Intelligence Data Venture S.r.l.
Viale Virgilio 20/D, 74121 Taranto (TA), Italia
P.IVA / C.F.: 03413430731
Contact: investors@codezen.ai
Intelligence Data Venture S.r.l. ("IDV", "we", "us") is the data controller responsible for processing your personal data in connection with the CodeZen Investor Data Room and related investor relations activities.
2. Types of Data Collected
We may collect the following categories of personal data:
Identity data: full name, company name, job title
Contact data: email address, phone number, WhatsApp number
Investor profile data: jurisdiction, investor type, accreditation status
Technical data: IP address, browser type, device information, session data
Usage data: document views, download history, Data Room access logs
Signing data: electronic signature records processed through DocuSign
3. Purpose of Processing
Your personal data is processed for the following purposes:
Investor relations: managing communications, responding to inquiries, and facilitating the investment process
Data Room access management: authenticating users, enforcing NDA agreements, and controlling access to confidential materials
Document signing: facilitating electronic signature of investment documents via DocuSign
Investment tracking: monitoring interest levels, managing the investor pipeline, and maintaining records of investor interactions
Legal compliance: fulfilling regulatory obligations related to securities offerings and corporate governance
4. Legal Basis for Processing
We process your personal data on the following legal bases under the GDPR:
Legitimate interest (Art. 6(1)(f) GDPR): investor relations management, Data Room security, and fraud prevention
Consent (Art. 6(1)(a) GDPR): marketing communications and optional newsletters. You may withdraw consent at any time.
Contract performance (Art. 6(1)(b) GDPR): processing necessary to execute investment documents, NDAs, and related agreements
Legal obligation (Art. 6(1)(c) GDPR): compliance with applicable securities laws and regulatory requirements
5. Data Retention
Your personal data will be retained for as long as the investor relationship remains active. After the relationship ends, we retain data for an additional 10 years to comply with legal and regulatory obligations, including corporate record-keeping, tax compliance, and potential legal claims.
Technical logs and access records are retained for a minimum of 5 years for security and audit purposes.
6. Third-Party Data Sharing
We may share your personal data with the following third parties, solely for the purposes described in this policy:
DocuSign: for electronic signature processing of investment documents and NDAs
Google (Gmail / Workspace): for email communications related to investor relations
WhatsApp (Meta): for real-time investor communications, where initiated by you
We do not sell, rent, or trade your personal data to any third party. Data is shared only as necessary to provide our services and fulfill our obligations.
7. Your Rights Under GDPR
As a data subject, you have the following rights:
Right of access (Art. 15): obtain confirmation of whether your data is being processed and request a copy
Right to rectification (Art. 16): request correction of inaccurate personal data
Right to erasure (Art. 17): request deletion of your personal data, subject to legal retention requirements
Right to data portability (Art. 20): receive your data in a structured, machine-readable format
Right to object (Art. 21): object to processing based on legitimate interest or direct marketing
Right to restriction (Art. 18): request restriction of processing in certain circumstances
Right to lodge a complaint: file a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) at www.garanteprivacy.it
The CodeZen Data Room uses session cookies for authentication and localStorage for user preferences and session restoration. We do not use tracking cookies, advertising cookies, or any third-party analytics cookies.
For detailed information about the cookies and storage mechanisms we use, please refer to our Cookie Policy.
9. Security Measures
We implement appropriate technical and organizational measures to protect your personal data, including:
Encryption of data in transit (TLS/SSL) and at rest
Access controls and role-based permissions for Data Room content
Mandatory NDA execution before access to confidential materials
Audit logging of all Data Room access and document interactions
Regular security reviews and vulnerability assessments
10. International Data Transfers
Your data may be processed by third-party service providers located outside the European Economic Area (EEA). Where such transfers occur, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.
11. Updates to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. We encourage you to review this page periodically. Continued use of the Data Room after changes constitutes acceptance of the updated policy.