Version 2026-09-13 · Effective 13 September 2026
The controller for Project Apex is the legal operator identified in the Legal Notice. Privacy requests can be sent to the professional contact address published there, currently info@projectapex.eu.
Depending on how you use Project Apex, we may process account identifiers, name, email, phone number, business and dealer information, billing identity, vehicle and listing information, uploaded media and documents, enquiry content, Buyer Intent answers, Buyer Demand criteria, consent records, payment and invoice references, support communications, moderation and audit records, security logs, device/browser information and analytics events where consent is given.
Project Apex does not need complete payment-card data and relies on its payment provider for card processing.
Contract and pre-contract steps. We process account, listing, dealer, enquiry, Buyer Demand, payment and service data to provide requested marketplace services, review submissions, operate pilots, activate paid services and support users.
Legal obligations. We process billing, invoice, transaction, tax, accounting, consumer-withdrawal, legal-notice and compliance information where required by Belgian or EU law.
Legitimate interests. We process proportionate data for platform security, fraud prevention, abuse prevention, service reliability, auditability, marketplace integrity, business analytics and relevant B2B prospect research. These interests are balanced against the rights and expectations of the individuals concerned.
Consent. We rely on consent for optional analytics storage, optional marketing/newsletter subscriptions and for product actions that explicitly require the buyer to authorise sharing or an introduction. Marketing/newsletter consent is separate from the service communications needed to review a listing, operate Buyer Demand, process an enquiry or administer a Founding Dealer Pilot. Refusing marketing consent does not block those requested services. Consent can be withdrawn for future processing where the processing is based on consent.
When a buyer submits an enquiry, the contact details and message are shared only with the relevant seller/dealer and Project Apex personnel or processors necessary to operate the service. Buyer Intent uses structured information voluntarily supplied by the buyer to give the seller factual context; it does not verify identity, funds, financing eligibility or purchase commitment.
Buyer Demand is private by default. Anonymised demand details are shared with eligible dealers only when the buyer has enabled sharing. Personal contact details remain private until the buyer explicitly permits an introduction or another lawful sharing route applies.
Project Apex may research specialist dealerships and professional contacts using publicly accessible business websites, dealer inventory pages, professional directories, company registries and professional social/business sources. The categories may include company name, public business contact details, professional name and role, website, inventory evidence, country/region and publicly observable commercial characteristics relevant to Project Apex.
This research is used to assess dealer fit, contactability, compliance and potential participation. A public professional contact detail is not treated as consent to marketing. Before outreach, Project Apex applies the relevant channel, country and human compliance gates. Individuals whose data was obtained indirectly are informed no later than the first communication or within the applicable GDPR period unless a lawful exception applies.
A person may object at any time to direct marketing and associated profiling. Project Apex records suppression so that a valid objection or unsubscribe instruction is respected.
Approved LIVE listings and verified public dealer profiles may be visible to anyone. Public information can include seller/dealer attribution, vehicle data, photos, location at the level displayed on the listing, business website and other information deliberately published for marketplace discovery. Private billing, Stripe, subscription, pilot and account-security fields are not part of the public profile.
Essential storage is used for authentication, security and preferences. Optional analytics is activated only after consent. If analytics consent is accepted, Project Apex may record page and listing interactions such as views, saves, shares or dealer-profile clicks and may use analytics tooling to understand aggregate marketplace usage. Analytics consent can be rejected or withdrawn through the available cookie controls.
Personal data may be processed by infrastructure, hosting, database, authentication, payment, email-delivery, analytics, cloud productivity, accounting/e-invoicing and support providers acting for Project Apex, and by sellers/dealers when a buyer intentionally contacts them. Public authorities, courts or professional advisers may receive data where legally required or necessary to establish, exercise or defend legal claims.
Current technical service categories include Base44 for platform infrastructure, Stripe for payment processing, email-delivery infrastructure, Google services for authorised business communication/calendar workflows and Google Analytics where the user has consented. A structured e-invoicing/Peppol provider is used only once the production route has been verified.
Some service providers may process data outside the European Economic Area. Where a transfer is subject to GDPR transfer restrictions, Project Apex relies on an applicable adequacy decision, Standard Contractual Clauses or another legally recognised safeguard made available by the relevant provider. Users may contact Project Apex for information about applicable safeguards.
Project Apex keeps personal data only for as long as necessary for the relevant purpose, legal obligation or dispute. Account and operational marketplace data is retained while the account/service is active and then deleted or minimised when no longer needed, subject to legal records that must be kept longer.
Payment, invoice and accounting records are retained for the applicable Belgian statutory period; Belgian tax rules currently require relevant invoices and accounting documents to be preserved for 10 years. Security, consent, audit and legal-compliance evidence may be retained for the period reasonably necessary to demonstrate compliance or handle claims. B2B prospect data that does not lead to an active relationship is periodically reviewed and is deleted, suppressed or refreshed when it is no longer relevant or accurate.
Project Apex uses authentication, role-based and row/field-level access controls, service-role separation, restricted admin entities, audit logging and payment/webhook verification measures intended to prevent unauthorised access. Dealers are scoped to their own private commercial and billing data; public verified dealer information is separated from protected subscription, pilot and payment fields.
Project Apex uses deterministic rules and AI-assisted tooling for tasks such as curation support, vehicle intelligence, dealer research, matching, quality checks and workflow prioritisation. These tools are not used to make solely automated decisions that produce legal or similarly significant effects on an individual without a human or other lawful safeguard. Human gates remain required for dealer outreach approval, material moderation and commercial activation where designed.
Subject to the GDPR conditions, you may request access, rectification, erasure, restriction, portability and information about processing, and you may object to processing based on legitimate interests. You have an unconditional right to object to direct marketing. Where processing is based on consent, you may withdraw that consent for future processing.
Requests can be sent using the controller contact details in the Legal Notice. Project Apex may request proportionate information to verify identity before acting on a request and will respond within the legally applicable period.
If you believe personal data has been processed unlawfully, you may contact Project Apex first and you also have the right to lodge a complaint with the competent supervisory authority. For a controller established in Belgium, the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données) is the principal supervisory authority, without affecting your right to contact another competent authority where GDPR permits.
This policy may be updated when products, providers or legal requirements change. The current version and effective date are shown at the top of this page. Material changes that affect an active contractual relationship will be communicated where required by law.