
Privacy Policy
How we collect, use, share, retain and protect your personal data across the Apex platform.
Last updated · January 2026
1. Who we are
Apex Euro Capital SA ("Apex", "we", "us", "our") is a Belgian-headquartered financial advisory and capital markets group with offices in Brussels and Athens. Apex acts as the data controller for personal data processed through this website, our funding application platforms, investor relations channels and client onboarding systems. Our registered address is Avenue Louise 480, 1050 Brussels, Belgium.
2. Scope of this policy
This policy applies to personal data we collect from website visitors, funding applicants, authorised representatives, beneficial owners, investors, portfolio company personnel, counterparties, service providers, job candidates and any other identified or identifiable natural person interacting with Apex.
3. Categories of personal data we collect
- Identification data, full legal name, date and place of birth, nationality, government-issued ID, signature.
- Contact data, postal address, email, telephone, preferred language.
- Professional data, job title, employer, professional qualifications, regulatory status.
- Financial data, bank details, source of funds, source of wealth, transaction history, credit information, tax residency and TIN.
- KYC / AML data, UBO declarations, sanctions screening results, PEP status, adverse media findings.
- Transactional data, funding application content, term sheets, drawdown schedules, repayment history.
- Technical data, IP address, device identifiers, browser, OS, referring URLs, session logs, cookies and similar technologies.
- Communication data, recorded calls (where notified), email correspondence, meeting notes, support tickets.
- Special category data, only where strictly necessary and with explicit consent or another lawful basis under Article 9 GDPR.
4. How we collect personal data
- Directly from you when you complete a form, submit an application or contact us.
- From authorised representatives, advisors, brokers or intermediaries acting on your behalf.
- From publicly available sources, company registries, sanctions lists and credit bureaus.
- From third-party KYC/AML providers, identity verification vendors and risk databases.
- Automatically through cookies, log files and analytics on our digital properties.
5. Purposes and legal bases of processing
- Contract performance (Art. 6(1)(b)), onboarding, executing facility agreements, servicing investments.
- Legal obligation (Art. 6(1)(c)), AML/CFT, KYC, sanctions screening, tax reporting, accounting, FATCA/CRS.
- Legitimate interest (Art. 6(1)(f)), fraud prevention, network and information security, business analytics, client communications.
- Consent (Art. 6(1)(a)), marketing communications, optional cookies, certain research participation.
- Public interest / vital interest, only in narrowly defined regulatory or safety scenarios.
6. Recipients and disclosures
We may share personal data with: affiliated Apex entities; institutional investors and lending partners involved in a transaction; KYC, AML and identity verification providers; legal, tax and audit advisors; payment institutions and custodians; IT and cloud service providers operating under written processor agreements; competent regulators, courts and law-enforcement authorities where legally required.
7. International data transfers
Where personal data is transferred outside the European Economic Area, we rely on European Commission adequacy decisions or, in their absence, on Standard Contractual Clauses (SCCs) complemented by transfer impact assessments and supplementary technical and organisational measures.
8. Retention
- KYC/AML records, 10 years after the end of the business relationship (Belgian AML Law).
- Transaction and accounting records, 10 years.
- Marketing data, until consent is withdrawn or 3 years of inactivity.
- Website logs, up to 12 months.
- Unsuccessful job applications, 12 months unless you consent to a longer talent-pool retention.
9. Your rights
- Access, rectification and erasure (subject to legal retention obligations).
- Restriction of, and objection to, processing.
- Data portability for data processed by automated means on the basis of contract or consent.
- Withdrawal of consent at any time, without affecting prior lawful processing.
- The right not to be subject to solely automated decisions producing legal effects.
- The right to lodge a complaint with the Belgian Data Protection Authority (gegevensbeschermingsautoriteit.be).
10. Security
Apex maintains an ISO 27001-aligned information security programme including encryption in transit and at rest, role-based access controls, multi-factor authentication, secure development practices, regular penetration testing, incident response procedures and mandatory annual security training for all personnel.
11. Cookies
We use strictly necessary cookies to operate the site and, with your consent, analytics and functional cookies to improve user experience. You may manage preferences at any time via our cookie banner or your browser settings.
12. Children
Our services are not directed at individuals under 18 years of age and we do not knowingly collect personal data from minors.
13. Changes to this policy
We review this policy at least annually and whenever there is a material change to our processing activities. The "last updated" date above reflects the most recent revision.
14. Contact our Data Protection Officer
Data protection enquiries: dpo@apexeurocapital.com
Postal: Apex SA, Data Protection Officer, Avenue Louise 480, 1050 Brussels, Belgium.
