Privacy Policy

Version 3 · 25 Sept 2026

1. Controller

The controller responsible for the processing of personal data on the Platform within the meaning of Art 4 no. 7 GDPR is:

GZE Advisory / Gregor Zehetner
2540 Bad Vöslau, Austria
Email: privacy@fractionista.com

For the purposes of this Privacy Policy, "Fractionista", "we", or "us" means the above controller. "You" means the natural person whose personal data we process, typically the individual Account holder on the Platform, or a natural person acting for a Company User.

2. Scope

2.1 This Privacy Policy applies to personal data processed through the web application at app.fractionista.com and the authentication subdomain auth.fractionista.com (the "Platform").

2.2 The marketing website at fractionista.com / www.fractionista.com is a separate WordPress installation and is governed by a separate privacy notice. Where short versions of executive profiles from the Platform are embedded there (§7), this Policy applies to that data.

2.3 The Platform is offered exclusively to entrepreneurs (B2B). If you are acting for a legal entity, this Policy applies to your personal data as a natural person (e.g. your name, email, photo), while the legal entity itself is not a data subject under the GDPR.

2.4 The Platform is currently provided as a beta version, as is. Features, and with them the data we process, may still change during this phase; we update this Policy accordingly (§19). To build the best possible offering and user experience, we welcome any feedback as a valuable contribution (§20).

3. Definitions

Capitalised terms not defined here have the meaning given in the Terms of Service. "GDPR" means Regulation (EU) 2016/679. "DSG" means the Austrian Datenschutzgesetz. "Processing", "personal data", "controller", and "processor" are used as defined in Art 4 GDPR.

4. Categories of Personal Data We Process

We process the following categories of personal data, in each case only as necessary for the purposes set out in §5. The lists give examples; the forms on the Platform show which details are collected in each case.

4.1 Identity and Account data

Email address, first and last name, profile photo, language preference, your role on the Platform (executive, Company, asker, administrator) and, as the record of your acceptance of the Terms and this Policy, the time of acceptance, the version accepted and the IP address and browser used.

4.2 Executive profile data (if you register as a CxO Candidate)

  • Professional details, in particular biography, tagline, roles, industries, work areas, leadership experience, LinkedIn or XING profile URL, city and country.
  • Information on your entrepreneurial experience (companies founded or sold).
  • Your CV, uploaded as a PDF.
  • Profile-review material: your optional note to the reviewer, the AI-assisted review summary (§13), the review status and the reviewer's note when we ask for changes.
  • Availability, such as collaboration modes, hours per week and earliest start date.
  • Visibility preferences and your public profile URL.

4.3 Company data (if you register for a Company)

Contact email, company name and logo, company address, registry identifiers (commercial register number, registry court, VAT ID), website and LinkedIn URL, company description and the Company's review status.

4.4 Job Offer data

The details Company Users enter for a Job Offer, such as title, roles, location, collaboration type, period, scope, compensation type and description.

4.5 Engagement and activity data

  • Favourited Job Offers, applications and the messages exchanged between an executive and a Company about an application, questions and answers in the Ask the Experts programme, and requests for exploration calls.
  • Visits to public profiles and views of Job Offers, counted for statistics: without cookies, through a pseudonymous daily key derived from the IP address and browser, and for signed-in visitors additionally the account and its role. Executives receive, at most, aggregate counts for their own profile and never the identity of a viewer.
  • Notification preferences.

4.6 Billing data (Company subscribers only)

Subscription plan, term and status, and the identifiers our payment provider Stripe assigns to you (§10). Card data is handled by Stripe alone; we do not receive or store card numbers.

4.7 Technical and log data

Authentication cookies (§9), server logs kept by our hosting provider for a short rolling window (IP address, user agent, request path, status code), and anonymous, cookie-less performance telemetry (§9.2).

4.8 Audit trail

We keep a record of changes to profiles, Job Offers and settings: what changed, by whom and when.

5. Purposes and Legal Bases

The table below shows why we process each category of data and on which legal basis under Art 6 GDPR.

Purpose Categories (§4) Legal basis Creating your Account, authenticating you, providing the Platform, letting you publish and discover profiles and offers 4.1, 4.2, 4.3, 4.4, 4.5, 4.7 Art 6(1)(b) GDPR: performance of the contract with you (the Terms of Service) Forwarding questions and call requests to executives (§7) 4.1, 4.5 Art 6(1)(b) GDPR: performance of the contract with you (the Terms of Service) Processing Company subscriptions, issuing invoices, handling failed payments 4.1 (Company), 4.3, 4.6 Art 6(1)(b): contract; and Art 6(1)(c): legal obligation (tax / accounting law, in particular BAO, UGB) Sending transactional emails (sign-in codes, welcome, review outcomes, admin notifications) 4.1 Art 6(1)(b): contract Review of submitted executive profiles against our published criteria for activation, including the AI-assisted plausibility check described in §13; review of Company registrations 4.2 (including the CV), 4.3, 4.8 Art 6(1)(b): steps prior to entering into a contract, taken at your request; in the alternative Art 6(1)(f): legitimate interest in the integrity and quality of the marketplace Security, fraud prevention, abuse monitoring, enforcement of the Terms (including the anti-scraping provisions of the Terms) 4.1, 4.7, 4.8 Art 6(1)(f): legitimate interest in the security of the Platform and its Users Maintaining the audit trail for dispute resolution, security forensics, and regulatory compliance 4.8 Art 6(1)(f): legitimate interest; and Art 6(1)(c) where applicable Measuring aggregated performance of the Platform via Vercel Speed Insights (cookie-less, no personal profiles) 4.7 Art 6(1)(f): legitimate interest in operating a performant service Sending non-transactional communications (e.g. newsletter) if you opt in 4.1, 4.5 Art 6(1)(a): your consent (withdrawable at any time) Responding to authorities, enforcing or defending legal claims Any of the above Art 6(1)(c) or (f)

Our legitimate-interest analysis for Art 6(1)(f) purposes weighs the interests above against your reasonable expectations and the limited scope of the data processed. You may object to any legitimate-interest-based processing as described in §16.

6. Source of Data

Most personal data is collected directly from you. If you choose Google sign-in, we receive a limited set of profile data from Google (given name, family name, email, avatar URL). You can avoid this by signing in with the one-time code we email you instead. We do not enrich your profile with data obtained from third-party data brokers. The CV you upload and the links you name as evidence of a company sale also come from you; we retrieve those pages as needed for the purpose of the profile review. The AI model used in that review (§13) never accesses your LinkedIn or XING profile; our reviewers may open the link you gave us to check your details.

7. Who Sees Your Data on the Platform

The Platform shows your profile data in tiers, depending on the role and subscription of the viewing person. Visitors who are not signed in and other executives see a short version only (first name with the initial of your last name, country, roles, tagline); signed-in Companies see more depending on the situation or their subscription, up to the full profile with photo. Fractionista reserves the right to vary the set of information shown in order to optimise the marketing of your profile. Your CV may be made accessible to a Company in the course of establishing a direct contact.

Company profiles and Job Offers are generally visible to all authenticated Users and may, depending on settings, be surfaced on public pages.

Marketing website. If you, as an executive, switch on the option to be shown on our website, the short version of your profile (photo, first name with the initial of your last name, roles, country, tagline, and whether you accept questions or exploration calls) also appears in the overviews embedded on fractionista.com, which anyone can see without signing in. Your public profile page and that short version can be indexed by search engines. Both cease as soon as you switch the option or your profile's public visibility off. Copies in search-engine indexes, AI language models and caches may remain visible after the public profile display has been switched off; Fractionista has no influence over these and similar mechanisms.

Ask the Experts and exploration calls. We review questions and call requests addressed to an executive before forwarding them. The executive receives the request with the requester's name and company; the requester may receive an answer from the executive. An exploration call is arranged through the appointment-booking service the executive names, whose own privacy policy applies.

Data made accessible to a third party in the course of establishing a direct contact may be copied, stored or shared by that party in breach of the Terms. The Terms prohibit this; we are not liable for the conduct of third parties after disclosure.

8. Storage of Profile Photos, Company Logos and CVs

Profile photos and Company logos are stored in a private cloud-storage bucket operated by Supabase. Access is controlled by short-lived signed URLs issued by the Platform in accordance with the tiered visibility rules in §7. When a User disables publication or deletes their account, new signed URLs are no longer issued, and any previously issued signed URL expires within minutes.

The CV you upload is stored in a separate private bucket with no public access at all and is read only through short-lived links: by the review process, by administrators and, in the case described in §7, by a Company.

9. Cookies and Similar Technologies

We use only strictly necessary cookies and minimal, cookie-less performance measurement. We do not use any advertising cookies, tracking pixels, cross-site trackers, or third-party analytics services (no Google Analytics, no Meta Pixel, no Hotjar, no LinkedIn Insight Tag).

9.1 Strictly necessary cookies

  • sb-<project-ref>-auth-token: set by Supabase to maintain your authenticated session. HttpOnly, Secure, SameSite=Lax. Rolling lifetime, refreshed per session.
  • NEXT_LOCALE (or equivalent next-intl cookie): stores your chosen interface language. Default lifetime one year.

These cookies are strictly necessary to provide the Platform you have requested and do not require consent under § 165(3) TKG 2021 (Austrian implementation of Art 5(3) ePrivacy Directive).

9.2 Cookie-less performance measurement

We use Vercel Speed Insights to collect anonymous, aggregated performance metrics (page load times, core web vitals). Vercel Speed Insights does not set any cookies and does not build user profiles. Legal basis: Art 6(1)(f) GDPR, our legitimate interest in the operability of the Service. You may object as described in §16.

10. Recipients and Processors

We disclose personal data only to the categories of recipients listed below. Recipients that process data on our behalf (processors) act on our documented instructions under a data-processing agreement in accordance with Art 28 GDPR; the other recipients listed are independent controllers.

Recipient Function Data shared Location of processing Safeguards Supabase (Supabase Inc., via Supabase EU entity) Database, authentication, storage All Account, profile, offer, subscription, audit and storage data (§4.1 to 4.8) EU region (Frankfurt) DPA (GDPR addendum); EU-hosted data; SCCs where onward transfers occur Vercel (Vercel Inc.) Application hosting, CDN, serverless functions, Speed Insights HTTP requests, IP, user-agent, performance metrics Frankfurt (EU) for primary hosting; Vercel's global edge network for static assets DPA; EU-US Data Privacy Framework (for US processing by parent entity); SCCs Stripe (Stripe Payments Europe Ltd.) Payment processing, subscription management, invoicing (Company Users only) Company name, billing email, billing address, VAT ID, card data (handled by Stripe; not passed to us), transaction data Ireland (EU); some processing in the US by Stripe Inc. DPA; EU-US Data Privacy Framework; SCCs; PCI-DSS Resend (Resend, Inc.) Transactional email delivery Recipient email, first name, email subject and body EU region (Frankfurt) DPA; EU-US Data Privacy Framework; SCCs Anthropic (Anthropic Ireland, Ltd.) AI language model for the review of executive profiles (§13) Profile details without name, photo and contact data; the CV text without name and contact data; the content of the evidence pages you named; the model's summary Anthropic infrastructure in the USA DPA (Art 28); EU Standard Contractual Clauses (Module 2); no training on our data; inputs and outputs deleted within 30 days Google (Google Ireland Ltd.), only if you use Google sign-in OAuth authentication; we receive your given name, family name, email and avatar URL from Google Authentication handshake data Global (Google infrastructure) EU-US Data Privacy Framework; SCCs; your use of Google sign-in is optional (sign-in with an emailed one-time code is the alternative) Our legal, tax, and IT advisors Professional advice, accounting, support Only what is necessary for the engagement EU/EEA Professional secrecy obligations; DPAs where applicable Competent authorities Compliance with binding legal requests Only what is legally required Austria / EU Statutory basis

We do not sell personal data. We do not share personal data with advertising networks.

11. International Data Transfers

Our infrastructure is hosted in the EU. Some of the processors listed in §10 process data in the United States. Those transfers rest on the EU-US Data Privacy Framework adequacy decision where the processor is certified under it, and otherwise on the EU Standard Contractual Clauses, which form part of our contract with the processor. You may request a copy of the safeguards applicable to a transfer at privacy@fractionista.com.

12. Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, and thereafter only as required by law.

Data Retention Active Account data (§4.1 to 4.5, §4.7) For the duration of the Account. Inactive Accounts We reserve the right to delete Accounts that have had no successful sign-in for an extended period, typically at least 24 months. Where practicable, we will notify you in advance and give you a reasonable opportunity to reactivate the Account before deletion. Soft-deleted Accounts 28 days after the deletion request or the inactivity-based soft-deletion. During this grace period the Account can be restored on request. After the grace period, the Account and cascading personal data are permanently deleted. Billing and transactional data (§4.6) 7 years from the end of the relevant fiscal year, as required by § 132 BAO and § 212 UGB (Austrian tax and commercial law). This includes a mirror of relevant Stripe webhook events. Audit log (§4.8) For the duration of the Account, so that changes remain traceable; deleted with the Account. CV (§4.2) For the duration of the Account; deleted with the Account. AI-assisted review summary (§13) 24 months from its creation, as the record that the decision was made by a person. Note to the reviewer (§4.2) Deleted with the next decision on the profile. Waiting-list entries 24 months from joining the list. Before expiry we ask you whether you want to stay on it. Server logs (Vercel) Short rolling window managed by Vercel (approximately 24 hours by default). Transactional email logs (Resend) Approximately 30 days on Resend's side. Data retained under a legal hold (litigation, regulatory investigation) For the duration of the hold.

13. AI-Assisted Review of Submitted Profiles

When you submit your executive profile for review, we check your details for completeness, consistency and whether they meet our published criteria for activation (see the Terms). A large language model provided by Anthropic supports us in this. The model receives the information from your profile, from which we first remove your name, photo and contact details, the text of the CV you upload as a PDF, from which name and contact details are removed in the same way, and the content of the pages you name as evidence of a company sale. From this it prepares a summary of observations and open questions for our review.

The decision to activate your profile, to ask for changes or to invite you to the waiting list is always made by a member of the Fractionista team. There is no decision based solely on automated processing within the meaning of Art 22 GDPR (see §14). If we ask you for changes, you can leave us a note when you resubmit; only we see that note, and we delete it once we have decided.

The legal basis is Art 6(1)(b) GDPR (steps prior to entering into a contract, taken at your request) and, in the alternative, our legitimate interest in the quality and security of the Platform (Art 6(1)(f) GDPR). Where we rely on our legitimate interest, you may object on grounds relating to your particular situation (§16).

Anthropic Ireland, Ltd., Dublin (Ireland), processes the data on our behalf as a processor under Art 28 GDPR. Processing takes place on servers in the USA; that transfer is based on the EU Standard Contractual Clauses, which form part of our contract with Anthropic (§10, §11). Anthropic does not use the data to train its models and deletes inputs and outputs within 30 days. Only where content is identified as a violation of Anthropic's usage policies does Anthropic retain it for up to two years.

We keep the model's summary for at most 24 months (§12).

We are still exploring further features that may involve additional processing of personal data: algorithmic matching and ranking of CxO Candidates against Job Offers (and vice versa), and AI-assisted recommendations surfaced in the user interface. Neither is live at the date of this Policy. Before we activate any such feature, we will update this Policy, notify you in a reasonable manner and, where the feature would involve automated decision-making with legal or similarly significant effects within the meaning of Art 22 GDPR, obtain the legal basis required by that provision (typically your explicit consent).

14. Automated Decision-Making

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Art 22 GDPR. The profile review in §13 is supported by an AI model, but every decision on a profile (activation, a request for changes, an invitation to the waiting list, suspension) is made by a human reviewer who reads the model's summary and the profile itself; the summary contains no score and triggers nothing on its own. Technical filtering and search (e.g. narrowing Job Offer lists by country) is not automated decision-making in the Art 22 sense.

If this changes, the last paragraph of §13 applies.

15. Security

We protect personal data through appropriate technical and organisational measures under Art 32 GDPR, in particular encryption in transit and at rest, role-based access restrictions and the contractual obligations of our processors (§10, §11).

No system is ever completely secure. If we become aware of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority (Austrian DSB) without undue delay and, where the risk is high, notify affected Users in accordance with Art 33-34 GDPR.

Security vulnerabilities can be reported to security@fractionista.com.

16. Your Rights

Under Chapter III of the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art 15): confirmation whether we process your data and, if so, a copy together with the prescribed information.
  • Right to rectification (Art 16): correction of inaccurate data and completion of incomplete data. Most fields can also be corrected by you directly in your Account settings.
  • Right to erasure ("right to be forgotten", Art 17): deletion of your data where one of the listed grounds applies. The self-service Account deletion flow on the Platform is the fastest path.
  • Right to restriction (Art 18): restriction of processing in the situations listed in Art 18.
  • Right to data portability (Art 20): receipt of the data you have provided to us in a structured, commonly used, machine-readable format.
  • Right to object (Art 21): objection, on grounds relating to your particular situation, to any processing based on Art 6(1)(f) (our legitimate interests). You may object to direct-marketing processing (if we ever undertake any) at any time without giving reasons.
  • Right to withdraw consent (Art 7(3)): withdrawal of any consent you have given (e.g. to newsletters), without affecting the lawfulness of processing already performed.
  • Right to lodge a complaint with a supervisory authority (Art 77): in Austria, the Österreichische Datenschutzbehörde (DSB), Barichgasse 40-42, 1030 Vienna, www.dsb.gv.at. You may also lodge a complaint with the supervisory authority of your habitual residence or place of work.

To exercise any of these rights, email us at privacy@fractionista.com. We will respond without undue delay and in any event within one month of receipt (extendable by two months for complex requests, with notice to you). We may ask for proof of identity where reasonably necessary to prevent unauthorised disclosure.

17. Data Protection Officer

We are not required to appoint a data protection officer under Art 37 GDPR. The general privacy contact is privacy@fractionista.com.

18. Children

The Platform is not intended for and not directed at persons under eighteen (18) years of age. We do not knowingly process the personal data of minors. If we become aware that we have collected data from a minor, we will delete it without delay.

19. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, our processors or applicable law. When we publish a new version, we present it to you the next time you use the Platform and ask for your renewed acceptance; material changes are additionally announced by email where we hold your address. Each version applies from the date it is published.

Each version of this Policy carries a version identifier and an effective date; the version currently in force is the one that applies to your use of the Platform.

20. Contact

Fractionista, operated by GZE Advisory / Gregor Zehetner, 2540 Bad Vöslau, Austria
Privacy: privacy@fractionista.com
Security reports: security@fractionista.com