You agree to the privacy policy below, and the Privacy Policy for Substack, the technology provider.
Privacy Policy
Edelbridge Alpha (the “Publication”) Data controller: Edelbridge Alpha GmbH, Switzerland (the “Publisher”, “we”, “us”, “our”) Contact: alpha@edelbridge.capital Last updated: 12 July 2026
This Privacy Policy explains how we collect, use, and protect personal data when you read, subscribe to, comment on, or otherwise interact with the Publication, which is hosted on the Substack platform operated by Substack Inc.
We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and, where applicable to readers in those regions, the EU General Data Protection Regulation (GDPR) and the UK GDPR.
Two parties process your data. Substack operates the platform (accounts, hosting, payments infrastructure, analytics, cookies) and processes your data under its own Privacy Policy at https://substack.com/privacy. We, as the publisher, are the data controller for the subscriber and reader data made available to us through the Publication. This Policy covers our processing. For Substack’s processing, including platform cookies and account data, please refer to Substack’s policy.
1. Data We Collect
Through Substack’s publisher tools, we may receive and process:
Identity and contact data: your email address and, if provided, your name and profile information.
Subscription data: subscription tier (free/paid), sign-up date, plan, and payment status. We never see or store your full card details. Payments are handled by Substack and its payment processor, Stripe (see Stripe’s privacy policy at https://stripe.com/privacy).
Engagement data: whether emails were opened or links clicked, posts viewed, and general activity statistics provided by Substack’s analytics.
Content you submit: comments, chat messages, replies to our emails, survey responses, and correspondence with us.
Technical data: limited technical information (such as approximate location by country/region) as surfaced in Substack’s analytics dashboards.
We do not knowingly collect sensitive personal data within the meaning of the FADP or special category data under the GDPR (e.g. health data, political opinions) and ask that you do not include such data in comments or correspondence. We do not knowingly collect data from anyone under 18; the Publication is not directed at minors, and we will delete such data if we become aware of it.
We do not collect your financial portfolio details, and you should never send us details of your holdings, account numbers, or personal financial circumstances. We cannot and do not provide personalised advice, and any such information sent to us will be disregarded and deleted where practicable.
2. How and Why We Use Your Data (Purposes and Legal Bases)
Under the FADP, processing is permitted where it complies with the statutory data protection principles; where the GDPR or UK GDPR applies to you, we rely on the legal bases below.
Purpose Data used Legal basis (GDPR/UK GDPR, where applicable) Delivering the newsletter and paid content you signed up for Contact, subscription data Performance of a contract (Art. 6(1)(b)) Managing subscriptions, billing status, and account issues Contact, subscription data Performance of a contract Sending the free newsletter you subscribed to Contact data Consent (Art. 6(1)(a)); you may withdraw at any time by unsubscribing Understanding readership and improving content Engagement, technical data Legitimate interests (Art. 6(1)(f)): running and improving the Publication Moderating comments and community spaces Content you submit Legitimate interests: maintaining a safe, lawful community Responding to your messages Contact data, correspondence Legitimate interests / contract Complying with legal obligations (tax, accounting, regulatory, law enforcement requests) As required Legal obligation (Art. 6(1)(c)) Establishing, exercising, or defending legal claims As required Legitimate interests
We do not sell your personal data, and we do not share it with third parties for their own direct marketing. We do not use your data for automated individual decision-making producing legal or similarly significant effects, and we do not carry out high-risk profiling within the meaning of the FADP.
3. Who We Share Data With
Substack Inc. (platform host and email delivery) and its sub-processors, including Stripe (payments). Substack acts as the platform through which all subscriber data flows.
Service providers we may use to run the Publication (e.g. analytics, survey, or scheduling tools), bound by appropriate contractual protections, and only where necessary.
Professional advisers (lawyers, accountants, auditors) and authorities where required by law, court order, or to protect our legal rights.
A successor publisher or buyer if the Publication or the Publisher is transferred, sold, or reorganised, in which case your data will remain subject to protections materially consistent with this Policy and you will be notified.
4. International Transfers
We are based in Switzerland. Substack and Stripe are U.S. companies, so your data is transferred to and stored in the United States and potentially other countries. Where personal data is transferred from Switzerland, the UK, or the EEA to countries without an adequate level of data protection, we and our processors rely on safeguards recognised under the FADP and, where applicable, the GDPR/UK GDPR, including standard contractual clauses recognised by the Swiss Federal Data Protection and Information Commissioner (FDPIC) and the European Commission, the UK International Data Transfer Addendum, and, where applicable, certification under the Swiss-U.S., EU-U.S., or UK Extension to the Data Privacy Framework. Details are available on request.
Note that Switzerland is recognised by the European Commission and the UK as providing an adequate level of data protection, so transfers from the EEA/UK to us in Switzerland do not require additional safeguards.
5. Retention
Subscriber data is retained while you are subscribed and for a reasonable period afterwards to handle queries, re-subscriptions, and legal obligations.
Business and billing-related records may be retained for up to 10 years in accordance with Swiss record-keeping obligations (Art. 958f of the Swiss Code of Obligations).
Comments and community content may persist after you unsubscribe; you can delete your own comments via Substack or ask us to remove them.
When data is no longer needed, it is deleted or anonymised. Note that unsubscribing removes you from mailings but Substack may retain platform account data under its own policy.
6. Your Rights
Under the FADP and, where applicable, the GDPR or UK GDPR, you have the right to: request information about and access to your data; rectify inaccurate data; erase your data; restrict or object to processing (including any processing based on legitimate interests); receive your data in a portable format; and withdraw consent at any time (e.g. by clicking “unsubscribe” in any email), without affecting the lawfulness of prior processing. These rights are subject to conditions and exceptions under applicable law.
To exercise these rights, contact us at alpha@edelbridge.capital. We may need to verify your identity, and we will respond within the timeframe required by applicable law (30 days under the FADP; one month under the GDPR/UK GDPR, extendable where permitted). Some rights are also exercisable directly through your Substack account settings, which is often faster for account-level requests.
You also have the right to lodge a complaint with a supervisory authority:
Switzerland: Federal Data Protection and Information Commissioner (FDPIC), https://www.edoeb.admin.ch
EEA: the data protection authority of your member state
UK: Information Commissioner’s Office (ICO), https://ico.org.uk
We would appreciate the chance to resolve any concern first.
California and other U.S. state residents: depending on your state, you may have rights to know, access, correct, delete, and opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information as defined by the CCPA/CPRA. You may exercise applicable rights by contacting alpha@edelbridge.capital. We will not discriminate against you for exercising them.
7. Cookies and Tracking
We do not set our own cookies. Substack sets cookies and similar technologies (including email open/click tracking pixels) when you use the platform and read our emails; these are governed by Substack’s Privacy Policy and cookie disclosures. Most email clients allow you to block tracking pixels by disabling remote image loading.
8. Security
We limit access to subscriber data, use the security controls provided by Substack, protect our own accounts with strong authentication, and do not export subscriber lists except where necessary. However, no transmission or storage system is completely secure, and to the extent permitted by law we cannot guarantee absolute security of data processed via third-party platforms.
9. Third-Party Links
The Publication links to third-party sites and services. Their privacy practices are their own; review their policies before providing them any data.
10. Changes to This Policy
We may update this Policy from time to time. The current version, with its “Last updated” date, will always be posted on the Publication, and material changes will be notified by reasonable means. Continued use after changes take effect constitutes acknowledgement of the updated Policy.
11. Contact
Privacy questions or rights requests: alpha@edelbridge.capital Edelbridge Alpha GmbH, Switzerland
