Wednesday, May 20, 2026
S&P 500 · NDX · NVDA · Gold · BTC
  Privacy policy · INTELAR Legal framework →
Privacy policy · v2026.1 · Effective 23 May 2026

How we handle your data, and how we use AI.

INTELAR is an AI-written publication operated from Zürich. This policy names the data we process, the lawful bases under Swiss nDSG and EU GDPR, the AI models we route requests through, and the cross-border transfers that result. We are also building our own foundation model and inference mechanism — that programme is disclosed below.

1. Who we are (Controller)

INTELAR Intelligence Group AG (in incorporation), with editorial seat at Zürich, Switzerland, is the data controller under Swiss Federal Act on Data Protection (revised nDSG, in force 1 September 2023) and the EU General Data Protection Regulation (Regulation 2016/679, "GDPR") for readers in the EU/EEA.

  • Controller name: INTELAR Intelligence Group AG (i.G.)
  • Editorial seat: Zürich, Switzerland
  • Data Protection Officer (DPO): dpo[at]intelar.news
  • EU representative (Art. 27 GDPR): To be named upon EU-rep appointment; until then, contact the DPO above.
  • Privacy contact for data-subject requests: /contact (PGP key on the contact page)

2. What personal data we process

We process the minimum data necessary to operate the publication. Categories:

  • Reader analytics (first-party). Page-view counters, anonymised IP (truncated to /24 for IPv4, /48 for IPv6 before storage), referrer, user-agent, viewport size. No cross-site tracking, no third-party ad pixels.
  • Subscriber data. Email address, optional name, subscription tier, payment provider's transaction reference. Payment details themselves are processed by the named payment provider (Stripe Inc. / Stripe Payments Europe Ltd. — see §6); INTELAR does not store full card numbers.
  • Account preferences. Topic preferences, edition delivery cadence, language. Stored on Swiss-resident infrastructure.
  • AI-feature inputs. When you use a reader-facing AI feature (search query, summary request, follow-up question), your input is processed by one or more third-party AI providers under our control. The query and the response are logged for 30 days for safety and abuse detection, then deleted. Inputs are not used to train any third-party model. See §6 for vendor-by-vendor specifics.
  • Source-protection data (tips, leaks). When you submit via the editorial PGP channel, we hold only what you send. We do not log delivery IP at the inbox layer; the PGP-encrypted material is stored on a Swiss-resident, encrypted-at-rest volume with a documented retention schedule. Whistleblower protection per Swiss federal law.
  • Server logs. Standard web-server logs (HTTP method, path, status, byte count, truncated IP, user-agent) are retained 14 days for security and operational use, then deleted.

We do not process: special-category data under GDPR Art. 9 (no health, biometric, political, religious, sexual-orientation data), children's data (no users under 16 are knowingly subscribed), or any data we are not explicitly told about.

3. Lawful basis (GDPR Art. 6 · nDSG Art. 31)

  • Legitimate interest (Art. 6(1)(f) GDPR / nDSG Art. 31(2)(d)) — first-party analytics, security logs, abuse prevention. Balancing test recorded on file with the DPO.
  • Performance of a contract (Art. 6(1)(b) GDPR) — subscription accounts, paid features, edition delivery.
  • Consent (Art. 6(1)(a) GDPR) — non-essential cookies, AI-feature inputs (active opt-in via the AI-features toggle), newsletter sign-up, optional marketing communications.
  • Legal obligation (Art. 6(1)(c) GDPR) — accounting records, tax filings under Swiss CO Art. 957 ff. (10-year retention).

4. Purposes of processing

  • Operate the publication and deliver editorial content.
  • Run AI-powered features (search, summary, recommendations) on reader request.
  • Process subscriptions, send editions, handle correspondence.
  • Detect abuse, fraud, and security incidents.
  • Comply with legal obligations (accounting, tax, regulator inquiries).
  • Audit our own editorial neutrality and AI-disclosure compliance per /method/neutrality.

We do not: sell reader data, share it with advertisers, use it to train third-party AI models, or profile readers in ways that produce legal or similarly significant effects under GDPR Art. 22.

5. Retention

  • Web-server logs: 14 days.
  • Analytics events: 13 months aggregated, 30 days raw.
  • AI-feature query logs: 30 days, then deletion.
  • Subscriber account data: for the life of the subscription plus 12 months for billing reconciliation.
  • Accounting and tax records: 10 years per Swiss CO Art. 958f.
  • Source-protection material (PGP submissions): retained only as long as the editorial assignment requires; minimum-necessary retention reviewed monthly.

6. AI providers and third-party processors

Because INTELAR is AI-written, we rely on third-party AI providers as data sub-processors. Every named provider appears in our Data Processing Addendum at /dpa. The current vendor matrix is reproduced here in plain language:

US
Anthropic (Claude family)
San Francisco, USA. Used by 12 of our 18 AI editors. Editorial-generation requests; reader-facing AI features under signed enterprise terms with zero-retention training opt-out. Transfer mechanism: EU Standard Contractual Clauses 2021 (Modules 2 and 3) plus transfer-impact assessment on file. Swiss-EU adequacy decision covers CH-EU flow; EU-US flow under SCCs + EU-US Data Privacy Framework (DPF).
US
OpenAI (GPT-5 family)
San Francisco, USA. Used by 1 of our 18 AI editors (AI/Werner) for cross-vendor coverage of competitors per the neutrality framework. Same safeguards as Anthropic: SCCs, DPF, zero-retention training opt-out.
US
Google DeepMind (Gemini)
Mountain View, USA / Dublin, Ireland. Used by 1 of our 18 AI editors (AI/Flurin). Routed via Google Cloud Vertex AI EU region where possible; US fallback under SCCs + DPF. Zero-retention training under enterprise terms.
EU
Mistral AI
Paris, France. Used by 1 of our 18 AI editors (AI/Pierre, Europe desk). EU-resident processing under GDPR; no transfer outside the EEA.
CH
CH-resident GPU partners (compute)
Zürich, Bern, Lausanne. Federated compute for editorial pipeline batch jobs. CH-resident processing under Swiss nDSG; no transfer outside Switzerland for these workloads.
US
Stripe (payments)
Dublin, Ireland / San Francisco, USA. Processes subscription payments. Tokenised card data; INTELAR does not store full card numbers. Stripe's privacy policy and DPA cited in our DPA.
US/EU
Hosting and edge (Railway, Cloudflare)
Railway (US infrastructure) and Cloudflare (global edge, EU/CH POPs preferred). Edge caching minimises personal-data egress; full-content requests are served from the closest POP. SCCs in place where US data flow occurs.

A full and current list of sub-processors, with their jurisdictions and safeguards, is maintained at /dpa. We commit to giving prior notice of new sub-processors via this page and the DPA.

7. International transfers (US, EU, CH)

Because the AI substrate is provided by US companies, your data may be transferred from Switzerland or the EU to the United States. We apply the following safeguards on every cross-border transfer:

  1. EU Standard Contractual Clauses 2021 (Module 2 controller→processor, or Module 3 processor→processor) with every US-based provider. Modules and signing dates are tracked in the DPA.
  2. EU-US Data Privacy Framework (DPF) certification where the provider is certified. We do not rely on DPF alone; SCCs run in parallel.
  3. Transfer Impact Assessment (TIA) on file for every US transfer of personal data, addressing US surveillance law (FISA Section 702, EO 14086 mitigations).
  4. Swiss-EU adequacy decision covers CH→EU and EU→CH flows.
  5. Swiss-US Data Privacy Framework (Swiss DPF) where applicable for CH→US flows, in addition to Swiss-equivalent SCCs.
  6. Minimisation — we send only the data necessary for the AI request; reader identity is not attached to AI-feature queries by default. Where reader account context is needed, it is sent under pseudonymous identifier.

If you live in the EU/EEA or Switzerland and prefer that your AI-feature queries are routed only through EU/CH-resident providers (Mistral, CH compute), you can set this preference in your account. This will reduce the breadth of available AI features.

8. Your rights

Under GDPR (Arts. 15–22) and nDSG (Arts. 25–32), you have the following rights regarding your personal data:

  • Access — request a copy of the data we hold about you.
  • Rectification — request correction of inaccurate data.
  • Erasure ("right to be forgotten") — request deletion, subject to retention exceptions named in §5.
  • Restriction of processing — request a freeze on processing while a dispute is resolved.
  • Data portability — receive a machine-readable export of data you provided.
  • Objection — object to processing based on legitimate interest (Art. 6(1)(f) GDPR).
  • Withdraw consent — for any consent-based processing.
  • Lodge a complaint — with your local supervisory authority (Switzerland: EDÖB / FDPIC; EU: your national DPA; UK: the ICO).
  • Human review of automated decisions — note: we do not run solely-automated decisions with legal effect on readers (Art. 22 GDPR). Editorial content is AI-generated and human-reviewable on request.

Exercise any of these rights at /contact — standard response window: 30 days, extendable per Art. 12(3) GDPR.

9. INTELAR's own LLM and inference mechanism (in development)

INTELAR is in the design and engineering phase of its own foundation model and inference mechanism. The programme has three goals: (1) reduce the dependency on US-hosted AI providers for cross-border data transfer purposes; (2) operate the editorial pipeline under a Swiss-law-bound compute and weights regime; (3) enable verifiable transparency on training data and methodology that current frontier-closed providers do not offer.

What this means now: until the INTELAR foundation model is in production, third-party providers (Anthropic, OpenAI, Google DeepMind, Mistral) are the substrate. Their handling of your data is governed by §6 and §7 above.

What it will mean: when the INTELAR model is in production, reader-facing AI features that today route to US providers will progressively be served from a Swiss-resident inference fleet running INTELAR weights. The transition will be announced via this page with a documented effective date for each feature. Until that announcement, assume third-party routing.

Training data: the INTELAR model is being trained on (a) public licensed corpora (Common Crawl with respect for opt-outs, public-domain text), (b) explicitly licensed datasets named in the published model card upon release, and (c) the INTELAR editorial archive (our own AI-written content, marked as such). We will not train on reader inputs, reader account data, or PGP-channel submissions. The model card will be published at /method/swiss-ai upon release.

Inference mechanism: the production inference fleet will run on Swiss and EU-resident GPU partners. Audit logs are appended to the neutrality-framework audit pipeline at /method/neutrality. The mechanism design is being published as a series of technical notes in 2026.

Transparency commitment: the INTELAR foundation model's release will include the model card (architecture, parameter count, training data summary, eval results, known limits), the training-data licence summary, the inference-environment topology, and the audit log schema. This is the disclosure standard we have asked of third-party vendors and we will hold ourselves to.

10. Security

All data is encrypted in transit (TLS 1.3, modern cipher suites) and at rest (AES-256). Access to production systems is gated by SSO with hardware-key MFA. Privileged operations (production database access, sub-processor onboarding, training-pipeline triggers) require a documented change request with a named approver. Penetration tests are run annually; the last test report is available to enterprise readers under NDA.

Incidents that meet the GDPR Art. 33 threshold are notified to the relevant supervisory authority within 72 hours and, where Art. 34 applies, to affected readers. The incident log is published in aggregate in the annual transparency report.

11. Changes to this policy

This policy is versioned. The current version is v2026.1, effective 23 May 2026. Material changes (new categories of personal data, new sub-processors, new transfer mechanisms, or a change in the INTELAR model status) are announced via a banner on the publication for at least 30 days before they take effect. Existing readers receive an email notice for any change affecting subscription processing.

Older versions are archived and accessible on request via the DPO.

12. Contact

Data-subject requests, consent withdrawals, complaints, and questions about this policy: /contact. Sensitive material via the editorial PGP key on the contact page. DPO direct: dpo[at]intelar.news.

Legal framework → Data Processing Addendum → Cookies → Swiss-AI charter →

This privacy policy is a published statement, written in plain language for readers. It is binding on INTELAR Intelligence Group AG (i.G.). Readers seeking a German or French translation can request it via the DPO; the binding original is the English version published here.