Apex Lab What We Measure About FAQ
Login
EN/NL
Book a pilot

Privacy Policy

Last updated: 16 May 2026

The Apex Lab ("we", "us", "our") processes personal data with care. This Privacy Policy explains what data we collect, why we collect it, and what rights you have under the GDPR.

Summary

  • We collect only what is necessary for: website use, contact/enquiries, service delivery, and (optionally) questionnaires & wearables.
  • For health data (questionnaires/wearables) we ask for explicit consent, apply additional safeguards, and restrict access.
  • We use, among others, Cloudflare Pages (website hosting), Google Workspace/Drive (storage), and Labfront (project environment for wearable/questionnaire data).
  • You can exercise your rights via info@apexlab.nl. We respond within 30 days.

1. Who is responsible?

Controller: The Apex Lab — trade name of Pro Performance Therapy — Dutch Chamber of Commerce (KvK): 87119722.

We have not appointed a Data Protection Officer (DPO).

Our role may vary: for the website, intake, scheduling, and our own reporting we act as controller. For assignments commissioned by employers we may act (in part) as processor on behalf of the employer (under a data processing agreement).

2. What data do we process?

2.1 Website & communication

Data: name, email, phone, message; technical data (IP, device, browser).

Source: provided by you (contact/appointment). Our website is a static site hosted on Cloudflare Pages; the contact option opens your own email client (a "mailto" link) and is not processed through a third-party form tool. We do not use third-party website analytics or tracking.

Purpose: contact, quotation/appointment, and site security.

2.2 Client/participant administration

Data: name, email, phone, organisation/department, role, invoicing and payment details.

Purpose: performance of the agreement, scheduling, invoicing, account management.

2.3 Questionnaires & wearables (only with consent)

Data (special category personal data): questionnaire responses (e.g. stress/sleep), wearable datasets (e.g. heart rate, stress/HRV indicators, sleep duration/stages), timestamps, task types/work context.

Source: provided by you, via systems you connect (e.g. Garmin → Labfront) or upload (CSV/Excel) to Google Drive or Labfront.

Purpose: analysis and advice on workload, recovery, and vitality; reporting to you (and, if contractually agreed, summarised/anonymised to the commissioning party).

Important: do not share medical information via a regular contact route. For questionnaires/wearables we use a protected environment. Health data is processed only with explicit consent and kept separate from regular administration.

Before participating you receive our Informed Consent form, which sets out exactly what data we collect, how we process it, and what rights you have.

3. Purposes and legal bases

  • Contact and follow-up: legitimate interest art. 6(1)(f) and/or performance of a contract art. 6(1)(b)
  • Quotes, scheduling and delivery: art. 6(1)(b)
  • Invoicing and statutory tax retention: art. 6(1)(c)
  • Site security: art. 6(1)(f)
  • Questionnaires and wearables (health data): solely explicit consent art. 6(1)(a) in conjunction with art. 9(2)(a)
  • Newsletter/knowledge sharing: art. 6(1)(a)

You can withdraw consent at any time via info@apexlab.nl (not retroactively).

4. Retention periods

  • Website contact/enquiries: max. 12 months after the contact is concluded.
  • Client files/reports: max. 24 months after the end of the engagement (unless otherwise agreed contractually or necessary for legal claims).
  • Health data (questionnaires/wearables): 12–24 months after the end of the engagement, or earlier on your request; anonymised, non-identifiable statistics may be retained longer.
  • Invoice and transaction data: 7 years (statutory tax obligation).

5. Sharing data (recipients)

We do not share data with third parties outside the categories below, unless necessary for delivery, with your consent, or as legally required.

(Sub)processors we use:

  • Cloudflare, Inc. — website hosting and content delivery / security for the static marketing site (apexlab.nl).
  • Google Workspace/Drive (Google Ireland Ltd.) — email, document storage and spreadsheets (incl. raw data/exports). We have a Data Processing Addendum with Google; Google provides appropriate transfer safeguards (see section 6).
  • Labfront (Labfront Inc.) — research/project environment for wearable and questionnaire data (storage and processing for analysis & reporting). Labfront hosts in the US (AWS); see section 6 for safeguards.

We enter into data processing agreements with all processors. Third parties do not use the data for their own purposes.

6. Transfers outside the EEA

  • Labfront: data may be stored/processed in the United States. We safeguard this with Standard Contractual Clauses (SCCs) and additional measures.
  • Google Workspace/Drive: primarily an EU entity; depending on the service, sub-processors outside the EEA may be involved. We rely on Google's SCCs and (where applicable) the EU–US Data Privacy Framework.
  • Cloudflare: operates a global content delivery network; requests may be served from data centres outside the EEA. We rely on Cloudflare's SCCs and applicable transfer safeguards.

Your rights remain in force in the event of international transfers. On request we provide information about the relevant safeguards and sub-processors.

7. Security

  • Encryption in transit (TLS/HTTPS) and at rest (encrypted storage at our processors).
  • Access control on a need-to-know basis, strong passwords, and MFA where possible.
  • Separate storage of health data (pseudonyms/Participant IDs, key file kept apart).
  • Data minimisation & pseudonymisation in analyses/reports.
  • Periodic review of access and processors; incident and data-breach procedure in line with the GDPR (notification to the supervisory authority/data subjects where required).

8. Your rights

You have the right to access, rectification, erasure, restriction, portability, objection (where based on legitimate interest), and withdrawal of consent.

You can submit requests via info@apexlab.nl. We respond within 30 days. We may request additional identification.

9. Minors

Our services are aimed at adults/working professionals. We do not knowingly request data from minors. If we nevertheless receive such data, we delete it as soon as reasonably possible, unless a legal obligation requires otherwise.

10. Automated decision-making / profiling

We do not make decisions based solely on automated processing with legal effect. Analyses and scores (stress/sleep indices) are always interpreted by a professional.

11. Cookies

Our static marketing site does not set analytics, marketing, or tracking cookies. Strictly necessary security cookies may be set by our hosting/CDN provider (Cloudflare). See our Cookie Statement for details.

12. Complaints

Do you have a complaint about our data processing? Let us know via info@apexlab.nl. If we cannot resolve it together, you can contact the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

13. Changes

We may amend this Privacy Policy. The date of the most recent update is always shown at the top. We will inform you of material changes via the website and/or by email.

14. Contact

Questions or requests about privacy? Email: info@apexlab.nl

Product

PlatformWhy Apex LabWhat We MeasureFor Teams

Company

AboutFAQBook a pilotinfo@apexlab.nl

Legal

Privacy PolicyTermsCookiesDisclaimer

Access

LoginLinkedInNederlands

© 2026 Apex Lab. Based in the Netherlands.GDPR-compliant · EU data residency