Floreo
Lab

Privacy Policy

Version: 1.1 | Effective Date: Oct 9, 2026

This Privacy Policy explains how Floreo processes personal data when you use the Floreo Lab platform. We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and the Austrian Data Protection Act (DSG).

1.Controller

The controller within the meaning of Art. 4(7) GDPR is:

  • Cassio Dounis Accioly, operating the platform under the name Floreo Lab
  • Neustiftgasse 48, 1070 Vienna, Austria
  • Email: support@floreolab.com

Full provider details are available in our Imprint.

No data protection officer has been appointed, as the conditions of Art. 37 GDPR are not met.


2.What Personal Data We Process

Depending on your interaction with the Platform, we may process the following categories of personal data:

2.1 Account Data
  • Email address
  • Encrypted password
  • Account creation date
  • Terms acceptance timestamp
  • IP address at registration
  • User agent (browser/device information)
2.2 Portfolio & Financial Data
  • Assets added to your portfolio
  • Transaction data entered by you

This data is provided voluntarily by you.

2.3 Technical & Usage Data
  • IP address
  • Log files
  • Device type
  • Browser type
  • Operating system
  • Date and time of access
  • API usage logs
  • Error and performance reports (see Section 5)
2.4 Communication Data
  • Emails sent to support
  • Feedback messages
  • Support inquiries
  • AI chat interactions (see Sections 4 and 8)
2.5 Payment Data
  • Billing information
  • Subscription status
  • Payment identifiers

Payment processing may be handled by external payment providers.


3.Legal Basis for Processing (Art. 6 GDPR)

We process your data based on the following legal grounds:

3.1 Contract Performance (Art. 6(1)(b) GDPR)

Processing necessary to provide the Service, including:

  • Account management
  • Portfolio tracking
  • Allocation data and insights
  • Performance calculations
  • User authentication
  • Provide AI-based portfolio insights
3.2 Legitimate Interests (Art. 6(1)(f) GDPR)

Processing necessary for:

  • IT security
  • Fraud prevention
  • System monitoring
  • Service improvement
  • Debugging and stability

Our legitimate interest lies in ensuring the secure and reliable operation of the Platform.

3.3 Consent (Art. 6(1)(a) GDPR)

If applicable:

  • Marketing emails
  • Analytics cookies
  • Optional tracking technologies
  • Optional AI personalization features

You may withdraw consent at any time.


4.AI-Based Features

The Platform may offer AI-powered features, including:

  • AI chat assistance
  • Portfolio analysis explanations
  • Risk commentary
  • Performance summaries

These features use external Large Language Models (LLMs).


5.Data Sharing & Processors (Art. 28 GDPR)

5.1 Providers

We use carefully selected service providers who process data on our behalf:

Hosting Provider
  • DigitalOcean, LLC – application and database hosting in the Frankfurt (Germany) region
Email Provider
  • Twilio SendGrid – transactional emails (account verification, password resets, alerts)
Error and Performance Monitoring
  • Sentry (Functional Software, Inc.) – error and performance monitoring, using Sentry's EU data region. Error reports may contain your IP address, browser information and the page or request in which the error occurred.
AI Service Providers
  • OpenAI – ChatGPT models
  • Google – Gemini models

These providers act as processors under Art. 28 GDPR and are bound by Data Processing Agreements (DPAs).

5.2 Anonymization & Minimization

To provide AI functionality, selected portfolio-related information may be transmitted to third-party AI model providers.

At transmission only strict necessary financial data is transmitted. The following data are NOT transmitted:

  • Direct identifiers (name, email)
  • User IDs
  • Authentication credentials

We apply data minimization principles (Art. 5(1)(c) GDPR).


6.International Data Transfers

Hosting and error monitoring take place within the EU/EEA. Our AI providers (OpenAI, Google) and our email provider (Twilio SendGrid) may process data outside the European Economic Area (EEA), including the United States.

Where such transfers occur, we rely on:

  • Standard Contractual Clauses (SCCs)
  • EU adequacy decisions
  • EU–US Data Privacy Framework (if applicable)

7.No Automated Decision-Making (Art. 22 GDPR)

AI-generated responses:

  • Are informational only
  • Do not produce legally binding decisions
  • Do not replace financial advice
  • Do not automatically execute transactions

Users remain fully responsible for investment decisions.


8.Confidentiality of AI Interactions

AI chat messages:

  • May be temporarily stored for context
  • May be logged for security and abuse prevention
  • Are not used to build user profiles for advertising

If future AI training on aggregated, anonymized data is introduced, this will only occur in compliance with GDPR.


9.Cookies & Tracking Technologies

The Platform currently uses only strictly necessary cookies and comparable browser storage, required for:

  • Authentication and session management
  • Security (e.g. protection against cross-site request forgery)
  • Storing your interface preferences (e.g. language, colour mode)

These are necessary to provide the service you requested and therefore do not require consent under § 165(3) of the Austrian Telecommunications Act (TKG 2021).

We do not currently use analytics, advertising or cross-site tracking cookies. Should such technologies be introduced, they will only be activated after your explicit consent, which you may withdraw at any time.


10.Data Retention

  • Account data: stored while account exists
  • Portfolio data: stored until deletion
  • AI interaction logs: retained only as necessary for functionality and security
  • Log files: retained for limited security periods

When you delete your account, your account and portfolio data are deleted immediately and irreversibly from the live system. Residual copies contained in encrypted backups are overwritten within 30 days.

Data that we are required to retain under statutory obligations (e.g. accounting records for invoiced payments) is kept for the retention period prescribed by law and then deleted.


11.Your Rights

You have the right to:

  • Access your data
  • Correct inaccurate data
  • Delete your data
  • Export your data
  • Restrict processing
  • Object to processing
  • Withdraw consent

You also have the right to lodge a complaint with a supervisory authority. The competent authority for us is:

Österreichische Datenschutzbehörde (Austrian Data Protection Authority) Barichgasse 40–42, 1030 Vienna, Austria — dsb@dsb.gv.at, www.dsb.gv.at


12.Minors

The Service is not directed at persons under 18 years of age, and creating an account requires you to be at least 18 (see our Terms of Service). We do not knowingly process the personal data of minors. If we become aware that we have done so, the data will be deleted.


13.Security Measures

We implement:

  • HTTPS encryption
  • Secure password hashing
  • Access control mechanisms
  • Encrypted backups
  • Infrastructure security monitoring

We apply appropriate safeguards when transmitting data to AI providers.


14.Changes to This Policy

We may update this Privacy Policy to reflect:

  • Legal changes
  • Technical changes
  • Introduction of new AI features

Material changes will be communicated via email or platform notification.


15.Contact

For all data protection inquiries, please contact us at:

See also our Imprint and our Terms of Service.