Privacy
Privacy notice
What we collect, why we collect it, who else sees it, and what you can ask us to do about it. Written to be read, not to be survived.
Last updated: 10 September 2026
This notice covers the FuseAIs website and our business relationships. If you are in the EEA or the UK, the EU data protection page sets out legal bases, transfers and your GDPR rights in more detail.
1. Who we are
FuseAIs provides an AI platform for private, compliant applications built on enterprise documents and data. This notice explains how we handle personal data when you use this website or deal with us commercially.
Questions go to sales@fuseanalytics.com.
2. What we collect
When you browse
Our host records standard server logs — IP address, page requested, timestamp, user agent — which is unavoidable for serving a website and is used to keep it running and secure.
We also use Google Analytics, loaded through Google Tag Manager, to understand how the site is used: which pages are visited, in what order, for how long, roughly where visitors are, and what kind of device and browser they use. To do this Google sets cookies and identifiers in your browser and receives your IP address, which we have configured Google Analytics to truncate before it is stored. We use this data only to improve the site; we do not use it for advertising and we do not combine it with anything you send us through the contact form or the demo.
You can opt out by blocking cookies for this site in your browser, by installing Google's Analytics opt-out add-on, or by browsing with JavaScript disabled. Google describes its own handling of this data at policies.google.com.
When you try the demo
The "Try it" section on our homepage sends the text you paste, or the first page of a PDF you drop, to our own API to detect and tokenize personal data and to classify the document. It is processed to show you the result and is not stored by the demo. Please use the sample or test content rather than real personal data.
When you contact us
The contact form asks for your name, email address and message, and optionally a phone number. We use these only to answer you. Your email address becomes the reply address on the message we receive, so a reply reaches you directly.
We also use your IP address briefly to rate-limit submissions and block automated abuse. It is held in memory for no more than ten minutes and is never stored in a database or included in the email we receive.
When you use the platform
Content you send to the API is processed to produce the result you asked for. Where that content contains personal data, you decide what to send and why — we act on your instructions. The platform includes PII detection, redaction and tokenization so identifiers can be removed before content reaches a model or a knowledge base. We also record usage metadata (API key, endpoint, token counts) to meter and bill the service and enforce limits.
Business contacts
If you meet us at an event or are introduced to us, we may hold your name, employer, role and business contact details to follow up. You can ask us to delete these at any time and we will.
3. What we do not do
- We do not sell personal data.
- We do not share it with advertisers or data brokers.
- We do not use your content to train models for our own benefit or anyone else's.
- We do not use analytics for advertising, and we do not track you across other websites.
- We serve our own fonts and assets. The only third-party script on the site is Google Tag Manager, described above.
4. Who else processes it
We use a small number of service providers to run the site and the platform — currently Vercel for hosting, Google for website analytics (Google Tag Manager and Google Analytics), Resend for delivering contact emails, and Amazon Web Services for platform hosting and model inference. Web fonts are served from our own origin rather than a third-party CDN. The EU data protection page lists what each one handles and where.
We will disclose personal data if the law requires it — a court order or a valid legal process. Where we are permitted to tell you first, we will.
5. How long we keep it
- Contact enquiries
- As long as needed to handle the enquiry and any follow-up, then deleted in the ordinary course.
- Rate-limiting records
- Ten minutes, in memory only.
- Server logs
- Per our host's retention period, typically a matter of days.
- Analytics data
- Held by Google Analytics for 14 months, then deleted or aggregated.
- Demo submissions
- Not stored. Processed to show you the result and discarded.
- Platform content
- Per your agreement and the retention rules you configure.
- Billing records
- As long as tax and accounting law requires.
6. Security
Traffic to this site and the API is encrypted in transit over TLS. API credentials are held server-side and never exposed to the browser. Platform access is controlled by scoped, revocable keys with per-key usage limits. Form submissions are validated and sanitised on the server before they go anywhere.
No system is perfectly secure. If you believe you have found a vulnerability, please tell us at sales@fuseanalytics.com before disclosing it publicly — see the legal information page for how we handle reports.
7. Your choices and rights
You can ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. Write to sales@fuseanalytics.com and we will respond within one month.
If you are in the EEA or the UK, the GDPR gives you further rights — restriction, portability, objection, and complaint to a supervisory authority. Those are set out on the EU data protection page.
To stop analytics, block cookies for this site or use Google's opt-out add-on, as described in section 2. Because we send no marketing email from this site, there is no list to unsubscribe from. If that changes, every message will carry a working unsubscribe link.
8. International transfers
Our providers, including Google for analytics, process data in the United States and at global edge locations. Where personal data leaves the EEA or the UK, the transfer relies on Standard Contractual Clauses, an adequacy decision, or another lawful mechanism. If you need processing pinned to a particular region, the platform supports that — tell us the constraint and we will confirm in writing.
9. Children
This is a business service. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, tell us and we will delete it.
10. Changes
When our practices change we will update this notice and revise the date at the top. If a change materially affects how we handle your data, we will tell affected customers directly rather than relying on this page alone.
Need paperwork for your compliance team?
Tell us what you need — a DPA, a security questionnaire, or a signed copy of these terms.