Privacy Policy

Eldarion Solutions S.L. and its affiliates (“Eldarion”, “we”, “us”) build and operate an AI-powered financial research and workflow platform for investment professionals. We are dedicated to protecting the personal data entrusted to us and to processing it lawfully, transparently and only for the purposes described below.

Controller
Eldarion Solutions S.L. · B88998174
Service
eldarion.ai — AI-powered financial research platform
Last updated
1 September 2026
Version
1.0

This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, and the rights available to you.

01Applicability of This Privacy Policy

This Privacy Policy applies to personal data that Eldarion processes as a controller, including personal data collected through:

  • our public websites, including eldarion.ai and any documentation, help centre or marketing pages we operate;
  • the Eldarion platform and its modules — the chat agent, QSand (visual workflow editor), the Tool Workshop, the valuation toolkit, Luca (equity research), the Wealthma, Asset Managers and Atrium surfaces, the administration console and the help centre;
  • our email interfaces, including submissions sent to our ingestion mailboxes and our transactional and campaign email;
  • commercial, support, recruitment and event interactions with prospects, customers and visitors.

If you use Eldarion through your employer or another organisation, that organisation determines who may access the Services, what data is loaded into them and how long it is kept. Questions about those choices should be directed to that organisation in the first instance.

02Personal Data We Collect and Process

2.1Information you provide to us

  • Account and identity data — name, business email address, employer, job title, professional role and seniority, the modules and permissions assigned to you, language preference, and the credentials used to authenticate you (password hashes, and, where enabled, single sign-on identifiers and multi-factor authentication data).
  • Commercial and billing data — contracting entity, subscription tier, seat allocation, billing contact, purchase orders, invoicing and transaction history. Card details, where applicable, are captured directly by our payment processor and are not stored on Eldarion systems.
  • Communications data — support requests and their attachments, bug reports and product feedback, in-app ratings of agent answers, survey and interview responses, webinar and event registrations, and correspondence sent to any of our mailboxes.
  • Interactions on public channels — the content of posts, comments or messages you direct to Eldarion on professional and social networks.

2.2Information we collect automatically

  • Log and technical data — IP address, approximate location derived from it, browser type and version, operating system, device and screen characteristics, referring and exit pages, time zone, and the date and time of each request.
  • Service usage metadata — sign-in and session events, modules and features opened, number and type of queries submitted (chat, deep research, workflow runs, valuation runs, report exports), workflow and tool executions, latency and error events, token and compute consumption, and administrative actions recorded in our audit log.
  • Cookies and similar technologies — strictly necessary cookies for authentication, session integrity and security, and — where you consent — preference, measurement and analytics technologies. See our Cookie Policy for the full inventory, purposes and durations, and for how to change your choices at any time.

2.3Information we receive from third parties

  • Your organisation — where your employer provisions or de-provisions your account, it supplies your identity and entitlement data to us.
  • Identity and security providers — single sign-on and directory providers, and security vendors that alert us to leaked or compromised credentials and to fraudulent or abusive activity.
  • Marketing and data-enrichment vendors — business contact details, employer, role and firmographic attributes, used to qualify and address prospective customers.
  • Advertising and measurement partners — aggregate and campaign-level engagement metrics.
  • Market data and research providers — including our financial reference data supplier. This data concerns issuers, instruments and markets; it may incidentally include personal data of company officers, analysts or other public figures.
  • Events, partners and referrers — conference organisers, integration partners and customers who refer a contact to us.

2.4Publicly available information

We process information that is lawfully public — corporate registries, regulatory filings, exchange disclosures, issuer publications, financial news, professional networks and firm websites — in order to operate and improve the research capabilities of the Services. Where such sources contain personal data (for example the name and role of a board member quoted in a filing), we process it on the basis of our legitimate interest in providing a financial research service, and we apply the safeguards described in sections 5 and 8.

2.5Sensitive data

Eldarion does not seek to collect special categories of personal data (Article 9 GDPR) and the Services are not designed to receive them. Users must not upload special-category data into the platform except where their own customer agreement expressly provides for it.

03How We Use Personal Data

  • To provide the Services — to create, authenticate and administer accounts, apply entitlements and feature flags, execute queries, workflows, valuations and report exports, and deliver results through the interface or by email.
  • To operate our infrastructure — hosting, storage, caching, backup, monitoring, capacity planning and incident response.
  • To bill and administer the commercial relationship — subscription management, metering, invoicing, collections and accounting records.
  • To support you — to answer questions, reproduce and resolve incidents and communicate about service status, releases and maintenance windows.
  • To develop, evaluate and improve the Services — measuring quality, latency and cost, analysing failure patterns, evaluating models and prompts, and building new features. Wherever the purpose permits it, we do this on aggregated or de-identified data.
  • To personalise your experience — retaining your language, layout, module and workspace preferences and surfacing relevant content.
  • To secure the Services and prevent abuse — authentication, rate limiting, sandboxing of code execution, abuse and fraud detection, audit logging and investigation of security incidents.
  • To market our Services — sending commercial communications to business contacts, running and measuring campaigns, and organising events. You may withdraw consent or object at any time.
  • To comply with law and defend our rights — meeting accounting, tax, statutory and regulatory obligations, responding to lawful requests from authorities, and establishing, exercising or defending legal claims.

3.1Artificial intelligence models and your data

The Services use large language models — including third-party foundation models made available to us under enterprise terms — to generate research, analysis and workflow output.

3.2Aggregated and de-identified data

We aggregate or de-identify personal data so that it can no longer reasonably be attributed to an identified or identifiable person, and we use the result for statistics, benchmarking, capacity planning and product research. We do not attempt to re-identify such data.

04Who We Share Your Personal Data With

We do not sell personal data. We disclose it only to the following categories of recipients:

  • Affiliates — other entities within the Eldarion group, for the operational, administrative and support purposes described in this Policy.
  • Cloud and infrastructure providers — our production environment is hosted on Google Cloud Platform in the europe-west1 (Belgium) region, together with the associated managed database, object storage and logging services.
  • AI model providers — foundation model providers that perform inference on our behalf under enterprise terms that prohibit training on submitted content.
  • Market data providers — the financial reference data suppliers whose datasets power the research surfaces.
  • Operational vendors — email delivery and workspace providers, error monitoring and observability tooling, customer support tooling, analytics providers and professional services firms. An up-to-date list of subprocessors is available at https://www.eldarion.ai/subprocessors.html and to customers on request.
  • Payment and billing providers — for the processing of subscription payments and the maintenance of accounting records.
  • Your organisation — where you use the Services through a customer account, its administrators can see account, entitlement and usage information relating to your use of the Services.
  • Professional advisers, auditors and authorities — lawyers, accountants and auditors under duties of confidentiality, and regulators, courts or law enforcement where disclosure is legally required or necessary to protect our rights or the safety of others.
  • Corporate transactions — a counterparty, and its advisers, in connection with a merger, acquisition, financing, reorganisation or insolvency, subject to appropriate confidentiality protections.
  • Advertising and measurement partners — only where you have consented, and only for the campaign measurement and interest-based marketing described in our Cookie Policy.

Every vendor that processes personal data on our behalf acts under a written contract that meets Article 28 GDPR, restricts processing to our documented instructions and imposes confidentiality and security obligations.

05How We Keep Your Personal Data Secure

We implement technical and organisational measures appropriate to the risk of the processing, and we review them as the platform evolves. These include: encryption of data in transit (TLS) and at rest; role-based access control with least-privilege provisioning and periodic access review; multi-factor authentication for administrative access; network segmentation and a sandboxed, isolated execution environment for code run by the platform; secrets management; audit logging of privileged and administrative actions; backup and restoration procedures; vulnerability management and dependency scanning; secure development practices and change control; vendor security due diligence; and a documented security incident response process, including notification of the competent supervisory authority and of affected individuals where legally required.

No system can be guaranteed to be completely secure. If you believe your account or credentials have been compromised, contact admin@eldarion.ai immediately.

06International Data Transfers

Eldarion is established in Spain and hosts its production environment within the European Union. Some of our vendors, affiliates or model providers are, however, located outside the EEA, the United Kingdom or Switzerland, or may access data from such locations. Where personal data is transferred to a country that does not benefit from an adequacy decision, we rely on one or more of the following:

  • Adequacy decisions — European Commission, UK and Swiss determinations that a country, territory or certification framework offers an adequate level of protection.
  • Standard Contractual Clauses — the European Commission’s SCCs (Implementing Decision (EU) 2021/914), together with the UK International Data Transfer Addendum and the Swiss adaptations issued by the FDPIC.
  • Supplementary measures — informed by a transfer impact assessment, including encryption, pseudonymisation, access limitation and a commitment to challenge disproportionate government access requests.
  • Derogations — in limited and non-repetitive cases, one of the situations set out in Article 49 GDPR, such as your explicit consent or the necessity of the transfer for the performance of a contract.

You may request a copy of the relevant transfer mechanism, with commercially sensitive terms redacted, by writing to admin@eldarion.ai.

07Data Retention

We keep personal data only for as long as we have a legitimate need for it. The applicable period is determined by:

  • the duration of the contractual relationship with you or with your organisation, and the retention periods that customer has configured or instructed;
  • statutory retention obligations, in particular commercial, tax and accounting rules, and any anti-money laundering or regulatory record-keeping duties that apply to us;
  • the existence of an actual or reasonably anticipated dispute, investigation or legal claim.

By way of orientation: account and entitlement records are kept for the life of the account and for 12 months thereafter; security and audit logs for 12 months; billing and accounting records for the period required by applicable commercial and tax law; and marketing contact data until you object or withdraw consent, or after 24 months of inactivity. When a retention period ends we delete the data or irreversibly anonymise it. Where immediate deletion is not technically possible — for example within an encrypted backup — we isolate the data and protect it from further processing until deletion occurs on the normal backup cycle.

08Jurisdiction-Specific Provisions — EEA, United Kingdom and Switzerland

This section applies where the GDPR (Regulation (EU) 2016/679), the UK GDPR and Data Protection Act 2018, or the Swiss Federal Act on Data Protection apply to our processing. The controller is Eldarion Solutions S.L., Calle Cirilo Amorós 581, 46004 Valencia, Spain.

8.1Legal bases for processing

PurposeLegal basis (Art. 6 GDPR)Principal data categories
Account creation, authentication and provision of the ServicesPerformance of a contract (Art. 6(1)(b)); where the contract is with your employer, our legitimate interest in serving our customer (Art. 6(1)(f))Identity and account data, credentials, entitlements, usage metadata
Service-related and administrative communicationsPerformance of a contract (Art. 6(1)(b)); legitimate interest in operating the Services (Art. 6(1)(f))Identity and contact data, communications data, log data
Billing, metering, collections and accountingPerformance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))Commercial and billing data, usage and consumption metering
Customer support and incident resolutionPerformance of a contract (Art. 6(1)(b)); legitimate interest in resolving incidents (Art. 6(1)(f))Identity data, communications data, log and diagnostic data
Service quality measurement, evaluation and product developmentLegitimate interest in improving and securing a service our customers rely on (Art. 6(1)(f))Usage metadata, quality and error signals, feedback, aggregated or de-identified data
Personalisation of the interface and contentLegitimate interest in delivering a usable service (Art. 6(1)(f)); consent where required for non-essential cookies (Art. 6(1)(a))Preferences, usage metadata, cookie and device identifiers
Security, abuse and fraud prevention, audit loggingLegitimate interest in protecting the Services, our users and our customers (Art. 6(1)(f)); legal obligation (Art. 6(1)(c))Log and technical data, authentication events, audit records
Marketing communications, campaigns and eventsConsent (Art. 6(1)(a)); legitimate interest in business-to-business direct marketing to existing contacts (Art. 6(1)(f))Business contact data, employer and role, engagement metrics
Disclosure to vendors, affiliates and partnersPerformance of a contract (Art. 6(1)(b)); legitimate interest in operating efficiently (Art. 6(1)(f))The categories necessary for the relevant service
Legal compliance, requests from authorities, legal claimsLegal obligation (Art. 6(1)(c)); legitimate interest in establishing, exercising or defending legal claims (Art. 6(1)(f))Any category relevant to the obligation or claim
Corporate reorganisation, merger or acquisitionLegitimate interest in conducting corporate transactions (Art. 6(1)(f))Account, commercial and contact data

Where we rely on legitimate interests, we have carried out a balancing assessment weighing those interests against your rights and freedoms. You may request a summary of the relevant assessment by writing to admin@eldarion.ai.

8.2Provision of data and automated decision-making

Providing account and billing data is necessary to enter into and perform the contract; without it we cannot give you access to the Services. Providing marketing preferences is voluntary. Eldarion does not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing within the meaning of Article 22 GDPR. The Services generate analytical output that is intended to be reviewed by a qualified professional.

8.3Supervisory authorities

You may lodge a complaint with the supervisory authority of your habitual residence, place of work or the place of the alleged infringement — in Spain, the Agencia Española de Protección de Datos (www.aepd.es); in the United Kingdom, the Information Commissioner’s Office (ico.org.uk); in Switzerland, the Federal Data Protection and Information Commissioner (edoeb.admin.ch). We would appreciate the opportunity to address your concern first.

09Minors’ Data

The Services are professional tools intended exclusively for business users and are not directed at, or intended for use by, individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have collected such data, we will delete it without undue delay. If you believe a minor has provided us with personal data, write to admin@eldarion.ai.

10Your Data Protection Rights

Subject to the conditions and exceptions of applicable law, you have the right to:

  • Access — obtain confirmation as to whether we process your personal data and a copy of it;
  • Rectification — have inaccurate or incomplete data corrected or completed;
  • Erasure — obtain deletion of your data where one of the grounds in Article 17 GDPR applies;
  • Restriction — obtain the restriction of processing in the cases set out in Article 18 GDPR;
  • Objection — object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests, and object absolutely to processing for direct marketing;
  • Portability — receive the data you provided to us in a structured, commonly used and machine-readable format and have it transmitted to another controller where technically feasible;
  • Withdraw consent — at any time, without affecting the lawfulness of processing carried out before the withdrawal;
  • Not be subject to automated decision-making producing legal or similarly significant effects;
  • Lodge a complaint with a supervisory authority, as set out in section 8.3.

To exercise these rights, write to admin@eldarion.ai. We may need to verify your identity before acting, and we will respond within one month of receipt, extendable by two further months where the request is complex, in which case we will inform you of the extension and its reasons. Exercising your rights is free of charge unless the request is manifestly unfounded or excessive. You can unsubscribe from marketing communications at any time using the link in any such message.

If your request concerns Customer Content processed on behalf of a customer organisation, we will refer you to that organisation, or assist it in responding, as our data processing agreement requires.

11Updates to This Privacy Policy

We may update this Privacy Policy to reflect changes in our Services, our vendors, or the legal, regulatory and technical environment. The “Last updated” date at the top of this document indicates when the current version took effect, and previous versions are archived and available on request. Where a change is material we will provide advance notice by email or through the Services and, where the law requires it, we will seek your consent.

12How to Contact Us

Controller
Eldarion Solutions S.L. — B88998174
Registered office
Calle Cirilo Amorós 581
46004 Valencia (Valencia), Spain
Privacy enquiries, rights requests and security incidents
admin@eldarion.ai · eldarion.ai

Eldarion · Privacy Policy v1.0 · 1 September 2026