Privacy Policy

BlackSheep SGR S.p.A.  ·  GDPR Reg. (EU) 2016/679
Home

Last updated: 27 March 2026  ·  Cookie Policy

1. Data Controller and Data Protection Officer

The Data Controller is:

BlackSheep SGR S.p.A. (also known as BlackSheep Ventures)
Via Dante 7, 20123 Milan (MI), Italy
VAT / P.IVA: 14297580962  ·  REA: MI-2772643
Email: info@blacksheep.ventures  ·  Website: blacksheep.ventures

BlackSheep SGR S.p.A. is an Alternative Investment Fund Manager (AIFM) authorized and supervised by the Bank of Italy (Banca d'Italia) pursuant to Directive 2011/61/EU, registered under number 15518.4.

The Data Protection Officer (DPO) is:

Antonio Dettoli — Chief Financial Officer, BlackSheep SGR S.p.A.
Email: antonio.dettoli@blacksheep.ventures
Address: Via Dante 7, 20123 Milan (MI), Italy

2. Scope of this Policy

This Privacy Policy describes how BlackSheep SGR S.p.A. collects, uses, stores and protects personal data of individuals who interact with the website blacksheep.ventures (the "Website"), including through its contact forms, investor relations communications, and other channels described below.

This Policy does not cover personal data processed in the context of employment relationships, fund subscription agreements, or regulatory reporting, which are governed by separate notices provided to the relevant data subjects at the time of collection.

3. Categories of Personal Data Collected

Depending on how you interact with the Website, we may collect the following categories of personal data:

CategoryExamplesSource
Identity dataFirst name, last name, professional titleProvided directly by you
Contact dataEmail address, phone number, company nameProvided directly by you
Professional dataRole, organisation, investment history, AUMProvided directly by you
Business dataStartup name, pitch deck, funding stage, sector, financial projectionsProvided directly by you (pitch submissions)
Navigation dataIP address, browser type, pages visited, timestampsAutomatically collected via server logs
Communication dataContent of messages submitted via contact forms or emailProvided directly by you

We do not collect special categories of personal data (as defined under Art. 9 GDPR) through the Website.

4. Purposes and Legal Bases of Processing

4.1 General contact and enquiries

When you submit a general enquiry through our contact form, we process your name, email address, and message to respond to your request.

Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) in responding to enquiries; or pre-contractual steps at your request (Art. 6(1)(b) GDPR).

4.2 LP newsletter and communications to existing investors

If you are a limited partner (LP) of one of the funds managed by BlackSheep SGR S.p.A., we process your contact data to send periodic updates, reports, and fund communications.

Legal basis: Performance of contract and legal obligations under fund documentation (Art. 6(1)(b) and 6(1)(c) GDPR); and legitimate interest in maintaining investor relations (Art. 6(1)(f) GDPR).

4.3 Investor relations — Fund II

If you have expressed interest in BlackSheep II — Domain-Specific AI Fund, we process your contact and professional data to provide fund information, schedule meetings, and share relevant materials during the fundraising process.

Legal basis: Consent (Art. 6(1)(a) GDPR) and/or pre-contractual steps (Art. 6(1)(b) GDPR). You may withdraw consent at any time by contacting our DPO.

4.4 Spontaneous job applications

If you submit a spontaneous application or CV, we process your personal and professional data to evaluate your profile for current or future positions.

Legal basis: Consent (Art. 6(1)(a) GDPR), provided by voluntarily submitting your application. You may withdraw consent at any time.

4.5 Startup pitch submissions

If you submit a pitch or business plan for potential investment, we process the information provided — including data about founders, the company, and its business model — to evaluate the investment opportunity.

Legal basis: Consent (Art. 6(1)(a) GDPR) and pre-contractual steps (Art. 6(1)(b) GDPR). Voluntary submission constitutes consent to the processing described herein.

4.6 Website navigation data

Server logs automatically collect technical data for security, fraud prevention, and website administration. This data is not used for profiling or behavioural tracking.

Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) in maintaining the security and proper functioning of the Website.

4.7 Regulatory and legal obligations

As an AIFM regulated by the Bank of Italy, BlackSheep SGR S.p.A. may process personal data to comply with AML, KYC, and other applicable regulatory obligations.

Legal basis: Legal obligation (Art. 6(1)(c) GDPR).

5. Data Retention

Processing activityRetention period
General contact enquiries24 months from last interaction, unless a contractual relationship is established
LP communicationsDuration of the fund + 10 years (applicable financial regulation)
Fund II investor relationsUp to 36 months from initial contact; extended if subscription commences
Job applications12 months from receipt, unless extended consent is given
Pitch submissions24 months from submission; extended if due diligence commences
Navigation / server logs90 days, unless longer retention is required for security purposes
Regulatory / AML / KYC data10 years from end of business relationship (as required by law)

At the end of each retention period, personal data is securely deleted or anonymised.

6. Recipients and Data Transfers

Personal data may be disclosed to the following categories of recipients:

  • IT service providers — website hosting (Netlify Inc., USA), email infrastructure, and CRM platforms, acting as data processors under written agreements;
  • Professional advisors — legal, tax, and audit firms, under confidentiality obligations;
  • Regulatory authorities — Banca d'Italia, Consob, the Garante per la protezione dei dati personali, and other authorities where required by law;
  • Fund service providers — fund administrators, custodians, and auditors;
  • Co-investors and advisors — in the context of investment transactions, subject to confidentiality arrangements.

Personal data will not be sold or shared with third parties for commercial or marketing purposes.

7. International Data Transfers

Some of our service providers operate outside the European Economic Area (EEA). Where personal data is transferred to a third country, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission;
  • Adequacy decisions, where applicable;
  • Other safeguards permitted under Chapter V GDPR.

For details on safeguards applicable to specific transfers, contact our DPO at antonio.dettoli@blacksheep.ventures.

8. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

RightDescription
Access (Art. 15)Obtain confirmation of whether we process your data and receive a copy
Rectification (Art. 16)Request correction of inaccurate or incomplete data
Erasure (Art. 17)Request deletion where there is no longer a lawful basis for processing
Restriction (Art. 18)Request limitation of processing in certain circumstances
Portability (Art. 20)Receive your data in a structured, machine-readable format
Objection (Art. 21)Object to processing based on legitimate interest or for direct marketing
Withdraw consent (Art. 7(3))Withdraw consent at any time without affecting lawfulness of prior processing

To exercise any right, contact our DPO at antonio.dettoli@blacksheep.ventures. We will respond within one month of receipt (extendable by two months for complex requests, with prior notice).

You have the right to lodge a complaint with the Garante per la Protezione dei Dati Personali (www.garanteprivacy.it), Piazza Venezia 11, 00187 Rome — or with the supervisory authority of your country of residence or establishment.

9. Cookies

The Website uses only strictly necessary technical cookies required for the proper functioning of the site. No analytics, profiling, or third-party marketing cookies are used.

For full details, see our Cookie Policy.

10. Minors

The Website is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently done so, please contact us and we will promptly delete such data.

11. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices or applicable law. The date of the most recent revision is shown at the top of this page. Material changes will be communicated via a notice on the Website.

12. Contact

For any questions or requests relating to this Policy or the processing of your personal data:

Data Protection Officer
Antonio Dettoli — BlackSheep SGR S.p.A.
Via Dante 7, 20123 Milan (MI), Italy
antonio.dettoli@blacksheep.ventures