Privacy policy
Last updated: 7 October 2026
1. Data controller
[RAGIONE SOCIALE], VAT [P.IVA], [INDIRIZZO SEDE LEGALE], Italy. Contact: hello@dn3.dev.
No Data Protection Officer has been appointed, as one is not required for our activity.
2. Data we collect
Scoping call booking: name, email, optional project link, free description, product type, starting point, product of interest, chosen date and time, referring page and UTM parameters.
Data-room access request: first and last name, company or fund, role, email, phone, average ticket, investment stage and timing, source, message.
Accounts (approved investors and administrators): email, encrypted password, sign-in dates. With Google sign-in we receive name, email and profile picture.
Technical data: IP address and browser information in server logs, for security and abuse prevention.
We do not collect special categories of data (Art. 9 GDPR): please do not enter them in free-text fields.
3. Purposes and legal bases
Organising the scoping call and replying to you: pre-contractual steps at your request (Art. 6(1)(b) GDPR).
Assessing data-room requests, creating accounts and managing relations with prospective investors: pre-contractual steps (Art. 6(1)(b)) and legitimate interest in selecting counterparts (Art. 6(1)(f)).
Site security, spam and fraud prevention: legitimate interest (Art. 6(1)(f)).
Legal, accounting and tax obligations if a contract follows: legal obligation (Art. 6(1)(c)).
We do not use your data for marketing or profiling and never sell it. No decisions are based solely on automated processing.
4. Providing data
Required form fields are needed to act on your request; without them we cannot book the call or assess access. Optional fields are up to you.
5. Recipients and providers
Data is processed by authorised DN3 staff and by providers acting as processors (Art. 28 GDPR):
hosting and infrastructure for the site and database (cloud provider with servers in the EU or adequate safeguards);
Google Ireland Ltd. for Google Calendar and Google Meet (event and invitation) and, if you choose it, Google sign-in;
the provider sending automatic emails (confirmations, approvals, alerts);
Cloudflare for domain management and forwarding of incoming @dn3.dev mail.
An up-to-date list of providers is available on request at hello@dn3.dev.
6. Transfers outside the EEA
Some providers may process data in the United States. Such transfers rely on the EU-US Data Privacy Framework, where the provider is certified, or on the European Commission's Standard Contractual Clauses (Art. 46 GDPR).
7. Retention
Bookings and leads that do not become clients: 24 months from the last interaction.
Rejected data-room requests: 12 months; approved: for the relationship and 24 months after the last sign-in, unless revoked earlier.
Accounts: until you ask for deletion or access is revoked.
Contract and tax records: 10 years, as required by law.
Technical logs: 90 days at most.
8. Your rights
You may at any time request access, rectification, erasure, restriction and portability, and object to processing based on legitimate interest (Arts. 15-22 GDPR).
Write to hello@dn3.dev: we reply within 30 days. You can cancel a call at any time from the link in the confirmation email.
You may lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or the authority of your country of residence.
9. Security
Data travels over encrypted connections (HTTPS). Database access is limited to the site's server and authorised administrators; passwords are stored only in encrypted form.
10. Changes
We may update this notice. The date above shows the latest version; account holders will be told about material changes.