Skip to main content
Fugen Services logo

Legal

Privacy Policy

This policy explains what personal data we collect, why we collect it, how long we keep it and what you can ask us to do with it. It is written to be read rather than to cover us.

Last updated

Who we are

Fugen Services ("we", "us") is the data controller for personal data collected through this website. You can reach us at hello@fugenservices.co.uk or on +44 7488 265083.

What we collect, and why

We collect only what we need for a specific purpose.

Enquiry details. When you submit the contact form we collect your name, email address, and optionally your phone number, company, service interest and budget range, plus the message you write. We use this solely to respond to your enquiry and to manage the resulting conversation.

Technical data for abuse prevention. We store a one-way hashed form of your IP address and your browser's user-agent string alongside form submissions. The hash means we can recognise repeated abuse from the same source without retaining an identifier that points back to you.

Attribution data. We record which page a submission came from, the referring URL and any campaign parameters in the link you followed. This tells us which marketing works. It is not used to build a profile of you.

Analytics. We use privacy-respecting analytics to understand which pages are read and where people leave. We do not use this data to identify individuals.

Our lawful basis

For responding to your enquiry we rely on legitimate interests — you contacted us, and replying is the obvious expectation. Where we later send you marketing that is not a direct reply, we rely on consent, which you can withdraw at any time.

For abuse prevention and security logging we rely on legitimate interests in protecting the service.

How long we keep it

Data Retention
Enquiries that do not become projects 24 months from last contact
Client project records 7 years after the engagement ends, for tax and contractual reasons
Hashed IP and user-agent 12 months
Analytics 26 months

We delete on schedule rather than keeping things indefinitely "in case".

Who we share it with

We do not sell personal data and we do not share it for advertising.

We use a small number of processors to run the service — hosting, email delivery and analytics providers. Each is bound by a data processing agreement and may only act on our instructions. Where a processor operates outside the UK we rely on an approved transfer mechanism.

The AI assistant on this site

If you use the chat assistant, what you type is sent to Mistral AI, a company based in France, to generate a reply. Alongside your message we send only the relevant passages of our own public website content and the recent turns of that same conversation. We do not send your name, email address, phone number or IP address.

Mistral processes the request on our behalf under their API terms and does not use it to train their models on the tier we use.

Chat transcripts are stored so we can answer follow-up questions and see where the assistant gives poor answers. They are deleted automatically after 90 days by a scheduled job. Alongside each conversation we store a salted, one-way hash of your IP address and your browser's user-agent string, used only to detect abuse of the endpoint — the hash cannot be reversed to recover your IP address.

If you give the assistant your contact details, those are stored separately as an enquiry and kept for as long as we need them for the business relationship, exactly as with the contact form. Deleting a transcript does not delete an enquiry you deliberately submitted.

The assistant is a language model. It can be wrong, and it cannot make commitments on our behalf. Anything that matters — a price, a timescale, a scope — we confirm in writing.

We will disclose data where we are legally required to.

Where your data is held

Our infrastructure is hosted within the UK or the European Economic Area. Where a client requires UK-only residency for their own project data, we configure that specifically and document it.

Your rights

Under UK GDPR you can ask us to:

  • Tell you what we hold about you and provide a copy
  • Correct anything inaccurate
  • Delete your data, where we have no overriding obligation to keep it
  • Restrict or object to our processing
  • Port your data to another provider
  • Withdraw consent, where consent was the basis

Email us and we will respond within one month. There is no charge.

If you are not satisfied with how we handle your request you can complain to the Information Commissioner's Office at ico.org.uk.

Security

We encrypt data in transit and at rest, restrict access to those who need it, and log administrative access. No system is perfectly secure, and we would rather say that plainly than claim otherwise. If a breach affects your rights we will notify you and the ICO as required.

Children

This site is aimed at businesses. We do not knowingly collect data about anyone under 16.

Changes

We will update the date at the top of this page when this policy changes materially, and we keep the previous version available on request.