What we collect, and what we don't.

This policy covers lxsys.com, the enquiries and support work that follow from it, and the tools we use to publish to our own social media accounts. It is written to be read, not to be survived. Last updated 23 August 2026.

Who we are

LXSYS designs, installs and supports AI-driven meeting rooms. For the information described here, LXSYS is the controller — we decide what is collected and why.

CompanyLXSYS
Address230 Goddard, Irvine, CA 92618, United States
Emailsales@lxsys.com
Phone(949) 581-8000

What we collect

There is no account to create on this site, and we run no advertising trackers. We ask for what the job needs and nothing beyond it.

When you browse this site

Our web server records the request: IP address, browser user agent, the page requested, and the time. We use this to keep the site up, investigate faults, and block abuse. We also count page views in aggregate to see which pages are useful.

When you contact us

Whatever you choose to send — typically your name, email address, phone number, company, and what you tell us about the room. If you use the on-site assistant, your questions are stored so we can improve the answers and follow up if you ask us to.

When you subscribe to Room notes

Your email address. Nothing else, and only until you unsubscribe.

When you become a customer

Site and room details, a billing contact, a delivery address, and the records of the work we did — as-builts, asset tags, service history.

Social media integrations

LXSYS publishes to its own accounts on LinkedIn, X, Meta (Facebook and Instagram) and TikTok. We use a self-hosted scheduling tool to draft, schedule and publish those posts and to read back how they performed. Only accounts owned by LXSYS, or connected by an authorized LXSYS administrator who has the right to do so, are ever linked to that tool.

When an account is connected through a platform's official OAuth flow, the platform gives us:

  • the account or page identifier, handle and display name
  • the profile or page picture
  • the list of pages or organizations that the connecting account is permitted to post to
  • performance metrics for the posts we published — impressions, engagements, clicks and similar counts

We do not receive, request or store private messages, direct messages, contact lists, follower lists, email addresses of followers, or the content of anyone else's account.

How access tokens are used

Connecting an account gives us an access token: a credential the platform issues that lets our tool act on that account, within the permissions you approved on the platform's own consent screen.

  • Tokens are used only to publish or schedule content to the connected account and to read back metrics for posts we published.
  • They are stored encrypted at rest on our own server. They are never placed in a browser, a spreadsheet, or a third-party service.
  • They are never sold, rented, shared or transferred to anyone.
  • They are not used to build advertising or behavioural profiles, and are never combined with data bought from a data broker.
  • They are refreshed only for as long as the connection is live.

You can revoke a token at any moment from the platform's own settings — LinkedIn, X, Facebook, Instagram and TikTok each provide this — or by emailing sales@lxsys.com. When a connection is removed, the token and the connected account details listed above are deleted from our systems.

Our use of information received from these APIs follows each platform's developer terms, including the Meta Platform Terms, the LinkedIn API Terms of Use, the X Developer Agreement and Policy, and the TikTok Developer Terms of Service. Where a platform's terms are stricter than this policy, the platform's terms apply.

Cookies

We use only the cookies needed to run the site and to remember your cookie choice. If you choose Accept, we also load Google Analytics 4, which sets its own first-party cookies so we can see which pages are useful; Google processes that data for us. If you choose Essential only, Google Analytics is never loaded at all — nothing is requested from Google and no analytics cookie is set. Choosing Essential only in the banner is respected — it is not a dark pattern with a second meaning. There are no advertising or cross-site tracking cookies on this domain.

We do not sell your personal information

We have never sold personal information, and we do not share it for cross-context behavioural advertising. No arrangement exists under which anyone pays us for it.

We do share it, narrowly, with: the hosting and infrastructure providers that run our servers; the email service that delivers our replies and newsletter; the social platforms themselves, at the moment we publish a post; our professional advisers where they need it; and any authority where the law requires it. Each is permitted to use it only for that purpose.

How it is protected

Data is held on servers we control in the United States. Traffic is encrypted in transit with TLS. Credentials and access tokens are encrypted at rest and scoped per service. Administrative surfaces are not publicly indexed, and access is limited to named staff who need it. Backups are taken and access-controlled the same way.

No system is perfect. If a breach affects your personal information, we will tell you and the relevant authority within the time the law allows, and we will tell you what we know rather than what sounds best.

How long we keep it

Web server logsUp to 90 days
Enquiries and quotesUp to 7 years, as business and tax records
Newsletter subscriptionUntil you unsubscribe
Social access tokens and connected account detailsUntil the connection is removed, then deleted
Post performance metricsUp to 24 months

Your rights

Whatever jurisdiction you are in, you can ask us to:

  • tell you what we hold about you, and give you a copy
  • correct anything that is wrong
  • delete it, where we are not required to keep it
  • send it to you or another provider in a portable format
  • stop or limit a particular use, or withdraw a consent you gave earlier

If you are in California

The CCPA, as amended by the CPRA, gives you the right to know what is collected and why, to delete it, to correct it, to opt out of its sale or sharing, and to limit the use of sensitive personal information. We do not sell or share personal information, and we do not collect sensitive personal information as that term is defined, so there is nothing to opt out of — but the right stands and we will confirm that in writing if you ask. You will never be treated differently for exercising any of it. An authorized agent may act for you with written proof.

To exercise any right, email sales@lxsys.com. We reply within one business day and complete the request within 45 days, extending only where the law allows and telling you if we do.

Children

This site and our services are for businesses. They are not directed at children, and we do not knowingly collect information from anyone under 16. If you believe we have, write to us and we will delete it.

Changes

If this policy changes, the date at the top changes with it. If a change materially affects how we use information already collected, we will say so on this page rather than hope you do not notice.

Contact

Questions, requests, or a complaint about how we handled your information:

CompanyLXSYS
Address230 Goddard, Irvine, CA 92618, United States
Emailsales@lxsys.com
Phone(949) 581-8000

See also our Terms of Service.