Last updated: August 26, 2026
Private by default
We do not publish a client list. A client’s identity, relationship with LWS, website ownership, domains, personnel, credentials, architecture, source code, analytics, security posture, business records, content, project status, pricing, and communications are treated as non-public unless the client gives express written permission or disclosure is legally required.
Limited access and use
We request only the access reasonably needed for the agreed work, use it only for that work and related security, support, billing, or legal obligations, and limit access to authorized personnel and providers with a legitimate need. Client access does not authorize unrelated marketing, public case studies, model training, portfolio display, or reuse of client content.
Credentials and production data
Credentials belong in an approved secret manager or access-control system, not email, public forms, source code, tickets, screenshots, or documentation. We avoid copying production data when synthetic or redacted data is sufficient and avoid exposing personal or regulated data in logs and diagnostics.
Subprocessors and client instructions
Infrastructure, payment, monitoring, backup, communications, or support providers may process the minimum data needed to deliver the contracted service. The client agreement and documented client instructions control the service scope, data roles, authorized subprocessors, retention, export, return, deletion, incident notice, and any industry-specific requirements.
Disclosure requests and incidents
We evaluate legal demands and disclose only what we reasonably believe is required. If we discover a security incident involving client data, we investigate, contain, preserve appropriate evidence, and notify the affected client as required by contract and applicable law. Public statements do not identify a client without authorization unless law requires it.
End of service
At the end of a service, we return, transfer, delete, or retain client information according to the agreement, documented instructions, backup lifecycle, security needs, disputes, and legal recordkeeping obligations. Technical deletion from backups follows the applicable rotation schedule.
