Privacy policy
Last updated September 2026 · Template — review with counsel before production use.
This policy explains what personal data 3f3 processes, why, on what lawful basis, and the rights you have. 3f3 is operated as an internal communication tool licensed to your employer (“the company”), which is the data controller for your messages and account. The platform operator acts as a processor on the company's instructions.
1. Data we process
- Account data: display name, email address, username, company membership, role.
- Authentication data: a salted argon2id password hash, an encrypted TOTP secret (AES-256-GCM), WebAuthn public keys, hashed recovery codes, and session records (IP address, user-agent, timestamps).
- Content you create: messages, uploaded files and images, link previews, contacts, read state.
- Operational logs: an audit trail of security-relevant admin actions (password resets, role and licence changes).
We practise data minimisation: no marketing profile, no behavioural tracking, no third-party analytics or advertising SDKs are present in the product.
2. Lawful bases (GDPR Art. 6)
- Contract / legitimate interests of the company (Art. 6(1)(b)/(f)): providing an internal messaging service to its staff.
- Legal obligation (Art. 6(1)(c)): retaining audit records where required.
- Consent (Art. 6(1)(a)): only where explicitly requested, e.g. accepting these terms at account creation. Consent can be withdrawn at any time.
3. Where data is hosted
3f3 is designed to be hosted entirely within the European Union. The database and object storage endpoints are configuration values; this deployment is operated with EU-region infrastructure and no data is transferred to a non-EU provider by the application itself. If your operator changes this, they must update this section and put an appropriate transfer mechanism in place.
4. Retention
- Messages and files: kept for the life of the workspace, or until deleted by a user or administrator. A lapsed licence locks access but does not delete data.
- Sessions: until expiry, logout, or revocation.
- Audit log: retained for security and compliance purposes.
- On account erasure: personal identifiers are overwritten within the grace period described below.
5. Security
- Transport encryption (HTTPS/WSS) is enforced in production, including HSTS.
- Passwords are hashed with argon2id and an application-side pepper; TOTP secrets are encrypted at rest.
- Two-factor authentication (TOTP and WebAuthn passkeys) is available and can be made mandatory by your company.
- Rate limiting protects authentication endpoints. Uploaded files pass through an antivirus hook.
- Tenancy isolation is enforced at the database level: a user belongs to exactly one company and conversations never cross that boundary.
6. Your rights
You can exercise the following at any time, in Settings → Privacy & data, or by contacting your company administrator:
- Access & portability (Art. 15/20): download a machine-readable export of your data.
- Erasure (Art. 17): request deletion of your account. Erasure runs after a 7-day grace period during which you can cancel. Your past messages are retained but attributed to “Erased user”.
- Rectification (Art. 16): correct your profile, or ask an administrator to.
- Complaint: you may lodge a complaint with your local supervisory authority.
7. Cookies
3f3 sets a single strictly-necessary, HttpOnly session cookie. It carries an opaque identifier only, is not used for tracking, and needs no consent banner. No other cookies are set.
8. Sub-processors
The core product uses no third-party data processors. Any infrastructure provider engaged by your operator to host the EU database/storage must be listed here by that operator, with a data-processing agreement in place.