← Legal
Privacy & Data Protection
Version 2026-08-27-v2 · effective 29 Aug 2026
# FUSE Privacy & Data Protection
This Privacy & Data Protection document describes how **IT Project Pros, Inc., doing business as FUSEONai** ("FUSEONai," "we," "us," or "our") handles personal information in connection with the FUSE software-as-a-service platform ("FUSE" or the "Service"). It also contains customer data-processing terms, security/data-handling terms, and how to obtain the FUSE subprocessor schedule.
This document is intentionally combined so customers do not have to navigate separate privacy, data-processing, security, and subprocessor documents.
## Part A - Privacy Notice
### 1. Scope
This Privacy Notice applies to personal information that FUSEONai collects or processes in connection with:
- FUSE account creation and administration;
- use of the FUSE application;
- customer onboarding;
- support and service communications;
- subscription administration;
- security and audit activity; and
- FUSE-related websites or forms that link to this notice.
When FUSEONai processes personal data solely on behalf of a business customer, the customer generally determines the purposes and means of that processing and Part B also applies.
### 2. Information We Collect
Depending on how a person interacts with FUSE, we may collect the following categories.
#### A. Account and Profile Information
- name;
- business email address;
- organization;
- job title or business role;
- organization membership;
- user role and permissions;
- account identifiers; and
- authentication-related identifiers supplied by the authentication service.
#### B. Customer-Provided Information
FUSE may process personal information contained within Customer Data, including documents, comments, evidence, workflow assignments, approvals, assessments, uploaded files, or other records that a customer chooses to enter into the Service.
FUSEONai does not require customers to submit unnecessary personal information and customers should avoid submitting Restricted Data unless expressly authorized.
#### C. Application, Device, and Security Information
We may collect:
- sign-in and authentication events;
- date and time of access;
- application activity;
- audit events;
- system and security logs;
- browser or device information;
- IP address when reasonably necessary for security, fraud prevention, audit, or legal-record purposes;
- feature usage; and
- error or performance information.
#### D. Communications and Support
We may collect information contained in support tickets, service requests, emails, meeting records, and other communications with FUSEONai.
#### E. Subscription and Administrative Information
We may collect organization contacts, subscription plan, entitlement information, Order Form references, legal-acceptance records, billing contacts, and payment-status information.
If payments are later processed through a payment provider, FUSEONai should not store full payment-card credentials unless expressly designed and authorized to do so.
### 3. Sources of Personal Information
We may obtain personal information:
- directly from the individual;
- from the individual's employer or organization;
- from an organization administrator;
- from an identity or authentication service;
- from Customer-Directed Third-Party Services at Customer's direction;
- automatically through use of the Service; and
- from service providers that support FUSE operations.
### 4. How We Use Personal Information
FUSEONai may use personal information to:
- create and administer accounts;
- authenticate users;
- provide and operate FUSE;
- apply permissions and tenant isolation;
- provide customer support;
- maintain audit and approval history;
- secure accounts and investigate suspicious activity;
- troubleshoot and maintain the Service;
- communicate operational or contractual information;
- administer subscriptions and entitlements;
- satisfy legal, contractual, and compliance obligations;
- respond to valid legal process;
- protect FUSEONai, customers, users, and third parties; and
- improve Service reliability, usability, security, and capacity.
Where required by law, FUSEONai will rely on an appropriate legal basis for processing.
### 5. How We Disclose Personal Information
We may disclose personal information to:
#### A. Customer Organization
A user's organization administrators and other authorized personnel may have access to information associated with the user's work in FUSE, including assignments, comments, approvals, activity, and audit history.
#### B. FUSE Subprocessors
FUSEONai may disclose information to service providers acting on FUSEONai's behalf to provide functions such as hosting, data storage, authentication, communications, security, monitoring, support, and related operations.
FUSEONai provides the current FUSE Subprocessor Schedule to Customer on request. Part D explains how to obtain it.
#### C. Customer-Directed Third-Party Services
When Customer enables an integration, FUSE may transmit information to the third-party service as directed by Customer. Those services are controlled by their own agreements and privacy practices and are not FUSE Subprocessors solely because they interoperate with FUSE.
#### D. Legal and Safety Disclosures
We may disclose information when reasonably necessary to comply with law, valid legal process, or binding governmental requests; to protect rights or safety; to investigate fraud, abuse, or security incidents; or to establish, exercise, or defend legal claims.
#### E. Corporate Transactions
Information may be transferred as part of a merger, acquisition, financing, reorganization, bankruptcy, or sale of relevant business assets, subject to applicable law and appropriate confidentiality protections.
### 6. Sale and Advertising Sharing
FUSE is a B2B governance platform. FUSEONai does not sell Customer Data.
FUSEONai does not intend to sell personal information for monetary consideration or share personal information for cross-context behavioral advertising. If those practices change, FUSEONai will update this notice and provide any legally required choices before the new practice begins.
### 7. Data Retention
FUSEONai retains personal information only for as long as reasonably necessary for the purpose for which it was collected, the customer relationship, security and audit needs, contractual obligations, dispute resolution, and applicable legal requirements.
FUSEONai's operational retention schedule is:
| Category | Retention Rule |
|---|---|
| User account/profile data | Active account plus five years |
| Legal acceptance and contract audit records | Five years after the subscription ends or terminates |
| Application/security logs | Five years |
| Support records | Five years |
| Customer Data | Subscription Term plus contractual export/deletion period |
| Backups | Normal backup-rotation period, subject to legal holds |
| Website/form analytics data, if any | Not applicable — FUSEONai operates no website or product analytics |
FUSEONai will not publish a retention period that the production system cannot actually satisfy.
### 8. Privacy Rights
Depending on applicable law and the person's location, a person may have rights to request:
- access to personal information;
- correction of inaccurate information;
- deletion;
- a portable copy;
- information about categories of information collected and disclosed;
- restriction or objection to certain processing; or
- an appeal where a state privacy law provides one.
Where FUSEONai processes information on behalf of a business customer, FUSEONai may direct the request to the applicable customer or assist the customer in responding.
FUSEONai will not discriminate against an individual for exercising a legally protected privacy right.
Requests may be submitted to:
**Privacy Contact:** tech@fuseonai.com
**Mail:** 680 W. Nye Lane, Ste 101, Carson City, NV 89703
FUSEONai may take reasonable steps to verify a request.
### 9. Notice at Collection
Where applicable law requires a notice at or before collection of personal information, FUSEONai will provide a concise notice or conspicuous link to this Privacy & Data Protection document at the relevant collection point.
The software implementation should present the notice or link on account/authentication screens and other FUSE-controlled forms that collect personal information.
The notice should identify the categories collected, the purposes, retention information, and a link to this document, as required by applicable law.
### 10. Cookies and Similar Technologies
FUSE may use strictly necessary technologies required for authentication, security, session management, and application operation.
If FUSEONai later uses nonessential analytics, advertising, or similar technologies, FUSEONai will update this notice and implement consent or opt-out mechanisms where required.
### 11. Security
FUSEONai uses reasonable administrative, technical, and organizational safeguards designed to protect personal information. Security controls may include authentication, authorization, tenant isolation, encryption, audit logging, backup/recovery measures, monitoring, and controlled production access.
No system can guarantee absolute security.
### 12. Children
FUSE is a business service and is not directed to children. FUSEONai does not knowingly provide FUSE accounts for personal use by children under 18.
### 13. International Data
If personal data is transferred across national borders, FUSEONai will use a lawful transfer mechanism where required.
FUSEONai offers the Service to customers in the United States only, and personal data is processed in the United States. FUSEONai does not rely on standard contractual clauses or another cross-border transfer mechanism at initial release. If the Service is offered outside the United States, this notice will be updated before that offering begins.
### 14. Changes to This Notice
FUSEONai may update this document. The current version and effective date will remain available in FUSE. Material changes will be communicated as required by applicable law or contract.
### 15. Privacy Contact
**IT Project Pros, Inc. d/b/a FUSEONai**
680 W. Nye Lane, Ste 101
Carson City, NV 89703
Email: tech@fuseonai.com
---
# Part B - Customer Data Processing Terms
## 16. Applicability and Roles
16.1 This Part B applies when FUSEONai processes personal data on Customer's behalf in providing the Service.
16.2 Where applicable privacy law uses the terms controller/business and processor/service provider/contractor, Customer generally acts as the controller/business for Customer Data and FUSEONai acts as the processor/service provider for processing performed on Customer's documented instructions.
16.3 FUSEONai may act independently as a controller/business for limited information it processes for its own legitimate business purposes, such as account administration, security, contract records, fraud prevention, and legal compliance, as permitted by law.
## 17. Customer Instructions
17.1 Customer instructs FUSEONai to process Customer Data as necessary to provide, maintain, secure, support, and administer FUSE; to perform Customer's configured workflows and integrations; and as otherwise documented in the parties' agreement.
17.2 Customer is responsible for ensuring its instructions comply with applicable law and that it has provided required notices and obtained required rights or permissions.
17.3 If FUSEONai reasonably believes an instruction violates applicable data-protection law, FUSEONai may notify Customer and suspend the affected processing while the parties address the issue, where legally permitted.
## 18. Processing Details
**Subject Matter:** Provision of the FUSE SaaS platform and related support.
**Duration:** Subscription Term plus the applicable post-termination retention/deletion period.
**Nature and Purpose:** Hosting, organizing, securing, transmitting, analyzing, displaying, supporting, and otherwise processing Customer Data as required to provide FUSE and customer-directed functionality.
**Categories of Data Subjects:** Customer employees, contractors, representatives, users, business contacts, and other individuals whose personal data Customer chooses to include in Customer Data.
**Categories of Personal Data:** Business contact information, account identifiers, roles, workflow activity, comments, approvals, audit history, and personal information that Customer elects to include in Customer Data.
**Restricted Data:** Not authorized unless expressly agreed in writing.
## 19. Confidentiality
FUSEONai will ensure that personnel authorized to process Customer personal data are subject to appropriate confidentiality obligations.
## 20. Security Measures
FUSEONai will maintain reasonable security measures appropriate to the nature and risk of the processing, including controls described in Part C and the actual production security architecture.
FUSEONai will not describe a security control as implemented until that control is actually operating in production.
## 21. Subprocessors
21.1 Customer generally authorizes FUSEONai to use the FUSE Subprocessors set out in the current FUSE Subprocessor Schedule, which FUSEONai provides on request under Part D.
21.2 FUSEONai will require a FUSE Subprocessor to protect personal data in a manner consistent with FUSEONai's applicable contractual and legal obligations.
21.3 FUSEONai remains responsible for the performance of its FUSE Subprocessors to the extent required by applicable law and the parties' agreement.
21.4 FUSEONai will give Customer at least 30 days' notice in the Service before a material new FUSE Subprocessor begins processing personal data. Customer may object in writing during that period, stating the grounds; the parties will discuss the objection in good faith, and if it cannot be resolved Customer may terminate the affected subscription without penalty for the remainder of its term.
## 22. Customer-Directed Third-Party Services
22.1 Customer-Directed Third-Party Services are selected and authorized by Customer.
22.2 FUSEONai may transmit Customer Data to a Customer-Directed Third-Party Service only as directed or configured by Customer or its authorized administrators.
22.3 Customer is responsible for determining the third party's suitability, legal terms, security, privacy practices, and permitted data use.
22.4 A Customer-Directed Third-Party Service does not become a FUSE Subprocessor solely because FUSE connects to it.
## 23. Data Subject Requests
Where required by applicable law and taking into account the nature of processing, FUSEONai will provide reasonable assistance to Customer in responding to a legally valid request concerning personal data processed on Customer's behalf.
If FUSEONai receives a request that primarily concerns Customer Data, FUSEONai may direct the requester to Customer unless law requires FUSEONai to respond directly.
## 24. Security Incidents
24.1 FUSEONai will maintain procedures to investigate and respond to confirmed unauthorized access to or acquisition, disclosure, alteration, or destruction of Customer Data under FUSEONai's control that constitutes a reportable security incident under applicable law or contract.
24.2 FUSEONai will notify Customer without undue delay after confirming an incident requiring notice and will provide reasonably available information necessary for Customer to understand the nature and scope.
24.3 The standard agreement does not state an outer notification period beyond Section 24.2. A specific period may be agreed in an Order Form or a negotiated data-protection addendum.
24.4 Notice of an incident is not an admission of fault or liability.
## 25. Assistance and Compliance Information
Upon reasonable request and subject to confidentiality and security restrictions, FUSEONai will provide information reasonably necessary for Customer to evaluate FUSEONai's compliance with these data-processing terms.
Any enhanced audit right, penetration-test report, certification package, or on-site review requested by an enterprise customer should be addressed through the applicable Order Form or security addendum and may be subject to reasonable limitations and fees.
## 26. Return and Deletion
Upon termination or expiration, FUSEONai will provide the data-export opportunity and deletion process described in the FUSE SaaS Agreement and applicable Order Form.
FUSEONai may retain information required for legal, security, audit, fraud-prevention, or dispute purposes and may retain backup copies until they age out under normal backup rotation, subject to confidentiality obligations.
## 27. International Transfers
Where legally required, the parties will implement an appropriate data-transfer mechanism.
At initial release the Service is offered in the United States only and personal data is processed in the United States, so no cross-border transfer mechanism applies. A mechanism will be stated here before the Service is offered in another market.
---
# Part C - Security and Data Handling
## 28. Security Principles
FUSEONai's security program for FUSE should be designed around:
- organization-level tenant isolation;
- least-privilege access;
- role-based authorization;
- authenticated user access;
- separation of development and production;
- controlled production access;
- encryption in transit;
- encryption at rest where supported by the approved production services;
- audit logging for sensitive and legally significant events;
- secure software-development practices;
- backup and recovery;
- vulnerability and dependency management;
- incident response; and
- periodic review of access and controls.
## 29. Tenant Isolation
FUSE is a multi-tenant service. Customer Data must be logically isolated so an Authorized User from one customer organization cannot access another customer's data unless a separately authorized support or cross-organization access mechanism exists and is expressly controlled, logged, and permitted.
Cross-tenant isolation failures are treated as release-blocking security defects.
## 30. Identity and Access
FUSE should:
- authenticate users before access to protected application resources;
- determine authorization within FUSE rather than relying solely on the external identity provider;
- enforce organization context and role permissions on protected requests;
- support prompt removal or disabling of user access; and
- maintain appropriate audit evidence for administrator and support access.
## 31. Encryption
FUSEONai will use industry-standard encrypted transport for production network communications containing Customer Data.
Data-at-rest protections will reflect the capabilities and configuration of the approved production hosting, database, file-storage, and backup services.
## 32. Audit Logging
FUSE should maintain audit records for security-sensitive and governance-significant events, including:
- user authentication events where appropriate;
- legal acceptance;
- role/permission changes;
- customer-administrator actions;
- approvals and decision gates where required by product design;
- platform support access;
- sensitive configuration changes; and
- security events.
Audit records must be protected against ordinary-user modification.
## 33. Production and Development Separation
Production Customer Data must not be copied into development or test environments except under a specifically approved, controlled, and legally appropriate process.
Development and production credentials, databases, and environments should be separated.
## 34. Backups and Recovery
FUSEONai will maintain backup and recovery measures appropriate to the production architecture.
Published recovery commitments must match tested capabilities.
## 35. Security Review and Incident Response
FUSEONai will maintain procedures for:
- vulnerability handling;
- security-event investigation;
- containment;
- remediation;
- customer notification when required;
- evidence preservation; and
- post-incident review.
## 36. Customer Security Responsibilities
Customer is responsible for:
- selecting appropriate users and roles;
- protecting user endpoints and credentials;
- maintaining secure Customer-Directed Third-Party Services;
- promptly disabling departed or unauthorized users;
- configuring integrations and access appropriately; and
- notifying FUSEONai of suspected account compromise.
---
# Part D - FUSE Subprocessor Schedule
## 37. FUSE Subprocessors
FUSEONai maintains a current FUSE Subprocessor Schedule identifying each subprocessor that
processes personal data on FUSEONai's behalf, its function, the categories of personal data it
processes, and the processing location.
FUSEONai will provide the current FUSE Subprocessor Schedule to Customer on request. Requests
should be sent to tech@fuseonai.com with the subject line "Subprocessor Schedule."
The schedule is provided on request rather than published because the subprocessors and processing
locations applicable to a Customer depend on the deployment model. Where an Order Form or a
negotiated amendment provides for a different deployment model or processing location, that Order
Form or amendment controls for that Customer, and the subprocessors and locations applicable to that
deployment will be stated in it.
FUSEONai uses no subprocessor for transactional communications: notifications are delivered in the
Service only. FUSEONai uses no analytics, telemetry, or third-party monitoring subprocessor.
## 38. Changes to Subprocessors
FUSEONai may update the schedule as production vendors change. Where required by applicable law or Customer's contract, FUSEONai will provide advance notice of a material new subprocessor and any applicable objection process.
---
# Contact
**IT Project Pros, Inc. d/b/a FUSEONai**
680 W. Nye Lane, Ste 101
Carson City, NV 89703
Privacy: tech@fuseonai.com
Legal: tech@fuseonai.com
™