Florin21 Terms of agreement:
Last updated August 2026
These Terms govern the services provided by Florin21 Limited, a company registered in Northern Ireland under company number NI696830, registered office 87 High Street, Newry, County Down, Northern Ireland, BT34 1HG (“Florin21”, “we”, “us”). Engaging our services means you agree to these Terms. Please read them alongside our Privacy Policy and our FCA Risk Summary, both of which form part of them.
What Florin21 is, and what it is not
Florin21 is a technical support and advisory service. The following four points define our role. They apply to every service, every client, at all times, and nothing else in these Terms qualifies them.
We never hold your Bitcoin. We do not take custody, possession or control of client Bitcoin at any point, in any amount, for any period. We cannot move, spend, freeze or access it.
We never hold your keys. We do not ask for, receive, record or store seed phrases, recovery words, private keys, passphrases or PINs. You must never disclose them to us. No arrangement we design gives us the ability to spend your Bitcoin unless separately agreed with you in writing.
We never handle your money. We do not accept, hold or transmit client money, and we do not buy, sell, exchange or transfer Bitcoin or currency on your behalf. Where you acquire or dispose of Bitcoin you do so through your own account, at your own chosen venue, with your own funds, on your own instruction. We are not a party to that transaction and take no part in it.
We are paid only by you. We receive no commission, introducer fee, referral fee, revenue share, rebate or other benefit from any exchange, broker, custodian, manufacturer or other third party. Our only remuneration is the fee you pay us directly. If this ever changes we will say so in these Terms and in writing to you before it applies to your engagement.
What we do instead is help you understand, design, build, document and maintain your own arrangements, so that you hold and control your own Bitcoin yourself, with our support. Note on communications. No genuine message from Florin21 will ever ask for seed words, passphrases, private keys or remote access to a signing device. Any message that does is fraudulent. Please report it to us.
Our services
- Self-custody design and support. Design, configuration and documentation of Bitcoin custody arrangements, including hardware signing devices, wallet software and full node operation.
- Multi-signature, multi-vendor custody architecture. Custody designs that distribute signing across multiple keys and multiple independent hardware vendors, so that a defect or compromise affecting any one device or vendor does not by itself cause loss of funds.
- Bitcoin security review. Structured review of an existing arrangement, covering backup design, redundancy, key distribution, operational procedure and recovery testing.
- Bitcoin treasury structuring for businesses. Guidance for companies on how Bitcoin might be held, secured, governed and accounted for within their existing arrangements.
- Bitcoin inheritance and succession planning. Guidance on arrangements intended to allow Bitcoin to be located, accessed and transferred by executors, trustees or beneficiaries, including our published inheritance planning materials.
- Bitcoin Inheritance Recovery Support. Support for executors, trustees, beneficiaries or nominated persons in locating and recovering Bitcoin held under an arrangement we previously designed or documented.
- Education on acquiring Bitcoin. Education on the practical, security and operational considerations relevant to acquiring Bitcoin, including venue types, settlement, withdrawal practice and address verification. This is teaching, not transacting. You select your own venue, open your own account and place your own orders.
- Education, workshops and published materials. Workshops, written guides, briefings and other educational resources.
- Ongoing advisory retainers. Continuing support where a written retainer is in place, on the terms of that retainer and section 5 below.
Your engagement letter, proposal or order confirmation sets out the services to be provided to you. Where it conflicts with these Terms, it prevails on scope and fees, and these Terms prevail on everything else. Not every service is offered at all times.
What we do not do
No financial advice. We do not provide financial, investment, tax, legal or accountancy advice. Nothing we provide is a personal recommendation to buy, sell, hold or deal in Bitcoin or any other asset, or advice on whether Bitcoin is suitable for you. All commercial and financial decisions remain yours.
No regulated activity. Florin21 is not authorised or regulated by the Financial Conduct Authority and carries on no regulated activity. In particular we do not deal in cryptoassets as principal or agent; arrange, or make arrangements with a view to, deals in cryptoassets; receive, transmit, place or execute orders; operate any trading platform; safeguard or administer cryptoassets or private keys; hold client money or client assets; or issue stablecoins or arrange staking.
No introductions. Where we discuss exchanges, brokers, custodians, manufacturers or software providers, we do so on an educational basis so that you can make your own selection. We do not introduce you to any venue, open or access accounts on your behalf, communicate with venues on your behalf, or take part in any transaction. Any contract you enter into with a third party is between you and them alone.
No promotion. Our materials are provided for information and education. They are not an inducement or invitation to engage in investment activity.
We rely on your information. We do not verify or audit the information you or others give us, and we are not responsible for consequences arising from information that is inaccurate, incomplete or out of date. Bitcoin involves risk. Its value can fall as well as rise. Transactions are irreversible. Loss of keys or backups will generally mean permanent, irrecoverable loss of funds. Please read our FCA Risk Summary before engaging us.
The nature and currency of our advice
Point in time. Everything we provide is based on the information, technical understanding, vendor documentation and threat intelligence reasonably available to us on the date it is given.
No continuing duty. Unless a written retainer is in place, we have no continuing duty to monitor, review, update or notify you about any recommendation after delivery. Completing an engagement ends our involvement in it.
A changing threat environment. The security of Bitcoin custody depends on hardware, firmware, software and cryptographic assumptions that change over time. Vulnerabilities may exist that are unknown to us, to the vendor and to the wider security community at the time we advise, and may only be discovered later. A recommendation that was sound when made may cease to be appropriate because of a defect or attack technique discovered afterwards.
No guarantee of security. We do not warrant that any arrangement we design, review or recommend is or will remain secure, or that it will prevent loss, theft or compromise. Our work aims to reduce risk in line with good practice. It cannot eliminate it.
Not an audit. Unless expressly agreed in writing as a separate engagement, our work is not a penetration test, source code audit, firmware audit or security certification of any product.
Third-party hardware, firmware and software
Our work regularly involves hardware signing devices, wallet software, node software and backup media designed and manufactured by independent third parties. We do not design, manufacture, control, audit or maintain any of them.
No warranty. We give no warranty or representation as to any third-party product, including its design, manufacture, supply chain integrity, firmware, the quality or sufficiency of its random number generation or entropy, its resistance to attack, or the accuracy of its vendor’s claims.
Selection is not a guarantee of integrity. Recommending, selecting or configuring a product reflects our assessment of the information publicly available at that time. It does not transfer to us any liability for a defect, vulnerability, supply chain compromise or vendor failure in that product, whether or not the defect existed at the time we advised and whether or not it was then known. Your remedy for such a defect lies against the vendor.
Why we favour distributed designs. Our standard approach spreads signing across multiple keys and multiple independent vendors precisely because single-vendor and single-signature arrangements concentrate this risk. If you instruct us to implement, or choose to retain, an arrangement that does not follow this approach, you do so on your own assessment of the risk and we will record that instruction in writing.
Monitoring is a retained service
Proactive monitoring of vendor advisories, firmware releases and disclosed vulnerabilities, and proactive notification to you of matters affecting your arrangement, are provided only under a written advisory retainer and only while it is in force.
If you do not hold a current retainer we do not monitor your arrangement, we do not track your devices or firmware versions, and we are not obliged to contact you about any vulnerability or incident, however serious. Monitoring and maintenance are your responsibility.
We may occasionally issue general security notices to past clients or to our wider audience as a matter of goodwill. Doing so creates no duty to do so again, no monitoring obligation and no advisory relationship, and does not vary these Terms.
A retainer does not make us responsible for the security of your arrangement or for your implementation of our recommendations.
Your responsibilities
You agree that you will:
- Apply firmware and software updates promptly and monitor the security advisories published by the vendors of the products you use.
- Implement and maintain the recommendations we make, and tell us if you do not intend to. We are not responsible for the consequences of a recommendation that is not implemented, is partly implemented or is later altered.
- Independently verify receive addresses, transaction details and any instruction appearing to come from us, using a different channel, before acting on it.
- Keep your seed words, passphrases, private keys and backups secure, secret and under your own control, and never disclose them to us or anyone else.
- Create, securely store and periodically test backups and recovery procedures for every key.
- Complete a full recovery test of any arrangement before moving material value into it.
- Tell us promptly if you suspect any device, key, backup or arrangement has been lost, compromised or exposed.
- Give us accurate and complete information, and update it when it changes.
- Comply with the laws that apply to you, including tax, sanctions and anti-money laundering law.
Failure to do these things may cause loss for which we are not responsible, and we may rely on that failure in answer to any claim.
Who we work with
Our services are available to individuals, businesses and organisations that can form legally binding contracts. You must be at least 18, or the age of majority where you live if higher. If you engage us on behalf of an entity, you confirm you are authorised to bind it. You confirm that you are not subject to any sanctions regime and that the funds and assets connected with our work derive from lawful sources. We may decline or end any engagement where we have concerns about sanctions, source of funds or financial crime, and need not give reasons. We may refuse our services to any person or entity at our discretion.
Fees, payment and cancellation
Fees are agreed before work starts. We give a quotation or estimate beforehand and will not exceed it without your approval. Unless otherwise agreed in writing, fees are payable in advance. You are responsible for applicable taxes.
Payment methods. We accept bank transfer and Bitcoin. Where payment is in Bitcoin, the amount is fixed in pounds sterling at the time of invoice and you bear any exchange rate movement before settlement.
Late payment. We may charge interest on overdue sums at 1.5% per month or the maximum permitted by law, whichever is lower, and may suspend work. You agree to pay our reasonable recovery costs to the extent permitted by law.
Consumers: your right to cancel. If you are a consumer contracting with us at a distance, you may cancel within 14 days of the day after the contract is made, without giving a reason, under the Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013. Tell us in writing at [email protected] within that period and we will refund all payments received within 14 days. If you asked us to start work during that period and then cancel, you must pay a proportionate amount for the work done.
Digital content. For downloadable guides, kits and templates, you will be asked at the point of purchase to consent to immediate delivery and to acknowledge that you thereby lose the 14-day cancellation right. Once download or access begins, that right ends. Where a product is sold through a third-party platform whose refund policy is more generous, that policy applies to that purchase.
Business customers. Statutory cancellation rights do not apply to business engagements. Fees are non-refundable once work has started, unless agreed in writing.
Nothing here affects your statutory rights.
Confidentiality and your information
We treat everything you tell us in confidence, and you agree to do the same with our confidential information. Neither of us will disclose the other’s confidential information or use it for any other purpose. This does not cover information that is already public through no fault of the receiver, was lawfully held before disclosure, was independently developed, or is lawfully obtained from a third party. If either of us is legally required to disclose, we will tell the other first unless prohibited. These obligations continue after our work ends.
Information about your arrangement. In custody design, documentation and inheritance planning we may hold output descriptors, extended public keys, device models and firmware versions, address information, quorum structure and details of nominated persons. We never hold seed words, private keys, passphrases or PINs.
Descriptors and extended public keys cannot be used to spend your Bitcoin, but they do reveal your balances and transaction history, so we treat them as highly sensitive. We hold them encrypted at rest, on a need-to-know basis, and only for as long as necessary.
You may instruct us in writing at any time not to retain this information, or to delete it. Doing so may prevent us from providing Bitcoin Inheritance Recovery Support or assisting your executors or beneficiaries later. Our Privacy Policy has the full detail.
Our materials
Reports, analyses, diagrams, templates, guides, briefings and website content we produce remain our property. You may use them for your own internal purposes, which for a business means within your own organisation, by your own personnel and professional advisers. You may not sell, publish, redistribute or use them to provide services to third parties.
Documents prepared specifically for you may be shared with your own advisers, executors, trustees and nominated persons for the purposes for which they were prepared, provided they are made aware of these restrictions.
The Florin21 name and logo may not be used without our written permission. We may use any feedback you give us without payment or acknowledgement.
Limitation of liability
Please read this section carefully.
What we never exclude. Nothing in these Terms limits our liability for death or personal injury caused by our negligence, for fraud, or for anything else that cannot lawfully be limited. If you are a consumer, nothing here affects your statutory rights, including your right under the Consumer Rights Act 2015 to services carried out with reasonable care and skill.
What we are not liable for. Subject to the above, we are not liable for:
- any fall in the value of Bitcoin or any other asset;
- any loss caused by a defect, vulnerability or failure in third-party hardware, firmware or software, including any defect in key or seed generation;
- any loss caused by your failure to meet your responsibilities in section 7, including failure to apply firmware updates, implement a recommendation, test a recovery or maintain backups;
- any loss caused by your disclosure of a seed phrase, passphrase, private key or credential to anyone;
- any act or omission of a third-party exchange, broker, custodian, manufacturer or service provider;
- any loss caused by theft, fraud, coercion, social engineering, phishing or physical attack directed at you;
- any loss arising after an engagement ends, where no retainer is in force, from something we did not notify to you;
- any loss arising from inaccurate or incomplete information given to us;
- loss of profit, business, goodwill or anticipated savings, or any indirect or consequential loss.
Cap. Subject to “What we never exclude” above, our total liability arising from these Terms and all services under them, whether in contract, negligence, breach of statutory duty or otherwise, is limited to the greater of £25,000 or the total fees you paid us in the twelve months before the event giving rise to the claim.
Higher limits. Where the value at risk in an engagement warrants it, we will discuss a higher cap with you before work begins. Any increase must be agreed in writing and may be reflected in our fees.
Time limit. Claims must be notified to us in writing within twelve months of the date you became aware, or should reasonably have become aware, of the circumstances giving rise to them, and in any event within two years of delivery of the relevant service.
Why these limits are reasonable. They reflect the nature of our services and the fees charged, the fact that we hold neither your keys nor your funds and cannot move them, the fact that your arrangement’s security depends substantially on your own conduct and on products made by third parties we do not control, the availability to you of insurance and of a direct remedy against those third parties, and our willingness to agree a higher cap if you consider this one inadequate.
Our services are otherwise provided as they are, without warranties beyond those expressly given in these Terms and those that cannot be excluded by law. We do not promise that our website will be uninterrupted, error-free or always available.
Ending an engagement
You may end an engagement at any time by writing to us, subject to payment for work already done and to your cancellation rights in section 9.
We may end or suspend an engagement on reasonable written notice, or immediately where you are in material breach, have not paid a sum due, or where we have concerns about sanctions, source of funds or financial crime.
Ending an engagement does not take away materials already delivered to you, and your licence to use them continues. On request within 90 days we will provide a copy of the documentation prepared for you, subject to payment of any outstanding fees.
Sections 1, 3, 4, 5, 10, 11, 12 and 14 continue to apply after an engagement ends.
General
Changes to these Terms. We may update these Terms and will give at least 30 days’ notice of material changes by posting on our website or by email. Changes do not apply retrospectively to an engagement already agreed and in progress. Each version shows the date it was revised, and previous versions are available on request. Continuing to use our services after a change takes effect means you accept it.
Governing law. These Terms and any dispute arising from them are governed by the law of Northern Ireland, and the courts of Northern Ireland have exclusive jurisdiction. If you are a consumer resident elsewhere in the UK or in the EU, this does not deprive you of the protection of the mandatory law of your place of residence or of your right to bring proceedings there.
Disputes. Please contact us first at [email protected]. We will acknowledge within five working days and aim to respond substantively within 20. If a dispute is not resolved, we both agree to attempt mediation in good faith through the Law Society of Northern Ireland Mediation Service, or if unavailable the Barrister Mediation and Arbitration Service of the Bar of Northern Ireland, before starting proceedings. Nothing here prevents either of us from seeking urgent injunctive relief, and if you are a consumer nothing here affects your right to go to court.
Severability. If any provision is found invalid or unenforceable it will be severed and the rest will continue in effect.
Events outside our control. We are not liable for delay or failure to perform caused by events outside our reasonable control, including acts of nature, fire, flood, strike, war, terrorism, act of government, epidemic, or failure of telecommunications, internet or electricity supply.
Everything else. These Terms, with your engagement letter or order confirmation, our Privacy Policy and our FCA Risk Summary, are the entire agreement between us and replace anything agreed earlier. A failure to enforce a provision is not a waiver of it. You may not transfer your rights under these Terms; we may transfer ours on notice to you. Nobody who is not a party to these Terms may enforce them.
Contact. [email protected]. By using our services you consent to communicating with us electronically. Given the nature of our work, please treat any unexpected message appearing to come from us with caution and verify it independently before acting on it.
Data protection. Our Privacy Policy explains how we handle personal information. Florin21 is registered with the Information Commissioner’s Office under registration number [ICO REGISTRATION NUMBER].
By using our services you confirm that you have read and understood these Terms and our FCA Risk Summary, and agree to be bound by them.
Florin21 Limited, registered in Northern Ireland, company number NI696830. Registered office 87 High Street, Newry, County Down, BT34 1HG.