Legal
Privacy Policy
How we collect, use, and protect your data. Last updated: July 2026.
1. Data Controller
The data controller responsible for data processing on this website is:
We take the protection of your personal data seriously. This privacy policy explains how we handle your data when you use our website (closelook.net), our newsletter publication (substack.closelook.net), and related services.
2. Access Data and Hosting
You can visit our website without providing personal information. Each time a page is accessed, the web server automatically stores a server log file containing the requested file name, your IP address, date and time of access, data volume transferred, and the requesting provider. This data is used solely for ensuring trouble-free operation and improving our services, pursuant to Art. 6(1)(f) GDPR.
2.1 Hosting — Cloudflare
Our website is hosted via Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). Cloudflare acts as our hosting provider and content delivery network (CDN). All access data is processed on Cloudflare’s servers. Cloudflare is certified under the EU-U.S. Data Privacy Framework (DPF).
Cloudflare may process data including IP addresses, system configuration information, and other information about traffic to and from our website for security, performance, and analytics purposes.
2.2 Newsletter Platform — Substack
Our newsletter is operated via Substack, Inc. (111 Sutter Street, San Francisco, CA 94104, USA). When you subscribe to our newsletter on substack.closelook.net, Substack collects your email address, subscription preferences, and reading activity. Substack’s own privacy policy governs data processing on their platform. Substack processes data in the United States under the EU-U.S. Data Privacy Framework.
3. Payment Processing
Subscription payments are processed by Stripe, Inc. (354 Oyster Point Blvd, South San Francisco, CA 94080, USA) via Stripe Payment Links on /subscribe/. When you make a payment, Stripe collects your payment information (credit card details, billing address, email) directly on Stripe-hosted checkout pages. We do not store your credit card information on our servers. Stripe is certified under the EU-U.S. Data Privacy Framework. For details, see Stripe’s Privacy Policy.
For paid newsletter delivery, your Stripe customer record is imported by Substack Pro to grant access to subscriber-only newsletter content. Substack does not act as payment processor under this architecture.
4. Cookies and Tracking Technologies
4.1 General Information
We use cookies and similar technologies on our website. Cookies are small text files stored on your device. Some cookies are deleted after your browser session ends (session cookies), while others remain on your device to recognize your browser on subsequent visits (persistent cookies).
Strictly necessary cookies are used without consent to provide the requested service. For all other cookies and tracking technologies, we obtain your consent before activation via our consent management tool.
4.2 Consent Management
We use our own first-party consent banner to inform you about cookies and tracking technologies and to obtain and document your consent pursuant to Art. 7(1) GDPR. On your first visit you choose between “Essential only” (the default — no analytics or marketing technologies run) and “Accept all” (essential + analytics + marketing). Your choice is stored on your device in browser local storage (key cl-consent); no data is sent to any third party by the banner itself. If your browser sends a Do Not Track signal, we treat it as “Essential only” automatically and do not show the banner.
You can change or withdraw your consent at any time via the “Cookie settings” link in the footer of every page. Withdrawing consent stops analytics and marketing scripts from loading on subsequent page views and deletes the analytics cookies previously set by us. Withdrawal is as easy as giving consent (Art. 7(3) GDPR).
4.3 Google Analytics 4
We use Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) for statistical analysis of website usage. Google Analytics uses cookies (_ga, _ga_*) to collect information about your visit including pages viewed, time spent, referral source, and device/browser information. Google Analytics 4 does not log or store individual IP addresses; for EU traffic, IP data is used only for coarse geolocation and dropped before logging. This processing is based on your consent pursuant to Art. 6(1)(a) GDPR. Google Analytics only loads after you choose “Accept all” in our consent banner — no analytics cookies are set before that choice.
We have configured Google Analytics with minimal retention periods: event-level data is retained for 2 months and user-level data for a maximum of 14 months, after which it is automatically deleted by Google.
Google is certified under the EU-U.S. Data Privacy Framework. You can opt out of Google Analytics at any time by withdrawing your consent via “Cookie settings” in the footer (this also deletes the analytics cookies we set) or by installing the Google Analytics Opt-out Browser Add-on.
4.4 LinkedIn Insight Tag
We use the LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland) to measure the effectiveness of our LinkedIn advertising campaigns and to understand how visitors interact with our website after clicking on LinkedIn content. The Insight Tag collects data about page visits, referral URLs, IP addresses, device and browser characteristics, and timestamps. This processing is based on your consent pursuant to Art. 6(1)(a) GDPR and only activates after you choose “Accept all” in our consent banner.
LinkedIn is certified under the EU-U.S. Data Privacy Framework. For details, see LinkedIn’s Privacy Policy.
4.5 First-Party Cookies and Similar Storage
The following cookies and local-storage entries are set by closelook.net itself:
| Name | Type | Purpose | Lifetime | Category |
|---|---|---|---|---|
cl-consent | Local storage | Stores your cookie-consent choice | Until deleted | Essential |
cl_tier | Cookie | Remembers verified access — subscriber (account unlock) or registered (“Join free”) | 30 days | Essential |
cl_unlocked | Cookie | Remembers individually unlocked paid dossiers | 30 days | Essential |
CF_Authorization | Cookie | Cloudflare Access session during the account-unlock sign-in | Session | Essential |
cl-push-* | Local storage | Remembers your push-notification preferences and prompt dismissals | Until deleted | Essential |
_ga, _ga_* | Cookie | Google Analytics visitor and session distinction | Up to 2 years | Analytics — only after “Accept all” |
Essential entries are required for the requested functionality (consent memory, paid-content access, notification preferences) and are used pursuant to Art. 6(1)(b) and (f) GDPR and § 25(2) TDDDG; they are not used for tracking.
5. Data Processing for Communication
When you contact us (e.g., via email or contact form), we collect personal data you voluntarily provide pursuant to Art. 6(1)(b) GDPR to process your inquiry. After complete processing, your data will be deleted unless you have consented to further use or we are legally required to retain it.
Data relating to customer inquiries will be restricted after complete processing and deleted after expiry of statutory retention periods (tax and commercial law) pursuant to Art. 6(1)(c) GDPR.
6. Social Media Presence
We maintain online presences on LinkedIn and X (formerly Twitter). When you visit our profiles on these platforms, the respective platform operator may collect and process data for market research and advertising purposes. Please refer to the privacy policies of each platform for details:
7. AI Search Engines and Machine-Readable Data
7.1 llms.txt and AI Bot Access
We provide machine-readable files (llms.txt and llms-full.txt) at the root of our website to help AI search engines (such as Perplexity, ChatGPT, Google Gemini, and Claude) understand and accurately represent our content. These files contain publicly available information about our research products, frameworks, and services. They do not contain personal data of users or subscribers.
Our robots.txt file explicitly permits crawling by AI bots including GPTBot (OpenAI), ClaudeBot (Anthropic), PerplexityBot, Google-Extended, and Amazonbot. This is done to ensure our research is accurately cited by AI-powered search engines. No personal data is shared with these services through crawling. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in accurate representation of publicly available content).
7.2 Schema.org Structured Data
We embed Schema.org structured data (JSON-LD) on our pages to help search engines and AI systems understand our content structure. This includes metadata such as article titles, publication dates, author names (Thomas Look), organization information (Closelook Venture GmbH), product descriptions, and breadcrumb navigation. All structured data reflects publicly available information and does not contain personal data of visitors or subscribers.
8. Newsletter and Subscription Services
8.1 Substack — Content Delivery
Our newsletter is operated through Substack Inc. (San Francisco, CA, USA). When you subscribe to our newsletter via Substack, Substack processes your email address and subscription preferences. Substack acts as a joint controller for subscriber data. This processing is based on your consent pursuant to Art. 6(1)(a) GDPR when you subscribe.
Substack may use tracking technologies in emails (open tracking, click tracking) to measure newsletter performance. For details, see Substack’s Privacy Policy. You can unsubscribe at any time via the unsubscribe link in every email.
8.2 Stripe — Payment Processing
Subscription payments to the C+ Portfolio tier are processed directly by Stripe, Inc. (San Francisco, CA, USA) via Stripe-hosted Payment Links. When you subscribe, Stripe processes your payment information (credit card data, billing address) on its own infrastructure. We do not receive or store your full credit card number. After payment, Substack Pro imports your Stripe customer record so paid newsletter content reaches your inbox. Stripe is certified under the EU-U.S. Data Privacy Framework. For details, see Stripe’s Privacy Policy.
8.3 Subscriber Verification — Account Unlock on closelook.net
To give paying newsletter subscribers access to subscriber-only content on closelook.net itself, we maintain a minimal mirror of active subscriber records from Substack — the subscriber email address and subscription status — in Cloudflare Workers KV (see Section 2.1). This record is used solely to verify your entitlement when you unlock paid content; it is not used for marketing and is not shared with anyone else.
The unlock flow at /account/unlock/ is protected by Cloudflare Access: you verify your email address by signing in with Google or via a one-time code sent to your email. Cloudflare processes your email address for this authentication. After successful verification, we set the cl_tier cookie (see Section 4.5) so your access persists on this device for 30 days.
Legal basis: Art. 6(1)(b) GDPR (performance of the subscription contract). Subscriber records are synchronised with your Substack subscription status and removed once you are no longer a subscriber.
8.4 Free Registration — “Join free”
Parts of closelook.net (such as full newsletter editions on the page, the complete screener table, and the Weekly Signal track record) are available after a free registration at /join/. When you register, we store your email address, the time of registration, and your delivery-consent choice in Cloudflare Workers KV (see Section 2.1) to operate your access to registered content. We do not store passwords: the sign-in link we email you is valid for 15 minutes and works once. After you click it, we set the cl_tier cookie (see Section 4.5) so your access persists on this device for 30 days.
The sign-in email is delivered by Resend, Inc. (San Francisco, CA, USA), our transactional email provider, which processes your email address for the sole purpose of delivering that message. If — and only if — you tick the optional delivery checkbox, your email address is also added to our Substack list so the newsletters reach your inbox (see Sections 2.2 and 8.1); on-page reading works without it.
Legal basis: Art. 6(1)(b) GDPR (provision of the requested registered access) and Art. 6(1)(a) GDPR (optional email delivery consent). You can request deletion of your registration data at any time via the contact details in the imprint; unsubscribing from email delivery is possible at any time via the link in every email.
9. Push Notifications
If you opt in, we send browser push notifications — at most one editorial notification per day (our Daily Pulse, the Weekly Signal, or a short portfolio note). This is entirely optional.
9.1 What We Store
When you enable notifications, your browser generates a push subscription: a unique endpoint URL at your browser vendor’s push service plus two cryptographic keys. We store only this subscription together with the date you subscribed and a last-seen timestamp. We do not store your name, email address, or IP address with it, and we cannot read any other data from your device.
9.2 Legal Basis — Consent
Processing is based on your consent pursuant to Art. 6(1)(a) GDPR. This consent is given through your browser’s own notification-permission prompt, which appears only after you actively choose “Enable” — it is separate from and independent of any cookie choice. You are never subscribed without that explicit opt-in, and you may withdraw it at any time (see 9.4).
9.3 Delivery — Browser Push Services
The notification itself is delivered by your browser vendor’s push service: Google (Firebase Cloud Messaging) for Chrome and Android, Apple (Apple Push Notification service) for Safari, and Mozilla for Firefox. We send the message and your subscription to that service for delivery; this can involve a transfer to the United States, governed by each provider’s own privacy policy. The subscription record is stored by us in Cloudflare Workers KV (see Section 2.1).
9.4 Retention and Withdrawal
We keep your subscription until you unsubscribe or it becomes invalid; we automatically delete subscriptions that the push service reports as expired or removed. You can withdraw your consent at any time, and it is as easy to withdraw as to give: turn off notifications for closelook.net in your browser settings, or use the unsubscribe control on our site. Withdrawal stops all future notifications and deletes your subscription from our store.
10. Hosting and Content Delivery
10.1 Cloudflare Pages
Our website is hosted on Cloudflare Pages (Cloudflare Inc., San Francisco, CA, USA). Cloudflare provides content delivery network (CDN) services, DDoS protection, and web application firewall functionality. When you access our website, Cloudflare may process your IP address, browser information, and request data for security and performance optimization purposes. This processing is based on Art. 6(1)(f) GDPR (legitimate interest in secure and performant website operation).
Cloudflare is certified under the EU-U.S. Data Privacy Framework. For details, see Cloudflare’s Privacy Policy.
10.2 Self-Hosted Fonts
We serve web fonts (DM Sans, Source Serif 4, JetBrains Mono) directly from our Cloudflare-hosted infrastructure. Fonts are not loaded from third-party CDNs, so no personal data is transmitted to font providers when you load our pages.
11. Third Country Data Transfers
Some of our service providers are based in the United States. Where applicable, data transfers to the US are covered by the EU-U.S. Data Privacy Framework adequacy decision. Where service providers are not certified under the DPF, we rely on EU Standard Contractual Clauses as appropriate safeguards.
Despite all contractual and technical measures, the level of data protection in third countries may not be equivalent to that in the EU. In particular, local authorities may have access rights to personal data that are not sufficiently limited from a European data protection perspective.
12. Your Rights
As a data subject, you have the following rights under the GDPR:
- Right of access (Art. 15) — request information about your personal data we process
- Right to rectification (Art. 16) — request correction of inaccurate data
- Right to erasure (Art. 17) — request deletion of your data, subject to legal exceptions
- Right to restriction (Art. 18) — request restriction of processing in certain circumstances
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format
- Right to lodge a complaint (Art. 77) — file a complaint with a supervisory authority
Right to Object
Where we process personal data based on legitimate interests (Art. 6(1)(f) GDPR), you may object to such processing at any time with effect for the future. For direct marketing purposes, you may exercise this right at any time without restriction. For other purposes, objection is possible where grounds relating to your particular situation apply.
13. Contact
For questions regarding the collection, processing, or use of your personal data, or to exercise your rights, please contact us at:
Closelook Venture GmbH
Email: [email protected]