Privacy Policy
Fusewise AG (“Fusewise”, “we”, “us” or “our”) is committed to protecting the privacy and security of the personal data provided to us or collected by us through our website and in the course of our business activities. We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR). As Fusewise is established in Switzerland, the FADP is our primary data-protection regime; references to GDPR provisions (such as legal bases under Article 6 GDPR) are included for transparency and apply where the GDPR is applicable to the relevant processing.
This Privacy Policy explains how we collect and use personal data about you and the rights you have in relation to that data. Where we request data from you, we indicate whether providing it is mandatory or voluntary. We may provide further privacy notices where appropriate; any such notice supplements this Privacy Policy and should be read together with it.
Scope. This Privacy Policy applies to personal data for which Fusewise is the controller. For example, data about visitors to our website, prospective and actual customer contacts, business contacts and suppliers, and job applicants. It does not govern the personal data contained in the documents and data that our customers (law firms and similar organisations) upload to and process through the Fusewise platform. For that content, Fusewise acts as a processor on the customer’s documented instructions, and the processing is governed by the customer agreement and the associated Master Service Agreement (MSA) and the Data Processing Agreement (DPA), not by this Privacy Policy.
1. Who is responsible for your personal data
The controller responsible for the processing of your personal data is: Fusewise AG, Kurhausstrasse 8, 8703 Erlenbach, Switzerland; email dataprotection@fusewise.com.
We have not appointed a statutory data protection officer (DPO); our internal data-protection contact can be reached at dataprotection@fusewise.com. You can raise any data-protection matter with us using the contact details in Section 7.
Representative in the EU. For the purposes of Article 27 GDPR, our representative in the European Union is Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria. Data subjects in the EU may contact our EU representative on any data-protection matter via Prighter’s online portal at https://app.prighter.com/portal/18891604654.
2. How and which personal data we collect
We collect and process personal data as described below. The categories of data and the purposes depend on how you interact with us.
2.1 Business development and marketing
We collect personal data about prospective customers, their representatives, and other business contacts in the course of our business-development activities. The data typically include your name, contact details (address, email address and telephone numbers), employer and role, business interests, and the communications you have with us. We obtain these data directly from you, from other business contacts, or from publicly available sources (such as professional networks and company websites).
We use these data to establish and develop our business relationship with you, to identify products or services that may be of interest, to send you publications and marketing communications, and to invite you to events, in each case to the extent permitted by law. The legal basis is our legitimate interest in conducting and developing our business (Art. 6(1)(f) GDPR; the corresponding provisions of the FADP) or steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR).
We send marketing emails only where we have a business relationship with you or where you have consented (Art. 6(1)(a) GDPR). You can unsubscribe at any time using the link at the end of our emails or by contacting us (see Section 7).
2.2 Customers and the provision of our Services
Where you are, or work for, a customer, we process personal data to set up and administer your account, to provide and support the Services, to manage billing, and to communicate with you. These data typically include your name, business contact details, role, account and login data, usage and support data, and billing information. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR), our legitimate interest in operating, securing and improving the Services (Art. 6(1)(f) GDPR), and compliance with legal obligations (Art. 6(1)(c) GDPR).
Customer content is processed as a processor. Personal data contained in the documents and data that a customer uploads to or processes through the Fusewise platform is processed by Fusewise only as a processor, on the customer’s documented instructions, under the customer agreement and the DPA. This Privacy Policy does not apply to that content; if you are an individual whose data appears in such content, please contact the relevant customer (the controller).
2.3 Use of our website
When you visit our website, we collect usage data such as your domain name, browser type, session identifier, IP address, the pages you visit, the date and time of your visit, and related metadata. We use these data to provide and secure the website, to make its content and functions available, and to analyse how the website is used. The legal basis is our legitimate interest in operating and securing our website (Art. 6(1)(f) GDPR) and, where applicable, the performance of a contract (Art. 6(1)(b) GDPR).
To achieve these purposes we use cookies and similar technologies in the following categories: strictly necessary, preference, statistics/analytics and marketing. Our baseline analytics is privacy-friendly and cookieless and self-hosted on our own infrastructure; cookie-based statistics (such as heatmaps and session recordings via Microsoft Clarity) and marketing (such as the LinkedIn Insight Tag) are used only with your consent. Where the law requires consent, we obtain it through our cookie-consent banner, and you can withdraw or change your choices at any time. Further information is set out in our Cookie Policy, available at www.fusewise.com/cookie-policy.
Social media plugins. Our website includes a LinkedIn social plugin (and our LinkedIn company page), which you can recognise by the LinkedIn icon. The plugin is not activated automatically; if you interact with it, information about your visit is transmitted to LinkedIn and associated with your LinkedIn account where you are logged in. Further information on how LinkedIn processes such data is available in LinkedIn’s own privacy policy.
2.4 Recruitment
If you apply for a position, internship or contractor role with us, you may provide personal data, which can include special categories of personal data. These data typically include your CV (including qualifications and professional experience), references and assessments, and, only where lawful and relevant, extracts such as criminal-record or debt-enforcement register extracts. We use these data to assess and process your application and to verify the information you provide. The legal basis is our legitimate interest in recruiting (Art. 6(1)(f) GDPR), steps prior to entering into an employment or service contract (Art. 6(1)(b) GDPR), and, where we process special categories of data, your explicit consent or another applicable legal basis. If we use a third-party applicant-tracking provider, it processes these data on our behalf as a processor. If your application is unsuccessful, we retain your data only for a limited period unless you agree to a longer retention.
2.5 Suppliers, advisers and other contacts
We process personal data about our suppliers, advisers and their personnel in order to manage those relationships and to receive products and services, and about anyone who otherwise contacts us or provides data to us. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR), our legitimate interest (Art. 6(1)(f) GDPR) or compliance with a legal obligation (Art. 6(1)(c) GDPR). We may also process personal data where necessary to establish, exercise or defend legal claims (Art. 6(1)(f) GDPR) or to comply with applicable law (Art. 6(1)(c) GDPR).
2.6 Profiling and automated decision-making
We do not carry out profiling that produces legal effects concerning you or similarly significantly affects you, and we do not take decisions about you based solely on automated processing within the meaning of Article 22 GDPR. Any basic segmentation we apply for marketing does not have legal or similarly significant effects, and you may object to it at any time.
The artificial-intelligence features of the Fusewise platform operate on customer content under the relevant customer’s control and instructions and are intended for review by qualified professionals; they do not make automated decisions about visitors to our website or our business contacts.
3. When and to whom we disclose your personal data
3.1 Recipients
Where necessary or useful for the purposes described in this Privacy Policy, we may disclose your personal data to:
- service providers that process personal data on our behalf, including our cloud hosting and infrastructure provider (Microsoft, Azure; Switzerland), productivity and collaboration tools (Microsoft 365), website analytics and session-recording tools (Microsoft Clarity), and our communications, CRM and marketing tools (including the LinkedIn Insight Tag);
- our EU representative (Prighter EU Rep GmbH);
- professional advisers (such as lawyers, auditors and insurers) bound by confidentiality;
- courts, authorities or other parties where we are legally, regulatorily or professionally required to disclose, or in connection with legal proceedings or to establish, exercise or defend legal claims; and
- a successor or counterparty in connection with a merger, reorganisation or sale of our business or assets.
Our processors are bound by written data-processing agreements and may use personal data only to provide their services to us.
3.2 Transfers abroad
Personal data for which we are the controller is primarily stored in Switzerland and the EU/EEA. Where we transfer personal data to a country that does not ensure an adequate level of data protection under applicable law, we put in place appropriate safeguards, in particular the EU Standard Contractual Clauses together with the Swiss addendum (and the UK addendum where relevant), or rely on a statutory exception (for example, your explicit consent, the performance of a contract, or the establishment, exercise or defence of legal claims). You may request a copy of the safeguards we use; in individual cases we may need to redact parts that are confidential or relate to the privacy of others. Our main recipients outside Switzerland and the EU/EEA are service providers in the United States (for example HubSpot, GitHub, Linear, Vanta, Microsoft Clarity, the LinkedIn Insight Tag and Fathom), in each case under the EU Standard Contractual Clauses and the Swiss addendum. We can provide details of the specific recipients and safeguards on request.
4. Security of your personal data
We maintain technical and organisational measures designed to protect personal data, in electronic and physical form, against unauthorised access, misuse or disclosure, unauthorised alteration, and unlawful destruction or accidental loss. Our information-security programme is aligned with ISO/IEC 27001 and the SOC 2 Trust Services Criteria (certification in progress). Access to systems requires authentication and is granted on a least-privilege, need-to-know basis, and our personnel and service providers who may access confidential information (including personal data) are bound by confidentiality obligations.
We use encryption technologies (such as TLS) to protect data in transit. Please note that ordinary email is not encrypted; we recommend you do not send us sensitive information by unencrypted email.
5. How long we keep your personal data
We retain personal data only for as long as necessary for the purposes for which it was collected. We retain data for longer where required to comply with legal and regulatory obligations, for as long as claims may be brought against us, and for as long as legitimate interests (including data security) require. Personal data contained in customer content is returned or deleted in accordance with the customer agreement and the DPA. We can provide further information about applicable retention periods on request.
6. Your rights
Subject to applicable law, you have the right to:
- request access to your personal data and certain information about how it is processed;
- request the rectification of inaccurate or incomplete personal data;
- request the erasure of your personal data;
- request that we restrict the processing of your personal data;
- object to the processing of your personal data; and
- where applicable, request the portability of personal data you provided to us.
Where our processing is based on your consent, you may withdraw that consent at any time; this does not affect the lawfulness of processing carried out before withdrawal or processing based on another legal basis. We may decline or restrict a request where permitted by law or data-protection rules, and will explain our decision in accordance with the applicable provisions. We generally do not charge a fee, and we may need to verify your identity before acting on a request.
If you believe we have not handled your request or concern satisfactorily, you may lodge a complaint with the competent data-protection authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch); in the EU, it is the supervisory authority of your country of residence, workplace or the place of the alleged infringement.
7. How to contact us
Fusewise AG, Kurhausstrasse 8, 8703 Erlenbach, Switzerland. Email: dataprotection@fusewise.com.
EU representative (Art. 27 GDPR): Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria, online portal: https://app.prighter.com/portal/18891604654.
Please make requests in writing, by email or letter, using the details above.
8. Changes to this Privacy Policy
We may update and amend this Privacy Policy from time to time to reflect changes in how we process personal data or in legal requirements. Any changes will be published on this page, so please check it regularly.
As at: 18 June 2026.