APAS Ltd. (“we,” “our,” or “us”) operates APAS® Cloud, a HIPAA-compliant 360° marketing intelligence platform for full-funnel attribution, data activation, and marketing performance optimization. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services. By using the Platform, you also agree to our Terms of Service.
1. What we process, why, and on what legal basis
Each purpose has its own legal basis, and none of them is inferred from your mere use of this website:
- Website analytics — a first-party analytics cookie, a first-party browser identifier (with its backup cookie), the pages you view, and where you arrived from. Purpose: understanding how visitors use our website so we can improve it. Legal basis: your consent, given through the consent banner and withdrawable at any time.
- Advertising measurement — a click identifier, a colour-coded conversion stage, a conversion value where configured, and — where it applies — an irreversible cryptographic hash of contact details you provided. Purpose: measuring which of our adverts work. Legal basis: your consent, given through the consent banner and the consent checkbox on our forms; if you do not consent, nothing is shared with any advertising platform.
- Ad click verification — technical details of a click on one of our advertisements, including IP address, browser user-agent, approximate location, and a click identifier. Purpose: detecting bots, click fraud, and threats to the security of our services. Legal basis: our legitimate interests; the GDPR expressly recognises fraud prevention and network security as legitimate interests. You have the right to object — see the Your Rights section.
- Enquiries you send us — your name, contact details, and anything you write in a form, booking, or demo request. Purpose: responding to you and providing the service you asked for. Legal basis: performance of a contract, or steps taken at your request before entering into one.
- Legal compliance — where we must process or retain information to comply with legal and financial regulatory obligations to which we are subject.
2. Information we collect
2.1 Information you provide
We collect information you voluntarily provide when you:
- Request a demo or consultation
- Subscribe to our newsletter
- Contact us via email or forms
- Create an account or use our services
- Submit a form, schedule an appointment, or interact with a chatbot powered by the Platform
This may include: name, email address, company name, phone number, and any other information you choose to provide.
2.2 Automatically collected information
When you visit our website — and only in accordance with the choice you make in the consent banner — we collect certain information about your device and browsing actions:
- Pages viewed, time spent on pages, and how you navigate
- Referral source and click data
- Browser type, version, and device information
- Coarse derived location (city level), computed at ingest
- APAS® ID and APAS® Click ID attribution identifiers (apasid, apasclid)
Our website analytics does not store your IP address — it is discarded at ingest, keeping only the coarse derived geography above. The only place an IP address is retained is the ad click verification described in section 6, and those records are deleted automatically after approximately 91 days.
3. How we use your information
We use the information we collect to:
- Provide, operate, and maintain our services
- Process your requests and communications
- Send you technical notices and updates
- Respond to your comments and questions
- Analyze usage trends and improve our services
- Measure advertising effectiveness through de-identified conversion reporting
- Detect, prevent, and address bot activity, click fraud, and technical issues
- Comply with legal obligations
4. Attribution tracking
APAS® Cloud uses attribution tracking to understand visitor behavior and conversion touchpoints across digital channels. We:
- Generate unique identifiers — the APAS® ID (apasid) and APAS® Click ID (apasclid) — stored in your browser's local storage with backup cookies, only after you consent via the banner
- Capture URL parameters including UTM codes and click IDs from advertising platforms
- Track visitor sessions, form submissions, phone calls, and appointment bookings
- Store attribution data for analysis and reporting
This data helps us measure marketing effectiveness and optimize conversion paths. Attribution identifiers remain on your device and are never shared with third parties in a way that could identify you.
5. Tracking & cookies data
We use privacy-friendly technology to understand how visitors use our website and improve their experience finding what they need. We use a small set of first-party cookies and browser-storage keys: an analytics cookie, a browser identifier used exclusively within our own systems for marketing attribution (with a backup cookie), a click identifier captured from ad-click URLs that is scoped to individual clicks rather than to visitors (with a backup cookie), and the keys that remember the choices you make on this site. Every one of them is listed item by item — with its purpose and lifetime — in our consent banner's “What this stores” disclosure. All of these stay on our domain. None follow users to other websites, and none are shared with third-party trackers or advertising networks. Our website analytics tool is configured to create user profiles only when a visitor identifies themselves, for example by submitting a form or booking — anonymous visitors have no persistent profile on our analytics platform. We also monitor website traffic to detect and block malicious bot activity and unauthorized access attempts, helping keep our infrastructure and your data secure.
Our website analytics do not collect any personal information, preferences, or interests through browsing activity. The only data gathered includes general usage patterns such as where users came from, pages visited, time spent on site, and how they navigate our services. We do not store your IP address for analytics — it is discarded at ingest, keeping only coarse derived geography — and our network-level visit capture stores no IP for organic visits. This helps us make our website easier to use and ensures important information is easy to find.
User privacy is paramount — we do not sell, share, or transfer any personally identifiable visitor information to third parties, advertising networks, or data brokers. Where de-identified advertising measurement is used, only de-identified conversion codes and a click identifier — and, where applicable, irreversible cryptographic hashes that cannot be reversed to identify you — are shared. We never share plain-text names, emails, phone numbers, or any information that could identify you.
6. Ad click verification
When you arrive from one of our advertisements, that click is checked for automated and fraudulent traffic before our website loads. This check records technical details of the request — the IP address it came from, the browser user-agent, general location, and a click identifier — so that we can detect bots and click fraud, protect our advertising budget, and keep our services secure. It is not used to build a profile of you or to infer anything about your interests, and these records are automatically deleted after approximately 91 days. Because this check happens before our website loads, it happens before any consent banner can be shown; nothing is stored on or read from your device at this stage. Anything later stored on your device — analytics identifiers or cookies — happens on our website itself, and only in accordance with the choice you make there. Where privacy law requires a legal basis for this check, we rely on our legitimate interest in preventing fraud and securing our services.
7. Global Privacy Control (GPC)
We respect the Global Privacy Control (GPC) signal. If your browser sends a GPC signal, our website will automatically detect it and disable all attribution and analytics data collection. No identifiers will be created, no cookies will be set, and no analytics scripts will load. You can enable GPC in your browser's privacy settings or by using a browser that supports it by default, such as Brave or DuckDuckGo.
8. Advertising measurement
We measure the effectiveness of our advertising by reporting de-identified conversion events to advertising platforms. When users arrive at our website from an advertisement and later take an action (such as submitting a form, making a call, or booking an appointment), we may notify the advertising platform using a color-coded system (red, orange, yellow, white, green) that represents general conversion stages — never revealing who our users are or what specific products or services they're interested in. These color codes are universal across all industries and cannot be used to identify any specific product, service, or personal information. This de-identified reporting uses only a random click identifier, a color code, a conversion value where configured, and — where applicable — an irreversible cryptographic hash. It simply helps us understand which channels are effective at helping people find the services they need, allowing us to focus our resources on the most helpful advertising channels.
9. Your choice
When you first visit our website, a consent banner will ask you to choose, purpose by purpose — analytics, and advertising measurement — with nothing pre-ticked and declining as easy as accepting. Each purpose lists exactly what it stores in your browser, and for how long. If you decline everything, no identifiers will be created, no cookies will be set, and no analytics data will be collected. If you accept, your choices apply for your session and future visits.
You can change or withdraw your choices at any time: once you have made a choice, a floating “Cookie preferences” button appears on this site and reopens your preferences, pre-filled with your current choices. The same panel opens from any Cookie preferences link. Withdrawing is as easy as consenting was, and you can also withdraw entirely by requesting deletion of your data below.
Additionally, our forms and scheduling tools include a consent checkbox that allows you to decline data sharing with advertising platforms before submitting your information. If you opt out, no data — not even de-identified conversion events — will be sent to any advertising platform. We encourage you to consent, as it helps others find and benefit from the services we offer.
If you would like to request deletion of any data associated with your browsing activity, click this link: DELETE MY DATA. It works immediately and automatically: the identifiers and cookies stored in your browser are removed on the spot, and the analytics records tied to them are erased from our systems within a few hours — no account and no explanation needed. Alternatively, you can contact us at [email protected].
10. Do Not Sell or Share
We do not sell your personal information. If you live in a US state with a comprehensive consumer privacy law and want to opt out of any sharing with advertising platforms regardless of how “sharing” is interpreted, use this link — no account, no login, no explanation needed: Do Not Sell or Share My Personal Information. It applies immediately, applies going forward, and does not expire. It stops information associated with your browser being shared with advertising platforms; it does not delete anything and does not affect your use of this site. If your browser sends a GPC signal, we treat it as this opt-out automatically and you do not need to use the link.
11. Data sharing and disclosure
We share personal information only with providers who help us run this website and our services, and only for that purpose:
- Advertising platforms — de-identified conversion events only, as described in section 8, subject to your consent
- Cloud hosting and infrastructure providers — where this website and its data are run
- Analytics providers — to understand how the site is used, under the consent described above
- Email delivery providers — to send you messages you asked for
- Telephone and messaging providers — where you call or text us
- Legal requirements — when required by law or to protect our rights
- Business transfers — in connection with a merger, sale, or acquisition
Where HIPAA applies to the data being processed, the providers involved operate under signed Business Associate Agreements (BAAs). We do not sell your information to data brokers, and we do not share it with anyone for their own independent marketing. A current list naming the specific providers is available on request.
12. Data security
We implement appropriate technical and organizational security measures to protect your personal information, including:
- Enterprise-grade infrastructure with BAA-covered partners where HIPAA applies
- Continuous HIPAA compliance auditing through our partnership with Compliancy Group, the leading HIPAA compliance auditing platform in the United States
- Advanced bot detection and click fraud prevention
- All data processing on HIPAA-compliant US-based servers
- SHA-256 cryptographic hashing for any identifiers shared with advertising platforms
However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
13. Data retention
Retention follows the purpose of each category:
- Ad click verification records — deleted automatically after approximately 91 days
- Analytics data — retained only while your consent stands, and deleted on request: cleared from your browser at once and erased from our systems within a few hours
- Enquiries and communications — kept for as long as needed to respond to you and to meet our legal and record-keeping obligations
Where a longer retention period is required or permitted by law, we keep only what that obligation covers. Visitors may request deletion of their data at any time through the DELETE MY DATA mechanism or by contacting us directly.
14. Your rights
Depending on your location, you may have certain rights regarding your personal information, including:
- Receive confirmation as to whether or not personal information concerning you is being processed, and access your stored personal information
- Receive a copy of personal information you directly volunteer to us in a structured, commonly used, and machine-readable format
- Request rectification of your personal information that is in our control
- Request erasure of your personal information — for browsing and analytics data, the DELETE MY DATA link above works immediately
- Object to processing carried out on the basis of legitimate interests, including the ad click verification described in section 6
- Request to restrict processing of your personal information by us
- Withdraw consent at any time, as easily as you gave it — via the floating “Cookie preferences” button, any Cookie preferences link on this site, or the DELETE MY DATA link
- Opt out of data sharing with advertising platforms via the consent checkboxes on forms, or the Do Not Sell or Share link
- Use the Global Privacy Control (GPC) signal to disable all analytics and attribution
- Lodge a complaint with a data protection supervisory authority — in Cyprus, the Office of the Commissioner for Personal Data Protection (dataprotection.gov.cy), or the authority in the country where you live or work
Some of these rights have legal limits — where one applies, we will tell you what part of a request we must decline and why.
To exercise these rights, please contact our Data Protection Officer using the details in the Contact section below.
15. International data transfers
APAS Ltd. is established in Cyprus, in the European Union, and personal data collected through this website is processed on servers in the United States. Where our providers are certified under the EU–US Data Privacy Framework, transfers rely on the European Commission's adequacy decision of 10 July 2023. Where they are not, we rely on the European Commission's Standard Contractual Clauses together with an assessment of the protections available in the destination country. You can request a copy of the safeguards we rely on by contacting us.
16. Children's privacy
We understand the importance of protecting children's privacy, especially in an online environment. Our services are not designed for or directed at children. Under no circumstances shall we allow use of our services by minors. We do not knowingly collect personal information from minors. If a parent or guardian becomes aware that their child has provided us with personal information without consent, please contact us immediately.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Effective Date” at the top.
18. Contact us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact our Data Protection Officer:
- Privacy Officer: Lesley Van De Mortel
- Email: [email protected]
- Phone: +357 943 27221
- Address: APAS Ltd., Onisiforou Center, 2nd floor, Agios Theodoros, 8011 Paphos, Cyprus