Privacy Policy
Aidvance GmbH · aidvance.co/privacy
1. Who we are
Controller: Aidvance GmbH, Wiener Straße 18, 10999 Berlin, Germany (registration no. HRB 274326 B), e-mail: info@aidvance.co (“Aidvance”, “we”). Our external data protection officer is Oliver Pikolleck, HiLevDATA GmbH & Co. KG. You can reach the data protection officer at privacy@aidvance.co.
2. This policy at a glance
This policy explains how we process personal data, organised by your relationship with us. The general parts (sections 1 to 4) apply to everyone; then read the section that matches your situation:
| Your situation | Relevant section |
|---|---|
| You visit our website aidvance.co | Section A: Website visitors |
| You apply for a job with us | Section B: Job applicants |
| You work with us as a consultant or advisor | Section C: Consultants and advisors |
| You correspond or cooperate with us in a business context | Section D: Business contacts and correspondence |
| You visit or follow our LinkedIn page | Section E: Social media |
3. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and, where processing is based on legitimate interests, the right to object (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future. To exercise your rights, contact privacy@aidvance.co. You also have the right to lodge a complaint with a supervisory authority, in particular the Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI), www.datenschutz-berlin.de.
Right to object (Art. 21 GDPR): where we process your personal data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
No automated decision-making within the meaning of Art. 22 GDPR takes place.
4. International data transfers
Some of our service providers are located in the United States. Transfers to them are based on the EU-U.S. Data Privacy Framework (adequacy decision of the European Commission) or, where a provider is not DPF-certified, on the EU Standard Contractual Clauses accompanied by a transfer impact assessment. Details are documented in our vendor inventory and transfer impact assessments.
Section A: Website visitors
A.1 Hosting and server logs
This website is hosted by Netlify, Inc., San Francisco, USA, as our processor. When you visit the site, the web server technically requires and briefly processes connection data, in particular your IP address, date and time of access, the requested page, referrer URL and browser information (server log files). Legal basis is our legitimate interest in providing and securing the website (Art. 6(1)(f) GDPR). Log data is not merged with other data sources and is deleted by the hosting provider after a short period.
A.2 No cookies, no tracking, no third-party embeds
This website does not set cookies, does not use analytics or tracking tools, does not embed social media plugins or third-party content (fonts are served from our own server) and does not run advertising. Should this change, this policy will be updated and, where legally required, your consent will be requested beforehand.
A.3 Contact by e-mail
If you contact us by e-mail, we process the data you provide to handle your enquiry (Art. 6(1)(b) GDPR where the enquiry relates to a contract, otherwise Art. 6(1)(f) GDPR). Enquiry correspondence is deleted when no longer required, unless statutory retention periods apply.
Section B: Job applicants
B.1 What data we process
- Application documents: CV, cover letter, certificates, references, portfolio
- Contact and identification data, and data you provide in interviews
- Where applicable: data received from recruiting agencies engaged by us, or from publicly available professional profiles you maintain (Art. 14 GDPR)
- Interview notes and structured assessments prepared by us
B.2 Purposes and legal bases
Decision on the establishment of an employment relationship: Section 26(1) BDSG and Art. 6(1)(b) GDPR (pre-contractual steps).
Defence against legal claims (Art. 6(1)(f) GDPR): retention of application data after a rejection for the period in which claims under the German General Equal Treatment Act (AGG) can be asserted.
Talent pool (Art. 6(1)(a) GDPR): we keep your application beyond the process only with your explicit consent, which you may withdraw at any time. Talent pool data is stored for no longer than 24 months after inclusion and is then deleted; if you withdraw your consent, it is deleted immediately.
Special categories of data (Art. 9 GDPR): please submit only information that is necessary for the application. Where your application nevertheless contains special categories of personal data (for example health data or information about a severe disability), we process it in accordance with Section 26(3) BDSG and Art. 9(2)(b) GDPR only to the extent necessary to exercise rights or comply with obligations under employment and social security law.
B.3 Recipients and retention
Access is limited to the people involved in the hiring decision. Processors include our IT providers (in particular Microsoft 365). Where a recruiting agency is involved, it either provided your profile to us or receives feedback on the process status. If we do not hire you, your application data is deleted six months after the rejection, unless you have consented to the talent pool or a legal dispute requires longer retention. If you are hired, the data becomes part of your personnel file and the privacy notice for employees applies. Provision of your application data is required to consider you for the position; every hiring decision is made by people.
Section C: Consultants and advisors
C.1 What data we process
- Identification and contact data (name, address, e-mail, phone, business details)
- Professional data (CV, qualifications, publications, affiliations, references)
- Contract and billing data (agreement terms, fees, invoices, bank details, VAT information)
- Communication content and metadata (e-mail, video calls, meeting notes and, where announced, meeting transcripts)
Where we do not collect data from you directly (Art. 14 GDPR), sources are publicly available professional profiles, publications, or referrals by partners.
C.2 Purposes and legal bases
Performance of the agreement (Art. 6(1)(b) GDPR): onboarding, coordination and management of the engagement, payment of fees.
Legal obligations (Art. 6(1)(c) GDPR): retention of accounting and tax records (Sections 147 AO, 257 HGB), audit obligations.
Legitimate interests (Art. 6(1)(f) GDPR): IT and information security, protection of intellectual property and confidential information, corporate housekeeping, and presentation of our advisory network to investors or regulatory bodies in the scope customary for such purposes.
C.3 Recipients and retention
Processors and recipients include our IT providers (in particular Microsoft 365), our tax advisors, banks for payment processing and, where required, legal counsel or authorities. We keep engagement data for the term of the agreement and delete it afterwards, unless statutory retention periods apply: six years for business correspondence and ten years for accounting and tax records. Provision of the data in C.1 is required to enter into and perform the engagement.
Section D: Business contacts and correspondence
D.1 What data we process
If you correspond or cooperate with us in a business context (for example as a clinical expert, partner, vendor contact or prospective cooperation partner), we process your contact details (name, role, organisation, e-mail, phone), the content of our correspondence, and meeting notes and, where announced, meeting transcripts. Where we do not collect data from you directly (Art. 14 GDPR), sources are publicly available professional information or referrals.
D.2 Purposes, legal basis and retention
We process this data to initiate, maintain and coordinate business relationships and partnerships. Legal basis is our legitimate interest in conducting and developing our business (Art. 6(1)(f) GDPR) or, where our contact relates to a contract, Art. 6(1)(b) GDPR. Processors include our IT providers (in particular Microsoft 365 and Notion). We keep contact and correspondence data for as long as the business relationship is relevant; business correspondence is retained for six years (Section 257 HGB).
Section E: Social media
We maintain a company page on LinkedIn to present Aidvance and communicate with the professional public. When you visit or interact with our page, LinkedIn Ireland Unlimited Company, Dublin, Ireland, processes your personal data under its own responsibility; details are set out in LinkedIn’s privacy policy. For the aggregated statistics LinkedIn provides to us about our page (Page Insights), we and LinkedIn are joint controllers (Art. 26 GDPR) on the basis of LinkedIn’s Page Insights Joint Controller Addendum. We process data in this context on the basis of our legitimate interest in corporate communication and public relations (Art. 6(1)(f) GDPR). We do not transfer the data to other systems. You can exercise your rights against LinkedIn directly, which is usually more effective, or contact us at privacy@aidvance.co.
5. Changes to this policy
We update this policy when our processing changes. The current version is always available at aidvance.co/privacy.