Privacy Policy
This policy explains what personal data we collect when you use this website, why we collect it, who else sees it, and what you can do about it. We have kept it specific: it describes what this site actually does, not what a website of this kind might do.
Appex Consulting P.C. is the controller of the data described here.
Who we are
Appex Consulting P.C., registered in Greece at Dimitriou Gounari 22, 15343 Athens, VAT number EL802774840 (ΑΦΜ 802774840), General Commercial Registry (ΓΕΜΗ) number 182529204000. We trade as Appex Consulting and refer to ourselves below as “we”, “us” and “our”.
For anything about this policy or your personal data, contact us at hello@appexconsulting.com.
What this policy covers
This policy covers this website and the ways you can contact us through it.
It does not cover the work we do inside our clients’ systems. When we implement or support a client’s Salesforce organisation, any personal data in that system belongs to the client — they decide how it is used, we act only on their instructions under our agreement with them, and their own privacy policy governs it. If you believe your data sits in a client’s system and you want it corrected or removed, contact that organisation directly and we will support them in responding.
What we collect, why, and on what basis
When you send us a message
Our contact form collects your first and last name, company, email address, phone number, how you found us, which services you are interested in, and your message. The fields marked with an asterisk are required; without them we cannot reply.
We use this to answer your enquiry and to assess whether we can help. Our lawful basis is our legitimate interest in responding to business enquiries, and where you are asking about working with us, steps taken at your request before entering into a contract.
Submitting the form sends these details to our customer relationship system, Salesforce, where our team follows up. Nothing you enter is used for advertising, and we do not add you to a mailing list.
When you book a meeting
Our booking window is Google Calendar’s appointment scheduling. It loads only when you open it — if you never click “Book a Meeting”, your browser never contacts Google. Once open, the details you enter create an appointment in our Google Workspace calendar, and Google may set its own cookies at that point. You can also open the booking page in its own tab from the link inside the window. Google processes the appointment as our provider, and its own privacy policy additionally applies to the scheduling page itself.
Our lawful basis is your request and steps before entering into a contract.
When you email or call us
If you email hello@appexconsulting.com or use the phone number on the site, we hold that correspondence in our Google Workspace mailboxes to answer you and keep a record of what was agreed. Our lawful basis is our legitimate interest in managing our business relationships.
When you apply for a job
When you apply through the form on a job post, we receive your name, email address, phone number, your LinkedIn profile if you give one, your CV, and anything you write in the message box. It is stored on our own systems, where only Appex administrators can open it, and a copy is sent to our own careers inbox so we notice it promptly. It is not shared with anyone outside Appex. If you would rather send a speculative CV by email instead, it reaches us at careers@appexconsulting.com.
We hold what you send to assess your application. Our lawful basis is steps prior to entering into a contract and our legitimate interest in recruiting. We keep applications for 24 months so we can consider you for later roles, then delete them. Tell us at any time if you would rather we deleted yours sooner.
The application form is protected by Google reCAPTCHA, which judges whether a form is being filled in by a person. Google receives your IP address and how you moved through the page, under its own privacy policy.
When you simply browse
Our hosting provider, Hostinger, keeps standard server logs: your IP address, the time of the request, the page requested and your browser’s user-agent string. These exist to keep the site available and secure, on the basis of our legitimate interest, and are held by Hostinger for a short period, typically no more than 30 days.
This site runs Google Analytics, and only if you agree to it. We use it to count visits and see which pages people find useful. There is no advertising technology, nothing is sold or shared, and we do not build a profile of who you are unless you tell us.
Cookies and local storage
- No cookies unless you accept them. If you accept analytics, Google Analytics sets two cookies, _ga and _ga_0P2MRPJ22E, so a returning visit is not counted twice. Decline, or ignore the banner, and nothing is set.
- One item of local storage. Your browser remembers your scroll position on each page under the key appexScroll. It is deleted when you close the tab, and it never leaves your browser.
- Google Calendar loads only when you open the booking window, and Google may then set its own cookies. Nothing loads beforehand.
- Google reCAPTCHA loads on our contact and job application forms, to stop automated submissions. Our lawful basis is our legitimate interest in protecting the site from abuse.
You are asked once, in a small banner, before anything non-essential loads — nothing reaches Google until you accept. You can change your mind whenever you like using the Cookie Settings link in the footer, and withdrawing deletes the cookies an earlier acceptance had set.
Who else processes your data
- Salesforce (Salesforce Ireland Limited) — our customer relationship system, where contact form submissions and client records are held.
- Google (Google Ireland Limited) — our email and document storage, the booking calendar, and reCAPTCHA.
- Hostinger (Hostinger International Ltd) — hosts this website and keeps the server logs described above.
- Professional advisers and authorities — accountants, lawyers or public authorities, where we are required or legally entitled to share information.
We do not sell your personal data, and we do not share it for advertising.
Transfers outside the EEA
Some of the providers above are based in, or store data in, the United States. Where personal data leaves the European Economic Area, it is protected by the European Commission’s Standard Contractual Clauses, and where applicable by the provider’s certification under the EU–US Data Privacy Framework. You can ask us for a copy of the safeguards that apply.
How long we keep it
- Enquiries and client records — for the life of the relationship and 5 years afterwards, to meet our contractual, tax and accounting obligations. Enquiries that do not become client relationships are held for the same period and then deleted.
- Job applications — 24 months.
- Server logs — a short period at our hosting provider, typically no more than 30 days.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- have inaccurate data corrected;
- have your data erased, where we have no overriding reason to keep it;
- restrict how we use it while a concern is being resolved;
- receive it in a portable form, where processing is based on consent or a contract;
- object to processing based on our legitimate interests, including at any time;
- withdraw consent, where we have relied on it.
To exercise any of these, email hello@appexconsulting.com. We will respond within one month. We do not make automated decisions about you and we do not profile you.
If you are not satisfied with our response, you can complain to the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifisias 1-3, 115 23 Athens, or through dpa.gr.
Security
The site is served over HTTPS. Access to our email, document storage and customer relationship system is limited to the people who need it and protected by multi-factor authentication. No system is completely secure, so we cannot promise absolute security — but if a breach ever affects your data, we will notify you and the authority where the law requires it.
Children
This website is aimed at businesses and is not directed at children. We do not knowingly collect personal data from anyone under 15. If you believe a child has given us their details, contact us and we will delete them.
Links to other websites
Our site links to websites we do not operate, including our clients’ sites and Salesforce’s. We are not responsible for their content or their privacy practices, and we encourage you to read their policies.
Changes to this policy
We may update this policy. The current version is always on this page and the date it took effect is shown at the end. If we make a change that materially affects how we use your data, we will say so prominently on the site.
Contact us
Questions, requests or complaints: hello@appexconsulting.com, or write to us at Dimitriou Gounari 22, 15343 Athens, Greece.
Last updated: 21 August 2026
