GDPR & Data Privacy
ApexCharts is committed to protecting personal data and complying with the General Data Protection Regulation (GDPR) (EU) 2016/679, as well as other applicable privacy laws. This page explains how we handle personal data in connection with our products and services.
Our Role Under GDPR
ApexCharts occupies distinct roles depending on the context:
As a Data Controller
When you visit our website, create an account, or purchase a license, ApexCharts acts as a Data Controller for the personal data you provide (such as name, email address, billing information, and support communications). We determine the purposes and means of processing this data.
As a Data Processor
ApexCharts is primarily a client-side JavaScript library. When you integrate ApexCharts into your own product or platform, ApexCharts code runs entirely within your users’ browsers and does not transmit any end-user data to ApexCharts servers. In this capacity, ApexCharts does not act as a Data Processor for your end users’ data.
However, if you use ApexCharts support services or share any personal data with us in the course of a support engagement, ApexCharts may act as a Data Processor for that data, subject to a Data Processing Agreement.
Personal Data We Collect and Process
When you are a customer or prospective customer of ApexCharts, we may process the following categories of personal data:
Contact Information
- Name, email address, company name, job title, postal address, and telephone number.
- Used to manage your account, provide support, and communicate about your license.
Billing and Transaction Data
- Invoice details and payment confirmation records.
- Payment card data is processed directly by our payment provider, Stripe, and is not stored on ApexCharts systems.
Account and Usage Data
- Login credentials (email and hashed password), subscription status, license keys, and account activity logs.
Support Communications
- Content of emails, support tickets, and any files or data shared with our support team in the course of resolving a technical issue.
Website Usage Data
- Anonymized analytics tracked with Google Analytics.
Legal Basis for Processing
We process personal data on the following legal bases:
Contract Performance (Art. 6(1)(b) GDPR)
- Processing your name, email, and billing data to deliver the services you have purchased and to fulfil our contractual obligations.
Legitimate Interests (Art. 6(1)(f) GDPR)
- Maintaining security, preventing fraud, and improving our products.
Legal Obligation (Art. 6(1)(c) GDPR)
- Retaining billing and transaction records as required by applicable tax and accounting law.
Consent (Art. 6(1)(a) GDPR)
- Where you have opted in to receive marketing communications. You may withdraw consent at any time.
Data Retention
- Account data is retained for the duration of your account plus 12 months after account closure.
- Billing records are retained for 12 months to comply with legal obligations.
- Support communications are retained for 3 years.
- Where data is no longer needed, it is securely deleted or anonymised.
Data Transfers
ApexCharts operates from the United States. If we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy decisions where applicable.
Our key sub-processors are listed in the section below.
Sub-Processors
ApexCharts uses the following third-party sub-processors to deliver its services. All sub-processors are bound by data processing agreements and provide appropriate guarantees regarding data protection.
| Sub-Processor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | USA / EU |
| AWS / GCP | Hosting & infrastructure | USA |
| GitHub | Source code management | USA |
| Zendesk | Customer support | USA |
| Zoho Email | Transactional email | USA |
Your Rights
As a data subject under GDPR, you have the following rights:
Right of Access (Art. 15)
- Request a copy of the personal data we hold about you.
Right to Rectification (Art. 16)
- Request correction of inaccurate or incomplete personal data.
Right to Erasure (Art. 17)
- Request deletion of your personal data (“right to be forgotten”), subject to legal retention obligations.
Right to Restriction (Art. 18)
- Request that we limit the processing of your personal data in certain circumstances.
Right to Data Portability (Art. 20)
- Request that we provide your data in a structured, machine-readable format.
Right to Object (Art. 21)
- Object to processing based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent (Art. 7(3))
- Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, contact us at: privacy@apexcharts.com
We will respond within 30 days of receiving your request. We may ask you to verify your identity before processing the request.
If you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority.
Data Processing Agreement (DPA)
Customers may request our Data Processing Agreement (DPA). We will provide our standard DPA upon request. Please contact privacy@apexcharts.com to request a copy.
Data Protection Contact
For privacy-related questions or to exercise your rights, please contact: privacy@apexcharts.com

Please wait...