Privacy policy
norevixa.us
Last updated September 28, 2026
01. Date and scope
This policy took effect on September 28, 2026. It applies to norevixa.us and the public pages, inquiry form, support chat and consent controls operated by Norevixa. It explains what the site records when a person reads a page, sends an inquiry or opens a chat, and how paid advertising traffic is handled.
The catalogue is inquiry-only. No account is created, no password is collected, no payment is taken, and no card data is requested. The site does not sell a physical product or present a binding quote.
02. Who controls the data
The controller is Norevixa, trading at norevixa.us. The postal address is 97 Workshop Way, Floor 2, Austin, Texas 04073, Austin, Texas, United States. Norevixa is a small digital studio for web projects, automation and one-off consultations. This policy uses “we” for Norevixa and “you” for the person using the site.
03. Data received
The inquiry form writes your name, phone, email, address, the kind of inquiry, your message, requested specification and consent tick. When the form is rendered and sent, the site records the rendered time and sent time. The server also records the IP address, browser user-agent string and referring URL.
The support chat keeps the conversation and a token in your browser so you can return to it. The chat may receive your name, phone, email, message and consent. The consent choice is stored in the browser under site_consent_v2. Nothing else on this site persists a choice.
Technical and access data includes server and access logs. Advertising links may carry click identifiers: gclid, msclkid and fbclid. Optional storage may carry advertising or analytics information only after the required choice described below.
04. Why we use it
We use inquiry details to understand a requested web project, website repair and support task, automation request or one-off web consultation; to reply; to decide whether the work fits; and to prepare a scope discussion. We use chat details to continue the support conversation and answer the message.
We use rendered and sent times, IP address, user-agent and referring URL to protect the form from abuse, investigate delivery failures and maintain the site. We use consent records to remember whether optional storage was allowed or declined. We use advertising click identifiers to attribute a permitted advertising visit and to handle the campaign path that brought you here.
05. Legal bases
| Purpose | Legal basis |
|---|---|
| Reply to an inquiry and discuss requested work | Consent when you submit the form or chat; steps at your request before a contract. |
| Provide an agreed service if one follows | Contract or steps needed to enter a contract. |
| Security, abuse prevention and site operation | Legitimate interest in keeping a public service safe and functional. |
| Optional advertising and analytics storage | Consent. It is not required to read the site or send a basic inquiry. |
| Legal requests and records | Legal obligation where one applies. |
06. Paid traffic and click identifiers
Google Ads, Microsoft Advertising and Meta Ads send traffic here today. Google Ads can attach gclid to a click. Microsoft Advertising can attach msclkid. Meta Ads can attach fbclid where a campaign runs there. These identifiers help describe the advertising path. Their presence in a URL is not itself permission for optional storage. The names google ads and microsoft advertising refer to those same advertising services.
We do not state that any advertising platform has reviewed, approved or verified this site. The platforms named here are traffic and technology providers, not a guarantee of an outcome from an advertisement.
07. Consent Mode v2
Consent Mode v2 holds ad_storage, ad_user_data, ad_personalization and analytics_storage denied until the visitor allows storage. If the visitor declines or withdraws, the four signals are set back to denied the moment they decline or withdraw. This consent mode behaviour applies to each of those four signals.
The page remains available when optional storage is declined. The consent banner does not block reading, contacting Norevixa or changing the choice through Cookie settings. A Global Privacy Control signal is handled as an opt-out as described below.
08. Service providers
Data can be received by the following providers for the purposes above:
- Google Ireland Ltd / Google LLC for Google Ads and its consent signals.
- Microsoft Ireland Operations Ltd for Microsoft Advertising. Its own handling is covered by the Microsoft privacy statement at
privacy.microsoft.com. - Meta Platforms Ireland Ltd for Meta Ads where a campaign runs there.
- The hosting provider that serves this site and stores the inquiry database.
- The mail provider that carries an inquiry notification to the operator’s inbox.
Providers receive only what their service needs to perform the stated operation, subject to their own terms and privacy notices.
09. Transfers
Some providers may process data outside the country where it was collected, including across the United States, the European Economic Area or other locations used in their infrastructure. Where a transfer applies, it is made under the provider’s contractual safeguards, an adequacy decision where available, or another lawful transfer mechanism. The provider’s own notice explains its current locations and safeguards.
10. Retention periods
| Record | Period |
|---|---|
| Enquiries and their email copies | 24 months |
| Chat transcripts | 12 months |
| Server and access logs | 30 days |
| Record of a consent choice | 12 months |
| Data request response record | Kept only as needed to document the response and any legal duty. |
At the end of each stated period, the relevant record is deleted or securely made unavailable unless a legal obligation requires a longer period.
11. Security measures
We limit the public form to the fields needed for an initial inquiry, use HTTPS for transmission where supported by the hosting setup, restrict database and mail access to the operator’s working systems, and keep access logs for a short period. Chat tokens are held in the visitor’s browser to reconnect the conversation. We do not ask for passwords, API keys or payment details in public forms.
No internet service is risk-free. Do not send credentials or unnecessary personal records. If you believe a message exposed sensitive information, contact us promptly at [email protected].
12. GDPR rights for European visitors
For visitors who reach the site from Europe, GDPR rights include access, rectification, erasure, restriction, portability, objection, and withdrawing consent. These gdpr rights let you ask what personal data we hold, correct it, request deletion, ask us to limit processing, receive data you supplied in a usable format, object to legitimate-interest processing, or withdraw consent without changing the lawfulness of earlier processing.
These rights can have legal limits. We may need to verify the request and retain a minimal record that a request was answered.
13. United States state rights
US state privacy law applies, including California’s CCPA and CPRA and the other state laws in force for eligible residents. Depending on the state, rights may include access, correction, deletion, portability, appeal, and information about processing. California residents may ask about categories and purposes of personal information and may opt out of sale or sharing. This site does not sell personal information for money. The ccpa and CPRA terms describe the California rights relevant to an eligible request.
To exercise a right, write to [email protected]. We do not discriminate against a person for making a lawful request.
14. Global Privacy Control
Global Privacy Control, including the Sec-GPC header, is honoured as an opt-out without asking again. This global privacy control signal keeps optional advertising and analytics storage denied. You may also use the site’s Decline control or Cookie settings.
15. Children
This site is for businesses and adults arranging digital work. It is not for children, and Norevixa does not knowingly take data from children. If a parent or guardian believes a child has sent personal data, contact [email protected] and ask for its removal.
16. Complaints
You may complain to your state Attorney General. California residents may complain to the California Privacy Protection Agency in California. Visitors covered by GDPR may complain to a data protection authority in the country where they live, work or believe an infringement occurred. Contacting Norevixa first is useful but is not required where the law gives you a direct complaint route.
17. Making a data request
Send the request to [email protected] or write to Norevixa, 97 Workshop Way, Floor 2, Austin, Texas 04073, Austin, Texas, United States. State the right you want to use, the email or other details that may help us locate the record, and a safe way to answer. We answer a data request within 7 days. We may ask for enough information to verify that the request concerns you.
18. Changes to this policy
When this policy changes, we publish the new version on this page, update the effective date and describe a material change near the policy heading. A change does not remove rights that applied to processing already completed. The current version is the one available at privacy.html.
19. Human contact
A human contact for privacy questions, advertising consent concerns and data requests is [email protected]. You can also call +1 (898) 555-0558 or write to 97 Workshop Way, Floor 2, Austin, Texas 04073, United States.
Contact Norevixa about a project or read the cookie and advertising statement.