Trust Centre
Everything your security review will ask for, in one place.
Written to be read by procurement and security, and printable.
Overview
Data processing
We act as processor / service provider on your behalf. A Data Processing Agreement is executed before go-live covering GDPR, UK GDPR, CCPA/CPRA and other US state laws, DPDP (India), and PIPEDA with applicable provincial legislation.
Processing jurisdictions are disclosed; none added without 30 days' notice and your approval. The transfer mechanism is documented per customer region.
Capabilities
Access and devices
Named accounts only; shared accounts prohibited; monthly access reviews; leavers reported within 4 hours.
Managed devices with full-disk encryption, endpoint protection, automatic screen lock and remote wipe.
Private workspaces where screens are not visible to third parties.
No screenshots, downloads or storage of customer material outside your tooling, except transiently where your workflow requires.
Quarterly compliance attestation.
Audit on 10 days' notice.
Overview
Personnel
Identity and background checks appropriate to jurisdiction before access, with evidence retained. Confidentiality, IP assignment and acceptable-use undertakings signed before access.
No subcontractors or gig platforms without your written approval; any individual with access to personal data is a sub-processor on terms no less protective than the DPA.
Published terms
Sub-processors
Changes are notified 30 days in advance.
| Entity | Purpose | Location | Date added |
|---|---|---|---|
| Helpdesk platform (client-designated) | Ticketing and customer communications | Per client instance | At go-live |
| Cloud infrastructure provider | Managed workspace hosting | US, EU | 2026-01-12 |
| Device management provider | Endpoint management and encryption | US | 2026-01-12 |
| Identity provider | Named-account authentication and access review | US, EU | 2026-02-03 |
| Background check provider | Pre-access identity and background checks | India, US | 2026-02-17 |
Overview
Customer consent and application access
Customer applications and code are accessed only within a case the customer initiated, or a proactive engagement their plan entitles them to. Customers are informed before any material change.
Changes are attributable to a named engineer and reversible. Calls are recorded only with consent under the customer's jurisdiction and your policy.
Overview
Outbound communications
CASL (Canada), CAN-SPAM and TCPA (US), ePrivacy (EU/UK) and TRAI (India). Opt-outs actioned within 24 hours. Only your approved templates.
No representation about features, outcomes or pricing beyond your published materials. We indemnify you for breach.
Published terms
Certifications and attestations
| Framework | Status |
|---|---|
| SOC 2 Type II | In progress |
| ISO 27001 | Scoping |
| Quarterly internal attestation | Available on request |
Overview
Contact
security@fusioncx.com — response within 1 business day.
No commitment either way
Request the operating plan
Squads, shifts, SLAs and pricing applied to your numbers, in five business days.