Privacy policy

Last updated 4 August 2026 · Regulation (EU) 2016/679 (GDPR), arts. 13–14 · LOPDGDD 3/2018

ControllerWhat I holdWhy & legal basisProcessorsWatermarkingTransfersRetentionYour rightsAI & your data

The short version. To run this service I need one piece of personal data about you: your email address. There is no analytics, no advertising, no tracking pixel, no third-party script, and no profiling. Nothing is sold or shared for marketing. Every report you open carries your email address as a watermark — that is explained in full below, because you are entitled to know it before you read anything.

1. Who is responsible for your data

Swipe the table sideways →

ControllerJosé Luis Pascual Irigoyen, acting as a sole trader (empresario individual)
AddressCalle Manuela Malasaña 5, 28004 Madrid, Spain
Contact[email protected]
Data protection officerNone appointed. The conditions in art. 37 GDPR are not met: the core activity is not large-scale monitoring and no special-category data is processed. Write to the address above with any data protection question and it reaches the controller directly.
Supervisory authorityAgencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es

2. What personal data I hold, and where it came from

DataWhere it comes fromWhere it is stored
Your email addressYou, at checkout (via Stripe) or when you ask for a login linkCloudflare Workers KV, as the key sub:<your email>
Your subscription status — active or revokedDerived from Stripe's payment eventsSame KV record
A login session token (the ie_session cookie)Created when you log inIn your own browser. It is a signed token containing your email address and an expiry; the server keeps no copy.
Payment data — card details, billing address, country, any tax IDYou, at checkoutStripe only. I never see, receive or store your card number. I see that a payment succeeded and the email address attached to it.
Email delivery records — which message was sent to which address, and whether it was deliveredGenerated when a report alert or login link is sentResend
Server access logs — IP address, timestamp, page requested, browser user-agentAutomatically, by the hosting networkCloudflare, under its own retention policy

That is the complete list. I do not ask for, and do not hold, your name, postal address, telephone number, date of birth, national ID number, or any special category of data under art. 9 GDPR.

3. Why I process it, and on what legal basis

PurposeData usedLegal basis
Give you access to the research you paid for; keep you logged in; check on each request that your subscription is still activeEmail, subscription status, session cookieArt. 6(1)(b) — performance of the contract you entered into
Send you a login link when you ask for oneEmailArt. 6(1)(b)
Email you when a new report or an updated rating is publishedEmailArt. 6(1)(b) — these alerts are part of the subscription, not marketing. Every one carries an unsubscribe link and you can switch them off without cancelling.
Take payment and issue the corresponding invoiceEmail, payment data (held by Stripe)Art. 6(1)(b) and art. 6(1)(c) — legal obligation under Spanish tax and invoicing law
Watermark each report with the subscriber's email address, to deter and trace redistribution of paid researchEmailArt. 6(1)(f) — legitimate interest. See section 5, which sets out the balancing test.
Keep the site available and defend it against attack — rate limiting, bot filtering, uptime checksIP address, user-agent (held by Cloudflare)Art. 6(1)(f) — legitimate interest in a functioning, secure service

No consent-based processing takes place, which is why this site has no cookie banner: there is nothing to consent to. See the cookie policy.

4. Who else touches your data

These are the only third parties involved. Each is bound by a data processing agreement under art. 28 GDPR, except where noted that the party acts as a controller in its own right.

WhoWhat forRoleWhere
Stripe Payments Europe, Limited
One Wilton Park, Dublin 2, D02 FX04, Ireland — with Stripe, LLC (354 Oyster Point Blvd, South San Francisco, CA 94080, USA)
Taking payment, managing your subscription, storing your cardProcessor for payment execution; independent controller for fraud prevention and its own regulatory complianceIreland / USA
Cloudflare, Inc.
101 Townsend St, San Francisco, CA 94107, USA
Hosting the site, the CDN, the login gate, and the key-value store holding your subscription recordProcessorUSA, with edge servers worldwide including the EU
Plus Five Five, Inc. (Resend)
2261 Market Street #5039, San Francisco, CA 94114, USA
Sending login links and report alertsProcessorUSA
GitHub, Inc.
88 Colin P. Kelly Jr. St., San Francisco, CA 94107, USA
Storing the source code and running the automation that builds the reportsProcessorUSA
UptimeRobot (Itserv OU / UptimeRobot Service Provider Ltd)Checking every few minutes that the site is reachableProcessorEU

Two things worth being explicit about.

The company that generates the research text — Anthropic — never receives any subscriber data. The report pipeline is fed public company filings, earnings-call transcripts and market data. It has no access to the subscriber list, and the subscriber list is not stored anywhere the pipeline can reach.

The market data provider, Financial Modeling Prep, likewise receives only ticker symbols. It has no subscriber data of any kind.

Beyond these, your data is disclosed to no one. It is not sold, rented, shared for advertising, or used to train any model. It would be disclosed to a public authority only where I am legally compelled to do so.

5. Watermarking — and why I think it is fair

Every report page served to a logged-in subscriber has that subscriber's email address embedded in it. If a paid report is republished, the copy identifies the account it came from.

This is processing on the basis of legitimate interest (art. 6(1)(f)), so you are entitled to the balancing test rather than just the assertion:

6. Transfers outside the EEA

Stripe, LLC, Cloudflare, Inc., Resend (Plus Five Five, Inc.) and GitHub, Inc. are established in the United States, so your email address is transferred there.

You may request a copy of the safeguards in place for any of these transfers.

7. How long it is kept

Swipe the table sideways →

DataKept for
Email address and subscription recordWhile your subscription is active, and for 12 months afterwards so that a returning subscriber keeps their access history. Deleted on request at any time.
Session cookie30 days, or until you log out or clear your browser. It is not renewed in the background.
Billing and invoicing recordsHeld by Stripe and by me for the periods Spanish law requires: 4 years (art. 66 Ley General Tributaria) and 6 years for accounting books and supporting documents (art. 30 Código de Comercio). These records cannot be deleted on request while that period runs — art. 17(3)(b) GDPR.
Email delivery logsUnder Resend's own retention policy, currently measured in days, not years.
Server access logsUnder Cloudflare's own retention policy.

8. Your rights

Under arts. 15–22 GDPR you have the right to:

Write to [email protected]. I will answer within one month (art. 12(3) GDPR). There is no charge and you do not have to give a reason.

If you are not satisfied with the answer, you can complain to the Agencia Española de Protección de Datos (www.aepd.es) or to the supervisory authority of the EU country where you live. You do not have to complain to me first.

9. AI, and what it does and does not see

The research on this site is produced by a large language model running a fixed analytical process, under the methodology and responsibility of José Luis Pascual, CFA. Two consequences for your privacy:

There is no automated decision-making producing legal or similarly significant effects concerning you within the meaning of art. 22 GDPR. The reports are automated analysis of companies, not decisions about you; they are identical for every subscriber and are not personalised in any way.

10. Security

The site is served only over HTTPS. Session tokens are cryptographically signed, marked HttpOnly, Secure and SameSite, and cannot be read by JavaScript. Access to paid reports is re-checked against the subscription record on every single request, so a cancellation takes effect immediately rather than at the end of a cached session. No card data ever reaches this site's servers.

If a personal data breach occurs that is likely to result in a risk to your rights, I will notify the AEPD within 72 hours and, where the risk is high, notify you directly (arts. 33–34 GDPR).

11. Changes

If this policy changes materially, the new version will be published here with a new date, and subscribers will be told by email before it takes effect. Previous versions are available on request.

Aviso legalPrivacyTermsCookiesResearch disclosures

José Luis Pascual · Calle Manuela Malasaña 5, 28004 Madrid, Spain · [email protected]