Legal
Privacy Policy
This policy explains what personal data GSLDM SL collects when you visit gsldm.com or contact us, why we collect it, how long we keep it, and the rights you have under the General Data Protection Regulation (GDPR).
01Who we are
The data controller responsible for the processing described in this policy is:
- Company
- GSLDM SL
- Tax ID (NIF)
- [NIF to be completed]
- Registered office
- [Registered address to be completed], Spain
- info@gsldm.com
GSLDM SL has not appointed a Data Protection Officer, as it is not required to do so under Article 37 GDPR. Any question about this policy or about your personal data can be sent to the email address above.
02Scope of this policy
This policy applies to the website available at gsldm.com (the "Site") and to the personal data we process when you browse it or use its contact form. It does not cover data that we may process under a separate licence, evaluation or services agreement relating to the GSLDM data model; that processing is governed by the terms of the relevant agreement.
The Site is an informational, marketing website. It does not require an account, does not offer a login, and does not provide any transactional service.
03Data we collect
3.1 Data you give us through the contact form
When you use the "Request information" form, we collect the data you type into it:
- Work email address (required)
- Institution — the bank, agent or platform you represent (optional)
- Comment — any free-text message you choose to include (optional)
We also record the date and time the form was submitted. Please do not include special categories of personal data (such as health, political or religious information) or confidential deal information in the comment field; the form is intended for a short introduction only.
3.2 Data collected automatically
Like most websites, our hosting infrastructure automatically records standard technical information when your browser requests a page or resource, including your IP address, browser type and version, operating system, referring URL, the pages requested and the time of the request. This information is contained in server logs and is used solely to operate, secure and troubleshoot the Site. We do not use it to build a profile of you.
3.3 Analytics data (only with your consent)
If you accept analytics cookies in the consent banner, we use Google Analytics 4 (via the Firebase
Analytics SDK) to measure how the Site is used. Google Analytics assigns a random, pseudonymous identifier to your
browser (stored in the _ga cookie) and records the pages you view, the time spent on them, the referring
site, your approximate location (derived from your IP address, which Google Analytics 4 does not store), and your
browser, device type, language and screen size. We have disabled Google Signals and all advertising features, so this
data is not used for advertising or to track you across other websites.
If you decline, or do not answer the banner, the analytics code is not loaded and none of this data is collected. Your choice itself is stored in your browser's local storage so that we do not ask you again.
3.4 What we do not collect
The Site does not use advertising, remarketing or social-media tracking, and does not create user accounts. Full details of the cookies used are in our Cookie Policy.
04Purposes and legal bases
We process personal data only for the purposes below, each on the legal basis indicated (Article 6 GDPR).
| Purpose | Data used | Legal basis |
|---|---|---|
| Responding to your enquiry about GSLDM, its documentation, access or licensing | Contact form data | Art. 6(1)(b) — steps taken at your request prior to entering into a contract; and Art. 6(1)(f) — our legitimate interest in answering enquiries addressed to us |
| Measuring the audience of the Site and understanding which content is read, in order to improve it | Analytics data (section 3.3) | Art. 6(1)(a) — your consent, given through the cookie banner and withdrawable at any time via the "Cookie settings" link in the footer |
| Operating, securing and troubleshooting the Site, and preventing abuse of the contact form | Technical data (server logs) | Art. 6(1)(f) — our legitimate interest in keeping the Site available and secure |
| Complying with legal obligations and establishing, exercising or defending legal claims | Any of the above, as required | Art. 6(1)(c) — legal obligation; Art. 6(1)(f) — legitimate interest |
We do not add contact form submissions to a mailing list, use them for automated marketing, or sell or rent them to anyone. If we later wish to send you marketing communications, we will only do so with your prior consent or where otherwise permitted by law, and you will be able to opt out at any time.
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you.
05Who we share data with
We share personal data only with service providers who process it on our behalf and under our instructions (data processors), and with authorities where required by law. Our current providers are:
| Provider | Role | Location |
|---|---|---|
| Google Cloud EMEA Ltd (Firebase Hosting, Cloud Functions, Cloud Firestore) | Hosts the Site, executes the contact form handler and stores form submissions | Site hosting on Google's global content delivery network; form handler in Frankfurt (europe-west3); form submissions stored in Madrid (europe-southwest1) |
| Google Ireland Ltd / Google LLC (Google Analytics 4) | Audience measurement — only if you accept analytics cookies | European Union and United States (see section 6) |
| Google LLC (Google Fonts) | Serves the web fonts used on the Site | Global |
| Cloudflare, Inc. (cdnjs) | Serves an animation library used on the Site | Global |
| Our email service provider | Delivers a copy of each form submission to our mailbox | European Union |
When your browser loads a resource from a third-party provider (fonts, scripts), that provider necessarily receives your IP address and standard request headers in order to deliver the resource. Those providers act under their own privacy notices for that limited technical processing.
We may also disclose personal data where required by law, court order or a competent authority, or where necessary to protect our rights, property or safety or those of others. If GSLDM SL is involved in a merger, acquisition or sale of assets, personal data may be transferred to the successor entity subject to this policy.
06International transfers
We store contact form submissions in the European Union. Some of our providers are headquartered in, or operate infrastructure in, countries outside the European Economic Area (EEA), including the United States; in particular, Google Analytics data may be processed by Google LLC on servers in the United States. Where personal data is transferred outside the EEA, we rely on one or more of the following safeguards under Chapter V GDPR:
- an adequacy decision of the European Commission, including the EU-US Data Privacy Framework, under which Google LLC is certified; and/or
- the European Commission's Standard Contractual Clauses, supplemented where necessary by additional technical and organisational measures.
You may request a copy of the relevant safeguards by contacting us at the address in section 12.
07How long we keep data
- Contact form submissions are kept for as long as needed to respond to and follow up your enquiry, and in any event for no longer than 24 months after our last exchange with you, unless a business relationship is established, in which case the data will be retained under the terms of that relationship.
- Server logs are retained by our hosting provider for a short period (typically no more than 30 days) for security and diagnostic purposes, unless a specific incident requires longer retention.
- Analytics data: user- and event-level data in Google Analytics is retained for
2 months (the shortest setting Google offers); aggregated, non-identifying reports are retained for
longer. The
_gacookies expire after 2 years or when you withdraw consent, whichever is sooner, and the record of your consent choice expires after 12 months. - We may retain data for longer where required to comply with a legal obligation, to resolve disputes or to enforce our agreements, in which case it will be restricted to those purposes.
When data is no longer needed, it is deleted or irreversibly anonymised.
08Your rights
Under the GDPR and Spanish Organic Law 3/2018 (LOPDGDD), you have the right to:
- Access the personal data we hold about you and obtain a copy of it;
- Rectify inaccurate or incomplete data;
- Erase your data where there is no longer a lawful reason for us to keep it;
- Restrict processing in the circumstances set out in Article 18 GDPR;
- Object to processing based on our legitimate interests, on grounds relating to your particular situation — and object at any time to direct marketing;
- Data portability — receive the data you gave us in a structured, commonly used, machine-readable format, where processing is based on a contract or consent and carried out by automated means;
- Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal. For analytics cookies, use the "Cookie settings" link in the footer of any page.
To exercise any of these rights, email info@gsldm.com from the address you used to contact us, or otherwise provide enough information for us to verify your identity. We will respond within one month, extendable by two further months for complex requests, in which case we will tell you. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.
You also have the right to lodge a complaint with a supervisory authority. In Spain this is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es. If you live in another EU/EEA country, you may complain to the authority of your place of residence or work.
09Security
We apply technical and organisational measures appropriate to the risk to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These include transport encryption (HTTPS/TLS) for all traffic to the Site, encryption at rest for stored form submissions, access restricted to authorised personnel on a need-to-know basis, and the use of established cloud infrastructure providers that maintain recognised security certifications.
No transmission over the internet is completely secure. If you become aware of a security issue affecting the Site, please let us know at info@gsldm.com.
10Children
The Site is directed at professionals working in the syndicated loan market and is not intended for anyone under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
11Changes to this policy
We may update this policy from time to time to reflect changes in our processing, in the Site or in applicable law. The date at the top of the page indicates when it was last revised. Where a change is material, we will make this clear on the Site. We encourage you to review this page periodically.
12Contact
For any question, request or complaint relating to this policy or to your personal data, contact:
- Controller
- GSLDM SL
- info@gsldm.com
- Post
- [Registered address to be completed], Spain