Privacy Policy
Last Updated: October 1, 2026
This Privacy Policy explains how Apex Cloud Tech LLC ("Apex Cloud Tech," "DotlyGuard," "we," "us," or "our") collects, uses, stores, protects, and discloses personal information when you use the DotlyGuard website, web applications, endpoint agents, APIs, dashboards, and related services (collectively, the "Service").
By accessing or using the Service, you acknowledge that you have read and understood the practices described in this Privacy Policy.
1. Scope and Roles Under Data Protection Laws
This Privacy Policy applies to personal information collected through our website, web console, endpoint agents, APIs, billing portals, customer support channels, and related digital properties.
Under applicable data protection laws (including the EU General Data Protection Regulation / UK GDPR and the California Consumer Privacy Act as amended by the CPRA):
DotlyGuard as a Data Controller / Business: We act as a Controller regarding your account registration details, direct billing data, website browsing metadata, and direct customer support communications.
DotlyGuard as a Data Processor / Service Provider: When you install the DotlyGuard Agent to monitor internal endpoints, servers, and networks, you (the customer organization) act as the Controller, and DotlyGuard processes endpoint telemetry strictly on your behalf and pursuant to your instructions and our Data Processing Addendum (DPA).
2. Information We Collect
2.1 Account and Billing Information
When you create an account, register an administrator, or buy a subscription, we collect:
Identity & Contact Data: Full name, business email address, company name, phone number, and job title.
Authentication Credentials: Passwords, multi-factor authentication (MFA) metadata, and API authorization keys.
Billing Information: Payment card information, billing address, and transaction records. Payment-card processing is handled directly by third-party PCI-DSS-compliant payment processors; DotlyGuard does not store full credit card numbers on its servers.
2.2 Endpoint Telemetry and Security Logs (Customer Data)
When the DotlyGuard Agent is deployed across monitored devices, it automatically collects technical telemetry necessary for anomaly detection, threat hunting, and compliance audit logging:
Host & System Identification: Hostnames, local device identifiers, machine UUIDs, MAC addresses, private/public IP addresses, OS version/kernel architecture, and hardware configurations.
Process & Activity Telemetry: Executable names, process file paths, parent-child process trees, running services, system call traces, and installed software inventories.
Security & Authentication Events: Usernames logged into the endpoint, interactive logon/logoff timestamps, privilege escalation actions, failed authentication attempts, and audit-log records.
File & Network Metadata: File modification events, file hashes (e.g., SHA-256), active network socket connections, outbound destination IP addresses, and DNS lookup records.
Notice on Sensitive Inadvertent Ingestion: Endpoint activity monitors (such as command-line logging) may capture sensitive tokens or personal credentials if they were improperly executed in clear text on the monitored endpoint. Customers are responsible for configuring agent ignore/masking rules for high-risk directories.
2.3 Web Platform & Usage Information
When you interact with the DotlyGuard dashboard or marketing website, we automatically collect:
Log & Device Data: Browser user-agent, operating system, referrer URLs, IP-derived approximate geolocation (city/country level), session duration, and clickstream navigation.
Operational Diagnostics: Crash logs, dashboard latency metrics, API rate-limit utilization, and error traces.
2.4 Communications
If you submit a support ticket or contact our security research team, we record your contact history, submitted ticket details, system diagnostics, and file attachments provided during remediation.
3. How We Use Your Information
We process collected information to:
Provide and Maintain the Platform: Provision tenant instances, verify administrative logins, establish agent-to-server TLS handshakes, and route alerts.
Process Threat Detections: Parse and correlate logs across endpoints to alert you to indicators of compromise (IoCs), rootkits, unauthorized privilege escalations, and anomalous network connections.
Account Administration & Billing: Process renewals, calculate device-tier usage, collect subscription fees, and send invoice receipts.
Security & System Integrity: Detect malicious tampering, mitigate denial-of-service attempts against our APIs, and ensure cloud infrastructure uptime.
Customer Support: Troubleshoot agent build issues, assist with deployment automation, and investigate reported bugs.
Legal & Regulatory Compliance: Enforce our Terms and Conditions, satisfy tax/audit demands, and comply with valid law enforcement subpoenas.
4. Legal Bases for Processing (EEA/UK Individuals)
If you reside in the European Economic Area (EEA), United Kingdom, or Switzerland, our legal bases under the GDPR for collecting and processing your personal data include:
Performance of a Contract (GDPR Art. 6(1)(b)): Providing the Service, managing administrative credentials, and executing subscription commitments.
Legitimate Interests (GDPR Art. 6(1)(f)): Securing our infrastructure, refining detection heuristics, preventing platform fraud, and analyzing product performance.
Compliance with Legal Obligations (GDPR Art. 6(1)(c)): Retaining billing records for statutory tax audits and answering court directives.
Consent (GDPR Art. 6(1)(a)): Where you have affirmatively consented to non-essential cookies, web beacons, or direct promotional materials (which you may withdraw at any time).
5. Cookies and Tracking Technologies
We use strictly necessary and performance-oriented cookies:
Strictly Necessary Cookies: Essential for session state persistence, CSRF protection, and dashboard authentication. The platform cannot function properly without these.
Analytics & Performance Cookies: Help us aggregate anonymized traffic patterns to understand dashboard usage and resolve navigation bottlenecks.
You can configure your browser to reject non-essential cookies; however, disabling certain cookies may impact platform navigation and session stability.
6. Disclosure and Sharing of Information
DotlyGuard does not sell, rent, or trade your personal information. We disclose data solely within these parameters:
Authorized Sub-processors and Cloud Infrastructure: We rely on vetted third parties for secure hosting, database orchestration, email dispatch, and billing operations (e.g., AWS, GCP, Stripe). All sub-processors are bound by strict contractual data-protection standards and confidentiality obligations.
Corporate Transactions: If Apex Cloud Tech LLC undergoes a merger, acquisition, corporate reorganization, asset sale, or bankruptcy proceeding, customer records and telemetry may be transferred as an acquired business asset under equivalent confidentiality assurances.
Legal Enforcement & Safety: We may disclose information if required to do so by applicable law, search warrant, court order, or regulatory summons, or when necessary to protect the life, safety, or fundamental property rights of DotlyGuard, our customers, or the public.
With Your Explicit Direction: When you authorize external integrations, webhooks, or third-party SIEM/SOAR connections through our API.
7. Global Data Transfers
Apex Cloud Tech LLC may host, process, and route customer data through infrastructure distributed across the United States and other global regions.
When we transfer personal data subject to European, UK, or Swiss data-protection frameworks outside those territories, we ensure adequate protections are implemented through:
Transferring to countries recognized by the European Commission as offering an adequate level of data protection.
Executing approved Standard Contractual Clauses (SCCs) or the UK International Data Transfer Addendum (IDTA).
Enforcing supplementary technical safeguards, including end-to-end cryptographic transit protections.
8. Data Security and Technical Safeguards
We implement defense-in-depth security measures designed to safeguard personal data and security telemetry:
Encryption Standards: Data in transit is protected using TLS 1.3/TLS 1.2; sensitive database fields and stored telemetry archives are encrypted at rest using AES-256.
Access Controls: Production infrastructure access is restricted via role-based access controls (RBAC), multi-factor authentication (MFA), and audited bastion layers.
Vulnerability Management: Periodic automated vulnerability assessments, container scanning, and internal patch management routines.
Note: No internet transmission or storage platform is completely impenetrable. You remain responsible for keeping your administrative credentials confidential and ensuring endpoint security configurations comply with internal policies.
9. Data Retention and Account Deletion
Operational Telemetry: Monitored endpoint logs, system activity records, and event alerts are retained for the duration specified in your subscription plan tier (e.g., 30, 90, or 365 days) and subsequently purged via automated rolling pipelines.
Account Records: Administrative profile data, invoices, and transaction histories are retained for as long as your account remains active, and thereafter as necessary to satisfy statutory tax, accounting, and legal requirements.
Data Retrieval on Termination: Following account termination, telemetry data is retained in a dormant state for thirty (30) days to allow for final administrative exports. Following this 30-day window, records are queued for irreversible cryptographic deletion or overwriting.
10. Aggregated Threat Intelligence and Heuristics
DotlyGuard may generate de-identified, anonymized, and aggregated statistical records from processed security metadata (such as file hashes, malware signatures, network indicators of compromise, and rule-matching frequencies).
We use this aggregated data to publish cybersecurity threat research, train detection heuristics, and improve global endpoint defenses. This aggregated data cannot be reverse-engineered to identify you, your organization, or any individual.
11. Your Privacy Rights
Depending on your jurisdiction (including the EEA, UK, Switzerland, California, and other US states with comprehensive privacy legislation), you may have the following rights:
Right of Access / Portability: Obtain confirmation of processing and request a portable copy of your personal data.
Right to Rectification: Request correction of inaccurate or incomplete personal information.
Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to statutory retention exemptions.
Right to Restrict or Object to Processing: Request that we pause or limit processing under specific circumstances, or object to processing founded upon legitimate interests.
Right to Withdraw Consent: Revoke previously granted consent without affecting the lawfulness of prior processing.
To exercise these rights, email [email protected]. We will authenticate your administrative identity before processing substantive account changes. You may also lodge a complaint with your local data protection supervisory authority.
12. California & US State Privacy Disclosures (CCPA / CPRA)
Under the California Consumer Privacy Act (CCPA/CPRA) and related state frameworks:
No Sale or Sharing: DotlyGuard does not "sell" your personal information, nor do we "share" personal information for cross-context behavioral advertising.
Categories Collected: Identifiers (names, emails, IP addresses), commercial information (purchase history), internet activity (telemetry, console interactions), and professional information (company affiliations).
Non-Discrimination: We will not discriminate against you, deny services, charge different prices, or alter service levels because you exercised your statutory privacy rights.
13. Children's Privacy
DotlyGuard is strictly an enterprise B2B and professional IT infrastructure service. It is not intended for or directed toward individuals under the age of 18. We do not knowingly collect personal data from minors. If you discover that a child has provided us with personal information, contact us immediately at [email protected] to initiate prompt deletion.
14. Changes to This Privacy Policy
We may periodically revise this Privacy Policy to reflect modifications to the Service, operational requirements, or applicable privacy statutes. When changes are made, the "Last Updated" date at the top of this document will be amended. For material changes, we will provide advance notification through your administrative dashboard or via direct email.
15. Contact and Data Protection Inquiries
For questions, Data Subject Access Requests (DSARs), or Data Processing Addendum (DPA) inquiries, contact our privacy team at:
Entity: Apex Cloud Tech LLC
Attention: Privacy & Data Protection Officer
Email: [email protected]
Address
Unit No. A1518 312 W 2nd St, Casper, WY 82601 United States