DN3mvp studio
How it worksPricingWho it's forFAQ
ITBook a scoping callBook the call
Notice under Articles 13-14 GDPR

Privacy policy

Last updated: 7 October 2026

1. Data controller

[RAGIONE SOCIALE], VAT [P.IVA], [INDIRIZZO SEDE LEGALE], Italy. Contact: hello@dn3.dev.

No Data Protection Officer has been appointed, as one is not required for our activity.

2. Data we collect

Scoping call booking: name, email, optional project link, free description, product type, starting point, product of interest, chosen date and time, referring page and UTM parameters.

Data-room access request: first and last name, company or fund, role, email, phone, average ticket, investment stage and timing, source, message.

Accounts (approved investors and administrators): email, encrypted password, sign-in dates. With Google sign-in we receive name, email and profile picture.

Technical data: IP address and browser information in server logs, for security and abuse prevention.

We do not collect special categories of data (Art. 9 GDPR): please do not enter them in free-text fields.

3. Purposes and legal bases

Organising the scoping call and replying to you: pre-contractual steps at your request (Art. 6(1)(b) GDPR).

Assessing data-room requests, creating accounts and managing relations with prospective investors: pre-contractual steps (Art. 6(1)(b)) and legitimate interest in selecting counterparts (Art. 6(1)(f)).

Site security, spam and fraud prevention: legitimate interest (Art. 6(1)(f)).

Legal, accounting and tax obligations if a contract follows: legal obligation (Art. 6(1)(c)).

We do not use your data for marketing or profiling and never sell it. No decisions are based solely on automated processing.

4. Providing data

Required form fields are needed to act on your request; without them we cannot book the call or assess access. Optional fields are up to you.

5. Recipients and providers

Data is processed by authorised DN3 staff and by providers acting as processors (Art. 28 GDPR):

hosting and infrastructure for the site and database (cloud provider with servers in the EU or adequate safeguards);

Google Ireland Ltd. for Google Calendar and Google Meet (event and invitation) and, if you choose it, Google sign-in;

the provider sending automatic emails (confirmations, approvals, alerts);

Cloudflare for domain management and forwarding of incoming @dn3.dev mail.

An up-to-date list of providers is available on request at hello@dn3.dev.

6. Transfers outside the EEA

Some providers may process data in the United States. Such transfers rely on the EU-US Data Privacy Framework, where the provider is certified, or on the European Commission's Standard Contractual Clauses (Art. 46 GDPR).

7. Retention

Bookings and leads that do not become clients: 24 months from the last interaction.

Rejected data-room requests: 12 months; approved: for the relationship and 24 months after the last sign-in, unless revoked earlier.

Accounts: until you ask for deletion or access is revoked.

Contract and tax records: 10 years, as required by law.

Technical logs: 90 days at most.

8. Your rights

You may at any time request access, rectification, erasure, restriction and portability, and object to processing based on legitimate interest (Arts. 15-22 GDPR).

Write to hello@dn3.dev: we reply within 30 days. You can cancel a call at any time from the link in the confirmation email.

You may lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or the authority of your country of residence.

9. Security

Data travels over encrypted connections (HTTPS). Database access is limited to the site's server and authorised administrators; passwords are stored only in encrypted form.

10. Changes

We may update this notice. The date above shows the latest version; account holders will be told about material changes.

DN3, agentic software studio, Milan. dn3.dev. hello@dn3.dev
HomePress kitInvestor kitPrivacyCookie