1. Who we are
Forward Invest S.r.l., Via Adelaide Ristori 38, 00197 Roma (RM), Italy, fiscal code and VAT number 18586341002, registered with the Companies Register of Rome (REA RM-1794105), is the data controller for personal data collected through this site and through correspondence that follows from it.
Contact for anything in this policy: contact@forwardinvest.ai.
Data Controller Details:
Forward Invest S.r.l. · Società a socio unico
Registered office: Via Adelaide Ristori 38, 00197 Roma (RM), Italy
Codice fiscale e Partita IVA: 18586341002 · REA: RM-1794105 · Capitale sociale: €100.000 i.v.
Società soggetta all'attività di direzione e coordinamento di Zero S.r.l.
Certified Email (PEC): forwardinvest@pec.it · Email: contact@forwardinvest.ai
Responsible person for data matters: Charles Dieffenthaler. No data protection officer is appointed; none is required for this activity.
2. What we collect
We collect only what you give us and what a web server records by default:
- Contact form: Name, email address, company name and website, year founded, revenue and EBITDA for the last financial year, headquarters location, and anything you write in the message field. Only name and email are required.
- Call request form: The same fields as the contact form, plus your preferred days and times for a call.
- Correspondence: The emails you send us and our replies.
- Server logs: IP address, browser type, pages visited and time of visit, kept by our hosting provider for security and error diagnosis.
We do not ask for, and please do not send, special categories of data such as health, political or religious information.
3. Cookies and storage
This site uses only strictly necessary cookies or equivalent browser storage, where the platform it runs on requires them: for security, for routing, and for preferences you ask for. These do not require consent under the applicable exemption.
We use no analytics, no advertising pixels and no third-party trackers. Optional analytics or any other tracking will not be enabled without a separate notice and, where required, your consent before any such cookie is set.
Cookies in use at the date of this policy: None.
For further technical details on how our digital presence maintains privacy by design, please refer to our Cookie Policy.
4. Why we use your data, and on what legal basis
- Responding to your enquiry: To reply to you and to hold the conversation you asked for.
Legal basis: steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR). - Evaluating a possible transaction: To assess whether your company fits what we do and to keep a record of our exchanges.
Legal basis: our legitimate interest in evaluating investment and acquisition opportunities (Art. 6(1)(f) GDPR), which we consider does not override your interests given the nature of the data. - Meeting legal duties: To keep records that Italian company, tax and anti-money-laundering rules require once a transaction is under way.
Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR). - Operating the site: To keep the site secure and working.
Legal basis: our legitimate interest in running a secure website (Art. 6(1)(f) GDPR).
We do not send marketing communications. If we ever wish to, we will ask for your consent first, and you will be able to withdraw it at any time.
5. Who has access
Inside Forward Invest, access is restricted to the members of our team and advisory board who assess enquiries.
Outside Forward Invest, access is limited to:
- Hosting infrastructure provider: which hosts the site and holds the server logs under strict security protocols;
- Email delivery provider: which delivers our email communication;
- Professional advisers: Lawyers, accountants and auditors bound by professional confidentiality, when a transaction is being assessed;
- Authorities: Courts, regulators or public authorities, where the law requires it.
Each provider acts on our instructions under a written agreement. We do not sell personal data and we do not share it with anyone for their own marketing.
6. Transfers outside the European Economic Area
Where a provider processes data outside the European Economic Area (EEA), we rely on an adequacy decision of the European Commission or on the Standard Contractual Clauses (SCCs), with additional safeguards where needed.
You may ask us at any time which mechanism applies to a given provider by writing to contact@forwardinvest.ai.
7. How long we keep it
- Enquiries that do not lead to a transaction: Up to 24 months from our last exchange, then permanently deleted.
- Enquiries that lead to a transaction: For the life of the relationship, and afterwards for the period required by Italian company, tax and limitation rules, generally ten years.
- Server logs: Up to 12 months, unless needed longer for a security incident or a legal claim.
8. Your rights
Under the General Data Protection Regulation you may ask us for access to your data, for its correction or deletion, for a restriction of its use, for a copy in a portable format, and you may object to processing based on our legitimate interests. Where processing is based on consent, you may withdraw it at any time.
How to exercise your rights: Send requests to contact@forwardinvest.ai. We answer within one month. We may need to confirm your identity first.
You may also lodge a complaint with the Italian supervisory authority:
Garante per la protezione dei dati personali
Piazza Venezia 11, 00187 Roma, Italy
Website: www.garanteprivacy.it
Or to the competent data protection authority of the country where you live or work.
9. Security
The site is served over HTTPS with TLS transport encryption. Data you send us is stored in systems with access limited strictly to the authorized personnel named in Section 5, protected by passwords and two-factor authentication (2FA).
No transmission over the internet is completely secure, which is one more reason not to send sensitive material before a formal bilateral confidentiality agreement (NDA) is in place.
10. Changes
We may update this policy from time to time. The date at the top tells you when it last changed. Material changes will be prominently flagged on this page.
11. Record of Processing Activities
In accordance with Article 30 of the GDPR, Forward Invest S.r.l. maintains an internal record of data processing activities governing all information collected through this digital presence:
| Data Category | Collected How | Where It Lives | Who Can See It | Kept For | Legal Basis |
|---|---|---|---|---|---|
| Contact form submissions (name, email, company, financial figures, message) |
Website form | Mailbox / CRM | Simone, Charles, advisers on a live file | 24 months from last exchange; longer if a transaction follows | Pre-contractual steps (Art. 6(1)(b)); Legitimate interest (Art. 6(1)(f)) |
| Call requests (name, email, preferred times, notes) |
Website form | Mailbox / CRM | Simone, Charles | 24 months from last exchange | Pre-contractual steps (Art. 6(1)(b)) |
| Email correspondence | Email communication | Email infrastructure | Team members on the thread | 24 months from last exchange; longer if a transaction follows | Pre-contractual steps (Art. 6(1)(b)); Legitimate interest (Art. 6(1)(f)) |
| Server logs (IP, browser, pages, timestamp) |
Automatic HTTP requests | Hosting infrastructure | Technical maintenance; Charles | 12 months | Legitimate interest in security (Art. 6(1)(f)) |
| Transaction files (once an NDA is signed) |
Secure data room, email | Protected cloud / data room | Deal team, legal counsel, audit advisers | Life of relationship plus 10 years | Contractual obligations (Art. 6(1)(b)); Legal obligations (Art. 6(1)(c)) |
Controller: Forward Invest S.r.l. · Responsible person for data matters: Charles Dieffenthaler. No special categories of data are processed by design.
12. Rights Request Procedure & Incident Protocol
Requests arrive at contact@forwardinvest.ai. Charles Dieffenthaler is the internal owner. The response window is one month from receipt, extendable by two months for complex requests if the data subject is notified within the first month.
Internal Step-by-Step Procedure
- Step 1 — Acknowledgment: Acknowledge receipt within two working days and, if the sender's identity is not obvious from the address, ask for confirmation.
- Step 2 — Scope search: Search the three repositories listed in the record of processing: form destination, email, and any active transaction file.
- Step 3 — Access request: Send a copy of everything held, in a readable format, with the applicable retention period and sources.
- Step 4 — Deletion request: Delete from all three repositories and confirm in writing. If a transaction file exists and the law requires retention, explain which records must be kept and why.
- Step 5 — Correction, restriction, objection: Apply the requested change, note it in the record, and confirm in writing.
- Step 6 — Audit log: Log the request, date received, date answered and action taken in a designated register kept with the record of processing.
Data Breach Escalation Protocol
A data breach that is likely to put individuals at risk must be reported to the Italian Data Protection Authority (Garante) within 72 hours of discovery pursuant to Article 33 GDPR. If a device containing founder data is lost, an inbox is compromised, or a service provider reports a security incident, legal counsel is notified immediately on the same day without waiting for the full picture.