Skip to content

Trust Center

Clear evidence for a careful AI rollout.

Apex Chatbot publishes the controls, providers and limitations a buyer should review before connecting customer conversations. This page is a guide to the current public evidence. It does not claim an external certification or a control that is not documented.

Source reviewed: 2026-08-14

Direct answer

How does Apex Chatbot handle business data?

Apex Chatbot stores primary application and conversation data in an EU-hosted Supabase project, uses published subprocessors for specific product functions, and documents retention, deletion and transfer terms in its Privacy Policy and DPA. Customers remain responsible for their notices, lawful basis and configuration.

Security

Documented controls

The public DPA describes the technical and organizational measures below. Product behavior and operational evidence are linked to their own public sources. Contractual requirements should be confirmed before purchase.

Data location and transfers

Primary database storage is configured in Frankfurt. Some application, payment, email, AI and voice providers can process limited data outside the EEA under the safeguards described in the DPA and subprocessor list.

Encryption

The DPA documents TLS 1.2 or higher in transit and provider-managed AES-256 encryption for database storage.

Access and tenant boundaries

The DPA documents row-level database security, role-gated administration and restricted production access.

Retention and deletion

The Privacy Policy defines the current retention periods. Account and conversation data is scheduled for deletion within 30 days after account deletion, subject to legal retention duties.

Human control

Automation is designed around drafts, routing and approval where a workflow can create business risk. Exact workflow behavior depends on the selected product and configuration.

Reliability evidence

The public status page reports product checks. The changelog records shipped product changes. Neither is a contractual SLA unless a separate agreement says so.

What this Trust Center does not claim

  • No SOC 2, ISO 27001 or other external certification is claimed here.
  • No universal uptime, recovery-time or regional-processing guarantee is implied.
  • A buyer-specific security questionnaire, SLA, retention policy or deployment requirement must be scoped in writing.
  • AI output should be configured, tested and monitored for the buyer's use case.

Need a security or privacy review?

Send the requirement, intended product and data categories to adam@apexchatbot.com. We will answer from the current implementation and identify anything that needs a written scope.

Email the operator