Skip to content

Trust Centre

Everything your security review will ask for, in one place.

Written to be read by procurement and security, and printable.

Overview

Data processing

We act as processor / service provider on your behalf. A Data Processing Agreement is executed before go-live covering GDPR, UK GDPR, CCPA/CPRA and other US state laws, DPDP (India), and PIPEDA with applicable provincial legislation.

Processing jurisdictions are disclosed; none added without 30 days' notice and your approval. The transfer mechanism is documented per customer region.

Capabilities

Access and devices

  • Named accounts only; shared accounts prohibited; monthly access reviews; leavers reported within 4 hours.

  • Managed devices with full-disk encryption, endpoint protection, automatic screen lock and remote wipe.

  • Private workspaces where screens are not visible to third parties.

  • No screenshots, downloads or storage of customer material outside your tooling, except transiently where your workflow requires.

  • Quarterly compliance attestation.

  • Audit on 10 days' notice.

Overview

Personnel

Identity and background checks appropriate to jurisdiction before access, with evidence retained. Confidentiality, IP assignment and acceptable-use undertakings signed before access.

No subcontractors or gig platforms without your written approval; any individual with access to personal data is a sub-processor on terms no less protective than the DPA.

Published terms

Sub-processors

Changes are notified 30 days in advance.

EntityPurposeLocationDate added
Helpdesk platform (client-designated)Ticketing and customer communicationsPer client instanceAt go-live
Cloud infrastructure providerManaged workspace hostingUS, EU2026-01-12
Device management providerEndpoint management and encryptionUS2026-01-12
Identity providerNamed-account authentication and access reviewUS, EU2026-02-03
Background check providerPre-access identity and background checksIndia, US2026-02-17

Overview

Customer consent and application access

Customer applications and code are accessed only within a case the customer initiated, or a proactive engagement their plan entitles them to. Customers are informed before any material change.

Changes are attributable to a named engineer and reversible. Calls are recorded only with consent under the customer's jurisdiction and your policy.

Overview

Outbound communications

CASL (Canada), CAN-SPAM and TCPA (US), ePrivacy (EU/UK) and TRAI (India). Opt-outs actioned within 24 hours. Only your approved templates.

No representation about features, outcomes or pricing beyond your published materials. We indemnify you for breach.

Published terms

Certifications and attestations

FrameworkStatus
SOC 2 Type IIIn progress
ISO 27001Scoping
Quarterly internal attestationAvailable on request

Overview

Contact

security@fusioncx.com — response within 1 business day.

No commitment either way

Request the operating plan

Squads, shifts, SLAs and pricing applied to your numbers, in five business days.