Privacy Policy

Last updated: 1 August 2026

1. Introduction and Scope

This Privacy Policy explains how Apex Circle (“we”, “us”, “our”) collects, uses, shares, and protects personal data belonging to applicants, Members, Event attendees, and visitors to our website (“you”).

This Policy applies alongside our Terms and Conditions and any Event-specific waiver or risk acknowledgment form you complete. Where those documents contain additional detail about a specific type of processing (for example, photography consent), that detail applies in addition to this Policy.

1.1 We are the data controller for the personal data described in this Policy for the purposes of the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.

1.2 Where an Event is delivered by an independent third-party activity provider (for example, a speedboat charter company, karting circuit, or indoor skydiving centre), that provider will typically also be a separate data controller for the information it collects directly from you on-site, such as its own waiver form. Its use of your data is governed by its own privacy notice, which we encourage you to read before the Event.

2. Information We Collect

The table below sets out the main categories of personal data we collect and where each comes from.

Category of dataExamplesWhere it comes from
Identity and contact dataName, email address, phone number, city/location, LinkedIn or company details provided on applicationDirectly from you, via our website and app
Application and profiling dataFounder stage, industry, motivation for joining, responses to admissions questionsDirectly from you, via progressive profiling in our email sequence and application forms
Membership and payment dataMembership tier, fees paid, invoices, transaction recordsDirectly from you and from our payment processor (we do not store full card numbers)
Health and fitness informationAny medical condition, injury, pregnancy, or fitness limitation you disclose that is relevant to your safe participation in an EventDirectly from you, via a specific health/risk disclosure question or on-site waiver form — provided only with your explicit consent
Event and attendance dataWhich Events you registered for or attended, squad groupings, Apex Points and badges earnedGenerated internally when you register for and attend Events
Photographs and videoImages and footage captured at Events in which you may appearCaptured by us or a photographer/videographer at the Event, per Section 7 of our Terms
Communications dataEmails, WhatsApp or Instagram DM messages, and other correspondence with usDirectly from you, and via our email provider, messaging, and DM outreach tools
Technical and usage dataIP address, browser type, device information, pages visited, cookies and similar identifiersAutomatically, via our website and analytics tools
Marketing and advertising dataAd interactions, campaign source, engagement with our Instagram, Meta, and email contentAutomatically, via Meta advertising tools and our email provider, and directly from your interactions with our content

We do not intentionally collect personal data from anyone under the age of 18. Membership is restricted to adults — see Section 1.2 of our Terms and Conditions.

3. How We Use Your Information and Our Legal Basis

Under UK GDPR, we must have a valid legal basis for each way we use your personal data. The table below sets out our main purposes and the basis we rely on.

PurposeOur legal basis
Processing your application and admitting you as a MemberNecessary to take steps at your request before entering into a contract with you, and to perform that contract
Organising and delivering Events you register for, including sharing necessary details with third-party activity providersPerformance of a contract with you
Assessing your fitness and safety to participate in a specific Event based on health information you discloseExplicit consent (Article 9 UK GDPR, as this is special category data) — see Section 4
Processing payments and maintaining financial recordsPerformance of a contract, and compliance with our legal obligations (tax and accounting)
Sending you membership and Event-related emails (confirmations, logistics, safety information)Performance of a contract / legitimate interests in running the community
Sending you marketing emails, waitlist nurture sequences, and Instagram/DM outreachConsent (for prospective Members and non-customers) or legitimate interests / soft opt-in (for existing Members and applicants, where permitted under PECR)
Running targeted advertising campaigns (Meta, Instagram)Consent, via the cookie and advertising choices you make and Meta’s own consent tools
Using photographs/video from Events for marketingConsent, as set out in Section 7 of our Terms and Conditions
Improving our website, community, and Event offering; internal analyticsLegitimate interests in understanding and improving our services
Preventing fraud, enforcing our Terms, and resolving disputesLegitimate interests / compliance with legal obligations

Where we rely on ‘legitimate interests’, we have considered that our interest in running a curated, safe, and well-organised community is not overridden by your own rights and interests, and you can object at any time — see Section 8.

4. Special Category Data: Health Information

4.1 We ask you to disclose relevant medical conditions, injuries, or fitness limitations before certain Events, as described in Section 3.5 of our Terms and Conditions. We only do this where relevant to a specific activity, and we rely on your explicit consent as our Article 9 condition for processing this information.

4.2 You are free to withhold this information, but doing so may mean we or a third-party activity provider cannot allow you to safely participate in the relevant Event.

4.3 We share health information with the relevant third-party activity provider strictly on a need-to-know basis, limited to what is necessary for them to assess your safety to participate. Health information you disclose is stored in our application database with restricted access. We do not use health information for any marketing purpose, and we do not include it in general Member profiles beyond what is necessary for the specific Event.

4.4 We retain health information for no longer than necessary for the Event and any immediate follow-up (such as an insurance or incident report), after which it is deleted or anonymised in accordance with Section 9.

4.5 If you wear or reference data from a fitness or wellness device (for example, a wearable ring or watch) in conversation with us, we do not systematically collect or store that data unless you provide it to us directly and explicitly for a stated purpose.

5. Who We Share Your Data With

We share personal data with the following categories of recipient, each acting either as our data processor (acting on our instructions) or as an independent controller in their own right:

  • Third-party activity providers (speedboat, karting, ice bath, indoor skydiving operators) — limited Event and, where relevant and consented to, health information necessary to deliver the activity safely (independent controllers for their own on-site processing);
  • Our application hosting and database provider — stores Member, application, Event, and (where consented to) health data on our behalf, and hosts the website and app you interact with (data processor);
  • Our email delivery provider — used to send transactional emails (confirmations, receipts) and marketing/nurture communications (data processor);
  • Stripe — our payment processor, used to process membership and Event payments; Stripe also acts as an independent controller for its own regulatory and fraud-prevention purposes (we do not store full card details ourselves);
  • AI-assisted application review tools — where we use an AI service to help review or summarise applications as described in Section 10, limited application data may be processed for this purpose. This data is not used to train the underlying AI provider’s models by default (data processor);
  • Meta (Instagram/Facebook) — used for advertising and audience targeting; certain technical and engagement data is shared with Meta as an independent controller under its own terms;
  • Messaging and outreach tools — including WhatsApp Business and Instagram direct messaging, used for Event logistics and outreach;
  • Professional advisers and insurers — where necessary to obtain advice, arrange event insurance, or handle an incident or claim;
  • Regulators, law enforcement, or courts — where we are legally required to disclose data, or to protect our rights, property, or safety, or that of others.

We require our processors to implement appropriate technical and organisational measures to protect your data and to only process it on our documented instructions. A full, up-to-date list of our specific sub-processors is available on request — see Section 14.

6. International Data Transfers

Several of the third-party providers we use for hosting, application infrastructure, email delivery, payments, and advertising may store or process personal data outside the UK, including in the United States or other jurisdictions where their infrastructure is located. Where this occurs, we rely on recognised safeguards, such as the UK’s data protection adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, to ensure your data continues to receive an appropriate level of protection.

7. Cookies and Similar Technologies

Our website uses cookies and similar technologies to operate correctly, remember your preferences, measure site usage, and support advertising, including Meta’s tracking pixel where enabled.

  • Strictly necessary cookies are used to operate core website functionality and do not require consent.
  • Analytics and advertising cookies (including any Meta pixel) are only set with your consent, given via our cookie banner, which you can withdraw at any time through your browser or cookie settings.

8. Data Retention

We keep personal data only for as long as necessary for the purposes described in this Policy, taking into account:

  • Applicant data for unsuccessful or non-converting applicants: up to 12 months, after which it is deleted unless you re-engage;
  • Active Member and Event data: for the duration of your membership and a reasonable period afterwards for record-keeping, dispute resolution, and re-engagement;
  • Financial records: as required by UK tax law, generally 6 years from the end of the relevant financial year;
  • Health information disclosed for a specific Event: deleted or anonymised shortly after the Event and any related follow-up, per Section 4.4;
  • Marketing data: until you unsubscribe or object, or after a period of prolonged inactivity, whichever is sooner.

9. Your Rights

Under UK GDPR, you have the following rights in relation to your personal data, subject to certain exemptions:

  • Right of access — to obtain a copy of the personal data we hold about you;
  • Right to rectification — to have inaccurate or incomplete data corrected;
  • Right to erasure — to have your data deleted in certain circumstances;
  • Right to restrict processing — to limit how we use your data in certain circumstances;
  • Right to data portability — to receive certain data in a portable format;
  • Right to object — to object to processing based on legitimate interests, and to object to direct marketing at any time, free of charge;
  • Right to withdraw consent — where we rely on consent (including for health information or marketing), you may withdraw it at any time without affecting the lawfulness of processing before withdrawal;
  • Right to complain — to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113, although we would welcome the chance to address your concern directly first.

To exercise any of these rights, contact us at info@apexcircle.nl. We will respond within one month, as required by law.

10. Automated Decision-Making

We use AI-assisted tools to help review, summarise, or shortlist applications. This assists our team but does not replace it: a human always reviews and makes the final decision on membership admission. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing without human involvement.

11. Security

We use appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction, including access controls, secure processors, and, for special category data, additional care around who within our team can access it. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours where required, and will notify you directly where the breach is likely to result in a high risk to you.

12. Children

Apex Circle membership and Events are restricted to adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If we become aware that we have inadvertently collected data from a minor, we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will post the updated version on our website with a revised “Last updated” date, and will notify active Members directly of any material change where reasonably practicable.

14. Contact Us

If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at info@apexcircle.nl.