Privacy Policy
August 10, 2026 · August 10, 2026
This policy explains what we collect, why, how long we keep it, and what you can ask us to do about it. It covers this website and the services we deliver to clients.
Who we are
Fluxy Brand Group LLC ("Fluxy", "we", "us"), a Florida limited liability company trading as Fluxy Brand Group, is a product and consulting studio based in Clermont, Florida, United States. We build AI agents, web applications, CRM systems, data pipelines, and business-intelligence dashboards.
For information we collect through this website, Fluxy is the controller. For information we handle inside a client's systems during an engagement, Fluxy generally acts as a processor on that client's written instructions, and the client's own privacy policy governs the underlying data.
What we collect
Information you give us
- Contact form and email. Name, email address, company, project type, budget range, and whatever you write in the message field.
- Engagement records. Contracts, invoices, correspondence, and project documentation.
- Credentials you choose to share. API keys, repository access, or system logins needed to perform the work.
Information collected automatically
- Analytics. We use Cloudflare Web Analytics, which is privacy-first and does not use cookies, does not fingerprint visitors, and does not track you across sites. We see aggregate page views, referrers, and country — not individuals.
- Server and security logs. Our host records IP addresses and request metadata for security, abuse prevention, and reliability.
- Fonts. This site loads typefaces from Google Fonts, which receives your IP address as part of that request.
What we do not collect
We do not sell personal information. We do not share it with advertisers. We do not run advertising or cross-site tracking pixels. We do not knowingly collect information from anyone under 18.
Why we use it
We use personal information only for these purposes:
- Responding to enquiries and preparing proposals
- Performing a contract with you and delivering agreed services
- Invoicing, accounting, and tax records
- Securing and maintaining our systems
- Meeting legal, regulatory, and professional obligations
Where the GDPR or UK GDPR applies, our lawful bases are contract performance, legitimate interests (running and securing the business), consent where required, and legal obligation.
AI systems and your data
Because we build AI systems, this deserves its own section.
- We do not use client data to train foundation models. Client information is used to build and test the system contracted for, and nothing else.
- Third-party model providers. Where a project uses an external model API, data passed to that API is governed by that provider's terms. We identify every such provider in writing before the engagement begins and configure zero-retention or no-training options wherever the provider offers them.
- Human review. AI output is probabilistic and can be wrong. Systems we build are designed to keep a human in the loop for consequential decisions, and we document where those checkpoints sit.
- Logging. Agent systems typically log their actions so they can be audited. We agree retention periods for those logs with you in writing.
How long we keep it
- Enquiries that do not become projects: up to 24 months.
- Client and engagement records: for the life of the engagement plus seven years, to satisfy tax and limitation-period requirements.
- Credentials: revoked and deleted at handoff. We ask you to rotate any secret we held.
- Analytics: aggregate only, retained per Cloudflare's policy.
Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, to object to processing, and to withdraw consent.
Florida residents. The Florida Digital Bill of Rights may give you rights of access, correction, deletion, portability, and opt-out of sale or targeted advertising. We do not sell personal information or conduct targeted advertising.
California residents. Under the CCPA/CPRA you may request disclosure of categories collected, deletion, and correction. We do not sell or share personal information as those terms are defined, and we will not discriminate against you for exercising any right.
EEA and UK residents. You may lodge a complaint with your supervisory authority. We do not currently target the EEA or UK market.
To exercise any right, email [email protected]. We respond within 45 days and may need to verify your identity first.
Security
We use encryption in transit, access controls scoped to the minimum needed, multi-factor authentication on accounts that support it, and prompt credential rotation at project handoff. No system is perfectly secure, and we do not claim otherwise. If a breach affects your personal information, we will notify you and any required regulator without undue delay.
International transfers
We operate from the United States and our providers may process data in the United States and elsewhere. Where required, transfers rely on Standard Contractual Clauses or another approved mechanism.
Changes to this policy
We update this policy when our practices change. The effective date at the top always reflects the current version. Material changes will be announced on this page, and where we hold your contact details and the change is significant, by email.
Questions about this page: [email protected] · Fluxy Brand Group LLC, Clermont, Florida, United States.