Privacy
Policy
How Fusiora collects, uses, stores, and protects your personal data in compliance with the GDPR.
Data Protection Contact
Mr. Samuel Alvarez
Fusiora OÜ · Company ID: 16994706 · VAT: EE102745315
Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145, Estonia
info@fusiora.comData Controller
The data controller is Fusiora OÜ, registered at Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145, Estonia. Company ID: 16994706 · VAT: EE102745315.
Data protection contact: Mr. Samuel Alvarez — info@fusiora.com.
Fusiora OÜ is not legally required to appoint a Data Protection Officer (DPO) under Art. 37 GDPR, but has designated a single point of contact for all matters concerning personal data processing and the exercise of data subject rights.
Legal Bases for Processing
We process your personal data under Art. 6 GDPR, on the following legal bases depending on the purpose:
- Performance of contract (Art. 6(1)(b)) — provision of contracted services, billing, technical support, and provisioning.
- Legal obligation (Art. 6(1)(c)) — accounting, taxation, anti-money laundering (KYC), response to judicial requests.
- Legitimate interest (Art. 6(1)(f)) — network security, fraud prevention, anti-abuse, service improvement, direct marketing to existing customers.
- Consent (Art. 6(1)(a)) — non-essential cookies, marketing communications to prospects, public testimonials.
- Vital interest (Art. 6(1)(d)) — cooperation with authorities in exceptional situations requiring protection of life.
Legitimate interest has been assessed through a balancing test (LIA). You may request a summary by writing to info@fusiora.com.
Personal Data We Collect
We collect the following categories of data:
- Identification — first name, last name, ID document when KYC applies, date of birth.
- Contact — email address, phone, postal address.
- Billing — tax address, Tax ID/VAT, invoice history. Card data is not stored in our systems; it is tokenised by a PCI-DSS payment provider.
- Technical — IP address, browser type and version, operating system, device identifiers, approximate geolocation by IP.
- Service usage — access logs, server logs, consumption metrics, support tickets.
- Account — credentials (hashed), preferences, language, 2FA key.
- Cookies and similar technologies — session identifiers, consent records, analytics.
- Communications — content of tickets, emails and chat with support.
We do not process special categories of data (Art. 9 GDPR: health, racial origin, sexual orientation, biometric data, etc.). If inadvertently submitted in tickets, it will be deleted without processing.
Purposes of Processing
Data is processed exclusively for:
- Provision and management of contracted services (hosting, domains, VPS, support).
- Billing, collection, bad-debt management and tax compliance.
- Identity verification (KYC) and anti-fraud / anti-money laundering compliance.
- Infrastructure security, abuse detection and attack mitigation.
- Customer care, query response and incident resolution.
- Service communications (technical notices, maintenance, renewals).
- Direct marketing to existing customers regarding similar services, with a permanent right to object.
- Aggregated analytics and continuous service improvement.
- Compliance with legal obligations and response to competent authorities.
Consent and Withdrawal
A. Where processing is based on consent, it is collected freely, specifically, informed and unambiguously, through an affirmative action (unchecked checkbox, click on cookie banner, etc.).
B. You may withdraw consent at any time by writing to info@fusiora.com or from your client panel. Withdrawal does not affect the lawfulness of prior processing.
C. Withdrawal of consent may prevent the provision of features that rely exclusively on that legal basis.
Data Retention
We retain data only for as long as necessary for the purposes described:
- Active account data — for the entire duration of the service.
- Account data after termination — up to 180 days to allow reactivation, then anonymised or deleted.
- Billing data — 7 years under Estonian tax law and EU directives.
- KYC and AML data — 5 years after the end of the relationship, under Directive (EU) 2015/849.
- Access logs and security logs — up to 12 months on the basis of legitimate interest in security.
- Support tickets — 3 years after closure for historical record and service quality.
- Cookies — as stated in the cookie policy (max. 13 months).
- Data following serious incident or fraud — up to an additional 365 days for investigation and legal disclosure.
Once the retention periods have elapsed, data is irreversibly deleted or anonymised, including rotating backups.
Your Rights under the GDPR
You have the following rights, exercisable free of charge by writing to info@fusiora.com:
- Access (Art. 15) — obtain confirmation and a copy of the data we process about you.
- Rectification (Art. 16) — correct inaccurate or incomplete data.
- Erasure / right to be forgotten (Art. 17) — delete your data when no longer necessary or when you withdraw consent.
- Restriction of processing (Art. 18) — restrict the use of your data in certain cases.
- Portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format, or request direct transmission to another controller.
- Objection (Art. 21) — object to processing based on legitimate interest or to direct marketing at any time.
- Not to be subject to automated decisions (Art. 22) — including profiling with significant legal effects.
- Withdrawal of consent (Art. 7(3)) — without retroactive effect on prior processing.
- Complaint to supervisory authority (Art. 77) — Andmekaitse Inspektsioon (AKI) in Estonia, or your national authority.
We will respond within a maximum period of 1 month from receipt (extendable to 2 months for complex requests, with prior notice). We may require reasonable identity verification.
International Transfers
Some processors are located outside the European Economic Area (EEA), mainly in the United States and the United Kingdom. For these transfers we apply one or more of the safeguards provided in Chapter V of the GDPR:
- Adequacy decision (Art. 45) — United Kingdom; United States only with regard to companies certified under the EU-US Data Privacy Framework (DPF).
- Standard Contractual Clauses (Art. 46(2)(c)) — SCCs approved by the European Commission (Decision 2021/914) for transfers not covered by adequacy.
- Supplementary measures — encryption in transit and at rest, access controls, transfer impact assessments (TIAs).
You may request a copy of the applicable SCCs or information on the location of each processor by writing to info@fusiora.com.
Processors and Sub-processors
We share data with the following processors, all bound by a data processing agreement under Art. 28 GDPR:
- WHMCS Ltd (United Kingdom) — billing and CRM management. Basis: UK adequacy decision.
- Cloudflare Inc. (USA) — CDN, WAF, DDoS mitigation. Basis: SCCs + DPF.
- Bunny.net (BunnyWay d.o.o.) (Slovenia) — CDN and static content delivery. Basis: EEA.
- Crisp IM SAS (France) — live support chat. Basis: EEA.
- Trustpilot A/S (Denmark) — review collection. Basis: EEA + consent.
- Stripe Payments Europe Ltd (Ireland) — card payment processing. Basis: EEA.
- Datacenter providers (EU) — physical server hosting in Germany, France, the Netherlands and Estonia.
- Sentry (Functional Software Inc.) (USA) — error tracking. Basis: SCCs + DPF.
- FraudRecord — industry fraud prevention. Basis: legitimate interest + SCCs.
An up-to-date list is available on request. Processors may not use your data for any other purpose or engage sub-processors without prior written authorisation.
Security Measures
We implement appropriate technical and organisational measures in accordance with Art. 32 GDPR:
- TLS 1.3 encryption in transit for all web and API communications.
- Encryption at rest (AES-256) for backups and sensitive data.
- Bcrypt/argon2 hashing for passwords; rotating session tokens.
- Role-based access control (RBAC) with least-privilege principle.
- Mandatory two-factor authentication (2FA) for staff with data access.
- Network segmentation, perimeter firewalls and WAF.
- Access logging and monitoring; anomaly detection.
- Encrypted backups regularly tested.
- Annual penetration tests and security audits.
- Regular data protection training for all staff.
- Documented incident response and breach notification procedure.
Cookies and Similar Technologies
We use strictly necessary cookies for the site's functioning (session, authentication, language preference, load balancing) which do not require consent under Art. 5(3) of the ePrivacy Directive.
Non-essential analytics and preference cookies are activated only after your explicit consent via the cookie banner, where you can accept, reject or configure by category.
You may withdraw or modify your consent at any time via the "Cookie Preferences" link in the footer.
See the Cookie Policy for full details on each cookie, purpose, duration and provider.
Automated Decisions and Profiling
We use limited automated systems for:
- Fraud detection — analysis of order patterns, IP, payment method and device fingerprint to prevent fraud. It may result in manual review or order rejection.
- KYC scoring — automated risk assessment for anti-money laundering compliance.
- Anti-spam and anti-abuse filtering — in email and network services.
You have the right (Art. 22) not to be subject to decisions based solely on automated processing with significant legal effects. In such cases, you may request human intervention, express your point of view and contest the decision by writing to info@fusiora.com.
Direct Marketing
We may send you commercial communications about services similar to those you have contracted, based on legitimate interest (soft opt-in) under Art. 13(2) of the ePrivacy Directive.
For communications to prospects or about unrelated products, we will request prior explicit consent.
You may object to direct marketing at any time, free of charge and without justification, via the "Unsubscribe" link included in every email, from your client panel or by writing to info@fusiora.com. The objection will take effect without delay.
Children's Privacy
Our services are not directed at children under the age of 16 (13 years in Estonia, pursuant to Art. 8 GDPR and § 8 of the Estonian Personal Data Protection Act).
We do not knowingly collect data from minors without the verifiable consent of a parent or legal guardian. If we detect that we have processed a minor's data without such consent, we will delete the information without delay.
If you are a parent or guardian and believe that a minor in your care has provided personal data, contact info@fusiora.com for immediate removal.
Personal Data Breach
In the event of a security breach affecting personal data:
- Notification to the supervisory authority (AKI Estonia) within a maximum of 72 hours of detection, under Art. 33 GDPR.
- Notification without undue delay to affected data subjects where there is a high risk to their rights and freedoms, under Art. 34 GDPR.
- Communication of the scope, nature, categories affected, measures taken and recommendations.
- Immediate containment, forensic investigation and reinforcement of measures to prevent recurrence.
We keep an internal register of all breaches, under Art. 33(5) GDPR.
Sources of the Data
Most data is obtained directly from you. Occasionally we receive data from third parties:
- Payment providers (Stripe, PayPal, etc.) — payment confirmation and anti-fraud signals.
- Domain registrars — when you transfer a domain to Fusiora.
- FraudRecord and industry anti-fraud networks — risk signals.
- KYC verification agencies — identity validation.
- Public sources (commercial registers, sanctions lists) — AML compliance.
Disclosure to Authorities and Third Parties
A. We may disclose data to law enforcement or competent authorities only upon a valid legal request (court order, tax requisition, etc.), following the principles of necessity, proportionality and minimisation. Requests: info@fusiora.com.
B. Authorised internal staff may access data for operational, support or compliance purposes under strict confidentiality and RBAC controls.
C. In the event of a merger, acquisition or sale of assets, data may be transferred to the successor, subject to prior notification and the same safeguards.
D. We do not sell personal data to third parties under any circumstances.
Links to Third-Party Services
Our services may contain links to third-party sites. Fusiora is not responsible for their data practices. Review their privacy policies independently before providing them with information.
Complaints and Appeals
If you consider that a request has been denied or mishandled, you may appeal internally within 28 calendar days of the response, by writing to info@fusiora.com.
Regardless of the internal appeal, you retain the right to lodge a complaint with the competent supervisory authority:
Andmekaitse Inspektsioon (AKI) — Tatari 39, 10134 Tallinn, Estonia · aki.ee · info@aki.ee.
You may also refer the matter to the supervisory authority of your country of residence if you reside in another EEA Member State.
Changes to This Policy
We may update this policy to reflect legal, technical or operational changes. The current version is always published on this page with the date of last review.
In case of material changes affecting your rights or the processing, we will notify you at least 30 days in advance by email or prominent notice in the client panel.
Version history available on request at info@fusiora.com.
Reviewed and approved on April 22, 2026 by Mr. Samuel Alvarez.
v2.0