Skip to content
UniPrisma
About
  • Startups
  • VCs
  • Universities
  • Medtech & Biotech
News & Insights

Privacy Policy

Last updated: 27 July 2026

1. Introduction

UniPrisma Kft. (registered office: Révay köz 4, 1065 Budapest, Hungary; company registration number at the Company Registry Court of the Metropolitan Court of Budapest: 01-09-448571; hereinafter: the “Data Controller” or “UniPrisma”), operating UniPrisma Venture Studio, pays particular attention to ensuring that its activities comply with the applicable legal requirements governing personal data.

This includes, in particular, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the “General Data Protection Regulation” or “GDPR”), and the provisions of Act CXII of 2011 on the right to informational self-determination and freedom of information.

The purpose of this Privacy Policy is to ensure transparency of the Data Controller’s data processing activities and to inform all individuals whose personal data is processed (the “Data Subjects”) about their rights and about how their data is handled.

This Privacy Policy applies to personal data processed in connection with UniPrisma’s activities: operating the website uniprisma.com, responding to enquiries, co-building ventures with founders, universities, and research institutions, facilitating investment and co-investment, conducting market and technology validation, and maintaining relationships with founders, investors, universities, partners, and other stakeholders of the innovation ecosystem.

2. Data Controller

The Data Controller responsible for your personal data is:

Name: UniPrisma Kft.

Registered office: Révay köz 4, 1065 Budapest, Hungary

Company registration number: 01-09-448571 (registered by the Company Registry Court of the Metropolitan Court of Budapest)

VAT number: 26606572-2-42

International VAT number: HU26606572

Managing Director: Károly Zoltán Szántó

Contact for privacy matters: Hello@uniprisma.com

We are not required to appoint a statutory Data Protection Officer under Article 37 GDPR. Privacy enquiries are handled by Thijmen Meijer, Chief Operating Officer, reachable at the email address above.

3. Principles of data processing

In line with Article 5 GDPR, the Data Controller applies the following principles to all processing of personal data:

Lawfulness, fairness and transparency. The Data Controller processes personal data lawfully, fairly, and in a transparent manner, cooperating with Data Subjects and providing clear information about how their data is handled.

Purpose limitation. Personal data is collected only for specified, explicit, and legitimate purposes, and is not further processed in a manner incompatible with those purposes.

Data minimisation. The Data Controller limits the personal data collected and processed to what is strictly necessary for the purposes identified in this Policy.

Accuracy. The Data Controller takes reasonable steps to keep personal data accurate and up to date, and to promptly correct or delete inaccurate data upon request.

Storage limitation. Personal data is retained only for as long as necessary for the purposes for which it was collected, in line with the retention periods set out in this Policy.

Integrity and confidentiality. The Data Controller protects personal data against unauthorised access, loss, misuse, alteration, disclosure, or destruction through appropriate technical and organisational measures.

Accountability. The Data Controller is responsible for complying with the principles above and is able to demonstrate compliance with them.

4. Personal data we collect

Depending on how you interact with UniPrisma, we may collect the following categories of personal data.

Identification and contact data

  • Full name
  • Job title or role
  • Organisation name and type
  • Work email address
  • Phone number, where provided
  • Country of operation

Professional information

  • Role and seniority
  • Your organisation’s type (startup, venture capital fund, university, technology transfer office, research institution, corporate partner, or other)
  • Venture or institutional details you choose to share, such as the technology or research involved, stage, funding history, market focus, or investment strategy
  • Publicly available information about you or your organisation
  • Visual brand assets: organisation logo files provided to us for use in our materials

Correspondence and meeting records

  • Emails, calls, and meeting notes arising from our interactions
  • Responses to forms you submit to us
  • Notes and records kept in our customer relationship management system
  • Where AI-assisted transcription or meeting summary tools are used, the transcribed content of meetings. We currently use Google Meet’s “Take notes for me” (Gemini-powered) and Attio Notetaker for this purpose. The use of such tools requires your prior consent, obtained at the start of the meeting.

Technical data (website)

  • IP address
  • Browser type and device information
  • Pages visited and time on site
  • Referral source

We do not knowingly collect special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, or health data). If you share such data with us voluntarily, we will only process it where we have a valid legal basis under Article 9 GDPR.

5. How we collect your data

We collect personal data through the following channels.

Directly from you

  • When you submit the contact form on uniprisma.com
  • When you email us, write to us, or respond to our outreach
  • When you connect with us on LinkedIn or similar professional networks
  • When you take part in a meeting, call, or interview with us
  • When you attend an event at which we are present

From publicly available sources

  • Your organisation’s website
  • Public professional profiles, including LinkedIn, company registries, and press releases
  • Public databases relevant to venture capital and research commercialisation, including Dealroom, Crunchbase, and university technology transfer listings

From third parties

  • Mutual contacts who introduce you to us
  • Event organisers, where you have consented to share your details
  • Referral partners and co-investors

6. Why we use your data and legal basis

We process your personal data for the purposes below. Each processing activity has a defined legal basis under Article 6 GDPR.

Responding to enquiries submitted through our website or by email. Legal basis: your consent (Article 6(1)(a) GDPR), and, where relevant, pre-contractual steps taken at your request (Article 6(1)(b) GDPR).

Building and maintaining relationships within the innovation and venture capital ecosystem. Legal basis: our legitimate interest in developing UniPrisma’s venture building activity and maintaining relevant professional relationships with founders, investors, universities, and partners (Article 6(1)(f) GDPR). You have the right to object to this processing at any time.

Contacting you about UniPrisma’s activities, including co-building opportunities, insights, and announcements. Legal basis: your consent for marketing communications (Article 6(1)(a) GDPR); legitimate interest for direct professional correspondence relevant to your role (Article 6(1)(f) GDPR).

Delivering venture building services and fulfilling our agreements with founders, portfolio companies, investors, and partners. Legal basis: performance of a contract to which you or your organisation is a party (Article 6(1)(b) GDPR).

Assessing ventures, research, and investment opportunities, including technical and market validation. Legal basis: legitimate interest (Article 6(1)(f) GDPR), and, where you have approached us with a proposal, pre-contractual steps taken at your request (Article 6(1)(b) GDPR).

Facilitating introductions to investors and co-investors, where you have asked us to do so or agreed to it. Legal basis: your consent (Article 6(1)(a) GDPR).

Keeping accurate records of meetings with you, including the use of AI transcription or summary tools. Legal basis: your explicit prior consent (Article 6(1)(a) GDPR), obtained at the start of the meeting. You may withdraw consent at any time.

Complying with our legal, accounting, and tax obligations. Legal basis: compliance with legal obligations to which we are subject (Article 6(1)(c) GDPR).

Securing our systems and preventing fraud or abuse. Legal basis: legitimate interest (Article 6(1)(f) GDPR).

Displaying your name, organisation, role, and logo in public UniPrisma materials, including the uniprisma.com website, the UniPrisma LinkedIn page and other social media channels, communications, presentations, reports, and events. Legal basis: your consent (Article 6(1)(a) GDPR), captured at the point of entering into cooperation or in subsequent correspondence. You can withdraw this consent at any time by writing to Hello@uniprisma.com, and we will remove your name and logo from active materials within a reasonable period. Historical references already included in previously published materials, reports, or event documentation may remain in place.

Legitimate interest assessment: where we rely on legitimate interest as a legal basis, we have conducted a balancing test to ensure that your rights and freedoms do not override that interest. A copy of the relevant legitimate interest assessment is available on request by contacting Hello@uniprisma.com.

7. Who we share your data with

Your personal data may be shared with the following categories of recipients.

The UniPrisma team: Currently Károly Zoltán Szántó (CEO and Managing Director) and Thijmen Meijer (COO). Access may be extended to future UniPrisma employees, contractors, and advisors on a strict need-to-know basis.

Our service providers (processors): Each service provider acts on our instructions under a written data processing agreement meeting the requirements of Article 28 GDPR.

Provider Service Location of processing
Attio Customer relationship management; Attio Notetaker (AI meeting notes and summaries linked to contact records) United States
Clever Cloud SAS Website hosting, and hosting of the internal system that receives contact form submissions France (EU), hosted in Paris; processing takes place entirely within the EU, so no third-country transfer is involved for this processor
Plausible Insights OÜ Cookie-free website analytics (Plausible Analytics) Estonia (EU), with data hosted in the EU
Google Ireland Limited (Google Workspace) Email, calendar, document storage; Google Meet “Take notes for me” (Gemini-powered AI meeting summaries); Google Analytics 4 where you have accepted analytics Ireland (EU), with sub-processors in the United States
Slack Technologies Limited Internal messaging, including notification of new contact form submissions Ireland (EU), with sub-processors in the United States

Additional processors may be engaged from time to time. An up-to-date list is available on request.

Co-investors, investors, and partners: Where you have asked us to make an introduction, or have otherwise agreed to it, we may share relevant details of you and your venture with investors, co-investors, or partners.

Professional advisors: Lawyers, accountants, and other professional advisors bound by professional confidentiality obligations.

Public authorities: Where disclosure is required by law, court order, or regulatory process.

Public materials: Where you have consented, your name, organisation, and logo may be displayed publicly on uniprisma.com, on our social media channels, and in our publications, events, and ecosystem materials. This means the information will be accessible worldwide. You can request removal at any time by writing to Hello@uniprisma.com.

What we do not do

  • We do not sell your personal data.
  • We do not share your personal data with advertising networks.
  • We do not publish individual-level data without your explicit consent.

8. International data transfers

Some of our service providers, or their sub-processors, are based outside the European Economic Area (EEA), primarily in the United States. When we transfer your personal data outside the EEA, we rely on the safeguards recognised under Chapter V of the GDPR.

EU-US Data Privacy Framework. Where the processor is certified under the Data Privacy Framework, we rely on the adequacy decision of the European Commission of 10 July 2023 (Commission Implementing Decision (EU) 2023/1795).

Standard Contractual Clauses. Where the Data Privacy Framework does not apply, we enter into the Standard Contractual Clauses adopted by the European Commission under Commission Implementing Decision (EU) 2021/914.

Transfer impact assessments. Where required, we conduct transfer impact assessments to confirm that the safeguards provide a level of protection essentially equivalent to that of the GDPR.

You can request a copy of the safeguards applicable to transfers of your personal data by contacting Hello@uniprisma.com.

9. How long we keep your data

We retain personal data only as long as necessary for the purposes set out in this Policy and to meet our legal obligations. Specific retention periods are as follows.

  • Contact form submissions and enquiries: up to 3 years from our last contact with you, or sooner if you request deletion.
  • CRM records of active relationships: for the duration of the relationship, plus 3 years after it ends.
  • CRM records of prospects contacted but not engaged: up to 3 years from the last meaningful contact; sooner if you object.
  • Records relating to portfolio companies and investments: for the duration of the relationship, plus 8 years, as required by Hungarian accounting and tax law.
  • Meeting notes and AI-assisted transcripts: up to 1 year after the meeting, unless you withdraw consent sooner.
  • Marketing mailing list entries: until you unsubscribe or withdraw consent.
  • Event attendance records: up to 3 years after the event.
  • Website technical logs: typically up to 30 days.
  • Legal, accounting, and tax records: 8 years, as required by Hungarian law.
  • Logos and brand assets provided for our materials: for the duration of your participation, plus a reasonable period to remove them from active materials following withdrawal.

At the end of the applicable retention period, we delete or irreversibly anonymise the data.

10. Your rights

Under the GDPR, you have the following rights in relation to your personal data.

Right of access (Article 15). You can ask us to confirm whether we process your personal data and to obtain a copy, along with information about how we use it.

Right to rectification (Article 16). You can ask us to correct inaccurate or incomplete data about you.

Right to erasure (Article 17). You can ask us to delete your data where one of the grounds in Article 17 applies, for example where the data is no longer needed, you withdraw consent, or you object to processing.

Right to restriction of processing (Article 18). You can ask us to limit how we use your data in specific situations, for example while we verify a correction request or assess an objection.

Right to data portability (Article 20). Where processing is based on consent or contract and carried out by automated means, you can ask us to provide your data in a structured, commonly used, machine-readable format, or to transmit it directly to another controller where technically feasible.

Right to object (Article 21). You can object to processing based on our legitimate interest at any time. You have an unconditional right to object to processing for direct marketing purposes.

Right to withdraw consent (Article 7(3)). Where we process your data based on your consent, you can withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Right not to be subject to solely automated decision-making (Article 22). UniPrisma does not make decisions about you using solely automated processing that produce legal or similarly significant effects.

11. How to exercise your rights

To exercise any of the rights above, email Hello@uniprisma.com with a brief description of your request. We will respond within one month of receiving your request, as required by Article 12(3) GDPR. Where requests are complex or numerous, we may extend this period by a further two months and will inform you of any extension within one month of receipt.

Where your request is submitted electronically, we will respond electronically unless you ask otherwise.

We may need to verify your identity before acting on your request, in order to protect your personal data.

Exercising your rights is free of charge. We reserve the right to charge a reasonable fee or to refuse to act where a request is manifestly unfounded or excessive, in accordance with Article 12(5) GDPR.

12. Right to lodge a complaint and judicial remedy

If you believe we are not processing your personal data in accordance with the law, you have the right to lodge a complaint with a data protection supervisory authority. You also have the right to an effective judicial remedy.

Supervisory authority in Hungary

Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)

Headquarters: 1055 Budapest, Falk Miksa utca 9-11., Hungary

Postal address: 1363 Budapest, Pf. 9., Hungary

Telephone: +36 (1) 391-1400

Fax: +36 (1) 391-1410

Email: ugyfelszolgalat@naih.hu

Website: naih.hu

Other supervisory authorities: You may also lodge a complaint with the supervisory authority of the Member State of your habitual residence, place of work, or place of the alleged infringement, in accordance with Article 77 GDPR.

Judicial remedy: You have the right to apply to the competent court of your place of residence or habitual abode, in accordance with Article 79 GDPR. We would appreciate the chance to address your concerns directly before you contact a supervisory authority or court. If you have any issues with how we handle your data, please write to Hello@uniprisma.com first and we will respond promptly.

13. Cookies and website analytics

Our website records whether you have responded to our analytics notice. With your consent, we use Google Analytics 4, whose cookies are set only after you accept on our cookie banner. We also use Plausible Analytics, an EU-hosted analytics service that sets no cookies at all. Our contact form runs on our own website and sets no third-party cookies. We do not use advertising cookies, cross-site tracking, or social media trackers. If we introduce marketing tools in future, we will update this Policy and re-prompt your consent through the cookie banner before setting any new non-essential cookies. Full details, including the specific cookies set, their purposes, and how to manage your preferences, are available in our separate Cookie Policy at uniprisma.com/cookie-policy.

14. How we protect your data

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, misuse, or alteration. These measures include:

  • Encryption of data in transit (HTTPS, TLS) and at rest
  • Access controls limiting data access to authorised team members
  • Strong authentication requirements on all work systems
  • Firewall, antivirus, and spam protection on the Data Controller’s systems
  • Password protection on electronic devices
  • Regular backups and business continuity planning
  • Vendor due diligence and data processing agreements with all processors
  • Incident response procedures in the event of a personal data breach

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and, where the breach is likely to result in a high risk, inform affected individuals without undue delay, in accordance with Articles 33 and 34 GDPR.

We maintain a record of personal data breaches in accordance with Article 33(5) GDPR, including the scope of affected personal data, the range and number of affected Data Subjects, the time, circumstances, and impact of the incident, and the measures taken to resolve it.

15. Children’s data

UniPrisma’s activities are directed at professional audiences. We do not knowingly collect personal data from children under the age of 16. If you believe we hold data from a minor, please contact Hello@uniprisma.com and we will delete it promptly.

16. Changes to this Policy

The Data Controller reserves the right to amend this Policy from time to time to reflect changes in our practices, our service providers, or legal requirements. Any updates will be posted on this page with a revised “last updated” date at the top.

For material changes, we will notify you by email where we have your contact details on file, or through a prominent notice on our website, with reasonable prior notice.

17. Contact us

For any questions about this Policy or about how we process your personal data, please contact us.

Email: Hello@uniprisma.com

Post: UniPrisma Kft., Révay köz 4, 1065 Budapest, Hungary

This Policy is governed by Hungarian law. Any disputes arising in connection with this Policy shall be subject to the exclusive jurisdiction of the competent Hungarian courts, without prejudice to your right to lodge a complaint with a supervisory authority or to seek a judicial remedy under the GDPR. Budapest, July 2026.

UniPrisma
Explore
  • About
  • Startups
  • VCs
  • Universities
  • Medtech & Biotech
  • News & Insights
  • Let’s talk
Legal
  • Privacy Policy
  • Cookie Policy
  • Legal notice
Connect
LinkedIn

© 2026 UniPrisma Kft. All rights reserved.

We use essential cookies to make our website function properly. If you agree, we will also use cookies to perform enhanced website functionality and personalisation, and to analyse traffic. Read our Cookie Policy.