Privacy Policy
Last updated: 1 October 2026
This policy explains how FG Relations ("we", "us") handles personal data when you visit fgrelations.com, submit an inquiry, use the AI brief tool or use our client portal. It is written to meet the EU General Data Protection Regulation (GDPR), Spain's Organic Law 3/2018 (LOPDGDD), the UK GDPR, and US state privacy laws such as the California Consumer Privacy Act (CCPA/CPRA).
1. Data controller
FG Relations, Avenida de los Américas, Murcia, Spain · info@fgrelations.com · +44 203 773 0547
2. What we collect
- Inquiry form: company name, contact name, email, phone (if given), role, target markets, investor relations needs and your message.
- AI brief tool: company name, description and goals you type in.
- Client portal: name, company, email, password (stored only in hashed form by our authentication provider) and documents you or we upload.
- Visit statistics (only with consent): pages viewed, time of visit and a random visitor identifier stored in your browser.
- Emails and calls: anything you send us at info@fgrelations.com or by phone.
We do not knowingly collect data from children under 16, and we do not ask for special-category data. Please do not include it in submissions.
3. Why we use it and legal basis
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Replying to inquiries and preparing proposals | Steps prior to a contract (6(1)(b)) and legitimate interest (6(1)(f)) |
| Providing the client portal and our services | Performance of a contract (6(1)(b)) |
| Generating an AI engagement brief at your request | Steps prior to a contract (6(1)(b)) |
| Account and service emails (confirmations, document notices) | Performance of a contract (6(1)(b)) |
| Visit statistics | Consent (6(1)(a)), which you can withdraw at any time |
| Keeping business and accounting records | Legal obligation (6(1)(c)) |
| Site security and preventing misuse | Legitimate interest (6(1)(f)) |
We do not use your data for automated decisions that have legal or similarly significant effects on you. The AI brief is an informal draft, not a decision.
4. Who we share it with
We share personal data only with service providers that process it on our behalf under data processing terms:
- Website hosting, database, file storage and authentication providers;
- Email delivery providers (for confirmations and notifications);
- AI model providers, only for text you submit to the AI brief tool;
- Google Fonts, which receives your IP address when the site loads its typefaces.
We may also disclose data where required by law or to protect our legal rights. We do not sell personal information and do not share it for cross-context behavioural advertising.
5. International transfers
Some providers are located outside the European Economic Area, including in the United States. Where this happens, transfers rely on an adequacy decision (such as the EU–US Data Privacy Framework for certified providers) or the European Commission's Standard Contractual Clauses.
6. How long we keep it
We keep inquiry, client and portal data for up to 6 years after our last contact or the end of an engagement, then delete it, unless the law requires longer. Visit statistics are kept in aggregate form. You can ask us to delete your data earlier (see section 7).
7. Your rights (EU / UK)
You have the right to access, correct, delete, restrict or object to the processing of your data, to data portability, and to withdraw consent at any time without affecting earlier processing. Email info@fgrelations.com; we reply within one month.
You may complain to the Spanish Data Protection Agency (AEPD, www.aepd.es), to the supervisory authority where you live, or in the UK to the Information Commissioner's Office (ico.org.uk).
8. Your rights (United States)
Residents of California and other US states with privacy laws may request to know what personal information we collect, use and disclose; request deletion or correction; and opt out of sale or sharing (we do neither). We will not discriminate against you for using these rights. Send requests to info@fgrelations.com; we may need to verify your identity, and you may use an authorised agent. We honour Global Privacy Control signals as an opt-out.
Categories collected in the last 12 months: identifiers (name, email, phone), professional information (company, role), information you provide in messages and documents, and — with consent — internet activity on this site. Sources: you directly. Purposes: as listed in section 3.
9. Security
We use access controls so each client can see only their own portal documents, and we limit staff access to what is needed. No online system is completely secure; please tell us immediately if you suspect misuse of your account.
10. Cookies
See our Cookie Policy.
11. Changes
We may update this policy. The date above shows the latest version; material changes will be highlighted on this site.
