Privacy Policy

Last updated: 19 July 2026.

This policy explains how FWRD Digital processes personal data across two surfaces: the marketing website at fwrd.digital, and the FWRD platform — the self-serve website builder at app.fwrd.digital, including its login-less /start onboarding. Where a section applies to only one of the two, we say so.

1. Who is responsible

FWRD Digital (sole proprietorship), based in Utrecht (full registered address available on request and in the order confirmation), registered with the Dutch Chamber of Commerce under number 42057087, VAT ID NL005461307B53, is the controller within the meaning of Article 4(7) GDPR for the personal data collected through the website and the platform.

Contact for privacy matters: [email protected].

2. What data we collect

We collect only data you actively provide, plus the technical data needed to run the service securely. With your consent we additionally use analytics and an ad-measurement pixel (Reddit) — see our cookie policy. Beyond that we use no profiling trackers and no third-party cross-site cookies.

2.1 Contact and diagnosis form (website)

2.2 Newsletter (website)

2.3 Platform account and content (app.fwrd.digital)

The content you submit to the builder is business information you intend to publish on your own website. Please do not enter other people's personal data (for example customer records) into the builder unless you have a lawful basis to do so — if you do, you act as controller for that data and these terms apply to our role as processor (see our terms).

2.4 Technical data

3. AI features and how your content is processed

The FWRD platform builds and edits websites with the help of a large language model. When you use the builder — on the login-less /start flow, or while generating, editing or chatting about your site — the text and content you provide for that purpose is sent to our AI model provider, DeepSeek, which returns the generated result. In practice this means the business description, contact details, prices, brand information and page content you submit (and any documents or images you upload as input) are transmitted to the model provider so it can produce or revise your site.

We instruct the provider not to use your content to train its models, and we send only what is needed to perform the task you asked for. The model returns text; it does not make any decision with legal or similarly significant effects for you, and you review and approve what appears on your site. Processing by this provider may take place outside the European Economic Area; the safeguards for that transfer are described in §6.

4. Legal basis

We process your data only on one of the following grounds under Article 6(1) GDPR:

5. Processors (third parties)

We use the processors below. We conclude data processing agreements with all of them under Article 28 GDPR. Where a processor is located outside the EEA, the transfer safeguards in §6 apply.

Party Purpose Which data Location
Cloudflare, Inc. Hosting (Cloudflare Pages/Workers), CDN, edge routing, bot protection (Turnstile) IP address, user-agent, request headers, country code where applicable Global edge network; transfer outside the EEA under SCCs
Supabase, Inc. Platform database and authentication (accounts, sites, builder data) Account email, authentication data, the site content and builder data you create EU region where configured; transfer outside the EEA, where applicable, under SCCs
DeepSeek AI text generation for the website builder (generating and editing your site content) The business information and page content you submit to generate or edit your site, plus documents or images you upload as input Processed by the provider; may take place outside the EEA (see §6)
Sanity.io (Sanity Inc.) Content management and storage of website form submissions Name, email, form content, country code, timestamp EU or US data centres depending on project setting; transfer outside the EEA under SCCs
Resend (Resend Inc.) Sending email notifications and transactional email (no marketing mailings) Name, email and message content of the confirmation or notification email US; transfer under SCCs
Reddit, Inc. Measuring the effectiveness of our Reddit ad campaigns (conversion pixel, loaded only after your consent via the cookie banner) Cookie ID (_rdt_uuid), pages visited, sign-up/purchase events, IP address, user-agent US; transfer under SCCs

We do not sell data to third parties. The only advertising-related script we use is the Reddit conversion pixel described above, and it runs solely after your consent via the cookie banner.

6. International transfers

Some of the processors above are located, or process data, outside the European Economic Area. Where that is the case, we put in place appropriate safeguards for the transfer — as a rule the European Commission's Standard Contractual Clauses (Implementing Decision 2021/914) — or rely on another lawful transfer mechanism under Chapter V GDPR. This includes the transfer of the content you submit to the builder to our AI model provider. You can request more information about the safeguards for a specific transfer via [email protected].

7. How long we keep it

8. Automated decision-making

We do not take decisions with legal or similarly significant effects for you based solely on automated processing. The diagnosis tool and the AI builder generate suggestions and content based on your input — these are informative and are reviewed and approved by you before they take effect. The AI does not evaluate you or make eligibility decisions about you.

9. Your rights

Under the GDPR (Articles 15–22) you have the right to:

You can exercise your rights by emailing [email protected]. We respond within one month (Art. 12(3) GDPR). If we have doubts about your identity we may ask for additional information to verify it.

10. Complaint to the supervisory authority

If you believe we process your data incorrectly and we cannot resolve it together, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). See autoriteitpersoonsgegevens.nl.

11. Security

We take appropriate technical and organisational measures to protect personal data, including TLS encryption of all connections, scope-limited API tokens, bot protection via Cloudflare Turnstile, and strict access control to our Sanity and platform environments. In the event of a data breach we apply the notification duty under Article 33 GDPR (within 72 hours to the Autoriteit Persoonsgegevens).

12. Changes

We may amend this privacy policy. We announce material changes on this page. The date at the top shows the last change.

Contact

FWRD Digital · Utrecht, NL · CoC 42057087 · VAT NL005461307B53 · [email protected]

question 1 of 4

Where are you now?

One choice. We'll match the right plan.