Privacy Policy and Personal Data Protection Notice
Version in force as of: August 2026 — Document No. 1 since establishment
This privacy policy and personal data protection notice (hereinafter the "Policy") is intended to inform, in an exhaustive manner consistent with the transparency requirements set out in Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (hereinafter the "GDPR" or the "Regulation"), every natural person concerned by the data processing operations carried out in connection with the website available at fastsolve.eu, the conversational assistant known as "FastSolve IA", and the client relationship management platform available at espace.fastsolve.eu (hereinafter collectively the "Services"), published and operated by FastSolve (hereinafter "FastSolve", the "Data Controller", "we", "us" or "our").
This Policy is further established in accordance with applicable complementary provisions of national law, depending on the data subject's country of residence, including in particular: the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data; the French Act No. 78-17 of 6 January 1978 on Information Technology, Data Files and Civil Liberties, as amended by Act No. 2018-493 of 20 June 2018; and, more broadly, the principles enshrined in Council of Europe Convention 108+ for the protection of individuals with regard to the processing of personal data.
Any person consulting the Services, using them, creating an account, or transmitting personal data of any kind through them, is deemed to have read this Policy, which is binding on them under the conditions and limits described below. This Policy does not, by itself, create any contractual obligation distinct from those arising, where applicable, from a service agreement separately concluded between FastSolve and its client.
Table of Contents
- Title I — General Provisions, Definitions and Guiding Principles
- Title II — Exhaustive Description of the Processing Operations Carried Out
- Title III — Legal Bases, Retention Periods and Summary Record
- Title IV — Recipients, Processors and Transfers Outside the European Union
- Title V — Data Security, Breach Management and Incident Notification
- Title VI — Rights of Data Subjects and Procedures for Exercising Them
- Title VII — Automated Individual Decision-Making and Profiling
- Title VIII — Miscellaneous and Final Provisions
- Annex I — Glossary of GDPR Concepts
- Annex II — List of Processors and Recipients
- Annex III — Normative References
Title I — General Provisions, Definitions and Guiding Principles
Article 1 — Purpose and Scope
This Policy sets out the manner in which FastSolve collects, processes, retains, transmits and, where applicable, transfers the personal data of natural persons interacting with the Services, whether as mere visitors, prospects who have submitted an enquiry, users of the conversational assistant, or clients holding an account on the client portal. It does not apply to any third-party site, application or service to which the Services may link, FastSolve being unable to be held liable for third parties' data protection practices.
Article 2 — Identification of the Data Controller
Within the meaning of Article 4(7) of the GDPR, the controller of the data described in this Policy is the operator of FastSolve, an independent professional activity, reachable exclusively by electronic means at contact@fastsolve.eu. As the thresholds and criteria set out in Article 37 of the GDPR are not met (large-scale processing of special categories of data, regular and systematic large-scale monitoring of data subjects, or processing carried out by a public authority), FastSolve is not required to appoint a Data Protection Officer ("DPO"); in the absence of such an officer, all requests and complaints relating to this Policy are handled directly at the above email address.
Article 3 — General Definitions
Unless expressly stated otherwise, capitalised terms used in this Policy have the meaning given to them in Article 4 of the GDPR, summarised on a non-exhaustive basis in Annex I below. In the event of any discrepancy between this Policy and the text of the GDPR, the latter prevails.
Article 4 — Guiding Principles Applicable to All Processing Operations
In accordance with Article 5 of the GDPR, all processing operations described in this Policy are carried out in cumulative compliance with the following principles:
- Lawfulness, fairness and transparency (Article 5(1)(a)): every processing operation rests on an identified legal basis (Title III) and is subject to prior, clear and accessible information, such as this Policy.
- Purpose limitation (Article 5(1)(b)): data is collected for specified, explicit and legitimate purposes and is not further processed in a manner incompatible with those purposes.
- Data minimisation (Article 5(1)(c)): only data that is adequate, relevant and limited to what is necessary for the purposes pursued is collected.
- Accuracy (Article 5(1)(d)): reasonable steps are taken to ensure that inaccurate data, having regard to the purposes for which it is processed, is erased or rectified without delay.
- Storage limitation (Article 5(1)(e)): data is kept in a form permitting identification of data subjects for no longer than is necessary for the purposes for which it is processed (Title III).
- Integrity and confidentiality (Article 5(1)(f)): data is processed in a manner ensuring appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage (Title V).
- Accountability (Article 5(2)): FastSolve is able to demonstrate compliance with the foregoing principles and maintains internal documentation of its processing activities to that end.
It is expressly stated that no data collected in connection with the Services is, at any time, sold, rented, exchanged or monetised to a third party for commercial, advertising or statistical purposes unrelated to the purposes described in this Policy.
Title II — Exhaustive Description of the Processing Operations Carried Out
This Title describes, processing operation by processing operation, the nature of the data concerned, its origin, the manner in which it is processed, and the persons or entities that may have access to it. Each processing operation is linked, in Title III, to a specific legal basis and its own retention period.
Article 5 — Processing No. 1: Contact Form and Quote Requests
When a natural person completes the contact form available on fastsolve.eu, the following data is collected: their name, the name of the company or organisation they represent, where applicable, their email address, the nature of the need expressed, an indicative budget, and the literal content of the message drafted. In addition to this declarative data, and for the technical security purposes described in Article 9, the connecting IP address and a timestamp are also recorded. This data is transmitted exclusively, by email, to the FastSolve team, for the sole purpose of analysing and processing the enquiry made.
Article 6 — Processing No. 2: "FastSolve IA" Conversational Assistant
The conversational assistant integrated into the Services is designed to guide the natural person interacting with it towards the most relevant service offering in light of the need expressed, and, where applicable, to prepare a message putting them in contact with the FastSolve team. To this end, the full textual content of each message entered by the data subject is transmitted, in real time and via application programming interface ("API"), to Anthropic PBC, a company incorporated under the laws of the State of Delaware (United States of America), which provides FastSolve, acting as processor within the meaning of Article 28 of the GDPR, with a generative language model (named "Claude") that produces the reply subsequently displayed to the data subject. The data subject is expressly informed that any personal information they choose, on their own initiative, to mention within their text input will necessarily be included in the data thus transmitted. FastSolve does not persistently retain, on its own servers, the content of exchanges with the conversational assistant, such content existing only in the volatile memory of the data subject's browser for the duration of the session, subject to the case described in the following article.
Article 7 — Processing No. 3: Voluntary Transmission of a Conversation Summary
Where the data subject activates, on their own initiative, a feature to transmit the content or a summary of their conversation with the assistant (in particular via the so-called "copy" or "pre-fill the contact form" features), the data thus transmitted is processed under the same terms, for the same purpose and under the same regime as that described in Article 5 relating to the contact form.
Article 8 — Processing No. 4: Account Creation, Authentication and Session Management on the Client Portal
The creation of an account on the client portal takes place at FastSolve's initiative, following the validation of a project by the data subject. The following is then processed: the company name or designation of the entity represented, the data subject's email address, and a password of which only an irreversible cryptographic fingerprint ("hash"), not the plain-text value, is retained in FastSolve's systems, such that no FastSolve staff member, nor any third party, is able to view that password. At each login, a unique session identifier is generated and associated with the data subject's account; where the "remember me" feature is activated, an additional identifier with an extended validity period is generated and retained through secure technical means, for the sole purpose of avoiding the need to re-enter credentials on subsequent logins.
Article 9 — Processing No. 5: Security, Logging and Prevention of Abusive Use
For the sole purpose of preserving the integrity and availability of the Services as well as the security of its clients' accounts, FastSolve implements automated rate-limiting mechanisms associated with the IP address at the origin of the request, in particular in respect of login attempts to the client portal, contact form submissions, and requests made to the conversational assistant. Login attempts, whether successful or not, are logged technically, including the IP address, timestamp and outcome of the attempt, solely to detect fraudulent, automated or malicious behaviour (brute-force attacks, intrusion attempts, harassment of the Service). This technical data is not used for any other purpose, in particular commercial or statistical.
Article 10 — Processing No. 6: Project Management, File Upload and Access
In the course of carrying out a project, FastSolve may receive, store and make available to the data subject, via their client portal account, files, links or textual content relating to that project, as well as receive, where applicable, documents that the data subject chooses to upload themselves. These items are stored in storage space strictly partitioned and associated with the data subject's account, not accessible to FastSolve's other clients, and not indexed by search engines. Functional previews of a project may, for the purpose of protection against unauthorised disclosure prior to final validation and payment, include a visible technical watermark.
Article 11 — Processing No. 7: Invoicing and Accounting and Tax Obligations
Prior to issuing an invoice, FastSolve collects from the data subject or the entity they represent the following information: company name, postal address, VAT identification number where applicable, and billing email address. Once incorporated into an issued invoice, this information is not subsequently modified, in accordance with the integrity and immutability requirements applicable to accounting documents, and is retained for the period prescribed by applicable legal, tax and accounting obligations, independently of the fate of the other data in the data subject's account (Title III).
Article 12 — Processing No. 8: Cookies and Trackers
FastSolve does not use any audience-measurement cookie, advertising-profiling cookie, behavioural-targeting cookie, nor any script or resource loaded from a third-party domain: the Services establish no network connection, from the data subject's browser, to any domain other than fastsolve.eu or espace.fastsolve.eu, as evidenced by the Content Security Policy technically implemented across the Services. Only strictly necessary cookies within the meaning of Article 5(3) of Directive 2002/58/EC (the "ePrivacy Directive"), as transposed into national law and interpreted by the guidelines of the French data protection authority (CNIL) and the Belgian Data Protection Authority (APD), are deposited: a technical anti-abuse cookie on the contact form, and, on the client portal exclusively, a session cookie and, where applicable, an extended-login cookie, both indispensable to the operation of authentication and to the partitioning of accounts. Pursuant to the foregoing texts, these strictly necessary cookies are exempt from prior consent.
Title III — Legal Bases, Retention Periods and Summary Record
Article 13 — Legal Bases of the Processing Operations
In accordance with Article 6(1) of the GDPR, each processing operation described in Title II rests on one of the following legal bases, to the exclusion of any other:
- Article 6(1)(b) — performance of pre-contractual steps taken at the data subject's request, or performance of a contract: Processing No. 1 (contact form), Nos. 2 and 3 (conversational assistant and voluntary transmission), No. 4 (account and authentication), No. 6 (project management) and No. 7 (invoicing, as regards its contractual component).
- Article 6(1)(c) — compliance with a legal obligation to which FastSolve is subject: Processing No. 7, specifically as regards the retention of invoices and accounting records for the applicable statutory period.
- Article 6(1)(f) — legitimate interests pursued by the controller: Processing No. 5 (security and prevention of abusive use), FastSolve's legitimate interest in preserving the integrity, availability and security of its Services, as well as in protecting its clients' accounts against unauthorised access, having been weighed against the fundamental rights and freedoms of data subjects, this balancing exercise showing a minimal impact on such rights given the strictly limited nature and duration of the data thus processed.
It is expressly stated that none of the processing operations described in this Policy rests on consent within the meaning of Article 6(1)(a) and Article 7 of the GDPR: the cookies implemented falling within the exemption applicable to strictly necessary cookies (Article 12), and all other processing operations arising, by construction, from a voluntary and unambiguous step taken by the data subject constituting, at the very least, a pre-contractual measure within the meaning of Article 6(1)(b).
Article 14 — Retention Periods
In accordance with the storage limitation principle (Article 4), the data collected is retained only for the period strictly necessary to achieve the purposes pursued, as detailed below:
- Contact enquiries not followed by the conclusion of a project: retained for the period necessary for their processing, and for a maximum of three (3) years from the last exchange with the data subject, after which such data is deleted or anonymised.
- Active client accounts and associated data (excluding invoicing): retained for the duration of the business relationship, then deleted or archived within a reasonable period following the end of that relationship.
- Invoices and accounting records: retained for the statutory retention period applicable to accounting and tax documents in the relevant jurisdiction, generally between seven (7) and ten (10) years, in accordance with the legal obligation referred to in Article 13.
- Technical security logs (login attempts, rate limiting): retained for a period strictly limited to what is necessary to detect and address abusive use, generally on the order of several weeks to a few months at most.
- Content of exchanges with the conversational assistant: not persistently retained by FastSolve beyond the browsing session, subject only to the voluntary transmission referred to in Article 7.
Title IV — Recipients, Processors and Transfers Outside the European Union
Article 15 — Internal Recipients
Only authorised members of the FastSolve team, to the strict extent necessary for the performance of their duties, have access to the data described in this Policy.
Article 16 — Processors
In accordance with Article 28 of the GDPR, FastSolve engages the processors listed in Annex II, with whom a contract or contractual terms governing the processing of personal data have been entered into or are deemed applicable. No processor is authorised to process the data received for any purpose other than that strictly defined by FastSolve's instructions.
Article 17 — Transfers of Data Outside the European Economic Area
As follows from Article 6 and Annex II, the use of Anthropic PBC, a company established in the United States of America, to provide the language model underlying the conversational assistant, entails a transfer of personal data outside the European Economic Area within the meaning of Chapter V of the GDPR (Articles 44 to 50). This transfer is governed by the standard contractual clauses adopted by the European Commission by Implementing Decision (EU) 2021/914 of 4 June 2021, in accordance with Article 46(2)(c) of the GDPR, as well as, where applicable, by the additional safeguards and measures implemented by that processor in accordance with its own contractual documentation. No other processing operation described in this Policy involves a transfer of data outside the European Union.
Title V — Data Security, Breach Management and Incident Notification
Article 18 — Technical and Organisational Security Measures
In accordance with Article 32 of the GDPR, FastSolve implements the following technical and organisational measures, appropriate to the nature, scope, context and purposes of the processing as well as the risks to data subjects: systematic encryption of communications between the data subject's browser and FastSolve's servers by means of the HTTPS/TLS protocol; storage of passwords exclusively in hashed form using recognised cryptographic algorithms; strict logical partitioning of a client's data and files from those of other clients; automated limitation of the number of login attempts; hosting of all data on infrastructure itself secured by its hosting provider (Annex II).
Article 19 — Notification of Personal Data Breaches
In the event of a personal data breach, within the meaning of Article 4(12) of the GDPR, likely to result in a risk to the rights and freedoms of the natural persons concerned, FastSolve undertakes to notify the competent supervisory authority as soon as possible and, where feasible, no later than forty-eight (48) hours after becoming aware of it, in accordance with Article 33 of the GDPR, and to communicate the breach to the data subjects concerned where it is likely to result in a high risk to their rights and freedoms, in accordance with Article 34 of the GDPR.
Title VI — Rights of Data Subjects and Procedures for Exercising Them
Article 20 — Right of Access
In accordance with Article 15 of the GDPR, every data subject has the right to obtain from FastSolve confirmation as to whether or not personal data concerning them is being processed and, where that is the case, access to that data as well as to information relating to the purposes of the processing, the categories of data concerned, the recipients, the envisaged retention period, and the source of the data where it was not collected directly from them.
Article 21 — Right to Rectification
In accordance with Article 16 of the GDPR, every data subject has the right to obtain, without undue delay, the rectification of inaccurate personal data concerning them, as well as to have incomplete data completed.
Article 22 — Right to Erasure ("Right to be Forgotten")
In accordance with Article 17 of the GDPR, every data subject has the right to obtain, without undue delay, the erasure of personal data concerning them, in the cases provided for by that article, in particular where such data is no longer necessary in relation to the purposes for which it was collected. This right is exercised subject to applicable statutory retention obligations, in particular accounting and tax obligations (Article 14), which, to that extent only, preclude early erasure of the data concerned.
Article 23 — Right to Restriction of Processing
In accordance with Article 18 of the GDPR, every data subject may obtain restriction of the processing of their data, in particular where they contest its accuracy, for the period enabling FastSolve to carry out the necessary verifications, or where the processing is unlawful and the data subject opposes erasure in favour of restriction of its use.
Article 24 — Right to Data Portability
In accordance with Article 20 of the GDPR, every data subject has the right to receive the personal data they have provided to FastSolve in a structured, commonly used and machine-readable format, and has the right to transmit that data to another controller without hindrance from FastSolve, to the extent that the processing concerned rests on consent or on the performance of a contract and is carried out by automated means.
Article 25 — Right to Object
In accordance with Article 21 of the GDPR, every data subject may object, on grounds relating to their particular situation, to processing of their data resting on FastSolve's legitimate interest (Article 13), in which case FastSolve will no longer pursue that processing, unless it demonstrates compelling legitimate grounds overriding the interests, rights and freedoms of the data subject, or that the processing is necessary for the establishment, exercise or defence of legal claims.
Article 26 — Right to Withdraw Consent and Post-Mortem Directives
Where, exceptionally, a processing operation were to rest on the data subject's consent, the data subject would have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent given before its withdrawal. The data subject further has the right to define, under the conditions provided for by the law of their country of residence, directives concerning the retention, erasure and communication of their data after their death.
Article 27 — Procedures for Exercising Rights
All of the above-mentioned rights may be exercised by simple email to contact@fastsolve.eu, specifying the subject of the request. In accordance with Article 12 of the GDPR, FastSolve undertakes to respond to any request within one (1) month of its receipt, this period being extendable by a further two (2) months in light of the complexity and number of requests, the data subject being informed of any such extension and its reasons within the initial one-month period. FastSolve reserves the right to request, under the conditions provided for in Article 12(6) of the GDPR, any reasonable evidence of the identity of the person making the request, where there is reasonable doubt as to that identity.
Title VII — Automated Individual Decision-Making and Profiling
Article 28 — Absence of Fully Automated Decision-Making
In accordance with Article 22 of the GDPR, none of the processing operations described in this Policy, including those involving the use of the "FastSolve IA" conversational assistant (Article 6), gives rise to a decision based solely on automated processing, including profiling, which produces legal effects concerning the data subject or similarly significantly affects them. The conversational assistant merely guides the data subject towards the most relevant service offering in light of the information they themselves have provided, and prepares, where applicable, a message for the attention of the FastSolve team; it does not, under any circumstances, conclude, validate or invoice any contractual commitment on behalf of the data subject, human intervention being systematically required to that end.
Title VIII — Miscellaneous and Final Provisions
Article 29 — Minors
The Services, being exclusively professional in purpose, are not intended for minors. FastSolve does not knowingly collect data concerning minors and invites any legal representative aware of such collection to report it without delay to the address referred to in Article 27, for the purpose of deleting such data.
Article 30 — Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to any other administrative or judicial remedy, any data subject who considers, after having contacted FastSolve under the conditions set out in Article 27, that the processing of their data does not comply with the provisions of the GDPR, has the right to lodge a complaint with the supervisory authority competent for their habitual place of residence, place of work, or the place of the alleged infringement, in accordance with Article 77 of the GDPR, and in particular:
- in Belgium, with the Data Protection Authority (APD/GBA) — www.autoriteprotectiondonnees.be;
- in France, with the Commission nationale de l'informatique et des libertés (CNIL) — www.cnil.fr;
- or, for any other jurisdiction, with the competent national data protection supervisory authority.
Article 31 — Absence of a Data Protection Impact Assessment
Given the nature, scope, context and purposes of the processing operations described in this Policy, and the absence of large-scale processing of special categories of data within the meaning of Article 9 of the GDPR, large-scale systematic monitoring, or innovative use of new technologies presenting a high risk to the rights and freedoms of natural persons, FastSolve considers that none of these processing operations requires a Data Protection Impact Assessment ("DPIA") within the meaning of Article 35 of the GDPR. This assessment is reviewed in the event of a substantial change to the processing operations carried out.
Article 32 — Amendment of this Policy
FastSolve reserves the right to amend this Policy at any time, in particular to reflect developments in the Services, the tools and processors used, or the applicable regulatory framework. The version in force is that published at fastsolve.eu/en/privacy/, the date of last update appearing at the top of this document. Any substantial amendment will be brought to attention through a visible notice on the Services.
Article 33 — Governing Law
This Policy is governed by the GDPR and, on a complementary basis, by the law applicable in the data subject's habitual place of residence, without prejudice to any applicable mandatory provisions of public policy.
Article 34 — Contact
For any question relating to this Policy, to the protection of their personal data, or to the exercise of their rights, any data subject may, at any time, contact FastSolve at the following email address: contact@fastsolve.eu.
Annex I — Glossary of GDPR Concepts
- Personal data (Article 4(1)): any information relating to an identified or identifiable natural person, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.
- Processing (Article 4(2)): any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, restriction, erasure or destruction.
- Restriction of processing (Article 4(3)): the marking of stored personal data with the aim of limiting its processing in the future.
- Profiling (Article 4(4)): any form of automated processing of personal data consisting of using that data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning their performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
- Pseudonymisation (Article 4(5)): the processing of personal data in such a way that it can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and subject to technical and organisational measures.
- Controller (Article 4(7)): the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing.
- Processor (Article 4(8)): the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
- Recipient (Article 4(9)): the natural or legal person, public authority, agency or other body to which personal data is disclosed, whether a third party or not.
- Consent (Article 4(11)): any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
- Personal data breach (Article 4(12)): a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
Annex II — List of Processors and Recipients
- Hostinger — hosting of the fastsolve.eu website, the espace.fastsolve.eu platform, the associated database, and delivery of emails via its outbound mail (SMTP) service. Data location: European Union.
- Anthropic PBC — provision, via application programming interface, of the generative language model used by the "FastSolve IA" conversational assistant (Article 6). Location: United States of America. Safeguards applicable to the transfer: European Commission standard contractual clauses (Article 17).
This list is subject to change; the up-to-date version is the one published on this page.
Annex III — Normative References
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR).
- Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (the "ePrivacy Directive").
- Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.
- French Act No. 78-17 of 6 January 1978 on Information Technology, Data Files and Civil Liberties, as amended.
- Council of Europe Convention 108+ for the protection of individuals with regard to the processing of personal data.
- European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries.