Legal
GDPR policy
This policy sets out how Aurienta Life Sciences complies with the EU General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (UAVG) in its own operations, and what clients, suppliers and partners can expect from us.
Last updated 1 October 2026 · See also our Privacy policy
1. Scope
This policy applies to all personal data Aurienta Life Sciences B.V. (in formation) handles, in Amsterdam and in Shanghai, in every service line: supplier due diligence, market entry and representation, and distribution. It applies to our staff, contractors and anyone working on our behalf. Our privacy policy explains the same practices from the point of view of the people whose data we use.
2. Our principles
We follow the principles of Article 5 GDPR in everything we do:
- Lawful, fair and transparent. Every use of personal data has a legal basis and is explained in our privacy policy.
- Purpose limitation. We collect data for a stated purpose and do not reuse it for something unrelated.
- Data minimisation. We collect only what the task needs. A due diligence dossier records the people behind a company only as far as needed to show who owns and controls it.
- Accuracy. We correct data when we learn it is wrong. If a fact in a released dossier turns out to be wrong, we inform the recipients we know of and reissue it.
- Storage limitation. We keep data no longer than our retention schedule allows, then delete or anonymise it.
- Integrity and confidentiality. We protect data with technical and organisational measures (section 8).
- Accountability. We document our processing and can show how we comply.
3. Our role: controller or processor
In most of our work we decide why and how personal data is used, so we act as controller. This includes our CRM, our know-your-customer checks and the due diligence dossiers we prepare. Where a client asks us to handle personal data only on its instructions, we act as processor and sign a data processing agreement under Article 28 GDPR. Our data processing agreement is available on request from info@aurientalife.com. Where we and a partner decide together, we agree our respective responsibilities in writing under Article 26 GDPR.
4. Records and assessments
- We keep a record of processing activities as required by Article 30 GDPR, and review it at least once a year.
- Before starting a new kind of processing that may pose a high risk to people, we carry out a data protection impact assessment (DPIA). This includes the integrity and sanctions screening we carry out for due diligence.
- We build privacy into new services and tools from the start (data protection by design and by default).
5. Due diligence and screening data
Our Global Supplier Verification service and our own know-your-customer checks involve information about directors and beneficial owners of companies. We limit this to identity, role, ownership and the results of sanctions, politically exposed person and adverse media screening. We do not look for special category data. Where public sources link a person to enforcement actions or offences, we record only what is needed for the dossier, and only where Article 10 GDPR and the UAVG allow it. People named in a dossier can use their rights as described in our privacy policy.
6. Service providers
We only use service providers that give sufficient guarantees of GDPR compliance. Each one signs a data processing agreement before receiving personal data. We keep a list of our processors, including our CRM and website platform, Microsoft 365, screening database providers and, for registrations in China only, our registration agent in Shanghai, and review it when we add a new one.
7. Data storage and international transfers
- EU storage by default. We store all personal data on servers in the European Union, in our CRM and website platform (HubSpot, EU data centre) and Microsoft 365. Suppliers and partners in China submit their information directly into these EU systems. We do not keep copies on servers outside the EU.
- Remote access by our China Desk. Our China Desk team in Shanghai works only through secure login to our EU systems, with multi-factor authentication and access on a need-to-know basis. Because remote access from outside the EEA can count as a transfer under Chapter V GDPR, we cover it with the European Commission's Standard Contractual Clauses and a transfer impact assessment.
- Registration in China as the exception. Personal data is shared with and stored in China only when a client asks us to register a product or raw material there. The information needed for the registration is shared with our registration agent in Shanghai under Standard Contractual Clauses, and is also handled in line with China's Personal Information Protection Law (PIPL). We tell the client in advance which data is involved.
- Other transfers. Personal data only leaves the EEA with a valid safeguard under Chapter V GDPR: an adequacy decision, or the Standard Contractual Clauses backed by a transfer impact assessment.
8. Security
- Access on a need-to-know basis, with multi-factor authentication on business systems
- Encryption of data in transit, and of devices that hold personal data
- Confidentiality agreements with staff, contractors and every supplier we assess
- Separation of client files, so one client's data is not visible to another
- Regular review of access rights, and removal of access when someone leaves
9. Use of AI tools
We use AI tools to help research public sources and draft documents. We only use tools whose terms prevent our client data from being used to train their models. Every fact in a dossier is checked by a person against its source, and no decision about a person is made by AI alone.
10. Requests from individuals
Anyone can use their rights of access, rectification, erasure, restriction, portability and objection by writing to info@aurientalife.com. We log each request, confirm the person's identity where needed and reply within one month. If a request is complex, we may extend this by up to two more months and will explain why.
11. Data breaches
Staff report any suspected data breach immediately. We record every breach, assess the risk and, where required, notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours of becoming aware of it. Where the risk to people is high, we also inform them without undue delay.
12. Responsibility and review
Our Chief Operating Officer is responsible for data protection and can be reached at info@aurientalife.com. We have assessed that we are not currently required to appoint a statutory Data Protection Officer, and will review this as our activities grow. Staff receive data protection training when they join and each year after. We review this policy at least once a year. Last updated: 1 October 2026.
