Last updated 4 August 2026 · Regulation (EU) 2016/679 (GDPR), arts. 13–14 · LOPDGDD 3/2018
The short version. To run this service we need one piece of personal data about you: your email address. There is no analytics, no advertising, no tracking pixel, no third-party script, and no profiling. Nothing is sold or shared for marketing. Every report you open carries your email address as a watermark — that is explained in full below, because you are entitled to know it before you read anything.
Swipe the table sideways →
| Controller | José Luis Pascual Irigoyen, acting as a sole trader (empresario individual). In this policy, “we”, “us” and “our” refer to him. |
|---|---|
| Address | Calle Manuela Malasaña 5, 28004 Madrid, Spain |
| Contact | info@jlpascual.com |
| Data protection officer | None appointed. The conditions in art. 37 GDPR are not met: the core activity is not large-scale monitoring and no special-category data is processed. Write to the address above with any data protection question and it reaches the controller directly. |
| Supervisory authority | Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es |
| Data | Where it comes from | Where it is stored |
|---|---|---|
| Your email address | You, at checkout or when you ask for a login link | A key-value store at the hosting provider, as the key sub:<your email> |
Your subscription status — active or revoked | Derived from the payment provider's events | Same record |
A login session token (the ie_session cookie) | Created when you log in | In your own browser. It is a signed token containing your email address and an expiry; the server keeps no copy. |
| Payment data — card details, billing address, country, any tax ID | You, at checkout | The payment provider only. We never see, receive or store your card number. We see that a payment succeeded and the email address attached to it. |
| Email delivery records — which message was sent to which address, and whether it was delivered | Generated when a report alert or login link is sent | The email delivery provider |
| Server access logs — IP address, timestamp, page requested, browser user-agent | Automatically, by the hosting network | The hosting provider, under its own retention policy |
| Your email address, if — and only if — you ticked the box asking for a subscription offer when you requested the free sample | You, by ticking that box. Leaving it unticked stores nothing | The site's own key-value store, and it deletes itself 40 days later |
That is the complete list. We do not ask for, and do not hold, your name, postal address, telephone number, date of birth, national ID number, or any special category of data under art. 9 GDPR.
| Purpose | Data used | Legal basis |
|---|---|---|
| Give you access to the research you paid for; keep you logged in; check on each request that your subscription is still active | Email, subscription status, session cookie | Art. 6(1)(b) — performance of the contract you entered into |
| Send you a login link when you ask for one | Art. 6(1)(b) | |
| Email you when a new report or an updated rating is published | Art. 6(1)(b) — these alerts are part of the subscription, not marketing. Every one carries an unsubscribe link and you can switch them off without cancelling. | |
| Take payment and issue the corresponding invoice | Email, payment data (held by the payment provider) | Art. 6(1)(b) and art. 6(1)(c) — legal obligation under Spanish tax and invoicing law |
| Watermark each report with the subscriber's email address, to deter and trace redistribution of paid research | Art. 6(1)(f) — legitimate interest. See section 5, which sets out the balancing test. | |
| Keep the site available and defend it against attack — rate limiting, bot filtering, uptime checks | IP address, user-agent (held by the hosting provider) | Art. 6(1)(f) — legitimate interest in a functioning, secure service |
| Send you at most two emails about a subscription after you have read the free sample | Email address | Art. 6(1)(a) — your consent, given by ticking an unticked box, withdrawable in one click from any of those emails |
One thing here runs on consent and nothing else does: the two subscription emails in the table above, and only if you ticked the box that asks for them. Leave it unticked and no consent is recorded, because none is needed — everything else on this site is either the contract you bought or the legitimate interest in keeping the site working. There is still no cookie banner, and that has not changed: a banner is for non-essential cookies, this site sets none, and the box on the sample form is a box you can see rather than a script running behind one. See the cookie policy.
Your email address is handled on our behalf by service providers in the following categories, each under a written data-processing agreement. They may use it only to perform the service and for nothing else.
| Category | What they do with it |
|---|---|
| Payment processing | Take payment and manage your subscription. Card details go to the payment provider and are never seen or stored by this site. A payment provider also acts as a controller in its own right for fraud prevention and its own regulatory compliance. |
| Hosting and content delivery | Serve the site, run the login gate, and hold the record of whether your subscription is active. |
| Email delivery | Send login links and report alerts. |
| Source control and build automation | Store the code and run the process that builds the reports. |
| Availability monitoring | Check every few minutes that the site is reachable. Receives no personal data. |
The identity of any individual provider is available on request. It is not published here, because a public inventory of the systems holding subscriber data is useful mainly to someone attacking them.
What is not shared. The language model that writes the research never receives any subscriber data. It is given company filings, earnings-call transcripts and market data. It has no access to the subscriber list, and the subscriber list is not stored anywhere it can reach. The market-data provider receives only ticker symbols.
Beyond these, your data is disclosed to no one. It is not sold, rented, shared for advertising, or used to train any model. It would be disclosed to a public authority only where we are legally compelled to do so.
Every report page served to a logged-in subscriber has that subscriber's email address embedded in it. If a paid report is republished, the copy identifies the account it came from.
This is processing on the basis of legitimate interest (art. 6(1)(f)), so you are entitled to the balancing test rather than just the assertion:
Some of that processing takes place in the United States. Those transfers are made either under the European Commission's EU–U.S. Data Privacy Framework adequacy decision of 10 July 2023, or under the Standard Contractual Clauses adopted by the Commission, depending on the provider.
You may request a copy of the safeguards in place for any transfer.
Swipe the table sideways →
| Data | Kept for |
|---|---|
| Email address and subscription record | While your subscription is active, and for 12 months afterwards so that a returning subscriber keeps their access history. Deleted on request at any time. |
| Session cookie | 30 days, or until you log out or clear your browser. It is not renewed in the background. |
| Billing and invoicing records | Held by the payment provider and by us for the periods Spanish law requires: 4 years (art. 66 Ley General Tributaria) and 6 years for accounting books and supporting documents (art. 30 Código de Comercio). These records cannot be deleted on request while that period runs — art. 17(3)(b) GDPR. |
| Email delivery logs | Under the email provider's own retention policy, currently measured in days, not years. |
| Server access logs | Under the hosting provider's own retention policy. |
| Email address given with the subscription-offer box ticked | 40 days, then it is deleted automatically. The two emails are sent on day three and day ten; the record exists only to know which have gone, and it is removed as soon as the second one has. Withdraw consent at any point and nothing further is sent. |
Under arts. 15–22 GDPR you have the right to:
Write to info@jlpascual.com. We will answer within one month (art. 12(3) GDPR). There is no charge and you do not have to give a reason.
If you are not satisfied with the answer, you can complain to the Agencia Española de Protección de Datos (www.aepd.es) or to the supervisory authority of the EU country where you live. You do not have to complain to us first.
The research on this site is produced by a large language model running a fixed analytical process, under the methodology and responsibility of José Luis Pascual, CFA. Two consequences for your privacy:
There is no automated decision-making producing legal or similarly significant effects concerning you within the meaning of art. 22 GDPR. The reports are automated analysis of companies, not decisions about you; they are identical for every subscriber and are not personalised in any way.
The site is served only over HTTPS. Session tokens are cryptographically signed, marked HttpOnly, Secure and SameSite, and cannot be read by JavaScript. Access to paid reports is re-checked against the subscription record on every single request, so a cancellation takes effect immediately rather than at the end of a cached session. No card data ever reaches this site's servers.
If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the AEPD within 72 hours and, where the risk is high, notify you directly (arts. 33–34 GDPR).
If this policy changes materially, the new version will be published here with a new date, and subscribers will be told by email before it takes effect. Previous versions are available on request.
José Luis Pascual · Calle Manuela Malasaña 5, 28004 Madrid, Spain · info@jlpascual.com