DataFuseAI
Privacy Policy
Your data is yours—and we're committed to keeping it that way.
At DataFuseAI, trust and transparency guide how we collect, use, and protect your information.
Effective Date: January 02, 2026
This Privacy Policy explains how DataFuseAI ("DataFuseAI," "we," "us," or "our") collects, uses, shares, and protects Personal Data when you use our website, products, and services.
By using our Services, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use our Services.
1. Scope of This Privacy Policy
- DataFuseAI website(s) and marketing pages (the "Website")
- Managed Deployment (we host and operate DataFuseAI for you in our cloud environment) (the "Hosted Service")
- Private-hosted (your infrastructure) (DataFuseAI is deployed in Customer's private cloud or servers, with vendor support during deployment) (the "Private-Hosted Service")
- Local on-premise (offline) (Customer-controlled environment, potentially without internet connectivity) (the "Offline Deployment")
- Support and communications (the "Support Services")
This Privacy Policy does not cover third-party services you connect to DataFuseAI (such as AWS, Azure, Databricks, FTP/SFTP providers, databases, and APIs). Their privacy policies and terms apply.
2. Important Role Split: Controller vs Processor
2.1 When DataFuseAI is a Processor (Customer Data)
When a customer organization uses DataFuseAI to connect systems, run queries, execute pipelines, schedule jobs, and export results, we generally process Customer Data on the customer's behalf.
In this context:
- Customer = Data Controller
- DataFuseAI = Data Processor
2.2 When DataFuseAI is a Controller (Business Data)
DataFuseAI is a Data Controller for Personal Data we process for our own business operations, including:
- Website inquiries and marketing communications
- Account and tenant administration
- Billing and subscription management
- Support communications
- Security monitoring and fraud prevention
3. Personal Data We Collect
3.1 Account and Identity Data
We may collect:
- name
- work email address
- company/organization name
- username and account identifiers
- role/group membership and permissions
- profile preferences (e.g., timezone, locale)
3.2 Authentication and Security Data
We may collect:
- login timestamps
- failed login attempts
- password reset events
- OTP verification events
- IP address and device/browser information
- session identifiers
3.3 Billing and Commercial Data
If applicable, we may collect:
- billing contact details
- subscription plan and invoice details
- payment status and transaction records
- tax-related information where required
3.4 Usage Data and Platform Telemetry
We may collect information about how the Service is used, such as:
- feature usage events (e.g., queries executed, pipelines created, jobs run)
- performance metrics (latency, system health)
- error and diagnostic events
Note: DataFuseAI may use analytics/telemetry for security, reliability, and product improvement. We do not use Customer Data for advertising.
3.5 Customer Data Processed in the Service (Highly Sensitive)
Customer Data may include (depending on what customers connect and process):
- data from databases, files, data warehouses, and cloud storage
- query results
- pipeline outputs
- intermediate processing outputs (temporary or staged artifacts)
- profiling outputs and derived statistics
3.6 Metadata and Configuration Data
We may process metadata such as:
- schema/table/column names and data types
- query text (e.g., SQL)
- pipeline definitions and job schedules
- dependency graphs (what depends on what)
- engine configuration identifiers
Metadata can be sensitive because it may reveal business logic or internal structure.
3.7 Credentials and Secrets
Customers may provide secrets for connectivity, including:
- database credentials
- API keys
- OAuth tokens
- SSH keys and certificates
We store secrets using security controls such as encryption and access restriction. Customers should follow least-privilege and rotation practices.
3.8 Logs, Audit Logs, and Observability Data
We may process:
- system logs and diagnostics
- pipeline/job execution logs
- audit logs (such as exports, permission changes, and key actions)
Logs may contain sensitive information depending on customer inputs and configuration.
3.9 Uploads, Drivers, and Exports
We may process:
- uploaded files (e.g., CSV/Excel/JSON)
- uploaded drivers/connectors (e.g., JAR/JDBC drivers)
- user-initiated exports/downloads
3.10 Support Communications
We may process:
- support tickets and messages
- emails and chat communications
- attachments and diagnostic files shared for troubleshooting
4. Sources of Personal Data
We may collect Personal Data from:
- you directly (registration, support, Website forms)
- your organization's administrators (user provisioning, role assignment)
- your browser/device (cookies and telemetry)
- connected third-party services (Customer-controlled sources/sinks)
- service providers supporting our operations
5. How We Use Personal Data
We use Personal Data to:
- Provide and operate the Service (queries, pipelines, jobs, file management, exports)
- Authenticate and authorize access (RBAC, session controls, security checks)
- Maintain security and prevent abuse (monitoring, fraud prevention, incident detection)
- Provide customer support (troubleshooting, diagnostics, communications)
- Manage subscriptions and billing (invoices, payments, usage measurement if applicable)
- Improve and develop the Service (reliability, performance, feature improvements)
- Comply with legal obligations and enforce agreements
- Send service communications (administrative notices, operational updates)
- Send marketing communications where permitted by law and user preferences
6. Legal Bases (GDPR/UK GDPR Where Applicable)
Where GDPR/UK GDPR applies, we rely on one or more of the following legal bases:
- Contract necessity (to provide the Service)
- Legitimate interests (security, service improvement, fraud prevention)
- Consent (for certain cookies and marketing where required)
- Legal obligation (compliance requirements)
7. Sharing and Disclosure of Personal Data
We do not sell Customer Data.
We may share Personal Data in the following situations:
7.1 Service Providers (Subprocessors)
We may share Personal Data with trusted third-party providers who help us operate the Service (such as hosting, monitoring, support systems, email delivery, and payment processing). These providers may process Personal Data only on our instructions and for the purposes described in this Privacy Policy.
DataFuseAI maintains a list of subprocessors and will provide it upon request. We may update subprocessors over time and will provide notice where required by applicable law or contract.
If DataFuseAI processes Personal Data as a Data Processor on behalf of a Customer, the processing will be governed by our Data Processing Addendum (DPA) (where applicable), including terms related to international data transfers and the use of Standard Contractual Clauses (SCCs) when required.
7.2 Customer-Controlled Integrations
Customers may connect third-party services (cloud providers, databases, APIs). Those third parties process data under the customer's configuration and their own terms.
7.3 Legal Requirements
We may disclose information if required to comply with law, regulation, or legal process.
7.4 Business Transfers
If DataFuseAI is involved in a merger, acquisition, financing, or sale of assets, Personal Data may be transferred as part of that transaction, subject to appropriate safeguards.
8. International Data Transfers
DataFuseAI may process Personal Data in countries other than your own. Where required by applicable law (including GDPR/UK GDPR), we implement safeguards such as contractual protections (including Standard Contractual Clauses (SCCs) where applicable) and appropriate security measures.
Customers may be able to select their hosting region depending on their subscription and deployment model.
9. Data Retention
We retain Personal Data only as long as reasonably necessary for the purposes described in this Privacy Policy, including compliance and security needs.
Because retention can vary by customer configuration and deployment model, the following are our standard defaults for the Hosted Service unless otherwise agreed:
- Account data: retained for up to 14 days after account termination
- Audit logs: retained for up to 1 month
- System/application logs: retained for up to 14 days
- Query history: retained for up to 7 days
- Pipeline/job run history: retained for up to 7 days
- Trash/soft-delete items: retained for up to 7 days
- Backups: retained for up to 7 days
- Support tickets: retained for up to 12 months
- Post-termination export window: up to 14 days
Deleted data may remain in backups until backup rotation completes. Legal holds may delay deletion.
For Private-Hosted Service and Offline Deployment, retention is primarily controlled by the Customer environment.
10. Security
We maintain administrative, technical, and organizational measures designed to protect Personal Data, including:
- encryption in transit (TLS)
- encryption at rest for Hosted Service systems
- tenant isolation (Hosted Service)
- role-based access control (RBAC)
- restricted access to production systems for authorized personnel
- monitoring, logging, and incident response practices
Shared Responsibility: Customers are responsible for securing their source systems, user access, credentials, exports, and downstream storage.
12. Your Rights and Choices
Depending on your location and applicable law (including GDPR/UK GDPR, CCPA/CPRA, and other applicable U.S. state privacy laws), you may have rights such as:
- access to Personal Data
- correction
- deletion
- portability
- restriction or objection
- withdrawal of consent (where applicable)
- opt out of certain processing (such as targeted advertising where applicable)
12.1 Requests Involving Customer Data
If your Personal Data is contained in Customer Data processed by a DataFuseAI customer, please contact that customer directly. DataFuseAI generally cannot act on such requests without the customer's instructions.
12.2 Requests Involving DataFuseAI Business Data
You may submit requests related to DataFuseAI-controlled data by contacting us (Section 15).
12.3 California Privacy Rights (CCPA/CPRA)
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), as amended by the CPRA, including the right to:
- request access to Personal Data we collect about you
- request deletion of Personal Data (subject to exceptions)
- request correction of inaccurate Personal Data
- opt out of "sale" or "sharing" of Personal Data (as defined under CCPA/CPRA)
- not be discriminated against for exercising your privacy rights
We do not sell Customer Data. If we engage in "sharing" for cross-context behavioral advertising on our Website (for example, through advertising pixels), you may opt out where required by law.
13. AI/ML Training Statement
DataFuseAI does not use Customer Data to train generalized artificial intelligence or machine learning models for other customers' benefit.
14. Children's Privacy
DataFuseAI is not directed to children under 13, and we do not knowingly collect Personal Data from children.
15. Contact Us
For privacy questions or requests:
- Email: privacy@datafuseai.com
- Legal: legal@datafuseai.com
- Security (optional): security@datafuseai.com