Privacy Policy
Effective date: 2026-10-01
This policy explains what personal information FUSSEC Services LLC ("we", "us") collects through fusion-ai.cloud and the Fusion AI service, why, who we share it with, and the choices you have.
1. Who we are
FUSSEC Services LLC is a limited liability company organized in New Mexico, United States, with its address at 6820 S Stemmons Fwy, Ste 115 #2008, Corinth, TX 76210, USA. For any privacy question or request, write to hello@fusion-security.com.
Fusion AI is a business service. It is not intended for consumers or for children under 16, and we do not knowingly collect their information.
2. What we collect and why
| Where | What | Why |
|---|---|---|
| Account sign-up | Name, email, organization name, password (stored only as a salted hash) | To create and secure your account and provide the service |
| Early access and newsletter forms | Email, language, page you signed up from | To tell you when early access opens and send the updates you asked for |
| Contact form | Name, email, message | To answer you. Messages are sent to our mailbox and are not stored in our database |
| Free security scan | The domain name you submit, plus public technical information about that domain (DNS records, certificates, web server headers, services reachable from the internet) | To show you the scan results. If you ask for the report by email, we also receive your email |
| Quizzes and calculators | Your answers, and your email and company name if you choose to provide them | To compute your result and send it to you |
| Microsoft 365 or Google Workspace connection (only if you connect it) | For the users of your organization: name, email address, licenses, multi-factor authentication status, and the access tokens needed to read them | To verify your security settings account by account. We process this data on behalf of your organization (see section 5) |
| Content you add to the service | Policies, evidence files and notes, compliance answers | To build and keep your compliance file |
| Technical data | IP address, browser language, pages requested | To run and secure the service (rate limiting, abuse prevention), and to show you the page for your country |
We do not sell personal information, we do not use it for advertising, and we do not use analytics or advertising trackers.
Country detection. To show you the right version of the site, we look up the country of your IP address in a geolocation database stored on our own server ("IP geolocation by DB-IP"). Your IP address is not sent to a third party for this.
AI features. Some features (policy drafting, gap analysis, the assistant chat and the audit simulator) send the text needed for the request to OpenRouter, which routes it to an AI model provider. We design these requests not to include your users' names or emails. Please do not paste personal information into the assistant chat.
3. Legal bases (EU and UK users)
Where the GDPR or UK GDPR applies, we rely on: the performance of our contract with you (account, service, scans you request); our legitimate interests in running, securing and improving the service and answering inquiries; your consent where you give it (early access list, newsletter), which you can withdraw at any time; and legal obligations where applicable.
4. Who we share it with
We use the following service providers, only for the purposes above:
| Provider | Role | Data involved |
|---|---|---|
| Contabo GmbH | Server hosting (servers located in the United Kingdom) | All data stored by the service |
| OVH | Delivery of contact-form emails | Contact-form messages |
| Discord | Internal notifications to our team that an event happened (sign-up, lead, contact request) | Organization or company name, domain scanned; no names, emails or messages |
| Stripe | Payment processing; Stripe may act as the merchant of record for purchases | Payment and billing information, handled by Stripe under its own privacy policy |
| OpenRouter and the AI model provider it routes to | AI features described above | Text of the request |
| Microsoft or Google | Only when you connect your Microsoft 365 or Google Workspace | The directory information described above |
Blog articles may embed YouTube or Vimeo videos, which are subject to those providers' policies.
We may also disclose information if required by law, to protect our rights or users, or as part of a merger or acquisition, in which case this policy will continue to apply.
5. Data we process for our customers
When your organization connects its Microsoft 365 or Google Workspace, or adds content about its staff, we process that data on its behalf and under its instructions. Your organization is responsible for having an appropriate basis to share it with us. A Data Processing Addendum is available on request at hello@fusion-security.com.
6. International transfers
We are a United States company and our servers are located in the United Kingdom. Some providers listed above are located in the United States. Where EU or UK law requires a transfer mechanism, we rely on the European Commission's Standard Contractual Clauses (and the UK addendum) or on the provider's certification under the EU-U.S. Data Privacy Framework.
7. How long we keep it
- Account data: while your account is open, and up to 12 months after it is closed, unless you ask us to delete it sooner.
- Early access and newsletter: until you ask us to remove you.
- Contact messages: up to 24 months in our mailbox.
- Emails left on quizzes, calculators and scan reports: up to 24 months.
- Scan results: up to 24 months.
- Server logs: kept for a limited period and rotated automatically.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, including deleting your account, write to hello@fusion-security.com. We answer within 30 days. If you are in the EU or UK, you can also lodge a complaint with your data protection authority.
9. Cookies and browser storage
We do not use advertising or analytics cookies. We use:
- a
marketcookie that remembers the country version you chose (one year); - your browser's local storage to keep you signed in to the application and to remember your language.
Because we do not track you across websites, we do not respond differently to "Do Not Track" signals.
10. Security
We use encrypted connections (HTTPS), store passwords only as salted hashes, restrict access to the systems that hold your data, and limit the rate of sensitive requests. No system is perfectly secure; if a breach affects your information, we will notify you as required by law.
11. Changes
We may update this policy. We will post the new version here with a new effective date and, for material changes, notify account holders by email.
12. Contact
FUSSEC Services LLC, 6820 S Stemmons Fwy, Ste 115 #2008, Corinth, TX 76210, USA. Email: hello@fusion-security.com.