Skip to content
FLORIS3

Privacy Policy

Your data, protected

How FLORIS³ processes personal data on this website, in our programmes and on the platform — under the GDPR and Austrian data protection law.

Version 2026-09-30 · Effective 30 September 2026

1.Scope

This policy explains how we process personal data when you:

  • visit floris3.com;
  • contact us, book a call or subscribe to our newsletter;
  • work with us as a client, prospective client, adviser or partner — including the Capital Blueprint, the Filing Package and our programmes;
  • use the FLORIS³ client application, or an investor portal we operate for one of our clients.

It is provided under Articles 13 and 14 of the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG) and the Austrian Telecommunications Act 2021 (TKG 2021).

2.Who is responsible

FLORIS³ GmbH

Salzgries 21/16, 1010 Vienna, Austria

FN 544762x, Commercial Court Vienna

Phone: +43 660 20 40 200

Email: hello@floris3.com

We have not appointed a data protection officer because the conditions of Article 37 GDPR are not met. All privacy requests are handled by our management at the address above.

3.Controller or processor

We are the controller for data of website visitors, people who contact us, newsletter subscribers, our clients’ and partners’ contact persons, and users of the client application.

We are a processor for data of investors, prospective investors, advisers and intermediaries that our clients collect through the platform and investor portals. Our client — the issuer or distributor — is the controller and decides why and how this data is processed; we process it only on its instructions under Article 28 GDPR. If you are an investor, the client’s privacy notice in the investor portal is the primary source of information, and requests should go to the client first. If you contact us, we forward your request and support the client.

4.What data we process

Website visitors

  • Server and security logs: IP address, date and time, requested page, referrer, browser and operating system.
  • With your consent only: usage statistics from Google Analytics 4, loaded through Google Tag Manager (pages viewed, events such as form starts and clicks, approximate location, device information, a pseudonymous identifier).

Enquiries and newsletter

  • Contact form: name, email, company, phone, role, and the details you give about your project (funding target, timing, structure, investors, message).
  • Newsletter: email address, subscription and unsubscription timestamps, consent record, and whether emails are opened or clicked.

Clients, prospective clients and partners

  • Contact persons: name, role, business contact details, communication history and meeting notes.
  • Contract and billing: company details, signatories, order, invoices, payments, bank details.
  • Blueprint and filing: information about your company, its owners and managers, and project documents you provide, as far as they contain personal data.
  • Client verification: identity and sanctions checks on the client, its beneficial owners and directors, where required for our own risk management.

Users of the client application

  • Account: name, email, role, hashed password, language and time-zone settings.
  • Security: two-factor secrets, session data, login history and an audit trail of actions.
  • Public wallet addresses where you connect a wallet — never private keys.
  • Support requests and in-app messages, and conversations with AI features where you use them.

Investor and adviser data (as processor)

  • Identity: name, date of birth, nationality, address, company details for legal entities.
  • KYC/AML: identity-document images, selfie and liveness results, sanctions and PEP screening results — processed by the identity-verification provider the client selects.
  • Investments: subscriptions, allocations, payment references, bank details, wallet addresses, register entries, distributions and tax data.
  • Signed documents, votes, messages and investor-portal usage.
  • For Distribution: adviser and intermediary details, their clients’ subscriptions, commission statements and payout bank details.

5.Purposes and legal bases

PurposeLegal basis
Operating and securing the websiteLegitimate interest in a secure, working website — Art. 6(1)(f) GDPR
Website analytics (Google Tag Manager, Google Analytics 4)Your consent — Art. 6(1)(a) GDPR, § 165(3) TKG 2021
Answering enquiries and preparing offersPre-contractual steps — Art. 6(1)(b); otherwise legitimate interest — Art. 6(1)(f)
NewsletterYour consent — Art. 6(1)(a) GDPR, § 174 TKG 2021
Performing the Blueprint, Filing Package and programmes; accounts and supportContract — Art. 6(1)(b); for contact persons of corporate clients: legitimate interest — Art. 6(1)(f)
Client verification and sanctions screeningLegal obligation — Art. 6(1)(c); legitimate interest in avoiding legal and reputational risk — Art. 6(1)(f)
Invoicing, accounting and taxLegal obligation under the BAO and UGB — Art. 6(1)(c)
Platform security, fraud prevention and audit trailsLegitimate interest — Art. 6(1)(f); legal obligation — Art. 6(1)(c)
Improving our services with aggregated, anonymised dataLegitimate interest — Art. 6(1)(f)
Investor and adviser dataOn the client’s instructions — Art. 28 GDPR; the client’s legal basis applies
Establishing or defending legal claims; requests from authoritiesLegitimate interest — Art. 6(1)(f); legal obligation — Art. 6(1)(c)

6.Who receives data

Service providers (processors)

ProviderPurposeLocation and safeguards
Vercel Inc.Website hosting and deliveryServed from the EU (Frankfurt); USA for support — EU-US Data Privacy Framework and Standard Contractual Clauses
Google Ireland Ltd.Google Tag Manager and Google Analytics 4, only with consentEU; transfers to Google LLC under the EU-US Data Privacy Framework
Resend Inc.Delivery of contact-form enquiries to our inboxUSA — EU-US Data Privacy Framework and Standard Contractual Clauses
Sendinblue SAS (Brevo)Newsletter delivery and subscription managementFrance (EU)
FinFortus GmbH, Salzgries 21/16, 1010 ViennaDevelopment and operation of the platform technologyAustria (EU)
Amazon Web Services EMEA SARLPlatform and investor-portal hosting, databases, email infrastructureEU data centres (Frankfurt); a Dedicated Environment may run in the client’s own AWS account

Every processor is bound by a data processing agreement under Article 28 GDPR. We inform clients at least 30 days before adding or replacing a processor that handles their data.

Providers selected per programme

Depending on the structure agreed in the Capital Blueprint, investor and client data is shared with licensed providers such as register keepers, custodians, identity-verification and sanctions-screening providers, e-signature services, payment providers, wallet providers and, where a client enables them, AI providers. Each is named in the client’s offer and in the investor portal’s privacy notice. Licensed providers typically act as independent controllers under their own licence and privacy terms.

Other recipients

  • Law firms, tax advisers and auditors engaged for a programme or by us — bound by professional secrecy.
  • On Distribution, the licensed partner under whose framework advisers sell, and the advisers themselves for their own clients’ data.
  • Courts, the Financial Market Authority, tax and other authorities where we are legally obliged.
  • A buyer or successor in the event of a merger or sale of the business, under confidentiality.

7.Blockchain records

Tokenised instruments are recorded on public blockchains. These records are replicated worldwide by independent nodes and cannot be changed or deleted by anyone, including us.

We never write names, identity documents or other directly identifying data to a blockchain. Only wallet addresses and transaction data are public. The link between a person and a wallet is kept off-chain in the platform, where all data-protection rights apply.

8.AI features and automated decisions

Where AI features are used in the platform, the relevant messages and data are sent to the AI provider configured for the client. Conversations are not used to train models, and our providers are contractually prohibited from doing so. AI features are identified as such in line with Article 50 of the EU AI Act.

Identity verification may use one-to-one biometric matching (a selfie against an identity document). This is special-category data under Article 9 GDPR, processed on the investor’s explicit consent and to meet anti-money-laundering obligations. Verification and screening results are automated, but the decision to accept or reject an investor is always taken or reviewed by a person at the client. There is no decision based solely on automated processing within the meaning of Article 22 GDPR.

9.Cookies and analytics

The website sets no cookies of its own. Google Tag Manager and Google Analytics 4 are loaded only after you click “Accept” in the consent banner; until then no request is sent to Google. Advertising and personalisation signals stay switched off (Google Consent Mode) even after you accept. You can withdraw consent at any time with effect for the future under “Cookie settings” in the footer — we then stop loading these tools and delete the Google Analytics cookies. The platform uses only storage that is strictly necessary for the service you request, which does not require consent under § 165(3) TKG 2021.

NameWhereDurationPurpose
floris3-consent (local storage)floris3.comUntil you change itRemembering your consent choice — strictly necessary
_ga, _ga_<ID>floris3.com, with consentUp to 2 yearsDistinguishing visits for Google Analytics 4
Session, access and refresh tokensClient application, investor portalsUntil logout or expiryAuthentication
Interface preferences (language, theme, layout)Client applicationUp to 12 monthsRemembering your settings

Investor portals run on our clients’ domains. Any additional analytics there are the client’s decision and are described in the portal’s own privacy notice.

10.How long we keep data

DataRetention
Server and security logs30 days; longer if needed to investigate a specific incident
Enquiries from prospective clients12 months after the last contact, unless a contract follows
Newsletter dataUntil you unsubscribe; proof of consent and unsubscription for as long as claims can be raised
Client accounts and programme dataFor the agreement; export within 30 days of its end; deletion or anonymisation within 90 days
Contracts, invoices, accounting records7 years from the end of the calendar year (§ 132 BAO, § 212 UGB)
Audit trails and legal acceptance recordsLifetime of the account plus 3 years (general limitation period); longer where records evidence securities subscriptions
Investor KYC/AML data (as processor)As instructed by the client, typically 5 years after the end of the business relationship under the FM-GwG
Application security logs12 months
Blockchain recordsPermanent — public ledgers cannot be changed

11.Your rights

Under Articles 15 to 21 GDPR you have the right to:

  • access the data we hold about you and receive a copy;
  • have inaccurate or incomplete data corrected;
  • have data erased where there is no longer a legal basis for keeping it;
  • restrict processing while a dispute about accuracy or lawfulness is resolved;
  • receive data you gave us in a structured, machine-readable format, or have it sent to another controller;
  • object to processing based on legitimate interest, and to direct marketing at any time without giving reasons;
  • withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.

Write to hello@floris3.com. We may ask you to confirm your identity. We answer within one month; for complex requests this may be extended by two further months, and we will tell you why. Requests are free of charge unless manifestly unfounded or excessive.

12.Supervisory authority

If you believe we process your data unlawfully, you may lodge a complaint with the Austrian Data Protection Authority or with the supervisory authority in your EU member state of residence or work.

Österreichische Datenschutzbehörde

Barichgasse 40–42, 1030 Vienna, Austria

Phone: +43 1 52 152-0 · Email: dsb@dsb.gv.at

www.dsb.gv.at

13.International transfers

We host the platform and store programme data in the European Union. Where a provider processes data in the United States, the transfer is based on the provider’s certification under the EU-US Data Privacy Framework or on the European Commission’s Standard Contractual Clauses, supplemented by encryption in transit and at rest. Transfers to the United Kingdom and Switzerland rely on the Commission’s adequacy decisions. A copy of the safeguards is available on request.

14.Security and breach notification

Our technical and organisational measures include:

  • TLS encryption in transit and encryption at rest; integration credentials and API keys encrypted with a managed key service; own keys (BYOK) in a Dedicated Environment;
  • strict tenant isolation, role-based access control and least-privilege access for our staff;
  • two-factor authentication, one-time codes for sensitive actions and multi-person approval for critical changes;
  • complete audit logging, short-lived links for document access and IP allow-listing for API use;
  • encrypted, geographically separated backups with regular restoration tests;
  • an annual independent penetration test and a documented incident-response process.

If a personal-data breach is likely to result in a risk to your rights, we notify the Data Protection Authority within 72 hours and inform affected persons without undue delay where the risk is high. Where we act as processor, we notify the responsible client within 24 hours of becoming aware of the breach, as set out in our Service Level Agreement.

15.Children and obligation to provide data

Our services are aimed at businesses and adults. We do not knowingly collect data from anyone under 18. If you believe a minor has given us data, tell us and we will delete it.

You are not legally obliged to give us personal data. Without the fields marked as required, however, we cannot answer your enquiry, conclude a contract or open an account. Investors must complete identity verification before a subscription can be accepted, because anti-money-laundering law requires it.

16.Changes to this policy

We publish changes here with a new version date. If we materially change how we process data of platform users, we also inform them by email or in the application. Earlier versions are available on request.

17.Contact

FLORIS³ GmbH, Salzgries 21/16, 1010 Vienna, Austria — hello@floris3.com. See also our Terms of Service and Impressum.