Apex Euro Capital legal and compliance
Legal

GDPR Compliance

Our framework for processing personal data under EU Regulation 2016/679 and the Belgian Data Protection Act.

Last updated · January 2026

1. Data controller

Apex Euro Capital SA, Avenue Louise 480, 1050 Brussels, Belgium, is the data controller for personal data processed via our platforms. For specific processing activities, an Apex affiliate may act as joint controller or processor, in which case the relevant relationship is documented in a written agreement.

2. Core principles (Article 5)

  • Lawfulness, fairness and transparency
  • Purpose limitation, data collected for specified, explicit and legitimate purposes
  • Data minimisation, adequate, relevant and limited to what is necessary
  • Accuracy, kept up to date, with reasonable steps to correct inaccuracies
  • Storage limitation, retained only for as long as necessary
  • Integrity and confidentiality, appropriate security, including encryption
  • Accountability, demonstrable compliance via documented records

3. Lawful bases we rely on

Contract performance, legal obligation, legitimate interest (subject to a balancing test), consent (where required), and, exceptionally, vital interests or public interest. Special category data (Article 9) is only processed where strictly necessary and lawful.

4. Records of processing activities (Article 30)

Apex maintains a comprehensive Record of Processing Activities (RoPA) covering controller and processor activities, updated whenever a new processing activity is introduced or materially changed.

5. Data Protection Impact Assessments (Article 35)

DPIAs are performed prior to any processing likely to result in a high risk to the rights and freedoms of data subjects, including large-scale processing of financial data, automated decision-making with legal effects and the deployment of new technologies (e.g. AI-assisted credit analytics).

6. Data subject rights

  • Access (Art. 15), rectification (Art. 16), erasure (Art. 17)
  • Restriction (Art. 18), objection (Art. 21), portability (Art. 20)
  • Withdrawal of consent at any time (Art. 7(3))
  • Right not to be subject to solely automated decisions with legal effects (Art. 22)
  • Right to lodge a complaint with a supervisory authority (Art. 77)

We respond to verified requests within one month, extendable by two further months for complex requests, in line with Article 12(3).

7. International transfers (Chapter V)

Personal data is processed within the EEA by default. Where a transfer outside the EEA is necessary, we rely on European Commission adequacy decisions or Standard Contractual Clauses (Module 1 to 4 as appropriate), complemented by a Transfer Impact Assessment and supplementary safeguards in line with the EDPB Recommendations 01/2020 post-Schrems II.

8. Processor management (Article 28)

All processors are subject to written Data Processing Agreements, due-diligence prior to engagement, and periodic re-assessment. Sub-processor changes require prior notice and an opportunity to object.

9. Personal data breach notification

Personal data breaches are notified to the Belgian Data Protection Authority without undue delay and, where feasible, within 72 hours of becoming aware (Article 33). Data subjects are notified where the breach is likely to result in a high risk to their rights and freedoms (Article 34).

10. Privacy by design and by default

Privacy and security requirements are embedded into the design of products, systems and third-party engagements, including default settings that minimise data collection and access.

11. Data Protection Officer

Apex has appointed a Data Protection Officer reporting independently to the Board. Contact: dpo@apexeurocapital.com.

12. Supervisory authority

Belgian Data Protection Authority (APD/GBA), Rue de la Presse 35, 1000 Brussels, contact@apd-gba.be.

Exercise your GDPR rights

Submit verified data subject requests to our DPO at dpo@apexeurocapital.com, we will respond within one month.