Security isn't a page we wrote once and forgot about — it's how we handle client accounts, ad platform access, and visitor data every day. Here's exactly what that looks like in practice.
All traffic to and from our site and tools is served over HTTPS/TLS.
Team members only get access to the accounts and data their role actually requires.
We only use third-party tools with their own strong security and privacy practices.
A defined process for identifying, containing, and disclosing security incidents.
We're a fully remote team, which means our security model is built around protecting accounts and endpoints rather than a physical office. Our core practices include:
Our website and internal tools are served exclusively over HTTPS/TLS. Data submitted through our forms is encrypted in transit to our sub-processors.
MFA is required on accounts with access to client ad platforms, analytics, and internal systems wherever the platform supports it.
Team members are granted access only to the specific client accounts and internal systems relevant to their role, and access is revoked promptly when someone leaves a project or the company.
Team members are trained on phishing recognition, secure credential handling, and safe use of client platform access.
Team members working with client accounts use devices with disk encryption, up-to-date OS patches, and screen-lock policies enabled.
We structure how we collect, use, and store personal data to align with the principles of major privacy regulations, including the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA). See our Privacy Policy for the specifics of what we collect and your rights regarding that data.
If your organization requires a completed security questionnaire or a signed Data Processing Agreement (DPA) as part of your vendor onboarding, contact us at security@foxlabdigital.com and we'll work through it with you directly.
In the course of running our site and delivering services, we share limited data with the following categories of third-party providers. Each operates under its own security and privacy practices in addition to ours.
| Purpose | Provider(s) | Data Involved |
|---|---|---|
| Website hosting | [YOUR HOSTING PROVIDER] | Site files, server logs |
| Web analytics | Google Analytics | Usage data, approximate location, device/browser info |
| Advertising measurement | Google Ads, Meta Ads | Campaign performance data, conversion events |
| Contact form processing | Google Apps Script / Google Sheets | Name, email, company website, budget, goal — as submitted through our contact forms |
| Email delivery | [YOUR EMAIL SERVICE PROVIDER] | Email address, newsletter engagement (for opted-in subscribers) |
This list reflects the tools we actually use as of the date above. We'll update it if that changes materially.
In the event of a confirmed security incident affecting personal data or client account access, our process is to:
Immediately revoke or rotate any compromised access credentials.
Determine the scope of what data or systems were affected.
Notify affected clients and, where legally required, regulators and individuals — without undue delay.
Fix the underlying cause and document what changed to prevent recurrence.
If you've discovered a vulnerability or security concern affecting our site or tools, we want to know about it. Please report it responsibly — don't publicly disclose it before we've had a chance to address it.
Email security@foxlabdigital.comTell us about your brand and goals. We'll review it personally and send a custom strategy — no templates, no sales pitch, just a real plan.
FoxLab Digital is a fully remote team — no office overhead, no geographic limits. Browse by country to see the cities and regions we actively serve.