Privacy Policy
Effective Date: April 1, 2026 · Last Updated: April 1, 2026
Gideon Strategic Partners ("we", "us", "our") respects your privacy. This Privacy Policy explains how we collect, use, share, and protect personal information you provide when you fill out forms on our website www.gideonsp.com or when you contact us. By submitting any form or contacting us, you agree to the practices described here.
Data We Collect
Personal data you provide directly:
- Name, email address, phone number, mailing address, company/organization, job title, country, and the content of your message or inquiry.
- Financial information or disclosures you provide for onboarding or advisory purposes (e.g., investment objectives, risk tolerance, preferred account types), identity verification information (e.g., government-issued IDs) as required by regulatory procedures.
- Communications preferences and consent preferences (e.g., marketing opt-in).
Data from your interaction with the site:
- IP address, browser and device information, pages visited, time and date of visits, referral source.
- Cookies and similar tracking technologies (see Section 9).
Data from third parties (where applicable):
- If you link or sign up through a third-party service, we may receive basic contact information from that service, consistent with your settings on that service.
- Data from trusted counterparties or custodians as needed for our services and regulatory compliance.
How We Collect Data
- Through forms you submit on our website (e.g., contact forms, request-for-information, appointment scheduling, onboarding forms).
- Automatically via cookies, analytics, and server logs as you browse.
- Through email or other communications you initiate with us.
- From third-party services you authorize (e.g., CRM, onboarding platforms), in accordance with your permissions.
How We Use Your Data
- To respond to inquiries, schedule meetings, onboard clients, and provide wealth management and financial advisory services.
- To administer, improve, and optimize our website and services.
- To verify your identity and comply with regulatory requirements (e.g., Know Your Customer, Anti-Money Laundering).
- To communicate about your inquiry, our services, and relevant updates.
- To analyze usage, trends, and performance to improve client experience and our marketing efforts (only if you have consent for marketing).
- To meet legal obligations and protect our rights and safety.
Legal Bases for Processing (GDPR Context)
- Consent: for marketing communications and any processing requiring your opt-in.
- Performance of a contract or taking steps at your request prior to entering into a contract: responding to inquiries, initiating service, onboarding.
- Legitimate interests: for site administration, service improvement, and fraud prevention.
- Compliance with legal obligations: regulatory reporting, AML/KYC, tax reporting, and other applicable laws.
Sharing Your Data
- Service providers and partners who process data on our behalf (e.g., CRM, email communications, data hosting, analytics) under strict contractual safeguards.
- Within Gideon Strategic Partners and affiliated entities as necessary for our services and operations.
- With regulators, auditors, or law enforcement as required by law or to protect our rights and clients.
- With your consent or at your direction (e.g., if you authorize us to share information with a partner).
International Transfers
If we transfer your data outside your home country, we rely on appropriate safeguards (e.g., contracts and applicable data protection laws) to protect your information.
Data Retention
- We retain personal data for as long as necessary to provide services, fulfill our contractual and regulatory obligations, and resolve disputes.
- Financial records and onboarding information may be retained for the period required by law or regulation (often several years, depending on jurisdiction and purpose).
- Marketing data is kept as long as you have not opted out, or as permitted by applicable laws.
- If you wish to request deletion or have retention preferences, contact us using the details in Section 18.
Your Rights
- Access and obtain a copy of your data.
- Rectification of inaccurate or incomplete data.
- Deletion of data in certain circumstances (subject to regulatory and contractual obligations).
- Restriction of processing in certain situations.
- Objection to processing based on legitimate interests or for direct marketing.
- Portability of your data in a structured, commonly used format.
- Withdraw consent at any time (for processing based on consent).
- California residents: rights under the California Consumer Privacy Act/CPRA, including the right to opt out of certain data sharing and to request deletion where permissible. See the Do Not Sell/Share section for more details.
Cookies and Tracking Technologies
- We use cookies and similar technologies to analyze site usage, remember your preferences, and tailor your experience.
- You can manage cookie preferences in your browser or through provided opt-out mechanisms.
- Some cookies are essential for site functionality and cannot be disabled without affecting our services.
Do Not Track
We respond to Do Not Track signals where required by law. Your continued use of the site implies consent to our data practices described in this policy.
Security and Safeguards
We maintain a comprehensive information-security program designed to protect client information, including:
- Encryption of data in transit and at rest where feasible.
- Access controls, authentication, and role-based permissions.
- Regular security assessments and employee training.
- An incident response plan to detect, respond to, and remediate security incidents.
- For financial services, we apply the GLBA Safeguards Rule and related industry practices to protect nonpublic personal information (NPI) we collect and maintain about clients and prospective clients.
AML/KYC and Financial Services-Specific Practices
- We may collect and verify identity, assess risk, and monitor transactions as required by applicable anti-money-laundering, know-your-customer, and other financial-services-related regulations.
- Information collected for these purposes is used to establish and maintain your client relationship and fulfill regulatory obligations.
Children's Privacy
Our services are not directed to children under 16 (or the applicable age in your jurisdiction). We do not knowingly collect personal data from children.
Do Not Sell/Share (California)
- California residents have rights under CPRA, including the right to opt out of certain data sharing and the right to request deletion. If you are a California resident and would like to exercise these rights, please contact us at the details in Section 18.
- We do not sell data as a business model, and if applicable, we provide a mechanism to opt out of data sharing with third parties.
Your Choices and Opt-Out
- Marketing communications: unsubscribe from emails via the link in the message or contact us to stop marketing communications.
- You can update your preferences by contacting us or via any account settings we provide.
Data Breach Notifications
In the event of a data breach affecting your personal information, we will notify you and relevant regulators as required by law, and take steps to mitigate the impact and prevent recurrence.
Changes to This Policy
We may update this policy from time to time. We will post the latest version and indicate the date of the latest revision. Your continued use of our site and services after changes constitutes your acknowledgment of the updated policy.
How to Contact Us
Data Controller: Gideon Strategic Partners
If you have privacy concerns, you may also contact our privacy officers: Edwin Kispert at kispert@gideonsp.com or Bre Rekenthaler at rekenthaler@gideonsp.com.