Privacy

How we handle your data.

This policy describes, in plain terms, what data Forward Factory collects, why it processes it and how you exercise your rights under the LGPD (Brazil's data protection law).

Última atualização: June 12, 2026

Controller and data protection officer

The controller of the personal data processed on this site is Forward Factory, registered under CNPJ 62.987.097/0001-25. The decisions about data processing described in this policy are the controller's responsibility.

The Data Protection Officer (DPO) can be reached at contato@forwardfactory.xyz, the channel through which data subjects exercise their rights and clarify privacy questions.

What data we collect

We collect only the data necessary to respond to a business inquiry and operate the site:

  • Data you provide in the contact form: name, email, company, asset type, estimated volume (optional) and your message.
  • Technical submission data: the browser's user-agent, recorded with the lead for security and diagnostics.
  • Browsing data via cookies and similar technologies, only when you consent to the analytics and/or marketing categories (see the cookies section).

We do not collect sensitive data and do not request personal documents through the site. KYC/AML procedures, when applicable to a structured operation, take place outside the site, under their own process.

Market access account

The /mercado terminal lets you create an access account. The account does not enable investing and does not move funds — the market operates in demo mode. For this feature, we process:

  • Registration data: display name and email, confirmed via a verification link sent to your inbox.
  • Access credential: your password is stored exclusively as a cryptographic hash (Argon2id) — we have no access to the plain-text password.
  • Security records: IP address and browser user-agent for authentication events (sign-in, failed attempts, password reset), kept in an audit trail aimed at fraud prevention and protecting your own account.

Legal basis: carrying out procedures at the data subject's request for registration and authentication (LGPD art. 7, V) and legitimate interest for security records and fraud prevention (art. 7, IX). Transactional account emails (verification and password reset) are sent through the processor Resend.

Account session cookies are strictly necessary (always-active category): httpOnly, restricted to this origin and expiring automatically; they do not track your browsing. You may request account deletion at any time via contato@forwardfactory.xyz.

Identity verification (KYC) and anti-money-laundering (AML)

DRAFT — pending legal/DPO review. To comply with identity verification and anti-money-laundering obligations (Law 9,613/1998 and CVM Resolution 50/2021), when you start identity verification in the /mercado terminal we process:

  • Identity document (national ID or driver's license — front and back) and the data it contains: name, CPF and date of birth.
  • A selfie, treated as biometric data, to confirm that the person submitting the document is its holder (proof of life/identity).
  • The result of anti-money-laundering (AML) checks: screening your name/CPF against public lists of politically exposed persons (PEP), sanctions lists (domestic and international) and adverse media, recording the result and the evidence of each check.

Legal basis: compliance with a legal/regulatory obligation (LGPD art. 7, II) and, for the biometric data, processing necessary for the controller to comply with a legal obligation (art. 11, II, "a"). We do not rely on consent, since verification and AML screening are regulatory obligations.

The PEP, sanctions and adverse-media checks are carried out by our compliance team and serve exclusively the duty to prevent money laundering and terrorist financing; they are not used for advertising or automated decision-making.

Retention: verification data and documents and the AML screening records are kept for at least 5 years after the end of the relationship, in accordance with CVM Resolution 50; afterwards they are discarded. Security: the CPF is stored encrypted; documents and evidence live in private storage, accessible only via temporary links to authorized reviewers; images are reprocessed to strip metadata (EXIF/GPS).

Sharing: the data is not shared with third parties, except where required by a competent authority — including, where applicable, a report to the Financial Activities Control Council (COAF). Your data-subject rights (art. 18) follow the general section, subject to the minimum retention required by law.

Purpose and legal basis

We process form data to respond to your inquiry and assess a potential business relationship, with the legal basis of legitimate interest for the B2B relationship (LGPD art. 7, IX) and the execution of preliminary procedures at your request (art. 7, V).

Analytics and marketing cookies are processed exclusively on the basis of your consent (art. 7, I), collected freely, informedly and unequivocally through the cookie banner, and revocable at any time.

Who we share data with

We do not sell personal data. We share data only with processors that handle information on our behalf, to the extent necessary to operate the site:

  • Vercel: hosting and delivery of the site.
  • Resend: sending the lead notification email to our institutional inbox and transactional market-account emails (email verification and password reset).
  • Supabase: lead storage, when that destination is enabled.
  • Plausible: cookie-free audience metrics with no personal data (always loads, as it is privacy-first).
  • Cloudflare Turnstile: anti-bot verification on the form (a challenge without tracking cookies).
  • Google (Analytics), Meta and LinkedIn: only if you consent to analytics/marketing cookies; they receive browsing data for measurement and advertising.

Cookies and similar technologies

We classify cookies into three categories. Necessary cookies keep the site functional and record your own consent choice, and are always active. Analytics cookies measure how the site is used and marketing cookies support advertising and remarketing; both only load after your explicit consent.

Before consent, no analytics or marketing cookie is installed. You can accept, refuse or adjust the categories at any time, and withdrawal is as simple as consent.

International transfers

Some processors (Vercel, Resend, Cloudflare, Google, Meta and LinkedIn) process data on servers outside Brazil. In those cases, the international transfer observes the LGPD's hypotheses and safeguards (arts. 33 to 36), including contractual clauses and protection standards adopted by those providers.

Retention and deletion

We keep lead data for the period necessary for the business relationship and, in the absence of interaction, for up to 24 months, after which it is deleted or anonymized. Legal or regulatory obligations may require retention for a different period; in those cases, the data is kept only for that purpose.

Market account data is kept for as long as the account exists. After account deletion, security audit records (IP, authentication events) are retained for up to 12 months for fraud prevention and compliance purposes, then deleted.

Data subject rights

Under art. 18 of the LGPD, you may, at any time, request:

  • confirmation that processing exists and access to your data;
  • correction of incomplete, inaccurate or outdated data;
  • anonymization, blocking or deletion of unnecessary or excessive data;
  • portability of the data to another provider, upon request;
  • information about the entities with which we share data;
  • withdrawal of consent and objection to processing based on it.

To exercise any of these rights, write to contato@forwardfactory.xyz. We will respond within the legal deadline. You may also petition the Brazilian National Data Protection Authority (ANPD).

Information security

We adopt technical and organizational measures compatible with the nature of the data: traffic over HTTPS/HSTS, security headers, validation and anti-bot verification on the form, and restricted access to storage systems. No method is infallible, but we work to mitigate risks of unauthorized access, loss or improper alteration.

Changes to this policy

We may update this policy to reflect legal, technical or business changes. The date of the last revision appears at the top of this page. Relevant changes will be flagged on the site itself.

Cookie preferences

You can review or withdraw your cookie consent at any time: .

Questions about privacy?

Reach our data protection channel. We answer access, correction and deletion requests within the legal deadline.