Fusion Arc Hosting – Privacy Policy

Effective Date: September 11, 2026
Last Updated: September 11, 2026

1. Who We Are

Fusion Arc Hosting, a division of Fusion Arc Telecom LLC (“Fusion Arc,” “Fusion Arc Hosting,” “we,” “us,” or “our”), provides web hosting, reseller hosting, virtual server, dedicated server, domain registration and management, infrastructure, customer support, and related technology services.

This Privacy Policy explains how we collect, use, disclose, process, retain, and protect Personal Information and describes the privacy rights and choices that may be available to you.

This Privacy Policy applies to information collected through or in connection with:

  • our websites;

  • Client Area and billing systems;

  • orders and service provisioning;

  • live chat;

  • support tickets;

  • email and other customer communications;

  • domain registration and transfer services;

  • hosting, server, and infrastructure services;

  • security, fraud-prevention, and abuse-prevention systems;

  • customer verification processes;

  • analytics and advertising technologies; and

  • other products, systems, or services operated by Fusion Arc Hosting.

This Privacy Policy operates together with our Terms of Service, Acceptable Use Policy, Refund & Payment Policy, Domain Registration terms, and other applicable agreements and policies.


2. Our Role When Processing Information

Depending on the circumstances, Fusion Arc may process Personal Information in different legal roles.

2.1 Information About Fusion Arc Customers and Visitors

When Fusion Arc determines why and how Personal Information is processed for activities such as:

  • account creation;

  • billing;

  • customer support;

  • order processing;

  • fraud prevention;

  • marketing;

  • security;

  • service administration; or

  • website operation,

Fusion Arc generally acts as the controller, business, or equivalent entity under applicable privacy law.

2.2 Information Hosted by Our Customers

Customers may use Fusion Arc services to host or process information concerning their own:

  • visitors;

  • customers;

  • users;

  • employees;

  • subscribers;

  • members; or

  • other individuals.

For Personal Information contained within customer-hosted websites, applications, databases, email accounts, files, backups, or other customer content, the customer generally determines the purposes and means of processing.

In those circumstances, Fusion Arc generally acts as a processor, service provider, contractor, infrastructure provider, or similar entity on behalf of the customer.

Customers are responsible for determining whether their own collection and processing of Personal Information complies with applicable law, including providing required notices and obtaining required permissions or legal bases.

Fusion Arc may access or process customer-hosted data where reasonably necessary to:

  • provide requested technical support;

  • maintain the service;

  • restore data;

  • secure our network;

  • investigate abuse;

  • diagnose technical problems;

  • respond to security incidents;

  • comply with law; or

  • otherwise perform obligations permitted by our agreements.


3. Personal Information We Collect

We collect Personal Information directly from you, automatically from devices and systems, and from third parties involved in providing our services.

3.1 Information You Provide

Identifiers and Contact Information

This may include:

  • first and last name;

  • company or organization;

  • mailing address;

  • billing address;

  • email address;

  • telephone number;

  • country;

  • account username or identifier; and

  • other contact information.

Account and Service Information

This may include:

  • domains;

  • hosting plans;

  • server services;

  • IP assignments;

  • DNS configuration;

  • server names;

  • account settings;

  • service preferences;

  • service history; and

  • other information associated with products purchased from us.

Billing and Transaction Information

This may include:

  • invoices;

  • transaction history;

  • payment status;

  • transaction identifiers;

  • payment processor information;

  • refunds;

  • disputes;

  • chargebacks;

  • fraud indicators; and

  • limited payment-method information.

Full payment card information is generally processed directly by payment processors rather than stored in full by Fusion Arc.

Verification Information

Where reasonably necessary for fraud prevention, identity verification, account recovery, sanctions compliance, or order verification, we may request information such as:

  • government-issued identification;

  • limited payment verification;

  • ownership verification;

  • address verification; or

  • other information reasonably necessary to confirm identity or account ownership.

Customer Support and Communications

When you communicate with Fusion Arc through live chat, tickets, email, telephone, or another support channel, we may collect:

  • support ticket messages;

  • live-chat messages;

  • chat transcripts;

  • email correspondence;

  • call recordings where recording is disclosed;

  • attachments;

  • screenshots;

  • domain information;

  • server logs;

  • application logs;

  • error messages;

  • configuration information;

  • diagnostic information;

  • credentials you voluntarily provide;

  • information regarding your services; and

  • any other information you include in your communication.


3.2 Information Collected Automatically

When you access our websites, Client Area, services, or systems, we may automatically collect information including:

  • IP address;

  • browser type;

  • browser version;

  • operating system;

  • device type;

  • device identifiers;

  • timestamps;

  • pages viewed;

  • referring URLs;

  • approximate geographic information;

  • ISP or network provider;

  • session identifiers;

  • authentication events;

  • security events;

  • error logs;

  • service logs;

  • abuse indicators;

  • network information; and

  • technical diagnostic information.


3.3 Analytics and Session Information

We may use analytics, performance-monitoring, heatmap, session-replay, and diagnostic technologies to understand how our websites and services are used.

These technologies may collect information such as:

  • page navigation;

  • mouse movement;

  • clicks;

  • session duration;

  • browser information;

  • device information;

  • errors; and

  • website interaction information.

Where supported, sensitive payment fields and other designated sensitive fields are masked or excluded from session recording or replay technologies.

Analytics providers may include services such as Microsoft Clarity and other analytics technologies used by Fusion Arc.


3.4 Information From Third Parties

We may receive information from:

  • payment processors;

  • fraud-prevention providers;

  • advertising providers;

  • analytics providers;

  • domain registrars and registries;

  • datacenter providers;

  • network providers;

  • infrastructure providers;

  • security vendors;

  • backup and storage providers;

  • support platforms;

  • AI providers;

  • software vendors;

  • professional advisors; and

  • other service providers.


4. Notice at Collection

This section provides a summary of the principal categories of Personal Information Fusion Arc may collect, why we collect them, and typical retention considerations.

Actual collection depends on how you interact with Fusion Arc.

4.1 Identifiers and Contact Information

Examples: name, address, email address, telephone number, account identifiers, IP address.

Purposes: account creation, customer identification, billing, authentication, service delivery, support, fraud prevention, security, communications, and legal compliance.

Typical retention: generally for the life of the customer relationship plus approximately two years, unless longer retention is reasonably necessary for legal, security, accounting, dispute-resolution, or fraud-prevention purposes.


4.2 Commercial, Account, and Service Information

Examples: hosting products, domains, services purchased, invoices, server information, transaction history, account history.

Purposes: service delivery, billing, provisioning, support, account administration, security, accounting, taxation, and contractual administration.

Typical retention: account and service information is generally retained for the life of the account plus approximately two years. Financial records may be retained longer where required for tax, accounting, or legal purposes.


4.3 Support and Communications Information

Examples: support tickets, live-chat transcripts, emails, troubleshooting information, attachments, logs, and call recordings where disclosed.

Purposes: customer support, troubleshooting, quality assurance, security, dispute resolution, training personnel, recordkeeping, fraud and abuse prevention, and AI-assisted support.

Typical retention: generally approximately two to three years following closure or completion of the support interaction unless longer retention is reasonably necessary.


4.4 Internet, Device, and Network Activity

Examples: IP address, cookies, page activity, browser information, network information, service logs, security events, and device information.

Purposes: operating services, authentication, troubleshooting, cybersecurity, analytics, fraud prevention, advertising measurement, and service improvement.

Typical retention: determined based on operational need, tool configuration, legal requirements, security requirements, and applicable consent choices.


4.5 Payment and Transaction Information

Examples: invoice information, payment status, transaction IDs, limited payment metadata, refund and chargeback information.

Purposes: payment processing, refunds, billing, financial reporting, accounting, fraud prevention, tax compliance, and dispute resolution.

Typical retention: financial and accounting records may generally be retained for approximately seven years or another period required by applicable law.


4.6 Domain Registration Information

Examples: registrant name, organization, address, telephone number, email address, country, domain, and registration information.

Purposes: domain registration, transfer, renewal, ownership administration, registrar compliance, registry requirements, and legal or contractual requirements.

Typical retention: Fusion Arc retains domain information according to our operational and legal requirements. Registrars, registries, ICANN-related systems, and other domain providers may maintain separate retention obligations under their own policies and applicable requirements.


4.7 Verification and Sensitive Information

Examples: government identification, authentication information, account credentials voluntarily provided for support, or limited payment verification information.

Purposes: account verification, security, fraud prevention, recovery, sanctions compliance, abuse prevention, and legal compliance.

Fusion Arc’s policy is to use sensitive Personal Information only where reasonably necessary for legitimate operational, security, verification, service, or legal purposes.

We do not use sensitive Personal Information to infer personal characteristics for advertising purposes.


5. How We Use Personal Information

Fusion Arc may use Personal Information for the following purposes.

5.1 Providing Services

Including:

  • provisioning services;

  • hosting websites and applications;

  • operating servers;

  • configuring accounts;

  • managing DNS;

  • registering domains;

  • transferring domains;

  • providing backups;

  • managing infrastructure; and

  • providing customer support.

5.2 Billing and Account Administration

Including:

  • generating invoices;

  • processing payments;

  • issuing refunds;

  • managing subscriptions;

  • resolving payment disputes;

  • handling chargebacks;

  • accounting;

  • taxation; and

  • maintaining financial records.

5.3 Security, Fraud, and Abuse Prevention

Including:

  • intrusion detection;

  • malware detection;

  • spam prevention;

  • authentication;

  • account protection;

  • abuse investigations;

  • DDoS protection;

  • fraud detection;

  • sanctions screening;

  • vulnerability management;

  • threat detection; and

  • enforcing our agreements.

5.4 Customer Support

Including:

  • responding to tickets;

  • providing live-chat assistance;

  • diagnosing service issues;

  • reviewing logs;

  • resolving account problems;

  • maintaining support records;

  • routing support requests;

  • and improving customer service.

5.5 Communications

Including:

  • service notifications;

  • invoices;

  • security notices;

  • maintenance notifications;

  • account notices;

  • legal notices;

  • policy updates; and

  • marketing communications where permitted.

5.6 Service Improvement

Including:

  • website analytics;

  • performance analysis;

  • debugging;

  • feature development;

  • quality assurance;

  • usability analysis;

  • support improvement; and

  • operational planning.

5.7 Advertising and Attribution

Where permitted, we may use limited Personal Information to:

  • measure advertising performance;

  • attribute conversions;

  • optimize marketing campaigns;

  • prevent click fraud;

  • display targeted advertising; and

  • measure campaign effectiveness.

5.8 Legal Compliance

Including:

  • complying with lawful requests;

  • responding to court orders;

  • tax reporting;

  • accounting;

  • sanctions compliance;

  • regulatory compliance;

  • enforcing contractual rights; and

  • establishing or defending legal claims.


6. Legal Bases Under GDPR and UK GDPR

Where the GDPR, UK GDPR, or a comparable law applies, the legal basis for processing depends on the activity.

6.1 Performance of a Contract

We process Personal Information where reasonably necessary to:

  • provide purchased services;

  • administer your account;

  • register domains;

  • process transactions;

  • provide technical support; or

  • take requested steps before entering into a contract.

6.2 Legitimate Interests

We may process Personal Information where reasonably necessary for legitimate interests including:

  • securing systems;

  • preventing fraud;

  • preventing abuse;

  • improving services;

  • supporting customers;

  • maintaining reliable infrastructure;

  • protecting our legal rights; and

  • communicating with customers.

We consider applicable privacy rights when relying on legitimate interests.

6.3 Consent

We rely on consent where required by applicable law, including for certain:

  • cookies;

  • advertising technologies;

  • optional communications;

  • recordings;

  • live-chat processing; or

  • other optional processing.

Where processing depends on consent, you may withdraw consent where permitted by law.

Withdrawal does not affect processing that was lawful before consent was withdrawn.

6.4 Legal Obligations

We may process Personal Information where necessary to satisfy:

  • tax requirements;

  • accounting requirements;

  • regulatory obligations;

  • sanctions requirements;

  • domain-registration requirements;

  • court orders; or

  • other legal obligations.

6.5 Protection of Rights and Safety

Where permitted by law, information may be processed where reasonably necessary to protect Fusion Arc, customers, systems, personnel, property, or other individuals.


7. Cookies and Tracking Technologies

Fusion Arc uses cookies, pixels, session technologies, local storage, and similar technologies.

7.1 Essential Technologies

Used for:

  • login sessions;

  • authentication;

  • security;

  • shopping-cart functions;

  • load balancing;

  • fraud prevention; and

  • service operation.

7.2 Analytics Technologies

Used for:

  • website analytics;

  • session analysis;

  • usability;

  • performance;

  • troubleshooting;

  • heatmaps; and

  • session replay.

Providers may include services such as Microsoft Clarity and similar tools.

7.3 Advertising and Attribution Technologies

Used for:

  • conversion tracking;

  • advertising attribution;

  • campaign optimization;

  • targeted advertising;

  • advertising measurement; and

  • click-fraud prevention.

Providers may include:

  • Google;

  • Microsoft;

  • Meta;

  • Reddit;

  • ClickCease; and

  • similar platforms.

7.4 Cookie and Privacy Controls

Where required by law, visitors may receive controls allowing them to accept or manage non-essential technologies.

We honor Global Privacy Control and other legally recognized universal opt-out mechanisms where required by applicable law.


8. Live Chat, Monitoring, and Recording

Fusion Arc uses customer-support and live-chat technologies, including tawk.to.

Live-chat conversations may be:

  • monitored;

  • stored;

  • reviewed;

  • analyzed;

  • processed;

  • summarized; and

  • maintained as chat transcripts.

Associated information may include:

  • your name;

  • email address;

  • IP address;

  • browser information;

  • account information;

  • chat messages;

  • timestamps; and

  • technical or service information you provide.

Where required by applicable law or Fusion Arc policy, a notice is displayed before a live-chat interaction begins.

When a notice states that a chat will be monitored, recorded, stored, processed, or processed using AI, clicking an affirmative option such as:

  • Accept;

  • I Accept;

  • Accept & Start Chat; or

  • a substantially similar option

indicates your consent to the activities described in that notice, subject to applicable law.

If you decline the notice, live chat may not begin.

Other support channels may remain available.

For text-based chats, “recording” may include storage of the conversation as a written chat transcript.

Telephone, voice, or other communications may be recorded where recording is disclosed and permitted by law.


9. Artificial Intelligence and Automated Assistance

Fusion Arc uses or may use artificial intelligence, machine-learning, automated support, and related technology to assist customer service and business operations.

Providers currently used or authorized may include:

  • OpenAI;

  • Google, including Gemini;

  • tawk.to, including tawk.to AI functionality; and

  • other AI, automation, communications, or support technology providers selected by Fusion Arc.

The technology provider used may vary by feature or workflow.

The inclusion of a provider in this Policy does not mean every customer’s information is sent to that provider.


9.1 Information AI Systems May Process

Depending on the support interaction and system configuration, information provided to AI-assisted systems may include:

  • customer messages;

  • relevant chat history;

  • support-ticket content;

  • account identifiers;

  • domain names;

  • service information;

  • troubleshooting details;

  • logs;

  • diagnostic information;

  • attachments or excerpts where required;

  • relevant support history; and

  • technical context necessary to understand the request.

We seek to limit information provided to AI systems to information reasonably relevant to the intended task.


9.2 How AI May Be Used

AI may assist with:

  • generating suggested responses;

  • generating customer-facing responses;

  • summarizing conversations;

  • translating messages;

  • classifying requests;

  • routing support requests;

  • retrieving support information;

  • assisting technical personnel;

  • identifying possible troubleshooting steps;

  • quality assurance;

  • fraud detection;

  • security analysis;

  • spam detection; and

  • improving support efficiency.

AI-generated information can contain errors.

Where appropriate, Fusion Arc personnel may review, modify, override, or correct AI-generated information.


9.3 Automated Decisions

Fusion Arc does not currently use customer-support AI to make solely automated decisions that produce legal or similarly significant effects concerning customers.

Security, anti-abuse, or fraud systems may automatically generate warnings, scores, restrictions, or alerts. Human review may be used where appropriate, particularly when material account action is required.

Where applicable law grants rights relating to automated decision-making, profiling, or similar technologies, Fusion Arc will honor those rights.


9.4 Third-Party AI Providers

Information submitted to an AI-assisted system may be transmitted to an authorized AI or technology provider.

Depending on the service, such providers may process information as:

  • service providers;

  • processors;

  • contractors;

  • independent businesses or controllers for limited purposes; or

  • another role determined by applicable law and the provider relationship.

Third-party AI providers may maintain their own infrastructure, security systems, subprocessors, logs, or legally required records.

Fusion Arc evaluates and configures AI services based on operational, privacy, security, contractual, and technical requirements.


9.5 Sensitive Information and AI

Customers should avoid providing unnecessary secrets or highly sensitive information through live chat or other support channels.

Unless specifically necessary and requested through an appropriate support process, do not send:

  • full payment-card numbers;

  • Social Security numbers;

  • SSH private keys;

  • private encryption keys;

  • API secrets;

  • recovery codes;

  • authentication tokens;

  • database passwords;

  • account passwords;

  • private signing keys;

  • protected health information; or

  • other highly sensitive credentials.

Where practical, Fusion Arc may remove, redact, or limit exposure of sensitive information before using external tools.

However, if a customer voluntarily includes sensitive information in a message, attachment, diagnostic log, or support request, that information may be processed as part of the communication before it can be identified or removed.


10. Payment Processing

Fusion Arc uses third-party payment processors, including Stripe and PayPal.

These providers may process information such as:

  • customer name;

  • billing address;

  • email address;

  • payment credentials;

  • transaction amount;

  • currency;

  • IP address;

  • fraud information;

  • transaction identifier;

  • payment authorization information; and

  • dispute or chargeback information.

Stripe and PayPal may process certain information according to their own privacy policies and independent legal or regulatory obligations.

Fusion Arc generally does not store complete payment-card information when it is processed directly by a payment provider.

We may retain:

  • transaction IDs;

  • payment status;

  • invoice information;

  • limited payment metadata;

  • refund information;

  • chargeback information; and

  • other records needed for accounting, fraud prevention, customer service, or legal compliance.


11. Domain Registration, Transfers, and Enom

Fusion Arc uses third-party domain providers, including Enom, to provide domain-registration and related services.

When you:

  • register a domain;

  • transfer a domain;

  • renew a domain;

  • modify registration information; or

  • otherwise manage a domain,

Fusion Arc may transmit required information to Enom and other organizations involved in the domain-registration ecosystem.

Information may include:

  • registrant name;

  • organization;

  • mailing address;

  • email address;

  • telephone number;

  • country;

  • domain name;

  • registration dates;

  • transfer information;

  • domain status; and

  • other information required for the applicable domain extension.

Information may also be processed by:

  • the applicable registry operator;

  • ICANN-related systems;

  • domain privacy providers;

  • escrow providers;

  • dispute-resolution providers;

  • technical service providers; and

  • other entities necessary to operate or regulate domain registration.

Certain registrars and registries may act as independent controllers or otherwise have independent legal and contractual obligations concerning domain-registration information.

Their privacy practices, retention requirements, disclosure obligations, or data requirements may differ from Fusion Arc’s.

Public WHOIS or RDAP services may display or redact registration information depending on:

  • the domain extension;

  • registrar policy;

  • registry policy;

  • domain privacy settings;

  • ICANN requirements; and

  • applicable law.

Even when registration information is redacted from public lookup systems, underlying registration information may continue to be retained or accessible where required for legitimate, contractual, regulatory, or legal purposes.


12. Billing and Account Management Systems

Fusion Arc uses WHMCS software as part of its billing, customer-management, ordering, invoicing, support, service-provisioning, and automation environment.

Fusion Arc’s primary WHMCS deployment is self-hosted on infrastructure operated or controlled by Fusion Arc Hosting.

Fusion Arc does not use WHMCS Cloud as the primary hosting environment for its customer database.

Information processed through our WHMCS environment may include:

  • customer profiles;

  • contact information;

  • services;

  • domains;

  • invoices;

  • transactions;

  • support information;

  • account history;

  • service configuration;

  • order information; and

  • payment metadata.

WHMCS or services associated with WHMCS may receive limited information where necessary for:

  • licensing;

  • software updates;

  • technical support;

  • diagnostics;

  • fraud-related modules;

  • integrations; or

  • other features configured by Fusion Arc.


13. Hosting and Infrastructure Technology

Fusion Arc uses commercial, open-source, and internally managed technologies to provide and secure hosting services.

Technology used within our infrastructure may include products or services from providers such as:

  • cPanel;

  • CloudLinux;

  • LiteSpeed Technologies;

  • Imunify360 and related Imunify services;

  • JetBackup;

  • Softaculous;

  • KernelCare;

  • DNS and PowerDNS-related technologies;

  • server-monitoring technologies;

  • network-management systems;

  • security providers;

  • operating-system providers; and

  • other hosting and infrastructure software vendors.

Depending on configuration, such technologies may process or receive limited information including:

  • server IP addresses;

  • hostnames;

  • licensing identifiers;

  • operating-system information;

  • resource-usage information;

  • security events;

  • malware indicators;

  • abuse indicators;

  • backup metadata;

  • server diagnostics;

  • error logs; and

  • information Fusion Arc intentionally provides when requesting technical support.

The presence of software in our infrastructure does not mean that the software vendor receives all customer information or has direct access to customer content.

Information provided to a vendor depends upon:

  • system architecture;

  • software configuration;

  • licensing;

  • support requirements;

  • integrations; and

  • the specific service being provided.


14. Datacenter, Network, and Infrastructure Partners

Fusion Arc operates services using hardware, network connectivity, datacenter space, infrastructure, and related services provided by multiple infrastructure partners.

Current or representative providers may include:

  • InterServer;

  • GTHost; and

  • other datacenter, dedicated-server, colocation, bandwidth, network, hardware, cloud, storage, and infrastructure providers.

Depending on architecture and service location, infrastructure providers may host, store, carry, or technically have access to:

  • servers;

  • network traffic;

  • customer-hosted data;

  • IP addresses;

  • backups;

  • server identifiers;

  • hardware information;

  • network logs;

  • abuse information; and

  • other technical information necessary to provide infrastructure.

Fusion Arc may:

  • add providers;

  • replace providers;

  • migrate servers;

  • change datacenters;

  • change network carriers; or

  • move services between facilities

as operational requirements evolve.

The infrastructure providers named in this Policy are representative and may not represent every provider used at every point in time.


15. Backups and Disaster Recovery

Fusion Arc uses backup and disaster-recovery systems, including technologies provided by JetBackup and other storage or infrastructure providers.

Depending on the service, backups may contain:

  • website files;

  • databases;

  • email;

  • account configuration;

  • server data;

  • logs;

  • customer content; and

  • other data stored within the applicable service.

Backups may be stored on infrastructure physically separate from the production server.

Backup data may be transmitted to or stored through:

  • backup providers;

  • storage providers;

  • datacenter providers;

  • cloud or object-storage providers; and

  • other infrastructure selected by Fusion Arc.

Backup retention depends on:

  • the applicable service;

  • configured backup schedule;

  • purchased backup product;

  • system requirements;

  • disaster-recovery requirements; and

  • our Terms of Service.

Deletion from an active system may not immediately remove information from an existing backup. Information contained within backups may remain until the backup expires or is overwritten according to the applicable retention cycle.


16. How We Disclose Personal Information

Fusion Arc does not disclose Personal Information indiscriminately.

We disclose information where reasonably necessary to provide services, operate our business, protect our systems, comply with law, or accomplish another purpose disclosed in this Privacy Policy.

16.1 Payment Processors

Including providers such as:

  • Stripe; and

  • PayPal.

16.2 Domain Providers

Including:

  • Enom;

  • domain registries;

  • ICANN-related organizations;

  • domain privacy providers; and

  • associated technical providers.

16.3 Customer Support and Communications Providers

Including providers such as:

  • tawk.to;

  • email providers;

  • communications providers; and

  • other customer-support platforms.

16.4 AI and Automation Providers

Including providers such as:

  • OpenAI;

  • Google Gemini;

  • tawk.to AI; and

  • other authorized AI or automation services.

16.5 Infrastructure Providers

Including:

  • InterServer;

  • GTHost;

  • network providers;

  • datacenter operators;

  • hardware providers;

  • backup providers;

  • storage providers; and

  • other infrastructure partners.

16.6 Hosting and Security Technology Providers

Including technology providers related to:

  • cPanel;

  • CloudLinux;

  • LiteSpeed;

  • Imunify;

  • JetBackup;

  • Softaculous;

  • KernelCare;

  • DNS;

  • monitoring;

  • malware prevention; and

  • infrastructure management.

16.7 Analytics, Advertising, and Fraud-Prevention Providers

Including providers such as:

  • Google;

  • Microsoft;

  • Meta;

  • Reddit;

  • Microsoft Clarity;

  • ClickCease; and

  • similar providers.

16.8 Professional Advisors

We may disclose limited information to:

  • attorneys;

  • accountants;

  • auditors;

  • insurers;

  • insurance brokers;

  • consultants; and

  • other professional advisors.

16.9 Legal and Safety Disclosures

We may disclose information where we reasonably believe disclosure is necessary to:

  • comply with law;

  • comply with court orders;

  • respond to lawful government requests;

  • enforce our agreements;

  • investigate abuse;

  • prevent fraud;

  • protect our rights;

  • protect customers;

  • protect infrastructure;

  • protect public safety; or

  • address unlawful content or conduct.

This may include legally required reporting relating to child sexual abuse material or other unlawful activity.

16.10 Corporate Transactions

Personal Information may be transferred in connection with:

  • a merger;

  • acquisition;

  • investment;

  • financing;

  • restructuring;

  • bankruptcy;

  • sale of assets; or

  • similar corporate transaction.

Any such transfer remains subject to applicable privacy and confidentiality requirements.


17. Sale, Sharing, and Targeted Advertising

Fusion Arc does not sell customer lists for monetary consideration.

However, some privacy laws define “sale” or “sharing” broadly.

The disclosure of:

  • IP addresses;

  • cookies;

  • advertising identifiers;

  • device identifiers;

  • browsing activity;

  • page views; or

  • similar information

to advertising, analytics, or attribution providers may be considered:

  • a sale;

  • sharing;

  • targeted advertising; or

  • cross-context behavioral advertising

under certain state privacy laws even where Fusion Arc does not receive money for the information.

Where applicable, consumers may opt out through:

  • our cookie or privacy-preference controls;

  • a Do Not Sell or Share My Personal Information mechanism;

  • Global Privacy Control; or

  • a privacy request submitted to Fusion Arc.

Fusion Arc does not knowingly sell or share Personal Information of individuals under 16 for targeted advertising purposes.


18. International Data Transfers

Fusion Arc is based in the United States.

Our customers, infrastructure, vendors, and service providers may operate in multiple countries.

Personal Information may therefore be:

  • transmitted;

  • accessed;

  • stored; or

  • processed

in the United States or other jurisdictions.

Those jurisdictions may have privacy laws different from the laws where you live.

Where legally required, Fusion Arc uses or relies upon appropriate transfer safeguards, which may include:

  • Standard Contractual Clauses;

  • UK transfer mechanisms;

  • adequacy decisions;

  • recognized data-transfer frameworks;

  • contractual protections; or

  • another legally permitted transfer mechanism.


19. Information Security

Fusion Arc uses reasonable administrative, technical, and physical safeguards designed to protect Personal Information.

Depending on the system, these safeguards may include:

  • TLS encryption in transit;

  • authentication;

  • access controls;

  • account isolation;

  • network segmentation;

  • firewalls;

  • malware detection;

  • intrusion detection;

  • abuse monitoring;

  • vulnerability management;

  • security logging;

  • backups;

  • administrative access restrictions;

  • patching;

  • monitoring; and

  • security review procedures.

No system, transmission method, storage platform, or security measure is completely secure.

Accordingly, we cannot guarantee absolute security.

Customers are responsible for maintaining appropriate security for:

  • their passwords;

  • applications;

  • websites;

  • software;

  • accounts;

  • API credentials;

  • user permissions; and

  • hosted content.


20. Data Retention

Fusion Arc retains Personal Information only for as long as reasonably necessary for the purpose for which it was collected and for applicable:

  • legal;

  • accounting;

  • tax;

  • security;

  • fraud-prevention;

  • contractual;

  • backup;

  • dispute-resolution; or

  • compliance requirements.

Typical retention periods include the following.

20.1 Customer Account and Service Information

Generally retained for the duration of the account plus approximately two years.

20.2 Invoices, Transactions, and Accounting Records

Generally retained for approximately seven years or another period required by applicable tax, accounting, or legal obligations.

20.3 Support Tickets and Live-Chat Transcripts

Generally retained for approximately two to three years following closure or completion of the support interaction unless longer retention is reasonably necessary.

20.4 Email and Support Communications

Generally retained according to customer-support, security, legal, and operational requirements.

20.5 Call Recordings

Where applicable, retained according to the reason for the recording, applicable law, and operational requirements.

20.6 Verification Documents

Generally retained for no longer than approximately two years after verification unless longer retention is reasonably necessary or legally required.

20.7 Security and Abuse Information

May be retained for the period reasonably necessary to:

  • investigate incidents;

  • protect systems;

  • prevent repeat abuse;

  • detect fraud;

  • maintain evidence; or

  • establish or defend legal claims.

20.8 Domain Registration Information

Retained according to Fusion Arc’s operational requirements and applicable registrar, registry, ICANN, contractual, or legal requirements.

Domain providers may maintain separate retention schedules.

20.9 Analytics and Advertising Information

Retained according to:

  • applicable tool configuration;

  • consent preferences;

  • privacy settings;

  • operational requirements; and

  • applicable law.

20.10 Backups

Retained according to the applicable backup rotation and service configuration.

Data deleted from an active system may remain temporarily within backups until those backups expire or are overwritten.

20.11 Third-Party Systems

Third-party providers may maintain logs, backups, transaction records, or other information according to their own legitimate operational and legal requirements.

When Personal Information is no longer reasonably required by Fusion Arc, we may:

  • delete it;

  • anonymize it;

  • aggregate it; or

  • otherwise dispose of it securely.


21. Privacy Rights

Privacy rights depend on your jurisdiction.

Where applicable, you may have the right to:

  • access Personal Information;

  • know whether we process Personal Information;

  • obtain a copy of Personal Information;

  • obtain portable Personal Information;

  • correct inaccurate information;

  • request deletion;

  • request restriction of processing;

  • object to processing;

  • withdraw consent;

  • opt out of targeted advertising;

  • opt out of sale or sharing;

  • limit qualifying use of sensitive Personal Information;

  • appeal certain privacy decisions; and

  • make a complaint to a privacy regulator.


22. GDPR and UK GDPR Rights

Where applicable, individuals may have rights including:

  • access;

  • rectification;

  • erasure;

  • restriction;

  • data portability;

  • objection;

  • withdrawal of consent; and

  • rights relating to certain automated decision-making.

Where processing is based upon consent, withdrawing consent does not affect the lawfulness of processing performed before withdrawal.

Individuals may also lodge a complaint with their applicable supervisory authority.


23. United States State Privacy Rights

Residents of certain U.S. states may have privacy rights under applicable comprehensive state privacy laws.

Depending on the law, these may include rights to:

  • access;

  • know;

  • correct;

  • delete;

  • obtain a portable copy;

  • opt out of sale;

  • opt out of sharing;

  • opt out of targeted advertising;

  • opt out of qualifying profiling;

  • limit qualifying use of sensitive Personal Information; and

  • appeal a denied request.


24. California Privacy Rights

Where the California Consumer Privacy Act and California Privacy Rights Act apply, California residents may have rights to:

  • know categories of Personal Information collected;

  • know specific pieces of Personal Information collected;

  • know categories of sources;

  • know purposes for collection and use;

  • know categories of third parties;

  • access Personal Information;

  • delete qualifying Personal Information;

  • correct inaccurate Personal Information;

  • opt out of sale or sharing;

  • limit certain qualifying uses of sensitive Personal Information; and

  • exercise privacy rights without unlawful discrimination.

Fusion Arc’s policy is not to use sensitive Personal Information for purposes of inferring characteristics about consumers or for targeted advertising.


25. Colorado Privacy Rights

Where the Colorado Privacy Act applies, Colorado consumers may have rights to:

  • access Personal Data;

  • correct inaccurate Personal Data;

  • delete Personal Data;

  • obtain a portable copy of Personal Data;

  • opt out of targeted advertising;

  • opt out of qualifying sale;

  • opt out of qualifying profiling; and

  • appeal certain decisions regarding privacy requests.

If Fusion Arc denies a privacy request and applicable law provides an appeal right, you may request an appeal by responding to the decision and clearly stating that you wish to Appeal the privacy decision.


26. How to Submit a Privacy Request

You may submit a privacy request by:

Email:
privacy@fusionarchosting.com

or

Client Area:
Open a support ticket and select the applicable Privacy Request option where available.

We may request information reasonably necessary to verify:

  • your identity;

  • your account;

  • the scope of your request; or

  • an authorized agent’s authority.

We will not request substantially more Personal Information than reasonably necessary to verify the request.

Response periods depend on applicable law.

For example, GDPR requests are generally addressed within one month, subject to legally permitted extensions.

U.S. state laws may provide different response periods and extension rights.


27. Authorized Agents

Where applicable law allows an authorized agent to submit a request on your behalf, Fusion Arc may require:

  • evidence that the agent is authorized;

  • verification of your identity;

  • direct confirmation from you; or

  • other documentation permitted by applicable law.


28. Global Privacy Control and Opt-Out Signals

Where legally required, Fusion Arc recognizes qualifying opt-out preference signals, including Global Privacy Control (GPC).

Depending on the implementation and applicable law, an opt-out signal may apply to the browser or device from which the signal is received.

Account-level choices may require additional identification or account settings.


29. Sensitive Personal Information

Fusion Arc may process certain sensitive Personal Information where reasonably necessary to:

  • authenticate users;

  • protect accounts;

  • prevent fraud;

  • verify identity;

  • secure systems;

  • provide requested technical support;

  • process payments;

  • fulfill legal obligations; or

  • provide contracted services.

Fusion Arc does not use sensitive Personal Information for unrelated behavioral advertising or to infer sensitive characteristics about individuals.


30. HIPAA and Protected Health Information

Fusion Arc Hosting is not represented as a HIPAA-compliant hosting provider and does not ordinarily enter into Business Associate Agreements.

Customers must not store or process Protected Health Information through Fusion Arc services unless Fusion Arc has expressly agreed in writing to provide an appropriate service for that purpose.

Customers should not transmit Protected Health Information through general customer-support or live-chat channels.


31. Children’s Privacy

Fusion Arc services are intended for adults and business customers as described in our Terms of Service.

We do not knowingly collect Personal Information from children under 13 in violation of the Children’s Online Privacy Protection Act.

Our services are intended for customers who meet the age requirements stated in our Terms of Service.

We do not knowingly sell or share Personal Information of individuals under 16 for targeted advertising purposes.

If you believe a child has improperly provided Personal Information to Fusion Arc, contact:

privacy@fusionarchosting.com


32. Third-Party Websites and Services

Fusion Arc websites or services may contain links to third-party websites, applications, or services.

When you interact directly with an independent third party, its privacy practices are governed by its own policies.

Fusion Arc is not responsible for independent third-party privacy practices outside our control.

This provision does not alter Fusion Arc’s responsibilities where a third party acts as our processor, contractor, or service provider.


33. Electronic Communications

By maintaining an account or using our services, you may receive communications necessary to administer your services, including:

  • invoices;

  • payment notices;

  • security alerts;

  • support communications;

  • service notifications;

  • maintenance notices;

  • abuse notices;

  • account notices;

  • policy changes;

  • contractual notices; and

  • legally required notices.

These transactional or service communications may be necessary to maintain your account and generally cannot be disabled while the relevant service remains active.

Marketing communications may be opted out of where applicable.


34. Do Not Track

Some browsers transmit “Do Not Track” signals.

Because there is no universally accepted standard governing all Do Not Track signals, Fusion Arc does not rely upon DNT as its primary privacy-control mechanism.

Instead, we provide or recognize applicable privacy controls such as:

  • cookie preferences;

  • advertising opt-outs;

  • Global Privacy Control;

  • Do Not Sell or Share controls; and

  • direct privacy requests.


35. Changes to This Privacy Policy

Fusion Arc may update this Privacy Policy as our:

  • services;

  • infrastructure;

  • vendors;

  • technology;

  • legal obligations;

  • business practices; or

  • privacy requirements

change.

The Privacy Policy will display its most recent update date.

Where a change is material, Fusion Arc may provide additional notice using methods such as:

  • email;

  • website notices;

  • Client Area notices;

  • banners; or

  • other appropriate communications.

Where applicable law requires affirmative consent before beginning a materially different processing activity, Fusion Arc will request that consent as required.


36. Service Providers and Technology May Change

The specific providers identified in this Privacy Policy reflect current or representative providers used by Fusion Arc.

Fusion Arc operates a changing technical environment and may add, remove, replace, or modify:

  • software vendors;

  • datacenter providers;

  • network providers;

  • AI providers;

  • payment providers;

  • analytics providers;

  • backup providers;

  • security providers; and

  • other service providers.

We will update this Policy where changes materially affect our privacy practices or where required by applicable law.

The identification of a vendor in this Privacy Policy does not necessarily mean that vendor receives Personal Information from every customer or receives every category of Personal Information.


37. Contact Us

Privacy Requests and Questions

Email:
privacy@fusionarchosting.com

You may also submit a Privacy Request through the Fusion Arc Hosting Client Area where available.

General Support

Email:
support@fusionarchosting.com

Mailing Address

Fusion Arc Hosting
A Fusion Arc Telecom LLC Company
PO Box 1766
Gypsum, CO 81637
United States