Privacy Policy
Controller: EXOR Group Ltd, registered in Malta ("EXOR", "we", "us"). Contact: duncan.dimech@exorgroup.com Applies to: the APEX Pando platform and website ("the Service").
1. Introduction
This Privacy Policy explains how EXOR collects, uses, shares and protects personal data in connection with the Service. It should be read together with our Terms and Conditions and, where applicable, our Data Processing Agreement (DPA).
We respect privacy and collect only what is necessary to operate the Service. Much of the data within the Service is operational and non-personal (for example meeting-room names, schedules, advert content, and sensor readings) and falls outside the scope of this Policy, which concerns personal data only.
2. Who this Policy is for
This Policy covers personal data of:
- Account users — the individuals at a Tenant who register and use the Service (name, email, login).
- Website visitors — people who visit our website.
- Billing contacts — individuals named for billing and invoicing.
Where a Tenant processes personal data of their own customers or staff through the Service, the Tenant is the Controller and EXOR is the Processor — that processing is governed by the DPA, not this Policy.
3. What personal data we collect
You provide to us:
- Registration data: name, business email, account credentials.
- Billing data: billing contact, company details, VAT number. (Card details are handled by our payment processor; we do not store full card numbers.)
- Support data: information you include when contacting support@exorgroup.com.
Collected automatically:
- Technical data: IP address, browser/device type, log data, timestamps.
- Usage data: features used, actions taken, session information (used in aggregated/de-identified form where possible).
Not collected: The Service does not record whether individuals attend meetings, and does not link meeting content to identifiable persons. Optional audience-detection features process only anonymous, aggregate metadata on-device and do not store or transmit images or video.
4. Why we process it, and our lawful basis (GDPR Art. 6)
| Purpose | Lawful basis |
|---|---|
| Providing and administering your account | Performance of a contract |
| Billing and collecting Fees | Performance of a contract / legal obligation |
| Providing support | Performance of a contract |
| Securing the Service, preventing abuse | Legitimate interests |
| Improving the Service (de-identified where possible) | Legitimate interests |
| Sending service/transactional communications | Performance of a contract |
| Sending marketing (if any) | Consent |
| Complying with law, responding to lawful requests | Legal obligation |
5. Sharing personal data
We share personal data only as needed:
- Sub-processors — infrastructure, hosting, storage, backup and payment providers who process data on our behalf under contract (see our sub-processor list, available on request).
- Payment processor — to take payment.
- Professional advisers and authorities — where required by law, or to respond to lawful requests (including, per our Terms, forwarding Tenant identifying details to competent authorities on a lawful copyright/infringement request).
We do not sell personal data. Aggregated, de-identified and operational data that does not identify anyone is not personal data and may be used and shared as described in our Terms. [LAWYER REVIEW: ensure de-identification meets the GDPR anonymisation standard.]
6. International transfers
The Service is hosted within the European Union. Where any processing involves transfer outside the EEA, we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses.
7. How long we keep it
- Account data: for the life of the account and a reasonable period after closure.
- Billing records: as required by Maltese tax and accounting law (typically several years).
- Support data: for a reasonable period to handle and improve support.
- Backups: personal data in routine backups ages out on the normal backup cycle after deletion from active systems.
On account termination, Tenant Data is available for export (in CSV) for [30] days, then may be permanently deleted.
8. Your rights (GDPR)
You have the right to: access your personal data; rectify inaccurate data; erase data ("right to be forgotten"); restrict or object to processing; data portability; and to withdraw consent where processing is based on consent. You may also lodge a complaint with the Information and Data Protection Commissioner (IDPC) in Malta, or your local supervisory authority.
To exercise these rights, contact duncan.dimech@exorgroup.com. We respond within the time limits set by law (generally one month).
Where EXOR is a Processor (Tenant's own data subjects), such requests should be directed to the Tenant as Controller; we will assist the Tenant as required by the DPA.
9. Security
We apply commercially reasonable technical and organisational measures to protect personal data, including access controls, encryption in transit, and tenant isolation. No system is perfectly secure; we cannot guarantee absolute security. If a personal-data breach occurs, we will comply with our notification obligations under GDPR Arts. 33–34.
10. Cookies and website
Our website may use necessary and, with consent, analytics cookies. Details are in our Cookie Notice /legal/privacy.
11. Children
The Service is a business tool and is not directed at children. We do not knowingly collect personal data of children.
12. Changes
We may update this Policy. Material changes will be notified by email or in-app. The current version is always available at /legal/privacy.
13. Contact
Questions or requests: duncan.dimech@exorgroup.com, EXOR Group Ltd, 36, Serenity Triq tal-Qattus Birkirkara, Malta. Supervisory authority: Information and Data Protection Commissioner (IDPC), Malta — idpc.org.mt.