Trust & legal
Privacy Policy
What personal data we collect, why, on what legal basis, how long we keep it, and how to exercise your rights under the GDPR.
Last updated
This policy explains how George Lagkonakis handles personal data on Investo24. It is written to be read, not to be survived: where the GDPR requires a specific disclosure we make it, and where the honest answer is “we do not do that”, we say so instead of reserving the right to start.
Who is responsible for your data
The controller for the processing described here, within the meaning of Article 4(7) GDPR, is George Lagkonakis, who publishes Investo24 at https://www.investo24.com in a private capacity. Contact details are on the imprint.
For any question about this policy or to exercise a right described in section 6, write to giorgoslankonakes@gmail.com. We answer privacy requests from this address and no other.
We have not appointed a data protection officer. Our processing is not of a scale or nature that requires one under Article 37 GDPR; if that changes, this section will name the appointed person.
The short version
This site does not track you.
We set no cookies, run no analytics, embed no advertising pixels and load no third-party script unless you ask for one. Nothing on this site follows you across the web, and we do not build a profile of you.
That is unusual enough to be worth stating plainly. The only personal data we hold is data you deliberately send us — an email you write to us, or an address you give us for the newsletter once that is live. Everything else in this policy describes either the technical minimum required to serve a web page, or things we would have to tell you about before switching them on.
What we collect, why, and on what basis
Article 13 GDPR requires us to set out each purpose alongside its legal basis and retention period. This table is exhaustive for the site as it stands today.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Server log data: IP address, timestamp, requested URL, referrer, user agent | Delivering the page you requested, and detecting abuse or attacks | Art. 6(1)(f) — our legitimate interest in operating a secure, functioning website | Deleted or anonymised within 30 days |
| Your email address and the contents of your message | Answering the question you asked us | Art. 6(1)(f) — legitimate interest in responding to correspondence; Art. 6(1)(b) where your message concerns an agreement with us | 24 months after the exchange ends, then deleted |
| Your email address, if you subscribe to the newsletter | Sending the monthly briefing you asked for | Art. 6(1)(a) — your consent, withdrawable at any time | Until you unsubscribe, then deleted within 30 days |
We do not collect special categories of data (Art. 9 GDPR), we do not knowingly collect data from children, and we carry out no automated decision-making or profiling with legal or similarly significant effects (Art. 22 GDPR).
The contact form
Our contact form does not submit anything to us over the web. It assembles a message in your own email program, which you then send yourself. Your message therefore travels through your email provider, not through our servers, and we receive it exactly as we would receive any other email.
Practically, that means we never hold a draft you did not send, and your email provider's privacy policy governs the transmission.
Who else sees your data
We do not sell personal data, and we do not share it with the fund providers we write about. There are no affiliate or tracked outbound links on this site, so following a link out of here tells the destination nothing about you beyond what any ordinary web request carries. See section 7 below for what happens once you are on someone else's site.
The only categories of recipient are:
- Our hosting provider, which processes server logs strictly on our instructions under an Article 28 data processing agreement.
- A mailing provider, once the newsletter launches — named here before it does.
- Public authorities, where we are legally required to disclose and only to the extent required.
Fonts are served from our own domain rather than a font CDN, so rendering this page makes no request to any third party.
The exception is the market charts on the markets page. If you press “Load the charts”, your browser requests them from TradingView, which receives your IP address, your browser's details and the address of the page, and which says it records how its widgets are used. TradingView handles that under its own privacy policy, not on our instructions, and nothing comes back to us. The cookie policy lists the servers it contacts and what we found it stores.
Your rights
Under the GDPR you may exercise any of the following. Write to giorgoslankonakes@gmail.com and we will respond within one month, as Article 12(3) requires. We do not charge for this.
- Access (Art. 15) — a copy of the personal data we hold about you, and the details of how we process it.
- Rectification (Art. 16) — correction of inaccurate data, and completion of incomplete data.
- Erasure (Art. 17) — deletion, where one of the grounds in that article applies.
- Restriction (Art. 18) — suspension of processing while a dispute about accuracy or legitimate interest is resolved.
- Portability (Art. 20) — the data you gave us, in a structured, machine-readable format.
- Objection (Art. 21) — to processing based on legitimate interest, on grounds relating to your situation. Where you object to direct marketing we must stop, with no balancing test.
- Withdrawal of consent (Art. 7(3)) — at any time, for anything we do on the basis of consent.
You also have the right to lodge a complaint with a supervisory authority (Art. 77) — and you may do so with the authority in your own country of residence, which for most readers will be the easiest route. The authority for the publisher is the Office of the Commissioner for Personal Data Protection in Cyprus.
Links to other sites
This site links out to fund providers, regulators and document sources. Once you follow such a link you are on a site we do not control, governed by its privacy policy, not this one. Financial providers in particular are heavily instrumented — expect cookies, analytics and advertising tracking there even though there is none here.
None of our outbound links is tracked or carries a referral parameter, because nothing on this site is monetised.
Storage location and security
Data is processed on servers in the European Economic Area. Should any processing ever involve a transfer outside the EEA, we will rely on an adequacy decision or on the European Commission's standard contractual clauses, and will say so here first.
The site is served exclusively over HTTPS. We apply access controls and data minimisation as a matter of course — the strongest protection for data is not collecting it, which is the approach taken throughout.
Changes to this policy
We will update this policy when our processing changes — most likely when the newsletter or a privacy-friendly analytics tool goes live. Material changes will be announced on this page, and the date at the top always reflects the current version.
Where a change requires your consent, we will ask for it before the change takes effect rather than assuming it from continued use.