Legal

A clear processing boundary.

This overview explains how DataFuse approaches customer data. A signed DPA controls where one has been executed. Last updated August 23, 2026.

  • RolesThe customer determines which integrations and actions to run and is responsible for its instructions and lawful basis. DataFuse processes submitted data to provide the contracted service.
  • InstructionsProcessing is limited to operating, securing, supporting, and improving the service, plus documented customer instructions and applicable legal requirements.
  • SecurityDataFuse uses server-side credential resolution, scoped application permissions where providers support them, access controls, and error redaction for recognized secret patterns. Private deployments remain partly dependent on customer infrastructure.
  • Service providersInfrastructure, authentication, payment, and support providers may process data where needed to deliver the service. A current deployment-specific list is available on request.
  • AssistanceDataFuse will reasonably assist with data-subject requests, security investigations, deletion, and export to the extent applicable to the service and the signed agreement.
  • International transfersTransfer terms depend on the customer, deployment location, and providers selected. Required safeguards should be recorded in the signed DPA or order.
  • Deletion and returnCustomer data will be returned or deleted according to the product’s available controls, the agreed retention schedule, and legal recordkeeping requirements.

Request the signed DPA.

We will confirm the processing details, service providers, hosting region, and retention commitments for your deployment.

Contact legal