1. Acceptance of terms
By accessing or using APAS® Cloud (“the Platform”), operated by APAS Ltd. (“we,” “our,” or “us”), you agree to be bound by these Terms of Service. If you do not agree to these terms, you must not use the Platform.
2. Description of service
APAS® Cloud is a HIPAA-compliant 360° marketing intelligence platform. The Platform provides infrastructure for full-funnel attribution, data activation, and marketing performance optimization across digital channels — including but not limited to website analytics, conversion tracking, form and call capture, appointment scheduling, AI-powered knowledge bases (RAG), offline conversion delivery to advertising platforms, advanced bot detection and click fraud prevention, data warehousing, and privacy compliance management.
The specific features, integrations, and tools available through the Platform may change over time. All features provided through the Platform are subject to these Terms.
3. Compliance tools provided by APAS® Cloud
APAS® Cloud provides a comprehensive suite of privacy and compliance tools designed to help clients meet their regulatory obligations. These tools are built into the Platform and available to all clients:
3.1 Consent management
- Form consent field: Forms, bookings, and quizzes created through the Platform support a data consent field that gives website visitors the choice to decline data sharing with third-party advertising platforms before submitting their information. Clients can enforce its presence on every such surface, and its default state follows the account's consent model — pre-checked under the opt-out model, unchecked under the opt-in model, and never marked required, since consent must be freely given. If a visitor declines, no data — not even de-identified conversion events — will be sent to any advertising platform.
- Opt-out / Opt-in modes: The Platform supports both opt-out (default) and opt-in consent models. In opt-out mode, analytics load immediately while respecting the Global Privacy Control (GPC) signal. In opt-in mode, no identifiers are created, no cookies are set, and no analytics data is collected until the visitor explicitly accepts via a consent banner.
- Consent banner: A customizable consent banner is provided for clients operating in jurisdictions that require opt-in consent. It asks purpose by purpose with nothing pre-ticked and declining as prominent as accepting, discloses item by item what each purpose stores in the browser and for how long, and defers everything consent-gated until the visitor chooses. Every choice — including declines and withdrawals — is recorded as a versioned consent receipt capturing the purposes chosen, the wording seen, and the action taken. Withdrawal is built in: once a visitor has chosen, a floating “Cookie preferences” control reopens their preferences at any time.
- Global Privacy Control (GPC): The Platform automatically detects and honors the GPC signal. When a visitor's browser sends a GPC signal, all attribution and analytics data collection is disabled — no identifiers are created, no cookies are set, and no analytics scripts load.
3.2 Privacy policy and data deletion
- Privacy policy snippet: The Platform generates a ready-to-use privacy policy section that accurately describes analytics practices, advertising measurement, consent mechanisms, and visitor rights. This snippet automatically adapts based on whether opt-in or opt-out mode is selected.
- DELETE MY DATA: The Platform generates a one-click data deletion link that clients can embed in their privacy policy. When activated by a visitor, the identifiers and cookies in their browser are removed on the spot, and the analytics records tied to them are erased from our systems within the hour. A companion Do Not Sell or Share link records a durable advertising opt-out without deleting anything.
3.3 HIPAA-compliant data architecture
- Color-coded conversion events: Offline conversions sent to advertising platforms use an opaque color-coded system (red, orange, yellow, white, green) that represents general conversion stages. No Protected Health Information (PHI), personally identifiable information, or treatment details are ever shared with advertising platforms. These color codes are universal across all industries and cannot be used to infer any medical condition or personal information.
- Hashed data only: Where personal identifiers are used for advertising platform matching, only irreversible SHA-256 cryptographic hashes are transmitted. Plain-text names, emails, phone numbers, or any directly identifiable information are never sent to any advertising platform.
- Business Associate Agreements (BAAs): The Platform is built exclusively on enterprise-grade infrastructure. Where HIPAA applies to the data being processed, the infrastructure and service providers involved operate under signed BAAs; a current list naming the specific providers is available on request.
- US-based data processing: All client data is processed and stored exclusively on HIPAA-compliant servers located in the United States.
3.4 HIPAA compliance auditing
APAS® Cloud has partnered with Compliancy Group, the leading HIPAA compliance auditing platform in the United States, to ensure that all systems, processes, and infrastructure adhere to the latest HIPAA regulations. Our compliance posture is continuously audited and updated as regulatory requirements evolve.
3.5 In-platform warnings
The Platform provides explicit warnings when clients attempt to remove or disable compliance-related features. These warnings cite specific regulations (including Washington's My Health My Data Act and California's CCPA/CPRA), explain the consequences of removal, and recommend consulting legal counsel. All removal actions are logged for audit purposes.
4. Client responsibilities
While APAS® Cloud provides the compliance tools described in Section 3, you are solely responsible for ensuring that your use of the Platform complies with all applicable laws and regulations, including but not limited to:
- The Health Insurance Portability and Accountability Act (HIPAA)
- Washington's My Health My Data Act (MHMD Act)
- The California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA)
- The Virginia Consumer Data Protection Act (VCDPA)
- The Colorado Privacy Act (CPA)
- The Connecticut Data Privacy Act (CTDPA)
- The EU and UK General Data Protection Regulation (GDPR / UK GDPR) and the ePrivacy rules, where you serve EU or UK visitors
- Any other applicable federal, state, or international privacy laws
Your responsibilities include, without limitation:
- Deploying the APAS® Init Script on your website as instructed by the Platform
- Keeping consent fields on your forms where your jurisdiction requires them, and enforcing them account-wide where appropriate
- Publishing the provided privacy policy snippet — and the addenda that apply to you — on your website
- Implementing the DELETE MY DATA link, and the Do Not Sell or Share link where US state law applies, in your privacy policy
- Selecting the appropriate consent mode (opt-out or opt-in) for your jurisdiction, and enabling the consent banner if you serve EU or UK visitors
- Following all in-platform recommendations and warnings
- Maintaining your own legal compliance independent of the tools we provide
APAS® Cloud provides the tools — you are responsible for using them. Failure to deploy, configure, or maintain these tools as recommended constitutes non-compliant implementation and is done entirely at your own risk.
5. Limitation of liability
To the maximum extent permitted by law:
- The Platform is provided “as is” and “as available” without warranties of any kind, whether express or implied.
- APAS Ltd. shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to regulatory fines, penalties, or legal fees arising from non-compliant implementations.
- APAS Ltd. is not liable for any compliance issues, data breaches, or regulatory actions resulting from a client's failure to properly deploy, configure, or maintain the compliance tools provided by the Platform, including but not limited to the consent field, consent banner, privacy policy snippet, DELETE MY DATA link, and init script.
- APAS Ltd. is not liable for any compliance issues arising from a client's decision to remove, disable, or override compliance features after being warned by the Platform.
- APAS Ltd. is not liable for any compliance issues arising from a client's failure to heed in-platform recommendations, including but not limited to warnings displayed when removing consent fields or disabling privacy features.
Our total liability for any claim arising from or related to the Platform shall not exceed the fees paid by you to APAS Ltd. in the twelve (12) months preceding the claim.
6. Indemnification
You agree to indemnify, defend, and hold harmless APAS Ltd., its officers, directors, employees, and agents from and against any and all claims, liabilities, damages, losses, costs, and expenses (including reasonable legal fees) arising from or related to your use of the Platform, your violation of these Terms, or your non-compliant implementation of the tools and services provided — including but not limited to failure to deploy consent fields, privacy policy disclosures, data deletion mechanisms, or consent banners as recommended by the Platform.
7. Data processing
All client data is processed and stored on HIPAA-compliant servers located in the United States. Our data processing practices are described in detail in our Privacy Policy.
For clients who process Protected Health Information (PHI) through the Platform, a Business Associate Agreement (BAA) is included as a schedule to our customer agreement. A GDPR Data Processing Agreement, under which APAS Ltd. processes personal data only on the client's documented instructions, is likewise included as a schedule for all clients.
8. Signed agreements prevail
Clients of the Platform sign a customer agreement with APAS Ltd., together with its schedules — including, where applicable, the Business Associate Agreement and the Data Processing Agreement described above. If you have signed such an agreement, its terms prevail over these Terms of Service to the extent of any conflict. These Terms govern your use of this website and of the Platform where no signed agreement applies.
9. Modifications to terms
We reserve the right to modify these Terms of Service at any time. Changes will be posted on this page with an updated effective date. Continued use of the Platform after changes are posted constitutes your acceptance of the revised terms.
10. Governing law
These Terms shall be governed by and construed in accordance with the laws of the Republic of Cyprus, without regard to its conflict of law provisions. Any disputes arising from these Terms shall be subject to the exclusive jurisdiction of the courts of Cyprus.
11. Contact us
If you have any questions about these Terms of Service, please contact us:
- Email: [email protected]
- Address: APAS Ltd., Onisiforou Center, 2nd floor, Agios Theodoros, 8011 Paphos, Cyprus