Privacy notice

Effective 14 September 2026. Applies to mecenaria.com and the Mecenaria app.

Mecenaria helps university technical teams find sponsors. It is run by David Wermuth, Zürich, Switzerland, who is the data controller under the Swiss Federal Act on Data Protection (FADP) and, for users in the EU/EEA, the GDPR. Questions, corrections and deletion requests go to privacy@mecenaria.com.

1. Data about you, the user

Mecenaria stores as little about you as it can and still work:

  • Email address. Used to sign you in with a one-time code and to tell your team who is on the account. There is no password.
  • Team membership. Which team you belong to, and the team profile your team entered: team name, university, country, competition category.
  • What your team enters. Your sponsor roster, pipeline statuses, notes, follow-up dates, sponsors you log as won, and pitch drafts you generate. This is your team’s working data. It stays with the team across leadership handovers, which is the point of the product, and every member of the team can see it.
  • Technical logs. Our hosting and database providers keep short-lived server logs (IP address, browser type, requested page, timestamp) for security and debugging.

Cookies. The app sets only the session cookies needed to keep you signed in. Your light/dark theme choice is kept in your browser’s local storage. There are no analytics, advertising or tracking scripts.

Legal basis. Performance of the service you asked for (Art. 6(1)(b) GDPR) for your account and your team’s data; our legitimate interest in keeping the service secure (Art. 6(1)(f)) for the technical logs.

2. Data about sponsor companies

The heart of Mecenaria is a database of which companies sponsor which student teams. It is built from information companies and teams publish themselves: team partner pages, company websites, competition registries and public archives of those pages.

The sponsor database holds company-level information only:

  • company name, website domain, industry, and where the company operates;
  • which teams list the company as a sponsor, in which season and at which tier;
  • how to reach the company through its official channels: sponsorship or partnership programmes, role mailboxes such as sponsoring@ or info@, contact forms, and the legally required company imprint (Impressum) page.

We do not collect or store the names, personal email addresses, phone numbers or social-media profiles of individual employees. We do not scrape LinkedIn or buy contact lists. Where the app suggests “who to ask”, it links you to public search pages; it does not store the result. If a personal address ever ends up in the database by mistake, write to us and we remove it.

Mecenaria never sends email to sponsors. Teams write and send their own messages, one at a time, from their own accounts.

Legal basis. Legitimate interest (Art. 6(1)(f) GDPR) in compiling publicly available business information about companies. Information about a company as such is not personal data; where an imprint names a person, we hold only the company-level channel, not the person.

3. How your data is used

  • The gap list. Your team’s profile and roster are compared against the sponsor database to show which sponsors similar teams have and you do not.
  • Pitch drafts. When you ask for a draft, your team’s name, category and country plus the sponsor’s name and industry are sent to Anthropic’s API to generate the text. No member emails, notes or pipeline data are sent. Anthropic processes API inputs under its commercial terms and does not train on them.
  • The shared graph. When your team logs a sponsor as won, that sponsorship (team name and company, nothing else) can become visible to other teams as a company-level fact once we have reviewed it. Your notes, contacts and pipeline never leave your team.

We do not sell data, and we do not use it for advertising.

4. Where data is stored and who processes it

  • Supabase (database and sign-in), hosted on AWS in Stockholm, Sweden (EU). Sign-in codes are delivered by email through Supabase’s mail service.
  • Netlify (web hosting and content delivery). Netlify runs a global edge network; page requests may be served from outside the EU/Switzerland.
  • Anthropic (pitch drafts only, see above), United States.

Each provider acts as our processor under a data processing agreement, with the EU standard contractual clauses covering transfers outside the EU and Switzerland.

5. How long we keep it

  • Your account and your team’s working data: for as long as the team uses Mecenaria. A team can ask for full deletion at any time.
  • Technical logs: a few weeks, as set by the providers above.
  • The sponsor database: kept and refreshed for as long as Mecenaria exists. Entries are re-verified periodically and stale ones are dropped.

6. Your rights

You can ask for a copy of the data we hold about you, have it corrected, have it deleted, receive it in a portable format, or object to a particular use. Email privacy@mecenaria.com from the address on your account and we answer within a month. You can also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, in the EU, to your national data protection authority.

If you represent a company listed in the sponsor database and want an entry corrected or removed, write to the same address with the company name and domain.

7. Security

Data is encrypted in transit and at rest by the providers above. Access to team data is enforced in the database itself: a signed-in user can only read and change the rows of the team they belong to. Sign-in uses one-time codes, so there are no passwords to leak.

8. Changes

When this notice changes, the effective date at the top moves and signed-in users see a note in the app. Material changes are announced by email.

← back to Mecenaria