01Who we are
Apex Routing Inc. ("Apex Routing", "we", "us", "our") is a network infrastructure company incorporated in Canada and operating from the Province of Ontario. We provide enterprise network consulting services, a managed proxy dashboard platform, and IP address space services to business customers.
We are the organization accountable for the personal information described in this policy. Our handling of personal information is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
This policy covers our public website at apexrouting.com, our customer platform at dashboard.apexrouting.com, and the correspondence and support channels described in section 14.
02Information we collect
We collect only what we need to deliver, secure, bill for and support our services. The categories below describe everything we collect and where it comes from.
| Category | What it includes | Source |
|---|---|---|
| Account information | Name, business name, business email address, telephone number, job title, account username, and a securely hashed password. | Provided by you at sign-up or by your organization's administrator. |
| Billing information | Billing contact, billing address, tax registration numbers, invoice and payment history, and the last four digits and card brand of a payment method. | Provided by you; payment records returned to us by our payment processor. |
| Service configuration data | Proxy usernames, assigned egress IP addresses, allocated subnets, sub-account structures, and access credentials you create in the dashboard. | Created by you or provisioned by us on your instruction. |
| Connection and usage metadata | Timestamps, source and destination IP addresses, destination hostnames, bytes transferred, HTTP response status, authentication outcomes, and error events generated by our proxy infrastructure. | Generated automatically by our systems when the service is used. |
| Platform activity logs | Dashboard sign-in events, IP address and user agent at sign-in, administrative actions taken, and configuration changes. | Generated automatically when you use the dashboard. |
| Support correspondence | The content of emails and tickets you send us, and our replies. | Provided by you when you contact us. |
| Website analytics | Pages requested, referring page, approximate region, browser and device type, and aggregate traffic and security statistics. | Generated automatically by our web server and our content delivery network. |
We do not sell personal information, and we never have. We do not share it with advertisers, data brokers or marketing networks, and we do not use customer traffic data to build advertising or behavioural profiles.
Content passing through the service
Our proxy infrastructure transports network traffic on your instruction. That traffic may contain personal information relating to you or to third parties. We do not intercept, decrypt or inspect the payload of that traffic. We do not perform TLS interception. Our systems record only the connection metadata described above, and we act as a service provider processing that data on your behalf and under your instructions.
Where you use our services to process personal information about your own customers or end users, you are the organization accountable for that information. You are responsible for having a lawful basis for that processing and for providing any notices that your own privacy obligations require.
03How we use information
We use personal information only for the purposes identified below, and we do not use it for a new purpose without first obtaining your consent unless the law permits or requires otherwise.
- To provide the services — creating and administering your account, provisioning proxy credentials and IP allocations, authenticating your users, and routing traffic as configured.
- To bill and collect payment — generating invoices, calculating usage-based charges, processing payments, and maintaining financial records required by law.
- To support you — responding to enquiries, diagnosing faults, and investigating incidents you report.
- To secure and maintain the platform — detecting and preventing fraud, credential abuse, denial-of-service activity and unauthorized access; monitoring capacity and availability; and investigating suspected breaches of our Acceptable Use Policy.
- To meet legal obligations — responding to lawful requests from authorities, retaining records required by tax and corporate law, and responding to abuse complaints concerning IP space we control.
- To communicate with you — sending service notices, maintenance windows, security advisories, billing notifications and changes to our terms. These are operational messages and you cannot opt out of them while you hold an account.
- To improve the services — analysing aggregate performance and reliability data. Wherever practicable we use aggregated or de-identified data for this purpose.
We do not use personal information for automated decision-making that produces legal or similarly significant effects.
04Consent and legal basis
In most cases we collect, use and disclose personal information with your knowledge and consent. By opening an account, purchasing a service, or corresponding with us, you consent to the handling of your personal information as described in this policy.
Consent may be express (for example, when you complete a sign-up form) or implied by the circumstances (for example, when you email us and we use your address to reply). Where the information is sensitive, we seek express consent.
PIPEDA permits collection, use or disclosure without consent in limited circumstances, and we rely on those exceptions only where they apply — for example to investigate a breach of an agreement or a contravention of law, to comply with a subpoena, warrant or court order, or in an emergency threatening someone's life, health or security.
You may withdraw your consent at any time, subject to legal and contractual restrictions and reasonable notice. Withdrawing consent for information we need in order to operate your account will normally require us to close that account. Write to [email protected] to do so.
05Disclosure to third parties
We disclose personal information only in the situations set out below. In each case we identify the recipient, the reason, and the method of disclosure.
| Recipient | Why we disclose | Method of disclosure |
|---|---|---|
| Payment processor | To take payment, issue refunds and prevent payment fraud. Card details are entered directly with the processor; we never receive or store full card numbers. | Encrypted API call over TLS at the time of the transaction. |
| Infrastructure and hosting providers | To host our servers, network and data. They act on our instructions and do not use the data for their own purposes. | Data resides on their systems under a written services agreement. |
| Content delivery and security network | To serve our website, terminate TLS, and mitigate denial-of-service and bot traffic. | Traffic is routed through their edge network in transit. |
| Email and communication providers | To deliver and store our business correspondence with you. | Messages are transmitted and stored on their platform. |
| Upstream network operators and IP registries | To register, route and maintain IP address space, and to respond to abuse reports concerning that space, as required by registry policy. | Registry records and direct correspondence; some registration contact data is published in public WHOIS records. |
| Professional advisers | To obtain legal, accounting, audit and insurance advice. | Direct correspondence, under a duty of confidentiality. |
| Law enforcement and regulators | Where we are compelled by a valid subpoena, warrant, production order or other lawful demand, or where disclosure is otherwise permitted or required by law. | Direct written response to the requesting authority. |
| An acquirer | In connection with a merger, acquisition, financing or sale of assets. The information disclosed is limited to what is necessary to evaluate and complete the transaction. | Disclosure under a confidentiality agreement; the successor remains bound by this policy. |
Government and law enforcement requests
We disclose customer information to authorities only where we are legally compelled to do so, and we disclose no more than the demand requires. Where we are lawfully permitted to notify you of a request affecting your account, we will do so before responding, unless a court order or statute prohibits notice or there is a risk to life or safety.
06Service providers
We engage third-party service providers to perform functions on our behalf, including hosting, content delivery, email, monitoring, logging and payment processing. These providers may store or process personal information solely to perform those functions.
Before engaging a provider we assess their security posture, and we bind them by written contract to protect personal information to a standard comparable to our own, to use it only for the purposes we specify, and to return or destroy it when the engagement ends. We remain accountable for personal information that is in a provider's hands.
A current list of the service providers that process personal information on our behalf is available on request to [email protected].
07International transfers
Apex Routing operates infrastructure in Canada, the United States and Europe, and some of our service providers are located outside Canada. Personal information may therefore be stored or processed in, and transferred to, jurisdictions other than your own.
While personal information is in a foreign jurisdiction it is subject to the laws of that jurisdiction, and may be accessible to the courts, law enforcement and national security authorities of that country under their legal processes. We use contractual and technical safeguards to protect information that crosses borders, but those safeguards cannot displace foreign legal process.
If you require that your data remain within a specific jurisdiction, contact [email protected] before ordering so we can confirm whether we can accommodate that requirement.
08Retention
We keep personal information only as long as necessary to fulfil the purpose it was collected for, or as long as the law requires — whichever is longer. Our standard retention periods are:
| Record type | Retention period |
|---|---|
| Account and contact records | For the life of the account, then 24 months after closure. |
| Invoices, payment and tax records | 7 years from the end of the tax year, as required by Canadian tax law. |
| Connection and usage metadata | Up to 90 days, then deleted or aggregated into non-identifying statistics. |
| Dashboard security and audit logs | 12 months. |
| Support correspondence | 24 months from the close of the ticket. |
| Abuse reports and related investigation records | 24 months from resolution. |
Where an account is subject to a live dispute, investigation or legal hold, we retain the relevant records until the matter is resolved. When a retention period expires, records are securely deleted or irreversibly de-identified.
09Security practices
We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the information we hold. Our practices include the following.
- Encryption in transit. All access to our website, dashboard and APIs is served over HTTPS with modern TLS. Administrative access to our infrastructure is over SSH with key-based authentication.
- Credential protection. Account passwords are stored only as salted one-way hashes using an industry-standard adaptive hashing algorithm. Plain-text passwords are never stored or logged, and staff cannot retrieve them.
- Access control. Access to production systems and customer data is restricted to the personnel who need it to do their jobs, is granted on a least-privilege basis, and is revoked promptly when a role changes or ends.
- Network segmentation and filtering. Management interfaces and internal telemetry services are firewalled to known hosts and are not exposed to the public internet.
- Monitoring and audit logging. Administrative actions and authentication events are logged to a separate logging system, so that access to customer configuration can be reviewed after the fact.
- Payment isolation. Card data is captured by our PCI-compliant payment processor and never traverses or rests on our servers.
- Patching and hardening. Operating systems and service software are kept on supported releases and receive security updates.
- Backups. Configuration and account data is backed up on a regular schedule, and backups are protected to the same standard as production data.
- Vendor diligence. Providers that handle personal information on our behalf are assessed before engagement and bound by written contract.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach of security safeguards involving your personal information that creates a real risk of significant harm, we will notify you and the Office of the Privacy Commissioner of Canada as required by law, and we will tell you what happened and what steps you can take.
If you believe you have found a security vulnerability in our systems, please report it to [email protected]. We will acknowledge your report and will not pursue action against good-faith researchers who follow responsible disclosure.
10Your rights
Subject to the limited exceptions in the legislation, you have the right to:
- Access the personal information we hold about you, and be told how it has been used and to whom it has been disclosed.
- Correct information that is inaccurate or incomplete.
- Withdraw consent to our continued use of your information, subject to legal and contractual restrictions and reasonable notice.
- Request deletion of information we no longer need for the purpose it was collected for, or that we are not required to retain.
- Receive a copy of information you supplied to us, in a structured, commonly used format.
- Complain about our handling of your information, to us and to the relevant regulator.
To exercise any of these rights, email [email protected]. We will confirm your identity before acting on a request, respond within 30 days, and tell you in advance if we need an extension and why. Access requests are free of charge; if a request is unusually repetitive or costly we will give you a fee estimate before proceeding and you may withdraw the request.
If we refuse a request in whole or in part, we will tell you in writing why, which provision of the legislation we rely on, and how to complain.
12Children
Our services are sold to businesses and are not directed at children. We do not knowingly collect personal information from anyone under the age of majority in their province or state of residence. If we learn that we have collected such information, we will delete it. A parent or guardian who believes we hold information about a child may contact [email protected].
13Changes to this policy
We may update this policy to reflect changes in our services, our providers, or the law. The effective date at the top of this page always shows the current version.
Where a change materially affects how we handle personal information we already hold, we will notify account holders by email at least 30 days before it takes effect. Continuing to use the services after a change takes effect means you accept the updated policy. Previous versions are available on request.
14Contact & complaints
Our Privacy Officer is accountable for our compliance with this policy and can be reached at:
| Privacy Officer | Apex Routing Inc. |
| Privacy enquiries | [email protected] |
| Legal notices | [email protected] |
| Customer support | [email protected] — see our Support page |
| Jurisdiction | Province of Ontario, Canada |
We will acknowledge every privacy enquiry or complaint, investigate it, and tell you the outcome and any corrective action taken. If you are not satisfied with our response, you may bring a complaint to the Office of the Privacy Commissioner of Canada at priv.gc.ca.