Version 3 · 25 Sept 2026
The controller responsible for the processing of personal data on the Platform within the meaning of Art 4 no. 7 GDPR is:
GZE Advisory / Gregor Zehetner
2540 Bad Vöslau, Austria
Email: privacy@fractionista.com
For the purposes of this Privacy Policy, "Fractionista", "we", or "us" means the above controller. "You" means the natural person whose personal data we process, typically the individual Account holder on the Platform, or a natural person acting for a Company User.
2.1 This Privacy Policy applies to personal data processed through the web application at app.fractionista.com and the authentication subdomain auth.fractionista.com (the "Platform").
2.2 The marketing website at fractionista.com / www.fractionista.com is a separate WordPress installation and is governed by a separate privacy notice. Where short versions of executive profiles from the Platform are embedded there (§7), this Policy applies to that data.
2.3 The Platform is offered exclusively to entrepreneurs (B2B). If you are acting for a legal entity, this Policy applies to your personal data as a natural person (e.g. your name, email, photo), while the legal entity itself is not a data subject under the GDPR.
2.4 The Platform is currently provided as a beta version, as is. Features, and with them the data we process, may still change during this phase; we update this Policy accordingly (§19). To build the best possible offering and user experience, we welcome any feedback as a valuable contribution (§20).
Capitalised terms not defined here have the meaning given in the Terms of Service. "GDPR" means Regulation (EU) 2016/679. "DSG" means the Austrian Datenschutzgesetz. "Processing", "personal data", "controller", and "processor" are used as defined in Art 4 GDPR.
We process the following categories of personal data, in each case only as necessary for the purposes set out in §5. The lists give examples; the forms on the Platform show which details are collected in each case.
Email address, first and last name, profile photo, language preference, your role on the Platform (executive, Company, asker, administrator) and, as the record of your acceptance of the Terms and this Policy, the time of acceptance, the version accepted and the IP address and browser used.
Contact email, company name and logo, company address, registry identifiers (commercial register number, registry court, VAT ID), website and LinkedIn URL, company description and the Company's review status.
The details Company Users enter for a Job Offer, such as title, roles, location, collaboration type, period, scope, compensation type and description.
Subscription plan, term and status, and the identifiers our payment provider Stripe assigns to you (§10). Card data is handled by Stripe alone; we do not receive or store card numbers.
Authentication cookies (§9), server logs kept by our hosting provider for a short rolling window (IP address, user agent, request path, status code), and anonymous, cookie-less performance telemetry (§9.2).
We keep a record of changes to profiles, Job Offers and settings: what changed, by whom and when.
The table below shows why we process each category of data and on which legal basis under Art 6 GDPR.
Purpose Categories (§4) Legal basis Creating your Account, authenticating you, providing the Platform, letting you publish and discover profiles and offers 4.1, 4.2, 4.3, 4.4, 4.5, 4.7 Art 6(1)(b) GDPR: performance of the contract with you (the Terms of Service) Forwarding questions and call requests to executives (§7) 4.1, 4.5 Art 6(1)(b) GDPR: performance of the contract with you (the Terms of Service) Processing Company subscriptions, issuing invoices, handling failed payments 4.1 (Company), 4.3, 4.6 Art 6(1)(b): contract; and Art 6(1)(c): legal obligation (tax / accounting law, in particular BAO, UGB) Sending transactional emails (sign-in codes, welcome, review outcomes, admin notifications) 4.1 Art 6(1)(b): contract Review of submitted executive profiles against our published criteria for activation, including the AI-assisted plausibility check described in §13; review of Company registrations 4.2 (including the CV), 4.3, 4.8 Art 6(1)(b): steps prior to entering into a contract, taken at your request; in the alternative Art 6(1)(f): legitimate interest in the integrity and quality of the marketplace Security, fraud prevention, abuse monitoring, enforcement of the Terms (including the anti-scraping provisions of the Terms) 4.1, 4.7, 4.8 Art 6(1)(f): legitimate interest in the security of the Platform and its Users Maintaining the audit trail for dispute resolution, security forensics, and regulatory compliance 4.8 Art 6(1)(f): legitimate interest; and Art 6(1)(c) where applicable Measuring aggregated performance of the Platform via Vercel Speed Insights (cookie-less, no personal profiles) 4.7 Art 6(1)(f): legitimate interest in operating a performant service Sending non-transactional communications (e.g. newsletter) if you opt in 4.1, 4.5 Art 6(1)(a): your consent (withdrawable at any time) Responding to authorities, enforcing or defending legal claims Any of the above Art 6(1)(c) or (f)Our legitimate-interest analysis for Art 6(1)(f) purposes weighs the interests above against your reasonable expectations and the limited scope of the data processed. You may object to any legitimate-interest-based processing as described in §16.
Most personal data is collected directly from you. If you choose Google sign-in, we receive a limited set of profile data from Google (given name, family name, email, avatar URL). You can avoid this by signing in with the one-time code we email you instead. We do not enrich your profile with data obtained from third-party data brokers. The CV you upload and the links you name as evidence of a company sale also come from you; we retrieve those pages as needed for the purpose of the profile review. The AI model used in that review (§13) never accesses your LinkedIn or XING profile; our reviewers may open the link you gave us to check your details.
The Platform shows your profile data in tiers, depending on the role and subscription of the viewing person. Visitors who are not signed in and other executives see a short version only (first name with the initial of your last name, country, roles, tagline); signed-in Companies see more depending on the situation or their subscription, up to the full profile with photo. Fractionista reserves the right to vary the set of information shown in order to optimise the marketing of your profile. Your CV may be made accessible to a Company in the course of establishing a direct contact.
Company profiles and Job Offers are generally visible to all authenticated Users and may, depending on settings, be surfaced on public pages.
Marketing website. If you, as an executive, switch on the option to be shown on our website, the short version of your profile (photo, first name with the initial of your last name, roles, country, tagline, and whether you accept questions or exploration calls) also appears in the overviews embedded on fractionista.com, which anyone can see without signing in. Your public profile page and that short version can be indexed by search engines. Both cease as soon as you switch the option or your profile's public visibility off. Copies in search-engine indexes, AI language models and caches may remain visible after the public profile display has been switched off; Fractionista has no influence over these and similar mechanisms.
Ask the Experts and exploration calls. We review questions and call requests addressed to an executive before forwarding them. The executive receives the request with the requester's name and company; the requester may receive an answer from the executive. An exploration call is arranged through the appointment-booking service the executive names, whose own privacy policy applies.
Data made accessible to a third party in the course of establishing a direct contact may be copied, stored or shared by that party in breach of the Terms. The Terms prohibit this; we are not liable for the conduct of third parties after disclosure.
Profile photos and Company logos are stored in a private cloud-storage bucket operated by Supabase. Access is controlled by short-lived signed URLs issued by the Platform in accordance with the tiered visibility rules in §7. When a User disables publication or deletes their account, new signed URLs are no longer issued, and any previously issued signed URL expires within minutes.
The CV you upload is stored in a separate private bucket with no public access at all and is read only through short-lived links: by the review process, by administrators and, in the case described in §7, by a Company.
We use only strictly necessary cookies and minimal, cookie-less performance measurement. We do not use any advertising cookies, tracking pixels, cross-site trackers, or third-party analytics services (no Google Analytics, no Meta Pixel, no Hotjar, no LinkedIn Insight Tag).
sb-<project-ref>-auth-token: set by Supabase to maintain your authenticated session. HttpOnly, Secure, SameSite=Lax. Rolling lifetime, refreshed per session.NEXT_LOCALE (or equivalent next-intl cookie): stores your chosen interface language. Default lifetime one year.These cookies are strictly necessary to provide the Platform you have requested and do not require consent under § 165(3) TKG 2021 (Austrian implementation of Art 5(3) ePrivacy Directive).
We use Vercel Speed Insights to collect anonymous, aggregated performance metrics (page load times, core web vitals). Vercel Speed Insights does not set any cookies and does not build user profiles. Legal basis: Art 6(1)(f) GDPR, our legitimate interest in the operability of the Service. You may object as described in §16.
We disclose personal data only to the categories of recipients listed below. Recipients that process data on our behalf (processors) act on our documented instructions under a data-processing agreement in accordance with Art 28 GDPR; the other recipients listed are independent controllers.
Recipient Function Data shared Location of processing Safeguards Supabase (Supabase Inc., via Supabase EU entity) Database, authentication, storage All Account, profile, offer, subscription, audit and storage data (§4.1 to 4.8) EU region (Frankfurt) DPA (GDPR addendum); EU-hosted data; SCCs where onward transfers occur Vercel (Vercel Inc.) Application hosting, CDN, serverless functions, Speed Insights HTTP requests, IP, user-agent, performance metrics Frankfurt (EU) for primary hosting; Vercel's global edge network for static assets DPA; EU-US Data Privacy Framework (for US processing by parent entity); SCCs Stripe (Stripe Payments Europe Ltd.) Payment processing, subscription management, invoicing (Company Users only) Company name, billing email, billing address, VAT ID, card data (handled by Stripe; not passed to us), transaction data Ireland (EU); some processing in the US by Stripe Inc. DPA; EU-US Data Privacy Framework; SCCs; PCI-DSS Resend (Resend, Inc.) Transactional email delivery Recipient email, first name, email subject and body EU region (Frankfurt) DPA; EU-US Data Privacy Framework; SCCs Anthropic (Anthropic Ireland, Ltd.) AI language model for the review of executive profiles (§13) Profile details without name, photo and contact data; the CV text without name and contact data; the content of the evidence pages you named; the model's summary Anthropic infrastructure in the USA DPA (Art 28); EU Standard Contractual Clauses (Module 2); no training on our data; inputs and outputs deleted within 30 days Google (Google Ireland Ltd.), only if you use Google sign-in OAuth authentication; we receive your given name, family name, email and avatar URL from Google Authentication handshake data Global (Google infrastructure) EU-US Data Privacy Framework; SCCs; your use of Google sign-in is optional (sign-in with an emailed one-time code is the alternative) Our legal, tax, and IT advisors Professional advice, accounting, support Only what is necessary for the engagement EU/EEA Professional secrecy obligations; DPAs where applicable Competent authorities Compliance with binding legal requests Only what is legally required Austria / EU Statutory basisWe do not sell personal data. We do not share personal data with advertising networks.
Our infrastructure is hosted in the EU. Some of the processors listed in §10 process data in the United States. Those transfers rest on the EU-US Data Privacy Framework adequacy decision where the processor is certified under it, and otherwise on the EU Standard Contractual Clauses, which form part of our contract with the processor. You may request a copy of the safeguards applicable to a transfer at privacy@fractionista.com.
We retain personal data only for as long as necessary for the purposes for which it was collected, and thereafter only as required by law.
Data Retention Active Account data (§4.1 to 4.5, §4.7) For the duration of the Account. Inactive Accounts We reserve the right to delete Accounts that have had no successful sign-in for an extended period, typically at least 24 months. Where practicable, we will notify you in advance and give you a reasonable opportunity to reactivate the Account before deletion. Soft-deleted Accounts 28 days after the deletion request or the inactivity-based soft-deletion. During this grace period the Account can be restored on request. After the grace period, the Account and cascading personal data are permanently deleted. Billing and transactional data (§4.6) 7 years from the end of the relevant fiscal year, as required by § 132 BAO and § 212 UGB (Austrian tax and commercial law). This includes a mirror of relevant Stripe webhook events. Audit log (§4.8) For the duration of the Account, so that changes remain traceable; deleted with the Account. CV (§4.2) For the duration of the Account; deleted with the Account. AI-assisted review summary (§13) 24 months from its creation, as the record that the decision was made by a person. Note to the reviewer (§4.2) Deleted with the next decision on the profile. Waiting-list entries 24 months from joining the list. Before expiry we ask you whether you want to stay on it. Server logs (Vercel) Short rolling window managed by Vercel (approximately 24 hours by default). Transactional email logs (Resend) Approximately 30 days on Resend's side. Data retained under a legal hold (litigation, regulatory investigation) For the duration of the hold.When you submit your executive profile for review, we check your details for completeness, consistency and whether they meet our published criteria for activation (see the Terms). A large language model provided by Anthropic supports us in this. The model receives the information from your profile, from which we first remove your name, photo and contact details, the text of the CV you upload as a PDF, from which name and contact details are removed in the same way, and the content of the pages you name as evidence of a company sale. From this it prepares a summary of observations and open questions for our review.
The decision to activate your profile, to ask for changes or to invite you to the waiting list is always made by a member of the Fractionista team. There is no decision based solely on automated processing within the meaning of Art 22 GDPR (see §14). If we ask you for changes, you can leave us a note when you resubmit; only we see that note, and we delete it once we have decided.
The legal basis is Art 6(1)(b) GDPR (steps prior to entering into a contract, taken at your request) and, in the alternative, our legitimate interest in the quality and security of the Platform (Art 6(1)(f) GDPR). Where we rely on our legitimate interest, you may object on grounds relating to your particular situation (§16).
Anthropic Ireland, Ltd., Dublin (Ireland), processes the data on our behalf as a processor under Art 28 GDPR. Processing takes place on servers in the USA; that transfer is based on the EU Standard Contractual Clauses, which form part of our contract with Anthropic (§10, §11). Anthropic does not use the data to train its models and deletes inputs and outputs within 30 days. Only where content is identified as a violation of Anthropic's usage policies does Anthropic retain it for up to two years.
We keep the model's summary for at most 24 months (§12).
We are still exploring further features that may involve additional processing of personal data: algorithmic matching and ranking of CxO Candidates against Job Offers (and vice versa), and AI-assisted recommendations surfaced in the user interface. Neither is live at the date of this Policy. Before we activate any such feature, we will update this Policy, notify you in a reasonable manner and, where the feature would involve automated decision-making with legal or similarly significant effects within the meaning of Art 22 GDPR, obtain the legal basis required by that provision (typically your explicit consent).
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Art 22 GDPR. The profile review in §13 is supported by an AI model, but every decision on a profile (activation, a request for changes, an invitation to the waiting list, suspension) is made by a human reviewer who reads the model's summary and the profile itself; the summary contains no score and triggers nothing on its own. Technical filtering and search (e.g. narrowing Job Offer lists by country) is not automated decision-making in the Art 22 sense.
If this changes, the last paragraph of §13 applies.
We protect personal data through appropriate technical and organisational measures under Art 32 GDPR, in particular encryption in transit and at rest, role-based access restrictions and the contractual obligations of our processors (§10, §11).
No system is ever completely secure. If we become aware of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority (Austrian DSB) without undue delay and, where the risk is high, notify affected Users in accordance with Art 33-34 GDPR.
Security vulnerabilities can be reported to security@fractionista.com.
Under Chapter III of the GDPR, you have the following rights regarding your personal data:
To exercise any of these rights, email us at privacy@fractionista.com. We will respond without undue delay and in any event within one month of receipt (extendable by two months for complex requests, with notice to you). We may ask for proof of identity where reasonably necessary to prevent unauthorised disclosure.
We are not required to appoint a data protection officer under Art 37 GDPR. The general privacy contact is privacy@fractionista.com.
The Platform is not intended for and not directed at persons under eighteen (18) years of age. We do not knowingly process the personal data of minors. If we become aware that we have collected data from a minor, we will delete it without delay.
We may update this Policy from time to time to reflect changes in our practices, our processors or applicable law. When we publish a new version, we present it to you the next time you use the Platform and ask for your renewed acceptance; material changes are additionally announced by email where we hold your address. Each version applies from the date it is published.
Each version of this Policy carries a version identifier and an effective date; the version currently in force is the one that applies to your use of the Platform.
Fractionista, operated by GZE Advisory / Gregor Zehetner, 2540 Bad Vöslau, Austria
Privacy: privacy@fractionista.com
Security reports: security@fractionista.com