Privacy & Data Governance

Privacy Policy

Corporate data protection specification establishing our binding zero-sale commitment, transparent service provider data sharing, functional storage disclosures, and defense-in-depth security standards.

Last Updated: September 2, 2026 GDPR, UK GDPR & CCPA / CPRA Compliant
Executive Summary: Core Privacy & Data Protection Standards
We Do Not Sell Personal Data

We explicitly declare that FixrWeb does not sell, rent, release, or monetize personal data under CCPA/CPRA § 1798.140, GDPR, or any global privacy statute.

Multi-Provider Data Sharing

We share technical telemetry, inquiries, and operational metadata on a need-to-know basis across our vetted multi-provider infrastructure ecosystem solely to operate, protect, and deliver services.

Functional LocalStorage Only

We store only one client-side UI preference key (fixrweb-theme) with zero personal data to preserve light or dark mode.

1. Definitive "WE DO NOT SELL PERSONAL DATA" Declaration

FixrWeb Technical Engineering Studio LLC ("FixrWeb", "we", "us", or "our") makes the following affirmative and irrevocable commitment to all visitors, clients, and commercial counterparties:

UNDER THE CALIFORNIA CONSUMER PRIVACY ACT (CCPA), CALIFORNIA PRIVACY RIGHTS ACT (CPRA) CAL. CIV. CODE § 1798.140, AND THE GENERAL DATA PROTECTION REGULATION (GDPR), FIXRWEB DOES NOT SELL, RENT, RELEASE, DISCLOSE, DISSEMINATE, MAKE AVAILABLE, TRANSFER, OR COMMUNICATE ORALLY, IN WRITING, OR BY ELECTRONIC OR OTHER MEANS, YOUR PERSONAL INFORMATION TO ANY THIRD PARTY FOR MONETARY OR OTHER VALUABLE CONSIDERATION.

We do not engage in cross-context behavioral advertising, automated user profiling, or the commercial distribution of client contact information.

2. Categories of Personal Information Collected & Operational Purposes

FixrWeb collects personal data exclusively when affirmatively and voluntarily provided by you, or automatically generated during network transit:

Commercial Inquiries & Discovery Form Submissions

When you submit a project discovery inquiry, architectural consultation request, or support ticket, we collect your full name, business email address, company name, project specifications, and optional budget estimates.

Operational Purpose: Used strictly to evaluate engineering requirements, prepare formal Statements of Work (SOW), provide architectural proposals, and correspond directly with you regarding your commercial engagement.

Direct Client Correspondence & Contract Management

When you contact us directly at contact@fixrweb.com, we retain your email address and message contents to maintain an accurate record of contractual specifications, engineering feedback, and technical support history.

3. Explicit Disclosure of Data Sharing with Multi-Provider Infrastructure

To deliver resilient, high-speed software engineering and managed cloud infrastructure, FixrWeb shares technical telemetry, server logs, and operational data on a need-to-know basis with vetted third-party infrastructure providers, data center nodes, edge WAF networks, and analytics processors selected dynamically across a global multi-provider ecosystem solely to operate, optimize, protect, and deliver services:

Edge Security & Anycast Routing Networks

Processes client IP addresses, HTTP request headers, and network packets at global edge nodes solely for DDoS mitigation, Web Application Firewall (WAF) filtering, SSL/TLS termination, and edge caching.

Multi-Cloud Compute, Bare-Metal & Storage Nodes

Hosts virtual machines, container clusters, encrypted object storage, and staging environments across tier-1 infrastructure partners necessary to run client applications and process diagnostic logs under strict enterprise data processing agreements.

Transactional Email Infrastructure

Processes inquiry submissions over encrypted TLS SMTP relays to deliver customer messages and proposal notifications to our engineering staff.

Legal Authorities & Fraud Prevention

FixrWeb may disclose operational records if required by valid subpoenas, court orders, or applicable law, or to investigate fraudulent chargebacks, security intrusions, and Acceptable Use Policy violations.

FixrWeb may update, add, or replace infrastructure subprocessors as needed to maintain security, compliance, and performance. FixrWeb reaffirms that it does not sell personal data.

4. Client-Side Local Storage & Zero Tracking Cookies

FixrWeb does not deploy advertising, marketing, or behavioral tracking cookies. We utilize standard browser localStorage solely for functional interface rendering:

Storage Key: fixrweb-theme
Permitted Values: "light" | "dark"
Technical Purpose: Preserves user visual theme preference across page navigations to eliminate Flash of Unstyled Content (FOUC).
Personal Identifiers: Zero. No user IDs, session tokens, or IP addresses are stored.

Because this storage item is strictly functional and necessary to display the user-selected visual layout, it does not require an intrusive cookie consent banner under GDPR, CCPA, or ePrivacy directives. You may clear your browser local storage at any time.

5. Server Diagnostic Logs & 30-Day Retention Schedule

When you access FixrWeb web infrastructure, our edge servers automatically generate standard technical access logs. These logs include:

  • Client Internet Protocol (IP) address
  • Browser user agent string and operating system family
  • Requested HTTP method, URL path, and response status code
  • Request timestamp and byte payload metrics

Legitimate Operational Purpose: These diagnostic logs are processed exclusively to defend against distributed denial-of-service (DDoS) attacks, detect automated vulnerability probing, identify application runtime exceptions, and ensure edge routing performance.

Purge Schedule: Diagnostic server logs are rotated and permanently purged on an automated rolling thirty (30) calendar day schedule.

7. Comprehensive Data Subject Rights (GDPR & CCPA/CPRA)

FixrWeb extends comprehensive data protection rights to all users globally:

  • Right of Access: You may request a complete export of any personal information we retain regarding your inquiries.
  • Right to Erasure ("Right to be Forgotten"): You may request immediate, permanent deletion of your inquiry data and records.
  • Right to Rectification: You may request correction or updates to inaccurate or outdated contact information.
  • Right to Data Portability: You may request your personal data in a structured, machine-readable format (JSON or CSV).
  • Right to Opt-Out of Data Sale: FixrWeb has never sold personal information and will never sell personal information under CCPA/CPRA.

To exercise any data rights, email our Data Protection Desk at contact@fixrweb.com. We respond to verified data requests within thirty (30) calendar days without charge.

8. Security Safeguards & Third-Party Attack Disclaimer

FixrWeb implements commercially reasonable technical and organizational safeguards designed to protect personal information against unauthorized access, destruction, alteration, or disclosure:

  • Strict enforcement of TLS 1.3 encryption in transit with automated HSTS security headers.
  • Edge Web Application Firewall (WAF) filtering and automated rate limiting against malicious traffic.
  • Multi-factor authentication (MFA) and SSH key authentication required for administrative infrastructure access.
  • Databases isolated in private subnets with AES-256 encryption at rest.

Disclaimer of Liability for Unauthorized Third-Party Attacks

While FixrWeb maintains rigorous commercial defense-in-depth measures, no transmission over the internet or computerized storage method is 100% secure. To the maximum extent permitted by applicable law, FixrWeb expressly disclaims all liability for any security breaches, data exposure, unauthorized third-party intrusions, zero-day software exploits, nation-state cyber warfare, or hostile cyber attacks that occur despite our implementation of commercially reasonable industry-standard security safeguards.

9. Multi-Provider Infrastructure Subprocessors & Data Transfers

FixrWeb operates a multi-provider, vendor-agnostic cloud network. We engage vetted enterprise infrastructure subprocessors across tier-1 partners, bare-metal facilities, edge networks, and data center operators to provide computing, DNS routing, storage, and email transmission. All subprocessors maintain SOC 2, ISO 27001, and GDPR compliance standards:

Edge CDN & Security Infrastructure
Global edge networks for Anycast DNS management, edge caching, and Anycast WAF security filtering.
Multi-Cloud Compute & Database Nodes
Tier-1 cloud hosts and bare-metal data centers for secure virtual machine compute, object storage, and container clusters.

FixrWeb may update, add, or replace infrastructure subprocessors dynamically as needed to maintain optimal uptime, performance, and security. FixrWeb never sells personal data.

10. Privacy Inquiries & Data Protection Officer

For questions, concerns, or formal data subject rights requests regarding this Privacy Policy, please contact our privacy desk directly:

Data Controller: FixrWeb Technical Engineering Studio LLC
Subject Line: Data Privacy & Subject Rights Request

Build with an engineering team that respects user privacy

We build fast, secure web applications and internal tools designed from the ground up for strict data protection.

Free Audit & Chat