top of page

Privacy Policy

Last update: 11 September 2026

Data protection is a top priority for us as a Switzerland-based company. That is why we implement controls to ensure your information remains protected and confidential throughout our collaboration.
​
For clients using our platform, tools and services, we have an additional Policy PMF-Engine.​

Venture Guidebook, an ​​A-QUANTO AG (or AQUANTO) company, is committed to protecting, maintaining confidentiality, and preserving the privacy of the information and data entrusted to us. We take appropriate measures to comply with applicable data protection regulations.

​

This privacy policy applies to all data we collect as data controllers concerning our business activities and website,
venture-guidebook.com. It does not apply to data we process on behalf of our customers, where our customers act as data controllers.

​

We regularly review and update this privacy policy and adapt our measures to meet requirements. The most current version is available on our website, and we recommend reading it periodically. 

​

Please read this privacy policy to learn about your rights, what data we collect, and how we use and protect it.​

​

Why we need personal data

We collect personal data primarily to provide and market our products and services (including our website), fulfil contracts and obligations, and perform our duties. We aim to be fully transparent when collecting data and only collect and process relevant information.

​

Some products and services cannot be provided or used without your consent. Where we rely on consent, we ask for it separately and clearly. Browsing our website does not by itself mean that you consent to this privacy policy. This policy explains how we handle personal data so that you can understand our practices and exercise your rights.

 

Furthermore, we are legally obliged to collect specific personal data to document our business activities and retain it for the period defined by the authorities (retention obligation).

​

Legal basis for processing

We process personal data only where we have a lawful basis to do so. Under the Swiss FADP, processing is lawful when it complies with the data protection principles and, where required, is justified by consent, an overriding private or public interest, or the law. Under the GDPR, we rely on the bases set out below.

  • Providing, operating, and marketing our products, services, and website: Performance of a contract and our legitimate interest in running and promoting our business.

  • Sending newsletters, subscriptions, and marketing communications: Your consent, which you can withdraw at any time.

  • Fulfilling contracts and related obligations with clients and partners: Performance of a contract.

  • Meeting legal and regulatory duties, such as accounting and retention: Compliance with a legal obligation.

  • Securing our website and preventing or investigating abuse: Our legitimate interest in protecting our systems and users.

  • Setting non-essential cookies and analytics: Your consent.

​​

How we collect personal data

We collect personal data on a lawful basis and limit collection to what is relevant. Depending on the situation, that basis may be your consent, the performance of a contract, a legal obligation, or a legitimate interest that does not override your fundamental rights. We may also collect publicly available data where it is in our legitimate interest, provided it is appropriate and does not override fundamental rights. How we collect personal data:

  • Directly: We receive personal data directly from individuals who use our website, actively participate in community activities (e.g., in blogs, forums, or events), register for publications, subscriptions, or newsletters, or contact us directly (e.g., via phone, email, contact forms, or personal meetings).

  • Indirectly: We also receive personal data indirectly through third parties, customer orders, public sources, or partner companies. In this situation, we predominantly act as data processors. Please ensure that, through the relevant service, you transmit the data you wish to provide to us.

​

We will obtain explicit consent from individuals before collecting, processing, or storing sensitive personal data. We obtain consent through explicit affirmative action, such as ticking a box on a web form. We ensure that consent is freely given after being informed. Individuals are informed about their right to withdraw consent at any time and the straightforward process to do so.

​

We may aggregate and augment personal data in profiles (e.g., in the CRM system) to better understand and serve our customers, partners, prospects, subscribers, and individuals, fulfil a legal obligation, or pursue our legitimate interests.

.​

 

What personal data do we collect

The specific data we collect and process depends significantly on the respective interaction and which products and services are used. Below is further information on the personal data collected in connection with our activities.

​​

Personal data refers to all information that identifies you personally, including contact information such as name, email address, company name and address, phone number, and other information about you or your company. Additionally, technical information such as log files, transactions, IP address of the internet device, browsing behaviour on our websites, or navigation/location data may also be personal data if it is possible to identify you directly or indirectly through it.

 

We avoid collecting, processing, and storing sensitive personal data whenever possible and only collect it for legitimate purposes. Sensitive personal data refers to particularly protected information, such as credit or debit card numbers, government-issued documents (e.g., passport, social security), biometric information, personal health information, personal information of children, or combinations of information that fall under the definition of "special categories of data" (according to the EU General Data Protection Regulation, GDPR) or other applicable privacy and data protection laws.

​

Use of personal data

In addition to the purposes already mentioned, we may use your personal data to:

  • Improve and further develop our products and services.

  • Provide or send you information that we believe may be of interest to you and is related to the products and services you use.

  • Send advertising or informational content in accordance with your communication preferences.

  • Collect statistical information on the use of our products and services, including the website, and use it to improve the experience and personalisation.

  • Serve you concerning administrative or support activities.

  • Monitor, prevent, or investigate security issues or abuse.

  • Fulfil legal requirements.

​

We may contact you on behalf of our external business partners or customers. In this case, we process your data only on behalf of the data controller, whether a customer or a partner.

 

We do not make decisions that produce legal effects concerning you, or similarly significantly affect you, based solely on automated processing, including profiling, within the meaning of Article 22 GDPR. Any AI-supported features we use assist our team and do not replace human judgement on decisions that affect you. Should this change, we will update this section and inform you.

​

Disclosure and sale of personal data to third parties

We never sell your personal data to third parties.

​

We do rely on trusted subcontractors and service providers to support our business operations and deliver services. All such providers are carefully vetted and bound by data protection agreements to uphold the same data protection and security standards that we follow. For example, we use Notion as a cloud-based workspace to manage content and some client information, and Miro as an online collaborative whiteboard tool for client projects. These platforms act as data processors on our behalf and process personal data only under our instructions and for the purposes we specify. Notion's platform is hosted on Amazon Web Services (AWS) and employs strong encryption to protect data at rest and in transit, in line with its commitments to EU GDPR compliance and international data transfer safeguards (e.g. standard contractual clauses). Likewise, Miro implements strong security measures. All data on Miro is encrypted in transit and at rest, and access is restricted through role-based permissions. Miro affirms its compliance with major data privacy laws, such as GDPR, and does not sell or share personal data with unrelated third parties. We ensure that each of our subcontractors (including Notion, Miro, and other service providers such as our payment and analytics providers) uses your data only for the intended purposes and maintains the confidentiality and security of your information. We remain responsible for protecting your personal data throughout these processing activities.

 

Transfer of personal data abroad

Some of our service providers process personal data outside Switzerland and the EU/EEA, mainly in the United States. Where a provider is certified under the Swiss-US and EU-US Data Privacy Framework, we rely on that adequacy; where it is not, we put in place either contractual clauses or our own controls. Data stays encrypted in transit and at rest, and we remain responsible as data controller. You can request details of the providers involved and information of the safeguards by contacting us.​

​

Your privacy rights

In connection with data processing, you have the rights listed below:

  • Access: You can ask us to verify whether we are processing your personal data and, if so, to provide more detailed information.

  • Correction: You can ask us to correct our records if you believe they contain incorrect or incomplete information about you.

  • Deletion: You can ask us to delete your personal data after you withdraw your consent to processing. In general, we delete your data that is no longer needed. Note that we cannot delete all your personal data due to legal obligations (e.g., historical data or data for accounting purposes).

  • Data portability: If you have provided us with personal data and it is technically feasible, you can ask us to transfer it electronically.

  • Processing restrictions: You can ask us to temporarily restrict the processing of your personal data if you dispute its accuracy or prefer to restrict its use rather than delete it.

  • Right to object to marketing, including profiling: You can object to the use of your personal data for marketing purposes, including profiling. We may need to retain some minimal information to comply with your request to stop marketing to you.

  • Right to withdraw consent: You can withdraw your consent to the processing of your personal data. This does not affect the legality of the processing carried out before the withdrawal of your consent. It may mean we cannot offer you certain products or services; in such cases, we will inform you.

​​

Before responding to a request regarding your data rights, we may ask you to provide proof of identity. This helps ensure that personal data is not disclosed to individuals who have no right to receive this data. We may also ask for sufficient information about your relationship with us so that we can locate your personal data.

​

Individuals have the right to be forgotten and get in touch with our data protection contact using the details below to exercise this right. We will respond to such requests without undue delay and ensure that data is erased from all systems, unless retention is required by law.

 

If your request is unfounded or excessive, we may refuse your request or charge a fee. We reserve the right not to comply with your request for legitimate reasons.

​

Cookies and tracking technologies

We, our partners and subcontractors use cookies or similar technologies (such as web beacons and JavaScript) to manage the website and its functions, analyse usage, track user activities, and collect aggregated demographic data about our users. Collecting this information allows us to customise the online experience, improve the performance, security, usability, and effectiveness of our web presence, and measure the effectiveness of our marketing, product, or service promotion activities.

​

We use cookies that are strictly necessary to operate the website without asking for consent. For all non-essential cookies and tracking technologies, including analytics and marketing cookies and any cross-site tracking, we ask for your consent before they are set, in line with the guidance of the Swiss Federal Data Protection and Information Commissioner (FDPIC). You can accept or decline these cookies and change your choice at any time through our cookie settings. Providers of non-essential cookies and referenced sites may collect additional technical data; where a third party sets its own cookies through content we reference, we do not control that collection.

​

For more information on our use of cookies and how to manage your cookie settings, please see our Cookie Notice.

​​

Security and confidentiality of personal data

We use various security technologies and procedures to protect the confidentiality and security of personal data. These procedures protect personal data from unauthorised access, use, damage, or disclosure. We protect personal data using measures such as encryption, security certificates, or strong multi-level authorisation procedures. Additionally, appropriate physical, technical, and organisational measures protect personal data.​

 

We cannot take responsibility for external websites, third-party content, or links to this information on our website, products, or services.

​​

Retention of personal data

We retain personal data only for as long as necessary for the purposes for which it was collected, according to statutory requirements and any other legal obligation. When personal data is no longer needed for these purposes and no legal retention period requires us to keep it, we delete it.

​

Data breach notification and protocol

In the event of a data breach, we will follow a structured protocol to mitigate risks and inform relevant parties:

  1. Detection and containment: Immediate steps to identify and contain the breach.

  2. Assessment: Evaluate the extent of the breach and potential impact.

  3. Notification: Where the breach is likely to result in a risk to individuals, we notify the competent supervisory authority without undue delay and, under the GDPR, within 72 hours of becoming aware of it. Under the Swiss FADP, we notify the Federal Data Protection and Information Commissioner as soon as possible. If the breach is likely to result in a high risk to individuals' rights and freedoms, we also inform the affected individuals without undue delay.

  4. Remediation: Take corrective actions to prevent future breaches and minimise harm.

  5. Documentation: Maintain records of the breach, including its impact and the measures taken.

​

Data protection contact

If you have any questions about this privacy policy or our data protection practices, please get in touch with us at:

​​

Email: guide@venture-guidebook.com

 

Contact: Christian Hug

Address: Venture Guidebook by A-QUANTO AG, Nordstrasse 9, CH-8006 Zürich

 

Data protection authority: We are subject to the Swiss Federal Data Protection and Information Commissioner. If you believe your rights have been violated, you have the right to submit a complaint to the data protection authority.

​

We reserve the right to modify this privacy policy and related documents at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their posting on the website. If we make material changes to this policy, we will notify you here that it has been updated, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it. 

​

The AQUANTO team is committed to complying with data protection regulations and ensuring the privacy and security of the personal data we process. Thank you for your trust.

​

Version history

This is Version 1.4, effective 11 September 2026. Earlier versions:

  • Version 1.3: 10 February 2026

  • Version 1.2: 6 May 2025

  • Version 1.1: 14 January 2025

  • Version 1.0: 3 September 2024

bottom of page