1. Who we are and what this policy covers
TheGoldMagazine is an independent editorial publication reporting on gold — its markets, its mines, its metallurgy and the people who work it. This Privacy Policy explains how we handle personal data collected through this website, including every article page, the archive, and any correspondence you send to the editorial desk.
This policy applies only to this website. Where an article links out to a mining company filing, a central bank statistical release, an exchange rulebook or a third-party research paper, that destination is governed by its own privacy practices, which we neither control nor endorse. We recommend reading the privacy notice of any site you visit through one of our links.
We are the controller of the personal data described here. That means we decide why and how it is processed. Where we use service providers — for hosting, for content delivery, or for aggregate audience measurement — those providers act as processors on our written instructions and may not use reader data for their own purposes.
2. The data we actually collect
We have deliberately built this publication to run on as little personal data as an honest editorial operation can. There is no reader account system, no paywall registration, no advertising identity graph, and no sale of reader data of any kind. In practice, the data that reaches us falls into three narrow categories.
2.1 Technical data created by the act of loading a page
When your browser requests a page, our hosting infrastructure necessarily receives your IP address, the requested URL, the referring URL if your browser sends one, your user-agent string, and the timestamp of the request. This is the irreducible technical exhaust of the web: without it, no server could return a page to the correct device. We use these server logs solely to serve content, to diagnose outages and errors, and to detect abusive traffic such as scraping floods or denial-of-service attempts.
2.2 Aggregate audience measurement
We measure how many people read each article, which sections hold attention, and roughly where in the world our readership sits, because that information shapes what we commission next. Where we use measurement tooling, we configure it for aggregate reporting: no cross-site tracking, no advertising profiles, no sale or sharing of measurement data with data brokers. Where the tooling supports it, IP addresses are truncated or hashed before storage.
2.3 Information you volunteer
If you write to the editorial desk — to file a correction, to offer a document, to pitch a story or to make a complaint — we receive whatever you choose to put in that message: your name, your email address, your employer if you mention it, and the substance of your correspondence. We keep editorial correspondence because journalism requires an audit trail: a correction request has to be traceable to its origin, and a source's material has to be defensible if the reporting is later challenged.
3. Why we process it, and on what legal basis
Under the UK and EU General Data Protection Regulation, every act of processing needs a lawful basis. Ours are as follows.
- Legitimate interests — serving pages, keeping the site available, preventing abuse, measuring readership in aggregate, and maintaining an editorial record of correspondence. We have assessed that these interests do not override your rights, because the data involved is minimal, short-lived and never used to build individual profiles.
- Journalism — where processing is necessary for the purposes of journalism, including holding documents, notes and correspondence relating to a story. Data protection law provides specific exemptions for journalistic processing, and we rely on them where publication in the public interest requires it.
- Consent — for any non-essential cookie or measurement technology that requires it in your jurisdiction, and for any editorial newsletter you actively subscribe to. Consent can be withdrawn at any time without affecting the lawfulness of prior processing.
- Legal obligation — where we must retain or disclose data to comply with a valid court order, statutory demand or regulatory requirement.
6. International transfers
Our infrastructure providers operate globally, so data may be processed outside your country of residence, including in jurisdictions whose data protection regimes differ from your own. Where personal data leaves the UK or European Economic Area, we rely on an adequacy decision where one exists, or on Standard Contractual Clauses supplemented by technical measures such as encryption in transit and at rest.
7. How long we keep things
- Server logs: retained for a short operational window, ordinarily no longer than ninety days, then deleted or irreversibly aggregated.
- Aggregate readership statistics: retained indefinitely in a form that does not identify individuals.
- Editorial correspondence: retained for as long as the relevant story remains published and for a reasonable period afterwards, reflecting limitation periods for defamation and related claims.
- Newsletter subscriptions, where offered: retained until you unsubscribe, plus a short suppression record to ensure we do not re-add you by mistake.
8. Security
Traffic to and from this site is encrypted in transit. Access to any system holding correspondence is limited to editorial staff who need it, protected by strong authentication. Source material of a sensitive nature is handled outside ordinary systems, on need-to-know terms, and where appropriate is not stored electronically at all.
No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within seventy-two hours of becoming aware of it, and will notify affected individuals directly where the risk is high.
9. Your rights
Depending on where you live, you may have the right to request access to the personal data we hold about you, to have inaccurate data corrected, to have data erased, to restrict or object to processing, and to receive your data in a portable format. Where processing rests on consent, you may withdraw it at any time.
These rights are not absolute. Data protection law contains a journalism exemption, and we will rely on it where complying with a request would compromise a story in the public interest, expose a confidential source, or defeat the purpose of legitimate reporting. Where we refuse a request in whole or in part, we will tell you why, and you retain the right to complain to your national supervisory authority.
To exercise a right, write to the editorial desk with enough detail for us to locate the relevant records. We respond within one month, extendable by two further months for complex requests, and we will tell you if an extension applies.
10. Children
This publication is written for a general adult readership interested in commodities, monetary history and industry. It is not directed at children, and we do not knowingly collect personal data from anyone under sixteen. If you believe a child has sent us personal data, contact the editorial desk and we will delete it.
11. Changes to this policy
We update this policy when our practices change or when the law does. The revision date at the head of this page always reflects the current version. Material changes — anything that widens the categories of data collected or the purposes of processing — will be flagged prominently on the site rather than buried in a silent edit.
12. Automated decision-making and profiling
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you. There is no scoring of readers, no behavioural segmentation used to vary what an individual sees, and no personalised pricing of any kind, because there is nothing on this site to price.
Where article recommendations appear at the foot of a page, they are derived from the section, desk and publication date of the piece you are reading, not from a profile of you. Two readers arriving at the same article from different countries, on different devices, with different histories, see the same suggestions.
14. Sources, whistleblowers and confidential correspondence
Correspondence that identifies or could identify a confidential source receives handling beyond what data-protection law requires. Where a source asks for confidentiality and we accept, we do not hold identifying material in ordinary systems, we do not name the source in internal correspondence, and we do not disclose the identity in response to a subject access request made by a third party who believes they were written about.
This is the one area where our transparency obligations to a data subject and our obligations to a source can conflict. Where they do, we rely on the journalistic exemptions available under applicable data-protection law and we say so plainly rather than pretending no records exist.
If you intend to send us sensitive material, do not use a work device or a work email account. Contact the editorial desk first with a low-risk message asking how to proceed, and we will describe a safer route before you send anything of substance.
15. Data breaches
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as required by law. Where the breach is likely to result in a high risk to affected individuals, we will notify those individuals directly and without undue delay.
A breach notice from us will state what happened, what categories of data were involved, what we have done to contain it, what we recommend you do, and who to contact for further information. It will not minimise the incident or bury it in a policy update, and we will publish a summary on this site once containment is complete.
Contact the desk
Questions about this document, a correction request, a licensing enquiry or a data rights request all reach the same place: the editorial desk at TheGoldMagazine. Quote the page URL and, where relevant, the article and passage concerned.
