Legal

Privacy Policy

Effective May 4, 2026

1. Introduction

Lex Web Studio ("we," "our," "us") is a Florida-based digital studio. This Privacy Policy explains what personal information we collect when you visit lexwebstudio.com (the "Site") or engage our design, development, consulting, and related services, how we use and share that information, and the privacy rights available to you under applicable US state laws (including California, Virginia, Colorado, Connecticut, Florida, Texas, and other comprehensive privacy statutes), the EU/UK GDPR where applicable, and other relevant frameworks.

This Policy does not apply to third-party websites, products, or services we do not control, even if they link to or from our Site.

By using the Site, you acknowledge the practices described in this Policy. If you do not agree, please discontinue use of the Site.

2. Categories of Personal Information We Collect

In the past 12 months, we have collected the following categories of personal information, as defined under the California Consumer Privacy Act (CCPA) and similar state statutes:

  • Identifiers: name, email address, phone number, IP address, and device identifiers — collected directly from you or automatically when you visit the Site.
  • Customer records: billing details and contact information you provide as part of an engagement (collected directly).
  • Commercial information: services purchased, project history, and inquiry details (collected directly).
  • Internet or network activity: browser type, pages viewed, referring URL, time on page, and interaction with our Site (collected automatically via cookies and analytics).
  • Geolocation: approximate location derived from IP address (collected automatically).
  • Inferences: inferences drawn from the above to characterize your interests in our services (derived).
  • Professional information: company name and role, when voluntarily provided in an inquiry.

Sensitive personal information: We do not intentionally collect sensitive personal information (such as government IDs, precise geolocation, racial/ethnic origin, religious beliefs, health data, biometric data, or login credentials) through the Site. If you submit such information voluntarily through our contact form, we will treat it with the same protections applied to all personal information and will not use it for purposes other than those for which you provided it.

3. How We Use Personal Information

We use personal information for the following business purposes:

(a) to respond to inquiries and communicate with you about our services; (b) to deliver services contracted under a Statement of Work and process related payments; (c) to send administrative communications, project updates, and invoices; (d) to operate, secure, debug, and improve the Site and our services; (e) to detect, prevent, and respond to fraud, abuse, security incidents, or unlawful activity; (f) to comply with legal obligations and enforce our agreements; and (g) for internal analytics, where permitted by law.

We do not use your personal information for automated decision-making that produces legal or similarly significant effects without human review.

4. How We Share Personal Information

We share personal information only with the following categories of recipients, and only as necessary:

  • Service providers / processors who help us operate the Site and deliver our services — including hosting, email, analytics, customer support, AI providers, and payment processors (notably Stripe). Each is bound by contractual confidentiality and data-protection obligations.
  • Professional advisors (legal, accounting, insurance) under confidentiality.
  • Government authorities when required by law, valid legal process, or to protect our rights, property, or safety, or that of others.
  • Successors in interest in connection with a merger, acquisition, financing, or sale of all or substantially all of our assets.
  • Clients — only their own data submitted as part of an engagement, returned in the course of delivering services.

We do not sell your personal information for money. We do not knowingly engage in "sharing" personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. We do not sell or share personal information of consumers we know to be under the age of 16.

5. Cookies, Analytics, and Tracking Technologies

We use cookies and similar technologies — including first-party cookies, pixel tags, and analytics scripts — to operate the Site, remember preferences, measure traffic, and improve performance. We organize these into three categories: strictly necessary (always on — required for the Site to function), analytics (off by default, used to measure Site usage), and marketing (reserved for future use; none active today).

You can control non-essential cookies at any time through the cookie-preference banner that appears on your first visit, or by clicking "Cookie preferences" in the Site footer. Disabling strictly-necessary cookies is not possible because the Site cannot function without them; disabling analytics will not impair core functionality.

We honor browser-based opt-out preference signals, including the Global Privacy Control (GPC), as a valid opt-out request from California and Colorado residents (and others where required) for sale/sharing of personal information and for targeted advertising. When GPC is detected on your first visit, we automatically apply a reject-all preference and do not display the consent banner.

We do not currently use Google Analytics. We use first-party analytics provided by our application platform to count anonymized page views and CTA interactions; this analytics layer is fully gated by your consent choice and does not run unless you opt in.

6. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, tax, and reporting obligations, and to resolve disputes and enforce agreements. General retention periods:

• Contact form submissions: up to 36 months from last contact, unless an engagement begins. • Engagement records, contracts, and invoices: 7 years following the end of the engagement (US tax/recordkeeping standard). • Server and security logs: typically 90 days, longer where required for investigation. • Marketing-list data: until you unsubscribe, plus a short suppression-list retention to honor your opt-out.

After retention periods expire, we delete, deidentify, or aggregate personal information.

7. Your Privacy Rights

Depending on your state of residence, you may have the following rights with respect to your personal information. We honor verifiable requests from all US residents on a non-discriminatory basis, regardless of state, where operationally feasible.

California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Florida (FDBR), Texas (TDPSA), Utah, Oregon, Montana, Delaware, Iowa, Indiana, Tennessee, Minnesota, New Jersey, New Hampshire, Kentucky, Maryland, Rhode Island, and other states with comprehensive privacy laws:

  • Right to know / access the categories and specific pieces of personal information we have collected about you.
  • Right to delete personal information we hold about you, subject to exceptions.
  • Right to correct inaccurate personal information.
  • Right to data portability — to receive a copy in a portable, machine-readable format.
  • Right to opt out of the sale or sharing of personal information and of targeted advertising.
  • Right to limit use of sensitive personal information (where applicable).
  • Right to non-discrimination for exercising any of the above.
  • Right to appeal a denied request (in states that provide for one — VA, CO, CT, FL, TX and others).

California "Shine the Light":

California residents may request, once per calendar year, a list of third parties to whom we disclosed personal information for those parties' direct-marketing purposes in the preceding calendar year. We do not currently make such disclosures.

How to exercise your rights:

Email privacy@lexwebstudio.com or use our contact form. We will verify your identity using information already on file (typically your email address and information about a recent inquiry or engagement). Authorized agents may submit requests on your behalf with proof of authorization. We respond within 45 days (CCPA) or as required by your state's law, with one extension where reasonably necessary.

8. EU/UK Visitors (GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, our legal bases for processing your personal information are: (a) your consent, where given; (b) the performance of a contract with you; (c) compliance with a legal obligation; and (d) our legitimate interests in operating, securing, and growing our business, balanced against your rights.

You have the rights of access, rectification, erasure, restriction, portability, objection, and to withdraw consent at any time. You may also lodge a complaint with your local supervisory authority. We are the controller of personal information collected through the Site. International transfers from the EEA/UK to the United States rely on Standard Contractual Clauses or equivalent safeguards.

9. Security and Data Breach Notification

We use reasonable administrative, technical, and physical safeguards designed to protect personal information, including encrypted connections (HTTPS/TLS), access controls, principle-of-least-privilege provisioning, secure cloud hosting, and ongoing monitoring. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

If we experience a security incident affecting your personal information, we will notify affected individuals and applicable regulators in accordance with the breach-notification requirements of the law of your state of residence (or other applicable law).

10. Children's Privacy

The Site is not directed to children under 13 in the United States (or under 16 in the EU/UK), and we do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us at privacy@lexwebstudio.com and we will delete it promptly. We comply with the Children's Online Privacy Protection Act (COPPA) and equivalent state requirements.

11. Do-Not-Track Signals

The Site does not currently respond to "Do Not Track" (DNT) browser signals because no consistent industry standard for DNT compliance has emerged. We do, however, honor the Global Privacy Control (GPC) signal as described above.

12. Third-Party Services and Links

The Site and our services may integrate with or link to third-party platforms, including hosting and infrastructure providers, payment processors (Stripe), analytics, AI providers (e.g., OpenAI and similar), and email/marketing tools. We are not responsible for the content, policies, or practices of those third parties. Their handling of your information is governed by their own privacy notices, which we encourage you to review.

13. Changes to This Policy

We may update this Privacy Policy from time to time. The "Effective" date at the top of this page reflects the latest revision. Material changes will be highlighted on the Site, and where required by law we will obtain renewed consent. Continued use after the effective date of the updated Policy constitutes acceptance.

14. Contact and Designated Privacy Contact

For privacy questions, requests, or concerns, contact us at:

Lex Web Studio Attn: Privacy Officer Email: privacy@lexwebstudio.com General: hello@lexwebstudio.com Web: https://lexwebstudio.com/contact

If we cannot resolve your concern, you may have the right to contact your state Attorney General or applicable supervisory authority.

Questions? Email us at hello@lexwebstudio.com or use our contact form.