Skip to content
Let's talk
Home
Privacy Policy

Privacy Policy

Last Updated: 31 August 2026

This Privacy Policy (the “Policy”) explains how LAZAREV UX LLC (the “Company”, “We”, “Us”, or “Our”) collects, uses, stores, shares, and otherwise processes Personal Data when You visit or interact with https://www.lazarev.agency (the “Website”).

This Policy is intended to provide the information required under applicable privacy laws, including Regulation (EU) 2016/679 (GDPR), the UK GDPR, and the California Online Privacy Protection Act (CalOPPA), where those laws apply to Our Processing.

Providing Personal Data through a contact, booking, recruitment, or other Website form does not mean that You “agree” to this Policy. The Policy is a notice explaining Our Processing. We process Your Data only where We have an appropriate legal basis, as described below.

Where consent is required by law, We process non-essential Analytics and Marketing technologies only after You make an affirmative choice through the consent banner. You can change or withdraw that consent at any time via the “Cookie Settings” link in the Website footer. Withdrawal does not affect the lawfulness of Processing carried out before withdrawal.

We may update this Policy from time to time. The “Last Updated” date above will be changed whenever We make a substantive update. Where a change introduces Processing that is not covered by a consent You previously gave, We will request a new consent where required by law.

Definition

The following terms have the meanings specified below for the purposes of the Policy:

“Company” - refers to LAZAREV UX LLC, (EIN: 320691894), legal address: 8 The Green, 1, Dover, DE 19901, USA, represented by Kyrylo Lazariev (hereinafter –  “We”, “Us”, or “Our”).

“Website” - means all Content and links of the page 
https://www.lazarev.agency that provides Services to Users and provides information regarding the Services (also referred to as “LAZAREV.AGENCY”).

“Service” - is a combination of the Services provided by the Company through the Website.

“User” - any individual who visits, uses, or otherwise interacts with the Website (also referred to as “You”, “Your”).

“Content” - the information, Company provides via Website, including offers. Also, the Content includes but is not limited to: whole or elements of icons, illustrations, graphics, pictures, logo, etc., which is solely owned by the Company.

“Intellectual property rights” - all rights in, to, or arising out of: (i) any work, intangible work, copyrights, copyright registrations, creations, design, illustrations, symbols, marks, pictures, icons, trademarks, logo, and/or image that is used in commercial / personal purposes; (ii) any U.S., Ukrainian or foreign patent or any software therefore and any all reissues, divisions, continuations, renewals, extensions, and continuation-in-part thereof; (iii) moral rights, rights of publicity, right of personality, privacy, and likeness, whether arising by operation of law, contract, license or otherwise, goodwill, trade secret, and other intellectual property rights as may now exist or hereafter come into existence, and all applications therefore and registrations, renewals, and extensions thereof, under the laws of any state, country or other applicable jurisdiction.

“Services” - the Company's provision of UI/UX design services, creation of design for digital products.

“Third-Party” - means a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor, and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.

“Automatically-collected information” - the information collected automatically through the Website (or Third-party services used by this Website) is referred to as “Usage Data”.

“Cookies” - small text files stored on Your browser or device. References in this Policy to Cookies also include similar storage or access technologies, such as localStorage, where relevant.

“Data Controller”, “Owner” - means LAZAREV UX LLC, which determines the purposes and means of Processing Personal Data. You can contact Us about privacy matters at [email protected].

“Data Processor” - means a natural person or legal entity that processes Personal Data on behalf of the Controller (as defined in this Privacy Policy) (referred to as the “Processor”).

“European Union”, “EU” - means the Member States of the European Union. “European Economic Area” or “EEA” means the EU Member States together with Iceland, Liechtenstein and Norway.

“Personal Data”, “Personal Information” - any information that permits the identification or identification of a natural person directly, indirectly or in connection with other information. A name, an email, a password, etc., for example (also called the “Data”).

“Processing” - any operation or sequence of operations performed on Personal Data or sets of Personal Data.

“Cross Border Data Transfer” (“CBDT”) - a transfer of Personal Data from the European Economic Area (“EEA”) or the United Kingdom to a recipient in a country outside the relevant jurisdiction, including transfers to Controllers or Processors.

“IP address” - the unique network address of a node in an IP-based computer network.

About Lazarev.agency

LAZAREV.AGENCY is a product design agency. We are a global design team that creates designs for digital products such as SaaS platforms and management systems.

LAZAREV.AGENCY builds engaging User experience for early-stage startups by connecting the dots between User’s needs and the client’s business model. We are focused on business solutions, driving sales and increasing value with outstanding websites, interfaces and apps. We combine human empathy and intelligent data to provide the highest level of satisfaction for Our customers and their users.

Allow Us to assist You. Let's do it amazing!

User’s rights

Depending on the law that applies to Your Personal Data, You may have the rights described below. These rights are subject to the conditions and exceptions provided by applicable law.

Where GDPR or UK GDPR applies, You may have the right to:

  • Access Your Personal Data and obtain information about how We process it;
  • Correct inaccurate or incomplete Personal Data;
  • Request deletion of Your Personal Data where the legal conditions for erasure are met;
  • Request restriction of Processing in the circumstances provided by law;
  • Receive Personal Data You provided to Us in a structured, commonly used and machine-readable format, and request portability where applicable;
  • Object to Processing based on Our legitimate interests, including direct marketing where applicable;
  • Withdraw consent at any time where Processing is based on consent, and lodge a complaint with the competent supervisory authority. Users in the United Kingdom may complain to the Information Commissioner’s Office (ICO). To exercise Your privacy rights, contact Us at [email protected]. We will respond without undue delay and, where GDPR or UK GDPR applies, generally within one month, subject to any extension permitted by law.
  • Right to object. Where We rely on legitimate interests, You have the right to object to that Processing on grounds relating to Your particular situation. You may object to Processing for direct marketing purposes at any time.

Data We collect

We collect Personal Data that You provide to Us, limited technical information generated when the Website is requested, and information processed through the analytics and marketing tools described below. The exact Data collected depends on how You interact with the Website and on Your consent choices.

01Personal data that You provide to Us

When You submit a “Let’s Talk”, “Talk to us”, “Become a client”, “Book a session”, or other contact or project form, or contact Us by email, We process the information You provide. If You apply for a role or otherwise send Us recruitment materials, We also process the information You choose to provide for that purpose.

Depending on the form or interaction, this information may include:

  • Your name;
  • Your email address or business email address;
  • Your company, job title, phone number, or other business contact details, where provided;
  • Information about Your project, inquiry, booking request, budget, or other message content;
  • Links to Your professional or social profiles, resume, portfolio, or similar materials, where You choose to provide them;
  • Any other information You voluntarily include in a form, email, or communication with Us.

Fields marked as required must be completed so that We can process the relevant request. Other information is optional unless We specifically state otherwise.

02Automatically-collected information

The Website uses a combination of first-party server-side statistics, security infrastructure, and consent-dependent Analytics or Marketing tools. Not all technical information is stored, and some information is processed only transiently to deliver or secure the Website.

Our first-party server-side statistics may record the page path, referrer (internal path or external origin only), country, coarse device class (mobile/desktop), technical traffic classification (for example human view, bot, or speculative prefetch), HTTP status, and a daily pseudonymous visitor hash.

For the first-party statistics system, raw IP address and user-agent are used transiently in memory to calculate the daily hash and are not written to Our statistics database.

The daily visitor hash is generated using a random salt that changes each UTC day. The salt is kept for no longer than 48 hours, after which identifiers for the relevant day cannot be linked across days using that salt.

Plausible Analytics receives the page URL and referrer and, in transport only, the visitor’s IP address and user-agent to calculate its own daily-rotating visitor identifier. Plausible does not store the raw IP address or user-agent.

Google Analytics 4 and Ahrefs Analytics process Website usage information only after You consent to the Analytics category through the consent banner.

For Google Analytics 4, this may include page and event information, pseudonymous identifiers, and Analytics cookies after consent. Ahrefs Analytics operates without cookies but may still process technical request and usage information.

Cloudflare processes technical request information, including IP address and browser signals, for content delivery, security, traffic management, and bot protection, including Cloudflare Turnstile on contact forms.

Profound receives server-side bot and AI-crawler request metadata, including user-agent information and a truncated form of the IP address, to help Us understand automated access to the Website.

RB2B is used only after consent to the Marketing category. It is configured so that person-level and company-level identification applies to visitors located in the United States only.

Through RB2B, We may receive a visitor’s name, job title, company, business email, LinkedIn URL and location, and sometimes company website, industry, estimated employee count, and estimated revenue.

RB2B may associate Website activity and technical identifiers with information held by RB2B or its data partners in order to identify United States business visitors and provide professional or business contact information to Us.

The Website may also generate standard request metadata when it loads content or scripts from external delivery providers, including jsDelivr. Media content is served through Our own infrastructure hosted on AWS behind Cloudflare.

03Cookies

We use Cookies and similar technologies to operate and secure the Website, remember Your privacy choices, measure Website usage and, where You have provided the relevant consent, identify potential business visitors.

On Your first visit, the Website displays a consent banner that allows You to Accept All, Reject non-essential technologies, or Manage Your Preferences by category. The available categories are Necessary, Analytics and Marketing.

You can review or change Your choice at any time by using the “Cookie Settings” control available in the Website footer. Withdrawing consent does not affect the lawfulness of Processing carried out before withdrawal.

Necessary technologies

Necessary technologies are used to provide, secure and operate the Website and to remember the privacy choices You make. They are not used for advertising or behavioural profiling.

The Website currently uses:

  • la26:consent — a localStorage entry used to remember the choices You make in the consent banner. It does not itself contain Your name, email address or other directly identifying information. The choice remains stored on Your device until You change Your preferences, clear Your browser storage, or We ask You to renew Your choice, including where Our consent-based technologies or purposes materially change.
  • Cloudflare and Cloudflare Turnstile — used for Website delivery, security, traffic management and protection of contact forms against automated submissions. These services may process technical information such as IP address and browser/device signals and, depending on the security configuration, may use short-lived security cookies or tokens for the period necessary to validate a security challenge or maintain the relevant security state.

Analytics technologies

Analytics technologies help Us understand how visitors use the Website. The following Analytics services activate only after You consent to the Analytics category:

  • Google Analytics 4 (Google LLC). Google Analytics is operated through Google Tag Manager using Consent Mode v2 in Basic mode. Before Analytics consent, GA4 does not activate, Analytics events are not sent to Google Analytics, and Analytics cookies are not set.
  • Google Analytics may use the following first-party cookies:
    After Analytics consent, Google Analytics 4 may set first-party Analytics cookies, including _ga and property-specific _ga_* cookies, to distinguish visitors and maintain Analytics session state. Their default Google lifespan is up to approximately two years, subject to browser limits and Our configuration. If You withdraw Analytics consent through Cookie Settings, the Website stops Google Analytics transmission and deletes the Google Analytics cookies set by the Website.
  • Ahrefs Analytics — cookieless Website analytics that runs only after Analytics consent. It does not set Analytics cookies but may process technical request and usage information.

Our first-party server-side statistics and Plausible Analytics operate without Cookies or similar storage on Your device. They are used for aggregated Website statistics and are processed on the basis of Our legitimate interests, as further described in this Policy.

The Google Tag Manager container itself may be fetched from Google's servers before Analytics consent. This produces a standard network request containing technical connection information such as IP address and user-agent, but GA4 does not activate and Google Analytics data are not sent until Analytics consent is granted.

Marketing technologies

We currently use RB2B / Retention.com for business visitor identification. RB2B activates only after You consent to the Marketing category. The service is configured so that person-level and company-level identification is limited to visitors located in the United States.

When activated, RB2B uses first-party Cookies and similar identifiers for session continuity, visit attribution, location-based matching and visitor identity resolution. Depending on their function, these technologies last from the current session up to approximately 12 months. They do not themselves store a visitor's name, email address or telephone number.

RB2B may nevertheless associate Website activity and technical identifiers with information held by RB2B or its data partners to identify a United States business visitor and provide Us with professional or business information, such as name, job title, company, business email address, LinkedIn URL and location. We or service providers acting on Our behalf may use that information for relevant business communications, subject to applicable law.

You may opt out of RB2B / Retention.com identification through: https://app.retention.com/optout.

Managing Your choices

You do not need to accept Analytics or Marketing technologies in order to use the Website. You can:

  • accept or reject non-essential technologies when the banner is first displayed;
  • select Analytics and Marketing separately through Manage Preferences;
  • change or withdraw Your selection at any time through Cookie Settings in the Website footer;
  • delete Cookies through Your browser settings.

If We materially change the purposes for which a consent-based technology is used or add a new category of Processing that is not covered by Your previous choice, We will request consent again where required.

The Website does not currently respond to browser Do Not Track (DNT) signals as a separate Website control. You can manage Analytics and Marketing technologies at any time through Cookie Settings. When active, certain third-party Analytics or Marketing providers may receive information about Your online activity over time or across websites as described in this Policy.

Terms of data storage

We retain Personal Data only for as long as necessary for the purpose for which it was collected, subject to applicable legal, accounting, dispute-resolution, and enforcement requirements.

Current Website-related retention periods include:

First-party Website statistics: approximately 90 days. The daily random salt used for the pseudonymous visitor hash is retained for no longer than 48 hours. Plausible aggregate statistics are retained for the duration of Our Plausible subscription.

Google Analytics 4 event data: 14 months. Google _ga / _ga_* cookies: Google’s standard expiration periods (up to approximately two years) while Analytics consent remains active, but the Website deletes these cookies when Analytics consent is withdrawn.

Consent choice stored on the device: approximately 6 months, after which We may ask You to confirm Your preferences again.

Contact and project inquiries stored in Webflow and email copies in Google Workspace: for inquiries that do not result in an engagement, up to 12 months after the last substantive contact, unless a longer period is required for legal or dispute-related purposes.

Profound bot/AI-crawler logs: retained only for as long as necessary to analyse automated access to the Website and support Website security, taking into account the applicable service settings. Where such logs remain identifiable or pseudonymous, We periodically review whether continued retention is necessary.

Recruitment data: retained for the duration of the relevant recruitment process and for a limited period afterwards where reasonably necessary to manage recruitment records or legal claims. If We retain Your information for future opportunities, We will do so only where separately agreed and for the period communicated to You at that time.

How We process Your Data

01 How We process and where We store

We use selected service providers and infrastructure providers to operate the Website and process Personal Data for the purposes described in this Policy. Depending on the service, a provider may act as Our Processor or may process limited information under its own applicable privacy terms.

Webflow, Inc. (United States) - Website hosting and form submissions. Form submissions are also delivered as email notifications to [email protected] through Google Workspace.

Cloudflare, Inc. (United States / global edge network) - CDN, proxy, security, traffic management, Cloudflare Turnstile, and technical Processing supporting Our first-party statistics.

Plausible Insights OÜ (Estonia; EU-hosted servers) - server-side, privacy-preserving Website statistics. Plausible acts as a Processor under its data processing terms.

Google LLC / applicable Google entity - Google Tag Manager, Google Analytics 4 after Analytics consent, and Google Workspace for email copies of form submissions.

Ahrefs Pte. Ltd. (Singapore) - cookieless Website analytics after Analytics consent.

RB2B / Retention.com (United States) - United States-only person-level and company-level visitor identification after Marketing consent, as described above.

Profound (United States) - server-side analytics of bot and AI-crawler request logs, including truncated IP information and request metadata.

jsDelivr (multi-CDN infrastructure) - delivery of certain script libraries on case pages; the browser sends standard request information when those resources are requested.

Our media servers use AWS infrastructure behind Cloudflare. The media domain is operated as Our first-party infrastructure and is used to deliver Website assets.

02Cross Border Data Transfer

Because the Company is established in the United States and some of Our providers are located outside the EEA or the United Kingdom, Personal Data may be transferred internationally.

Where GDPR or UK GDPR applies, We use a lawful transfer mechanism as required for the relevant transfer, which may include:

  • an adequacy decision, including the EU-U.S. Data Privacy Framework or its UK Extension where the relevant recipient is validly certified and the transfer is covered;
  • the European Commission Standard Contractual Clauses (“SCCs”) for transfers from the EEA; and

the UK International Data Transfer Agreement (“IDTA”) or the UK Addendum to the SCCs, where applicable to transfers from the United Kingdom.

Plausible Analytics is provided by Plausible Insights OÜ in Estonia and, according to the information provided to Us, its relevant analytics data are hosted in the European Union.

03Disclosure of Personal Data

We do not sell Personal Data for monetary consideration. We do, however, disclose Personal Data or technical information to service providers, vendors, professional advisers, regulators, and other recipients where necessary for the purposes described in this Policy. This may include:

  • Website hosting, cloud, security, analytics, communications, content-delivery, and visitor-identification providers described above;
  • Professional advisers, including legal, accounting, and other consultants where reasonably necessary;
  • Government authorities, courts, regulators, or law-enforcement bodies where disclosure is required or permitted by law.

We may also disclose Personal Data:

  • to comply with applicable law, lawful process, or binding requests;
  • to protect Our rights, security, users, or third parties; and
  • in connection with a merger, acquisition, financing, reorganisation, sale of assets, or similar corporate transaction, subject to appropriate protections.

Changes to this Policy

We review this Policy periodically and update it when Our Processing, service providers, legal requirements, or consent model materially change. The “Last Updated” date at the top of this Policy will be changed when substantive revisions are made.

A change to this Policy does not by itself constitute consent to new Processing. If We introduce Processing that requires consent and is outside the scope of Your existing choice, We will request a new consent before carrying out that Processing where required by law.

Governing law

This Policy is intended to be interpreted in accordance with the privacy and data protection laws that apply to the relevant Processing. Nothing in this Policy limits any rights or remedies that cannot be waived under applicable law. Contractual matters relating to Your use of the Website are governed by Our Terms of Use.

Data Security

We implement reasonable and appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data. We also require appropriate privacy and security safeguards from Our service providers where required by applicable law. No method of transmission or storage can be guaranteed to be completely secure.

Continuation of Personal Data storage

We may retain Personal Data beyond the standard periods described above where this is necessary to comply with a legal obligation, respond to or defend a claim, resolve a dispute, or comply with a binding order. Consent does not by itself justify indefinite retention; if consent is withdrawn, We stop consent-based Processing unless another legal basis permits or requires continued Processing or retention.

Supplemental Notice for California Residents

CalOPPA applies to commercial websites that collect personally identifiable information from California users. This section provides additional California-facing disclosures. Based on the information currently available to Us, the Company does not meet the statutory thresholds for application of CCPA/CPRA.

CCPA/CPRA status.

Because CCPA/CPRA does not currently apply to the Company, We do not provide CCPA-specific consumer rights or a “Do Not Sell or Share My Personal Information” link solely under CCPA/CPRA. We will reassess this position if Our business or Processing reaches the applicable statutory thresholds.

Browser privacy signals. We do not currently treat Global Privacy Control (GPC) as a CCPA opt-out mechanism because CCPA/CPRA does not currently apply to the Company. Our handling of browser Do Not Track (DNT) signals and Your available Website controls are described in the Cookies section above.

Third-party collection over time. As described in this Policy, Analytics and Marketing providers may receive technical information when their services are active. Google Analytics 4 and Ahrefs Analytics activate only after Analytics consent, and RB2B activates only after Marketing consent and is configured for United States identification only.

Your controls. You can use “Cookie Settings” to manage Analytics and Marketing choices. United States visitors may also use the RB2B opt-out mechanism at https://app.retention.com/optout.

Policy updates. The effective version of this Policy is identified by the “Last Updated” date at the top. Material changes will be reflected by updating that date and, where appropriate, by providing additional notice.

California users may contact Us at [email protected] with questions about this Policy or Our privacy practices. We will respond in accordance with the law applicable to the request.

Accessibility. This Privacy Policy uses industry-standard technologies and was developed in line with the World Wide Web Consortium’s Web Content Accessibility Guidelines, version 2.1.

California Shine the Light. California “Shine the Light” law permits Users who are California residents to request and obtain from Us once a year, free of charge, a list of the Third Parties to whom We have disclosed their Personal Data (if any) for their direct marketing purposes in the prior calendar year, as well as the type of Personal Data disclosed to those parties.

Contact us

Please contact Us at [email protected] if You have questions about this Policy, wish to exercise a privacy right, object to Processing, withdraw a non-cookie consent, or make a privacy complaint.

Table of Contents