Legal
Privacy Policy
This website runs without analytics, without advertising networks and without social media plugins. Personal data essentially arises only when you write to us or request a checklist. What happens then is set out here in full.
1. Controller
The controller for the processing of personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Global Capital Strategy LLC
7901 4th St N, Suite 300
St. Petersburg, FL 33702
United States
E-mail: Hello@global-capital-strategy.com
2. Principles and legal bases
We process personal data only where that is necessary for a functioning website and for our services. Depending on the operation, the legal basis is your consent (Art. 6(1)(a) GDPR), the initiation or performance of a contract (b), or our legitimate interest in secure and stable operation (f).
3. Transfers to the USA
Global Capital Strategy LLC is established in the United States. When you contact us, your details are therefore necessarily processed in a third country within the meaning of Chapter V GDPR. Under certain conditions US authorities can access data stored there without legal protection equivalent to European standards being available in every case. By writing to us through a form or by e-mail, or by requesting the checklist, you consent to that transfer (Art. 49(1)(a) GDPR). You may withdraw your consent at any time with effect for the future.
4. Hosting and server log files
This website is hosted by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. A data processing agreement under Art. 28 GDPR is in place with the provider. Vercel is certified under the EU-US Data Privacy Framework, so the transfer rests on the European Commission’s adequacy decision (Art. 45 GDPR), supplemented by standard contractual clauses.
On every visit the provider automatically records server log files: the page requested, the time, the volume of data transferred, browser type and version, operating system, referring page and IP address. These data are technically necessary, are not combined with other sources, and serve solely to keep the site secure and available (Art. 6(1)(f) GDPR).
5. Encryption
This website uses SSL/TLS encryption throughout, which you can recognise by the “https://” in your browser’s address bar. While it is active, the data you send us cannot be read by third parties.
6. Contact form and session request
If you use either of the two forms, we process the details you enter — name, e-mail address, company where given, and your message or your answers to the questionnaire — solely in order to deal with your enquiry. The legal basis is your consent (Art. 6(1)(a) GDPR) and, where your enquiry concerns a contract, Art. 6(1)(b) GDPR.
We use Resend, Inc. (USA) as a processor to deliver these messages. To fend off automated bulk submissions we also process your IP address briefly; it is held in memory only, discarded after ten minutes at the latest, and never stored persistently.
7. Checklists and e-mails
If you request one of our checklists as a PDF, we process your e-mail address, the language in which you use the site and which checklist you requested. We first send you an e-mail with a confirmation link (double opt-in). Until you click that link we store nothing: your e-mail address, language, chosen checklist and the time of the request exist only inside the link itself, protected against alteration. The link expires after 48 hours. If you do not click it, your address is not used any further.
Once you confirm, you receive the checklist as a PDF and afterwards up to three further e-mails with notes on the checklist’s topic, such as company formation, banking or relocation. For this we store your e-mail address, your language and the time of sign-up as a contact in our recipient list at Resend, Inc. (USA), which we use as a processor. The legal basis is your consent (Art. 6(1)(a) GDPR); for the transfer to the USA see section 3. To fend off automated bulk sign-ups we briefly process your IP address as described in section 6. To demonstrate your consent, as Art. 7(1) GDPR requires of us, we also keep a note in our mailbox of when you requested the checklist and when you clicked the confirmation link. No IP address is stored with it.
You may withdraw your consent at any time. Every e-mail after confirmation contains an unsubscribe link; one click is enough. Your contact is then marked as unsubscribed and you receive no further e-mails. So that an unsubscribe is honoured even if something fails technically, we also receive a notification in our inbox. An informal message to the address above works as well.
8. Cookies and local storage
We set no cookies for analytics or advertising. The only thing stored is your preference on whether background animations are paused, in your browser’s local storage. That happens only if you operate the switch yourself, serves that purpose alone, and allows no conclusions about you as a person. You can delete the entry at any time through your browser settings.
9. What we do not use
This website uses no analytics or tracking services, no advertising networks and no social media plugins. Third-party content is loaded only after your explicit click; sections 9a and 9b name what that is. The typefaces are served from our own server, so no connection to Google Fonts or a comparable provider is made. There is no profiling and no automated decision-making, and we do not sell personal data.
9a. Appointment booking (Cal.com)
We use Cal.com, Inc. (USA) for scheduling. The calendar loads only once you operate the switch provided for it; before that, no connection to the provider is made. Loading it transmits your IP address and details of your browser to Cal.com, which is technically necessary. If you book an appointment, Cal.com processes the data you enter — name, email address, time zone and your answers to the booking questions — on our behalf. The legal basis for loading it is your consent (Art. 6(1)(a) GDPR), and for the booking the initiation of a contractual relationship (Art. 6(1)(b)). Section 3 applies to the transfer to the USA. The processing follows the provider’s data processing terms; for transfers out of the EEA, Cal.com relies on Standard Contractual Clauses or the EU-US Data Privacy Framework.
9b. Payments (Stripe)
Payment for the paid calls is handled by Stripe, Inc. (USA). Stripe processes the payment details you enter as a controller in its own right; we receive no complete card or account details, only whether a payment was made, together with the name and amount for allocation. The legal basis is performance of the contract (Art. 6(1)(b) GDPR).
10. Retention
Your enquiry stays with us until its purpose no longer applies — because it has been dealt with — and at the latest until you ask us to delete it or withdraw your consent. Mandatory statutory retention periods remain unaffected.
Your contact in the recipient list remains stored until you unsubscribe. After that we keep only your e-mail address marked “unsubscribed”, so that we can honour the unsubscribe and demonstrate the earlier consent (Art. 6(1)(f) GDPR). On request we delete this entry completely as well.
11. Your rights
- Access — to what we process about you (Art. 15 GDPR)
- Rectification — of inaccurate data (Art. 16)
- Erasure — of your data (Art. 17)
- Restriction — of processing (Art. 18)
- Portability — to receive your data in a common format (Art. 20)
- Objection — to processing based on legitimate interest (Art. 21)
- Withdrawal — of consent at any time, with effect for the future (Art. 7(3))
An informal message to the address above is enough.
12. Right to complain
Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority — in the EU, that of your habitual residence, your place of work, or the place of the alleged infringement.
13. Changes
We update this policy when the law or our processing changes. The version published here at the time applies.