At LongView Risk Management, accessible from https://lvrm.ag, the privacy and security of our visitors is a top priority. This Privacy Policy describes what personal data we collect, why we collect it, how we use and protect it, and what rights and choices you have.
This policy applies to information collected through our website only. It does not cover data collected offline or via third-party services that link to or from our site.
By accessing or using LongView Risk Management, you acknowledge that you have read and agree to this Privacy Policy. Questions or requests may be sent to info@longview.ag.
1. Information You Provide Directly
2. Automatically Collected Data
We process personal data for the following purposes:
| Purpose | Examples | Legal Basis (GDPR) |
|---|---|---|
| Service Delivery | Operating the website; responding to support requests | Contract / Legitimate Interests |
| Analytics & Improvement | Understanding usage patterns; improving features | Legitimate Interests |
| Email Marketing | Newsletters, updates, and promotional content | Consent |
| Transaction Processing | Processing orders, payments, and refunds | Contract |
| Financial Services | Investment features, portfolio management, financial reporting | Contract / Legal Obligation |
| Security & Fraud Prevention | Detecting malicious activity; protecting user accounts | Legitimate Interests |
| Legal Compliance | Meeting tax, regulatory, and court-ordered obligations | Legal Obligation |
LongView Risk Management uses cookies, web beacons, and similar technologies. Cookies are small text files placed on your browser to help us deliver and improve our services. We use the following categories:
| Category | Purpose | Examples | Duration |
|---|---|---|---|
| Strictly Necessary | Core functionality, security, session management. Cannot be disabled. | Session cookies, CSRF tokens, auth tokens | Session |
| Analytics / Performance | Anonymised visitor behaviour data; site performance improvement. | Google Analytics 4 (_ga, _gid, _gat) | Up to 2 years |
| Functional / Preference | Remembering your settings: language, dark mode, layout. | Theme preference, locale cookies | Up to 1 year |
| Embedded Content | Set by third-party content embedded in our pages. | YouTube, Google Maps, social media widgets | Varies by provider |
Managing Cookies: You can control or delete cookies through your browser settings. Opt-out tools: DAA Opt-Out, Your Online Choices (EU), Google Analytics Opt-Out. Disabling strictly necessary cookies may impair website functionality.
Cookie Consent: Where required by law (e.g. GDPR, ePrivacy Directive), you will be presented with a cookie consent banner on your first visit. Your preference is stored and honoured on subsequent visits.
We use Google Analytics 4 (GA4) to measure traffic and usage patterns. GA4 uses first-party cookies and does not use third-party cookies for cross-site tracking. Our privacy configuration includes:
You may opt out of Google Analytics tracking at any time via the Google Analytics Opt-Out Browser Add-on.
Payments are processed by PCI-DSS Level 1 compliant third-party processors. We do not store, transmit, or access full payment card numbers. Our payment infrastructure includes:
Transaction records (excluding card details) are retained for up to 7 years for accounting, tax, and legal compliance.
With your explicit consent, we may send newsletters, product updates, or promotional emails. Every commercial email includes a working one-click unsubscribe link in compliance with the CAN-SPAM Act and, where applicable, CASL. You may also unsubscribe by emailing info@longview.ag. Requests are processed within 10 business days. We may retain your address on a suppression list to honour your opt-out preference.
Financial information you provide is treated as sensitive personal data. It is used solely for the financial service or feature you are accessing and is not shared with third parties except as necessary to deliver that service, comply with legal obligations, or as you have explicitly consented. We apply encryption, access controls, and audit logging to all financial data.
Our pages may include embedded content from YouTube, Twitter/X, Spotify, Google Maps, or social media platforms. Embedded content behaves as if you visited the originating website directly and may collect data, set cookies, and track your interaction independently. We encourage you to review each provider’s privacy policy before interacting with embedded content.
We work with trusted third-party service providers who may access your personal data only to the extent necessary to perform services on our behalf. All processors are bound by Data Processing Agreements (DPAs). Categories include:
We do not sell your personal information. Data is shared only in these limited circumstances:
We implement appropriate technical and organisational measures to protect your personal data:
In the event of a personal data breach likely to result in risk to your rights, we will notify affected individuals and relevant supervisory authorities within the legally mandated timeframe (e.g. 72 hours under GDPR).
We retain personal data only as long as necessary to fulfil stated purposes or as required by law:
| Data Type | Retention Period | Reason |
|---|---|---|
| Server access logs | 90 days | Security monitoring and abuse prevention |
| Analytics data | Up to 14 months | Trend analysis (auto-deleted by GA4) |
| Newsletter subscriptions | Until unsubscribed + 30 days | Suppression list maintenance |
| Account data | Account lifetime + 12 months post-deletion | Dispute resolution and backups |
| Transaction records | 7 years | Tax and legal compliance |
| Financial records | 7 years | Tax, audit, and regulatory compliance |
| Contact form submissions | 3 years | Correspondence records and dispute resolution |
Depending on your location, you may have rights to access, correct, delete, restrict, or transfer your personal data. You may exercise these rights by contacting us at info@longview.ag. We will respond within the timeframe required by applicable law. You will never be penalised or discriminated against for exercising your privacy rights.
If you are in the EU or EEA, the General Data Protection Regulation (EU) 2016/679 grants you these rights:
Legal Bases for Processing: Art. 6(1)(a) Consent; Art. 6(1)(b) Contract; Art. 6(1)(c) Legal obligation; Art. 6(1)(f) Legitimate interests. For special category data, we rely on Art. 9(2)(a) explicit consent or other applicable bases.
International Transfers: Transfers outside the EEA are protected by EU Standard Contractual Clauses (SCCs, Commission Decision 2021/914), adequacy decisions, or other lawful Chapter V GDPR mechanisms.
Data Protection Officer: Where legally required, a DPO has been appointed. Contact: info@longview.ag.
We will respond to GDPR requests within 30 days (extendable by 2 months for complex cases). You may also lodge a complaint with your EU Member State’s supervisory authority (DPA).
The California Consumer Privacy Act (CCPA), as amended by the CPRA (effective January 1, 2023), grants California residents:
Personal information collected in the past 12 months: Identifiers (name, email, IP address); Internet or network activity (browsing history, site interactions); Commercial information (if purchases made); Geolocation data (if location features used); Inferences drawn to build user profiles.
Submit CCPA requests to info@longview.ag. We verify identity and respond within 45 days (extendable by 45 days). Authorised agents may submit requests on your behalf with proper documentation.
Other US State Privacy Rights: Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), Oregon (OCPA), and other states with similar privacy laws may exercise equivalent rights by contacting info@longview.ag.
LongView Risk Management is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13 (or under 16 in jurisdictions where a higher threshold applies, such as certain EU member states under GDPR Art. 8).
If we discover we have inadvertently collected data from a child under the applicable age threshold without verified parental consent, we will delete it immediately. Parents or guardians who believe their child has submitted data on LongView Risk Management should contact us at info@longview.ag. We will investigate and take corrective action within 72 hours of notification.
Any payment card data processed in connection with LongView Risk Management is handled in compliance with the Payment Card Industry Data Security Standard (PCI-DSS). Our compliance measures include: use of a PCI-DSS Level 1 certified payment processor; no storage, processing, or transmission of raw cardholder data on our own servers; HTTPS/TLS for all payment-related pages; and completion of annual PCI-DSS Self-Assessment Questionnaires (SAQ).
LongView Risk Management may contain links to third-party websites. Once you leave our site, this Privacy Policy no longer applies. We have no control over and accept no responsibility for external sites’ content, privacy policies, or practices. We recommend reviewing the privacy policy of any third-party site you visit.
Some browsers transmit “Do Not Track” signals to websites. There is currently no universally accepted standard for how websites must respond to DNT signals. At this time, LongView Risk Management does not alter its data collection practices in response to DNT browser signals. We will review this position as industry standards evolve.
We may update this Privacy Policy periodically. When material changes are made, we will update the “Last Updated” date at the top and post a prominent notice on our website, and where feasible notify subscribers via email. Your continued use of LongView Risk Management after any modification constitutes acceptance of the revised policy. We encourage you to review this page periodically.
For questions, data subject requests, or privacy complaints, please contact us:
We aim to respond to all enquiries within 5 business days, and within applicable legal deadlines for formal data subject requests.