Last updated 4 August 2026 · Regulation (EU) 2016/679 (GDPR), arts. 13–14 · LOPDGDD 3/2018
The short version. To run this service I need one piece of personal data about you: your email address. There is no analytics, no advertising, no tracking pixel, no third-party script, and no profiling. Nothing is sold or shared for marketing. Every report you open carries your email address as a watermark — that is explained in full below, because you are entitled to know it before you read anything.
Swipe the table sideways →
| Controller | José Luis Pascual Irigoyen, acting as a sole trader (empresario individual) |
|---|---|
| Address | Calle Manuela Malasaña 5, 28004 Madrid, Spain |
| Contact | [email protected] |
| Data protection officer | None appointed. The conditions in art. 37 GDPR are not met: the core activity is not large-scale monitoring and no special-category data is processed. Write to the address above with any data protection question and it reaches the controller directly. |
| Supervisory authority | Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es |
| Data | Where it comes from | Where it is stored |
|---|---|---|
| Your email address | You, at checkout (via Stripe) or when you ask for a login link | Cloudflare Workers KV, as the key sub:<your email> |
Your subscription status — active or revoked | Derived from Stripe's payment events | Same KV record |
A login session token (the ie_session cookie) | Created when you log in | In your own browser. It is a signed token containing your email address and an expiry; the server keeps no copy. |
| Payment data — card details, billing address, country, any tax ID | You, at checkout | Stripe only. I never see, receive or store your card number. I see that a payment succeeded and the email address attached to it. |
| Email delivery records — which message was sent to which address, and whether it was delivered | Generated when a report alert or login link is sent | Resend |
| Server access logs — IP address, timestamp, page requested, browser user-agent | Automatically, by the hosting network | Cloudflare, under its own retention policy |
That is the complete list. I do not ask for, and do not hold, your name, postal address, telephone number, date of birth, national ID number, or any special category of data under art. 9 GDPR.
| Purpose | Data used | Legal basis |
|---|---|---|
| Give you access to the research you paid for; keep you logged in; check on each request that your subscription is still active | Email, subscription status, session cookie | Art. 6(1)(b) — performance of the contract you entered into |
| Send you a login link when you ask for one | Art. 6(1)(b) | |
| Email you when a new report or an updated rating is published | Art. 6(1)(b) — these alerts are part of the subscription, not marketing. Every one carries an unsubscribe link and you can switch them off without cancelling. | |
| Take payment and issue the corresponding invoice | Email, payment data (held by Stripe) | Art. 6(1)(b) and art. 6(1)(c) — legal obligation under Spanish tax and invoicing law |
| Watermark each report with the subscriber's email address, to deter and trace redistribution of paid research | Art. 6(1)(f) — legitimate interest. See section 5, which sets out the balancing test. | |
| Keep the site available and defend it against attack — rate limiting, bot filtering, uptime checks | IP address, user-agent (held by Cloudflare) | Art. 6(1)(f) — legitimate interest in a functioning, secure service |
No consent-based processing takes place, which is why this site has no cookie banner: there is nothing to consent to. See the cookie policy.
These are the only third parties involved. Each is bound by a data processing agreement under art. 28 GDPR, except where noted that the party acts as a controller in its own right.
| Who | What for | Role | Where |
|---|---|---|---|
| Stripe Payments Europe, Limited One Wilton Park, Dublin 2, D02 FX04, Ireland — with Stripe, LLC (354 Oyster Point Blvd, South San Francisco, CA 94080, USA) | Taking payment, managing your subscription, storing your card | Processor for payment execution; independent controller for fraud prevention and its own regulatory compliance | Ireland / USA |
| Cloudflare, Inc. 101 Townsend St, San Francisco, CA 94107, USA | Hosting the site, the CDN, the login gate, and the key-value store holding your subscription record | Processor | USA, with edge servers worldwide including the EU |
| Plus Five Five, Inc. (Resend) 2261 Market Street #5039, San Francisco, CA 94114, USA | Sending login links and report alerts | Processor | USA |
| GitHub, Inc. 88 Colin P. Kelly Jr. St., San Francisco, CA 94107, USA | Storing the source code and running the automation that builds the reports | Processor | USA |
| UptimeRobot (Itserv OU / UptimeRobot Service Provider Ltd) | Checking every few minutes that the site is reachable | Processor | EU |
Two things worth being explicit about.
The company that generates the research text — Anthropic — never receives any subscriber data. The report pipeline is fed public company filings, earnings-call transcripts and market data. It has no access to the subscriber list, and the subscriber list is not stored anywhere the pipeline can reach.
The market data provider, Financial Modeling Prep, likewise receives only ticker symbols. It has no subscriber data of any kind.
Beyond these, your data is disclosed to no one. It is not sold, rented, shared for advertising, or used to train any model. It would be disclosed to a public authority only where I am legally compelled to do so.
Every report page served to a logged-in subscriber has that subscriber's email address embedded in it. If a paid report is republished, the copy identifies the account it came from.
This is processing on the basis of legitimate interest (art. 6(1)(f)), so you are entitled to the balancing test rather than just the assertion:
Stripe, LLC, Cloudflare, Inc., Resend (Plus Five Five, Inc.) and GitHub, Inc. are established in the United States, so your email address is transferred there.
You may request a copy of the safeguards in place for any of these transfers.
Swipe the table sideways →
| Data | Kept for |
|---|---|
| Email address and subscription record | While your subscription is active, and for 12 months afterwards so that a returning subscriber keeps their access history. Deleted on request at any time. |
| Session cookie | 30 days, or until you log out or clear your browser. It is not renewed in the background. |
| Billing and invoicing records | Held by Stripe and by me for the periods Spanish law requires: 4 years (art. 66 Ley General Tributaria) and 6 years for accounting books and supporting documents (art. 30 Código de Comercio). These records cannot be deleted on request while that period runs — art. 17(3)(b) GDPR. |
| Email delivery logs | Under Resend's own retention policy, currently measured in days, not years. |
| Server access logs | Under Cloudflare's own retention policy. |
Under arts. 15–22 GDPR you have the right to:
Write to [email protected]. I will answer within one month (art. 12(3) GDPR). There is no charge and you do not have to give a reason.
If you are not satisfied with the answer, you can complain to the Agencia Española de Protección de Datos (www.aepd.es) or to the supervisory authority of the EU country where you live. You do not have to complain to me first.
The research on this site is produced by a large language model running a fixed analytical process, under the methodology and responsibility of José Luis Pascual, CFA. Two consequences for your privacy:
There is no automated decision-making producing legal or similarly significant effects concerning you within the meaning of art. 22 GDPR. The reports are automated analysis of companies, not decisions about you; they are identical for every subscriber and are not personalised in any way.
The site is served only over HTTPS. Session tokens are cryptographically signed, marked HttpOnly, Secure and SameSite, and cannot be read by JavaScript. Access to paid reports is re-checked against the subscription record on every single request, so a cancellation takes effect immediately rather than at the end of a cached session. No card data ever reaches this site's servers.
If a personal data breach occurs that is likely to result in a risk to your rights, I will notify the AEPD within 72 hours and, where the risk is high, notify you directly (arts. 33–34 GDPR).
If this policy changes materially, the new version will be published here with a new date, and subscribers will be told by email before it takes effect. Previous versions are available on request.
José Luis Pascual · Calle Manuela Malasaña 5, 28004 Madrid, Spain · [email protected]