Privacy Policy and Personal Data Protection Notice

This privacy policy and personal data protection notice (hereinafter the "Policy") is intended to inform, in an exhaustive manner consistent with the transparency requirements set out in Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (hereinafter the "GDPR" or the "Regulation"), every natural person concerned by the data processing operations carried out in connection with the website available at fastsolve.eu, the conversational assistant known as "FastSolve IA", and the client relationship management platform available at espace.fastsolve.eu (hereinafter collectively the "Services"), published and operated by FastSolve (hereinafter "FastSolve", the "Data Controller", "we", "us" or "our").

This Policy is further established in accordance with applicable complementary provisions of national law, depending on the data subject's country of residence, including in particular: the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data; the French Act No. 78-17 of 6 January 1978 on Information Technology, Data Files and Civil Liberties, as amended by Act No. 2018-493 of 20 June 2018; and, more broadly, the principles enshrined in Council of Europe Convention 108+ for the protection of individuals with regard to the processing of personal data.

Any person consulting the Services, using them, creating an account, or transmitting personal data of any kind through them, is deemed to have read this Policy, which is binding on them under the conditions and limits described below. This Policy does not, by itself, create any contractual obligation distinct from those arising, where applicable, from a service agreement separately concluded between FastSolve and its client.

Table of Contents

Title I — General Provisions, Definitions and Guiding Principles

Article 1 — Purpose and Scope

This Policy sets out the manner in which FastSolve collects, processes, retains, transmits and, where applicable, transfers the personal data of natural persons interacting with the Services, whether as mere visitors, prospects who have submitted an enquiry, users of the conversational assistant, or clients holding an account on the client portal. It does not apply to any third-party site, application or service to which the Services may link, FastSolve being unable to be held liable for third parties' data protection practices.

Article 2 — Identification of the Data Controller

Within the meaning of Article 4(7) of the GDPR, the controller of the data described in this Policy is the operator of FastSolve, an independent professional activity, reachable exclusively by electronic means at contact@fastsolve.eu. As the thresholds and criteria set out in Article 37 of the GDPR are not met (large-scale processing of special categories of data, regular and systematic large-scale monitoring of data subjects, or processing carried out by a public authority), FastSolve is not required to appoint a Data Protection Officer ("DPO"); in the absence of such an officer, all requests and complaints relating to this Policy are handled directly at the above email address.

Article 3 — General Definitions

Unless expressly stated otherwise, capitalised terms used in this Policy have the meaning given to them in Article 4 of the GDPR, summarised on a non-exhaustive basis in Annex I below. In the event of any discrepancy between this Policy and the text of the GDPR, the latter prevails.

Article 4 — Guiding Principles Applicable to All Processing Operations

In accordance with Article 5 of the GDPR, all processing operations described in this Policy are carried out in cumulative compliance with the following principles:

It is expressly stated that no data collected in connection with the Services is, at any time, sold, rented, exchanged or monetised to a third party for commercial, advertising or statistical purposes unrelated to the purposes described in this Policy.

Title II — Exhaustive Description of the Processing Operations Carried Out

This Title describes, processing operation by processing operation, the nature of the data concerned, its origin, the manner in which it is processed, and the persons or entities that may have access to it. Each processing operation is linked, in Title III, to a specific legal basis and its own retention period.

Article 5 — Processing No. 1: Contact Form and Quote Requests

When a natural person completes the contact form available on fastsolve.eu, the following data is collected: their name, the name of the company or organisation they represent, where applicable, their email address, the nature of the need expressed, an indicative budget, and the literal content of the message drafted. In addition to this declarative data, and for the technical security purposes described in Article 9, the connecting IP address and a timestamp are also recorded. This data is transmitted exclusively, by email, to the FastSolve team, for the sole purpose of analysing and processing the enquiry made.

Article 6 — Processing No. 2: "FastSolve IA" Conversational Assistant

The conversational assistant integrated into the Services is designed to guide the natural person interacting with it towards the most relevant service offering in light of the need expressed, and, where applicable, to prepare a message putting them in contact with the FastSolve team. To this end, the full textual content of each message entered by the data subject is transmitted, in real time and via application programming interface ("API"), to Anthropic PBC, a company incorporated under the laws of the State of Delaware (United States of America), which provides FastSolve, acting as processor within the meaning of Article 28 of the GDPR, with a generative language model (named "Claude") that produces the reply subsequently displayed to the data subject. The data subject is expressly informed that any personal information they choose, on their own initiative, to mention within their text input will necessarily be included in the data thus transmitted. FastSolve does not persistently retain, on its own servers, the content of exchanges with the conversational assistant, such content existing only in the volatile memory of the data subject's browser for the duration of the session, subject to the case described in the following article.

Article 7 — Processing No. 3: Voluntary Transmission of a Conversation Summary

Where the data subject activates, on their own initiative, a feature to transmit the content or a summary of their conversation with the assistant (in particular via the so-called "copy" or "pre-fill the contact form" features), the data thus transmitted is processed under the same terms, for the same purpose and under the same regime as that described in Article 5 relating to the contact form.

Article 8 — Processing No. 4: Account Creation, Authentication and Session Management on the Client Portal

The creation of an account on the client portal takes place at FastSolve's initiative, following the validation of a project by the data subject. The following is then processed: the company name or designation of the entity represented, the data subject's email address, and a password of which only an irreversible cryptographic fingerprint ("hash"), not the plain-text value, is retained in FastSolve's systems, such that no FastSolve staff member, nor any third party, is able to view that password. At each login, a unique session identifier is generated and associated with the data subject's account; where the "remember me" feature is activated, an additional identifier with an extended validity period is generated and retained through secure technical means, for the sole purpose of avoiding the need to re-enter credentials on subsequent logins.

Article 9 — Processing No. 5: Security, Logging and Prevention of Abusive Use

For the sole purpose of preserving the integrity and availability of the Services as well as the security of its clients' accounts, FastSolve implements automated rate-limiting mechanisms associated with the IP address at the origin of the request, in particular in respect of login attempts to the client portal, contact form submissions, and requests made to the conversational assistant. Login attempts, whether successful or not, are logged technically, including the IP address, timestamp and outcome of the attempt, solely to detect fraudulent, automated or malicious behaviour (brute-force attacks, intrusion attempts, harassment of the Service). This technical data is not used for any other purpose, in particular commercial or statistical.

Article 10 — Processing No. 6: Project Management, File Upload and Access

In the course of carrying out a project, FastSolve may receive, store and make available to the data subject, via their client portal account, files, links or textual content relating to that project, as well as receive, where applicable, documents that the data subject chooses to upload themselves. These items are stored in storage space strictly partitioned and associated with the data subject's account, not accessible to FastSolve's other clients, and not indexed by search engines. Functional previews of a project may, for the purpose of protection against unauthorised disclosure prior to final validation and payment, include a visible technical watermark.

Article 11 — Processing No. 7: Invoicing and Accounting and Tax Obligations

Prior to issuing an invoice, FastSolve collects from the data subject or the entity they represent the following information: company name, postal address, VAT identification number where applicable, and billing email address. Once incorporated into an issued invoice, this information is not subsequently modified, in accordance with the integrity and immutability requirements applicable to accounting documents, and is retained for the period prescribed by applicable legal, tax and accounting obligations, independently of the fate of the other data in the data subject's account (Title III).

Article 12 — Processing No. 8: Cookies and Trackers

FastSolve does not use any audience-measurement cookie, advertising-profiling cookie, behavioural-targeting cookie, nor any script or resource loaded from a third-party domain: the Services establish no network connection, from the data subject's browser, to any domain other than fastsolve.eu or espace.fastsolve.eu, as evidenced by the Content Security Policy technically implemented across the Services. Only strictly necessary cookies within the meaning of Article 5(3) of Directive 2002/58/EC (the "ePrivacy Directive"), as transposed into national law and interpreted by the guidelines of the French data protection authority (CNIL) and the Belgian Data Protection Authority (APD), are deposited: a technical anti-abuse cookie on the contact form, and, on the client portal exclusively, a session cookie and, where applicable, an extended-login cookie, both indispensable to the operation of authentication and to the partitioning of accounts. Pursuant to the foregoing texts, these strictly necessary cookies are exempt from prior consent.

Title III — Legal Bases, Retention Periods and Summary Record

Article 13 — Legal Bases of the Processing Operations

In accordance with Article 6(1) of the GDPR, each processing operation described in Title II rests on one of the following legal bases, to the exclusion of any other:

It is expressly stated that none of the processing operations described in this Policy rests on consent within the meaning of Article 6(1)(a) and Article 7 of the GDPR: the cookies implemented falling within the exemption applicable to strictly necessary cookies (Article 12), and all other processing operations arising, by construction, from a voluntary and unambiguous step taken by the data subject constituting, at the very least, a pre-contractual measure within the meaning of Article 6(1)(b).

Article 14 — Retention Periods

In accordance with the storage limitation principle (Article 4), the data collected is retained only for the period strictly necessary to achieve the purposes pursued, as detailed below:

Title IV — Recipients, Processors and Transfers Outside the European Union

Article 15 — Internal Recipients

Only authorised members of the FastSolve team, to the strict extent necessary for the performance of their duties, have access to the data described in this Policy.

Article 16 — Processors

In accordance with Article 28 of the GDPR, FastSolve engages the processors listed in Annex II, with whom a contract or contractual terms governing the processing of personal data have been entered into or are deemed applicable. No processor is authorised to process the data received for any purpose other than that strictly defined by FastSolve's instructions.

Article 17 — Transfers of Data Outside the European Economic Area

As follows from Article 6 and Annex II, the use of Anthropic PBC, a company established in the United States of America, to provide the language model underlying the conversational assistant, entails a transfer of personal data outside the European Economic Area within the meaning of Chapter V of the GDPR (Articles 44 to 50). This transfer is governed by the standard contractual clauses adopted by the European Commission by Implementing Decision (EU) 2021/914 of 4 June 2021, in accordance with Article 46(2)(c) of the GDPR, as well as, where applicable, by the additional safeguards and measures implemented by that processor in accordance with its own contractual documentation. No other processing operation described in this Policy involves a transfer of data outside the European Union.

Title V — Data Security, Breach Management and Incident Notification

Article 18 — Technical and Organisational Security Measures

In accordance with Article 32 of the GDPR, FastSolve implements the following technical and organisational measures, appropriate to the nature, scope, context and purposes of the processing as well as the risks to data subjects: systematic encryption of communications between the data subject's browser and FastSolve's servers by means of the HTTPS/TLS protocol; storage of passwords exclusively in hashed form using recognised cryptographic algorithms; strict logical partitioning of a client's data and files from those of other clients; automated limitation of the number of login attempts; hosting of all data on infrastructure itself secured by its hosting provider (Annex II).

Article 19 — Notification of Personal Data Breaches

In the event of a personal data breach, within the meaning of Article 4(12) of the GDPR, likely to result in a risk to the rights and freedoms of the natural persons concerned, FastSolve undertakes to notify the competent supervisory authority as soon as possible and, where feasible, no later than forty-eight (48) hours after becoming aware of it, in accordance with Article 33 of the GDPR, and to communicate the breach to the data subjects concerned where it is likely to result in a high risk to their rights and freedoms, in accordance with Article 34 of the GDPR.

Title VI — Rights of Data Subjects and Procedures for Exercising Them

Article 20 — Right of Access

In accordance with Article 15 of the GDPR, every data subject has the right to obtain from FastSolve confirmation as to whether or not personal data concerning them is being processed and, where that is the case, access to that data as well as to information relating to the purposes of the processing, the categories of data concerned, the recipients, the envisaged retention period, and the source of the data where it was not collected directly from them.

Article 21 — Right to Rectification

In accordance with Article 16 of the GDPR, every data subject has the right to obtain, without undue delay, the rectification of inaccurate personal data concerning them, as well as to have incomplete data completed.

Article 22 — Right to Erasure ("Right to be Forgotten")

In accordance with Article 17 of the GDPR, every data subject has the right to obtain, without undue delay, the erasure of personal data concerning them, in the cases provided for by that article, in particular where such data is no longer necessary in relation to the purposes for which it was collected. This right is exercised subject to applicable statutory retention obligations, in particular accounting and tax obligations (Article 14), which, to that extent only, preclude early erasure of the data concerned.

Article 23 — Right to Restriction of Processing

In accordance with Article 18 of the GDPR, every data subject may obtain restriction of the processing of their data, in particular where they contest its accuracy, for the period enabling FastSolve to carry out the necessary verifications, or where the processing is unlawful and the data subject opposes erasure in favour of restriction of its use.

Article 24 — Right to Data Portability

In accordance with Article 20 of the GDPR, every data subject has the right to receive the personal data they have provided to FastSolve in a structured, commonly used and machine-readable format, and has the right to transmit that data to another controller without hindrance from FastSolve, to the extent that the processing concerned rests on consent or on the performance of a contract and is carried out by automated means.

Article 25 — Right to Object

In accordance with Article 21 of the GDPR, every data subject may object, on grounds relating to their particular situation, to processing of their data resting on FastSolve's legitimate interest (Article 13), in which case FastSolve will no longer pursue that processing, unless it demonstrates compelling legitimate grounds overriding the interests, rights and freedoms of the data subject, or that the processing is necessary for the establishment, exercise or defence of legal claims.

Article 26 — Right to Withdraw Consent and Post-Mortem Directives

Where, exceptionally, a processing operation were to rest on the data subject's consent, the data subject would have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent given before its withdrawal. The data subject further has the right to define, under the conditions provided for by the law of their country of residence, directives concerning the retention, erasure and communication of their data after their death.

Article 27 — Procedures for Exercising Rights

All of the above-mentioned rights may be exercised by simple email to contact@fastsolve.eu, specifying the subject of the request. In accordance with Article 12 of the GDPR, FastSolve undertakes to respond to any request within one (1) month of its receipt, this period being extendable by a further two (2) months in light of the complexity and number of requests, the data subject being informed of any such extension and its reasons within the initial one-month period. FastSolve reserves the right to request, under the conditions provided for in Article 12(6) of the GDPR, any reasonable evidence of the identity of the person making the request, where there is reasonable doubt as to that identity.

Title VII — Automated Individual Decision-Making and Profiling

Article 28 — Absence of Fully Automated Decision-Making

In accordance with Article 22 of the GDPR, none of the processing operations described in this Policy, including those involving the use of the "FastSolve IA" conversational assistant (Article 6), gives rise to a decision based solely on automated processing, including profiling, which produces legal effects concerning the data subject or similarly significantly affects them. The conversational assistant merely guides the data subject towards the most relevant service offering in light of the information they themselves have provided, and prepares, where applicable, a message for the attention of the FastSolve team; it does not, under any circumstances, conclude, validate or invoice any contractual commitment on behalf of the data subject, human intervention being systematically required to that end.

Title VIII — Miscellaneous and Final Provisions

Article 29 — Minors

The Services, being exclusively professional in purpose, are not intended for minors. FastSolve does not knowingly collect data concerning minors and invites any legal representative aware of such collection to report it without delay to the address referred to in Article 27, for the purpose of deleting such data.

Article 30 — Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, any data subject who considers, after having contacted FastSolve under the conditions set out in Article 27, that the processing of their data does not comply with the provisions of the GDPR, has the right to lodge a complaint with the supervisory authority competent for their habitual place of residence, place of work, or the place of the alleged infringement, in accordance with Article 77 of the GDPR, and in particular:

Article 31 — Absence of a Data Protection Impact Assessment

Given the nature, scope, context and purposes of the processing operations described in this Policy, and the absence of large-scale processing of special categories of data within the meaning of Article 9 of the GDPR, large-scale systematic monitoring, or innovative use of new technologies presenting a high risk to the rights and freedoms of natural persons, FastSolve considers that none of these processing operations requires a Data Protection Impact Assessment ("DPIA") within the meaning of Article 35 of the GDPR. This assessment is reviewed in the event of a substantial change to the processing operations carried out.

Article 32 — Amendment of this Policy

FastSolve reserves the right to amend this Policy at any time, in particular to reflect developments in the Services, the tools and processors used, or the applicable regulatory framework. The version in force is that published at fastsolve.eu/en/privacy/, the date of last update appearing at the top of this document. Any substantial amendment will be brought to attention through a visible notice on the Services.

Article 33 — Governing Law

This Policy is governed by the GDPR and, on a complementary basis, by the law applicable in the data subject's habitual place of residence, without prejudice to any applicable mandatory provisions of public policy.

Article 34 — Contact

For any question relating to this Policy, to the protection of their personal data, or to the exercise of their rights, any data subject may, at any time, contact FastSolve at the following email address: contact@fastsolve.eu.

Annex I — Glossary of GDPR Concepts

Annex II — List of Processors and Recipients

This list is subject to change; the up-to-date version is the one published on this page.

Annex III — Normative References