1.Scope
This policy explains how we process personal data when you:
- visit floris3.com;
- contact us, book a call or subscribe to our newsletter;
- work with us as a client, prospective client, adviser or partner — including the Capital Blueprint, the Filing Package and our programmes;
- use the FLORIS³ client application, or an investor portal we operate for one of our clients.
It is provided under Articles 13 and 14 of the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG) and the Austrian Telecommunications Act 2021 (TKG 2021).
2.Who is responsible
FLORIS³ GmbH
Salzgries 21/16, 1010 Vienna, Austria
FN 544762x, Commercial Court Vienna
Phone: +43 660 20 40 200
Email: hello@floris3.com
We have not appointed a data protection officer because the conditions of Article 37 GDPR are not met. All privacy requests are handled by our management at the address above.
3.Controller or processor
We are the controller for data of website visitors, people who contact us, newsletter subscribers, our clients’ and partners’ contact persons, and users of the client application.
We are a processor for data of investors, prospective investors, advisers and intermediaries that our clients collect through the platform and investor portals. Our client — the issuer or distributor — is the controller and decides why and how this data is processed; we process it only on its instructions under Article 28 GDPR. If you are an investor, the client’s privacy notice in the investor portal is the primary source of information, and requests should go to the client first. If you contact us, we forward your request and support the client.
4.What data we process
Website visitors
- Server and security logs: IP address, date and time, requested page, referrer, browser and operating system.
- With your consent only: usage statistics from Google Analytics 4, loaded through Google Tag Manager (pages viewed, events such as form starts and clicks, approximate location, device information, a pseudonymous identifier).
Enquiries and newsletter
- Contact form: name, email, company, phone, role, and the details you give about your project (funding target, timing, structure, investors, message).
- Newsletter: email address, subscription and unsubscription timestamps, consent record, and whether emails are opened or clicked.
Clients, prospective clients and partners
- Contact persons: name, role, business contact details, communication history and meeting notes.
- Contract and billing: company details, signatories, order, invoices, payments, bank details.
- Blueprint and filing: information about your company, its owners and managers, and project documents you provide, as far as they contain personal data.
- Client verification: identity and sanctions checks on the client, its beneficial owners and directors, where required for our own risk management.
Users of the client application
- Account: name, email, role, hashed password, language and time-zone settings.
- Security: two-factor secrets, session data, login history and an audit trail of actions.
- Public wallet addresses where you connect a wallet — never private keys.
- Support requests and in-app messages, and conversations with AI features where you use them.
Investor and adviser data (as processor)
- Identity: name, date of birth, nationality, address, company details for legal entities.
- KYC/AML: identity-document images, selfie and liveness results, sanctions and PEP screening results — processed by the identity-verification provider the client selects.
- Investments: subscriptions, allocations, payment references, bank details, wallet addresses, register entries, distributions and tax data.
- Signed documents, votes, messages and investor-portal usage.
- For Distribution: adviser and intermediary details, their clients’ subscriptions, commission statements and payout bank details.
5.Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Operating and securing the website | Legitimate interest in a secure, working website — Art. 6(1)(f) GDPR |
| Website analytics (Google Tag Manager, Google Analytics 4) | Your consent — Art. 6(1)(a) GDPR, § 165(3) TKG 2021 |
| Answering enquiries and preparing offers | Pre-contractual steps — Art. 6(1)(b); otherwise legitimate interest — Art. 6(1)(f) |
| Newsletter | Your consent — Art. 6(1)(a) GDPR, § 174 TKG 2021 |
| Performing the Blueprint, Filing Package and programmes; accounts and support | Contract — Art. 6(1)(b); for contact persons of corporate clients: legitimate interest — Art. 6(1)(f) |
| Client verification and sanctions screening | Legal obligation — Art. 6(1)(c); legitimate interest in avoiding legal and reputational risk — Art. 6(1)(f) |
| Invoicing, accounting and tax | Legal obligation under the BAO and UGB — Art. 6(1)(c) |
| Platform security, fraud prevention and audit trails | Legitimate interest — Art. 6(1)(f); legal obligation — Art. 6(1)(c) |
| Improving our services with aggregated, anonymised data | Legitimate interest — Art. 6(1)(f) |
| Investor and adviser data | On the client’s instructions — Art. 28 GDPR; the client’s legal basis applies |
| Establishing or defending legal claims; requests from authorities | Legitimate interest — Art. 6(1)(f); legal obligation — Art. 6(1)(c) |
6.Who receives data
Service providers (processors)
| Provider | Purpose | Location and safeguards |
|---|---|---|
| Vercel Inc. | Website hosting and delivery | Served from the EU (Frankfurt); USA for support — EU-US Data Privacy Framework and Standard Contractual Clauses |
| Google Ireland Ltd. | Google Tag Manager and Google Analytics 4, only with consent | EU; transfers to Google LLC under the EU-US Data Privacy Framework |
| Resend Inc. | Delivery of contact-form enquiries to our inbox | USA — EU-US Data Privacy Framework and Standard Contractual Clauses |
| Sendinblue SAS (Brevo) | Newsletter delivery and subscription management | France (EU) |
| FinFortus GmbH, Salzgries 21/16, 1010 Vienna | Development and operation of the platform technology | Austria (EU) |
| Amazon Web Services EMEA SARL | Platform and investor-portal hosting, databases, email infrastructure | EU data centres (Frankfurt); a Dedicated Environment may run in the client’s own AWS account |
Every processor is bound by a data processing agreement under Article 28 GDPR. We inform clients at least 30 days before adding or replacing a processor that handles their data.
Providers selected per programme
Depending on the structure agreed in the Capital Blueprint, investor and client data is shared with licensed providers such as register keepers, custodians, identity-verification and sanctions-screening providers, e-signature services, payment providers, wallet providers and, where a client enables them, AI providers. Each is named in the client’s offer and in the investor portal’s privacy notice. Licensed providers typically act as independent controllers under their own licence and privacy terms.
Other recipients
- Law firms, tax advisers and auditors engaged for a programme or by us — bound by professional secrecy.
- On Distribution, the licensed partner under whose framework advisers sell, and the advisers themselves for their own clients’ data.
- Courts, the Financial Market Authority, tax and other authorities where we are legally obliged.
- A buyer or successor in the event of a merger or sale of the business, under confidentiality.
7.Blockchain records
Tokenised instruments are recorded on public blockchains. These records are replicated worldwide by independent nodes and cannot be changed or deleted by anyone, including us.
8.AI features and automated decisions
Where AI features are used in the platform, the relevant messages and data are sent to the AI provider configured for the client. Conversations are not used to train models, and our providers are contractually prohibited from doing so. AI features are identified as such in line with Article 50 of the EU AI Act.
Identity verification may use one-to-one biometric matching (a selfie against an identity document). This is special-category data under Article 9 GDPR, processed on the investor’s explicit consent and to meet anti-money-laundering obligations. Verification and screening results are automated, but the decision to accept or reject an investor is always taken or reviewed by a person at the client. There is no decision based solely on automated processing within the meaning of Article 22 GDPR.
10.How long we keep data
| Data | Retention |
|---|---|
| Server and security logs | 30 days; longer if needed to investigate a specific incident |
| Enquiries from prospective clients | 12 months after the last contact, unless a contract follows |
| Newsletter data | Until you unsubscribe; proof of consent and unsubscription for as long as claims can be raised |
| Client accounts and programme data | For the agreement; export within 30 days of its end; deletion or anonymisation within 90 days |
| Contracts, invoices, accounting records | 7 years from the end of the calendar year (§ 132 BAO, § 212 UGB) |
| Audit trails and legal acceptance records | Lifetime of the account plus 3 years (general limitation period); longer where records evidence securities subscriptions |
| Investor KYC/AML data (as processor) | As instructed by the client, typically 5 years after the end of the business relationship under the FM-GwG |
| Application security logs | 12 months |
| Blockchain records | Permanent — public ledgers cannot be changed |
11.Your rights
Under Articles 15 to 21 GDPR you have the right to:
- access the data we hold about you and receive a copy;
- have inaccurate or incomplete data corrected;
- have data erased where there is no longer a legal basis for keeping it;
- restrict processing while a dispute about accuracy or lawfulness is resolved;
- receive data you gave us in a structured, machine-readable format, or have it sent to another controller;
- object to processing based on legitimate interest, and to direct marketing at any time without giving reasons;
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
Write to hello@floris3.com. We may ask you to confirm your identity. We answer within one month; for complex requests this may be extended by two further months, and we will tell you why. Requests are free of charge unless manifestly unfounded or excessive.
12.Supervisory authority
If you believe we process your data unlawfully, you may lodge a complaint with the Austrian Data Protection Authority or with the supervisory authority in your EU member state of residence or work.
Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Vienna, Austria
Phone: +43 1 52 152-0 · Email: dsb@dsb.gv.at
13.International transfers
We host the platform and store programme data in the European Union. Where a provider processes data in the United States, the transfer is based on the provider’s certification under the EU-US Data Privacy Framework or on the European Commission’s Standard Contractual Clauses, supplemented by encryption in transit and at rest. Transfers to the United Kingdom and Switzerland rely on the Commission’s adequacy decisions. A copy of the safeguards is available on request.
14.Security and breach notification
Our technical and organisational measures include:
- TLS encryption in transit and encryption at rest; integration credentials and API keys encrypted with a managed key service; own keys (BYOK) in a Dedicated Environment;
- strict tenant isolation, role-based access control and least-privilege access for our staff;
- two-factor authentication, one-time codes for sensitive actions and multi-person approval for critical changes;
- complete audit logging, short-lived links for document access and IP allow-listing for API use;
- encrypted, geographically separated backups with regular restoration tests;
- an annual independent penetration test and a documented incident-response process.
If a personal-data breach is likely to result in a risk to your rights, we notify the Data Protection Authority within 72 hours and inform affected persons without undue delay where the risk is high. Where we act as processor, we notify the responsible client within 24 hours of becoming aware of the breach, as set out in our Service Level Agreement.
15.Children and obligation to provide data
Our services are aimed at businesses and adults. We do not knowingly collect data from anyone under 18. If you believe a minor has given us data, tell us and we will delete it.
You are not legally obliged to give us personal data. Without the fields marked as required, however, we cannot answer your enquiry, conclude a contract or open an account. Investors must complete identity verification before a subscription can be accepted, because anti-money-laundering law requires it.
16.Changes to this policy
We publish changes here with a new version date. If we materially change how we process data of platform users, we also inform them by email or in the application. Earlier versions are available on request.
17.Contact
FLORIS³ GmbH, Salzgries 21/16, 1010 Vienna, Austria — hello@floris3.com. See also our Terms of Service and Impressum.
