Legal
Privacy Policy
What apysyk.com collects, why, who processes it, how long we keep it, and your rights.
Who we are
Apysyk (“we”, “us”) is the controller of the personal data described in this policy: we decide why and how it is used.
This policy covers the websites apysyk.com and mediakit.apysyk.com, our media kit. The Apysyk platform is governed by each customer’s agreement, and this policy does not cover customer data inside the platform.
For privacy requests and legal notices, write to sales@apysyk.com.
In short
- No cookies, no analytics scripts, no ads, and no third-party scripts or trackers. We learn about visits only from our CDN’s access logs.
- We collect personal data in two places: the “Get a demo” form, and our CDN’s access logs.
- Each demo request becomes one email to our sales inbox.
- Our CDN keeps access logs for about six months; they are then deleted automatically.
- Our team receives internal reports of the site’s visits, with IP addresses, networks, approximate places, times and pages: one a week, and up to three a day when someone visits the site or requests a demo.
- We do not sell personal data.
- You can object, and ask for access, correction or deletion, at any time.
What we collect
When you request a demo
What you type in the form at /demo/:
- your name;
- your work email;
- your company;
- a message, if you write one. It is optional.
Requesting a demo is voluntary. The form needs your name, work email and company only to send the request. No law or contract requires you to give them, but without them the form cannot send it.
What is sent automatically with the request:
- your IP address;
- your approximate location (city, region, country and time zone), which our CDN derives from your IP address;
- your network (its autonomous system number);
- your device type;
- your browser (its user agent);
- your browser’s language;
- the page the request came from;
- the time we received it.
The request becomes one email to our sales inbox. To limit how often the form can be used, the form’s server also keeps your IP address (for IPv6, its /64 network) and the times of your requests. They are held only in that server’s memory and are never written to disk or to logs. Apart from this and the CDN access logs described below, nothing else about the request is stored.
When you browse
- We use no cookies, no analytics scripts, no ads, and no third-party scripts or trackers. We learn about visits only from the CDN access logs described below.
- The only thing the site stores in your browser is the address of the current page and your scroll position, in session storage (sessionStorage). It returns you to the same place after a reload, or when you go back or forward. It is cleared when you close the tab.
- Our hosting and CDN provider processes technical request data (your IP address, the page you request and your browser) to deliver the pages.
- Our CDN keeps access logs (IP address and port, date and time, the page requested, the page you came from, browser) for about six months; they are then deleted automatically.
- The media kit at mediakit.apysyk.com is hosted on GitHub Pages and has no forms, cookies or analytics. GitHub logs the IP address of every visitor to a GitHub Pages site for security purposes, as described in the GitHub General Privacy Statement. We do not receive those logs.
Why we use it
We use the data of a demo request to:
- reply to your request and arrange the demo;
- understand which company and network the request comes from;
- protect the form from abuse, with rate limits per IP address.
We use the CDN access logs for security, to investigate abuse, and to understand who visits the site. We email our team internal reports about the site’s visits and automated accesses, with details such as the IP address, the network and organization it belongs to, an approximate place, the browser and device, the pages requested and when, and the page it came from. A weekly report covers the whole week. Up to three times a day, a shorter report covers the hours before it, and it is sent only when someone visited the site or requested a demo. These reports help us tell companies interested in Apysyk apart from automated traffic and attacks.
To find the network and approximate place of an IP address, we look it up in a database that we download and query ourselves (DB-IP), in the reverse DNS, and in the public registries of internet addresses (RDAP), which receive only the IP address.
Session storage is used only to return you to your place on the page.
We do not sell personal data. We make no automated decisions about you with legal effects.
Legal basis
We rely on our legitimate interests: replying to people who ask about Apysyk, knowing which company is asking, understanding who visits the site and which companies are interested in Apysyk, and keeping the site and the form secure and safe from abuse.
- In Brazil, under the LGPD: article 7, IX, with article 10.
- In the European Economic Area and the United Kingdom, under the GDPR and the UK GDPR: article 6(1)(f).
You have the right to object to this use at any time, as the next section explains.
Your right to object
You can object at any time to our use of your personal data based on legitimate interests (GDPR and UK GDPR article 21; LGPD article 18).
To object, write to sales@apysyk.com. You can also ask us to delete your request at the same time.
Who processes it
Two providers process personal data for us, under their data processing terms:
- Amazon Web Services: hosting, the CDN, the functions that receive the form and prepare the visit reports, and email delivery through Amazon SES, in the United States (us-east-1).
- Google: Google Workspace, where our inbox lives. Google may process data in the United States and other countries.
Apysyk decides how the data is used and is responsible for it. These providers process it on our behalf.
International transfers
Your data is processed in the United States, and Google may also process it in other countries. These transfers rely on the data processing terms of AWS and Google, which include standard contractual clauses. You can ask us for a copy of these safeguards at sales@apysyk.com.
How, why and for how long the data is processed, the providers, the security measures and your rights, including petitioning the ANPD, are described in the other sections of this page.
How long we keep it
- Demo request emails: only as long as we need to answer your request and follow up on it, then we delete them.
- CDN access logs: about six months, then deleted automatically.
- Visit reports: in our team’s inbox only as long as we need them to follow the site’s visits, then we delete them.
- Rate-limit data (IP address and request times): only in the memory of the form’s server, until that server stops or newer requests push it out. There is no fixed expiry.
- Session storage: until you close the tab.
Your rights
To use any of these rights, write to sales@apysyk.com.
You can also complain to us about how we handle your data, at sales@apysyk.com. This does not stop you from complaining to a data protection authority, such as the ANPD in Brazil or the ICO in the United Kingdom.
In Brazil (LGPD, article 18)
- confirmation that we process your data;
- access to your data;
- correction of incomplete, inaccurate or out-of-date data;
- anonymization, blocking or deletion;
- portability;
- information about who we share your data with;
- objection;
- petition to the ANPD, Brazil’s data protection authority.
In the European Economic Area and the United Kingdom (GDPR and UK GDPR)
- access;
- rectification;
- erasure;
- restriction;
- portability;
- objection (article 21, see Your right to object);
- complaint to a supervisory authority, for example the ICO in the United Kingdom.
Security
- HTTPS everywhere, with HSTS.
- A strict Content Security Policy that allows only our own origin.
- No third-party code on the site.
- The form endpoint accepts requests only through our CDN.
- Access to the inbox is limited to our team.
To report a vulnerability, see Security.
Children
apysyk.com is not directed at children.
Do Not Track
We do not track you across sites, so a Do Not Track signal changes nothing here.
Changes to this policy
When we change this policy, we publish the new version on this page with a new “Last updated” date.
Contact
Privacy requests, legal notices and vulnerability reports: sales@apysyk.com.