GDPR Compliance Statement

Global Asset Management Standards (GAMS) — Standards Exchange

Version 1.1 · Effective 13 July 2026

This statement explains how the Standards Exchange platform (the websites at open.gamstandards.com, app.gamstandards.com and related services) complies with the EU General Data Protection Regulation (GDPR) and the UK GDPR. It is a plain-language summary provided for anyone who asks how we handle personal data. It should be read together with our Privacy Notice, which is the authoritative description of our processing.

Note on legal-entity details. The registered legal entity, postal address and (where applicable) EU/UK representative and Data Protection Officer are available on request from the contact below and are confirmed in our Privacy Notice. Please have your legal team review this statement before relying on it contractually.


1. Who we are

Standards Exchange is operated by Global Asset Management Standards ("GAMS", "we", "us"), which is the data controller for personal data processed through the platform.

For any privacy question or to exercise your rights, email privacy@gamstandards.com.


2. Our approach at a glance

  • EU data residency by default. Our primary databases, application servers, file storage and analytics warehouse run in Google Cloud's European Union region.
  • No third-party tracking or advertising. We use no Google Analytics, no advertising pixels, no cross-site trackers, and no data brokers. Usage analytics are first-party only.
  • Analytics that minimise personal data. We do not store visitors' IP addresses. Consent is required before any analytics cookie is set or any usage event is recorded.
  • Self-hosted fonts and assets. We do not load fonts or scripts from third-party content-delivery networks, so your IP address is not exposed to those third parties when you browse.
  • Data-subject rights are built in. You can obtain a copy of your data, correct it, or have your account and associated personal data erased.
  • Data minimisation in public directories. Public working-group rosters show only a member's name, role and representing firm — never contact details, photographs or social-media profiles — and only where the member has not opted out.

3. Personal data we process

Visitors (public pages)

Anyone can browse published standards and collections without an account. For visitors we process, only with your consent, anonymous first-party usage analytics — see section 5.

Members (registered users)

For people who join a working group or create an account we process:

Category Examples
Identity & profile Name, email address, job title, representing firm, and any optional profile details you add
Membership Working-group memberships and roles
Content Messages you post in discussion threads, documents you upload
AskAI interactions Questions you submit and the collection you asked about
Account/technical Authentication identifiers, timestamps (sign-in, activity)

We do not intentionally request special-category (sensitive) personal data, and the platform is not intended for children. Free-text fields can contain information you choose to provide, so please do not submit sensitive personal data in AskAI questions, discussion posts, or other free-text content.


4. Legal bases for processing (Art. 6)

Purpose Legal basis
Operating your account and working-group participation Performance of a contract / legitimate interests
Discussion threads and document collaboration Legitimate interests in operating the platform
Answering AskAI questions and identifying aggregate FAQ improvements Performance of a requested service / legitimate interests in improving published collections
Publishing working-group rosters in public directories Consent (opt-in) of the member displayed
First-party usage analytics Consent
Service and security communications Legitimate interests / legal obligation

Where we rely on legitimate interests, we have balanced those interests against your rights. Where we rely on consent, you may withdraw it at any time (see section 9).


5. Analytics — how it works and why it is privacy-preserving

We measure how the platform is used so we can improve it. Our analytics are designed to collect as little personal data as possible:

  • Consent first. No analytics cookie is set and no usage event is recorded until you accept analytics via our cookie banner. If you choose "Essential only," nothing is collected and any existing analytics cookie is deleted.
  • First-party only. Events are sent to our own servers. No third party (advertising network, analytics vendor) receives your data.
  • IP addresses are not stored. When an event reaches our server we use the IP address once, in memory, to derive an approximate location (country and region) using a local database — the IP is then discarded and never written to storage. Even that lookup uses a truncated IP address.
  • No cross-site identity. The only identifier is a random session ID held in a first-party cookie (gams_session) that expires after 30 minutes of inactivity and is not linked to your identity.
  • What we record: page path, page/resource type, an anonymous session ID, approximate location (country/region/city), referrer, browser user-agent, and the type of interaction (e.g. a document download). We do not record names, emails, or any direct identifier for analytics.
  • EU storage and limited retention. Analytics events are stored in a European-Union data warehouse and automatically deleted after at most 24 months.

AskAI questions and FAQ improvement

When a signed-in user submits a question to AskAI, we retain the question, account identifier, collection context, timestamp and grounding result for up to 90 days. This supports rate limiting, service operation and identification of recurring content gaps. Once a week, questions from the previous 30 days may be grouped into de-identified, aggregate FAQ opportunities for the working group responsible for that collection. A theme is shown only after at least three questions from at least two different users. Working groups see no raw queries or asker identities and must review a suggestion before it can become a draft FAQ.

AskAI question text is processed by Google Cloud Vertex AI as untrusted input to generate grounded answers and canonical themes. Recent-question shortcuts stored in your browser expire individually after 90 days and are removed when you sign out. Please do not include sensitive personal data in an AskAI question.


6. Cookies

We use a single first-party cookie, and only with your consent:

Cookie Type Duration Purpose
gams_session First-party 30-minute session Anonymous usage analytics (random ID, no link to your identity). Set only after you accept analytics.

Strictly-necessary cookies (for example, keeping you signed in) are used only in the authenticated application and only where required to deliver the service you requested. You can change or withdraw your analytics choice at any time via the Cookie preferences link in the site footer.

AskAI also uses browser session storage to keep the current conversation for the life of a tab. Up to five recent questions may be kept in local storage so they can be asked again; each expires after 90 days. AskAI browser storage is cleared when you sign out. These storage entries are functional, are not used for analytics and are not shared across sites.


7. Data residency and international transfers

Our core infrastructure — application servers, primary database, file storage and the analytics warehouse — is hosted in the European Union on Google Cloud.

A small number of sub-processors operate outside the EEA. Where they do, transfers are protected by the appropriate GDPR Chapter V safeguards (Standard Contractual Clauses and, where relevant, supplementary measures), under data-processing agreements compliant with Article 28.


8. Sub-processors

Sub-processor Purpose Location
Google Cloud Hosting, database, file storage, analytics warehouse European Union
Google Cloud Vertex AI Grounded AskAI answers, de-identified FAQ-theme analysis and AI-assisted drafting Google Cloud global endpoint, under the same Google Cloud data-processing agreement
Twilio SendGrid Transactional email delivery United States (SCCs)
LinkedIn Optional profile enrichment, only if you connect it United States (SCCs)

A current list of sub-processors is available on request. We maintain Article 28 data-processing agreements with each.


9. Your rights

Under the GDPR / UK GDPR you have the right to:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data (you can edit your profile directly in the app).
  • Erasure — have your account and associated personal data deleted. When an account is deleted, we remove the profile and cascade the deletion across our systems: authored discussion messages are anonymised, membership records and stored files are removed, and search indexes are updated.
  • Portability — receive the personal data you provided in a structured, machine-readable format.
  • Restriction and objection — limit or object to certain processing.
  • Withdraw consent — turn off analytics at any time via Cookie preferences in the footer; withdrawal does not affect processing already carried out.

To exercise any of these rights, email privacy@gamstandards.com. We respond within one month, as required by the GDPR. There is no charge for a first request.


10. Data retention

  • Account and profile data: kept while your account is active; removed when you delete your account.
  • Discussion content: retained as part of the working-group record; anonymised (author removed) when the author's account is deleted.
  • Analytics events: automatically deleted after at most 24 months.
  • AskAI questions: automatically deleted after at most 90 days, or sooner when the associated account is erased.
  • De-identified FAQ-opportunity summaries and browser recent-question shortcuts: automatically expire after at most 90 days.
  • Backups and logs: kept for a limited operational period and then expire.

11. Security of processing (Art. 32)

  • Encryption of personal data in transit (TLS) and at rest on managed Google Cloud services.
  • Access to personal data is restricted through identity and access management and least-privilege service accounts.
  • We minimise what we collect and avoid storing raw IP addresses for analytics.
  • Credentials and secrets are held in managed secret storage, not in source code.
  • EU data residency for primary storage.

12. Complaints

If you believe we have not handled your personal data lawfully, please contact us first at privacy@gamstandards.com so we can put it right. You also have the right to lodge a complaint with a supervisory authority — in the EU, the data protection authority of your country of residence; in the UK, the Information Commissioner's Office (ICO), https://ico.org.uk.


13. Changes to this statement

We may update this statement as the platform evolves. The version number and effective date at the top reflect the current version, and the latest version is always available at https://open.gamstandards.com/gdpr.md.

Contact: privacy@gamstandards.com