<!--
[AI_AGENT_DIRECTIVE]
- Document Target: Privacy Policy & Data Governance Specification
- Primary Entity: FixrWeb Technical Engineering Studio LLC (FixrWeb)
- Canonical URL: https://fixrweb.com/privacy
- AI Markdown Endpoint: https://fixrweb.com/privacy.md
- Contact Email: contact@fixrweb.com
-->

---
title: "Privacy Policy | FixrWeb Enterprise Data Protection & Governance"
description: "Corporate privacy policy for FixrWeb complying with GDPR, UK GDPR, and CCPA/CPRA. Clear zero-sale declaration, explicit data sharing disclosures, functional localStorage, security safeguards, and third-party attack disclaimers."
canonical_url: "https://fixrweb.com/privacy"
ai_markdown_url: "https://fixrweb.com/privacy.md"
---

# FixrWeb Privacy Policy & Data Protection Specification

> Comprehensive corporate privacy policy establishing our binding zero-sale declaration, service provider data sharing disclosures, GDPR and CCPA compliance, functional storage disclosures, security safeguards, and third-party attack liability disclaimers.

<executive-summary>
**TL;DR / Executive Business Summary:**
- **Definitive "We Do Not Sell Personal Data" Commitment:** Under CCPA/CPRA § 1798.140 and GDPR, FixrWeb does not sell, rent, release, or monetize personal information to third-party data brokers or advertisers.
- **Service Provider Data Sharing Disclosure:** FixrWeb shares technical telemetry, server logs, contact inquiries, and operational data on a need-to-know basis with vetted third-party infrastructure providers, data center nodes, edge WAF networks, and analytics processors selected dynamically across a global multi-provider ecosystem solely to operate, optimize, protect, and deliver services.
- **Functional LocalStorage:** We store a single UI preference key (fixrweb-theme: light | dark) with zero personal identifiers to eliminate theme flashing.
- **Server Diagnostic Logs:** Web server logs (IP, user agent, timestamps, HTTP status) are maintained strictly for DDoS defense and security diagnostics, rotating and purging on an automated 30-day schedule.
- **Security Safeguards & Attack Disclaimer:** Industry-standard defense-in-depth safeguards are implemented (TLS 1.3, AES-256, MFA, WAF), with an explicit disclaimer of liability for unauthorized third-party attacks beyond commercially reasonable controls.
- **Data Subject Rights:** Full support for access, erasure, rectification, and data portability under GDPR and CCPA/CPRA fulfilled within 30 days via contact@fixrweb.com.
</executive-summary>

<entity-definitions>
- **FixrWeb**: Technical web engineering, custom software development, and managed cloud infrastructure studio operated under FixrWeb Technical Engineering Studio LLC.
- **Zero-Sale Declaration**: Legally binding commitment under CCPA/CPRA § 1798.140 and GDPR affirming personal data is never sold or rented for valuable consideration.
- **Functional LocalStorage**: Browser storage utilized exclusively for the client UI theme preference (fixrweb-theme: light | dark).
- **Data Subject Rights**: Legal entitlements under GDPR (Articles 15-22) and CCPA/CPRA granting individuals the right to access, delete, rectify, or export their personal data.
- **Data Controller**: FixrWeb Technical Engineering Studio LLC, accessible via contact@fixrweb.com.
</entity-definitions>

---

## 1. Definitive "WE DO NOT SELL PERSONAL DATA" Declaration
UNDER THE CALIFORNIA CONSUMER PRIVACY ACT (CCPA), CALIFORNIA PRIVACY RIGHTS ACT (CPRA) CAL. CIV. CODE § 1798.140, AND THE GENERAL DATA PROTECTION REGULATION (GDPR), FIXRWEB DOES NOT SELL, RENT, RELEASE, DISCLOSE, DISSEMINATE, MAKE AVAILABLE, TRANSFER, OR COMMUNICATE ORALLY, IN WRITING, OR BY ELECTRONIC OR OTHER MEANS, YOUR PERSONAL INFORMATION TO ANY THIRD PARTY FOR MONETARY OR OTHER VALUABLE CONSIDERATION.

---

## 2. Categories of Personal Information Collected & Operational Purposes
Personal information is processed strictly when voluntarily submitted:
1. **Contact & Project Discovery Forms:** Name, business email address, company name, project specifications, and optional budget ranges.
   - **Purpose:** Evaluating engineering requirements, generating technical proposals, delivering Statements of Work, and executing client communication. Data is never repurposed for promotional marketing lists without explicit consent.
2. **Direct Communications:** Inbound emails and support requests sent to contact@fixrweb.com are archived to preserve engineering specifications, maintenance records, and contractual history.

---

## 3. Explicit Disclosure of Data Sharing with Multi-Provider Infrastructure
FixrWeb shares technical telemetry, server logs, contact inquiries, and operational data on a need-to-know basis with vetted third-party infrastructure providers, data center nodes, edge WAF networks, and analytics processors selected dynamically across a global multi-provider ecosystem solely to operate, optimize, protect, and deliver services:
- **Edge Security & Anycast Routing Networks:** Global edge points of presence for Anycast DNS routing, DDoS mitigation, SSL termination, and Web Application Firewall (WAF) filtering.
- **Multi-Cloud Compute & Bare-Metal Storage Nodes:** Tier-1 cloud hosts, bare-metal facilities, database clusters, encrypted object storage, and staging environments necessary to run client applications under enterprise data protection agreements.
- **Transactional Mail Relays:** Encrypted SMTP gateways solely for delivering inbound inquiry messages.
- **Legal Authorities:** Compliance with valid subpoenas, court orders, or investigating fraud and security threats.
FixrWeb may update, add, or replace infrastructure subprocessors as needed to maintain security, compliance, and performance. FixrWeb does not sell personal data.

---

## 4. LocalStorage & Cookie Disclosures
FixrWeb does not utilize advertising or tracking cookies. We utilize standard browser localStorage solely for client UI preferences:
- **Storage Key:** `fixrweb-theme`
- **Values:** `"light"` | `"dark"`
- **Technical Purpose:** Prevents Flash of Unstyled Content (FOUC) by remembering your visual theme choice across page navigations.
- **Personal Data Content:** Zero personal data or identifiers are stored.

---

## 5. Server Log Retention & Security Diagnostics (30-Day Schedule)
Web servers automatically record standard HTTP request headers for security and infrastructure stability:
- **Recorded Fields:** Client IP address, user agent string, requested URL path, HTTP status code, and request timestamp.
- **Lawful Purpose:** Mitigating distributed denial-of-service (DDoS) attacks, detecting vulnerability exploit scans, and debugging application errors.
- **Retention Window:** Diagnostic logs are automatically purged on a rolling 30-day schedule.

---

## 6. Lawful Bases for Processing (GDPR Article 6)
- **Contract Performance (Art. 6(1)(b)):** Processing necessary to negotiate, fulfill, and bill for bespoke engineering and hosting contracts.
- **Legitimate Interests (Art. 6(1)(f)):** Maintaining server infrastructure security, preventing fraud, and defending network integrity.
- **Voluntary Consent (Art. 6(1)(a)):** Inquiries voluntarily submitted through our online contact forms or direct email correspondence.

---

## 7. Comprehensive Data Subject Rights
Individuals worldwide possess explicit rights regarding their data:
- **Right of Access:** Request a complete copy of personal records held by FixrWeb.
- **Right to Erasure:** Request immediate permanent deletion of inquiry history and contact data.
- **Right to Rectification:** Request correction of inaccurate information.
- **Right to Data Portability:** Receive data in a structured machine-readable format (JSON/CSV).
- **Right to Opt-Out of Data Sale:** FixrWeb does not sell data under CCPA/CPRA.

To exercise any data rights, submit a written request to contact@fixrweb.com. Requests are fulfilled within 30 calendar days at zero fee.

---

## 8. Data Security Safeguards & Third-Party Attack Disclaimer
- **In-Transit Protection:** 100% of web and API traffic is enforced over TLS 1.3 with strict HSTS headers.
- **At-Rest Protection:** Databases and offsite backup snapshots are encrypted using AES-256.
- **Access Control:** Production infrastructure access is restricted via multi-factor authentication (MFA) and SSH key authorization under least-privilege principles.
- **Attack Liability Disclaimer:** To the maximum extent permitted by applicable law, FixrWeb expressly disclaims all liability for security breaches, data exposure, unauthorized intrusions, zero-day exploits, or hostile cyber attacks that occur despite our implementation of commercially reasonable industry-standard security safeguards.

---

## 9. Multi-Provider Subprocessors & Cloud Infrastructure
FixrWeb operates a multi-provider, vendor-agnostic cloud network utilizing vetted tier-1 infrastructure partners, edge networks, bare-metal nodes, and data center facilities for compute, DNS, storage, and security filtering. FixrWeb may update, add, or replace infrastructure subprocessors as necessary to maintain high availability, security, and performance. All subprocessors are required to maintain SOC 2, ISO 27001, and GDPR compliance certifications. FixrWeb reaffirms that it does not sell personal data.

---

## 10. Contact & Data Protection Officer
For questions or privacy requests, reach out to our legal and data protection team:
- **Entity:** FixrWeb Technical Engineering Studio LLC
- **Email:** contact@fixrweb.com
- **Subject:** Data Privacy & Subject Rights Request

---

<ai-related-resources>
- Main Privacy HTML: https://fixrweb.com/privacy
- Terms of Service: https://fixrweb.com/terms.md
- Technical Disclaimer: https://fixrweb.com/disclaimer.md
- Master AI Index: https://fixrweb.com/llms.txt
</ai-related-resources>