Skip to content
Legal

Privacy Policy

Last updated: August 20, 2026

This Privacy Policy describes how Apex Medical Consulting LLC (“Apex,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with the Apex platform, websites, and related services (the “Services”).

1. Who we are

The Services are operated by Apex Medical Consulting LLC, located at 101 MacArthur Dr, Edison, NJ 08837, USA. For privacy questions you can reach us at jp@apexmcdirect.com or by writing to the address above, attention: JP Ovalle.

Apex is a customer-relationship-management and care-coordination platform built for the healthcare sector. We serve two broad groups of people, and this Policy explains our practices for both:

  • Healthcare organizations and their staff — clinics, call-center agents, coordinators, sub-administrators, and clinicians who use Apex to manage patient inquiries and communication.
  • Patients and prospective patients — individuals who submit a health inquiry through a website form, social channel, phone call, or message that is captured and managed in Apex by a healthcare organization.

2. Our role: controller, processor, and Business Associate

When a healthcare organization uses Apex to manage patient information, that organization generally determines how the information is used, and Apex acts as a service provider / processor on its behalf. Where the organization is a HIPAA “covered entity” or another “business associate,” Apex acts as a Business Associate, and our handling of protected health information (“PHI”) is governed by a Business Associate Agreement (“BAA”) in addition to this Policy. We execute our standard BAA with each such organization before PHI is processed; organizations may request or execute a BAA at any time by contacting jp@apexmcdirect.com. Where a BAA conflicts with this Policy regarding PHI, the BAA controls.

For our own marketing website, account registration, and billing, Apex acts as a controller of the information described below.

3. Information we collect

3.1 Information you or your provider give us

  • Identity and contact details: first and last name, email and alternate email, mobile and alternate phone numbers, country and dialing code, date of birth, and gender.
  • Location details: mailing or physical address and, where provided, approximate geolocation and clinic address.
  • Account and professional details: username, password, role, profile photo, and — for clinicians — license number and practice information.
  • Health-related information you choose to share: the inquiry, symptoms, medical history, or other details a patient includes in a message, form, note, consultation record, follow-up, or uploaded document (which may include medical reports, prescriptions, or identification).
  • Communications: the content of SMS, email, voice calls (including call recordings and call logs), web chat, and social messages exchanged through the platform, along with related notes and dispositions.
  • Support and contact-form submissions: the name, email, phone, subject, and message you send us.

3.2 Information we collect automatically

  • Device and log data: IP address, browser and user-agent, device type and identifiers, and login history (including timestamps and session duration).
  • Cookies and similar technologies: we use strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. We do not currently load third-party advertising or analytics trackers. See “Cookies” below.

3.3 Information from third parties

When a patient contacts a provider through a connected channel — such as Facebook or Instagram messaging — we receive the message content and related conversation identifiers from that platform so the inquiry can be managed in Apex.

4. How we use information

  • To provide, operate, secure, and improve the Services.
  • To route patient inquiries to the appropriate organization, coordinator, or clinician, and to support follow-up and consultation workflows.
  • To send and receive communications (SMS, email, voice, chat, and push notifications) that you or a provider initiate or request.
  • To draft suggested message and call-script text using AI assistance. Suggested text is reviewed by a human before it is sent; the platform does not send AI-drafted messages automatically.
  • To authenticate users, enforce role-based permissions, maintain audit logs, prevent fraud and abuse, and meet legal and security obligations.
  • For the marketing website: to respond to demo requests and provide information about Apex.

We process this information on the legal bases of performing our contract with you or your provider, our legitimate interests in operating the Services, your consent where required, and compliance with law.

5. AI-assisted features

Apex uses third-party AI services (currently OpenAI) to classify incoming social-channel conversations and to draft suggested correspondence. Message content relevant to these features may be transmitted to the AI provider for processing. We instruct our providers to act as our processors and not to use your content to train their general models.

6. How we share information

We do not sell personal information. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

We share other categories of information only as follows:

  • With your healthcare organization and its authorized users, so they can manage your inquiry and care coordination.
  • With service providers (sub-processors) who process data on our behalf under contract, including:
    • Twilio — SMS, voice calls, and call recordings;
    • Meta (Facebook / Instagram) — social messaging;
    • OpenAI — AI classification and drafting;
    • Google — calendar scheduling and address lookup;
    • Amazon Web Services (S3) — encrypted file and backup storage;
    • our email-delivery provider and push-notification provider.
  • For legal reasons — to comply with law, respond to lawful requests, or protect the rights, safety, and security of users and the public.
  • In a business transfer — in connection with a merger, acquisition, or sale of assets, subject to this Policy.

7. How we protect information

We maintain administrative, physical, and technical safeguards designed to protect personal information, including:

  • Encryption in transit using TLS, with HTTP Strict Transport Security enabled in production;
  • AES-256 server-side encryption for files and database backups stored in Amazon S3, and application-level encryption of sensitive credentials;
  • Role-based access controls and least-privilege permissions;
  • Audit logging of create, update, and delete activity across patient and communication records, plus login-history tracking;
  • Secure, hashed password storage and session protections (Secure, HttpOnly, SameSite cookies).

No system is perfectly secure, and we cannot guarantee absolute security.

8. Data retention

We retain personal information for as long as needed to provide the Services, and thereafter as required to meet legal, regulatory, audit, and legitimate business obligations. As a general rule:

  • Account and staff records are kept for the life of the account and deleted or de-identified within ninety (90) days after the account relationship ends, except where longer retention is legally required.
  • Patient inquiry and communication records (including messages, call logs, and uploaded documents) are retained for as long as the responsible healthcare organization uses Apex to manage them; where Apex processes PHI on behalf of a provider, retention, return, and deletion are directed by that provider and the applicable BAA.
  • Security and audit logs are retained long enough to support HIPAA audit-trail expectations and security investigations.
  • Encrypted backups are overwritten on our standard backup rotation; data removed from live systems ages out of backups on that schedule rather than being individually deleted.

To request deletion of information we control, contact jp@apexmcdirect.com; requests concerning provider-controlled records may be directed to, or fulfilled with, the responsible organization.

9. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. Because much of the information in Apex is controlled by your healthcare organization, we may direct certain requests to that organization or fulfill them on its behalf. To make a request, contact us at jp@apexmcdirect.com. We will not discriminate against you for exercising your rights.

United States state privacy laws. If you live in a U.S. state with a comprehensive privacy law (such as California, Colorado, Connecticut, New Jersey, Texas, or Virginia), those laws may give you the rights above, along with the right to appeal a refused request. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising or use it for profiling that produces legal or similarly significant effects. You may submit requests — directly or, where the law allows, through an authorized agent — at jp@apexmcdirect.com; we will verify the request and respond within the time the applicable law requires. Health information handled for a HIPAA-covered organization is generally exempt from these state laws and is governed instead by HIPAA and the applicable BAA.

European Economic Area and United Kingdom. The Services are offered from the United States and are not directed to the EEA or UK. If GDPR or UK GDPR nonetheless applies to particular processing, the legal bases described in Section 4 apply, and you may also lodge a complaint with your local supervisory authority.

10. Cookies

We use cookies that are strictly necessary to operate the Services, keep you signed in, and protect against cross-site request forgery. These cookies are set with Secure, HttpOnly, and SameSite attributes. We do not currently use advertising or third-party analytics cookies. If this changes, we will update this Policy and provide any consent mechanism the law requires.

11. Children’s privacy

The Services are intended for use by healthcare organizations and adults. Where a provider uses Apex to manage information about a minor patient, it does so under its own authority and the applicable BAA. We do not knowingly collect information directly from children for our own purposes.

12. International data transfers and data residency

Our production systems — including application hosting, databases, and encrypted file and backup storage — are located in the United States. We and our service providers may nonetheless process information in countries other than the one in which you reside, for example when a communications provider routes a message internationally. Where personal information is transferred across borders and the law requires a transfer mechanism, we rely on appropriate safeguards such as standard contractual clauses or the service provider’s equivalent certified framework.

13. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, where required, provide additional notice.

14. Contact us

Questions or requests? Contact Apex Medical Consulting LLC at jp@apexmcdirect.com or 101 MacArthur Dr, Edison, NJ 08837, USA.

Get started

Upgrade your healthcare workflow.

See how Apex Medical CRM transforms patient engagement and care-team coordination — starting today.