAIL BEFORE PUBLICATION]
Mailing Address: [INSERT BUSINESS/PRIVACY MAILING ADDRESS BEFORE PUBLICATION]
For security reasons, please do not include passwords, complete payment-card numbers, or other unnecessary highly sensitive information in privacy requests.
We may request additional information to verify your identity before responding to certain requests.
33. PRIVACY REQUESTS AND AUTHORIZED AGENTS
Where applicable law permits an authorized agent to submit a privacy request on your behalf, we may require:
- evidence of the agent's authority;
- verification of your identity;
- confirmation directly from you; or
- other information permitted by law.
We may decline requests where we cannot reasonably verify the requester's identity or authority.
34. RESPONSE TO PRIVACY REQUESTS
ApexCM will endeavor to respond to verified privacy requests within the period required by applicable law.
We may extend the response period where permitted by law and will provide notice where legally required.
Some information may be exempt from access, deletion, correction, or other requests, including information that must be maintained for:
- security;
- fraud prevention;
- legal compliance;
- tax/accounting purposes;
- transaction records;
- dispute resolution;
- exercising or defending legal claims; or
- protecting the rights of another individual.
35. PRIVACY POLICY DOES NOT MODIFY CONTRACTUAL OBLIGATIONS
This Privacy Policy describes ApexCM's privacy practices. It does not independently create contractual rights beyond those required by applicable law and does not replace ApexCM's Terms of Service, Data Processing Agreement, subscription terms, or other agreements that may govern a customer's use of the Services.
Where a separate written agreement governs processing of particular information, that agreement may contain additional terms.
36. CONTACT FOR CUSTOMER-CONTROLLED INFORMATION
If ApexCM processes your information solely on behalf of an ApexCM business customer, the applicable business customer may be responsible for responding to your privacy request.
You may contact that business directly.
ApexCM may assist its business customers with appropriate requests as required by applicable law and applicable contractual obligations.
37. EFFECTIVE DATE
This Privacy Policy is effective as of September 5, 2026 and remains effective until replaced or updated.
