PRIVACY NOTICE
Your privacy, held as
privately as everything else.
Last updated 8 September 2026
This notice explains, in real detail, what information LX × AMG Luxe (“LX”, “we”, “us”) collects when you use this private platform, why we collect it, exactly how it is technically protected, how long we keep it, and the choices and rights available to you.
Who is responsible for your information
This platform is operated on behalf of LX × AMG Luxe. In keeping with the discretion we extend to every member relationship, we do not publish our operating entity’s legal name, registration number or registered address on this site. That information is verified and shared directly with members, and with any regulator or counterparty entitled to it, through your private office advisor — who remains your point of contact for any question about this notice.
What you give us
We only collect what a specific part of the platform genuinely needs to work. There is no separate marketing profile built from your visit, and nothing here is used to target you with advertising.
Sending a private request
Every request form on this platform — a residence enquiry, a service request from the private office menu, or an appointment booking with the private office — collects the same core contact details: your full name, email address and phone number, so a senior advisor can respond to you personally. Depending on the form, we also collect the specifics of what you are asking for — for example a residence name and the dates and guest count for a stay, a service type and destination, or a preferred appointment date, time and contact method — plus any free-text notes you choose to add. For an initial conversation, only your name, email and phone number are required; destination, dates, party size and notes are optional until an advisor is actually arranging something for you.
Creating and using a member account
If you register for membership, we collect your email address, a password you choose, and, optionally, your full name. We never see or store your password itself — see How we protect it below for exactly how it is handled. If you are issued a private access key as an alternative way to sign in, only a one-way cryptographic hash of that key is ever stored; the key itself exists only at the moment it is issued to you.
Signing up does not by itself make you an LX member — see our Terms and Security & Discretion pages for how membership is separately approved.
We do not ask for, through this website
Payment card numbers, bank details, passport or other government identification numbers, or travel documents. When those are genuinely needed to complete an arrangement, your advisor will collect them directly and securely, outside of this website.
Your device and visit
When you submit a request or sign in, our server sees the originating IP address the way any web server does. We do not store that address. Instead, before it ever reaches a database, it is passed through a one-way SHA-256 hash and combined with the form or endpoint you used (for example, a booking request versus a sign-in attempt). That hash cannot be reversed back into an IP address; it exists solely to power the rate-limiting described under How we protect it, and as a privacy-preserving record that a significant event occurred (such as “a request was received”) without identifying who sent it.
Standard, aggregate infrastructure logs (request timing, response codes, and similar operational data kept by our hosting provider) may exist for a short period for reliability and abuse investigation, in line with that provider’s own practices.
How we use your information
We process your information to take steps you request before, and in connection with, arranging private travel and services for you; to operate and secure member accounts; to protect this platform and its members from abuse, fraud and automated attacks; and, only where you separately and explicitly agree, to contact you about other LX offerings. Providing the service you asked for never depends on agreeing to anything beyond what is needed to respond to that request.
We do not use your information to build an advertising profile, we do not sell it, and we do not use it to train third-party advertising or data-broker systems.
How we protect it
Sign-in on this platform is handled entirely by our own systems — not by a third-party identity provider — and it is built so that the sensitive parts of your credentials are never stored in a form anyone (including our own staff) could read back.
- Passwords are never stored in plain text. Each password is hashed with PBKDF2-HMAC-SHA256 using 210,000 iterations and a unique, randomly generated salt per account, following current industry guidance for password storage. The original password is discarded the moment the hash is computed.
- Access keys are generated at random and shown to you once, at issuance. Only a SHA-256 hash of the key is ever written to our database — the key itself cannot be reconstructed from that hash.
- Sessions are represented by a random 32-byte token issued to your browser as the cookie described above. Only a hash of that token is stored on our side, sessions expire automatically after 30 days, and signing out invalidates the session on our server immediately, not just in your browser.
- Rate limiting on every request, sign-in and appointment form restricts submissions to five per hashed IP address, per form, in any ten-minute window, to slow down automated abuse. The address behind that check is hashed, never stored raw.
- A hidden field on our request forms acts as a spam trap: it is invisible to a person filling in the form normally, so a submission that fills it in is silently discarded as automated, without alerting the sender.
Access to request details and account records is limited, on our side, to private office staff who need it to respond to you, and every page that shows account or request data is built to query only the signed-in member’s own records — there is no view, anywhere on this platform, that shows one member’s information to another.
Who else sees it
Members of our private office staff who need it to respond to your request, and the infrastructure providers who host and run this platform on our behalf, under their own confidentiality and data processing obligations to us. We do not sell your personal information.
If a request moves forward into an actual arrangement — an aircraft charter, a villa booking, a protection detail and so on — we share only the details that specific third-party provider needs to deliver it (for example, your name, travel dates and relevant preferences), and only once you have confirmed you want to proceed. Those providers process what we share under their own privacy and safety obligations; see Security & Discretion for more on how those relationships are handled.
International transfers
LX serves private clients globally, and the providers who host this platform or fulfil a confirmed request may be located outside your own country. Where that is the case, we take steps consistent with applicable law — such as relying on recognised transfer mechanisms or contractual safeguards — before your information is processed there.
How long we keep it
We keep each category of information only for as long as it serves the purpose it was collected for, plus any period we are required or entitled to retain it by law:
- Request, service and appointment records are kept for the duration of the relationship they relate to, and for a limited period afterwards so a returning client does not have to repeat themselves, before being deleted or anonymised.
- Member accounts are kept while active. If an account has no activity for an extended period, we may reach out to confirm you still want it kept, or close it.
- Hashed IP records used for rate-limiting are tied to a rolling ten-minute window and are not retained beyond what that mechanism needs.
- Session tokens are deleted on sign-out and, in any event, expire automatically after 30 days.
Precise, category-by-category retention schedules are being finalised with our legal team; this notice will be updated once they are set.
Your rights
Depending on where you live, you may have the right to ask for:
- Access to the personal information we hold about you;
- Correction of information that is inaccurate or incomplete;
- Deletion of your information, subject to any legal retention obligation;
- Restriction of, or objection to, certain processing;
- Portability of information you provided to us, in a structured format; and
- Withdrawal of any consent you have previously given, at any time.
We do not sell personal information, so there is nothing to opt out of in that respect. To exercise any of these rights, contact us through your private office advisor or via Request Introduction. You also have the right to lodge a complaint with your local data protection authority.
Children’s privacy
This platform is intended for adults arranging private travel and services, and is not directed at children. We do not knowingly collect personal information from anyone under the age required by applicable law to consent to it. If you believe a minor has provided us with personal information, please contact us via Request Introduction so we can remove it.
Changes to this notice
We may update this notice as the platform, and the legal review behind it, develops. The date at the top shows when it was last revised; material changes will be reflected here before they take effect.