Legal
Privacy statement.
Aither — Αἰθήρ — de hoogste sfeer.
1. Introduction
Aither Network (“Aither”, “we”, “us”) is a trading name of VigIT B.V. and provides a closed, pre-vetted circle of supervisory board members, non-executive directors, executives and board secretaries to organisations in regulated and adjacent sectors. In our work we process personal data of members of the circle, of prospective members during the vetting process, of contacts at organisations that turn to the circle, and of visitors to our website. We think it matters that you know what we do with that data.
This statement sets out, for each situation, which data we process, why, on what legal basis, how long we keep it and with whom we share it. It also explains your rights and how to exercise them.
This statement corresponds to our internal record of processing activities, maintained in accordance with Article 30 GDPR.
2. Who is responsible for your data
Aither (VigIT B.V.) is the controller for all processing described in this statement.
| Item | Details |
|---|---|
| Controller | VigIT B.V., trading as Aither Network |
| Registered address | Rivium Westlaan 78, 2909 LD Capelle aan den IJssel, the Netherlands |
| Privacy contact | info@aithernetwork.com |
| Phone | +31 88 447 94 94 |
| Data Protection Officer | Not appointed; Aither is not required to do so. Please use the email address above for privacy matters. |
Where an organisation appoints a member of the circle, or starts a process with you following an introduction, that organisation becomes a controller in its own right for its processing of your data from that moment. Its own privacy statement applies to that processing.
When using certain LinkedIn functionality, Aither and LinkedIn may act as joint controllers. Where that applies, we have accepted the arrangements LinkedIn provides for this (Joint Controller Addendum). In such cases you may exercise your rights with either us or LinkedIn.
3. Where we obtain your data
We obtain data in two ways, and this determines how we inform you:
- Directly from you — for example when you have an introductory conversation with us, call or email us, or an organisation requests a confidential intake.
- From others or other sources — for example through an introduction by an existing member of the circle, from public professional networks and websites, from referees named as part of the vetting process, or via a service that compiles business contact details from public sources.
Where we do not obtain your data directly from you, we inform you no later than our first contact with you, and in any event within one month of obtaining it. Our first message to you therefore always states where we obtained your data, why we are contacting you and how you can object. If you do so, we stop immediately and delete your data, retaining only the minimum needed to ensure we do not contact you again.
4. What we process and why — members and prospective members of the circle
4.1 Introductory conversation
Admission to the circle never proceeds through open application, but through introduction by an existing member or a direct conversation following an introduction. The initial conversation serves to assess whether further vetting is worthwhile.
| Purpose | Data | Legal basis | Retention | Recipients |
|---|---|---|---|---|
| Assessing whether an introductory conversation leads to a vetting process | Name, contact details, role, employer, board-level experience, motivation | Steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR) | 6 months after the conversation, unless you agree to a vetting process | None |
4.2 Vetting for admission to the circle
Before anyone is admitted to the circle, we assess across four layers: the hard criteria per sector and role, a reference check on facts and integrity, a personal 45-minute conversation, and verification of formal AFM/DNB status where the role requires it.
| Purpose | Data | Legal basis | Retention | Recipients |
|---|---|---|---|---|
| Determining whether you meet the criteria for admission to the circle | CV, board-level and supervisory experience, references you have named yourself, the outcome of the personal conversation, information on prior AFM/DNB suitability assessments to the extent you provide it yourself | Steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR) | If admitted: see 4.3. If not admitted: 3 months after the decision, unless you request earlier deletion | None, other than the referees you have named yourself |
We only contact referees you have named yourself. Where a role requires a formal AFM or DNB assessment, that assessment takes place directly between you, the organisation and the regulator; we do not process criminal offence data ourselves and do not request a certificate of conduct.
4.3 Admission to the circle
| Purpose | Data | Legal basis | Retention | Recipients |
|---|---|---|---|---|
| Being able to put you forward when a suitable seat becomes available | Name, contact details, CV, board-level experience, sector preferences, outcome of the vetting process, availability and visibility preferences you have indicated yourself | Your consent (Art. 6(1)(a) GDPR) | Until you withdraw consent; every four years we ask you to confirm | None — an introduction to an organisation only takes place after discussing it with you |
We record when and how you gave consent. You may withdraw it at any time via info@aithernetwork.com; withdrawing is as easy as giving and has no effect on any process already under way.
Every four years we ask whether you wish to remain included, in line with the typical duration of a supervisory term. If you do not respond, or indicate you do not wish to remain, we delete your data.
You are not listed in a database that can be browsed. You determine your own visibility within the circle: you can indicate for which sectors, roles or organisations you do or do not wish to be approached.
4.4 Introduction to an organisation
| Purpose | Data | Legal basis | Retention | Recipients |
|---|---|---|---|---|
| Putting your profile forward, with commentary, to an organisation with an open seat | Name, contact details, CV, board-level experience, vetting outcome, motivation for the specific role | Your consent for the specific introduction (Art. 6(1)(a) GDPR) | Duration of the process at the organisation; if not appointed, deleted from that process within 4 weeks of its conclusion | The organisation to which you are introduced |
An introduction never takes place without our having discussed it with you beforehand. If you are appointed, the organisation becomes a controller in its own right for its processing of your data from that moment (see Article 2).
4.5 How we use LinkedIn and similar networks
Introductions within the circle usually take place through personal referral. Where we nonetheless use LinkedIn to identify or approach a prospective member, the following applies.
What we do: we prefer to make contact within the platform itself, through a connection request or message, using LinkedIn's official functionality. If you do not respond, we do not send a follow-up.
What we do not do: we do not collect profile data by automated means (scraping) and do not use tools that extract profiles outside official functionality. We do not build more extensive profiles than needed to assess whether an introductory conversation is worthwhile.
Where we contact you by email rather than through the platform, that message always states where we obtained your email address and how you can indicate that you do not wish to be contacted.
5. What we process and why — organisations and business contacts
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Administering membership: intake, discussing introductions, recording arrangements, invoicing the annual fee | Name, role, business contact details, correspondence, contract data | Performance of the contract (Art. 6(1)(b) GDPR) | Duration of the membership plus 2 years |
| Bringing Aither to the attention of organisations that may have a need for it | Name, role, organisation name, business contact details | Our legitimate interest in finding new organisations (Art. 6(1)(f) GDPR) | If there is no interest, we delete your data |
| Sending insights and invitations for a confidential intake | Name, email address, organisation, role | Your consent (Art. 6(1)(a) GDPR) | Until you unsubscribe |
| Invoicing and maintaining our administration | Contact, invoice and payment data | Performance of the contract (Art. 6(1)(b) GDPR); for retention thereafter: our statutory retention obligation (Art. 6(1)(c) GDPR) | 7 years, under Dutch tax law |
Every commercial email includes an unsubscribe option. If you unsubscribe, we no longer process your data for that purpose.
6. Our website
When you visit our website, technical data is processed such as the page requested, the time and your browser type. This is necessary to operate and secure the website, based on our legitimate interest (Art. 6(1)(f) GDPR).
For visitor statistics we use Plausible Analytics. This service sets no cookies, collects no personal data and uses no unique identifiers; the statistics cannot be traced back to you. No consent is required for this. Should we at any point set cookies that are not strictly necessary, we will ask for your consent beforehand.
7. Artificial intelligence and automated decision-making
We use AI-assisted tools in parts of our work, for example to summarise profiles or prepare correspondence. We use as little data as possible and do not process special category data in these applications.
No algorithm decides on admission to the circle or on an introduction. That judgment is made by a peer professional — at Aither, personally by Marc Magrijn — who attaches his name to every introduction. No decision about your admission or your suitability for a specific introduction is therefore ever made solely by automated means.
Where you interact directly with an AI system during a process, we will make this clear. If you would like to know how we used AI in your case, we will explain.
8. Who we share your data with
We never sell your data and do not provide it to third parties for their own marketing purposes. We share data only with:
- Organisations — only where you have agreed to a specific introduction.
- Suppliers processing data on our behalf (processors) — including our relationship systems, email and file storage, financial administration, website and email communications. We have a data processing agreement with each of them, recording that they act only on our instructions, are bound by confidentiality and apply appropriate security.
- Advisers and authorities — such as our accountant, a legal adviser, or the tax authority or a regulator where we are legally required to do so.
A current overview of the categories of suppliers we engage is available on request.
9. Transfers outside the European Economic Area
Some of our suppliers may be established outside the EEA or store data partly outside the EEA. In those cases we ensure appropriate safeguards: an adequacy decision of the European Commission, or the Standard Contractual Clauses adopted by the European Commission, supplemented by additional measures where necessary. A copy of the applicable safeguards is available on request.
10. How we protect your data
We take appropriate technical and organisational measures to protect your data against loss, misuse and unauthorised access. These include individual accounts with multi-factor authentication, access limited to those who need it for their work, encryption of data at rest and in transit, confidentiality obligations, and periodic review of our suppliers' security.
We maintain a register of security incidents. Should a data breach occur that poses a risk to your rights and freedoms, we report it to the Dutch Data Protection Authority within 72 hours and inform you where the breach is likely to result in a high risk to you.
11. Your rights
You have the following rights regarding your personal data:
- Access — you can ask what data we process about you and receive a copy.
- Rectification — you can have inaccurate data corrected or completed.
- Erasure — you can ask us to delete your data.
- Restriction — you can ask us to suspend processing temporarily.
- Objection — you can object to processing based on our legitimate interest. You can object to direct marketing at any time without giving reasons, and we will always stop.
- Portability — you can receive the data you provided to us in a commonly used format.
- Withdrawal of consent — where we rely on your consent, you can withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
You can submit a request via info@aithernetwork.com. We respond within one month. If your request is complex, we may extend this by two months and will tell you within the first month. To avoid disclosing data to the wrong person, we may ask you to identify yourself. Exercising your rights is free of charge.
If you are unhappy with how we handle your data or your request, we would like to hear from you first so we can put it right. You also always have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), PO Box 93374, 2509 AJ The Hague, the Netherlands (autoriteitpersoonsgegevens.nl).
12. Changes
We may amend this privacy statement where our services, our systems or the law give cause to do so. The current version is always available on our website, stating the version date. We will actively inform you of any substantial changes. In the event of any discrepancy between the Dutch and English versions, the Dutch version prevails.
Version 1.0 — effective 2 September 2026
Deze privacyverklaring in het Nederlands →