Skip to content

Privacy Policy

What we collect when you read TheGoldMagazine, why we collect it, how long we keep it, and the rights you can exercise over it.

Last updated 6 August 2026

1. Who we are and what this policy covers

TheGoldMagazine is an independent editorial publication reporting on gold — its markets, its mines, its metallurgy and the people who work it. This Privacy Policy explains how we handle personal data collected through this website, including every article page, the archive, and any correspondence you send to the editorial desk.

This policy applies only to this website. Where an article links out to a mining company filing, a central bank statistical release, an exchange rulebook or a third-party research paper, that destination is governed by its own privacy practices, which we neither control nor endorse. We recommend reading the privacy notice of any site you visit through one of our links.

We are the controller of the personal data described here. That means we decide why and how it is processed. Where we use service providers — for hosting, for content delivery, or for aggregate audience measurement — those providers act as processors on our written instructions and may not use reader data for their own purposes.

2. The data we actually collect

We have deliberately built this publication to run on as little personal data as an honest editorial operation can. There is no reader account system, no paywall registration, no advertising identity graph, and no sale of reader data of any kind. In practice, the data that reaches us falls into three narrow categories.

2.1 Technical data created by the act of loading a page

When your browser requests a page, our hosting infrastructure necessarily receives your IP address, the requested URL, the referring URL if your browser sends one, your user-agent string, and the timestamp of the request. This is the irreducible technical exhaust of the web: without it, no server could return a page to the correct device. We use these server logs solely to serve content, to diagnose outages and errors, and to detect abusive traffic such as scraping floods or denial-of-service attempts.

2.2 Aggregate audience measurement

We measure how many people read each article, which sections hold attention, and roughly where in the world our readership sits, because that information shapes what we commission next. Where we use measurement tooling, we configure it for aggregate reporting: no cross-site tracking, no advertising profiles, no sale or sharing of measurement data with data brokers. Where the tooling supports it, IP addresses are truncated or hashed before storage.

2.3 Information you volunteer

If you write to the editorial desk — to file a correction, to offer a document, to pitch a story or to make a complaint — we receive whatever you choose to put in that message: your name, your email address, your employer if you mention it, and the substance of your correspondence. We keep editorial correspondence because journalism requires an audit trail: a correction request has to be traceable to its origin, and a source's material has to be defensible if the reporting is later challenged.

4. Cookies and similar technologies

Strictly necessary cookies keep the site functioning: they hold session state, remember your cookie preferences, and support security measures. These cannot be switched off without breaking the site, and in most jurisdictions they do not require consent.

Any analytics or preference storage beyond that is optional. Where your jurisdiction requires prior consent, we ask before setting it, and a refusal costs you nothing: every article on this site is readable in full with all optional storage declined. You can also clear or block storage entirely through your browser settings, though blocking strictly necessary cookies may cause parts of the site to behave unpredictably.

We do not embed third-party advertising pixels, social network tracking widgets, or cross-site retargeting tags on article pages.

5. Who we share data with

We do not sell personal data. We do not rent, trade or license reader lists. The categories of recipient are limited to the following.

  • Hosting and content delivery providers, who process request data solely to deliver pages and absorb malicious traffic.
  • Aggregate measurement providers, under contractual terms restricting use to our own reporting.
  • Professional advisers — lawyers, auditors, insurers — where a specific matter requires it and confidentiality applies.
  • Law enforcement or courts, but only in response to a legally valid, properly scoped demand, and only after we have considered whether it can lawfully be resisted or narrowed. We will not volunteer source-identifying material.

6. International transfers

Our infrastructure providers operate globally, so data may be processed outside your country of residence, including in jurisdictions whose data protection regimes differ from your own. Where personal data leaves the UK or European Economic Area, we rely on an adequacy decision where one exists, or on Standard Contractual Clauses supplemented by technical measures such as encryption in transit and at rest.

7. How long we keep things

  • Server logs: retained for a short operational window, ordinarily no longer than ninety days, then deleted or irreversibly aggregated.
  • Aggregate readership statistics: retained indefinitely in a form that does not identify individuals.
  • Editorial correspondence: retained for as long as the relevant story remains published and for a reasonable period afterwards, reflecting limitation periods for defamation and related claims.
  • Newsletter subscriptions, where offered: retained until you unsubscribe, plus a short suppression record to ensure we do not re-add you by mistake.

8. Security

Traffic to and from this site is encrypted in transit. Access to any system holding correspondence is limited to editorial staff who need it, protected by strong authentication. Source material of a sensitive nature is handled outside ordinary systems, on need-to-know terms, and where appropriate is not stored electronically at all.

No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within seventy-two hours of becoming aware of it, and will notify affected individuals directly where the risk is high.

9. Your rights

Depending on where you live, you may have the right to request access to the personal data we hold about you, to have inaccurate data corrected, to have data erased, to restrict or object to processing, and to receive your data in a portable format. Where processing rests on consent, you may withdraw it at any time.

These rights are not absolute. Data protection law contains a journalism exemption, and we will rely on it where complying with a request would compromise a story in the public interest, expose a confidential source, or defeat the purpose of legitimate reporting. Where we refuse a request in whole or in part, we will tell you why, and you retain the right to complain to your national supervisory authority.

To exercise a right, write to the editorial desk with enough detail for us to locate the relevant records. We respond within one month, extendable by two further months for complex requests, and we will tell you if an extension applies.

10. Children

This publication is written for a general adult readership interested in commodities, monetary history and industry. It is not directed at children, and we do not knowingly collect personal data from anyone under sixteen. If you believe a child has sent us personal data, contact the editorial desk and we will delete it.

11. Changes to this policy

We update this policy when our practices change or when the law does. The revision date at the head of this page always reflects the current version. Material changes — anything that widens the categories of data collected or the purposes of processing — will be flagged prominently on the site rather than buried in a silent edit.

12. Automated decision-making and profiling

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you. There is no scoring of readers, no behavioural segmentation used to vary what an individual sees, and no personalised pricing of any kind, because there is nothing on this site to price.

Where article recommendations appear at the foot of a page, they are derived from the section, desk and publication date of the piece you are reading, not from a profile of you. Two readers arriving at the same article from different countries, on different devices, with different histories, see the same suggestions.

13. Newsletter and correspondence lists

If we operate an editorial newsletter, subscription is by explicit opt-in and the only mandatory field is an email address. We use it to send the newsletter and nothing else: no list rental, no sharing with advertisers, no enrichment against third-party data sets, and no transfer of the list in the event of a change of ownership without notifying subscribers first and offering deletion.

Every message contains a working one-click unsubscribe. Unsubscribing removes the address from the sending list within seven days and leaves behind only a suppression record — a hash of the address — retained so that the same address is not re-added by a later import.

14. Sources, whistleblowers and confidential correspondence

Correspondence that identifies or could identify a confidential source receives handling beyond what data-protection law requires. Where a source asks for confidentiality and we accept, we do not hold identifying material in ordinary systems, we do not name the source in internal correspondence, and we do not disclose the identity in response to a subject access request made by a third party who believes they were written about.

This is the one area where our transparency obligations to a data subject and our obligations to a source can conflict. Where they do, we rely on the journalistic exemptions available under applicable data-protection law and we say so plainly rather than pretending no records exist.

If you intend to send us sensitive material, do not use a work device or a work email account. Contact the editorial desk first with a low-risk message asking how to proceed, and we will describe a safer route before you send anything of substance.

15. Data breaches

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as required by law. Where the breach is likely to result in a high risk to affected individuals, we will notify those individuals directly and without undue delay.

A breach notice from us will state what happened, what categories of data were involved, what we have done to contain it, what we recommend you do, and who to contact for further information. It will not minimise the incident or bury it in a policy update, and we will publish a summary on this site once containment is complete.

16. Supervisory authorities and how to complain

If you believe we have handled your personal data unlawfully, we would rather hear from you first, because most complaints are resolved faster in an email than in a regulatory file. Write to the editorial desk with the words 'data complaint' in the subject line and a description of what you believe went wrong.

You do not have to come to us first. You have the right to lodge a complaint directly with the data-protection supervisory authority in the country where you live, where you work, or where you believe the infringement occurred. Exercising that right costs nothing and does not affect any other remedy available to you.

Contact the desk

Questions about this document, a correction request, a licensing enquiry or a data rights request all reach the same place: the editorial desk at TheGoldMagazine. Quote the page URL and, where relevant, the article and passage concerned.