Law enforcement guidelines
Procedure for official requests for information, preservation and emergency disclosure
Last updated: 19 August 2026
This is a translation provided for convenience. The German version is the legally binding one; if the two differ, the German wording prevails. Requests may be submitted in German or English to flexr.social@proton.me.
1. Who we are
The party responsible for the FLEXR platform is Julian Pachernegg, sole trader, Johann-Schrey-Weg 260, 8232 Grafendorf, Austria (see the legal notice). The service is operated from Austria; Austrian law applies. FLEXR is a sole proprietorship without its own legal department — requests are handled by the operator personally.
2. Serving requests
Please address official requests to flexr.social@proton.me, with the subject line “Behördenanfrage” (official request) or, where there is imminent danger, “NOTFALL — Behördenanfrage” (emergency). Service by post is possible to the address given above.
This email address is at the same time the single point of contact under Art. 11 of Regulation (EU) 2022/2065 (DSA) for direct electronic communication with the authorities of the Member States, the Commission and the European Board for Digital Services. The languages of communication are German and English. The point of contact for users under Art. 12 DSA is the same address; it is named in the community guidelines.
Requests must be submitted on official letterhead and must originate from the requesting body; we reply exclusively to an official address of the requesting authority. Requests from private individuals, law firms or private investigators are not answered through this procedure.
3. Details required
- requesting authority, file reference, name and official contact details of the case officer;
- legal basis of the request and, where required, the judicial authorisation or public prosecutor’s order;
- the most precise possible identification of the data subject: account email address, profile name or account ID;
- precise identification of the data requested and of the period concerned;
- the deadline by which the information is needed.
We cannot answer blanket requests that are not limited to specific accounts or periods.
4. Legal basis
- Austrian authorities: we provide information on the basis of the Code of Criminal Procedure, in particular upon a public prosecutor’s order or judicial authorisation, and on the basis of other statutory obligations to provide information.
- Authorities of other EU Member States: through the instruments of judicial cooperation, in particular the European Investigation Order, and through European Production and Preservation Orders under Regulation (EU) 2023/1543, applicable since 18 August 2026.
- Authorities of third countries: through mutual legal assistance (MLAT), involving the Austrian judicial authorities.
- We disclose subscriber data only where the statutory requirements are met. We do not provide information voluntarily beyond our statutory obligations — except in emergencies under section 6.
5. What data exists at all
We can only hand over what is actually stored. FLEXR does not carry out data retention and does not log connection data per user account.
| Type of data | Available? | Note |
|---|---|---|
| Subscriber data (email, name, date of birth, postcode/town, gender, gym, time of registration) | yes | Self-declared. Date of birth and photograph were visually checked against an official photo ID presented before activation — this is a visual check, not an official identification procedure (no eID, no KYC). The name is not checked against any register and is not to be treated as officially verified. Existing accounts from before the check was introduced may not have gone through it; we state this in the individual case. |
| Profile photos | yes | including approval status |
| Verification selfies and ID captures | as a rule no | deleted immediately after the review decision. They exist temporarily only while a review is still pending |
| Chat messages (content, timestamp, sender) | yes | plain text in the database, no end-to-end encryption; the original and the version sanitised for the recipient are stored separately |
| Matches, swipes, blocks, reports | yes | with timestamp |
| Messages flagged by the system | yes | including the reason for flagging |
| Device ID and user agent | yes | a random identifier generated by the client — not a hardware identifier, not an IMEI, not an advertising ID |
| Moderation decisions | yes | measure, scope, duration, underlying facts and basis |
| IP addresses per account or login | no | not stored in connection with the account; short-lived server logs at system level may contain IP and timestamp without any link to the account |
| Payment and card data | no | held exclusively by Stripe; please enquire there directly. We hold only the account’s Stripe identifiers |
| Passwords | not readable | stored only as a hash |
6. Emergency requests
Danger to life and limb
Where there are reasonable grounds to assume an immediate danger to the life or physical integrity of a person, we review a request as a priority. Disclosure takes place to the extent that an applicable legal basis permits or requires it in the specific case and we have assessed necessity and proportionality. We therefore do not give a blanket advance undertaking to hand data over — what we undertake is to review without delay and, where the legal position supports it, to be able to provide information without delay. Subject line: “NOTFALL — Behördenanfrage”.
Please set out in the request:
- the specific danger and the person concerned;
- why the information is necessary and urgent in order to avert it;
- exactly which data is needed;
- an official call-back number.
We handle emergency requests as a priority and confirm receipt as soon as the request has been seen. As a sole proprietorship we cannot guarantee a round-the-clock on-call service: in case of immediate danger, please also contact the police emergency number through the usual channels.
6a. Reports from us to you
Under Art. 18 DSA we report on our own initiative where we become aware of information giving rise to a suspicion that a criminal offence involving a threat to the life or safety of a person has taken place. Independently of that, we report the cases described in the community guidelines: human trafficking and sexual exploitation (section 4) and child sexual abuse material (section 7), the latter within 24 hours of becoming aware of it. The material concerned is locked against the automatic deletion routines and kept ready for handover.
7. Preservation requests
Upon an official request we preserve the existing data of an account and exempt it from the automatic deletion routines so that it remains available until the formal order arrives.
- Request by email with the subject line “Sicherung” (preservation), stating the account and the period.
- We preserve the data concerned and confirm this in writing.
- The preservation lasts 90 days and is extended once by 90 days upon request.
- If no formal order is received within that period, the preservation is lifted and the regular deletion period continues to run.
8. Retention and deletion
- If a user deletes their account, it is deactivated immediately and permanently deleted after a 30-day grace period, including the photos in object storage. After that the data cannot be restored.
- A preservation request under section 7 that arrives before that period expires suspends the final deletion.
- Payment-related records are subject to the statutory retention periods (as a rule seven years, Section 132 of the Austrian Federal Fiscal Code, BAO).
- Material relating to cases under section 7 of our community guidelines (CSAM) is preserved regardless, for handover to law enforcement.
9. Notifying the data subject
Under data protection law we are in principle obliged to inform data subjects about the processing of their data. We refrain from notifying them where
- the authority states a statutory prohibition on disclosure,
- a court order prohibits it, or
- notification would jeopardise an investigation or put a person at risk.
Please state expressly in the request if such a case applies.
10. Handling, form and costs
- Acknowledgement of receipt as a rule within three business days, emergencies as a priority.
- We provide information in writing in structured form (text or CSV), on request with details of the origin of the data.
- We do not charge for handling requests.
- We review every request for jurisdiction, legal basis and proportionality, and we object to requests that are manifestly inadmissible or disproportionately broad.
11. Contact
Julian Pachernegg, sole trader
Johann-Schrey-Weg 260, 8232 Grafendorf, Austria
Email: flexr.social@proton.me
This page describes a procedure and does not constitute a waiver of any rights or objections.