Legal
Privacy Policy
Contents
- 1. Who we are
- 2. What data we collect
- 3. How we use your data
- 4. Marketing communications
- 5. Legal basis
- 6. Data retention
- 7. Sharing and transfers
- 8. Cookies and tracking
- 9. Your rights
- 10. Security
- 11. Changes to this policy
- 12. Contact
- 13. AI compliance
This policy applies to data collected through 20quant.eu, associated subdomains, white paper download forms, newsletter subscriptions, and any marketing or research communications issued by 20Quant. It does not apply to the services or websites of third-party platforms we may reference.
1. Who we are
20Quant S.r.l. is a research and financial decision-support firm incorporated in Milan, Italy. We operate the website 20quant.eu and produce research publications, analytical frameworks, and educational content for professional and institutional audiences.
For the purposes of EU data protection law, 20Quant S.r.l. is the data controller responsible for personal data processed under this policy.
20Quant is the exclusive research and advisory partner to Simplify Partners S.A., a Luxembourg-domiciled investment firm. Data collected by 20Quant is not shared with Simplify Partners without your separate consent, except where legally required.
2. What data we collect
Information you provide directly
- Full name and email address when downloading research reports, white papers, or other gated content
- Name, organisation, and contact details when completing enquiry or contact forms
- Professional information (role, firm, jurisdiction) where voluntarily provided
- Correspondence and responses to communications we send you
Information collected automatically
- Browser type, device type, and operating system
- IP address and approximate geolocation (country or city level)
- Pages visited, time on site, and navigation paths
- Referral source (how you arrived at the site)
- Email open rates and link clicks where tracking is enabled in our communications
Information from third parties
We may receive limited professional information about you from LinkedIn or other professional networks where you have connected with us or engaged with our published content. We do not purchase contact lists.
3. How we use your data
We use personal data to:
- Deliver requested research reports, white papers, and analytical content
- Send newsletters, research updates, and market insights (with your consent)
- Respond to enquiries and manage professional correspondence
- Understand how our content is used and improve its quality and relevance
- Maintain records required by applicable financial regulation, including CONSOB rules
- Comply with legal obligations and enforce our terms of use
We do not use your data to build automated profiles for credit assessment, employment screening, or insurance purposes. We do not sell personal data.
4. Marketing communications
When you download a report or white paper from 20quant.eu, or subscribe to our newsletter, you consent to receive:
- Research updates and new analytical publications
- Market insights, commentary, and regime analysis
- Event invitations, webinar notices, and panel announcements
- Periodic updates on 20Quant services, frameworks, and capabilities
Frequency
We publish content on a weekly cadence. Marketing and service communications are less frequent and will not exceed a reasonable volume relative to editorial output.
Unsubscribing
Every communication we send includes a clearly visible unsubscribe link. You may also withdraw consent at any time by writing to us at the address in Section 12. Withdrawal of consent does not affect the lawfulness of any processing carried out before withdrawal.
Transactional messages
Delivering a requested document (such as a white paper PDF) is not a marketing communication. These messages may be sent regardless of marketing preference.
5. Legal basis for processing
Under the General Data Protection Regulation (GDPR) (EU) 2016/679, we rely on the following legal bases:
- Consent — for sending marketing and research communications. You provide this when submitting a download form or subscribing to our newsletter.
- Legitimate interests — for analytics, security, fraud prevention, and improving the quality of our content, provided these interests are not overridden by your rights.
- Legal obligation — where processing is required by applicable law, including financial services regulation.
- Contract performance — where data processing is necessary to fulfil a contractual obligation to you.
6. Data retention
We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law.
- Newsletter and marketing contacts: retained while you remain an active subscriber, and for up to 24 months following an unsubscribe request or last engagement, unless you request earlier deletion.
- White paper download records: retained for up to 36 months for audit and compliance purposes.
- Website analytics data: retained in anonymised or aggregated form beyond these periods.
- Correspondence: retained for up to 7 years where there is a regulatory or legal basis for doing so.
You may request deletion at any time. See Section 9 for your rights.
9. Your rights
Under GDPR and applicable Italian data protection law, you have the right to:
- Access the personal data we hold about you
- Rectification of inaccurate or incomplete data
- Erasure of your data, subject to legal retention requirements
- Restriction of processing in certain circumstances
- Data portability — to receive your data in a structured, machine-readable format
- Object to processing based on legitimate interests
- Withdraw consent at any time for processing that relies on consent, without affecting lawfulness of prior processing
To exercise any of these rights, contact us using the details in Section 12. We will respond within 30 days at no charge for reasonable requests.
If you believe we have not handled your data lawfully, you have the right to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (garante.it), or the supervisory authority in your country of residence within the EU.
10. Security
We implement technical and organisational measures appropriate to the risk level of the data we process. These include access controls, encrypted data transmission (TLS), and regular review of our data handling practices.
No transmission over the internet is completely secure. If you believe your data has been compromised in connection with our services, please contact us immediately.
11. Changes to this policy
We may update this policy periodically to reflect changes in our practices, technology, or legal requirements. Where changes are material, we will notify active subscribers by email and update the review date at the top of this page.
Continued use of our website or communications following an update constitutes acceptance of the revised policy.
12. Contact
For any questions about this policy, to exercise your rights, or to raise a data-related concern:
Requests are acknowledged within 5 business days and responded to within 30 calendar days in line with GDPR requirements.
13. AI compliance requirements and disclaimers
20Quant S.r.l. may use artificial intelligence (AI), automation, data analysis, workflow orchestration, and operational or decision-support systems in performing activities entrusted by clients. The use of these tools does not alter the professional nature of the engagement.
Fees remunerate 20Quant's experience, competence, operational coordination, professional judgement, and service outcomes, regardless of the tools used to perform the activities.
Authorisation to use AI
The client authorises 20Quant to use AI and automation tools for analysis, research, content production, reporting, document processing, workflow optimisation, operational support, and the development of intelligence and monitoring systems, to the extent necessary to perform the engagement.
Limitations on data use
Unless specifically authorised, 20Quant will not enter into external AI systems health data that identifies individuals, special categories of personal data under GDPR, unnecessary personal data, information enabling the direct identification of clients, patients, donors, investors or third parties, or confidential information not necessary for the performance of the engagement.
Where possible, anonymised, pseudonymised, or aggregated data will be used.
GDPR
The client remains the data controller. 20Quant acts exclusively within the limits of the engagement received, in accordance with the client's documented instructions, and in compliance with GDPR.
Where necessary, an agreement pursuant to Article 28 GDPR will be signed and 20Quant will be formally appointed as data processor.
Human review
All outputs produced with AI support must undergo human review before publication, final delivery, or external use. This includes content, reports, analyses, documents, commercial materials, institutional materials, dashboards, and external communications.
AI supports professional work but does not replace human control.
Client final approval
Responsibility for final approval remains with the client. In particular, the client approves public content, campaigns, institutional materials, financial content, medical or scientific content, tax content, legal content, reputational content, and communications addressed to clients, investors, donors, stakeholders, or third parties.
Errors in approved content
After client approval, 20Quant is not liable for errors, inaccuracies, or omissions in published or disseminated content, except in cases of wilful misconduct or gross negligence directly attributable to 20Quant.
Chatbots and AI assistants
Where chatbots, virtual assistants, automated interaction systems, or AI agents addressed to external users are used, users must be clearly informed that they are interacting with an AI system and not with a natural person.
This reflects Regulation (EU) 2024/1689 on artificial intelligence, Article 50, Transparency Obligations.
AI tool malfunctions and third-party services
20Quant is not responsible for service interruptions, unavailability, infrastructure errors, technical limitations, API changes, AI model changes, third-party provider policy changes, or operational discontinuities of external software or AI platforms where such events are not directly attributable to 20Quant.
AI as a tool, not a decision-maker
AI is used as a support tool, operational accelerator, analysis system, automation system, document-production support, and monitoring and research support. It is not used as a decision-making subject.
Final decisions always remain with the client.
Intellectual property
The use of AI does not alter ownership of deliverables as provided in the relevant contract.
20Quant retains ownership of methodologies, frameworks, workflows, prompt architecture, agentic systems, processes, templates, operating models, know-how, and internal tools developed in the course of its activities.
EU AI Act principles
AI systems used by 20Quant must be employed consistently with transparency, human oversight, accountability, data protection, operational security, proportionality of use, and reasonable traceability of activities where applicable.
Summary principle
AI is a professional tool used by 20Quant to increase the quality, speed, and operational capacity of the service.
20Quant's professional responsibility concerns the process, competence, and quality of the activity performed. Responsibility for final decisions, approval of content, and external use of materials remains with the client.