Privacy Policy
Privacy Policy
Last updated: 24 February 2026
This Privacy Policy describes how The Vanderbilt Portfolio AG (“we,” “us,” or “our”) collects, uses, and protects personal data when you use ZUG DAO (zugdao.com). We comply with the Swiss Federal Act on Data Protection (FADP, nFADP) and, where applicable, the EU General Data Protection Regulation (GDPR Regulation 2016/679).
1. Data Controller
The Vanderbilt Portfolio AG Zurich, Switzerland
For data protection enquiries: [email protected] (subject: Data Protection)
2. Legal Bases for Processing
We process personal data on the following legal bases:
- Consent (FADP Art. 6 / GDPR Art. 6(1)(a)): where you have given explicit consent, including for analytics cookies.
- Legitimate interests (FADP Art. 6 / GDPR Art. 6(1)(f)): for website security, fraud prevention, and basic site operation analytics, where these interests are not overridden by your rights.
- Contractual necessity (GDPR Art. 6(1)(b)): where processing is necessary to fulfil a service you have requested (e.g., newsletter delivery).
3. Data We Collect
a) Data collected automatically
When you visit ZUG DAO, our servers and third-party analytics tools may collect:
- IP address (anonymised where technically feasible)
- Browser type and version
- Operating system
- Referring URL
- Pages visited and time spent
- Date and time of visit
- Device type (desktop, mobile, tablet)
b) Google Analytics
We use Google Analytics 4 (GA4), operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google Analytics uses cookies and similar technologies to collect and analyse website usage data. Data collected by Google Analytics may be transferred to and processed on Google servers in the United States.
We have enabled IP anonymisation in Google Analytics. Google LLC participates in the EU-US Data Privacy Framework.
You can opt out of Google Analytics tracking by:
- Using the Google Analytics Opt-out Browser Add-on: tools.google.com/dlpage/gaoptout
- Enabling the “Do Not Track” header in your browser (where we honour this signal)
- Declining analytics cookies via our Cookie Consent tool
Google’s privacy policy: policies.google.com/privacy
c) Google Ad Manager
We use Google Ad Manager to serve display advertising. Google Ad Manager may use cookies, web beacons, and similar technologies to serve ads based on your visits to this and other websites. Google’s advertising practices are governed by Google’s privacy policy and the IAB Transparency and Consent Framework.
You can opt out of interest-based advertising:
- Google Ad Settings: adssettings.google.com
- Network Advertising Initiative: optout.networkadvertising.org
- European Interactive Digital Advertising Alliance: youronlinechoices.eu
d) Data you provide voluntarily
If you contact us by email, we retain your email address and correspondence for the purpose of responding to your enquiry and, where relevant, for our records. We do not add you to any mailing list without your explicit consent.
4. Cookies
We use cookies and similar tracking technologies. Please see our Cookie Policy for full details. You can manage cookie preferences at any time via our Cookie Consent tool.
5. Data Transfers Outside Switzerland and the EEA
Some of our service providers (including Google) process data outside Switzerland and the European Economic Area. Where this occurs, we rely on:
- Adequacy decisions by the Swiss Federal Council or European Commission
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Participation in recognised data transfer frameworks (EU-US Data Privacy Framework)
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Google Analytics data | 14 months (GA4 default, configured) |
| Email correspondence | 3 years from last contact |
| Server access logs | 90 days |
| Ad serving data | Per Google’s retention policies |
7. Your Rights
Under the Swiss FADP and/or GDPR, you have the right to:
- Access: request a copy of personal data we hold about you
- Rectification: request correction of inaccurate personal data
- Erasure: request deletion of your personal data (subject to legal retention obligations)
- Restriction: request that we restrict processing of your personal data
- Portability: receive your personal data in a structured, machine-readable format
- Object: object to processing based on legitimate interests
- Withdraw consent: where processing is based on consent, withdraw that consent at any time
To exercise any of these rights, contact us at [email protected] with the subject line “Data Request.” We will respond within 30 days (GDPR) or within the timeframe required by the FADP.
You also have the right to lodge a complaint with:
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC) — edoeb.admin.ch
- EU residents: the supervisory authority in your EU member state of habitual residence
8. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These include HTTPS encryption, access controls, and regular security reviews. No internet transmission is completely secure; we cannot guarantee absolute security.
9. Third-Party Links
ZUG DAO contains links to third-party websites. We are not responsible for the privacy practices of those sites. We encourage you to read their privacy policies.
10. Children
ZUG DAO is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be indicated by the “Last updated” date above. Your continued use of ZUG DAO after any update constitutes acceptance of the revised policy.
12. Contact
The Vanderbilt Portfolio AG Zurich, Switzerland [email protected]