Privacy Policy
How we collect, use and protect personal data on Open Venture.
Last updated 15 Jul 2026 · Effective 1 Aug 2026
This is the published version, free to read without an account. The version archive, and requests to export or erase your data, live in your workspace once you have signed in.
1. Who we are
Open Venture GmbH, Berlin, is the data controller for your account data. For content inside an organization's workspace (submissions, pipelines, assessments), the organization is the controller and we process that data on its behalf. Our Data Protection Officer can be reached at privacy@openventure.com.
2. Data we collect
You give us: name, work email, job title, organization, profile details, and the content you create — submissions, messages, assessments, and files you attach.
We generate usage events (screens visited, features used), device and log data, and derived signals such as match scores. We do not collect payment card data — sponsorship invoicing runs through our accounting provider.
3. How we use your data
To run the platform: matching startups to challenges, routing submissions to reviewers, powering analytics for your organization, and sending the notifications you have enabled. To improve it: aggregated, de-identified usage analysis. To communicate: service messages always; product updates only if you opted in. We never sell personal data, and we never charge applicants or monetize their submissions.
5. Retention
Account data is kept while your account is active and deleted within 30 days of account deletion, except where the law requires longer retention. Organization-owned content follows the organization's retention settings. Backups roll off within 35 days.
6. Your rights & choices
You can access, correct, export, or delete your personal data, object to or restrict processing, and withdraw consent at any time. Most of this is self-service: edit your profile directly, export your data from Settings, or delete your account entirely. We respond to requests within 30 days as required by the GDPR. You can also complain to your local supervisory authority.
7. Security
All traffic is encrypted in transit and data is encrypted at rest. Access to production data is role-restricted and logged. Two-factor authentication is available on every account, and organization admins can review and revoke active sessions. We notify affected users and authorities of any qualifying breach without undue delay.
8. International transfers
Data is hosted in the EU. Where a sub-processor processes data outside the EU/EEA, transfers rely on adequacy decisions or Standard Contractual Clauses with supplementary measures.
9. Changes to this policy
When we make material changes we notify you by email and in-app before they take effect, and update the version and dates at the top of this page. Earlier versions are listed below.