Legal
Privacy Policy
Last updated: 13 August 2026
1. Who we are
The Building Bridges Accelerator Leaders Directory (the "Service", available at accelerator.digitalvisions.biz) is operated by Building Bridges together with Digital Visions (jointly, the "Data Controller", "we", "us"). For any privacy matter you can reach us through the contact form.
2. What data we collect
We process the following categories of personal data:
- Membership application data — name, email address, job title, organization, LinkedIn URL, location (city, state/province, country), sector and regional focus, professional "superpower", portfolio information and open asks, as submitted through the application form.
- Account data — email address and hashed password for members with directory access. Passwords are stored using industry-standard one-way hashing (bcrypt) and are never readable by us.
- Contact and interest data — name, email address, organization and message content when you use our contact, partner or membership-interest forms.
- Technical data — server logs including IP address, timestamps and requested pages, kept for security and abuse prevention.
We do not use advertising trackers, analytics profiling cookies or any third-party marketing pixels.
3. Why we process it (legal bases, art. 6 GDPR)
- Consent (art. 6(1)(a)) — publishing your professional profile in the private directory. You give this consent explicitly during the application, and you may withdraw it at any time.
- Contract (art. 6(1)(b)) — creating and maintaining your membership account and, in the future, processing membership payments.
- Legitimate interest (art. 6(1)(f)) — responding to your enquiries, keeping the Service secure, and preventing spam and abuse.
- Legal obligation (art. 6(1)(c)) — retaining billing records where tax or accounting law requires it.
4. Who can see your profile
The directory is private. Full member profiles are visible only to authenticated, verified members of the network. Public pages show only aggregate, anonymized statistics (for example the total number of members or countries represented) — never names, emails or other identifying information.
5. Sharing and processors
We do not sell or rent personal data. Data is shared only with technical service providers acting as data processors: our hosting provider (Hetzner Online GmbH, Germany — data hosted in the EU) and, once payments launch, Stripe Inc. as payment processor. Each processor is bound by a data-processing agreement.
6. International transfers
Data is stored on servers located in the European Union. If a transfer outside the EEA ever becomes necessary (for example payment processing via Stripe), it will rely on adequacy decisions or Standard Contractual Clauses.
7. Retention
- Member profiles and accounts — kept while your membership is active, and deleted or anonymized within 90 days of a verified deletion request or account closure.
- Rejected or withdrawn applications — deleted within 12 months.
- Contact form messages — kept up to 24 months so we can follow up, then deleted.
- Server logs — kept up to 12 months for security purposes.
- Billing records — kept for the period required by applicable tax law.
8. Your rights
Under the GDPR you have the right to:
- Access — obtain a copy of the personal data we hold about you (art. 15);
- Rectification — have inaccurate data corrected (art. 16);
- Erasure — have your data deleted ("right to be forgotten", art. 17);
- Restriction — limit how we process your data (art. 18);
- Portability — receive your data in a structured, commonly used, machine-readable format (art. 20);
- Objection — object to processing based on legitimate interest (art. 21);
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, use the contact form. We respond within 30 days. You also have the right to lodge a complaint with your local data protection supervisory authority.
9. Security
The Service runs over HTTPS only. Passwords are hashed with bcrypt, access to member data is restricted to authenticated sessions, and the infrastructure is maintained with regular security updates.
10. Changes to this policy
We may update this policy as the Service evolves. Material changes will be announced to members by email or through the Service. The "last updated" date at the top always reflects the current version.
See also our Terms of Service and Cookie Policy.