Digital Worker

Privacy Policy

Version 2.1 — Effective 2026-09-22

This policy explains how personal data is processed in connection with the Digital Worker platform. If the Croatian and English versions differ, the Croatian version prevails.

1. Who we are

Apex Academy d.o.o. (trading as Digital Apex) operates the Digital Worker platform.

  • Registered seat: Stepinčeva 79, 21000 Split, Croatia
  • OIB: 77296720425 · VAT ID: HR77296720425
  • Court registration: Trgovački sud u Splitu, MBS 060446318
  • Data-protection contact: legal@apexacademy.hr (or by post to the registered seat, attn. "Data Protection")

We have not appointed a statutory Data Protection Officer because our processing does not meet the GDPR Art. 37 thresholds. The contact above is the single point of contact for data-protection queries and rights requests.

2. Two roles: controller and processor

Every Digital Worker customer gets its own instance of the platform, which we host and operate for it. That gives us two different roles:

  • Processor for our customers. Everything inside a customer's instance — user accounts, profiles, agent conversations, files, knowledge, apps and logs, and the data of the customer's own customers and visitors — is processed on behalf of that customer, who is the controller. We process it only on the customer's instructions under our Data Processing Agreement. If you use Digital Worker at work, your employer or the organisation that gave you access is the controller of your data in the instance; sections 4 and 7 explain how to exercise your rights.
  • Controller for our own business. We are the controller for the personal data of our customers' and prospects' contact persons, for contracts, invoicing, support and advisory communication, and for the operation and security of our own infrastructure. Section 3 describes this processing.

3. Data we process as controller

Category Examples Purpose Legal basis (GDPR) Retention
Business contact data name, business email, phone, job title, company Preparing offers, concluding and performing contracts, account administration Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interest in communicating with the customer's representatives Duration of the business relationship plus 5 years (limitation period); prospects not converted: 2 years after last contact
Billing and tax data invoices, company name, OIB/VAT ID, billing contact, payment records Invoicing and compliance with Croatian tax and accounting law Art. 6(1)(c) legal obligation 11 years (Croatian accounting retention)
Support and advisory communication emails, tickets, meeting notes, attachments Answering requests, delivering onboarding and advisory hours Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interest 2 years after the request is closed
Infrastructure and security data IP addresses, request metadata, server and container logs, monitoring data Operating, securing and troubleshooting the instances we host; detecting abuse Art. 6(1)(f) legitimate interest in secure operation Server and container logs rotate automatically by size and are overwritten, typically within days to a few weeks; data tied to a confirmed security incident is kept until the incident is closed plus up to 2 years as evidence
Inquiries data you send through a contact form or by email Answering your inquiry Art. 6(1)(f) legitimate interest; Art. 6(1)(b) steps before a contract 2 years after last contact

We do not sell personal data and do not use it for advertising profiles. Recipients are our hosting providers (see the sub-processor list), our accountants and IT service providers bound by confidentiality, and authorities where the law requires it.

4. Data we process for our customers

Inside an instance we process, on the customer's behalf, the data listed in the DPA. The customer decides what is collected, why and for how long. The platform's default retention settings are:

  • User accounts and profiles — for as long as the account exists in the instance.
  • Agent conversations — stored by default; the customer can switch this off per agent ("save transcripts"). Stored conversations are kept until the customer deletes them or the contract ends.
  • Agent run logs — records of background agent runs and their steps, kept for 30 days by default.
  • Audit log — 180 days; notifications — 30 days after they are read; code-sandbox code and output — 14 days. The instance administrator can change these periods.
  • When the contract ends — the instance stays available read-only for 30 days for export and is then deleted; hosting snapshots expire within a further 90 days.

If your data is in a customer's instance, please address rights requests to that organisation. If you contact us instead, we will forward your request to the customer without undue delay and help it respond.

5. Special categories and AI inputs

We do not ask for special categories of personal data (Art. 9 — e.g. health, religion, political opinions), and the platform is not configured for them. Anything typed into an agent is processed by the AI model provider the customer has connected to that agent. Customers choose and contract those providers themselves; treat the chat box accordingly.

6. Sub-processors and transfers

We host every instance in the European Union, with the providers listed at /legal/sub-processors.html. AI model providers, messaging channels and other integrations are chosen and connected by each customer under its own contract with them; they are not our sub-processors, and any transfer outside the EEA through them is the customer's decision as controller. Where we supply AI usage ourselves (for example during onboarding), the Order Form names the provider and the transfer safeguard.

7. Your rights

Under GDPR Articles 15–22 you have the right to:

  • Access (Art. 15) — receive a copy of your personal data. Users of an instance can download a ZIP of the data stored about their account (as JSON records; uploaded files are listed, not included) at GET /api/user/data-export, or ask the instance's organisation.
  • Rectification (Art. 16) — correct inaccurate data, including via the Profile page.
  • Erasure (Art. 17) — have your data deleted, where no legal obligation requires us to keep it.
  • Restriction (Art. 18) — ask us to pause processing in defined circumstances.
  • Data portability (Art. 20) — receive your data in a structured, machine-readable (JSON) format; the data export above fulfils this.
  • Objection (Art. 21) — object to processing based on legitimate interest.
  • Withdrawal of consent — where processing relies on consent, withdraw it at any time without affecting earlier processing.
  • Complaint — lodge a complaint with the Croatian Personal Data Protection Agency (AZOP, azop.hr) or the supervisory authority in your EU country of residence.

We respond to verified requests within one month (Art. 12(3)), extendable by two further months for complex requests.

8. Security

We use bcrypt for password storage, AES-256-GCM for stored secrets, TLS 1.2+ for all traffic, a separate instance per customer, isolated-vm sandboxing for customer-authored tool code, role-based access control, rate limiting, audit logging and checksummed backups before every platform upgrade. No system is completely secure. For data we process as controller, we notify the supervisory authority of a personal-data breach within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to people (Art. 33), and affected people where Art. 34 requires; for data in an instance, we notify the customer under the DPA.

9. AI transparency (EU AI Act)

Agents created on the platform must disclose their AI nature to people they interact with (AI Act Art. 50). See the EU AI Act statement.

10. Cookies

The platform uses only strictly necessary cookies and a few browser-storage entries for preferences. We do not use advertising or cross-site tracking. See the cookie policy.

11. Changes to this policy

We notify material changes by email to each customer's administrative contact at least 30 days before they take effect. The version number and effective date above change with every update; previous versions are available on request.

12. Contact and complaints

Questions and rights requests: legal@apexacademy.hr. If you are not satisfied with our answer, you may lodge a complaint with AZOP at azop.hr.

Back to sign in

© 2026 Apex Academy d.o.o., operator of Digital Apex