Privacy notice
How General Assets Research Group processes personal data when you visit this site, contact us, request a report or reach us from an advertisement.
This notice explains how General Assets Research Group ("we") processes personal data when you visit generalassets.eu, contact us, request one of our reports or reach us from an advertisement, in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), the Swiss Federal Act on Data Protection and applicable national law.
1. Controller
The controller is General Assets Research Group, Thurgauerstrasse 36/38, 8050 Zürich, Switzerland, zurich@generalassets.org. For any question about this notice or about your data, write to that address.
2. What we process, why and on what legal basis
Server logs. When you visit the site, our hosting server records technical data: the requested page, date and time, the status code, the amount of data transferred, the referring page, your browser and operating system, and your IP address. We process this data to deliver the site, to ensure its security and stability and to diagnose faults. Legal basis: Article 6(1)(f) GDPR (legitimate interest in the secure operation of the website). Logs are retained for 2 days and then deleted or anonymised.
Contact form and correspondence. If you contact us through the form or by email, we process the data you provide (name, email address, telephone number if given, subject and message) and the date and time of your message in order to answer your enquiry. Legal basis: Article 6(1)(f) GDPR (our legitimate interest in answering enquiries) and, where you have ticked the consent box, Article 6(1)(a) GDPR (consent). Enquiries are deleted 24 months after our last contact, unless a legal retention obligation applies.
Report requests and call-backs. On our report pages, for example those linked from our advertisements, you can request a report free of charge. We then process the details you enter: name, email address, telephone number, the report you chose and, if you tell us, the topics that interest you and the best time to call, together with the language and page you used and the date and time of your request. We use these details to give you the report and to contact you by email and telephone about our research: what we publish, what you would like covered and how the subscription works. We sell no investment products, and no one will contact you to sell you one. Legal basis: your consent, Article 6(1)(a) GDPR, which you give by ticking the box on the form and can withdraw at any time (section 5); after withdrawal we stop contacting you. We keep these details for 24 months after our last contact, unless you ask us to delete them earlier or a legal retention obligation applies. Between the two steps of the form, your browser keeps the details you typed in its session storage so that the second page is pre-filled; see the cookie notice.
Platform accounts. On platform.generalassets.eu you can open a free account to use our tools and courses. To run the account and keep your settings we process your name, your email address, your telephone number, your password (stored only as a one-way hash, which cannot be turned back into the password), the date you opened the account, the dates of your sign-ins and whether you asked to hear about new research. Legal basis: Article 6(1)(b) GDPR (the agreement under which we provide the platform). When you open an account, a member of our research team calls or emails you to introduce the platform and ask what you would like us to cover; this contact is about our research only and rests on the consent you give on the form (Article 6(1)(a) GDPR), which you can withdraw at any time. If you tick the box to hear about new research, we email you when a report is published, on the basis of your consent, which you can withdraw at any time (section 5). The tools themselves (the cost calculator, the KID reader, the risk monitor, the trade mentor) work in your browser: the figures you enter are not sent to us. We keep the account until you ask us to delete it, and we delete it ourselves after 24 months without a sign-in.
Advertising on Facebook and Instagram. We advertise our research on Facebook and Instagram, which are operated by Meta Platforms Ireland Limited. When you open one of our pages from such an advertisement, the link carries campaign parameters (such as utm_source, utm_campaign and utm_content) that name the campaign and the advertisement, and we store them with your request so that we know which advertisement brought you to us. We do not use the Meta Pixel, the Conversions API, Custom Audiences or any other Meta tool on this website, and we do not send your details to Meta. What Meta processes about you on its own platforms, before you reach our site, is governed by Meta's privacy policy. Legal basis for storing the campaign parameters: Article 6(1)(f) GDPR (our legitimate interest in measuring our advertising).
Web fonts. If you agree in our cookie dialog (“Accept all”, or “Web fonts” under “Customise”), this site loads the typefaces Archivo, IBM Plex Sans and IBM Plex Mono from Google Fonts. Your browser then requests the font files from Google's servers, which involves the transfer of your IP address to Google LLC, United States, under the EU–US Data Privacy Framework and standard contractual clauses. Without your consent, nothing is loaded from Google and the site uses your device's standard fonts. Legal basis: your consent, Article 6(1)(a) GDPR, which you can withdraw at any time with effect for the future under “Cookie settings” at the foot of each page.
We do not use analytics, advertising or social-media tracking tools on this website, we set no cookies for Meta or any other advertising network, we create no user profiles, and we do not sell personal data.
3. Recipients
The website is hosted by Hostinger International Ltd., with servers in Frankfurt am Main, Germany, which processes server data on our behalf under a data processing agreement pursuant to Article 28 GDPR. Your enquiries and report requests are stored on our own systems on those servers and are seen only by the members of our research team who answer you. The site is delivered and protected by Cloudflare, Inc., United States (content delivery network and security), which processes connection data such as your IP address on our behalf; Cloudflare is certified under the EU–US Data Privacy Framework and bound by standard contractual clauses. The site is delivered and protected by Cloudflare, Inc., United States (content delivery network and security), which processes connection data such as your IP address on our behalf; Cloudflare is certified under the EU–US Data Privacy Framework and bound by standard contractual clauses. We disclose personal data to other third parties only where required by law or where necessary to handle your request, and we do not share your details with Meta Platforms or any other advertising network.
4. Transfers outside the EU/EEA
Our team works from Switzerland, which the European Commission recognises as providing adequate data protection (adequacy decision 2000/518/EC). Apart from that, Cloudflare's network (section 3) and the loading of web fonts described above, we do not transfer your personal data outside the European Economic Area. Where any transfer occurs, we rely on an adequacy decision of the European Commission or on standard contractual clauses.
5. Your rights
Under the GDPR you have the right to request access to your personal data (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20), and to object to processing based on legitimate interests (Article 21). Where processing is based on consent, you may withdraw consent at any time with effect for the future. To exercise these rights, contact us at the address in section 1. You also have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work or place of the alleged infringement. You can withdraw your consent to being contacted at any time, for example by replying to one of our emails or by writing to the address in section 1; we then stop contacting you and delete your request, unless a legal obligation requires us to keep it. If you live in Switzerland, you may also contact the Federal Data Protection and Information Commissioner (FDPIC).
6. Security
The website is served over an encrypted connection (TLS). We apply technical and organisational measures appropriate to the risk to protect personal data against unauthorised access, loss or alteration.
7. Minors
This website and our advertising are directed at adults. We do not knowingly collect personal data from anyone under 18; if you believe a minor has given us their details, write to us and we will delete them.
8. Changes
We may update this notice from time to time. The current version is always available on this page. Last updated .