Updated: June 23, 2026
Introduction
RAIZERS places particular importance on respecting your privacy and protecting your personal data. In this regard, RAIZERS is committed to complying with applicable data protection regulations, including:
- Regulation (EU) 2016/679 of April 27, 2016, on data protection (the “GDPR”);
- Law No. 78-17 of January 6, 1978, as amended, known as the “Data Protection Act.”
These texts are collectively referred to in this policy as “Regulations.”To ensure transparency and fairness in data processing, the purpose of this Privacy Policy is to clearly explain:
- why we collect personal data,
- what data we collect,
- how we use it,
- how long we retain it,
- and what your rights are and how to exercise them.
The Privacy Policy applies to data concerning:
- individuals who visit the RAIZERS Platform (hereinafter the “Users”);
- individuals who register on the Platform and use the services offered (hereinafter “Users”);
- as well as any other natural person (customer, prospect) who provides personal information or data to RAIZERS in the course of its business activities.
Unless otherwise specified, the terms used in this Privacy Policy (e.g., “personal data,” “processing,” “data controller,” etc.) have the same meaning as defined by the GDPR.
1. Data Controller
RAIZERS SAS, a company registered under SIREN number 804 419 901, located at 15, rue du Colonel Driant, 75001 Paris, acts as the data controller for personal data processed in connection with its crowdfunding services.
RAIZERS PATRIMOINE, a company registered under SIREN number 884 244 112, located at 15, rue du Colonel Driant, 75001 Paris, acts as a separate data controller for personal data processed in connection with its insurance brokerage activities.
Each of these entities is responsible for the processing of personal data it carries out, in accordance with applicable regulations.
RAIZERS SAS and RAIZERS PATRIMOINE are both owned by RAIZERS SA, a company incorporated under Swiss law, registered in the Commercial Register of the Canton of Geneva under number CHE-405.531.212, located at Rue De-Candolle 20, 1205 Geneva. To facilitate the reading and understanding of this Privacy Policy, RAIZERS SAS and RAIZERS PATRIMOINE are collectively referred to hereinafter as “RAIZERS,” except where a specific distinction is necessary.
2. Type of Data Collected
RAIZERS collects personal data from individuals who visit its platform (the“Website Visitors”) or who register on it (the“Users”).
The personal data collected on the platform consists of information that enables RAIZERS to identify Users directly or indirectly for the purpose of providing the various services offered by the platform. This data is used by RAIZERS or by RAIZERS’ service providers or subcontractors.
3. Purpose of Processing
As part of its activities, RAIZERS processes personal data (hereinafter the “Data”) in accordance with one or more of the legal bases set forth in Article 6 of the GDPR:
- You create an account on the Platform;
- You wish to prepare and submit an application to RAIZERS or one of our partners.
Legal basis: prior consent, legitimate interests, necessary for the performance of precontractual measures and the performance of the contract, necessary to comply with legal obligations applicable to the activity of a crowdfunding and/or insurance brokerage service provider.
- Communication and customer loyalty initiatives.
Legal bases: consent and legitimate interests.
- Sending the newsletter to subscribers.
Legal basis: consent
- Managing the follow-up to received requests and questions;
- Handling appeals and managing complaints and disputes;
- Maintaining a record of requests and responses provided to the individuals concerned.
Legal bases: legitimate interest and legal and regulatory obligations.
- Statistical and market research.
Legal basis: legitimate interest.
- Enforcement of applicable contractual, legislative, regulatory, or administrative provisions following an instance of fraud, in accordance with applicable law, particularly those relating to the fight against money laundering and terrorist financing; to comply with audits by authorities such as the French Financial Markets Authority (AMF), the Prudential Supervision and Resolution Authority (ACPR), the Directorate General for Competition, Consumer Affairs, and Fraud Control (DGCCRF), and the National Commission on Informatics and Liberties (CNIL); as well as judicial and administrative authorities.
Legal basis: legal and regulatory obligations.
4. Consent
Users are systematically made aware of the Privacy Policy when they register on the RAIZERS Platform. In fact, creating an account implies the User’s express, full, and complete acceptance of this Privacy Policy.
Thus, the User expressly consents to the transfer of their Data among the various companies within the RAIZERS group for the purposes of managing their project, namely:
- Performance of the contract between the User and RAIZERS as a crowdfunding service provider.
- Processing of information, Data, and details provided by the User in connection with RAIZERS’s insurance brokerage activities.
If the User wishes to withdraw their consent to the processing of their Data, they may submit a request to RAIZERS in accordance with the procedure described in Article 10 below.
5. Categories of Personal Data
The Data collected on the platform consists of information that enables RAIZERS to identify Users directly or indirectly for the purpose of providing the various services offered by the platform. This may include, in particular:
- Identification data (last name, first name, email address, mailing address, phone number, etc.),
- Sociodemographic data (family status, marital status, employment, etc.),
- Economic and financial data and information (income, financial situation, tax status, bank account information, etc.),
- Data related to case management (amount of loan offers and supported projects, etc.) and necessary for analyzing specific needs within the framework of our various services,
- Connection data such as IP address and browsing data such as cookies.
6. Recipients of Personal Data
As part of its activities, RAIZERS may need to disclose the Personal Data it collects to the following recipients, to the extent necessary to achieve the purposes described in this policy:
a) RAIZERS Group Companies
When creating a profile on the platform and/or depending on the services requested, certain Data may be transmitted to Group companies, each acting for its own specific purposes:
- RAIZERS SAS: management of crowdfunding projects and related services;
- RAIZERS PATRIMOINE: management of insurance applications and related services.
b) Insurance partners (brokerage activities)
As part of its insurance brokerage activities, RAIZERS may transmit certain Data to partner insurers.
c) Service Providers and Subcontractors
RAIZERS may also disclose certain Data to service providers (hosting, maintenance, support, audience measurement, etc.) acting as subcontractors within the meaning of the GDPR. These service providers act solely on RAIZERS’ instructions and are subject to contractual confidentiality and security obligations.
The list of service providers and processors receiving the Data may be accessed at any time upon the User’s request.
d) Authorized Authorities and Agencies
In order to comply with its legal and regulatory obligations, RAIZERS may be required to disclose certain Data to the relevant authorities and agencies, including:
- the French Financial Markets Authority (AMF),
- the Prudential Supervision and Resolution Authority (ACPR),
- the DGCCRF,
- the CNIL,
- as well as to duly authorized judicial or administrative authorities, upon request and under the conditions provided for by regulations.
e) Restructuring Transactions (Sale, Merger, Change of Control)
In the event of a restructuring transaction (merger, acquisition, change of control, sale of assets) or insolvency proceedings, the Data may be disclosed to the relevant third parties (advisors, auditors, potential and/or actual acquirers), subject to appropriate safeguards and, where applicable, after notifying the data subjects when required by law.
7. Transfer of Data Outside the European Union
Data may be processed within the European Union. When, in connection with certain services, Data is transferred to a country outside the European Union or the European Economic Area, RAIZERS ensures that such transfer is subject to appropriate safeguards in accordance with the GDPR (for example: an adequacy decision, standard contractual clauses, or any other recognized mechanism). Additional information regarding transfers and the applicable safeguards is available upon request.
8. Shelf Life
The retention period for Data varies and depends on the nature of the Data and the purposes for which it is collected. Data is generally retained for as long as necessary to fulfill the contract and until the various applicable statutory retention periods have expired.
To ensure the proper processing of financial transactions, your Data must be retained and updated regularly for as long as you are a party to an investment.
RAIZERS undertakes to ensure that the collected Data is retained for no longer than is necessary for the purposes set forth above. The table below lists the main retention periods applicable to the operation of crowdfunding and insurance brokerage services:
For a period of 5 years following the repayment date for any loan investment;
For all other cases: 5 years from the termination of the contractual relationship, or from the date the application was denied.
Application denied: 5 years from the date of denial
Application approved: The term of the contractual relationship
For life insurance: 30 years from the date of total surrender or termination of the contract, or from the date of death
2 years for the purpose of compiling insurance files.
Up to 1 year from the date of collection for analytics cookies.
Once the specified time limits have expired, the Data are either deleted or anonymized, particularly for statistical purposes.
9. Security of Personal Data
We place particular importance on the confidentiality, integrity, and availability of your Data. As such, we implement appropriate technical and organizational measures to protect your Data from destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
Confidentiality and Restricted Access
- Access to Data is strictly limited to authorized individuals, solely within the scope of their duties.
- Our employees are bound by professional secrecy and a contractual confidentiality clause.
- Any person authorized to access Data is required to comply with applicable regulations as well as the Group’s internal rules.
Securing Data Transmissions and Forms
- Information transmitted via our website (particularly through forms) is collected using secure forms.
- Communications between your browser and our servers are encrypted using the HTTPS protocol.
- The strength of the SSL certificate is subject to regular audits.
Platform Security and Audits
- During the platform’s development, our service provider CAPSENS ensured its security.
- The platform undergoes an annual audit conducted by an independent firm.
- In accordance with our ISSP (Information Systems Security Policy), an audit is conducted following every major update to verify the absence of known vulnerabilities, particularly in the application’s dependencies.
Authentication, Passwords, and Awareness
- The web tools used by our teams to process data (particularly sensitive data) are protected by strong passwords and two-factor authentication (2FA).
- Employees receive security training upon joining the company, and a technical project manager conducts an account review.
- Passwords for web tools are reset quarterly by a technical project manager.
Session Management
- Users are automatically logged out after one (1) hour of inactivity (including in the back office).
Hosting and Backups
- Collected data is hosted and stored in databases located in France or within the European Union (EU).
- CAPSENS performs a database backup every twenty-four (24) hours.
- Backups are stored on a server separate from the production database and are retained for a period of seven (7) days.
10. Exercising Rights
In accordance with the provisions of the Regulations, the User may exercise their rights regarding the processing of their Data at any time:
- Right of Access to Data: access the information that has been provided to RAIZERS;
- Right to rectification of Data: to request the correction of any errors, outdated information, or omissions in the information provided to RAIZERS;
- Right to data portability: to request that RAIZERS send the information provided to RAIZERS to a third-party service, within the limits of the legal grounds justifying the collection and processing of such data;
- Right to erasure: request the erasure of the information provided to RAIZERS, subject to the legal grounds that justified the collection of such data;
- Right to restriction of processing: to set guidelines regarding the handling of Data after death;
- Right to withdraw consent: to request that certain information provided to RAIZERS not be used in future processing or transfers.
The User acknowledges, however, that processing carried out prior to the revocation of said consent remains fully valid.
The User also has the right to object, without providing a reason, to RAIZERS engaging in profiling based on their Data in connection with the sending of content or communications for commercial marketing purposes.
However, in accordance with Article 12.6 of the GDPR, in order to exercise these rights, RAIZERS, as the data controller, reserves the right to request proof of identity from the requester. The Data used to verify the User’s identity will be deleted once the request has been processed.
The User may exercise these rights by sending an email to contact@raizers.com or to one of the following mailing addresses:
For Internet users residing in France:
RAIZERS SAS
15, rue du Colonel Driant
75001 Paris
France
or
RAIZERS PATRIMOINE
15, rue du Colonel Driant
75001 Paris
France
For Internet users residing in any other country:
RAIZERS SA
RueDe-Candolle 20
1205 Geneva
Switzerland
RAIZERSis committed to responding to your request within a reasonable timeframe, which shall not exceed one (1) month from the date of receipt.
Please be advised that if, despite the response provided, you believe that the processing of your Data does not comply with the Regulations, you have the right to file a complaint with the Complaints Department of the French Data Protection Authority (CNIL), either directly on the CNIL website: www.cnil.fr, or by mail: 3 Place Fontenoy – TSA 80715 – 75334 Paris Cedex 07.
11. Evolution
RAIZERS may update this Privacy Policy to reflect changes in its practices or in applicable regulations. The applicable version is the one published on the Platform.