1. Controller
Afropean Business & Culture Network (ABCN) · [Legal form to be confirmed]
[Street address and number]
Frankfurt am Main
Germany
Represented by: Harmonie Essome (Founder & Lead)
Email: contact@abcn.network
Telephone: [Telephone number]
Data Protection Officer: A Data Protection Officer is not legally required and has not been appointed (Art. 37 GDPR, § 38 BDSG).
EU Representative: Not applicable (controller and initiative are established within Germany / the European Union).
2. Hosting and technical access data
The site currently uses Vercel (Vercel Inc.) for web hosting. Technical request data may include IP address, date/time, requested URL, browser/device metadata, and security or error information necessary to deliver and protect the service.
Event and application data is handled using Neon (Neon, Inc.) as the managed database service. The database project runs in the Frankfurt region (AWS eu-central-1), and the website’s server functions are pinned to Frankfurt as well.
Purpose & Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in technical delivery, operational resilience, and cybersecurity of the web service).
Technical Log Retention: 14 days (technical edge security and access logs for incident response and error diagnostics).
4. FIALI and event applications
The application form collects the following information strictly to evaluate eligibility:
Required information
- First name
- Last name
- Role / job title
- Email address
- Company or venture name
- Sector / business model
- Motivation for applying (free text)
- Confirmation that this privacy notice has been read
Optional information
- Country
- Phone number
- Company website
- Venture stage
- Interest in AI and digitalisation (free text)
- Interest in the startup innovation grant
In addition, the time of submission, the application’s processing status and internal administrator notes are stored. Each application is linked to the event it was submitted for.
Purposes
- Reviewing and evaluating applications for programme participation;
- Communicating regarding the selection and onboarding process;
- Planning workshops, cohort composition, and any grant allocation;
- Maintaining an internal administrative record.
Legal Basis: Art. 6(1)(b) GDPR (steps taken prior to entering into a programme agreement at the request of the applicant) and Art. 6(1)(f) GDPR (legitimate interest in fair evaluation, cohort coordination, and ecosystem matchmaking).
Application data is treated in strict confidence and is not automatically shared with third-party partners.
5. CMS and administration
Authorised ABCN administrators use a protected CMS to manage events and applications. Account details, session data, role/permission data and administrative changes are processed for security and administration. Application data is not publicly accessible.
6. Recipients, processors and international transfers
Access is limited to authorised personnel and technical service providers necessary for operation, security, and programme administration.
| Provider | Function | Processing location |
|---|---|---|
| Vercel Privacy policy | Hosting, content delivery and server-side rendering of the website. Processes technical access data such as IP address, time of request, requested URL and browser information. | Server functions are pinned to Frankfurt (fra1); static content is delivered from the nearest European edge location. |
| Neon Privacy policy | Managed database for event content and event applications, and authentication for the administration area. | The database project runs in AWS eu-central-1 (Frankfurt, Germany). |
Event listings and application submissions are sent from your browser directly to the database interface operated by Neon in Frankfurt. That service therefore receives your IP address and the technical details of the request. No other external service is contacted while you browse this site.
Data Processing & International Transfers: Data Processing Addenda (DPAs) based on EU Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR and certifications under the EU-U.S. Data Privacy Framework (DPF) are concluded with Vercel Inc. and Neon, Inc. The primary database cluster is hosted in AWS Frankfurt (eu-central-1).
7. Retention
Application Data: For the duration of the application selection procedure and programme execution, plus maximum 6 months following cohort conclusion (subject to statutory retention obligations).
Technical / Security Logs: 14 days (technical edge security and access logs for incident response and error diagnostics).
Data is deleted or anonymised when it is no longer required for the relevant purpose unless a statutory retention obligation applies.
8. Technical and organisational measures
Appropriate technical and organisational measures are in place to safeguard your data:
- All traffic is served over an encrypted HTTPS connection. HTTP Strict Transport Security instructs browsers to use encryption for every future visit as well.
- Protective response headers are set against content-type sniffing and embedding of the site in foreign frames, and access to camera, microphone and location is switched off.
- Referrer information sent to other websites is reduced to the bare domain.
- The administration area requires an individual login and an explicitly granted administrator role, and is excluded from search engine indexing.
- Application data is not readable from the public website; it is only accessible to signed-in administrators.
9. Your rights
Under the GDPR, individuals have rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21), and withdrawal of consent where applicable.
For privacy inquiries or rights requests, contact: contact@abcn.network.