The Gold Congress logo
The GoldCongress
Legal

Privacy Policy

Version 2.1 · Last updated: July 31, 2026

This policy explains, in plain language, what personal data The Gold Congress processes, why, on what legal basis, who it is shared with and what you can do about it. It covers TheGoldCongress.com and every service reachable from it: the Congress registration flow, the Magazine, the Academy, the Newsletter and the contact forms.

1. Who is responsible

The controller for the processing described here is the entity operating The Gold Congress. Operator identification is provided on request and will be stated in full here once the operating entity's registration data is verified, before commercial launch.

For any privacy matter you can write directly to privacy@thegoldcongress.com. We answer substantive requests within one month, as required by Art. 12 GDPR.

2. What data we collect

We only collect data you give us, plus the minimum technical data needed to serve the site.

  • Registration data — first name, last name, email address, optionally your organisation and a free-text message, plus the ticket tier you selected.
  • Newsletter data — email address and the topic interests you select.
  • Contact data — the topic you choose, your name, email and message.
  • Academy progress — which lessons you have marked complete and your quiz answers. This is stored in your own browser (see section 4).
  • Technical data — IP address, user agent, referring URL and timestamps, processed by our hosting provider in server logs for security and troubleshooting.

We do not ask for and do not want special-category data (health, political opinions, religion), and we do not process payment card data ourselves — a payment provider handles that if you buy a paid ticket.

3. Why we process it, and on what basis

PurposeLegal basis (GDPR)
Delivering your Congress access and ticketArt. 6(1)(b) — contract
Sending the Newsletter you asked forArt. 6(1)(a) — consent, withdrawable at any time
Answering your contact enquiryArt. 6(1)(b) / 6(1)(f) — pre-contract or legitimate interest
Keeping the site secure and availableArt. 6(1)(f) — legitimate interest
Aggregate, non-identifying usage statisticsArt. 6(1)(f) — legitimate interest
Invoicing and statutory bookkeepingArt. 6(1)(c) — legal obligation

We do not use your data for automated decision-making or profiling that produces legal effects for you.

4. Data stored in your browser

Some features work entirely on your device. Academy lesson progress, quiz state, your newsletter subscription confirmation and your registration confirmation are written to your browser's local storage so the site remembers them between visits.

This data is not transmitted to us by that mechanism, is not readable by other websites, and is deleted whenever you clear your browser's site data. If you use a different browser or device, that state will not follow you.

5. Cookies & analytics

We use a minimal set of strictly necessary cookies and equivalent storage for site functionality. We do not run advertising networks, cross-site tracking pixels or data brokers on this site, and we do not sell or rent personal data — ever.

Where aggregate analytics are used, they are configured to avoid identifying individual visitors. If we ever introduce analytics or marketing technologies that require consent, we will ask for it through a consent banner before they load, and you will be able to withdraw consent as easily as you gave it.

6. Processors and recipients

As of the date at the top of this page, the website is served as static pages and the forms on it write only to your own browser's local storage. There is therefore no live email provider, streaming provider, payment processor or analytics vendor receiving your data from this site today.

As the Congress is built out we will engage service providers who process personal data on our documented instructions under a data-processing agreement pursuant to Art. 28 GDPR. The categories we anticipate are:

  • Hosting and content delivery (serving this website — active today)
  • Email delivery (transactional confirmations and the Newsletter — not yet engaged)
  • Streaming and webinar infrastructure (delivering the live Congress — not yet engaged)
  • Payment processing (paid tickets only — not yet engaged)
  • Accounting and invoicing (statutory records — not yet engaged)

This page is updated when a category becomes active, and we publish the concrete list of named subprocessors on request. Beyond these, we disclose data only where we are legally required to do so.

7. International transfers

Some providers operate infrastructure outside the European Economic Area. Where data is transferred outside the EEA or Switzerland, we rely on an adequacy decision where one exists, and otherwise on the European Commission's Standard Contractual Clauses together with supplementary technical measures such as encryption in transit and at rest.

8. How long we keep data

  • Newsletter subscribers — until you unsubscribe, then deleted within 30 days (we keep a suppression record of your email hash so we do not re-add you).
  • Registration records — for the edition you registered for plus 12 months, so we can support replay access and answer queries.
  • Contact enquiries — 24 months from the last message in the thread.
  • Invoices and accounting records — for the statutory retention period applicable to the operating entity (typically 7–10 years).
  • Server logs — short-lived, typically under 30 days.

9. Your rights

Under the GDPR, the Swiss FADP and equivalent laws you can:

  • ask what data we hold about you and receive a copy (Art. 15)
  • have inaccurate data corrected (Art. 16)
  • have data erased where there is no overriding legal ground to keep it (Art. 17)
  • restrict processing while a dispute is resolved (Art. 18)
  • receive your data in a portable, machine-readable format (Art. 20)
  • object to processing based on legitimate interest (Art. 21)
  • withdraw consent at any time, without affecting prior lawful processing (Art. 7(3))

You can remove your address from the Newsletter at any time on our unsubscribe page, and every Newsletter email will carry a one-click unsubscribe link. For anything else, email privacy@thegoldcongress.com — we do not require a specific form or legal wording.

10. Security

We apply technical and organisational measures appropriate to the risk: TLS encryption in transit, encryption at rest with our infrastructure providers, least-privilege access for staff, and review of changes that touch personal data. No system is perfectly secure, so we also plan for failure: suspected breaches are investigated immediately and, where the threshold of Art. 33/34 GDPR is met, notified to the competent authority within 72 hours and to affected individuals without undue delay.

Concretely: registration, Newsletter and contact-form records live in a private database with no public access rules — the website running in your browser cannot read, change or delete them. Writes happen only through our server, which validates every submission against a strict schema before storing it, using a credential that is never sent to your browser. We store no passwords and no payment card data.

If you believe you have found a vulnerability, report it to security@thegoldcongress.com. We will not pursue good-faith researchers who give us reasonable time to fix an issue before disclosure. Our full practices are set out on the Security & Data Protection page.

11. Children

This service is intended for finance professionals and adult private investors. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.

12. Changes to this policy

We may revise this policy as the service evolves. The version number and date at the top always reflect the current text. Material changes — new purposes, new categories of recipient, changed retention — are announced on the website and, where the change affects a service you use, by email before they take effect.

13. Contact and complaints

Privacy contact: privacy@thegoldcongress.com. General enquiries via our Contact page; operator details on request via that form.

You always have the right to lodge a complaint with a supervisory authority — in the EU, the data protection authority of your habitual residence or place of work; in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC). We would appreciate the chance to resolve the issue with you first.