Swiss software by Innopulse Consulting GmbH, ZugData stored in Switzerland (Zurich)Security & privacy
FLIORE

Privacy Policy

Last updated: 30 September 2026

This is a translation provided for convenience. The German version is legally binding; in case of any discrepancy, the German version prevails.

FLIORE is built for confidentiality. This policy explains what personal data we process, why, where it is hosted, who may access it, and the rights available to individuals. It is provided for transparency and does not replace the Data Processing Agreement (DPA) entered into with each organisation, which prevails in case of conflict.

1. Who is responsible (controller / processor)

FLIORE is operated by Innopulse Consulting GmbH, Gotthardstrasse 30, 6300 Zug, Switzerland (UID CHE-219.727.921). For personal data that an organisation uploads or processes through FLIORE (its mandates, beneficial owners, documents and transactions), the organisation is the controller and FLIORE acts as its processor, processing that data only on the organisation's documented instructions. For data we process about our own account holders (name, email address, authentication and billing data), FLIORE is the controller.

2. What data we process

As processor, on behalf of an organisation: mandate and entity records; beneficial-owner details (name, date of birth, nationality, PEP status); documents stored in the vault; transactions and bank-statement data; screening and risk-assessment results; messages. As controller, for account holders: name, email address, hashed authentication factors, language, role, logs and billing information. We do not intentionally collect sensitive personal data unless an organisation chooses to store it within its own documents.

3. Purposes and legal bases

To provide the service under our contract with the organisation; to secure the platform and prevent abuse (overriding legitimate interest); to meet legal and regulatory obligations; and, for account data, to administer billing. Where required, processing of personal data from the EU relies on the corresponding GDPR legal bases (contract, legal obligation, legitimate interest). FLIORE does not sell personal data and does not use client data for advertising.

4. Where data is hosted

FLIORE stores application data and documents on Swiss cloud infrastructure (Supabase, data centre in Zurich, Switzerland); Swiss data-protection law applies. Where a subprocessor processes limited data outside Switzerland (see the Subprocessors page), that disclosure is covered by appropriate safeguards such as the EU Standard Contractual Clauses with the Swiss addendum.

5. Subprocessors

FLIORE uses a small number of vetted subprocessors to run the service (hosting, email delivery, payments and the AI provider). Each is bound by data-protection terms and processes only the data needed for its function. The current list, with the purpose and location of each, is maintained on the Subprocessors page.

6. How data is protected

Two-factor authentication for every account, which each organisation can make mandatory for all of its members; row-level security enforcing strict separation of organisations at the database layer, so no organisation can access another's data; encrypted document storage served only through short-lived signed links; encryption of message content; and an audit trail of security-relevant actions. Access by our personnel is restricted, logged and used only to operate and support the service.

7. AI and your data

FLIORE AI answers only from the data of the respective mandate within the organisation and cites the data it draws on. When you ask the assistant a question, the relevant mandate context – which may include names and PEP flags of beneficial owners, asset and liability figures, KYC status and document titles – is sent to the configured AI provider (by default Anthropic; optionally OpenAI or Azure OpenAI) solely to generate that answer. Client data is never used to train models and is not retained by the provider for any other purpose. Each provider is listed on the Subprocessors page. Organisations can disable AI entirely or bring their own AI key (BYOK) so that requests run under their own provider agreement. AI output is decision support: it supports, but does not replace, the judgement of the responsible person.

8. Retention

As processor, we retain an organisation's data for the life of the account and delete or return it after termination in line with the DPA, subject to any retention the organisation must observe (for example statutory record-keeping periods under anti-money-laundering law). Account and billing data we hold as controller is retained for as long as the law requires. Logs are retained to meet security and regulatory requirements. When an organisation is deleted, we remove all of its data completely once the 30-day restoration period has passed – including stored files and the sign-in accounts of its members; the audit trail is kept as evidence where a retention duty applies.

9. Rights of individuals

Depending on applicable law (the Swiss Federal Act on Data Protection, FADP, and, for individuals in the EU, the GDPR), individuals may request access, correction, deletion, restriction and data portability, or object to certain processing. Because most personal data in FLIORE is under the responsibility of the organisation that uploaded it, requests about that data should be directed to that organisation; FLIORE assists it as processor. For data for which we are the controller, contact us directly.

10. International transfers

Where personal data is disclosed to a subprocessor outside Switzerland or the EEA, we rely on recognised transfer mechanisms (adequacy decision, EU Standard Contractual Clauses with the Swiss addendum) and apply additional technical measures such as encryption in transit.

11. Changes to this policy

We may update this policy to reflect changes in the service or the law. Material changes will be communicated to account holders. The date shown above always identifies the current version.

12. Website, contact form and support

FLIORE is the controller for this processing. When you visit the website, our hosting provider processes technically necessary data (IP address, time, requested address, browser identifier) to deliver the pages and defend against attacks; these logs are kept for a short period. If you request a demo through the form or write to us, we process your email address, any company details and your message to answer your request, and keep them for as long as this and any follow-up questions require. Support requests from the application are stored with your account and handled by our team. You may ask us to delete this data at any time.

13. Demo workspace

You can try FLIORE without registering in your own demo workspace with fictitious sample data. For this we create a technical account with a random address that is not linked to you; we ask for no email address and no payment details and send no emails from the demo. We process the data you enter in the demo yourself and your IP address, which is stored briefly to prevent abuse (limiting the number of demos) and then removed automatically. Access ends after 24 hours. We then delete the demo workspace completely – data, files and the technical account – at the latest 48 hours after it was created. You can end the demo yourself at any time; it is then deleted immediately. Please do not enter real personal or client data in the demo. The legal basis is our legitimate interest in demonstrating the software to interested parties, or pre-contractual measures.

14. Contact

Innopulse Consulting GmbH, Gotthardstrasse 30, 6300 Zug, Switzerland – hello@fliore.com.

This page is provided for transparency and general information. It is not legal advice. The Data Processing Agreement and applicable law govern the actual rights and obligations of the parties.

Privacy Policy · FLIORE