EU DP Compliance
EU data protection
How we handle personal data under the General Data Protection Regulation — what we collect, why, who else touches it, and what you can ask us to do about it.
Last updated: 10 September 2026
This page is a plain-language summary of our data protection position. It is not a Data Processing Agreement. If you are evaluating FuseAIs as a processor of your own customers' personal data, ask us for a DPA and we will provide one alongside our security documentation.
1. Who is responsible
FuseAIs operates this website and the FuseAIs platform. For personal data submitted through this website — the contact form in particular — FuseAIs is the controller.
For personal data contained in documents and records you send to the platform for processing, you remain the controller and FuseAIs acts as a processor, acting on your documented instructions. That relationship is governed by a Data Processing Agreement rather than by this page.
2. What we process, and why
This website
We use Google Analytics, loaded through Google Tag Manager, to measure how the site is used: pages visited, session length, approximate location, and browser and device information. Google sets cookies and identifiers in your browser for this and receives your IP address, which Google Analytics is configured to truncate before storage. We use the data to improve the site only — not for advertising, and never combined with what you send through the contact form or the homepage demo. You can prevent it by blocking cookies for this site, installing Google's Analytics opt-out add-on, or disabling JavaScript.
The homepage demo sends the text you paste, or the first page of a PDF you drop, to our own API for PII detection, tokenization and classification. It is processed to show you the result and is not stored.
The contact form
When you submit the contact form we process the name, email address, message and — if you choose to provide it — phone number that you enter. We use these solely to answer your enquiry. Your email address is set as the reply address so that our response reaches you.
We also process your IP address transiently to rate-limit submissions and prevent abuse. It is held in memory only, for no more than ten minutes, and is never written to a database or included in the email we receive.
The platform
Content you submit to the API — documents, files and records — is processed to return the result you asked for. The platform provides PII detection, redaction and tokenization endpoints so that personal data can be removed before it reaches a model or is written into a knowledge base. Where inference runs on Amazon Bedrock, it stays inside AWS under its privacy and retention terms.
3. Legal bases
- Contact form
- Legitimate interests (Art. 6(1)(f)) in responding to enquiries about our services, or steps taken at your request prior to entering a contract (Art. 6(1)(b)).
- Abuse prevention
- Legitimate interests (Art. 6(1)(f)) in keeping the service available and free of automated abuse.
- Platform processing
- Performance of our contract with you (Art. 6(1)(b)). Where the content includes personal data of your own data subjects, your instructions and your legal basis govern it.
- Website analytics
- Legitimate interests in understanding how the site is used, with the opt-outs described in section 2. If a consent requirement applies to analytics cookies in your jurisdiction, we will ask before setting them.
4. How long we keep it
Contact enquiries are retained for as long as needed to deal with the enquiry and any follow-up, and are then deleted from our mailboxes in the ordinary course. Rate-limiting records expire within ten minutes. Analytics data is held by Google Analytics for 14 months. Demo submissions are not stored. Platform data is retained according to the terms of your agreement and the retention rules you configure.
5. Who processes data with us
We use the following sub-processors. We do not sell personal data, ever.
Web fonts are served from our own origin rather than a third-party CDN, so loading this site does not disclose your IP address to a font provider.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Vercel | Website hosting and delivery | IP address, request metadata | United States / global edge |
| Google (Google Tag Manager, Google Analytics) | Website analytics | Cookie and device identifiers, pages visited, approximate location, browser and device information, truncated IP address | United States / global |
| Resend | Delivery of contact form emails | Name, email address, phone number, message | United States |
| Amazon Web Services | Platform hosting and model inference (Amazon Bedrock) | Content you submit to the platform | Region selected for your deployment |
6. International transfers
Some of the providers above, including Google, process data in the United States. Where personal data of people in the European Economic Area or the United Kingdom is transferred outside that area, the transfer relies on the European Commission's Standard Contractual Clauses, on an adequacy decision such as the EU–US Data Privacy Framework where the provider is certified, or on another lawful transfer mechanism.
If your requirement is that data does not leave a particular region, the platform supports that: inference can be pinned to a chosen AWS region, or run on models you host yourself. Tell us the constraint and we will confirm in writing whether we can meet it.
7. Your rights
If you are in the EEA or the UK, the GDPR gives you the following rights over your personal data. We will respond within one month.
- Access
- A copy of the personal data we hold about you.
- Rectification
- Correction of data that is inaccurate or incomplete.
- Erasure
- Deletion of your data, where no legal basis requires us to keep it.
- Restriction
- A pause on processing while a dispute or correction is resolved.
- Portability
- Your data in a structured, machine-readable format.
- Objection
- An objection to processing carried out on legitimate interests.
- Complaint
- A complaint to your national supervisory authority, without going through us first.
8. Security
- All traffic to this site and the API is encrypted in transit over TLS.
- Contact form submissions are validated and sanitised server-side before being sent.
- API credentials are held server-side and are never exposed to the browser.
- Platform access is controlled by scoped, revocable API keys with per-key usage limits.
- PII detection and redaction are available as explicit steps in any workflow.
9. Exercising your rights, or asking a question
Write to sales@fuseanalytics.com with "Data protection" in the subject line, or call 212.377.6018. If you are not satisfied with our response you may complain to your national supervisory authority.
10. Changes
We will update this page when our processing changes, and revise the date at the top. Where a change materially affects how we handle your data, we will tell affected customers directly rather than relying on this page alone.
Need a DPA or a security review?
Tell us what your compliance team needs and we will send the paperwork.