Home About Analysis
Equities & Stocks Bonds & Fixed Income ETFs & Index Funds Commodities Foreign Exchange Digital Assets
Market Data Research Reports News & Insights Methodology Our Analysts Glossary FAQ Subscription Plans Contact Us

Privacy Policy

Vessel Financial Analytics ApS is committed to protecting your personal data and processing it transparently in accordance with applicable data protection legislation.

Data Controller: Vessel Financial Analytics ApS, CVR-nr. 42 81 66 37, Østerbrogade 56, 2100 Copenhagen Ø, Denmark.

Data Protection Contact: privacy@vessel-analytics.dk

Supervisory Authority: Datatilsynet (Danish Data Protection Agency), Carl Jacobsens Vej 35, 2500 Valby, Denmark. www.datatilsynet.dk

Last Updated: 14 March 2024

1. Introduction and Scope

This Privacy Policy describes how Vessel Financial Analytics ApS ("Vessel", "we", "us" or "our") collects, uses, stores, shares and protects personal data relating to visitors and users of our website at vessel-analytics.dk ("the Site"), and persons who subscribe to our research services, contact us by email or telephone, or otherwise interact with our business. We process personal data as a data controller under Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and the Danish Act on the Processing of Personal Data (Databeskyttelsesloven, Act No. 502 of 23 May 2018 with subsequent amendments). This Policy applies to all personal data we process regardless of the medium through which it is provided. If you are accessing the Site from outside Denmark, please note that your data may be transferred to and processed within the European Economic Area (EEA).

2. Personal Data We Collect

We collect the following categories of personal data: 2.1 Information you provide directly: — Contact form submissions: full name, email address, subject of enquiry and message content. — Subscription registrations: name, email address, professional affiliation (optional), billing address, and payment method details (processed by a PCI-DSS compliant payment processor; we do not store card numbers). — Email newsletter registrations: email address and communication preferences. — Customer support correspondence: email, telephone or written communications. 2.2 Information collected automatically: — Technical log data: IP address (truncated), browser type and version, operating system, referring URL, pages visited, time and date of access, session duration. — Analytics data: aggregated user behaviour metrics collected via privacy-compliant analytics tools. — Cookie data: as described in our Cookie Policy. 2.3 Information from third parties: — Payment processors may share transaction identifiers and billing verification data necessary for subscription management. — Business contact data may be verified against publicly available company registers where relevant for Institutional subscription due diligence.

3. Legal Basis for Processing

We rely on the following lawful bases under Article 6 GDPR: 3.1 Performance of a contract (Article 6(1)(b)): Processing necessary to fulfil subscription agreements, process payments, deliver research publications and provide customer support. 3.2 Compliance with a legal obligation (Article 6(1)(c)): Processing necessary to comply with Danish accounting law (Bogføringsloven), anti-money laundering obligations, tax reporting requirements, and regulatory record-keeping. 3.3 Legitimate interests (Article 6(1)(f)): Processing for the legitimate interests of operating a research business, including website security, fraud prevention, improving our services, direct marketing to existing customers (subject to right to opt out), and defending legal claims. We have conducted a Legitimate Interests Assessment (LIA) and determined that our interests are not overridden by data subjects' interests in each case. 3.4 Consent (Article 6(1)(a)): For email marketing communications to prospective subscribers and for non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing.

4. How We Use Your Personal Data

We use personal data for the following purposes: — To operate and manage your subscription, including billing, account management and access control. — To deliver research publications, reports, data and editorial content to which you have subscribed. — To respond to enquiries and support requests submitted via our contact form, email or telephone. — To send transactional communications (receipts, account notifications, service announcements). — To send marketing communications about our research services, events and publications (with opt-out available at all times). — To improve our website and research products by analysing aggregated usage data. — To detect, prevent and respond to fraud, security incidents and misuse of our services. — To comply with our legal and regulatory obligations under Danish and EU law.

5. Data Sharing and Transfers

We do not sell personal data to third parties. We share data only with: 5.1 Service providers acting as data processors: payment processing (Stripe Inc., contracted under EU Standard Contractual Clauses), cloud hosting (within the EEA), email distribution (within the EEA), and analytics providers operating under data processing agreements with appropriate safeguards. 5.2 Professional advisers: lawyers, accountants and auditors bound by professional confidentiality obligations. 5.3 Regulatory authorities: Datatilsynet, SKAT (Danish Tax Authority), and law enforcement authorities where required by applicable law or valid legal process. 5.4 Business transfers: In the event of a merger, acquisition or sale of all or part of our business, personal data may be transferred as part of that transaction. We will provide notice before any such transfer occurs. All third-party processors are contracted to process data only on our documented instructions and are required to implement appropriate technical and organisational security measures.

6. Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy or as required by law: — Subscriber account data: retained for the duration of the subscription and 5 years thereafter for accounting and tax compliance purposes. — Contact form enquiries: retained for 3 years from the date of last communication. — Website log data: automatically deleted after 90 days. — Email marketing opt-in records: retained until withdrawal of consent plus 3 years. — Financial transaction records: 5 years from the end of the accounting year in which the transaction occurred, as required by Bogføringsloven § 10. After retention periods expire, data is securely deleted or anonymised.

7. Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights: 7.1 Right of access (Article 15): You may request a copy of the personal data we hold about you and information about how it is processed. 7.2 Right to rectification (Article 16): You may request correction of inaccurate or incomplete personal data. 7.3 Right to erasure (Article 17): You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, where consent has been withdrawn, or where processing is unlawful. 7.4 Right to restriction of processing (Article 18): You may request that we restrict processing in certain circumstances (e.g. while accuracy is contested). 7.5 Right to data portability (Article 20): Where processing is based on consent or contract and carried out by automated means, you may request your data in a structured, machine-readable format. 7.6 Right to object (Article 21): You may object to processing based on legitimate interests, including direct marketing (which we will always honour immediately upon request). 7.7 Right to withdraw consent: Where processing is based on consent, you may withdraw consent at any time via your account settings or by contacting us. To exercise any of these rights, contact us at privacy@vessel-analytics.dk. We will respond within one calendar month (extendable by two further months for complex requests). We do not charge a fee for requests unless they are manifestly unfounded or excessive. You also have the right to lodge a complaint with Datatilsynet at www.datatilsynet.dk.

8. Security Measures

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction, including: — TLS/HTTPS encryption for all data transmitted between your browser and our servers. — Access controls limiting staff access to personal data on a need-to-know basis. — Regular security assessments and penetration testing of our infrastructure. — Staff training on data protection obligations. — Documented breach response procedures meeting the 72-hour notification requirement under GDPR Article 33.

9. Automated Decision-Making

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our data processing practices, legal requirements or business operations. We will publish the revised version with an updated "Last Updated" date. For material changes, we will provide notice via email to registered subscribers at least 14 days before the change takes effect.

Contact the Data Controller

Vessel Financial Analytics ApS
Østerbrogade 56, 2100 Copenhagen Ø, Denmark
Email: privacy@vessel-analytics.dk
Phone: +45 32 87 45 19