Who this notice is about
FusionAura Studio is the public trading and brand name used by this website. It is not a registered or incorporated company. This website does not state a registered company name, company number or registered office, and no such status should be inferred.
The intended website is https://fusionaurastudio.com. Privacy and business questions can be sent to FusionAura Studio at hello@fusionaurastudio.com.
This notice is a conservative international baseline based on the current website. It is not legal advice or a promise that the same privacy law or right applies in every country.
Information the website handles
A project inquiry collects a name, email address, selected service and project details. A company name is optional. The current form does not request a budget, attachment, payment information or marketing consent.
A privacy request collects an email address, request type, and optional name and concise details. A verification link confirms control of the supplied email address; higher-risk access, correction or deletion work still requires proportionate manual identity and scope review.
Admin accounts contain account and security information needed to protect private administration. Verified testimonials may contain a quote and only the identity, company, role or project fields for which publication, verification and permission have been recorded. Published Blog attribution is processed only when an approved article is published.
The application, web server and security controls may process technical information such as IP address, request path, user agent, request timing, session identifiers, security events and application errors. Keyed hashes are used for rate limiting and duplicate-submission control where implemented.
Why information is used
Inquiry information is used to respond to the enquiry, understand the requested project or service, take steps requested before a possible contract where applicable, maintain reasonable business and security records, and prevent abuse. Submitting an inquiry is not marketing consent and does not itself create a contract.
Other information is used to operate and secure the website, administer content, deliver transactional messages, verify and handle privacy requests, preserve proportionate security or audit records, maintain backups, and publish approved testimonials or article attribution where applicable.
With a visitor’s analytics choice set to Accept, the public website uses Google Analytics 4 to understand page use, important project or contact actions and successful inquiry submissions. It does not send Contact-form fields to Analytics. Analytics stays off before a choice and after rejection or withdrawal.
The application does not operate advertising pixels, remarketing, behavioural advertising, session replay, a newsletter, public accounts, online checkout or autonomous AI publishing.
Legal basis and applicability
The legal basis depends on the law that applies to the operator, the visitor and the particular processing. For UK or EU/EEA-facing processing, handling an inquiry may involve steps requested before entering a contract; proportionate security, administration and business-record processing may rely on legitimate interests where those interests are properly assessed; and some records may be required by law. Consent is used only where it is actually requested and can be withdrawn.
No single basis is asserted for every person or jurisdiction. Applicable bases, controller disclosures and any local notice requirements depend on the operator’s legal status, establishment, target customers and the processing involved.
Recipients and service providers
The intended hosting plan is Hostinger Premium Web Hosting. Hostinger documents web hosting, MariaDB, weekly provider backups, SSH/SFTP and related platform functions, but the actual account region, processing locations, contract, subprocessors, security settings and production runtime have not yet been verified.
Transactional email will use hello@fusionaurastudio.com as the intended public sender and reply identity only after the mailbox, delivery provider, TLS, sender authentication, failure visibility and production configuration pass testing. No production monitoring provider or AI processor receiving inquiry or privacy data is currently approved.
Google LLC provides the optional Google Analytics 4 service after analytics consent. Google may receive the requested page path, browser/device and technical request information, and approved event labels. Google Signals and advertising-personalisation signals are disabled in the site configuration. The Analytics property settings, contract terms, processing region, retention and deletion controls still require owner verification and legal review.
Information is shared only with service providers or advisers needed for the relevant operation, subject to verified access, security and contractual arrangements. Provider identities and international-transfer safeguards will be updated after the real production services and locations are confirmed.
International processing
Website and email services may process information outside a visitor’s country. No specific data-residency, adequacy, transfer-contract or certification claim is made until the production provider accounts, regions, subprocessors and agreements are verified.
How long information is kept
The proposed operational defaults are: unsuccessful or general inquiries for 12 months after the last meaningful interaction; obvious spam or abuse submissions for 90 days; closed privacy-request case records for 24 months; routine application and security logs for 90 days; resolved failed queue jobs for 30 days; and internal Admin or security audit records for 24 months. These are operational proposals, not statutory periods, and no destructive automation for them is active.
Withdrawal of testimonial permission suppresses public display immediately. Successful client, project, contract, tax and accounting records are not automatically deleted; their periods require review after the operator identity, establishment, contracts and applicable obligations are confirmed.
A proposed 30-day rolling operational-backup baseline remains subject to actual Hostinger capability and owner RPO/RTO approval. Provider backups may retain earlier information until they expire. After a restore, recorded deletion, anonymisation or withdrawal decisions should be reapplied where practical.
Security
The application uses restricted Admin access, mandatory two-factor authentication, encrypted sensitive database fields, CSRF protection, validation, rate limiting, database-backed sessions, audit logging and identifier-only queue jobs. Production requires a private application root, HTTPS and proxy verification, reliable queue processing, tested mail, protected writable storage, monitoring and backup restoration. No system can be guaranteed completely secure.
Cookies and storage technologies
The website uses first-party session and CSRF technologies needed for security, forms and authenticated Admin continuity. It also stores a first-party analytics preference for 180 days so an Accept or Reject choice can be respected.
Google Analytics 4 and its first-party analytics cookies remain completely unloaded until Accept is selected. Reject, withdrawal and an enabled Global Privacy Control signal keep Analytics blocked. Cookie settings in the footer allow the choice to be reviewed or changed, and withdrawal removes accessible Google Analytics cookies where technically possible.
Privacy rights and requests
Depending on the law that applies to you and to our processing, you may have rights relating to access, correction, deletion, restriction, objection, portability or withdrawal of consent.
Requests are assessed individually and may require proportionate identity verification. A public submission never automatically confirms that information is held, discloses personal information, or deletes a record.
Sale, sharing and behavioural advertising
Based on the current audited application, FusionAura Studio does not operate a system for selling personal information, cross-context behavioural advertising, advertising pixels or remarketing. Google Signals, ad storage, ad user data and ad personalisation are denied by the website’s Analytics configuration. This describes current behavior, not a permanent guarantee. The notice and consent assessment must be reviewed before those practices or tools change.
Contact and complaints
Email FusionAura Studio at hello@fusionaurastudio.com or use the privacy-request form for a privacy question.
The appropriate regulator or complaint route depends on the operator’s establishment, the visitor’s location and the law that applies. No universal regulator is named before those facts are established.
Changes to this notice
Each notice version has an effective date and change summary. Earlier published versions remain in the internal version history. This notice will be reviewed when processing practices, providers, technologies, services or applicable legal facts change.