APEX Narrative Group ← Back to site

Legal

Privacy Policy

Effective[EFFECTIVE DATE]
Last updatedAugust 27, 2026
Applies toapexnarrativegroup.com

01 Who We Are and What This Policy Covers

Apex Narrative Group (“Apex,” “we,” “us,” “our”) is a marketing, communications and digital growth agency operating as [LEGAL ENTITY NAME, e.g. Apex Narrative Group LLC, a Florida limited liability company], with its principal place of business at [STREET ADDRESS, CITY, FL ZIP].

This Privacy Policy explains how we handle personal information when you visit apexnarrativegroup.com, submit a form, request a marketing audit, schedule a strategy call, subscribe to our communications, apply for a role, or otherwise interact with us.

We handle data in two different capacities

This distinction matters, because different rules apply to each.

  • As a controller (our own data). When we collect information about you through this website, our marketing, or our sales process, we decide why and how it is used. This Policy governs that activity.
  • As a service provider or processor (our clients' data). When we build, host or manage marketing systems for a client, we handle information about that client's customers, patients and prospects on the client's instructions. We do not own that data and we do not use it for our own purposes. Our handling of it is governed by our written agreement with that client — including, where applicable, a Data Processing Addendum or a HIPAA Business Associate Agreement — and by that client's privacy policy, not this one.

If you are a patient, customer or prospect of one of our clients and you want to access, correct or delete your information, please contact that organization directly. They are the controller of that data. If you contact us, we will refer your request to them and assist them in responding, but we cannot act on it independently.

02 Information We Collect

Information you give us

  • Identity and contact data — name, company, job title, business email address, telephone number, mailing address.
  • Engagement data — your website URL, your stated marketing challenge, your approximate marketing budget range, and any other detail you choose to include in a form, email or call.
  • Communications — the content of emails, text messages, form submissions, chat messages, and notes or recordings from calls and meetings (where recording is disclosed and permitted).
  • Consent records — the exact disclosure text you agreed to, the boxes you checked, the phone number and email address you authorized, and the date, time, IP address and page URL at the moment you submitted it.
  • Recruitment data — if you apply to work with us, your résumé, work history, portfolio and any information you volunteer.

Information collected automatically

  • Device and connection data — IP address, browser type and version, operating system, device type, screen size, language and general location inferred from IP (typically city or region level).
  • Usage data — pages viewed, time on page, scroll depth, referring URL, exit pages, links and buttons clicked, form starts and completions.
  • Campaign identifiers — UTM parameters, click identifiers such as gclid or fbclid, and similar tags that tell us which campaign brought you here.
  • Cookies and similar technologies — described in our Cookie Policy.

Information from other sources

  • Business contact and firmographic data from commercial data providers and public sources.
  • Publicly available professional profiles and company information.
  • Advertising and analytics platforms, which report aggregated campaign performance to us.
  • Referrals, introductions and event or webinar registration lists.

Information we do not want

Please do not send us sensitive personal information through our website forms. That includes government identifiers, financial account numbers, precise geolocation, biometric data, and health or medical information about yourself or any identifiable individual. Our public web forms are not a HIPAA-compliant channel and must not be used to transmit protected health information. If you need to send us sensitive material in the course of an engagement, ask us for a secure channel.

03 How We Use Information

PurposeWhat this looks like in practice
Responding to youAnswering an inquiry, scheduling a strategy call, preparing and delivering a requested marketing audit.
Providing servicesPerforming work under a signed agreement, project communications, invoicing and account administration.
Marketing our own servicesSending newsletters, insights, event invitations and offers by email; sending text messages where you have separately opted in; running and measuring advertising.
Operating and improving the siteAnalytics, performance monitoring, testing, debugging, and improving content and conversion paths.
Security and fraud preventionDetecting bot submissions, abuse, and unauthorized access; maintaining logs.
Legal and complianceMaintaining consent and opt-out records, responding to legal process, enforcing our terms, establishing or defending legal claims.
RecruitmentEvaluating applications and communicating with candidates.

Automated decision-making

We do not make decisions that produce legal or similarly significant effects about you using solely automated processing. We do use routine lead scoring and segmentation to prioritize outreach; a person reviews any consequential decision.

Artificial intelligence

We use AI-assisted tools in producing creative, copy and analysis. We do not submit personal information to public, consumer-grade AI tools that train on submitted content, and we require enterprise terms that prohibit training on our inputs where personal information may be present.

If you are located in the European Economic Area, the United Kingdom or Switzerland, we rely on the following legal bases under the GDPR and UK GDPR:

  • Consent — for non-essential cookies, marketing email and SMS, and any use of sensitive data. You may withdraw consent at any time without affecting prior processing.
  • Contract — to take steps at your request before entering into a contract, and to perform a contract with you or your organization.
  • Legitimate interests — to operate and secure our site, to understand how it is used, to pursue business-to-business relationships, and to protect our legal rights, where those interests are not overridden by your rights.
  • Legal obligation — to comply with applicable law, including record-keeping obligations relating to consent and opt-outs.

05 How We Share Information

We do not sell personal information for money. We share it only as described below.

Service providers and subprocessors

We use vendors to run our business. Each is bound by contract to use the information only to provide services to us. Categories include:

  • Website hosting, content delivery and domain infrastructure
  • Customer relationship management and marketing automation
  • Email delivery and newsletter platforms
  • SMS and messaging platforms
  • Analytics and conversion measurement
  • Advertising platforms and tag management
  • Scheduling, video conferencing and call recording
  • Cloud storage, productivity and project management
  • Payment processing and accounting
  • Security, spam filtering and bot detection

A current list of our subprocessors is available on request at privacy@apexnarrativegroup.com.

Advertising and analytics partners

We use advertising and analytics technologies from third parties, which may set cookies or receive device identifiers and usage data directly. Under some state privacy laws, this activity may be treated as a “sale” or as “sharing” for cross-context behavioral advertising or targeted advertising, even though no money changes hands. You can opt out — see Your Privacy Rights and our Cookie Policy.

Professional advisors and corporate transactions

We may disclose information to our lawyers, accountants, auditors and insurers, and in connection with a merger, acquisition, financing or sale of assets, subject to confidentiality obligations.

Legal and safety

We may disclose information where we believe in good faith that it is required by law, subpoena or other legal process, or necessary to protect the rights, property or safety of Apex, our clients, our personnel or the public.

With your direction

We share information with others when you ask us to, including introductions to partners or vendors.

06 Cookies, Tracking and Global Privacy Control

We use cookies, pixels, tags, local storage and similar technologies. Categories, named vendors and your control options are set out in our Cookie Policy.

Global Privacy Control

We recognize the Global Privacy Control (GPC) browser signal. When we detect a GPC signal, we treat it as a valid request to opt out of the sale and sharing of personal information and of targeted advertising for that browser. Because the signal is browser-specific, it does not automatically apply across your other devices, and it will not identify you to us by name unless you are logged in or identified to us.

Do Not Track

Browsers may transmit a “Do Not Track” signal. There is no common industry standard for responding to it, and we do not currently respond to DNT. We do respond to GPC, as described above.

07 How Long We Keep Information

We keep personal information only as long as we need it, then delete or de-identify it. In general:

CategoryTypical retention
Inquiry and audit request records[24 months] from last contact, unless an engagement follows
Client engagement recordsTerm of the engagement plus [7 years], for contract, tax and defense purposes
Email and SMS marketing listsUntil you unsubscribe or opt out, then a suppression record is kept indefinitely so we do not contact you again
Consent and opt-out recordsAt least 5 years from the date of consent or opt-out, as evidence of compliance
Website analytics[14 months] at the event level; aggregate reporting may be kept longer
Job applications[12 months] from the close of the role, unless you ask us to keep it on file

We may retain information longer where required by law or where it is subject to a litigation hold.

08 Security

We maintain administrative, technical and physical safeguards designed to protect personal information, including encryption in transit, access controls on a least-privilege basis, multi-factor authentication on business systems, vendor due diligence, and periodic review of access.

No system is perfectly secure. We cannot guarantee that unauthorized access will never occur. If we experience a breach of security affecting personal information, we will notify affected individuals and regulators as required by applicable law, including the Florida Information Protection Act, Fla. Stat. § 501.171.

Email and text message are not secure channels. Please do not use them to send confidential, financial or health information.

09 Your Privacy Rights

Rights available depending on where you live

Depending on your state or country of residence, you may have some or all of the following rights:

  • Know and access — confirm whether we process your personal information and obtain a copy.
  • Correct — fix inaccurate personal information.
  • Delete — request deletion, subject to legal exceptions.
  • Portability — receive your data in a portable, machine-readable format.
  • Opt out — of targeted advertising, of the sale or sharing of personal information, and of profiling that produces legal or similarly significant effects.
  • Limit sensitive data — restrict use of sensitive personal information (California) or withhold consent to it (most other states).
  • Non-discrimination — we will not deny service, charge a different price or provide a different quality of service because you exercised a privacy right.
  • Appeal — if we decline your request, you may appeal (see below).

How to make a request

Email: privacy@apexnarrativegroup.com

Mail: Apex Narrative Group, Attn: Privacy, [STREET ADDRESS, CITY, FL ZIP]

Phone: [TOLL-FREE NUMBER]

Web form: apexnarrativegroup.com/privacy-request

We will acknowledge your request promptly and respond within 45 days, with one 45-day extension where reasonably necessary (we will tell you if we need it). We must verify your identity before acting, which typically means confirming control of the email address or phone number associated with the data. We will not ask you to create an account to make a request.

Authorized agents

You may use an authorized agent. We will require written proof of authorization signed by you and may separately verify your identity, except where the agent provides a valid power of attorney.

Appeals

If we deny your request, you may appeal by replying to our decision or writing to privacy@apexnarrativegroup.com with “Privacy Appeal” in the subject line. We will respond within 45 days (or 60 days where your state allows) explaining our decision. If your appeal is denied, you may contact your state Attorney General.

Opting out of marketing

  • Email — click the unsubscribe link in any marketing email, or email us. We honor opt-outs promptly and in all cases within 10 business days, as required by the CAN-SPAM Act.
  • Text messages — reply STOP to any message. See our SMS Terms.
  • Advertising cookies — use our cookie preferences control or enable Global Privacy Control in your browser.
  • Transactional messages — if you are an active client, we may still send non-marketing messages about your engagement.

10 State-Specific Notices

California

Under the California Consumer Privacy Act as amended (CCPA/CPRA), we disclose the following about the preceding 12 months:

Category (Cal. Civ. Code § 1798.140)CollectedDisclosed for a business purposeSold or shared
Identifiers (name, email, phone, IP, cookie IDs)YesYesYes — cookie and device identifiers for cross-context behavioral advertising
Customer records (§ 1798.80) such as business addressYesYesNo
Commercial information (services inquired about, budget range)YesYesNo
Internet or network activityYesYesYes
Geolocation (coarse, from IP)YesYesNo
Audio or visual (call and meeting recordings, where disclosed)YesYesNo
Professional or employment informationYesYesNo
Inferences (segments, lead scores)YesYesNo
Sensitive personal informationNo — we do not seek itNo
Biometric informationNoNo

We do not knowingly sell or share the personal information of consumers under 16 years of age. We do not use or disclose sensitive personal information for purposes requiring a right to limit under § 1798.121. To exercise your right to opt out, use the cookie preferences control or enable Global Privacy Control.

Shine the Light. California residents may request information about disclosure of personal information to third parties for their direct marketing purposes. We do not make such disclosures. Requests: privacy@apexnarrativegroup.com.

Florida

The Florida Digital Bill of Rights (Fla. Stat. § 501.702) applies to entities meeting a $1 billion global revenue threshold. Apex does not meet that threshold and is not a “controller” under the FDBR. We nonetheless extend the access, correction, deletion, portability and opt-out rights described above to Florida residents as a matter of practice. Separately, we are subject to the Florida Information Protection Act, Fla. Stat. § 501.171, governing data security and breach notification.

Other states

Residents of Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia have comprehensive privacy rights under their respective state laws. We honor the rights and appeal process described in Section 09 for residents of every state with a comprehensive privacy law, regardless of whether we meet that state's applicability threshold.

Texas and Nebraska residents: we may share personal data with third parties for targeted advertising. You may opt out as described above.

Nevada

Nevada residents may direct us not to sell certain covered information as defined by NRS 603A.340 by emailing privacy@apexnarrativegroup.com. We do not currently engage in such sales.

Washington and Nevada health data

We do not collect consumer health data as defined by the Washington My Health My Data Act or Nevada SB 370, and we do not operate this website as a health service.

11 Health Information and HIPAA

Apex serves healthcare organizations, medical practices and longevity companies. When we handle protected health information (PHI) on behalf of a covered entity, we act as a Business Associate under the Health Insurance Portability and Accountability Act, and that handling is governed by a written Business Associate Agreement with the client — not by this Privacy Policy.

In that role we:

  • Use and disclose PHI only as permitted by the BAA and by law;
  • Apply the HIPAA Security Rule safeguards to electronic PHI;
  • Execute BAAs with any subcontractor that may encounter PHI;
  • Report security incidents and breaches to the covered entity as required; and
  • Do not use PHI for our own marketing.

This website does not collect PHI. Information you submit through our forms is business contact information about you in your professional capacity. Do not submit patient information, medical records or health details through this site.

12 International Transfers

We are based in the United States and our vendors are primarily located in the United States. If you access this site from outside the U.S., your information will be transferred to, stored in and processed in the United States, where data protection law may differ from your jurisdiction.

Where we transfer personal data from the EEA, UK or Switzerland to the United States, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures where appropriate. You may request a copy of the relevant safeguards at privacy@apexnarrativegroup.com.

EEA and UK residents may lodge a complaint with their local supervisory authority. UK residents may contact the Information Commissioner's Office at ico.org.uk.

13 Children's Privacy

This website is directed to businesses and professionals. It is not intended for children. We do not knowingly collect personal information from anyone under 16, and we do not knowingly sell or share the personal information of anyone under 16.

If you believe a child has provided us with personal information, contact privacy@apexnarrativegroup.com and we will delete it.

14 Third-Party Sites and Social Media

Our website and our communications may link to third-party sites, including client websites and our own profiles on LinkedIn, Instagram and Facebook. We do not control those services and are not responsible for their content or privacy practices. Their own privacy policies apply once you leave our site.

15 Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of the page. If we make a material change to how we use personal information, we will provide additional notice — by email, by a notice on this site, or as otherwise required by law — before the change takes effect.

Prior versions are available on request.

16 Contact Us

Apex Narrative Group[LEGAL ENTITY NAME]

Attn: Privacy

[STREET ADDRESS]

[CITY], Florida [ZIP]

Email: privacy@apexnarrativegroup.com

General: hello@apexnarrativegroup.com

Phone: [PHONE]

For UK and EU inquiries, our representative is [APPOINT AN ARTICLE 27 REPRESENTATIVE IF YOU MARKET INTO THE EEA/UK, OR DELETE THIS LINE].