If you only read one section, read this.
Fastvue AI is operated by Fastvue Pty Ltd ("Fastvue", "we", "us"). It's an optional AI feature inside Fastvue Reporter. We wear two different "hats", because the law treats them differently:
| Data | Our role | Plain meaning |
|---|---|---|
| The matched text sent for assessment (and the AI's response) | Processor | We only handle it to provide the service, on your instructions. You're in charge of it. |
| Your licence key, usage counts, and billing/operational records | Controller | We decide how to use this for running our business: billing, fraud prevention, and keeping the service reliable. |
This mirrors how most business software works: you own your content; we own the operational record of your account.
Fastvue AI only ever assesses records that match a safeguarding keyword, and you decide exactly which ones. Everything else is never sent, never processed, and never seen.
When a record matches a keyword, we send only the context needed to assess risk, and only the fields relevant to that activity type:
In every case we also include two short, non-redacted fields: the specific keyword from your Keyword Group that matched, and the name of the Keyword Group it belongs to.
The matched keyword is deliberately sent as-is, because it's the signal Fastvue AI needs to assess risk. Our default keyword lists include sensitive terms (for example, names associated with adult content), and the AI has to see which keyword matched to tell a genuine concern from a coincidence. Personal details in the surrounding context are still redacted, so the matched keyword is the only part that isn't. If a Keyword Group instead contains information you'd rather not send at all, such as your own list of staff names, you can configure that group to not send its matched activity to Fastvue AI (see "You control what's sent" below).
Because these controls work at the source, withheld data never reaches Fastvue AI at all, a stronger protection than deleting it afterwards.
Before any text is sent to an AI model, an automatic step removes common personal identifiers (names, emails, phone numbers, payment-card numbers, postcodes, and national-insurance or social-security numbers) and replaces them with neutral tags. So the model sees "{redacted Person} mentioned self-harm" rather than a real name. Redaction is on by default. It reduces risk significantly but isn't claimed to be perfect, so it works alongside the controls above.
For each matched record we handle two kinds of data:
Your licence key, request and token counts, estimated cost, timing, and the outcome in summary form (risk level, confidence, category labels, the model used). This is the equivalent of an itemised phone bill: it shows that and how much, not what was said. It contains no request content.
The redacted keyword and context, and the AI's written reason. We keep this short-lived, redacted record so we can monitor accuracy and reduce false positives. It is automatically deleted after 14 days, never sold, and never used to train a third party's general-purpose AI model.
| Non-confidential operational data (licence, usage, outcomes) | 90 days, then auto-deleted |
| Redacted request content | 14 days, then auto-deleted |
Deletion is automatic (a nightly cleanup job). You can also ask us to delete specific records or your data entirely at any time, and we honour that promptly. Truly aggregated and anonymised statistics (which can't be traced back to you or any individual) may be kept longer to understand overall accuracy and performance.
On the roadmap: a Zero Data Retention option, where no request content is stored by anyone (Fastvue, our infrastructure provider, or the AI provider). It isn't available yet. It may become available at a later stage, based on customer demand and beta feedback. In the meantime, the Keyword Group controls above let you keep sensitive categories entirely local.
You (and the individuals whose data may appear in requests) can ask us to show you, export, correct, delete ("right to erasure"), or stop a particular kind of processing of your data. Email dataprivacy@fastvue.co and we'll respond within 30 days, free of charge for reasonable requests. Because we only ever see keyword matches, redact personal details, and keep content only briefly, there's usually very little personal data to act on, by design.
We run a separate database in each of three regions: Europe, the USA, and Australia. When you enable Fastvue AI you choose which region your data lives in, and it is stored in that region and stays there. We don't copy or replicate it to other regions.
If you choose Europe, your data is additionally covered by a formal EU residency guarantee suitable for GDPR, which also makes it the right choice for UK customers.
Your data is stored in the region you choose. Assessing it means sending the redacted text to an AI model, and that assessment takes place in the same region — your data is both stored and processed in the region you choose. We protect this in two further ways, which always apply no matter which model is in use:
We may change which model we use at any time based on ongoing quality testing; these two protections apply to all of them. In the rare event a request is processed outside your region, we rely on Standard Contractual Clauses (the standard regulator-approved transfer mechanism), plus the UK Addendum for UK customers.
A "sub-processor" is any third party that helps us deliver the service and may handle your data. Here is the complete list. We'll update it and notify customers before adding a new one.
| Sub-processor | What they do | Where | Train AI on your data? |
|---|---|---|---|
| Cloudflare, Inc. | The core platform: runs our code, stores data, records usage metrics, enforces rate limits, blocks bots, and secures admin access. Cloudflare also provides AI inference and model hosting (Workers AI). | Your chosen region (EU / US / Australia) | No |
| An AI model provider we route to for the safeguarding assessment. | Your chosen region (EU / US / Australia) | No |
How AI inference works: Fastvue AI sends the redacted text to an AI model for assessment. We continuously evaluate a range of models for accuracy, and we only ever route to providers whose terms prohibit training on your data. If we add or change a provider, we update this list and notify customers before the change goes live.
By enabling Fastvue AI you agree to these terms, which apply in addition to your existing Fastvue Reporter licence agreement.
Fastvue AI helps prioritise safeguarding alerts by classifying keyword-matched records by risk. It is a decision-support tool, not a replacement for human judgement. AI can occasionally make mistakes, including misclassifying a genuine concern. Flagged results should always be reviewed by a suitably trained person, and you remain responsible for your safeguarding decisions and processes.
We aim to keep Fastvue AI available and accurate but provide it on an "as is" basis without warranty that results will be error-free or uninterrupted. We may improve the underlying models and features over time. Where a change materially affects how your data is processed, we'll update this page and, where appropriate, notify you.
No. It only ever receives records that match a safeguarding keyword, and only the context around that match (see What Fastvue AI sees). Everything else is never sent. You can also exclude specific terms and configure Keyword Groups not to send their matched activity, so you control exactly what's evaluated.
Yes. Choose the Europe region and your stored data physically stays in the EU. We also have Standard Contractual Clauses in place for any cross-border processing (such as AI inference). You're a controller; we're your processor.
It isn't. Our AI providers are on plans that contractually prohibit training on customer inputs. We keep a short, redacted record only to monitor and improve Fastvue AI's own accuracy, never to train a third party's general model.
Today we keep a short, redacted record (14 days) to maintain accuracy, and you can minimise what's sent using the Keyword Group controls above. A Zero Data Retention option (no content stored by anyone) is something we may add later, based on customer demand and beta feedback. Tell us if it matters to you.
Personal details in the text we send are automatically redacted before it reaches any AI model. The one exception is the keyword that matched, which is sent as-is because it's exactly what Fastvue AI needs to assess risk (see What Fastvue AI sees). If a Keyword Group contains names or other sensitive terms you'd rather not send, configure that group not to send its matched activity to Fastvue AI.
Only the sub-processors listed above, plus authorised Fastvue staff via audited admin access. No one else, and we don't sell data.
Questions about anything on this page, or a Data Processing Agreement? Email dataprivacy@fastvue.co or contact our team.