GDPR Compliance

Your data protection rights under the General Data Protection Regulation

Last updated: January 2025

Important Notice

This page explains how Apito LLC ("Apito", "we", "us", or "our") complies with the General Data Protection Regulation (GDPR) and protects your personal data rights.

1. What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018. It applies to all organizations operating within the EU and those that offer goods or services to individuals in the EU, regardless of where the organization is based.

2. Our Commitment to GDPR

Apito is committed to protecting your privacy and ensuring compliance with GDPR requirements. We have implemented appropriate technical and organizational measures to protect your personal data and ensure that your rights are respected.

3. Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Contract Performance: To provide our API builder services and fulfill our contractual obligations
  • Legitimate Interest: To improve our services, ensure security, and prevent fraud
  • Consent: When you explicitly agree to specific processing activities
  • Legal Obligation: To comply with applicable laws and regulations

4. Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

Right to Access

You can request a copy of the personal data we hold about you and information about how we process it.

Right to Rectification

You can request that we correct any inaccurate or incomplete personal data we hold about you.

Right to Erasure (Right to be Forgotten)

You can request that we delete your personal data in certain circumstances, such as when it's no longer necessary for the purposes for which it was collected.

Right to Restrict Processing

You can request that we limit how we process your personal data in certain circumstances.

Right to Data Portability

You can request that we provide your personal data in a structured, commonly used, machine-readable format.

Right to Object

You can object to our processing of your personal data in certain circumstances, particularly for direct marketing purposes.

Rights Related to Automated Decision Making

You have the right not to be subject to decisions based solely on automated processing that significantly affect you.

5. How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us using the information provided at the bottom of this page. We will respond to your request within one month, though this period may be extended by two months if necessary.

Important Note

Before processing your request, we may need to verify your identity to ensure the security of your personal data. We may also ask for additional information to help us locate and process your request efficiently.

6. Data Processing Activities

a) What We Process

We process various types of personal data, including but not limited to:

  • Contact information (name, email, company)
  • Account credentials and authentication data
  • Usage data and analytics information
  • Support communications and feedback
  • Payment and billing information
  • Technical data (IP addresses, device information)

b) How We Process

Your personal data is processed securely using appropriate technical and organizational measures, including encryption, access controls, and regular security assessments.

7. Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When such transfers occur, we ensure that appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions by the European Commission
  • Certification schemes and codes of conduct
  • Binding corporate rules for multinational organizations

8. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Our data retention policies are designed to ensure that personal data is not kept longer than necessary.

9. Data Breach Notification

In the unlikely event of a data breach that affects your personal data, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.

10. Third-Party Processors

We work with carefully selected third-party service providers who help us operate our platform. All such providers are bound by contractual obligations to protect your personal data and comply with GDPR requirements. We regularly review and monitor their compliance.

11. Supervisory Authority

If you have concerns about our data processing activities, you have the right to lodge a complaint with your local data protection supervisory authority. You can find contact details for your supervisory authority on the European Data Protection Board website.

12. Updates to This Policy

We may update this GDPR compliance information from time to time to reflect changes in our practices, legal requirements, or regulatory guidance. We will notify you of any material changes by posting the updated information on our website.

13. Contact Us

If you have any questions about our GDPR compliance or wish to exercise your data protection rights, please contact us at:

Apito LLC

1309 Coffeen Avenue STE 1200

Sheridan, Wyoming 82801

Email: [email protected]

This GDPR compliance information is effective as of the date stated above and applies to all EU residents using our services.