Privacy Policy
Fuze processes two categories of personal data: the photographer's data (the app user) and their end clients' data (through the synced calendar). This policy explains precisely how, why and for how long.
1. Data controller
The Fuze service is published by TexturingXYZ SARL, 71 rue Ampère, 31670 Labège, France — SIRET 819 447 558 00027, Toulouse Trade and Companies Register 819 447 558, VAT FR03819447558. Fuze ("we") operates the service available at fuze.photo. For any question about your personal data: privacy@fuze.photo.
Last updated: 2026-08-03.
2. Two distinct roles
For your photographer data (account, preferences, catalogue, brand), we act as data controller.
For your end clients' data synced from your calendar (events, contacts, notes), you are the data controller and we act as a processor within the meaning of Article 28 GDPR. A DPA (Data Processing Agreement) is embedded in our Terms.
3. Data collected and purposes
- Account & identity — email, name, avatar. Purpose: authentication, service communication. Legal basis: performance of the contract (Art. 6.1.b).
- Studio & catalogue — studio name, city, offers, prices, constraints. Purpose: personalise Studio Brain recommendations. Basis: contract.
- Synced calendar — events (title, dates, duration, description, guests). Purpose: shoot detection, workload calculation, opportunities. Basis: contract + legitimate interest for business analysis.
- Derived metrics — shoot statistics, utilisation rate, estimated revenue. Purpose: opportunity engine and AI action plans.
- Usage & logs — in-app actions, AI calls, costs. Purpose: security, billing, improvement. Basis: legitimate interest.
- Cookies — see section 8.
- Marketing emails — sent only with explicit consent (opt-in). Basis: consent (Art. 6.1.a).
4. Artificial intelligence processing
The Studio Brain engine sends a compact summary of your studio context (offers, constraints, aggregated metrics) to third-party language models. That summary is structured to avoid transmitting the names, emails or phone numbers of your end clients.
Briefs, action plans and storyboards are AI-generated. You remain the final decision-maker: no fully automated decision is taken about your clients (Art. 22 GDPR).
Our AI processors are listed at /legal/subprocessors.
5. Recipients & processors
Your data is never sold. Recipients are exclusively our technical processors, bound by contracts compliant with Article 28 GDPR and, where applicable, Standard Contractual Clauses (SCC) for transfers outside the EU.
Full and up-to-date list: /legal/subprocessors.
See also section 13 "Google API Services" for the limited use of data obtained from Google APIs.
6. Transfers outside the European Union
Some processors operate outside the EU. Those transfers are governed by Standard Contractual Clauses adopted by the European Commission and by the technical and organisational security measures described in section 9.
7. Retention periods
- Account: duration of the contractual relationship + 3 years (commercial limitation period).
- Raw synced calendar: rolling 36 months, automatic purge beyond.
- Derived metrics & AI learning: duration of the relationship.
- Technical logs: rolling 12 months.
- Administrative audit logs: 3 years (legal traceability obligation).
- Cookie consents: 13 months maximum.
8. Cookies and trackers
We use three categories of cookies:
- Essential (always on): authentication session, security, language preference.
- Analytics (opt-in): anonymised audience measurement to improve the app.
- Marketing (opt-in): conversion tracking, disabled by default.
You can change your choice at any time via the banner or by deleting the amb_consent_v1 cookie.
9. Security (Art. 32 GDPR)
- Encryption in transit (TLS 1.3) and at rest.
- Calendar access tokens encrypted in the database with a dedicated key.
- Postgres Row-Level Security on all sensitive tables.
- Leaked-password checks at sign-up.
- Logging of administrator access.
- Verified daily backups.
10. Your GDPR rights
You have the following rights at any time:
- Access and portability — export your data as JSON from Settings → Account.
- Rectification — through the Settings, Studio, Brand and Channels pages.
- Erasure — "Delete my account" button in Settings.
- Restriction / objection — "Pause AI processing" button.
- Complaint — with your supervisory authority, e.g. the CNIL (cnil.fr).
Response time: 30 days maximum. Contact: privacy@fuze.photo.
11. Data breach
In the event of a breach likely to create a risk to your rights and freedoms, we will notify the competent authority within 72 hours and inform you directly without delay if the risk is high (Art. 33 & 34 GDPR).
12. Changes
Any substantial change to this policy will be notified to you by email and via an in-app banner at least 15 days before it takes effect.
13. Google API Services — Limited Use
Fuze's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
13.1 Google services used and scopes
- Google Calendar API — scope
calendar.readonly(read-only). Purpose: detect your shoots, compute your workload and available slots. Fuze never creates, modifies or deletes an event. - Google Analytics Data API (GA4) — scope
analytics.readonly(read-only). Purpose: retrieve aggregated metrics from your own GA4 property (sessions, conversions, traffic sources) to measure campaign performance. No identifiable end-user data is read. - Google Maps / Places / Geocoding API — server key, no Google account data. Purpose: geocode your studio address and identify public competitor studios within a radius you define.
- Google Sign-In (OAuth 2.0 / OpenID Connect) — scopes
openid,email,profile. Purpose: create and authenticate your account.
13.2 Limited Use commitments
- Google data is used only to provide and improve features that are visible to you inside Fuze.
- It is never sold, never transferred to data brokers, and never used for advertising, targeting or resale purposes.
- It is not used to train generalised artificial-intelligence models. Calls to language models are made with training opt-out enabled (see section 4).
- No human reads your Google data, except: (a) with your explicit consent, (b) for security reasons (investigating abuse or an incident), (c) to comply with a legal obligation, or (d) after aggregation and anonymisation for internal statistics.
- Sharing with our technical processors is limited to what is strictly necessary to operate the service (see /legal/subprocessors).
13.3 Retention and revocation
- Google OAuth tokens are encrypted at rest and used server-side only.
- You can revoke access at any time from Settings → Integrations, or from myaccount.google.com/permissions.
- Upon revocation, tokens are destroyed immediately and imported calendar data is deleted within 30 days.
- Synced calendar events are kept for a maximum of a rolling 36 months (see section 7).
13.4 Google Maps
Use of mapping features is also subject to the Google Maps Platform Terms of Service and the Google Privacy Policy.