Trust

The answers a review asks for, on one page.

Three kinds of answer live here. Where a claim can be checked without us, we say how to check it. Where it rests on a contract, we name the contract. Where we don't hold something, we use the word "no".

Last reviewed to confirm · date

Who you are dealing with

One firm, and its name is on the door.

The firm
FuseLoom — an AI consultancy. Six services: AI agents & automation, applications & solutions, AI strategy & roadmap, data & insight, digital transformation, AI enablement.
Legal entity
to confirm · registered name & number
Where we are
Kirresh AutoMall Complex, 148 Mecca Street, Amman, Jordan.
Who answers
Basem Qreieyeh, CEO & Founder — [email protected]. Correspondence in English or Arabic.
Who does the work
The people on the discovery call are on the team that builds it. If a phase needs a specialist, we name them before they start — never somebody you would only ever meet in a support thread, and never anyone working beside our contract rather than under it.
In an engagement

We ask for access. We don't ask for copies.

Your data quietly accumulating on somebody else's laptop is the part of a consulting engagement nobody writes into the contract. Here is how we keep it from happening.

You issue the access, and you can end it in a click. We work in accounts you create in your own systems, named to a person, with the narrowest permission the task allows. When the phase ends, you revoke them — you don't have to ask us to hand anything back first.

We build against the smallest real sample we can. Where an example only has to show the shape of your data, redacted or synthetic records do the job, and we'll say so rather than take the live export because it was offered.

We do not take a standing copy of your database, your CRM export or your customer list. What we hold during a project is the working material: notes, diagrams, prompts, code, and whatever sample was agreed in writing at the start of the phase.

Where that working material lives: to confirm · device & account controls

At the end, everything is handed over — code, prompts, accounts, documentation — and our copies of your material are deleted on request, with a written confirmation of what was deleted and when.

AI models

What a model sees, and what it is allowed to keep.

"Your data never trains AI models" is a sentence any firm can type. A sentence like that is only ever as good as the account it runs on. So: the account, the term, and the retention — the things a reviewer can check against a provider's own contract.

The account

Business terms, not the consumer app

Client work runs on business API accounts, never on consumer chat products, where the terms and the defaults are different.

to confirm · provider names & plan tiers

The term that matters

Training on your content is excluded by contract

Not by policy on our side — by the provider's own terms for that account type, which you can read without our involvement.

to confirm · clause reference & link

Retention

How long a prompt survives

Requests and responses sit in the provider's systems for a stated window and are then deleted. The window is theirs to publish, so we point at it rather than describe it.

to confirm · retention window & zero-retention status

Fine-tuning

We never turn your content into weights

FuseLoom does not fine-tune models on client material. Systems we build retrieve your approved documents at the moment of the question — your knowledge stays a file you control and can delete, not something baked into a model.

What is sent

Only the fields the task needs

A model that answers a delivery question does not need a national ID number, so it never receives one. Identifying fields the task doesn't use are stripped before the request leaves your systems, and which fields travel is agreed in writing before anything is connected.

When it doesn't know

It stops rather than invents

An agent answers from your approved material or not at all. A human keeps anything involving financial records, a contract or a relationship. The agent stops there and asks.

Standards

No SOC 2. No ISO 27001. Not today.

We will not display a badge we do not hold.

Those audits exist to answer one question well: can this vendor be trusted with a copy of our data inside their building? That is the right question for a company that hosts your customers on its own servers, and the work those audits demand is the right work for them.

A consultancy is a different shape of risk. We do not host your data — we work inside systems you own, under credentials you issue and can revoke. So the questions that actually protect you here are: who has access, granted by whom and for how long; what is in the contract; who is named when something goes wrong; and which outside services touch anything. This page answers each of them, and a signed DPA makes the answers binding.

Where an engagement changes that shape — if we host something for you rather than deliver it into your own accounts — the arrangement is written into the statement of work, along with who is responsible for what. If a certificate is a hard condition of your procurement, say so on the first call. Better we both know at the start than at signature.

Sub-processors

Everyone else who touches this.

These are the outside services involved in running fuseloom.com and our own correspondence. Client engagements may add providers; those are named in the statement of work.

Retention is each provider's own commitment, so we link to it rather than summarise it — a paraphrase is not something you can hold anyone to. Serving the typefaces from this site instead is planned; when that ships, the Google Fonts row disappears from this table.
Provider What it does for us What reaches it Where it is processed
Cloudflare Their trust hub & data terms ↗ Hosts the site and sits in front of it as the network that serves every page. Your IP address, the page you requested, and the ordinary details every browser sends. Cloudflare's global network — served from the location nearest the visitor.
Google Workspace Their data processing terms ↗ Runs our email — everything sent to and from [email protected]. Your message, your address, and anything you attach to it. to confirm · workspace data region
Resend Their data processing terms ↗ Delivers the two emails the site sends: your request as it reaches us, and the acknowledgement that goes back to you. What you typed into the form: your name, the email address or mobile number you gave, the time of day that suits, and your note. to confirm · sending region
Google Fonts What they receive, in their words ↗ Serves the typefaces this page is set in. Your IP address and basic browser details, at the moment the font files are fetched. Google's global network.
The contract pack

Paper first, if that's how you work.

Ask at [email protected] and the current drafts come back by email — before you send us a document, a login, or anything at all. Send your own templates instead and we'll mark plainly what we cannot sign.

NDA

Mutual, so it protects your side and ours. Signed before the conversation gets specific enough to matter.

MSA

The master agreement: liability, ownership of what we build, confidentiality, how either of us ends it. Signed once, then every project hangs off it.

SOW

One per phase. What gets built, what you keep, what it involves and how that scope was arrived at. Each phase ends at a door you can walk out of.

DPA

The data processing agreement: what we may process, on whose instructions, with which sub-processors, and what happens to it at the end. It makes the table above enforceable instead of merely published.

If something goes wrong

The name you write to, and what happens next.

Security contact: Basem Qreieyeh — [email protected]. Put "Security" in the subject line and it goes to the top of the pile. It reaches a person, not a ticket queue.

What you get back: an acknowledgment in writing from that person. Then, as we learn it — what happened, what we know for certain, what we don't know yet, and what we have already changed. We keep writing until it is closed, and we do not wait until we have a tidy story to send the first message.

If the cause sits with one of the services named above, we say which one and point you at their status page and their notice, so you are reading the source rather than our account of it.

Notification timing is a contract term, not a promise on a web page. It lives in the DPA, where it is enforceable — and it is one of the things we would rather agree before an incident than during one.

Found a flaw in this website itself? Same address.

Crossing a border

The cross-border question, before your counsel asks it.

Almost every data protection regime — Jordan's Personal Data Protection Law, the GDPR, and most of what sits between them — requires an organisation to be able to say where personal data goes and why it is allowed to go there. Wherever you are, your counsel will ask us. Here is the answer in advance.

This website and its contact form use services that process outside Jordan, where our office is. They are named in the table above, with what reaches each one — so you can check the list against your own rules rather than ours.

In an engagement, the default is that your data stays where it already is — inside your systems, under your accounts. What crosses a border is the specific request a system has to send to do its job, not your records.

If your policy or your regulator requires processing to stay inside a particular country or region, say it on the first call. It changes the design: which providers are available, whether a hosted model can be called at all, and sometimes whether the honest answer is a simpler system with no model in it. That is a real constraint to design around, not an objection to talk you out of.

This describes how we work. It is not legal advice — what your organisation is obliged to do is your counsel's call, and we will give them whatever detail they need to make it.

This website

Checkable from your own browser, right now.

Every row below is a response header this site actually sends, copied word for word from the file that sets it. Paste fuseloom.com into any public header checker and read them for yourself — we cannot edit what it reports.

Check it yourself: run fuseloom.com through a public header checker ↗. What headers don't prove: they describe the front door. The rest of this page is the building.
Header What it is set to What that means
Strict-Transport-Security max-age=31536000; includeSubDomains Your browser refuses to talk to this site unencrypted, and keeps refusing for a year after each visit — across every subdomain.
Content-Security-Policy default-src 'self'; script-src 'self' 'unsafe-inline' https://static.cloudflareinsights.com https://challenges.cloudflare.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data:; connect-src 'self' https://cloudflareinsights.com https://challenges.cloudflare.com; frame-src https://challenges.cloudflare.com; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; form-action 'self' Names every origin allowed to serve code, styles, fonts and images, blocks plug-ins and framing, and stops any form here posting anywhere but back to us. Its one loosening is 'unsafe-inline' — this site's own styles and scripts are written into the page rather than fetched as files, so the policy has to permit inline code, which weakens the protection against script injection. We print the policy in full rather than reprint the flattering half of it.
X-Frame-Options DENY Nobody can load this page inside their own frame and dress it up as theirs.
X-Content-Type-Options nosniff The browser never guesses what a file is. It takes our word or it refuses it.
Permissions-Policy camera=(), microphone=(), geolocation=(), interest-cohort=() Camera, microphone and location are switched off for the whole site — nothing here is even able to ask — and the page opts out of being used to sort you into an advertising cohort.
Referrer-Policy strict-origin-when-cross-origin When you follow a link away, the next site learns you came from fuseloom.com — not which page you were reading.

Something on this page not precise enough for your review? Write to [email protected] and tell us which line. If you're right, we'll fix the line — and if the answer is "we don't have that yet", it will say so here in those words.