LJ WEB MANAGEMENT
PRIVACY POLICY
Effective Date: July 2, 2026
This Privacy Policy explains how LJ Web Management, doing business as LJ Web Management ("LJ Web Management," "we," "us," or "our"), collects, uses, discloses, and protects information when you visit https://ljwebmanagement.com, contact us, schedule an appointment, or use our services.
1. INFORMATION WE COLLECT
Information you provide. We may collect your name, email address, telephone number, appointment details, messages, and other information you choose to provide through contact forms, appointments, consultations, or other communications.
Customer project information. In some projects, customers may provide business files, records, credentials, workflow information, personal information, confidential information, or other content needed to evaluate, build, operate, maintain, or change an automation. The information collected depends on the project. Customers should provide only information reasonably necessary for the requested services and must have the right to provide it to us.
Payment and transaction information. If you purchase services, we may collect billing details, transaction records, and information necessary to administer upfront project payments and recurring monthly fees. Payment-card information may be collected and processed directly by a third-party payment processor rather than stored by us.
Website and technical information. Our website and service providers may automatically collect information such as your IP address, visit date and time, pages or resources accessed, referring page, browser type and version, device or platform information, approximate location, language, and interactions with the website.
Cookies and analytics. We and our service providers may use essential cookies for website operation, session management, preferences, security, and form functionality. We may also use analytics technologies to understand website traffic and interactions. Available analytics tools and the information they collect may depend on our Odoo website configuration and your cookie choices.
2. HOW WE USE INFORMATION
We may use information to:
- respond to inquiries and schedule or conduct appointments; - evaluate customer needs and prepare proposals or contracts; - design, build, test, deliver, maintain, support, or modify automation systems; - process payments and administer customer relationships; - operate, secure, troubleshoot, and improve our website and services; - analyze website traffic and usage; - communicate service, administrative, security, or policy updates; - enforce agreements and protect our rights, customers, and others; and - comply with legal obligations and respond to lawful requests.
3. HOW WE DISCLOSE INFORMATION
We may disclose information:
- to Odoo and other vendors that provide website hosting, forms, appointments, analytics, communications, payment processing, cloud hosting, software, security, or other operational services; - to contractors or professional advisers who need the information to perform services for us and are subject to appropriate obligations; - when needed to perform a customer contract or implement a requested automation; - when required by law, court order, or lawful government request; - when reasonably necessary to protect rights, safety, property, or the integrity of our services; or - in connection with a merger, financing, acquisition, sale, reorganization, or transfer of some or all of our business or assets.
We do not sell personal information for money. If our practices change, we will update this Policy and provide any choices required by applicable law.
4. THIRD-PARTY SERVICES
Our website is operated through Odoo. Odoo may process submitted information, cookies, server logs, browser and device information, and other technical data as a service provider. Analytics, payment, automation, or other third-party providers may process information under their own terms and privacy policies. Links to third-party websites or services are governed by those third parties' policies, not this Policy.
5. CUSTOMER DATA AND CONFIDENTIAL INFORMATION
The type of data processed for a customer automation varies by project and should be addressed in the applicable proposal, contract, or other written agreement. Customers are responsible for obtaining any notices, permissions, and legal authority needed for LJ Web Management and its providers to process data supplied by or on behalf of the customer. Unless specifically agreed in writing, customers should not provide highly sensitive information that is unnecessary for the services.
6. DATA RETENTION
We retain information for as long as reasonably necessary for the purposes described in this Policy, including providing services, maintaining business and transaction records, resolving disputes, enforcing agreements, and complying with legal obligations. Retention periods vary based on the type of information, the customer contract, operational needs, and applicable law. Copies may remain temporarily in backups after deletion from active systems.
7. DATA SECURITY
We use reasonable administrative, technical, and organizational measures designed to protect information. No method of transmission, storage, or processing is completely secure, and we cannot guarantee absolute security.
8. YOUR CHOICES AND RIGHTS
You may contact us to request access to, correction of, or deletion of personal information we maintain about you. We may need to verify your identity and may retain information when permitted or required by law. Depending on where you live, you may have additional privacy rights. You may control cookies through your browser and any cookie controls presented on our website; disabling some cookies may affect website functionality.
9. CHILDREN'S PRIVACY
Our website and services are intended for business users and are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, please contact us.
10. INTERNATIONAL PROCESSING
Our vendors may process information in the United States or other countries. Those countries may have privacy laws different from those where you live.
11. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. The revised version will be identified by an updated effective date. Material changes may also be communicated through the website or other appropriate means.
12. SCOPE AND INTERPRETATION
This Policy applies to personal information handled by LJ Web Management in connection with its public website, inquiry and appointment processes, consultations, proposals, customer onboarding, project delivery, system maintenance, support, billing, and related business operations.
This Policy does not automatically govern a customer's own collection or use of information through an automation that we build for that customer. In that situation, the customer may determine why and how information is processed, and the customer's privacy notice may apply. We may act as a service provider or processor under the customer's written instructions.
A Service Agreement, data-processing agreement, confidentiality agreement, or other written contract may contain additional privacy and security terms. If a project-specific written agreement imposes a higher or more specific obligation, we will follow that obligation for the covered project.
This Policy does not apply to information that cannot reasonably be linked to an identified or identifiable person, unless applicable law treats that information as personal information. Aggregated or deidentified information may be used for lawful business purposes, provided that it is maintained in a form that is not reasonably linkable to an individual.
13. SOURCES OF INFORMATION
We may collect information directly from you when you complete a form, request information, join a waitlist, schedule an appointment, attend a consultation, communicate with us, sign a Service Agreement, pay an invoice, provide project requirements, request support, or otherwise interact with us.
We may collect information from the business or organization you represent. For example, a company may give us the contact details of an employee, contractor, vendor, customer, or project stakeholder so that we can perform requested services.
We may receive information from referral partners, professional advisers, public business directories, social-media profiles, or other lawful public sources when reasonably relevant to a business inquiry or customer relationship.
We may receive information from Odoo and other service providers that operate our website, appointment tools, forms, email delivery, analytics, payment systems, security services, or customer-support functions.
We may collect information from software, applications, accounts, APIs, databases, devices, or systems that a customer authorizes us to connect to, inspect, configure, automate, or support.
We may derive information from other information we hold. Examples include identifying an inquiry as a likely business customer, associating communications with a project, calculating transaction status, or creating operational records about support and maintenance.
14. DETAILED CATEGORIES OF INFORMATION
Identity information may include a person's name, username, business role, title, employer, department, or relationship to a customer or prospect.
Contact information may include an email address, telephone number, business address, mailing address, preferred contact method, and communication preferences.
Appointment information may include the selected appointment type, date and time, time zone, scheduling status, rescheduling or cancellation history, meeting link, notes, and information submitted to explain the purpose of a meeting.
Communication information may include emails, contact-form submissions, messages, meeting notes, support requests, feedback, and records of our responses.
Business information may include a company name, industry, website, organizational role, workflow description, process requirements, operational objectives, existing software, integration needs, and budget or purchasing information.
Contract and transaction information may include proposals, statements of work, agreements, invoices, payment status, subscription status, service periods, refunds, transaction dates, amounts, billing contacts, and tax-related records.
Payment providers may collect payment-card numbers, bank details, authentication information, and other payment credentials. We generally receive transaction confirmation and limited billing information rather than full payment-card details.
Project information may include workflow maps, instructions, specifications, test cases, configuration data, sample records, error logs, change requests, approval records, and documentation created during the project.
Customer-provided content may include documents, spreadsheets, images, audio, text, databases, records, messages, and other content that a customer asks us to use or process.
Access information may include account identifiers, API keys, tokens, credentials, permissions, and connection details supplied for a project. Where feasible, customers should use temporary, limited, role-based, or revocable access rather than sharing personal master credentials.
Technical information may include IP address, browser type and version, operating system, device or platform type, language, approximate location, time zone, referring URL, requested page or resource, visit date and time, session identifier, and diagnostic information.
Usage information may include pages viewed, buttons or links selected, navigation paths, time spent, appointment conversions, form interactions, errors, and other information about how the website or a provided system is used.
Security information may include authentication events, suspected abuse indicators, access logs, fraud-prevention signals, malware or vulnerability findings, incident reports, and records used to investigate or prevent unauthorized activity.
Preference information may include language, region, time zone, cookie choices, communication choices, and saved website or account preferences.
Inference information may include reasonable conclusions drawn from business communications, website activity, or service history for operational planning, support prioritization, security, or understanding likely service interests.
Sensitive information may occasionally be included in customer-provided project data. We do not request sensitive information unless it is reasonably necessary for an agreed service. Customers should notify us before supplying regulated, highly sensitive, or unusually high-risk data so that appropriate terms and safeguards can be evaluated.
15. INFORMATION WE DO NOT INTENTIONALLY REQUEST THROUGH GENERAL WEBSITE FORMS
General contact, waitlist, and appointment forms are not intended for Social Security numbers, government identification numbers, financial-account credentials, full payment-card details, medical records, biometric identifiers, precise geolocation, information about children, or other highly sensitive information.
Please do not submit passwords, secret keys, confidential datasets, or sensitive personal information through a general website form or ordinary appointment description.
If sensitive information may be needed for a customer project, the parties should first determine an appropriate transfer method, access model, contractual framework, and security approach.
Receiving unsolicited sensitive information does not mean that we have agreed that the information is necessary, suitable for the services, or subject to special regulatory obligations beyond those imposed by applicable law and an executed written agreement.
16. PURPOSES OF PROCESSING IN DETAIL
We use identity and contact information to identify the person communicating with us, respond to questions, manage appointments, prepare meetings, and maintain business records.
We use inquiry and consultation information to understand a prospective customer's workflow, identify potential automation opportunities, evaluate feasibility, estimate scope, and prepare proposed next steps.
We use contract and billing information to create proposals and invoices, administer upfront build payments and monthly service fees, record payment status, calculate refunds where applicable, collect amounts due, and comply with accounting and tax obligations.
We use project information to plan, design, configure, develop, integrate, test, document, deploy, maintain, troubleshoot, and change automation systems.
We use customer-provided data to perform the specific services requested by the customer and described in a Service Agreement or other documented instruction.
We use technical and usage information to deliver pages, maintain sessions, remember preferences, understand traffic, diagnose errors, improve navigation, evaluate performance, and plan website improvements.
We use security information to authenticate access, detect abuse, investigate suspected incidents, prevent fraud, protect systems and data, enforce agreements, and preserve evidence where reasonably necessary.
We use communications and support records to track requests, coordinate work, confirm decisions, resolve disputes, train personnel or contractors where appropriate, and improve service processes.
We may use contact information to send requested information, appointment confirmations, reminders, project communications, invoices, security notices, service updates, or legally required notices.
Where permitted by law, we may send information about services that may be relevant to an existing or prospective business customer. Recipients may opt out of promotional email using the instructions in the message or by contacting us.
We may use information to establish, exercise, or defend legal claims; obtain professional advice; conduct audits; respond to lawful process; and comply with regulatory, tax, accounting, insurance, and recordkeeping requirements.
We may use aggregated or deidentified information to understand general trends, measure service performance, develop internal benchmarks, and improve our offerings.
We do not use customer confidential information to train a public artificial-intelligence model unless the customer has expressly authorized that use in writing and the applicable provider terms and safeguards have been addressed.
17. PROCESSING ROLES
For our own website, appointments, business contacts, billing, and internal operations, LJ Web Management generally determines the purposes and means of processing and acts as the business or controller.
For information placed into a customer's automation, the customer may determine the purposes and essential means of processing. In that setting, LJ Web Management may act as the customer's service provider, contractor, or processor.
The correct role depends on the facts, applicable law, system design, and written agreement. Labels in this Policy do not override a role assigned by law.
Customers acting as controllers or businesses are responsible for providing required privacy notices, selecting a lawful basis where required, honoring individual rights, limiting instructions to lawful purposes, and executing any required data-processing terms.
When we process information solely on a customer's documented instructions, requests concerning that information may need to be directed to the customer. We may refer the requester to the customer or assist the customer as required by contract or law.
18. LEGAL BASES WHERE APPLICABLE
Some privacy laws require a legal basis for processing. Depending on the context, we may process information because it is necessary to take requested steps before entering a contract or to perform a contract.
We may process information to comply with legal obligations, including tax, accounting, recordkeeping, security, fraud-prevention, and lawful disclosure requirements.
We may process information for legitimate interests such as operating and improving our business, communicating with business contacts, securing systems, preventing abuse, administering customer relationships, and protecting legal rights, provided those interests are not overridden by applicable individual rights.
We may process information with consent where consent is appropriate or required. Consent may be withdrawn prospectively, but withdrawal does not affect processing that was lawful before withdrawal.
We may process information to protect vital interests or for other grounds recognized by applicable law in unusual circumstances.
The legal basis can vary by activity and jurisdiction. Contact us if you have a question about the basis for a particular activity.
19. WEBSITE HOSTING AND ODOO
Our public website currently uses an Odoo-hosted domain and Odoo website services. Information entered into website forms or appointment tools may be stored in or transmitted through our Odoo environment.
Odoo states that its services may collect contact data submitted through forms and may passively log browser and server information such as IP address, visit date and time, accessed resource, browser version, platform, and referring page.
Odoo services may use session and security cookies to support expected website functions. Depending on configuration, preference or analytics technologies may also be used.
Odoo's available features, providers, hosting arrangements, subprocessors, cookies, and retention practices may change. Odoo's own privacy and security materials govern Odoo's independent obligations and provide current details about its services.
The fact that Odoo documents an optional feature or provider does not mean that LJ Web Management has enabled that feature or uses that provider on every page.
We will not represent that a particular Odoo analytics, advertising, payment, session-recording, form-protection, or integration feature is active unless it is enabled in our environment.
20. COOKIES AND SIMILAR TECHNOLOGIES
A cookie is a small text file or identifier stored by or through a browser. Similar technologies may include local storage, pixels, tags, scripts, and server-side identifiers.
Essential cookies may be used to deliver website functions, maintain sessions, route traffic, protect forms, prevent abuse, remember security choices, or support content requested by the visitor.
Preference cookies may remember language, region, time zone, or other choices so that the website can provide a more consistent experience.
Analytics technologies may measure visits, page views, referrals, general location, device characteristics, navigation, and interactions so that we can understand and improve website performance.
Third-party content, embedded media, social links, or integrations may allow the applicable third party to receive technical information when the content loads or when a visitor interacts with it.
Cookie availability and duration vary by provider, configuration, browser, consent choice, and feature. The website's cookie notice or cookie-management interface, when displayed, provides additional current information.
You can use browser settings to block, delete, or receive warnings about cookies. Blocking essential cookies may prevent portions of the website from operating correctly.
Where required, optional cookies will be subject to the choices presented through an available consent mechanism. A visitor may be able to revise a cookie choice through that mechanism or by clearing stored cookies.
We do not promise that browser-based Global Privacy Control or Do Not Track signals will be recognized in every context. Where applicable law requires recognition of a valid signal, we will endeavor to process it as legally required.
21. ANALYTICS
We use website analytics to understand general traffic, visitor behavior, page performance, and interactions with inquiry or appointment pathways.
Depending on the Odoo configuration, analytics may be provided by Odoo, an Odoo-integrated analytics service, or another configured provider.
Analytics information may include technical, usage, referral, device, approximate-location, and event information. It may be aggregated or associated with online identifiers.
Analytics providers may set their own cookies or receive information under their own privacy terms. Optional analytics may depend on visitor consent where required.
We use analytics for measurement and improvement. We do not state in this Policy that we use behavioral advertising or cross-context advertising unless such technology is actually enabled.
22. APPOINTMENTS, CONTACT FORMS, AND COMMUNICATIONS
When you request an appointment or contact us, we collect at least the name, email address, telephone number, and information you include in the request.
Appointment records may be used to confirm, remind, reschedule, cancel, conduct, and follow up on consultations.
Communications may pass through email, calendar, videoconferencing, telephone, Odoo, or other tools selected for the interaction.
Do not assume that ordinary email, voicemail, or form submissions are encrypted end to end. Use a transfer method approved for the project when sending confidential or sensitive material.
We may keep a record of business communications to provide continuity, document decisions, resolve questions, manage the customer relationship, and meet legal or accounting obligations.
We do not record telephone or video calls without providing notice or obtaining consent when required by applicable law.
23. CUSTOMER PROJECT DATA
Customer project data may vary substantially from one automation to another. A system may process no personal information, limited business contact information, or information supplied from a customer's existing operations.
Before a project, customers should identify the expected categories of data, data subjects, sources, purposes, destinations, retention needs, access roles, regulated information, and geographic restrictions.
Customers should minimize the data made available for discovery, testing, and development. Synthetic, deidentified, masked, or limited sample data should be used where reasonably practical.
Customers should not provide production credentials when temporary or scoped access will work. Access should be revoked when no longer needed.
We may create temporary copies, transformed data, logs, error samples, test outputs, or backups as reasonably necessary to perform the work. The applicable Service Agreement may specify additional deletion or return procedures.
We may decline to receive or process data when the proposed use creates legal, security, ethical, or operational risk that has not been adequately addressed.
We do not independently verify every item of customer-provided data. Customers are responsible for the accuracy, quality, legality, and appropriateness of data supplied for their automations.
24. ARTIFICIAL INTELLIGENCE AND AUTOMATION PROVIDERS
A customer project may use artificial-intelligence, machine-learning, workflow, integration, or cloud services supplied by third parties.
The providers used for a particular project should be identified through the project scope, architecture, configuration, or Service Agreement when material to data handling.
Information submitted to a third-party model or automation service may be processed under that provider's business terms, privacy terms, data-retention settings, and security controls.
We seek to configure services consistently with the agreed project requirements, but customers should understand that third-party terms, features, model behavior, and data practices may change.
Customers should not submit restricted or highly sensitive information to an AI feature unless the parties have determined that the provider, account type, settings, contract, and intended use are appropriate.
Automated outputs may contain personal information derived from customer inputs or connected sources. Customers are responsible for appropriate review, correction, access controls, and use of those outputs.
25. SERVICE PROVIDERS AND CONTRACTORS
We may use vendors and contractors for hosting, website operation, scheduling, forms, email, communications, videoconferencing, analytics, payment processing, accounting, cloud infrastructure, development, integrations, security, support, and professional advice.
Service providers receive information reasonably necessary for their assigned function. The precise information depends on the provider and service used.
We seek to select providers appropriate to the nature of the service and information. No vendor relationship eliminates all privacy or security risk.
Providers may use subprocessors, infrastructure, or personnel in multiple locations, subject to their own contractual and legal obligations.
Some third parties act solely on our instructions, while others independently determine aspects of their processing. An independent controller's own privacy policy governs its independent processing.
Our provider list may change as services are added, replaced, upgraded, or discontinued. Project-specific providers may also differ by customer.
26. OTHER DISCLOSURES
We may disclose information within LJ Web Management to personnel and authorized contractors who need it for their responsibilities.
We may disclose information to the business customer that arranged an appointment, project, account, or service relationship involving the requester.
We may disclose information at a customer's direction, including to systems, vendors, recipients, or advisers selected by that customer.
We may disclose information to accountants, attorneys, insurers, auditors, and other professional advisers for legitimate business and legal purposes.
We may disclose information to investigate suspected fraud, abuse, security incidents, contract violations, or threats to rights, property, systems, or safety.
We may preserve and disclose information in response to a subpoena, court order, warrant, regulatory inquiry, or other lawful process.
Where legally permitted, we may evaluate the validity and scope of a request, seek clarification, object to an improper request, or notify an affected customer before disclosure.
We may disclose information in due diligence or a business transaction involving investment, financing, restructuring, sale, merger, acquisition, bankruptcy, or transfer of assets, subject to appropriate confidentiality measures where feasible.
We may disclose aggregated or deidentified information that does not reasonably identify an individual.
27. SALE, SHARING, AND TARGETED ADVERTISING
We do not sell personal information for money.
We do not knowingly sell personal information about children.
We do not currently state that we share personal information for cross-context behavioral advertising or process it for targeted advertising as those terms are defined by particular state privacy laws.
Some privacy laws define sale or sharing broadly and may treat certain advertising or analytics disclosures as regulated even when no money changes hands.
If our use of advertising or analytics technology changes in a way that creates a regulated sale, sharing, or targeted-advertising activity, we will update our notice and provide legally required choices before or when the change applies.
Service-provider disclosures necessary to operate our business are not intended as sales of personal information.
28. DATA MINIMIZATION AND PURPOSE LIMITATION
We seek to collect information reasonably relevant to an inquiry, appointment, customer relationship, project, legal obligation, security need, or business operation.
We encourage customers to limit project access and datasets to what is necessary for the agreed purpose.
We may ask a customer to remove unnecessary fields, mask sensitive values, use test data, or limit integration permissions.
We may use information for a compatible purpose reasonably related to the purpose described at collection, the customer relationship, system security, legal compliance, or protection of rights.
If a materially different use requires consent or a new notice under applicable law, we will seek that consent or provide that notice as required.
29. RETENTION CRITERIA
We do not use a single retention period for every category of information.
Inquiry and appointment information may be retained while we respond, evaluate a potential relationship, maintain reasonable follow-up records, and protect against duplicate, abusive, or disputed communications.
Customer relationship and project information may be retained during the relationship and for a reasonable period afterward to provide continuity, document work, address support, enforce agreements, resolve disputes, and meet legal obligations.
Contract, invoice, payment, tax, and accounting records may be retained for periods required or permitted by applicable law and ordinary business recordkeeping practices.
Security logs and incident records may be retained based on the nature of the event, investigative needs, system design, contractual commitments, and legal requirements.
Credentials and access tokens should be retained only while reasonably needed for the authorized function, subject to technical limitations, backup cycles, and project-specific requirements.
Customer project data may be returned, deleted, deactivated, archived, or retained according to the Service Agreement, customer instructions, platform capabilities, legal holds, and legitimate recordkeeping needs.
Backup copies may remain until overwritten or deleted through the applicable backup cycle. Backups are generally maintained for recovery and integrity rather than ordinary business use.
We may retain information longer when necessary for litigation, investigation, insurance, legal hold, security response, collection of amounts due, or compliance with law.
We may retain a minimal record of a request or transaction to demonstrate compliance, prevent fraud, document an opt-out, or protect legal rights even when other information is deleted.
We may delete information earlier when it is no longer reasonably needed and deletion is operationally feasible and legally permitted.
Third-party providers determine their own retention schedules subject to their agreements, settings, and legal obligations.
30. SECURITY PROGRAM
We use safeguards designed to be reasonable for the nature of our business and the information involved.
Safeguards may include access controls, authentication, least-privilege practices, account separation, secure configuration, encryption provided by platforms, backups, logging, vendor review, confidentiality obligations, and incident-response procedures.
The safeguards appropriate to a public contact form differ from those appropriate to a customer system processing confidential or regulated information.
Project-specific security requirements should be identified before implementation and stated in the applicable Service Agreement when material.
Customers are responsible for securing their own devices, networks, accounts, credentials, users, backups, and connected systems.
Customers should promptly remove access for departed personnel, rotate exposed credentials, apply updates, review permissions, and report suspected unauthorized activity.
No security control is perfect. Human error, malicious activity, software defects, vendor failures, and events beyond reasonable control can create risk despite safeguards.
We cannot guarantee that information will never be accessed, disclosed, altered, lost, or destroyed without authorization.
31. SECURITY INCIDENTS
We maintain procedures intended to identify, assess, contain, investigate, and respond to suspected security incidents affecting information under our control.
An event is not necessarily a legally reportable breach. The determination depends on the information, protections, access, acquisition, applicable law, and surrounding facts.
When legally required, we will provide or support notifications to affected individuals, customers, regulators, consumer reporting agencies, or others within the required time and manner.
When we process information for a customer, the applicable contract may assign incident-notification and cooperation responsibilities between the parties.
Customers should report suspected incidents involving our services promptly to info@ljwebmanagement.com and include enough non-sensitive detail for us to identify the relevant account or project.
Do not include passwords, full payment-card details, or unnecessary sensitive information in an initial incident email.
We may preserve logs, restrict access, suspend integrations, rotate credentials, or take other reasonable steps while investigating an incident.
32. INDIVIDUAL PRIVACY REQUESTS
Depending on applicable law, an individual may have rights to know or access personal information, obtain a copy, correct inaccurate information, request deletion, restrict or object to processing, withdraw consent, or receive information in a portable format.
Some jurisdictions provide rights to opt out of sale, sharing, targeted advertising, or certain profiling. We do not currently describe those activities as part of our ordinary practices, but we will honor rights that legally apply.
Rights are not absolute. Exceptions may apply for completing transactions, providing requested services, protecting security, preventing fraud, maintaining records, exercising legal rights, complying with law, or protecting another person's rights.
A request should identify the person, the relationship with LJ Web Management, the relevant email address or telephone number, the approximate interaction date, and the right being requested.
We may request additional information reasonably necessary to verify identity, authority, and the scope of the request.
We will not request more verification information than reasonably needed. Verification methods may vary based on request sensitivity and the risk of unauthorized disclosure or deletion.
If we cannot verify a request, we may deny it or limit our response and explain the reason where required.
An authorized agent may submit a request where permitted. We may ask for proof of authorization and may verify the request directly with the individual.
If information is controlled by one of our business customers, we may direct the requester to that customer and assist as required by law or contract.
We may charge a fee or decline repetitive, excessive, manifestly unfounded, technically infeasible, or abusive requests where applicable law permits.
Where the CCPA applies, we aim to confirm receipt within 10 days and substantively respond within 45 days of a verifiable request, with one 45-day extension where reasonably necessary and notice of that extension provided within the initial 45-day period. Where the GDPR or UK GDPR applies, we aim to respond within one month of a verifiable request, extendable by a further two months for complex or numerous requests, with notice of any extension provided within the initial month. For any other applicable law, we aim to respond within the period that law requires, with notice of any permitted extension.
If a request is denied, the requester may have a right to appeal or complain to a regulator depending on the applicable law.
We do not discriminate against a person for exercising an applicable privacy right.
33. COMMUNICATION CHOICES
You may ask us to stop promotional email by using an unsubscribe instruction provided in the message or contacting us.
An opt-out from promotional messages does not prevent transactional, appointment, billing, project, security, legal, or service communications.
You may ask us to update your business contact details or communication preferences.
Telephone and text-message choices will be honored as required by applicable law and any consent language presented when a number is collected.
We do not state that consent to promotional communications is required to purchase services unless expressly disclosed and legally permitted.
34. UNITED STATES STATE PRIVACY NOTICES
Privacy rights vary by state and may depend on residency, the nature of the information, the purpose of processing, and whether a law applies to LJ Web Management.
If an applicable state law grants you rights, you may submit a request using the contact details below.
The categories described in this Policy include identifiers, business contact information, internet or electronic activity, commercial or transaction information, professional or employment-related information, approximate location inferred from technical data, customer-provided content, and inferences.
We collect these categories from individuals, their organizations, customer-authorized systems, service providers, referrals, public business sources, and technical interactions.
We use and disclose these categories for the business and commercial purposes detailed throughout this Policy.
We do not knowingly use sensitive personal information to infer characteristics about individuals for unrelated purposes.
We do not offer financial incentives in exchange for personal information unless a separate notice describing material terms is provided.
State-law requests may be subject to verification, exceptions, response periods, appeal processes, and agent requirements described by the applicable law.
35. ILLINOIS RESIDENTS
LJ Web Management is based in Illinois and handles information in accordance with applicable Illinois requirements.
Illinois law may require notification following certain breaches involving defined categories of personal information.
This Policy is not a promise that every security event meets the legal definition of a breach or requires individual notification.
Illinois residents may contact us with questions or requests concerning personal information we maintain about them.
Certain Illinois laws govern specific information, such as biometric identifiers or health-related data. We do not intentionally collect biometric identifiers through our general website, contact, or appointment forms.
A customer project involving regulated Illinois data requires advance review and an appropriate written agreement before implementation.
36. CALIFORNIA AND OTHER COMPREHENSIVE STATE LAWS
If a comprehensive state privacy law applies to LJ Web Management and your information, you may have rights described in Section 32 and any additional rights provided by that law.
The applicability thresholds and exemptions differ by state. Business-contact information, employee information, customer-controlled project data, nonprofit activity, and other categories may be treated differently across laws.
Nothing in this Policy is intended to provide fewer rights than applicable law.
We do not extend a jurisdiction-specific statutory right to every person worldwide merely by describing it here, but we may honor requests voluntarily when reasonable and lawful.
37. EEA, UNITED KINGDOM, AND SWITZERLAND
If data-protection law in the European Economic Area, United Kingdom, or Switzerland applies, individuals may have rights of access, correction, erasure, restriction, objection, portability, and withdrawal of consent.
Individuals may also have a right to complain to the supervisory authority in their place of residence, work, or alleged infringement.
Where required, we rely on a legal basis described in Section 18.
Information may be transferred to the United States or other countries that may not provide the same level of legal protection as the individual's home country.
Where legally required, transfers may rely on adequacy decisions, approved contractual protections, provider transfer mechanisms, consent, or another recognized legal basis.
Customers exporting personal data through a project are responsible for identifying and documenting any transfer restrictions that apply to their use.
38. INTERNATIONAL USERS
Our business is located in the United States, and our website and services are primarily offered from the United States.
If you access the website from another country, information may be transferred to and processed in the United States and in locations used by our providers.
Local law may grant rights or impose obligations beyond those described here. Contact us if you believe a particular local requirement applies.
We may limit or decline a project when data-localization, licensing, regulatory, or cross-border requirements cannot reasonably be satisfied.
39. CHILDREN
Our general website and services are directed to businesses and business representatives, not children.
We do not knowingly collect personal information online from children under 13 through our general website.
We do not knowingly sell or share children's personal information for targeted advertising.
If we learn that a child submitted personal information through a general form without appropriate authorization, we will take reasonable steps to delete it where required.
A customer must not connect children's data to an automation without disclosing that fact before the project and establishing that the processing is lawful and appropriately safeguarded.
Parents or guardians who believe a child provided information may contact us using the details below.
40. THIRD-PARTY LINKS AND EMBEDDED CONTENT
Our website or communications may link to third-party websites, social-media pages, video platforms, appointment interfaces, maps, or other external resources.
A link does not mean that we control the third party's privacy, security, content, or practices.
The third party may collect information when you visit, sign in, play media, follow a link, or otherwise interact with its service.
Review the third party's privacy notice and settings before providing information.
We are not responsible for a third party's independent processing except to the extent applicable law provides otherwise.
41. BUSINESS TRANSFERS
Information may be evaluated, disclosed, or transferred in connection with a potential or completed financing, investment, merger, acquisition, reorganization, sale, bankruptcy, or transfer of business assets.
Recipients may include advisers, potential counterparties, lenders, investors, successors, and their service providers, subject to confidentiality restrictions where appropriate.
A successor may continue to process information consistently with this Policy, applicable notices, contracts, and law.
If a transaction materially changes the purposes for which personal information is used, additional notice or choice will be provided when required.
42. DEIDENTIFIED AND AGGREGATED INFORMATION
We may create statistics, reports, metrics, or datasets that are aggregated or deidentified.
We may use and disclose that information for operations, planning, security, research, service improvement, and lawful business purposes.
We will not intentionally attempt to reidentify information maintained as deidentified except to test whether deidentification measures work, prevent fraud, protect security, or as otherwise permitted by law.
Information is not considered deidentified merely because obvious identifiers have been removed if it can still reasonably be linked to a person.
43. AUTOMATED DECISION-MAKING
Our general website and appointment process are not intended to make solely automated decisions that produce legal or similarly significant effects about visitors.
Analytics may automatically categorize traffic, detect patterns, or generate measurements, but those functions are used for website operation, measurement, or security.
Customer automations may include automated rules or AI-assisted outputs selected for the customer's workflow.
The customer is responsible for determining whether its use involves legally regulated profiling or significant decisions and for implementing required notices, assessments, opt-outs, explanations, testing, and human review.
We may decline to design a system that would make unsafe, unlawful, deceptive, discriminatory, or inadequately supervised high-impact decisions.
44. PRIVACY BY DESIGN FOR CUSTOMER PROJECTS
Where appropriate to the project, we may discuss data minimization, role-based access, approval steps, logging, testing, retention, deletion, vendor selection, and human review.
Privacy and security requirements can affect project scope, architecture, schedule, and cost.
Customers should raise regulatory, contractual, residency, confidentiality, and risk requirements before accepting a proposal.
A technical feature does not by itself make a customer's use legally compliant. Compliance also depends on purpose, notices, consent, governance, training, policies, and actual operation.
Customers remain responsible for independent legal advice concerning their business and use of the delivered automation.
45. ACCURACY AND CORRECTION
We rely on individuals and customers to provide accurate information and notify us when material details change.
You may ask us to correct inaccurate business contact or appointment information.
We may preserve prior versions where reasonably necessary for transaction history, audit, security, dispute resolution, or legal compliance.
Correcting information in our active records may not automatically correct information independently maintained by a customer, vendor, or third party.
46. ACCOUNT AND CREDENTIAL PRACTICES
If a project involves an account, each user should use unique credentials where supported and should not share authentication secrets through insecure channels.
Customers should enable multi-factor authentication when available and appropriate.
Customers should grant only the permissions needed for the service and periodically review active users, tokens, integrations, and connected applications.
We may request credential rotation following exposure, personnel changes, project completion, suspicious activity, or a provider security notice.
We are not responsible for unauthorized access caused by a customer's failure to protect its credentials, subject to applicable law and written agreements.
47. CHANGES TO SERVICES AND PROVIDERS
Our website, services, vendors, integrations, and business processes may evolve.
We may add, replace, or discontinue providers when reasonably necessary for functionality, security, availability, cost, or business needs.
Project-specific vendor changes will be handled according to the applicable Service Agreement and any required notice or approval process.
We may update this Policy to reflect material changes in collection, use, disclosure, rights, or law.
The effective date at the top identifies the current version.
48. NOTICE OF MATERIAL CHANGES
When required, we will provide notice of a material change through the website, email, customer communication, or another reasonable method.
Changes apply prospectively from the stated effective date unless law permits or requires another approach.
If consent is required for a materially different use of previously collected information, we will seek consent before that use.
Continued use of a service after an updated notice does not waive privacy rights that cannot legally be waived.
49. DEFINITIONS
"Customer" means a person or organization that requests, purchases, or receives services from LJ Web Management.
"Customer project data" means information supplied, accessed, generated, or processed in connection with a customer's automation project.
"Personal information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household, where applicable law uses that or a similar definition.
"Process" or "processing" means an operation performed on information, including collection, access, storage, use, transmission, alteration, analysis, disclosure, deletion, or destruction.
"Service Agreement" means a proposal, contract, statement of work, order, invoice, data-processing agreement, or other written agreement governing particular services.
"Service provider" includes a vendor, contractor, processor, subprocessor, or platform used to support operations or deliver services, as the context requires.
"Sensitive information" means information treated as sensitive, special-category, regulated, or high-risk under applicable law or the relevant project context.
"Website" means https://ljwebmanagement.com and pages operated by LJ Web Management through that domain, unless stated otherwise.
50. HOW TO CONTACT US OR SUBMIT A REQUEST
Privacy questions, correction requests, deletion requests, access requests, complaints, and security reports may be sent to info@ljwebmanagement.com.
Please use a subject line that identifies the nature of the request, such as "Privacy Request" or "Security Report."
Include your name, relevant contact information, relationship with LJ Web Management, and enough detail for us to understand the request.
Do not include passwords, full payment-card numbers, secret keys, or unnecessary sensitive information in the initial message.
We may contact you for verification or clarification.
You may also contact us by telephone or mail using the information below.
51. CONTACT US
LJ Web Management
1108 E 9th St.
Lockport, IL 60441
United States
Email: info@ljwebmanagement.com
Phone: +1 877-559-3268
Website: https://ljwebmanagement.com