πŸ“‹ Table of Contents

πŸ“Š
β–Ό

Aevum News collects and processes personal data in strict accordance with GDPR principles. We only collect data that is necessary for the specified purposes and ensure transparency about every piece of information we gather.

Directly Provided Data

Data you voluntarily provide when interacting with our services:

Data TypePurposeLegal Basis
Full NameAccount creation & profileContractual Necessity
Email AddressCommunication & newsletter deliveryConsent / Legitimate Interest
Password (hashed)Account authenticationContractual Necessity
Billing InformationSubscription processingContractual Necessity
Phone NumberAccount verificationConsent
Newsletter PreferencesContent personalizationConsent
Demographic DataAnalytics & content improvementLegitimate Interest

Automatically Collected Data

Information gathered when you interact with our websites, apps, or services:

  • IP Address β€” Server logs, fraud detection, geographic localization
  • Device Information β€” Browser type, OS, device identifiers, screen resolution
  • Usage Data β€” Pages visited, click patterns, session duration, referral sources
  • Cookie Data β€” See our detailed Cookie Policy (Section 04)
  • Location Data β€” Approximate geographic location based on IP
  • Log Data β€” Server access logs, error reports, performance metrics

πŸ“Œ Important: We never sell your personal data to third parties. Any data sharing is limited to disclosed sub-processors operating under GDPR-compliant Data Processing Agreements (DPAs).

Specially Protected Data

We do not collect special category data (GDPR Article 9) including:

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic, biometric, or health data
  • Sexual orientation or sex life data

If you voluntarily provide any such data (e.g., through a contact form), we will delete it immediately and not process it further.

βš–οΈ
β–Ό

Under GDPR Article 6, we process personal data based on the following lawful grounds. We assess each processing activity individually to ensure a valid legal basis exists.

1. Contractual Necessity (Article 6(1)(b))

Processing necessary to perform a contract or take steps at your request prior to entering a contract:

  • Managing your Aevum News account
  • Processing subscription payments
  • Delivering premium content as agreed
  • Providing customer support for paid services

2. Legitimate Interest (Article 6(1)(f))

Processing for our legitimate business interests, provided these do not override your fundamental rights:

  • Improving our website and services through analytics
  • Network and information security
  • Preventing fraud and unauthorized access
  • Internal business operations and reporting
  • Sending related promotional communications (with opt-out)

ℹ️ Legitimate Interest Assessment (LIA): We maintain a documented LIA for every processing activity. These assessments balance our interests against your rights and are reviewed annually by our Data Protection Officer.

3. Consent (Article 6(1)(a))

Processing based on your freely given, specific, informed, and unambiguous consent:

  • Newsletter subscriptions
  • Non-essential cookies and tracking technologies
  • Marketing communications
  • Third-party content sharing

Consent can be withdrawn at any time with the same ease as it was given. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

4. Legal Obligation (Article 6(1)(c))

Processing necessary for compliance with a legal obligation:

  • Financial record keeping (tax requirements)
  • Law enforcement disclosure when legally compelled
  • Data retention for cybersecurity purposes
πŸ”‘
β–Ό

As an EU data subject, you have the following rights under GDPR. You can exercise any of these rights free of charge by contacting our Data Protection Officer at dpo@aevumnews.com.

πŸ‘οΈ
Right of Access (Art. 15) Request a copy of all personal data we hold about you, including purposes, categories, recipients, and retention periods.
✏️
Right to Rectification (Art. 16) Request correction of inaccurate or incomplete personal data. We will update or complete your data within 30 days.
πŸ—‘οΈ
Right to Erasure (Art. 17) Request deletion of your data when it is no longer necessary, consent is withdrawn, or processing is unlawful.
⏸️
Right to Restrict (Art. 18) Request limitation of processing while we verify accuracy, lawful grounds, or your objection status.
πŸ“€
Right to Portability (Art. 20) Receive your data in a structured, machine-readable format and transmit it to another controller.
🚫
Right to Object (Art. 21) Object to processing based on legitimate interest or public interest. We must stop unless we demonstrate compelling grounds.
πŸ€–
Automated Decision-Making (Art. 22) Right not to be subject to solely automated profiling. We do not use automated decision-making for significant decisions.
πŸ“œ
Right to Lodge Complaint (Art. 77) You may file a complaint with your supervisory authority. Our DPO is registered with the relevant EU Data Protection Authority.

βœ… How to Exercise Your Rights: Submit a request via email to dpo@aevumnews.com or through your account dashboard under "Privacy Settings." We respond within 30 days (extendable by 60 days for complex requests). You will receive written confirmation of the action taken.

πŸͺ
β–Ό

Aevum News uses cookies and similar tracking technologies to provide, secure, and improve our services. We obtain your consent before placing non-essential cookies via our cookie consent management platform.

Cookie Categories

Managing Cookie Preferences

You can manage your cookie preferences at any time through:

  1. Cookie Consent Banner: Click "Cookie Settings" in the banner to modify preferences
  2. Account Settings: Navigate to Privacy Settings β†’ Cookie Preferences
  3. Browser Settings: Block or delete cookies through your browser's settings menu
  4. Do Not Track: We respect DNT signals and will disable non-essential tracking

⚠️ Important: Blocking strictly necessary cookies will impair core website functionality. Disabling analytics cookies may reduce our ability to improve our services. Marketing cookies can be refused without affecting content access.

Cookie Retention Periods

Cookie TypeDurationPurpose
Session IDSession onlyAuthentication & navigation
Consent Preferences12 monthsRemember cookie choices
Analytics (anonymized)24 monthsUsage statistics
Marketing / Tracking6 monthsAd personalization
CSRF Tokens1 hourForm security
πŸ“…
β–Ό

We retain personal data only for as long as necessary for the purposes collected, in compliance with the GDPR storage limitation principle (Article 5(1)(e)).

Retention Schedule

Data CategoryRetention PeriodBasis
Active Account DataDuration of account + 90 days post-deletionContractual Necessity
Subscription Records7 years (tax compliance)Legal Obligation
Newsletter SubscriptionUntil consent withdrawnConsent
Comment DataDuration + 24 monthsLegitimate Interest
Server Access Logs90 daysSecurity / Legitimate Interest
Analytics Data26 months (anonymized after 12 months)Legitimate Interest
Email Correspondence3 yearsLegitimate Interest
Support Ticket Data24 monthsLegitimate Interest
Marketing PreferencesDuration + 12 monthsConsent
Account Deletion Logs5 yearsLegal / Compliance

πŸ“Œ Anonymization: After the retention period expires, personal data is either securely deleted or fully anonymized so it can no longer be associated with an identifiable individual. Anonymized data may be retained for aggregate analytics.

Deletion Process

When data retention periods expire or you exercise your right to erasure:

  1. Data is flagged for deletion in our primary systems
  2. Backup data is marked for automatic purge in the next backup cycle (max 90 days)
  3. Third-party sub-processors receive deletion notices within 30 days
  4. Deletion is logged and confirmed in writing upon request
πŸ”
β–Ό

Aevum News implements appropriate technical and organizational measures (GDPR Article 32) to protect personal data against unauthorized access, loss, alteration, and disclosure.

Technical Safeguards

  • Encryption in Transit: TLS 1.3 for all data transmission. HSTS enforcement across all domains.
  • Encryption at Rest: AES-256 encryption for databases, backups, and file storage.
  • Access Controls: Role-based access control (RBAC) with least-privilege principle. MFA required for all admin access.
  • Penetration Testing: Quarterly penetration tests by independent security firms (last audit: Q4 2024)
  • Vulnerability Scanning: Continuous automated scanning with SLA of 24 hours for critical findings
  • Key Management: Hardware Security Modules (HSM) for cryptographic key management
  • Network Security: Next-gen firewalls, DDoS protection, Web Application Firewall (WAF)
  • Logging & Monitoring: Real-time SIEM with automated incident detection and response

Organizational Safeguards

  • Data Protection Training: Mandatory GDPR training for all employees (annual refresh)
  • NDAs: All staff sign confidentiality agreements covering data protection obligations
  • Incident Response: Documented breach response plan with 72-hour reporting protocol
  • Business Continuity: DR plans tested quarterly with RTO of 4 hours, RPO of 1 hour
  • Vendor Management: Rigorous due diligence for all data processors
  • Physical Security: Biometric access controls for all data center facilities

βœ… Certifications: Aevum News maintains ISO 27001 (Information Security), ISO 27701 (Privacy Information Management), and SOC 2 Type II certifications. Audit reports available upon request under NDA.

Data Breach Notification

In the event of a personal data breach, we will:

  1. Detect and contain the breach within 1 hour
  2. Assess the risk to data subjects within 4 hours
  3. Notify our supervisory authority within 72 hours (Article 33)
  4. Notify affected data subjects without undue delay where risk is high (Article 34)
  5. Maintain a detailed breach register documenting facts, effects, and remedial actions
🌐
β–Ό

Where we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place in compliance with GDPR Chapter V (Articles 44–50).

Transfer Mechanisms Used

  • EU Standard Contractual Clauses (SCCs): Adopted per the European Commission's Updated SCCs (2021/914). Applied to all third-country transfers.
  • UK International Data Transfer Agreement (IDTA): For transfers from the UK.
  • European Commission Adequacy Decisions: Transfers to countries deemed adequate (e.g., Canada, Japan, South Korea, Switzerland).
  • Binding Corporate Rules (BCRs): Where applicable for intra-group transfers.

Transfer Destinations

ServiceDestinationSafeguard
Cloud Infrastructure (AWS)EU (Frankfurt, Ireland)Adequacy Decision
CDN (Cloudflare)Global (with EU data center)SCCs + EU-US DPF
Analytics (Google Analytics 4)US (with EU data processing)SCCs + EU-US DPF
Email ServiceEU (Netherlands)Adequacy Decision
Payment ProcessingEU (Switzerland)Adequacy Decision
Backup StorageEU (Germany)Adequacy Decision

πŸ“Œ Transfer Impact Assessments (TIAs): We conduct TIAs for all non-EEA transfers. Where appropriate, supplementary measures (technical, contractual, organizational) are implemented to ensure an essentially equivalent level of protection.

πŸ”—
β–Ό

We engage sub-processors only after rigorous due diligence. All sub-processors are bound by GDPR-compliant Data Processing Agreements (DPAs) that mandate equivalent data protection standards.

Current Sub-Processors

Service ProviderPurposeLocationStatus
Amazon Web Services (AWS)Cloud hosting, storage, computeEU (Frankfurt)EU Compliant
CloudflareCDN, DDoS protection, WAFGlobal (EU ops)Sch. Approved
Google Cloud PlatformAnalytics, AI processingEU (Netherlands)EU Compliant
StripePayment processingEU (Ireland)EU Compliant
SendGrid / PostmarkEmail deliveryEU (Netherlands)Sch. Approved
Auth0 / OktaIdentity & access managementEU (Ireland)EU Compliant
DatadogMonitoring & observabilityEU (Ireland)Sch. Approved
SentryError tracking & debuggingEU (Netherlands)Sch. Approved

A full, up-to-date list of sub-processors is available at aevumnews.com/subprocessors and is updated quarterly. We provide 30 days' notice before adding any new sub-processor.

βœ… Your Control: If you object to a sub-processor change, you may exercise your right to erasure of your account data. We will not penalize you in any way for legitimate objections to sub-processor changes.

πŸ‘Ά
β–Ό

Aevum News is committed to protecting the privacy of children. We comply with GDPR provisions regarding children's consent and the UK Age Appropriate Design Code (Children's Code).

Our Policy

  • Aevum News is not directed at children under 16 (or lower where applicable per local law)
  • We do not knowingly collect personal data from children under the age of consent
  • If we discover we have inadvertently collected data from a child, we will delete it immediately
  • Parents/guardians can contact us to request removal of any child's data

🚨 Report a Concern: If you believe a child's data has been collected without proper consent, contact our DPO immediately at dpo@aevumnews.com. We prioritize these cases with a 48-hour response commitment.

πŸ“
β–Ό

We may update this GDPR Compliance Policy periodically to reflect changes in our practices, technology, or legal requirements. We will notify users of material changes through:

  • Email notification to registered users (minimum 30 days prior)
  • Website banner prominently displayed on our homepage
  • In-app notifications for premium subscribers
  • Updated revision date at the top of this page

Current Version History

VersionDateChanges
v3.2Jan 15, 2025Updated sub-processor list; Added EU-US DPF references
v3.1Sep 1, 2024Updated cookie policy; Added AI processing disclosures
v3.0Mar 15, 2024Major revision; Added SCCs update; Restructured sections
v2.0Jan 1, 2024Added UK DPA 2018 alignment; Updated retention periods
v1.0May 25, 2018Initial GDPR compliance publication

πŸ“Œ Continued Use: Continued use of our services after a policy update constitutes acceptance of the revised terms. If you disagree with changes, you may terminate your account and request data deletion.

πŸ“§
β–Ό

For any questions, requests, or concerns regarding data protection, privacy, or GDPR compliance, please contact our designated Data Protection Officer:

πŸ›‘οΈ Aevum News Data Protection Office

Available for inquiries during business hours (CET, Monday–Friday)

πŸ“ž +31 (0)20-XXX-XXXX
πŸ“ Amstelveen, Netherlands
πŸ• Response within: 48 hours

Supervisory Authority

If you wish to lodge a complaint with a regulatory authority, our lead supervisory authority is:

De Autoriteit Persoonsgegevens (AP)
Dutch Data Protection Authority
Herengracht 597, 1017 CE Amsterdam, Netherlands
autoriteitpersoonsgegevens.nl

Additional Information

Data Controller: Aevum News B.V.
Registration Number: NLXXXXXXXX
VAT Number: NLXXXXXXXXXXB01
Registered Address: Aevum News B.V., Media Plaza 42, 1185 DB Amstelveen, Netherlands
GDPR Representative: EU Representative available upon request
UK GDPR Representative: UK Rep available upon request

Compliance Certifications & Standards

πŸ†
ISO 27001:2022 Information Security Management
πŸ›‘οΈ
ISO 27701:2019 Privacy Information Management
πŸ”’
SOC 2 Type II Security, Availability, Confidentiality
βœ…
EU-US DPF Data Privacy Framework Certified