1. Introduction & Scope
Aevum News ("we", "our", or "us") is committed to protecting the privacy and personal data of our readers, subscribers, contributors, and website visitors. This GDPR Compliance Policy outlines how we collect, process, store, and protect your personal information in accordance with the European Union's General Data Protection Regulation (EU) 2016/679 and applicable data protection laws.
This policy applies to all interactions with Aevum News, including our website, mobile applications, newsletter subscriptions, user accounts, analytics services, and customer support channels.
Note: While this policy is drafted to comply with GDPR standards, it is a template for informational purposes. Always consult qualified legal counsel to ensure full regulatory compliance for your specific operations.
2. Data Controller Information
The data controller responsible for your personal data is:
Organization: Aevum News Media Group
Registered Address: 42 Press Avenue, Suite 100, Berlin, 10115, Germany
Legal Entity: Aevum News GmbH
Registration Number: HRB 987654 B
3. Personal Data We Collect
We only collect personal data that is necessary for the purposes outlined below. Categories of data include:
- Identity Data: Name, username, profile picture (if provided)
- Contact Data: Email address, mailing address, phone number
- Technical Data: IP address, browser type, device information, OS, referring URLs, time zone
- Usage Data: Pages visited, article reading time, click patterns, subscription status, newsletter engagement
- Transaction Data: Payment information, subscription tier, billing history (processed securely via PCI-DSS compliant providers)
- Marketing Data: Preferences for newsletters, communication frequency, opt-in/opt-out choices
4. Lawful Basis for Processing
We process your personal data under the following GDPR-compliant lawful bases:
- Contractual Necessity: To provide subscribed services, manage accounts, and process payments.
- Consent: For newsletter subscriptions, personalized content recommendations, and non-essential cookies. Consent can be withdrawn at any time.
- Legitimate Interests: To improve website functionality, analyze usage trends, prevent fraud, and maintain service security. We balance these interests against your privacy rights.
- Legal Obligation: To comply with tax, anti-money laundering, and media licensing regulations.
5. Data Sharing & Third Parties
We do not sell your personal data. We only share data with trusted third-party processors who assist us in operating our platform:
- Newsletter Providers: For delivering and tracking email campaigns
- Payment Processors: Secure billing and subscription management
- Analytics Partners: Aggregated, anonymized site performance tracking
- Cloud Infrastructure: Secure data hosting and backup services
- Legal & Regulatory Bodies: When required by law, court order, or to protect vital interests
All third-party processors are bound by strict Data Processing Agreements (DPAs) and undergo regular compliance audits.
6. Data Retention Periods
We retain your personal data only as long as necessary:
- Active Subscribers: Duration of subscription + 12 months for support inquiries
- Newsletter Contacts: Until unsubscribe or 24 months of inactivity
- Technical & Analytics Data: 12 months (aggregated thereafter)
- Payment Records: 7 years (tax & legal compliance)
- Account Data: Purged or anonymized 90 days after voluntary deletion
7. Your Rights Under GDPR
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete information
- Erasure: Request deletion of your data ("Right to be Forgotten")
- Restriction: Limit processing under certain conditions
- Data Portability: Receive your data in a structured, machine-readable format
- Objection: Opt out of direct marketing or processing based on legitimate interests
- Automated Decision-Making: Not be subject to decisions based solely on automated processing
To exercise any right, contact our Data Protection Officer (Section 11). We will respond within 30 days, extendable by 60 days for complex requests.
9. Security Measures
We implement industry-standard technical and organizational safeguards:
- End-to-end encryption (TLS 1.3) for data in transit
- AES-256 encryption for data at rest
- Regular penetration testing & vulnerability assessments
- Role-based access control & multi-factor authentication for staff
- Annual privacy & security training for all employees
- Incident response plan with 72-hour breach notification protocol
10. International Data Transfers
If your data is transferred outside the European Economic Area (EEA), we ensure adequate protection through:
- European Commission adequacy decisions
- Standard Contractual Clauses (SCCs)
- Binding Corporate Rules (BCRs) where applicable
- Transfer Impact Assessments (TIAs) for high-risk jurisdictions
11. DPO & Contact Information
For privacy inquiries, data rights requests, or concerns, please contact our designated Data Protection Officer:
Data Protection Officer: Dr. Helena Vogel
Email: dpo@aevumnews.com
Phone: +49 30 9876 5432
Mailing Address: DPO Office, Aevum News GmbH, 42 Press Avenue, Suite 100, Berlin, 10115, Germany
You also have the right to lodge a complaint with your local supervisory authority or the Berlin Commissioner for Data Protection and Freedom of Information.
12. Policy Updates
We may update this policy to reflect changes in services, technology, or legal requirements. Material changes will be communicated via email or prominent website notice. Continued use of Aevum News after updates constitutes acceptance of the revised terms.
This document reflects Aevum News' commitment to transparent, accountable data stewardship. We believe privacy is a fundamental right, not an afterthought.