What we collect, and what we don't.
This policy covers lxsys.com, the enquiries and support work that follow from it, and the tools we use to publish to our own social media accounts. It is written to be read, not to be survived. Last updated 23 August 2026.
Who we are
LXSYS designs, installs and supports AI-driven meeting rooms. For the information described here, LXSYS is the controller — we decide what is collected and why.
| Company | LXSYS |
|---|---|
| Address | 230 Goddard, Irvine, CA 92618, United States |
| sales@lxsys.com | |
| Phone | (949) 581-8000 |
What we collect
There is no account to create on this site, and we run no advertising trackers. We ask for what the job needs and nothing beyond it.
When you browse this site
Our web server records the request: IP address, browser user agent, the page requested, and the time. We use this to keep the site up, investigate faults, and block abuse. We also count page views in aggregate to see which pages are useful.
When you contact us
Whatever you choose to send — typically your name, email address, phone number, company, and what you tell us about the room. If you use the on-site assistant, your questions are stored so we can improve the answers and follow up if you ask us to.
When you subscribe to Room notes
Your email address. Nothing else, and only until you unsubscribe.
When you become a customer
Site and room details, a billing contact, a delivery address, and the records of the work we did — as-builts, asset tags, service history.
Social media integrations
LXSYS publishes to its own accounts on LinkedIn, X, Meta (Facebook and Instagram) and TikTok. We use a self-hosted scheduling tool to draft, schedule and publish those posts and to read back how they performed. Only accounts owned by LXSYS, or connected by an authorized LXSYS administrator who has the right to do so, are ever linked to that tool.
When an account is connected through a platform's official OAuth flow, the platform gives us:
- the account or page identifier, handle and display name
- the profile or page picture
- the list of pages or organizations that the connecting account is permitted to post to
- performance metrics for the posts we published — impressions, engagements, clicks and similar counts
We do not receive, request or store private messages, direct messages, contact lists, follower lists, email addresses of followers, or the content of anyone else's account.
How access tokens are used
Connecting an account gives us an access token: a credential the platform issues that lets our tool act on that account, within the permissions you approved on the platform's own consent screen.
- Tokens are used only to publish or schedule content to the connected account and to read back metrics for posts we published.
- They are stored encrypted at rest on our own server. They are never placed in a browser, a spreadsheet, or a third-party service.
- They are never sold, rented, shared or transferred to anyone.
- They are not used to build advertising or behavioural profiles, and are never combined with data bought from a data broker.
- They are refreshed only for as long as the connection is live.
You can revoke a token at any moment from the platform's own settings — LinkedIn, X, Facebook, Instagram and TikTok each provide this — or by emailing sales@lxsys.com. When a connection is removed, the token and the connected account details listed above are deleted from our systems.
Our use of information received from these APIs follows each platform's developer terms, including the Meta Platform Terms, the LinkedIn API Terms of Use, the X Developer Agreement and Policy, and the TikTok Developer Terms of Service. Where a platform's terms are stricter than this policy, the platform's terms apply.
Cookies
We use only the cookies needed to run the site and to remember your cookie choice. If you choose Accept, we also load Google Analytics 4, which sets its own first-party cookies so we can see which pages are useful; Google processes that data for us. If you choose Essential only, Google Analytics is never loaded at all — nothing is requested from Google and no analytics cookie is set. Choosing Essential only in the banner is respected — it is not a dark pattern with a second meaning. There are no advertising or cross-site tracking cookies on this domain.
We do not sell your personal information
We have never sold personal information, and we do not share it for cross-context behavioural advertising. No arrangement exists under which anyone pays us for it.
We do share it, narrowly, with: the hosting and infrastructure providers that run our servers; the email service that delivers our replies and newsletter; the social platforms themselves, at the moment we publish a post; our professional advisers where they need it; and any authority where the law requires it. Each is permitted to use it only for that purpose.
How it is protected
Data is held on servers we control in the United States. Traffic is encrypted in transit with TLS. Credentials and access tokens are encrypted at rest and scoped per service. Administrative surfaces are not publicly indexed, and access is limited to named staff who need it. Backups are taken and access-controlled the same way.
No system is perfect. If a breach affects your personal information, we will tell you and the relevant authority within the time the law allows, and we will tell you what we know rather than what sounds best.
How long we keep it
| Web server logs | Up to 90 days |
|---|---|
| Enquiries and quotes | Up to 7 years, as business and tax records |
| Newsletter subscription | Until you unsubscribe |
| Social access tokens and connected account details | Until the connection is removed, then deleted |
| Post performance metrics | Up to 24 months |
Your rights
Whatever jurisdiction you are in, you can ask us to:
- tell you what we hold about you, and give you a copy
- correct anything that is wrong
- delete it, where we are not required to keep it
- send it to you or another provider in a portable format
- stop or limit a particular use, or withdraw a consent you gave earlier
If you are in California
The CCPA, as amended by the CPRA, gives you the right to know what is collected and why, to delete it, to correct it, to opt out of its sale or sharing, and to limit the use of sensitive personal information. We do not sell or share personal information, and we do not collect sensitive personal information as that term is defined, so there is nothing to opt out of — but the right stands and we will confirm that in writing if you ask. You will never be treated differently for exercising any of it. An authorized agent may act for you with written proof.
To exercise any right, email sales@lxsys.com. We reply within one business day and complete the request within 45 days, extending only where the law allows and telling you if we do.
Children
This site and our services are for businesses. They are not directed at children, and we do not knowingly collect information from anyone under 16. If you believe we have, write to us and we will delete it.
Changes
If this policy changes, the date at the top changes with it. If a change materially affects how we use information already collected, we will say so on this page rather than hope you do not notice.
Contact
Questions, requests, or a complaint about how we handled your information:
| Company | LXSYS |
|---|---|
| Address | 230 Goddard, Irvine, CA 92618, United States |
| sales@lxsys.com | |
| Phone | (949) 581-8000 |
See also our Terms of Service.