Privacy Policy
Last updated: 12 August 2026
In plain English: Your data is stored on secure cloud infrastructure with encryption and access controls. We share it only with trusted service providers who help us run the service under confidentiality obligations, or where required by law. We never sell or rent your data.
1. About This Policy
Apex Secure Tech ("Apex", "we", "us", "our") respects your privacy. This Privacy Policy explains how we collect, use, store, disclose, and protect personal information when you or your organisation use our vape detection, camera, and school security products, our dashboard, mobile application, and website (collectively, the "Service").
This policy applies to Australian users under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and to United Kingdom users under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Who We Are
Apex Secure Tech is the trading name of Mosh Support Pty Ltd, an Australian-owned company.
- ABN: 38 672 919 630
- Email: contact@apexsecuretech.com
- Phone: 0473 415 509
- Website: https://apexsecuretech.com
For the purposes of the UK GDPR, we act as a data processor on behalf of the schools that use our Service. The school is the data controller. For information we collect directly (e.g., website enquiries), we act as a data controller.
3. What Information We Collect
3.1 Information you provide to us
- Name, email address, phone number, school name, role
- Enquiry or support message content
- Account credentials for authorised administrators and staff users
- Billing and payment information (processed by our payment provider — we do not store card details)
3.2 Information collected via our devices and platform
- Device identifiers, firmware version, connection status
- Environmental sensor readings from our vape detectors (PM2.5 particulate matter, TVOC, dedicated vape signature readings, CO₂, temperature, humidity, and device battery level)
- Alert events (timestamp, location descriptor set by the school, event type)
- Camera footage from Apex cameras deployed in common areas at your school (bathrooms, dorms, and other private spaces are never within camera coverage)
- Dashboard usage logs, IP address, browser type, session duration
3.3 What we do NOT collect
- We do not capture audio inside the vape detectors — there are no microphones inside the units
- We do not identify individual students from detector data — our sensors detect vape events by location, not by person
- We do not use facial recognition in our camera systems
4. Why We Collect It (Purpose and Lawful Basis)
We collect and process personal information to:
- Deliver the Service to your school (contract performance)
- Provide alerts, dashboards, and reporting to authorised staff (legitimate interests / contract)
- Support installation, commissioning, and technical troubleshooting (contract)
- Improve our products and detection algorithms in aggregate, anonymised form (legitimate interests)
- Comply with legal, regulatory, and safety obligations (legal obligation)
- Respond to enquiries and provide customer support (contract / legitimate interests)
Under the UK GDPR, our lawful bases for processing are: performance of a contract, our legitimate interests in operating the Service, and compliance with legal obligations. Where we rely on consent, you can withdraw that consent at any time.
5. How We Store and Protect Information
Your data is stored on secure cloud infrastructure operated by our IoT platform provider. The provider uses industry-standard security controls, including:
- Encryption in transit (TLS 1.2+)
- Encryption at rest (AES-256)
- Role-based access controls
- Multi-factor authentication for administrator accounts
- Regular security assessments and penetration testing by the platform provider
Apex maintains internal controls including least-privilege access, audit logging, secure development practices, and staff confidentiality obligations.
6. Where Your Data Is Stored (Data Location)
Our IoT platform provider hosts customer data in secure regional data centres. For customers in Australia, New Zealand, the United Kingdom, and Europe, data is stored in Western Europe (Netherlands) or, for older accounts, Central Europe (Germany).
This data storage location applies to device telemetry, event logs, camera footage, and dashboard data. Apex's own internal business records (contracts, invoices, correspondence) are stored in Australia.
7. Cross-Border Data Disclosure
For Australian users (APP 8): By using the Service, you acknowledge that your data will be stored and processed outside Australia, in the Netherlands (or Germany for older accounts). Our platform provider is bound by strict contractual obligations including a Data Processing Agreement, and the European Union has data protection laws substantially similar to the Australian Privacy Principles.
For UK users: Your data is stored within Europe. Transfers between the UK and the EU are covered by the UK–EU adequacy decision and do not require additional safeguards. Where any transfer occurs outside the UK/EU, we use Standard Contractual Clauses or other approved safeguards.
8. Sub-Processors
To deliver the Service, we engage a limited number of trusted third-party service providers ("sub-processors"). These include:
- Our IoT platform and cloud infrastructure provider (for hosting, connectivity, data storage)
- Our payment processor (for handling billing)
- Our email and communication providers (for account emails, support responses)
- Our website hosting provider
All sub-processors are bound by written contracts requiring them to protect personal information consistent with this policy, the Australian Privacy Principles, and the UK GDPR.
A complete list of our current sub-processors is available on written request to contact@apexsecuretech.com. Schools and procurement teams can request this list to complete their vendor due-diligence.
9. Sharing Your Information
We do not sell, rent, or trade your personal information.
We only share personal information:
- With authorised staff at your school who have been granted access by an administrator
- With our sub-processors, under confidentiality obligations, to deliver the Service
- Where required by law, regulation, court order, or lawful government request
- To protect the rights, property, or safety of Apex, our customers, or the public
- In connection with a business sale, merger, or restructure, subject to the successor entity honouring this Privacy Policy
10. How Long We Keep Your Data
- Device alert events: retained for 12 months, then anonymised or deleted
- Camera footage: retained per your school's chosen storage plan (typically 7–30 days), then deleted
- Account information: retained while your school is an active customer + 12 months after account closure for support and legal purposes
- Billing records: retained for 7 years to comply with Australian tax and accounting law
- Support correspondence: retained for 2 years
When personal information is no longer needed, we securely delete or de-identify it in accordance with APP 11.
11. Your Rights
11.1 If you are in Australia
Under the Australian Privacy Principles you have the right to:
- Access the personal information we hold about you (APP 12)
- Request correction of inaccurate information (APP 13)
- Complain about our handling of your personal information
- Ask us not to use your information for direct marketing
11.2 If you are in the United Kingdom
Under the UK GDPR you have the right to:
- Access your personal data (right of access)
- Have inaccurate data corrected (right to rectification)
- Have your data deleted where lawful grounds exist (right to erasure)
- Restrict how we process your data
- Receive a copy of your data in a portable format (right to data portability)
- Object to processing based on our legitimate interests
- Withdraw consent at any time where consent is the lawful basis
- Lodge a complaint with the UK Information Commissioner's Office (ICO)
To exercise any of these rights, contact us at contact@apexsecuretech.com. We will respond within 30 days.
12. Children's Data
Our Service is deployed in schools, some of which include boarding facilities where minors reside. We take additional care with information that may relate to minors:
- Our detectors do not identify individual students — they detect environmental events by location only
- Cameras are deployed only in common areas by written agreement with the school; never in bathrooms, dorms, or private spaces
- The school (as data controller) is responsible for obtaining any parental consent required and for informing students about the presence of the Service
- Apex does not knowingly collect personal information directly from students
13. Data Breach Notification
Apex maintains an eligible data breach response process in line with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth) and, where applicable, Articles 33 and 34 of the UK GDPR.
If a data breach occurs that is likely to result in serious harm, we will:
- Notify the affected school as soon as practicable
- Report the breach to the Office of the Australian Information Commissioner (OAIC) within the required timeframe
- For UK data subjects, report to the ICO within 72 hours where legally required
- Provide affected individuals with information about the breach and steps they can take
14. Cookies and Website Tracking
Our website may use cookies and similar technologies to remember your preferences, understand how the site is used, and improve the experience. You can control cookies through your browser settings. Essential cookies (for account login and security) cannot be disabled without affecting functionality.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify affected users by email or through the Service. The date at the top of this policy shows when it was last updated.
16. Complaints
If you believe we have breached your privacy rights, please contact us first at contact@apexsecuretech.com. We will investigate and respond within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the relevant regulator:
- Australia: Office of the Australian Information Commissioner (OAIC) — https://www.oaic.gov.au
- United Kingdom: Information Commissioner's Office (ICO) — https://ico.org.uk
17. Contact Us
For any questions about this Privacy Policy or how we handle personal information:
Apex Secure Tech Email: contact@apexsecuretech.com Phone: 0473 415 509 Website: https://apexsecuretech.com
This Privacy Policy is governed by the laws of Australia (Privacy Act 1988 (Cth) and the Australian Privacy Principles) and the United Kingdom (UK GDPR and the Data Protection Act 2018).