Legal

Privacy policy

This policy explains what personal data Aurienta Life Sciences collects, why we use it, who we share it with and what your rights are. It applies to our website, our events and our business relationships with clients, suppliers and partners.

Last updated 1 October 2026 · See also our GDPR policy

1. Who we are

Aurienta Life Sciences B.V. (in formation) is the controller of your personal data. We are a private limited company under Dutch law, based in Amsterdam, the Netherlands. Our KvK number will be added once registration is complete.

For any question about this policy or your personal data, write to info@aurientalife.com.

2. What personal data we collect

  • Contact and meeting requests. Your name, business email, company, job title, country, the topics you choose and your message, when you fill in a form on our website or give us your details at an event such as CPHI Milan.
  • Business correspondence. Your name, contact details and the content of emails, calls and meetings with us.
  • Client, supplier and partner contacts. Names, roles and business contact details of people at the companies we work with.
  • Due diligence data. For our Global Supplier Verification service and our own know-your-customer checks: names, roles and ownership interests of directors and beneficial owners, and results of sanctions, politically exposed person and adverse media screening. We take this from public registers, official lists and public sources, or from the company itself.
  • Website data. Pages visited, device and browser type, approximate location and how you reached our site, collected through cookies once you allow them (see section 9).

We do not ask for sensitive data such as health, religion or political opinions, and we ask you not to send it to us.

3. Why we use it and our legal basis

PurposeLegal basis under the GDPR
Answering your request and arranging a meetingSteps at your request before a contract (Art. 6(1)(b)) or our legitimate interest in responding to business enquiries (Art. 6(1)(f))
Delivering our services and managing our relationship with youPerformance of a contract (Art. 6(1)(b))
Know-your-customer, sanctions and anti-bribery checks on clients and suppliersLegal obligations, including EU sanctions law (Art. 6(1)(c)), and our legitimate interest in not working with sanctioned or unidentifiable parties (Art. 6(1)(f))
Preparing supplier due diligence dossiersOur legitimate interest, and that of the buyers who rely on the dossier, in knowing who a supplier is (Art. 6(1)(f))
Sending news and invitations about our servicesYour consent (Art. 6(1)(a)), or our legitimate interest for existing business contacts. You can opt out at any time.
Analysing how our website is usedYour consent through the cookie banner (Art. 6(1)(a))
Bookkeeping and taxLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interest, we have weighed it against your rights. You can ask us about that assessment.

4. Who we share it with

We never sell personal data. We share it only where needed:

  • Service providers who process data for us under a data processing agreement, such as our CRM and website platform (HubSpot), Microsoft 365 for email and documents, and screening database providers.
  • Our China Desk in Shanghai, where a request or project concerns China. The team works only through secure login to our EU-based systems and does not keep separate copies.
  • Our registration agent in China, only when you ask us to register a product or raw material in China.
  • Partners you ask us to introduce you to, such as distributors, regulatory consultants or authorised representatives, and only with your agreement.
  • Clients who commission a due diligence dossier, for the data in that dossier.
  • Advisers and authorities, such as our accountants and lawyers, or a public authority where the law requires it.

5. Where your data is stored

On servers in the European Union. We store personal data in our EU-based systems: our CRM and website platform (HubSpot, EU data centre) and Microsoft 365. Suppliers and partners in China and other countries submit their information directly into these EU systems.

Access by our China Desk. Our China Desk team in Shanghai does not keep its own copy of your data. When the team needs information, it logs in to our EU systems through a secure connection with multi-factor authentication, and only sees what its task requires. Under the GDPR, viewing EU data from outside the EEA can count as a transfer. Where it does, we protect it with the European Commission's Standard Contractual Clauses and a transfer impact assessment.

Registration in China, only on request. Personal data is only stored in China when you ask us to register a product or raw material there. Chinese law requires a local agent for that registration, so the information needed for the registration file is shared with and stored by our registration agent in Shanghai. We tell you in advance which data is involved and protect the transfer with Standard Contractual Clauses. In China, the data is also protected under China's Personal Information Protection Law (PIPL).

Other service providers. If a service provider processes data outside the EEA, for example for technical support, we use the safeguards the GDPR requires: an adequacy decision by the European Commission (including the EU–US Data Privacy Framework where a US provider is certified), or the Standard Contractual Clauses. You can ask us for a copy of the safeguards that apply.

6. How long we keep it

DataRetention period
Contact and meeting requests that do not lead to a business relationship24 months after our last contact
Client, supplier and partner recordsFor the relationship, then 5 years
Know-your-customer and screening records5 years after the end of the relationship or assignment
Due diligence dossiers5 years after release, unless the client contract says otherwise
Invoices and accounting records7 years, as Dutch tax law requires
Website analytics cookiesAs stated in the cookie banner, at most 13 months

7. How we protect it

We use access control, multi-factor authentication, encryption in transit, confidentiality agreements and regular reviews of who can see what. Only people who need data for their work can access it. If a data breach occurs, we follow our breach procedure and notify the Dutch Data Protection Authority and affected people where the GDPR requires it.

8. Your rights

Under the GDPR you have the right to:

  • see the personal data we hold about you (access)
  • have incorrect data corrected (rectification)
  • have your data deleted, where there is no reason for us to keep it (erasure)
  • have the use of your data restricted (restriction)
  • receive your data in a usable format (portability)
  • object to our use of your data based on legitimate interest, and to direct marketing at any time (objection)
  • withdraw your consent at any time, without affecting earlier use

To use any of these rights, write to info@aurientalife.com. We may ask you to confirm your identity. We will reply within one month.

If you are not satisfied with how we handle your data, you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), autoriteitpersoonsgegevens.nl, or to the authority in the EU country where you live or work.

9. Cookies

Our website uses strictly necessary cookies to work and to remember your cookie choice. Analytics and marketing cookies, including HubSpot cookies that tell us which pages are visited, are placed only after you accept them in the cookie banner. You can change your choice at any time through the cookie settings link on our website or in your browser.

10. Changes to this policy

We may update this policy as our services develop. The latest version is always on this page. Last updated: 1 October 2026.