Privacy Policy
Last updated: 19 July 2026.
This policy explains how FWRD Digital processes personal data across two surfaces:
the marketing website at fwrd.digital, and the FWRD platform
— the self-serve website builder at app.fwrd.digital,
including its login-less /start onboarding. Where a section applies to only one of the
two, we say so.
1. Who is responsible
FWRD Digital (sole proprietorship), based in Utrecht (full registered address available on request and in the order confirmation), registered with the Dutch Chamber of Commerce under number 42057087, VAT ID NL005461307B53, is the controller within the meaning of Article 4(7) GDPR for the personal data collected through the website and the platform.
Contact for privacy matters: [email protected].
2. What data we collect
We collect only data you actively provide, plus the technical data needed to run the service securely. With your consent we additionally use analytics and an ad-measurement pixel (Reddit) — see our cookie policy. Beyond that we use no profiling trackers and no third-party cross-site cookies.
2.1 Contact and diagnosis form (website)
- Name (required)
- Email address (required)
- Message / comment (optional)
- Answers to the diagnosis questions (project type, scope, CMS preference, blog/SEO, budget range)
- Optionally, the URL of an existing website (optional, for the diagnosis)
2.2 Newsletter (website)
- Email address
- Time of subscription
2.3 Platform account and content (app.fwrd.digital)
- Account data: the email address and authentication details you use to create and sign in to a FWRD account. Authentication and account records are handled by Supabase (see §5).
- Content you submit to build your site: the business information and material you type or upload to generate and edit your website — for example your business name, address, phone number, email, opening hours, prices, brand and tone, the text of your pages, and any documents or images you upload as input.
- Builder history and memory: your instructions and the assistant's responses within a project, and a short summary the platform keeps so it can remember your preferences across edits.
- Site analytics you connect: if you connect Google Analytics or Search Console to your published site, the platform reads aggregated metrics (page views, top pages, top sources, search queries) to produce reports and suggestions. These are aggregate figures, not individual visitor identifiers.
The content you submit to the builder is business information you intend to publish on your own website. Please do not enter other people's personal data (for example customer records) into the builder unless you have a lawful basis to do so — if you do, you act as controller for that data and these terms apply to our role as processor (see our terms).
2.4 Technical data
- On each form submission we store the two-letter country code (e.g.
NL) that Cloudflare derives from the IP address. We do not store the full IP address ourselves. - Our hosting partner Cloudflare temporarily processes IP address, user-agent and request headers for edge routing and bot protection. See §5.
- Rate-limiting and abuse protection on the platform's AI endpoints use short-lived, per-IP counters to prevent misuse.
3. AI features and how your content is processed
The FWRD platform builds and edits websites with the help of a large language model. When you use the
builder — on the login-less /start flow, or while generating, editing or chatting about your
site — the text and content you provide for that purpose is sent to our AI model provider,
DeepSeek, which returns the generated result. In practice this means the business
description, contact details, prices, brand information and page content you submit (and any documents or
images you upload as input) are transmitted to the model provider so it can produce or revise your site.
We instruct the provider not to use your content to train its models, and we send only what is needed to perform the task you asked for. The model returns text; it does not make any decision with legal or similarly significant effects for you, and you review and approve what appears on your site. Processing by this provider may take place outside the European Economic Area; the safeguards for that transfer are described in §6.
4. Legal basis
We process your data only on one of the following grounds under Article 6(1) GDPR:
- Performance of, or steps prior to, a contract (Art. 6(1)(b)): when you submit the contact or diagnosis form we use your data to answer your request, send a quote, or carry out an assignment; and when you create a FWRD account and use the platform, to provide the service you signed up for, including generating and editing your site.
- Consent (Art. 6(1)(a)): for the newsletter and for optional analytics and ad-measurement cookies (see the cookie policy). You can withdraw consent at any time without affecting processing carried out before withdrawal.
- Legal obligation (Art. 6(1)(c)): for administration, invoicing and the statutory retention period (seven years for financial records under Article 52(4) of the Dutch General Tax Act).
- Legitimate interest (Art. 6(1)(f)): for bot protection and security (Cloudflare Turnstile + edge protection) and for preventing abuse of the AI features. The interest: preventing misuse, spam and attacks. Your interests are limited to a brief technical challenge and short-lived counters, without profiling.
5. Processors (third parties)
We use the processors below. We conclude data processing agreements with all of them under Article 28 GDPR. Where a processor is located outside the EEA, the transfer safeguards in §6 apply.
| Party | Purpose | Which data | Location |
|---|---|---|---|
| Cloudflare, Inc. | Hosting (Cloudflare Pages/Workers), CDN, edge routing, bot protection (Turnstile) | IP address, user-agent, request headers, country code where applicable | Global edge network; transfer outside the EEA under SCCs |
| Supabase, Inc. | Platform database and authentication (accounts, sites, builder data) | Account email, authentication data, the site content and builder data you create | EU region where configured; transfer outside the EEA, where applicable, under SCCs |
| DeepSeek | AI text generation for the website builder (generating and editing your site content) | The business information and page content you submit to generate or edit your site, plus documents or images you upload as input | Processed by the provider; may take place outside the EEA (see §6) |
| Sanity.io (Sanity Inc.) | Content management and storage of website form submissions | Name, email, form content, country code, timestamp | EU or US data centres depending on project setting; transfer outside the EEA under SCCs |
| Resend (Resend Inc.) | Sending email notifications and transactional email (no marketing mailings) | Name, email and message content of the confirmation or notification email | US; transfer under SCCs |
| Reddit, Inc. | Measuring the effectiveness of our Reddit ad campaigns (conversion pixel, loaded only after your consent via the cookie banner) | Cookie ID (_rdt_uuid), pages visited, sign-up/purchase events, IP address, user-agent | US; transfer under SCCs |
We do not sell data to third parties. The only advertising-related script we use is the Reddit conversion pixel described above, and it runs solely after your consent via the cookie banner.
6. International transfers
Some of the processors above are located, or process data, outside the European Economic Area. Where that is the case, we put in place appropriate safeguards for the transfer — as a rule the European Commission's Standard Contractual Clauses (Implementing Decision 2021/914) — or rely on another lawful transfer mechanism under Chapter V GDPR. This includes the transfer of the content you submit to the builder to our AI model provider. You can request more information about the safeguards for a specific transfer via [email protected].
7. How long we keep it
- Contact and diagnosis requests: up to 24 months after last contact, then deleted. Until automated retention is in place, deletion is done periodically by hand.
- Newsletter subscribers: until you unsubscribe. Unsubscribing via the link at the bottom of each newsletter removes your email address from the active list (within 14 days).
- Platform account and site data: for as long as your account exists. When you delete a site or your account, we delete the associated content within a reasonable period, save for backups that age out on their normal cycle and records we must keep by law.
- Builder content sent to the AI provider: we send only what is needed to perform each task; we do not use it to train models. Any retention on the provider side is governed by their terms and our instruction not to train on it.
- Customer administration / invoices: seven years under the statutory tax retention obligation.
- Server logs (Cloudflare): short term (Cloudflare standard, typically 30 days or less).
8. Automated decision-making
We do not take decisions with legal or similarly significant effects for you based solely on automated processing. The diagnosis tool and the AI builder generate suggestions and content based on your input — these are informative and are reviewed and approved by you before they take effect. The AI does not evaluate you or make eligibility decisions about you.
9. Your rights
Under the GDPR (Articles 15–22) you have the right to:
- Access the data we process about you;
- Rectify inaccurate data;
- Erasure ("right to be forgotten");
- Restrict processing;
- Object to processing based on legitimate interest;
- Data portability;
- Withdraw consent previously given.
You can exercise your rights by emailing [email protected]. We respond within one month (Art. 12(3) GDPR). If we have doubts about your identity we may ask for additional information to verify it.
10. Complaint to the supervisory authority
If you believe we process your data incorrectly and we cannot resolve it together, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). See autoriteitpersoonsgegevens.nl.
11. Security
We take appropriate technical and organisational measures to protect personal data, including TLS encryption of all connections, scope-limited API tokens, bot protection via Cloudflare Turnstile, and strict access control to our Sanity and platform environments. In the event of a data breach we apply the notification duty under Article 33 GDPR (within 72 hours to the Autoriteit Persoonsgegevens).
12. Changes
We may amend this privacy policy. We announce material changes on this page. The date at the top shows the last change.
Contact
FWRD Digital · Utrecht, NL · CoC 42057087 · VAT NL005461307B53 · [email protected]