Privacy Policy
Corporate data protection specification establishing our binding zero-sale commitment, transparent service provider data sharing, functional storage disclosures, and defense-in-depth security standards.
We explicitly declare that FixrWeb does not sell, rent, release, or monetize personal data under CCPA/CPRA § 1798.140, GDPR, or any global privacy statute.
We share technical telemetry, inquiries, and operational metadata on a need-to-know basis across our vetted multi-provider infrastructure ecosystem solely to operate, protect, and deliver services.
We store only one client-side UI preference key (fixrweb-theme) with zero personal data to preserve light or dark mode.
1. Definitive "WE DO NOT SELL PERSONAL DATA" Declaration
FixrWeb Technical Engineering Studio LLC ("FixrWeb", "we", "us", or "our") makes the following affirmative and irrevocable commitment to all visitors, clients, and commercial counterparties:
UNDER THE CALIFORNIA CONSUMER PRIVACY ACT (CCPA), CALIFORNIA PRIVACY RIGHTS ACT (CPRA) CAL. CIV. CODE § 1798.140, AND THE GENERAL DATA PROTECTION REGULATION (GDPR), FIXRWEB DOES NOT SELL, RENT, RELEASE, DISCLOSE, DISSEMINATE, MAKE AVAILABLE, TRANSFER, OR COMMUNICATE ORALLY, IN WRITING, OR BY ELECTRONIC OR OTHER MEANS, YOUR PERSONAL INFORMATION TO ANY THIRD PARTY FOR MONETARY OR OTHER VALUABLE CONSIDERATION.
We do not engage in cross-context behavioral advertising, automated user profiling, or the commercial distribution of client contact information.
2. Categories of Personal Information Collected & Operational Purposes
FixrWeb collects personal data exclusively when affirmatively and voluntarily provided by you, or automatically generated during network transit:
Commercial Inquiries & Discovery Form Submissions
When you submit a project discovery inquiry, architectural consultation request, or support ticket, we collect your full name, business email address, company name, project specifications, and optional budget estimates.
Operational Purpose: Used strictly to evaluate engineering requirements, prepare formal Statements of Work (SOW), provide architectural proposals, and correspond directly with you regarding your commercial engagement.
Direct Client Correspondence & Contract Management
When you contact us directly at contact@fixrweb.com, we retain your email address and message contents to maintain an accurate record of contractual specifications, engineering feedback, and technical support history.
3. Explicit Disclosure of Data Sharing with Multi-Provider Infrastructure
To deliver resilient, high-speed software engineering and managed cloud infrastructure, FixrWeb shares technical telemetry, server logs, and operational data on a need-to-know basis with vetted third-party infrastructure providers, data center nodes, edge WAF networks, and analytics processors selected dynamically across a global multi-provider ecosystem solely to operate, optimize, protect, and deliver services:
Edge Security & Anycast Routing Networks
Processes client IP addresses, HTTP request headers, and network packets at global edge nodes solely for DDoS mitigation, Web Application Firewall (WAF) filtering, SSL/TLS termination, and edge caching.
Multi-Cloud Compute, Bare-Metal & Storage Nodes
Hosts virtual machines, container clusters, encrypted object storage, and staging environments across tier-1 infrastructure partners necessary to run client applications and process diagnostic logs under strict enterprise data processing agreements.
Transactional Email Infrastructure
Processes inquiry submissions over encrypted TLS SMTP relays to deliver customer messages and proposal notifications to our engineering staff.
Legal Authorities & Fraud Prevention
FixrWeb may disclose operational records if required by valid subpoenas, court orders, or applicable law, or to investigate fraudulent chargebacks, security intrusions, and Acceptable Use Policy violations.
FixrWeb may update, add, or replace infrastructure subprocessors as needed to maintain security, compliance, and performance. FixrWeb reaffirms that it does not sell personal data.
4. Client-Side Local Storage & Zero Tracking Cookies
FixrWeb does not deploy advertising, marketing, or behavioral tracking cookies. We utilize standard browser localStorage solely for functional interface rendering:
Because this storage item is strictly functional and necessary to display the user-selected visual layout, it does not require an intrusive cookie consent banner under GDPR, CCPA, or ePrivacy directives. You may clear your browser local storage at any time.
5. Server Diagnostic Logs & 30-Day Retention Schedule
When you access FixrWeb web infrastructure, our edge servers automatically generate standard technical access logs. These logs include:
- Client Internet Protocol (IP) address
- Browser user agent string and operating system family
- Requested HTTP method, URL path, and response status code
- Request timestamp and byte payload metrics
Legitimate Operational Purpose: These diagnostic logs are processed exclusively to defend against distributed denial-of-service (DDoS) attacks, detect automated vulnerability probing, identify application runtime exceptions, and ensure edge routing performance.
Purge Schedule: Diagnostic server logs are rotated and permanently purged on an automated rolling thirty (30) calendar day schedule.
6. Lawful Bases for Data Processing (GDPR Article 6)
Under the EU General Data Protection Regulation (GDPR) and UK GDPR, FixrWeb processes personal data under the following recognized legal bases:
Contract Performance
Processing required to prepare technical proposals, execute Statements of Work, deliver custom code, and provision hosting.
Legitimate Interests
Processing necessary to safeguard infrastructure security, prevent malicious exploits, debug server errors, and protect business assets.
Voluntary Consent
Processing initiated upon your voluntary submission of contact details via our discovery forms or email correspondence.
7. Comprehensive Data Subject Rights (GDPR & CCPA/CPRA)
FixrWeb extends comprehensive data protection rights to all users globally:
- Right of Access: You may request a complete export of any personal information we retain regarding your inquiries.
- Right to Erasure ("Right to be Forgotten"): You may request immediate, permanent deletion of your inquiry data and records.
- Right to Rectification: You may request correction or updates to inaccurate or outdated contact information.
- Right to Data Portability: You may request your personal data in a structured, machine-readable format (JSON or CSV).
- Right to Opt-Out of Data Sale: FixrWeb has never sold personal information and will never sell personal information under CCPA/CPRA.
To exercise any data rights, email our Data Protection Desk at contact@fixrweb.com. We respond to verified data requests within thirty (30) calendar days without charge.
8. Security Safeguards & Third-Party Attack Disclaimer
FixrWeb implements commercially reasonable technical and organizational safeguards designed to protect personal information against unauthorized access, destruction, alteration, or disclosure:
- Strict enforcement of TLS 1.3 encryption in transit with automated HSTS security headers.
- Edge Web Application Firewall (WAF) filtering and automated rate limiting against malicious traffic.
- Multi-factor authentication (MFA) and SSH key authentication required for administrative infrastructure access.
- Databases isolated in private subnets with AES-256 encryption at rest.
Disclaimer of Liability for Unauthorized Third-Party Attacks
While FixrWeb maintains rigorous commercial defense-in-depth measures, no transmission over the internet or computerized storage method is 100% secure. To the maximum extent permitted by applicable law, FixrWeb expressly disclaims all liability for any security breaches, data exposure, unauthorized third-party intrusions, zero-day software exploits, nation-state cyber warfare, or hostile cyber attacks that occur despite our implementation of commercially reasonable industry-standard security safeguards.
9. Multi-Provider Infrastructure Subprocessors & Data Transfers
FixrWeb operates a multi-provider, vendor-agnostic cloud network. We engage vetted enterprise infrastructure subprocessors across tier-1 partners, bare-metal facilities, edge networks, and data center operators to provide computing, DNS routing, storage, and email transmission. All subprocessors maintain SOC 2, ISO 27001, and GDPR compliance standards:
FixrWeb may update, add, or replace infrastructure subprocessors dynamically as needed to maintain optimal uptime, performance, and security. FixrWeb never sells personal data.
10. Privacy Inquiries & Data Protection Officer
For questions, concerns, or formal data subject rights requests regarding this Privacy Policy, please contact our privacy desk directly:
Build with an engineering team that respects user privacy
We build fast, secure web applications and internal tools designed from the ground up for strict data protection.