GDPR and CCPA
Regional privacy rights, our role as processor for customers, and the sub-processors we use. Written to sit alongside the privacy policy rather than repeat it.
Last updated
Controller or processor
Which set of obligations applies to Fulcrum depends on whose data is in question.
- Website visitors. We are the controller. We decided to collect it and why. The privacy policy covers it.
- Shoppers on a customer's store. The retailer is the controller; Fulcrum is a processor acting on their documented instructions. We do not use that data for our own purposes, we do not sell it, and we do not use it to train models that serve other customers.
For customers: the data processing agreement
Where we act as processor, our Data Processing Agreement forms part of the contract. It covers the subject matter and duration of processing, the categories of data subject, our confidentiality and security obligations, the conditions for engaging sub-processors, our assistance with data subject requests and breach notification, and deletion or return of data when the contract ends: the terms required by GDPR Article 28(3).
Request a copy, or send us an executed one, at privacy@fulcrumsaas.com .
Sub-processors
These providers may process personal data on our behalf. We give customers notice before adding one, with a chance to object.
| Sub-processor | Function | Location |
|---|---|---|
| Twilio SendGrid | Notification and transactional email. A website form submission is delivered to us as an email, and that email is the only record of it | United States |
| Cloudflare | Turnstile bot mitigation on web forms, active only where a site key is configured | United States and global network |
| Google Analytics 4 | Aggregate analytics for this website, loaded only where a visitor has accepted analytics cookies | United States |
That is the whole list for this website. It runs as a single Go server we operate, which renders every page and handles its own form submissions in the same process, so no third party sits between your browser and us for anything you send us. There is no advertising network and no data warehouse, and no analytics provider unless a visitor accepts analytics cookies.
Where a website enquiry actually lives
Worth stating before the rights sections, because it shapes every answer in them. A form submission is not written to a database. It is composed into an email and sent to a shared Fulcrum inbox, and that email is the only copy. So an access request is answered by searching that inbox, an erasure request is met by deleting the emails found there, and a portability request produces what those emails contain. There is no lead record to extract, correct in place, or export.
International transfers
Personal data reaching Fulcrum is processed in the United States. For data originating in the EEA, the UK or Switzerland we rely on the European Commission's Standard Contractual Clauses (2021/914) and, for UK data, the ICO's International Data Transfer Addendum. We carry out a transfer impact assessment before onboarding a sub-processor that will receive such data.
Your rights under GDPR and UK GDPR
If you are in the UK, EEA or Switzerland, you have the right to:
- be told what we hold about you and get a copy of it (Art. 15);
- have inaccurate data corrected (Art. 16);
- have data erased where we no longer have grounds to keep it (Art. 17);
- restrict processing while a dispute is resolved (Art. 18);
- receive your data in a portable, machine-readable format (Art. 20);
- object to processing based on our legitimate interests (Art. 21);
- withdraw consent at any time, without affecting prior processing (Art. 7(3));
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Art. 22).
We do not make automated decisions of that kind about website visitors. Product recommendations shown to shoppers are ranking decisions made for a retailer, and they do not carry legal or similarly significant effects.
If we act as processor rather than controller, we will forward your request to the relevant retailer and assist them in answering it.
Complaints
You can complain to your local supervisory authority. In the UK that is the Information Commissioner's Office; in the EEA it is the authority for the country where you live or work. We would rather hear from you first, but nothing here requires you to come to us before going to a regulator.
Your rights in California (CCPA/CPRA)
California residents have the right to:
- know what categories of personal information we collect, why, and who we disclose it to;
- request a copy of the specific pieces we hold;
- request deletion, subject to the exceptions in the statute;
- request correction of inaccurate information;
- opt out of sale or sharing for cross-context behavioural advertising;
- limit the use of sensitive personal information;
- not be discriminated against for exercising any of these.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months, including for anyone under 16. We collect no sensitive personal information through this website, so there is nothing to limit.
Categories collected in the last 12 months, using the statute's own vocabulary: identifiers (name, work email, company, hashed IP); commercial information (the platform and traffic band you tell us about); and internet activity (the page you submitted from, the site that referred you, and any campaign parameters in the URL when you first arrived). Each is collected for the purposes set out in the privacy policy and retained on the schedule there.
Your rights in Colorado (CPA)
Fulcrum SaaS Inc. is registered in Denver. Colorado residents have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and certain profiling. We honour a Global Privacy Control signal as a valid universal opt-out mechanism. You may appeal a refused request by replying to our decision; we will respond to an appeal within 45 days and tell you how to contact the Colorado Attorney General if you remain unsatisfied.
Making a request
Email privacy@fulcrumsaas.com with what you want and enough detail to find your records. We acknowledge within 10 business days and respond within 30 days for GDPR requests and 45 days for US state requests, extendable once where the request is complex. We will tell you if that happens and why.
An authorised agent may act for you if you give them written permission; we may still contact you to confirm.
Breach notification
Where we are the controller and a breach is likely to result in a risk to your rights, we notify the relevant supervisory authority within 72 hours of becoming aware, and notify you directly where the risk is high. Where we are a processor, we notify the affected customer without undue delay so they can meet their own obligations.