1. Data controller
The data controller for this site is the operator of The Insiders Post. You can reach the data protection contact at [email protected].
What we collect, why we collect it, how long we keep it, and how to exercise your rights. Last updated 2026-08-28.
The Insiders Post is a public information service. Almost everything on the site is derived from SEC Form 4 filings, which are public records filed with the U.S. Securities and Exchange Commission. We do not require an account, we do not ask for your name or email to browse, and we do not run advertising. The only personal data we process is what is strictly necessary to operate the service: server logs, the optional analytics cookie described in our Cookie Policy, and any feedback you choose to send us.
The data controller for this site is the operator of The Insiders Post. You can reach the data protection contact at [email protected].
__cf_bm): strictly necessary, expires after 30 minutes of inactivity. See Cookie Policy §4.anonymize_ip: true, so the last octet of your IP address is removed before storage. See Cookie Policy §2.| Purpose | Lawful basis |
|---|---|
| Serving the website and routing requests | Legitimate interest (Art. 6(1)(f)) |
| Cloudflare bot protection | Legitimate interest (Art. 6(1)(f)) |
| Google Analytics 4 — only after consent | Consent (Art. 6(1)(a)) |
| Replying to your suggestion / email | Pre-contractual / contractual (Art. 6(1)(b)) |
| Complying with a legal request | Legal obligation (Art. 6(1)(c)) |
We do not sell personal data, and we do not share it with anyone else except where required by law (e.g. a valid court order).
| Data | Retention |
|---|---|
| Server logs | 30 days, then deleted |
| Suggestion form submissions | 24 months, then deleted |
| Email correspondence | 24 months from last contact, then deleted |
| Google Analytics 4 (when consented) | 14 months (Google's default), then auto-deleted |
CookieFirst consent decision (cookiefirst-consent cookie) | Approximately 12 months, then re-prompted |
You have the right to:
To exercise any of these rights, write to [email protected]. We respond within 30 days, free of charge. If your enquiry is complex we may extend that window by up to two further months and will tell you why.
Under GDPR Art. 27, non-EU controllers must appoint an EU representative. Our EU representative can be reached at [email protected].
We protect data in transit with HTTPS (HSTS enabled, TLS 1.2+). Application secrets are bound at runtime via the DigitalOcean App Platform, never committed. Access to the production database is restricted to operators with two-factor authentication. Despite our efforts, no system is 100% secure; if you ever discover a vulnerability, please email [email protected] so we can act fast.
We will update this page when our practices change. Material changes will also be flagged in the consent banner the next time you visit. The "Last updated" date at the top reflects the most recent revision.