FL3XX PRIVACY POLICY
Effective Date: 01 Aug 2025
Last Updated: 01 Aug 2025
FL3XX GmbH (“FL3XX”, “we”, “our”, or “us”) is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and protect your personal data when you interact with us via our websites, mobile apps, or services, in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR).
1. Who We Are
Controller:
FL3XX GmbH
Kolingasse 11
1090 Vienna, Austria
Email: legal@fl3xx.com
If you have questions or concerns about this Privacy Policy or how we handle your data, reach out to us.
Our appointed Data Protection Officer (DPO) can be contacted at the above address or via email.
2. What Data We Collect
Depending on how you interact with us, we may collect:
- Identification data: name, email address, company name, job title
- Contact data: phone number, mailing address
- Authentication data: login credentials, IP addresses
- Usage data: device data, browser type, pages visited, time spent, interactions
- Communication data: messages, support inquiries, chat logs
- Employment data (for applicants): CV, work history, qualifications
We do not knowingly collect personal data from children under 16.
3. How We Collect Your Data
- You provide it directly (e.g. when contacting us, signing up, or using our platform)
- It is collected automatically via cookies or analytics tools
- It may come from third-party integrations or business partners (e.g. CRM platforms)
4. Purposes and Legal Bases for Processing
| Purpose | Legal Basis (Art. 6 GDPR) |
| Provide and manage services | Contractual necessity (art. 6(1)8b)) |
| Respond to inquiries | Legitimate interest (art. 6(1)(f)) |
| Analyze and improve our website/services | Legitimate interest (art. 6(1)(f)); Consent (cookies) |
| Send marketing emails (where opted in) | Consent (Art. 6(1)(a)) |
| Fulfill legal obligations | Legal obligation (Art. 6(1)(c)) |
| Recruit personnel | Pre-contractual steps (Art. 6(1)(b) |
5. Data Sharing and Recipients
We may share your data with:
- Our affiliated companies and processors supporting service delivery
- Trusted third-party vendors (e.g. Amazon Web Services, HubSpot, Google Workspace)
- Legal or regulatory authorities if required by law
- External auditors for compliance (ISO, SOC2)
- Only where necessary, and always under appropriate safeguards
6. International Transfers
Some data may be processed outside the EEA (e.g. U.S.-based vendors). We use EU Standard Contractual Clauses (SCCs) and other safeguards to ensure your data is protected.
7. Cookies and Tracking
We use cookies and similar technologies for:
- Website functionality
- Analytics (e.g. HubSpot, Smartlook)
- Improving user experience
You can manage cookie preferences through your browser or by using our cookie banner.
8. Data Retention
We retain personal data only as long as necessary to fulfill the purposes above or comply with legal obligations. After that, data is securely deleted or anonymized.
9. Your Rights Under GDPR
You have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data (“right to be forgotten”) (Art. 17)
- Restrict or object to processing (Art. 18, 21)
- Data portability (Art. 20)
- Withdraw consent at any time (Art. 7(3))
- Lodge a complaint with a supervisory authority (e.g. Austrian DSB)
To exercise these rights, contact us at legal@fl3xx.com. We may request proof of identity before responding.
10. Data Security
We implement appropriate technical and organizational measures (TOMs) aligned with ISO 27001 and SOC 2 standards, including:
- Encryption
- Role-based access controls
- Regular audits and risk assessments
- Data breach response procedures
11. Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be posted here with a revised effective date. We encourage you to review it periodically.