Eldarion Solutions S.L. and its affiliates (“Eldarion”, “we”, “us”) build and operate an AI-powered financial research and workflow platform for investment professionals. We are dedicated to protecting the personal data entrusted to us and to processing it lawfully, transparently and only for the purposes described below.
This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, and the rights available to you.
This Privacy Policy applies to personal data that Eldarion processes as a controller, including personal data collected through:
If you use Eldarion through your employer or another organisation, that organisation determines who may access the Services, what data is loaded into them and how long it is kept. Questions about those choices should be directed to that organisation in the first instance.
We process information that is lawfully public — corporate registries, regulatory filings, exchange disclosures, issuer publications, financial news, professional networks and firm websites — in order to operate and improve the research capabilities of the Services. Where such sources contain personal data (for example the name and role of a board member quoted in a filing), we process it on the basis of our legitimate interest in providing a financial research service, and we apply the safeguards described in sections 5 and 8.
Eldarion does not seek to collect special categories of personal data (Article 9 GDPR) and the Services are not designed to receive them. Users must not upload special-category data into the platform except where their own customer agreement expressly provides for it.
The Services use large language models — including third-party foundation models made available to us under enterprise terms — to generate research, analysis and workflow output.
We aggregate or de-identify personal data so that it can no longer reasonably be attributed to an identified or identifiable person, and we use the result for statistics, benchmarking, capacity planning and product research. We do not attempt to re-identify such data.
We implement technical and organisational measures appropriate to the risk of the processing, and we review them as the platform evolves. These include: encryption of data in transit (TLS) and at rest; role-based access control with least-privilege provisioning and periodic access review; multi-factor authentication for administrative access; network segmentation and a sandboxed, isolated execution environment for code run by the platform; secrets management; audit logging of privileged and administrative actions; backup and restoration procedures; vulnerability management and dependency scanning; secure development practices and change control; vendor security due diligence; and a documented security incident response process, including notification of the competent supervisory authority and of affected individuals where legally required.
No system can be guaranteed to be completely secure. If you believe your account or credentials have been compromised, contact admin@eldarion.ai immediately.
Eldarion is established in Spain and hosts its production environment within the European Union. Some of our vendors, affiliates or model providers are, however, located outside the EEA, the United Kingdom or Switzerland, or may access data from such locations. Where personal data is transferred to a country that does not benefit from an adequacy decision, we rely on one or more of the following:
You may request a copy of the relevant transfer mechanism, with commercially sensitive terms redacted, by writing to admin@eldarion.ai.
We keep personal data only for as long as we have a legitimate need for it. The applicable period is determined by:
By way of orientation: account and entitlement records are kept for the life of the account and for 12 months thereafter; security and audit logs for 12 months; billing and accounting records for the period required by applicable commercial and tax law; and marketing contact data until you object or withdraw consent, or after 24 months of inactivity. When a retention period ends we delete the data or irreversibly anonymise it. Where immediate deletion is not technically possible — for example within an encrypted backup — we isolate the data and protect it from further processing until deletion occurs on the normal backup cycle.
This section applies where the GDPR (Regulation (EU) 2016/679), the UK GDPR and Data Protection Act 2018, or the Swiss Federal Act on Data Protection apply to our processing. The controller is Eldarion Solutions S.L., Calle Cirilo Amorós 581, 46004 Valencia, Spain.
| Purpose | Legal basis (Art. 6 GDPR) | Principal data categories |
|---|---|---|
| Account creation, authentication and provision of the Services | Performance of a contract (Art. 6(1)(b)); where the contract is with your employer, our legitimate interest in serving our customer (Art. 6(1)(f)) | Identity and account data, credentials, entitlements, usage metadata |
| Service-related and administrative communications | Performance of a contract (Art. 6(1)(b)); legitimate interest in operating the Services (Art. 6(1)(f)) | Identity and contact data, communications data, log data |
| Billing, metering, collections and accounting | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) | Commercial and billing data, usage and consumption metering |
| Customer support and incident resolution | Performance of a contract (Art. 6(1)(b)); legitimate interest in resolving incidents (Art. 6(1)(f)) | Identity data, communications data, log and diagnostic data |
| Service quality measurement, evaluation and product development | Legitimate interest in improving and securing a service our customers rely on (Art. 6(1)(f)) | Usage metadata, quality and error signals, feedback, aggregated or de-identified data |
| Personalisation of the interface and content | Legitimate interest in delivering a usable service (Art. 6(1)(f)); consent where required for non-essential cookies (Art. 6(1)(a)) | Preferences, usage metadata, cookie and device identifiers |
| Security, abuse and fraud prevention, audit logging | Legitimate interest in protecting the Services, our users and our customers (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) | Log and technical data, authentication events, audit records |
| Marketing communications, campaigns and events | Consent (Art. 6(1)(a)); legitimate interest in business-to-business direct marketing to existing contacts (Art. 6(1)(f)) | Business contact data, employer and role, engagement metrics |
| Disclosure to vendors, affiliates and partners | Performance of a contract (Art. 6(1)(b)); legitimate interest in operating efficiently (Art. 6(1)(f)) | The categories necessary for the relevant service |
| Legal compliance, requests from authorities, legal claims | Legal obligation (Art. 6(1)(c)); legitimate interest in establishing, exercising or defending legal claims (Art. 6(1)(f)) | Any category relevant to the obligation or claim |
| Corporate reorganisation, merger or acquisition | Legitimate interest in conducting corporate transactions (Art. 6(1)(f)) | Account, commercial and contact data |
Where we rely on legitimate interests, we have carried out a balancing assessment weighing those interests against your rights and freedoms. You may request a summary of the relevant assessment by writing to admin@eldarion.ai.
Providing account and billing data is necessary to enter into and perform the contract; without it we cannot give you access to the Services. Providing marketing preferences is voluntary. Eldarion does not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing within the meaning of Article 22 GDPR. The Services generate analytical output that is intended to be reviewed by a qualified professional.
You may lodge a complaint with the supervisory authority of your habitual residence, place of work or the place of the alleged infringement — in Spain, the Agencia Española de Protección de Datos (www.aepd.es); in the United Kingdom, the Information Commissioner’s Office (ico.org.uk); in Switzerland, the Federal Data Protection and Information Commissioner (edoeb.admin.ch). We would appreciate the opportunity to address your concern first.
The Services are professional tools intended exclusively for business users and are not directed at, or intended for use by, individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have collected such data, we will delete it without undue delay. If you believe a minor has provided us with personal data, write to admin@eldarion.ai.
Subject to the conditions and exceptions of applicable law, you have the right to:
To exercise these rights, write to admin@eldarion.ai. We may need to verify your identity before acting, and we will respond within one month of receipt, extendable by two further months where the request is complex, in which case we will inform you of the extension and its reasons. Exercising your rights is free of charge unless the request is manifestly unfounded or excessive. You can unsubscribe from marketing communications at any time using the link in any such message.
If your request concerns Customer Content processed on behalf of a customer organisation, we will refer you to that organisation, or assist it in responding, as our data processing agreement requires.
We may update this Privacy Policy to reflect changes in our Services, our vendors, or the legal, regulatory and technical environment. The “Last updated” date at the top of this document indicates when the current version took effect, and previous versions are archived and available on request. Where a change is material we will provide advance notice by email or through the Services and, where the law requires it, we will seek your consent.
Eldarion · Privacy Policy v1.0 · 1 September 2026