Privacy Policy and Cookie Notice

CCi30 Cryptocurrency Index

Version 1.0. Effective 10 October 2026. Last updated 10 October 2026.

1. About this policy

1.1 This policy explains what personal data CSP DAO LLC collects through the CCi30 Cryptocurrency Index website and its related services, why we collect it, what we do with it, who receives it, how long we keep it, and what rights you have.

1.2 The policy covers:

(a) the website at https://cci30.com and its subdomains (the "Site");

(b) the contact form on the Site, and e-mail sent to addresses at cci30.com;

(c) the paid index data API (the "API");

(d) the Model Context Protocol server at https://cci30.com/mcp (the "MCP Server");

(e) the public data files and data endpoints on the Site, such as the daily OHLCV values file and the constituents and weights files;

(f) our dealings with licensees, data vendors, suppliers, journalists, researchers and other business contacts.

1.3 Section 6 is our cookie notice. It lists each cookie and each item of browser storage that the Site uses, who sets it, why, and for how long.

1.4 This policy does not cover:

(a) websites of other organisations that the Site links to (see section 20);

(b) the use that Google makes of data for its own purposes, which Google's own privacy policy governs (see 5.3 and 5.5);

(c) systems that our customers run with index data they receive from us.

1.5 If you have a written agreement with us that contains data protection terms (for example a licence agreement), those terms apply as well. Where they conflict with this policy, the agreement prevails for the data it covers.

1.6 This policy is written in English. If we publish a translation, the English text prevails where the two differ.

1.7 The policy is laid out in layers. Section 4 is a one-page summary. Section 5 describes each processing activity in the same order: what data, from whom, why, on what legal basis, for how long, who receives it, and where it goes. Sections 6 to 10 cover cookies, recipients, transfers, retention and security. Sections 11 to 16 set out your rights under the laws of the European Economic Area, the United Kingdom, Switzerland, California, other US states and Brazil.

1.8 Our Terms of Use are published at https://cci30.com/terms/. They refer to this policy for personal data.

2. Who we are and how to contact us

2.1 The controller. The controller of your personal data is CSP DAO LLC, a limited liability company organised under the laws of the State of Wyoming, United States, formed on 2 March 2022 under Wyoming filing number 2022-001086782. Legal address: c/o Registered Agents Inc, 30 N Gould St, Ste R, Sheridan, WY 82801, United States. Legal Entity Identifier (LEI): 9845006BE86C7D0ZBC50. CSP DAO LLC is a subsidiary of CS&P SA, Panama, and is the administrator of the CCi30 Cryptocurrency Index. A "controller" is the person or organisation that decides why and how personal data is processed.

2.2 How to contact us. For any question about this policy or about your personal data, write to info@cci30.com. Please put "Privacy" in the subject line so that your message reaches the right person. Written requests can also be sent by post to: CSP DAO LLC, c/o Registered Agents Inc, 30 N Gould St, Ste R, Sheridan, WY 82801, United States.

2.3 People in the European Union. We are not established in the European Union, and we have not appointed a representative in the EU under Article 27 of the GDPR. If you are in the EU, write to us at info@cci30.com, or by post to the address in 2.2, about any matter connected with our processing of your personal data. You can also complain to a supervisory authority in the EU (13.2).

2.4 People in the United Kingdom. We are not established in the United Kingdom, and we have not appointed a representative in the UK under Article 27 of the UK GDPR. If you are in the UK, write to us at info@cci30.com, or by post to the address in 2.2, about any matter connected with our processing of your personal data. You can also complain to the UK Information Commissioner's Office (13.3).

2.5 Data protection officer. We have not appointed a data protection officer. Article 37 of the GDPR requires one where the core activities of a controller consist of large-scale, regular and systematic monitoring of individuals or large-scale processing of special categories of data. Our processing is neither. For Brazil, see 16.6.

3. Definitions

3.1 In this policy:

(a) "we", "us", "our" means CSP DAO LLC;

(b) "you" means any person whose personal data we process: a visitor to the Site, a person who writes to us, an API or MCP Server user, a licensee or a business contact;

(c) "personal data" means any information relating to an identified or identifiable natural person. Examples are a name, an e-mail address, an IP address and a cookie identifier. California law uses the term "personal information"; in this policy "personal data" covers both;

(d) "processing" means any operation on personal data, such as collecting, recording, storing, reading, using, sending or deleting it;

(e) "controller" has the meaning in 2.1. A "processor" is a person or organisation that processes personal data on behalf of a controller and on its instructions;

(f) "GDPR" means Regulation (EU) 2016/679. "UK GDPR" means the GDPR as it forms part of the law of the United Kingdom, read with the Data Protection Act 2018;

(g) "EEA" means the member states of the European Union, Iceland, Liechtenstein and Norway;

(h) "IP address" means the numerical address of a device's connection to the internet. Every request that a browser or program sends to a web server carries one;

(i) "hash" means a fixed-length value computed from an input by a one-way function. MD5 and SHA-256 are hash functions. A hash cannot be turned back into its input directly. A hash of a short input, such as an IP address, can still be matched by computing the hash of every possible input, so we treat hashed IP addresses as personal data;

(j) "cookie" means a small text file that a website stores in your browser and reads back on later requests. A "session cookie" is deleted when you close your browser. A "persistent cookie" stays until its expiry date or until you delete it. A "first-party cookie" is set under the address of the site you are visiting (cci30.com). A "third-party cookie" is set under another address (for example google.com);

(k) "local storage" means a storage area in your browser that a website can write to and read from. Unlike a cookie, it is not sent to the server with each request, and it has no expiry date;

(l) "API token" means the secret string that we issue to an API customer to prove its identity when it requests data;

(m) "MCP" means the Model Context Protocol, a published protocol that lets AI assistants and other programs request data from a server. A "licensed key" is a secret string that we issue to a licensee to use the MCP Server tools that require a licence;

(n) "licensee" means a person or organisation that holds a written licence from us to use the CCi30 index, its data or the CCi30 marks;

(o) "supervisory authority" means a public authority that enforces data protection law, such as a national data protection authority in the EEA or the Information Commissioner's Office in the United Kingdom.

4. Summary

4.1 The table below summarises our processing. Each row refers to a full description in section 5. Section 9 sets out every retention period in full.

ActivityPersonal dataLegal basis under the GDPRHow long we keep it
Delivering the Site (5.1)IP address and request details, held in memory while a request is handled; kept in an error record only when a request failsLegitimate interestsNot stored, and no access log is kept. Error records: see logs (5.10)
Contact form (5.2)Name, e-mail address, subject, message; hashed IP address for a rate limitSteps before a contract at your request; legitimate interestsMessage: as e-mail (5.4). A copy kept because the mail server refused it: until delivered, and at most 30 days. Rate-limit counter: deleted by a daily clean-up once it is more than one day old
reCAPTCHA (5.3)IP address, browser and device data, interaction data, Google cookiesLegitimate interestsOur server keeps nothing; Google keeps data under its own policies
E-mail (5.4)Address, name, content, attachmentsContract; legitimate interests; legal obligation24 months after the last message, unless a contract follows
Analytics (5.5)Random cookie identifier, pages viewed, links clicked, files downloaded, scrolling and form events, device and browser data, approximate location; e-mail addresses, telephone numbers or postal addresses in hashed form, where the Google tag picks them up from a page (5.5.4(g))Legitimate interestsEvent data: the retention period set in our Google Analytics property; cookies up to 2 years
API accounts (5.6)E-mail address, hash of the API token, account status and dateContractWhile the account is active, then 24 months
MCP Server (5.7)Hashed IP address for a rate limit; daily usage counts per licensed keyLegitimate interests; contractCounter: used for at most 2 minutes, deleted when newer counts replace it (5.7.2). Usage: last 60 days of use
Licensees and business contacts (5.8)Name, role, organisation, contact details, contracts, invoices, correspondenceContract; legitimate interests; legal obligationThe relationship, then the limitation period for contract claims
Administrator accounts and login protection (5.9)Login name, e-mail, password hash, session IP address and browser; hashed IP address after a failed loginLegitimate interestsWhile access is needed, then 30 days; sessions up to 14 days; failed-login count used for 15 minutes and deleted within about one day after it expires
Logs and alerts (5.10)Error lines; web server error records and system events, with IP addresses; mail delivery recordsLegitimate interestsPHP error log and mail delivery log: 8 weeks. System log files: about five weeks. System journal: until it reaches its size limit (5.10.7)
Backups (5.11)Copies of the data aboveLegitimate interestsRoutine backups: 14 days for the database, 3 days for the files. Copies made before maintenance work: 90 days after the work is checked
Legal claims (5.12)What the matter requiresLegitimate interestsUntil the matter is closed, plus the limitation period

4.2 We do not sell personal data. We do not show advertising. We do not send newsletters or marketing e-mail. We do not keep web server access logs. Section 19 lists what we do not do.

5. How we use personal data, activity by activity

5.1 Delivering the Site

5.1.1 What happens. When you open a page or download a file, your browser sends a request to our server. The request carries your IP address, the address of the page or file, the time, and technical details that browsers send by default: browser type and version, operating system, preferred language and, in some cases, the address of the page that linked to ours (the "referrer"). Our server needs this data to send the page back to you.

5.1.2 What we keep. Our web server does not keep access logs. When a request succeeds, it does not write your IP address or the pages you request to disk. The data is held in the server's memory while the request is handled and is then discarded. When a request fails with an error (for example because the connection breaks off, or because a part of the Site does not answer), the web server writes an error record to the server's system log. That record contains your IP address, the address of the page or file you asked for, the time, and the details your browser sent with the request, such as its identification string, your preferred language and the referring page. The web server blanks any cookies and login details in the record. Error records are covered in 5.10. The other exceptions are described in 5.2 (contact form rate limit), 5.7 (MCP Server rate limit) and 5.9 (failed logins).

5.1.3 Search. If you use the search box, the words you type are sent to our server as part of the page address so that the server can find matching pages. We do not store them.

5.1.4 Calculators. The calculators on the Tools pages download index data from our server and do their calculations in your browser. The amounts you type are not sent to us.

5.1.5 Content from other companies. The Site serves its pages, fonts, scripts and style sheets from its own server. The only page that loads content from another company is the home page, which loads Google Analytics (5.5) and Google reCAPTCHA (5.3). A link to another website (for example Wikipedia, LinkedIn or Google Scholar) sends nothing to that website until you click it.

5.1.6 Source. Your browser or the program you use.

5.1.7 Purposes. To deliver pages and data files to you; to keep the Site secure and available.

5.1.8 Legal basis. Article 6(1)(f) GDPR (legitimate interests). Our interest is in running a website that works and is secure. Your interest is in receiving the pages you ask for. The data is used only while the request is handled, so the effect on you is small.

5.1.9 Retention. Not stored beyond the handling of the request, except in an error record when the request fails (retention in 5.10.7).

5.1.10 Recipients. Hetzner Online GmbH, a company in Germany, provides the server and the network connection on which the Site, the API and the MCP Server run. It acts as our processor.

5.1.11 Location and transfers. The server is a Hetzner cloud server. The public RIPE network registry lists the block of network addresses that our server belongs to as Hetzner's, in the United States. See section 8.

5.1.12 Must you provide this data? A browser cannot receive a page without sending an IP address. If you do not want to send it, you cannot use the Site.

5.2 The contact form

5.2.1 Where it is. The contact form is on the home page, in the section "Contact the team". The "Contact" link in the menu of every page, and the "Request API access" and "Licensing enquiries" links on the Site, lead to it.

5.2.2 Data you enter.

(a) Your name (required, up to 120 characters).

(b) Your e-mail address (required). You type it twice so that a typing error is caught before you send.

(c) A subject chosen from a list: General inquiry, Commercial license, Academic license, Data and API, or Media (optional).

(d) Your message (required, up to 5,000 characters), and any other personal data you choose to write in it.

The limits in (a) and (d) are counted in bytes. A name or message written in a script other than the Latin alphabet reaches the limit with fewer characters.

5.2.3 Data collected automatically.

(a) A reCAPTCHA token, described in 5.3.

(b) Your IP address, for a rate limit. The form accepts up to 20 messages per hour from one IP address. To count them, the server stores a counter in the Site's database under a name built from the MD5 hash of your IP address. The IP address itself is not stored. The limit reads only the counters of the current hour and the hour before it. A clean-up runs once a day and deletes every counter that is more than one day old.

5.2.4 What happens to your message. The Site does not save your message in its database. The server turns the message into an e-mail and sends it to info@cci30.com. The e-mail is sent from our own address, info@cci30.com. It contains your name, your e-mail address and your message, with the subject you chose at the start of the message. Your e-mail address is placed in the "Reply-To" line so that our reply goes to you. When the mail server accepts the e-mail, the form tells you "Message sent", and from that point your message is handled as e-mail, as described in 5.4.

5.2.4A If the mail server does not accept your message. If our mail server refuses the e-mail, the Site keeps a copy of your message so that it is not lost. The copy holds the time, your name, your e-mail address, the subject and the message. It is stored as one line in a file on our server, outside the folders that the web server makes public, and only the server's web software and the people who run the server can read it. The form tells you that the message was not e-mailed and that a copy is kept. An automatic monitor tells the people who run the Site how many copies are waiting, without their content. We deliver or forward each copy to info@cci30.com as soon as we can, and then delete it from the file. Any copy still in the file 30 days after it was kept is deleted in any case. At present the Site cannot send e-mail: the mail settings are complete except for the mailbox password. Until that is entered, every message sent through the form is kept in this way, and the form tells you so.

5.2.5 Source. You.

5.2.6 Purposes.

(a) To answer your message.

(b) Where you ask about a licence, API access or another service, to discuss and prepare a contract with you or your organisation.

(c) To protect the form from automated abuse (the rate limit).

5.2.7 Legal basis.

(a) Where your message asks for a licence, API access or another service: Article 6(1)(b) GDPR, steps taken at your request before entering into a contract.

(b) Otherwise: Article 6(1)(f) GDPR, our legitimate interest in answering messages that people send us. You chose to write to us, and you expect a reply.

(c) The rate limit: Article 6(1)(f) GDPR, our legitimate interest in keeping the form and our mailbox free of automated abuse. The counter holds no readable IP address and is kept for a short time.

5.2.8 Retention. The message: see 5.4.5. A copy kept under 5.2.4A: until it is delivered or forwarded, and at most 30 days. The rate-limit counter: until the daily clean-up after it is more than one day old (5.2.3).

5.2.9 Recipients. Hetzner Online GmbH (server, 5.1.10). A2 Hosting (mailbox, 5.4.6). Google (reCAPTCHA, 5.3).

5.2.10 Transfers. See section 8.

5.2.11 Must you provide this data? No law or contract requires it. Without your name, e-mail address and message the form cannot be sent, and without an e-mail address we cannot reply. You can write to info@cci30.com instead; that route does not use reCAPTCHA.

5.3 Google reCAPTCHA on the contact form

5.3.1 What it is. reCAPTCHA is a Google service that estimates whether a form is being used by a person or by an automated program. The contact form uses the "invisible" version 2 of reCAPTCHA, which runs when you press "Send". The notice under the form reads: "This form is protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply."

5.3.2 When it loads. The reCAPTCHA script is loaded from www.google.com on the home page only. It loads when you first interact with the home page, or when the contact section comes close to the visible part of the page. If you press a mouse button, touch the screen or press a key, it loads at once. If you move the mouse, scroll with the mouse wheel or move the keyboard focus, it loads at that moment or 5 seconds after the page has finished loading, whichever is later. If you scroll down to the contact section, or arrive through a "Contact" link, it loads at once. It does not wait until you use the form, and the Site does not ask for your consent before it loads. If you do none of these things, it does not load.

5.3.3 What Google receives. When the script runs, your browser connects to Google's servers. Google receives your IP address and information about your browser and device, and may set or read cookies and browser storage under its own domains (see 6.4). Google states that reCAPTCHA works by collecting hardware and software information, such as device and application data, and sending it to Google for analysis.

5.3.4 The check. When you press "Send", reCAPTCHA gives your browser a token. If Google is not sure that you are a person, it may first show you a puzzle, such as a set of pictures to choose from. Our server sends the token and your IP address to Google, and Google replies whether the token is valid. If Google says it is not valid, or cannot be reached, the form rejects your message and you can write to us by e-mail instead. Our server does not keep the token or Google's reply.

5.3.5 Source. Your browser and device.

5.3.6 Purpose. To protect the contact form and our mailbox from spam and automated abuse.

5.3.7 Legal basis. Article 6(1)(f) GDPR, our legitimate interest in keeping the form free of automated abuse. This covers the loading of reCAPTCHA described in 5.3.2 and the check made when you send a message. We do not ask for your consent before reCAPTCHA loads.

5.3.8 Retention. Our server keeps nothing. Google keeps data under its own policies.

5.3.9 Recipients. Google, which provides reCAPTCHA under its own terms. As the notice under the form says, the Google Privacy Policy and Terms of Service apply to reCAPTCHA. Google's privacy policy is at https://policies.google.com/privacy.

5.3.10 Transfers. Google processes data in the United States and other countries. See section 8.

5.3.11 Must you provide this data? No. You can avoid reCAPTCHA by writing to info@cci30.com.

5.4 E-mail correspondence

5.4.1 Data. When you write to an address at cci30.com, or when a contact form message reaches us (5.2), we process: your e-mail address and name; the content of your message and of any attachments; any details in your signature (for example your job title, organisation and telephone number); the dates and technical headers of the e-mail; and our replies.

5.4.2 Sources. You. Sometimes a colleague of yours or another person who copies you into a message.

5.4.3 Purposes. To answer you; to conduct business with you or your organisation; to keep a record of what was asked, offered and agreed.

5.4.4 Legal basis.

(a) Article 6(1)(b) GDPR, where the correspondence concerns a contract with you or steps you asked for before a contract.

(b) Article 6(1)(f) GDPR in other cases: our legitimate interest in answering and in keeping a record of our business correspondence.

(c) Article 6(1)(c) GDPR, where a law requires us to keep the correspondence (for example accounting records).

5.4.5 Retention. We keep correspondence for 24 months after the last message in a conversation and then delete it. If the conversation leads to a contract, we keep it for as long as described in 5.8.5.

5.4.6 Recipients. A2 Hosting, a hosting company in the United States, hosts the e-mail for addresses at cci30.com, including the mailbox info@cci30.com, and acts as our processor. Within our organisation, only the people who handle the subject of your message read it.

5.4.7 Transfers. The mailboxes are on A2 Hosting's mail servers. The public ARIN network registry lists the network address of our mail server (mx.cci30.com) as A2 Hosting's, in the United States. See section 8.

5.4.8 Must you provide this data? No. If you do not give us an address, we cannot reply.

5.4.9 A word on security. E-mail is not encrypted from end to end. Do not send passwords, API tokens, payment card numbers, bank details or identity documents to us by e-mail or through the contact form.

5.5 Website analytics (Google Analytics 4)

5.5.1 What it is. We use Google Analytics 4, a Google service, to count visits and to see which pages and files are used. Our measurement ID is G-3MVKTJGHP4. Google Analytics is installed through the ExactMetrics plugin for WordPress.

5.5.2 Where it runs. Google Analytics runs on the home page only. No other page of the Site loads it. The Google tag script is loaded after the rest of the page has finished loading. The ExactMetrics plugin is set not to measure logged-in administrators and editors of the Site.

5.5.3 When it runs. Google Analytics runs each time a visitor opens the home page, except for logged-in administrators and editors (5.5.2). The Site does not show a cookie banner and does not ask for your consent before Google Analytics runs and sets its cookies. You can stop it in your browser as described in 6.6.2.

5.5.4 What Google receives when the tag runs.

(a) A random identifier that the tag stores in the _ga cookie in your browser (the "client ID"), and a session identifier stored in the _ga_3MVKTJGHP4 cookie.

(b) The address and title of each page you view, and the address of the page that brought you to the Site.

(c) Events recorded by the ExactMetrics plugin: page views; clicks on links to other websites; clicks on e-mail and telephone links; downloads of files with the extensions zip, mp3, mpeg, pdf, docx, pptx, xlsx and rar. Events recorded by Google's own "enhanced measurement", which is switched on for our measurement ID: page views, scrolling to near the end of a page (90 per cent of its height), clicks on links to other websites, file downloads, the start and the sending of a form (Google describes these events as recording the form's identifier and destination, not what you type), engagement with embedded videos, and page changes made without a reload.

(d) Your browser, device type, operating system, screen size and language.

(e) The time of each event.

(f) Your IP address, which your browser sends with each request to Google. Google states that Google Analytics 4 does not log or store IP addresses, and that it uses the address to estimate your location (country, region and city) before discarding it. The collection of this location and device detail is switched on for all regions.

(g) E-mail addresses, telephone numbers and postal addresses in hashed form, where the Google tag picks them up from a page. Google's "user-provided data collection" is switched on for our measurement ID, with automatic detection of e-mail addresses, telephone numbers and postal addresses. With this setting the Google tag can pick up such data from a page, for example from a form you fill in, and send it to Google in hashed form.

5.5.5 What we see. We see reports about groups of visitors: numbers of visits, pages viewed, files downloaded, countries, devices and browsers. We do not use the Google Analytics User-ID feature. We do not add names, e-mail addresses or other directly identifying data to what the Google tag sends; the tag itself can pick up contact details from a page and send them to Google in hashed form, as described in 5.5.4(g). We do not combine analytics data with contact form data, e-mail or API account data.

5.5.6 Purposes. To understand how the Site is used; to find pages that fail or confuse; to decide what to write and what to fix.

5.5.7 Legal basis. Article 6(1)(f) GDPR, our legitimate interest in understanding how the Site is used. Google Analytics runs without a cookie banner and without asking for your consent (5.5.3). You can object to this processing (11.2(g)), and you can refuse it in your browser as described in 6.6.

5.5.8 Retention. Google Analytics keeps event-level data for the retention period set in our Google Analytics property and then deletes it. For a standard property, Google offers a period of 2 months or 14 months. Reports that contain only totals may be kept longer. The _ga and _ga_3MVKTJGHP4 cookies expire 2 years after your last visit to a page that uses the tag.

5.5.9 Recipients. Google, which provides Google Analytics under the terms of our Google Analytics account. The ExactMetrics plugin runs on our own server. Its optional weekly usage report to its maker is not switched on. The plugin fetches the analytics reports that administrators see in the WordPress dashboard through its maker's reporting service (api.exactmetrics.com).

5.5.10 Transfers. Google processes analytics data in the United States and other countries. See section 8.

5.5.11 Must you provide this data? No. Refusing analytics has no effect on your use of the Site.

5.5.12 Deleting your analytics data. We cannot find analytics data about you from your name or e-mail address, because we do not link them. If you send us the value of the _ga cookie in your browser, we can ask Google to delete the analytics data linked to it.

5.6 Paid API customer accounts

5.6.1 Data we hold for each API account.

(a) Your e-mail address.

(b) Your API token, stored only as a SHA-256 hash (of the token in lower case). We cannot read your token back from the hash.

(c) Whether the account is active.

(d) The date the account was created, and an internal account number.

5.6.2 How requests are checked. Each API request carries your e-mail address and your token in the body of a POST request (the API ignores them if they are put in the web address). The API computes the hash of the token and compares it with the stored hash. The API does not record which customer made which request. The data service keeps only a running count of all the requests it receives, from customers and from the public pages alike. The count is held in memory, is not linked to any account, and restarts from zero when the service restarts.

5.6.3 Source. You, or your organisation when it orders the service for you.

5.6.4 Purposes. To provide the API under contract; to check that a request comes from an active customer; to manage the account and tell you about changes to the service; to bill for the service; to enforce the terms of the licence.

5.6.5 Legal basis.

(a) Article 6(1)(b) GDPR, performance of the contract with you.

(b) Where the contract is with your organisation and not with you: Article 6(1)(f) GDPR, our legitimate interest in managing the contract with your organisation.

(c) Article 6(1)(c) GDPR, for records that tax and accounting law require us to keep.

5.6.6 Retention. While the account is active. After the account ends, we keep the account record for 24 months and then delete it. Invoices and accounting records are kept for the period that tax and accounting law requires.

5.6.7 Recipients. Hetzner Online GmbH (server). A2 Hosting (e-mail with you).

5.6.8 Transfers. See section 8.

5.6.9 Must you provide this data? The contract requires an e-mail address and a token. Without them we cannot provide the API.

5.6.10 Your token. Keep your token secret. If you think someone else has it, tell us at once. Because we store only a hash, we cannot send you your existing token; we issue a new one.

5.7 The MCP Server

5.7.1 What it is. The MCP Server lets AI assistants and other programs request CCi30 index data. Some of its tools are open to everyone. Others are meant for licensees and need a licensed key once keys are issued. At present no licensed key has been issued, and every tool answers without a key.

5.7.2 Rate limit. To stop any one client from overloading the server, the MCP Server counts the requests that each IP address sends by POST (the method the protocol uses for its messages) in windows of 10 seconds and 60 seconds. It accepts up to 10 requests in 10 seconds and 60 requests in a minute. Each count is stored in the Site's database under a name built from the MD5 hash of the IP address. The IP address itself is not stored. A count is used for at most 2 minutes. Counts are deleted by number, not by age: on about one request in 40, the server deletes every count except the newest 200. When the MCP Server receives few requests, a count can therefore stay stored long after its 2 minutes of use, until newer counts replace it.

5.7.3 Usage counts for licensed keys. If you use a licensed key, the MCP Server records, for each day, how many times each tool was called under the label we gave your key. It keeps this record for the most recent 60 days on which the MCP Server was used. Requests without a key are counted together under the label "unauthenticated", with no IP address or other identifier.

5.7.4 Keys. When we issue a licensed key, we store it in the Site's database with the label we give it. Unlike API tokens (5.6.1(b)), licensed keys are stored as issued, not as hashes.

5.7.5 Sending your key. Send your key in the Authorization header (as a "Bearer" token) or the X-Api-Key header. The MCP Server also accepts the key in the web address (?key=), but we advise against it, because web addresses are often kept in the logs and history of the software that sends them.

5.7.6 Sources. Your device (the IP address). Us (the key label).

5.7.7 Purposes. To keep the MCP Server available to everyone; to manage licences; to check that use stays within the licence.

5.7.8 Legal basis.

(a) The rate limit: Article 6(1)(f) GDPR, our legitimate interest in keeping the service available and free of abuse.

(b) Usage counts: Article 6(1)(b) GDPR, performance of the licence with you, or, where the licence is with your organisation, Article 6(1)(f) GDPR, our legitimate interest in managing that licence.

5.7.9 Retention. As stated in 5.7.2 and 5.7.3. Keys and labels: while the licence is in force, then 24 months.

5.7.10 Recipients. Hetzner Online GmbH (server).

5.7.11 Must you provide this data? A program cannot reach the MCP Server without an IP address. A licensed key is needed only for the licensed tools.

5.8 Licensees, data vendors and other business contacts

5.8.1 Data. Name, job title, organisation, business e-mail address, telephone number and postal address; signatures; the terms and scope of licences and other contracts; the entries in our register of licensees; invoices and payment records; correspondence and notes of meetings.

5.8.2 Sources. You; your organisation; public sources such as company websites and public registers, where we look into a prospective licensee.

5.8.3 Purposes.

(a) To negotiate, perform and manage licences and data delivery agreements.

(b) To keep the register of licensees that our index administration requires.

(c) To send correction notices to entitled counterparties when a material error in an official close is corrected, as our index-data page promises.

(d) To deliver data feeds in the format and channel agreed.

(e) To keep accounting and tax records.

5.8.4 Legal basis.

(a) Article 6(1)(b) GDPR, where you are the contracting party.

(b) Article 6(1)(f) GDPR, where the contract is with your organisation: our legitimate interest in managing our business relationships and our index administration.

(c) Article 6(1)(c) GDPR, for records that tax and accounting law require.

5.8.5 Retention. For the duration of the relationship, then for the limitation period for contract claims under the law that governs the contract. Accounting records for the period that tax and accounting law requires.

5.8.6 Recipients. A2 Hosting (e-mail). Hetzner Online GmbH (server). Our professional advisers.

5.8.7 Must you provide this data? We need contact and contract details to enter into and perform a contract.

5.9 WordPress administrator accounts and login protection

5.9.1 Who this covers. The people who manage the Site's content, and anyone who tries to log in to the Site's administration area. Visitors cannot create accounts. The Site has no public user accounts.

5.9.2 Data for administrators.

(a) Login name, e-mail address, display name and role.

(b) Password, stored by WordPress only as a hash.

(c) Interface preferences.

(d) For each active login session, WordPress records the time of login, the time the session expires, the IP address and the browser identification string.

(e) If an administrator turns on two-factor login, the settings of the chosen method, such as the shared secret for an authenticator app and a set of backup codes. The "Two Factor" plugin that provides this is installed.

5.9.3 Login protection. The Site counts failed logins from each IP address, under a name built from the MD5 hash of the address. The count expires 15 minutes after the last failed attempt. After 5 failures, further logins from that address are refused until the count expires. A successful login deletes the count. This applies to anyone who tries to log in.

5.9.4 Analytics. The ExactMetrics plugin is set not to track logged-in administrators and editors with Google Analytics.

5.9.5 Purposes. To manage the Site; to keep the administration area secure.

5.9.6 Legal basis. Article 6(1)(f) GDPR, our legitimate interest in managing the Site and protecting it from unauthorised access. Where an administrator works for us under a contract, Article 6(1)(b) GDPR also applies.

5.9.7 Retention.

(a) Account data: while the person needs access; we delete the account within 30 days after access ends.

(b) Session records: until logout or expiry (2 days, or 14 days if "Remember me" was chosen).

(c) Failed-login counts: used for 15 minutes after the last failed attempt. An expired count is no longer used. WordPress deletes it when a login is next tried from the same address, or in its daily clean-up of expired entries, whichever comes first. No expired count stays in the database for more than about one day.

5.9.8 Recipients. Hetzner Online GmbH (server).

5.9.9 Must you provide this data? An administrator account needs a login name, an e-mail address and a password.

5.10 Error logs, system logs and monitoring alerts

5.10.1 PHP error log. The server records faults in the Site's software: the time, the error message, and the file and line where the error occurred. The log is not designed to hold personal data, but an error message can on occasion contain part of the data that caused the error.

5.10.2 System logs. The operating system records events such as administrator logins to the server, attempts to log in to the server, and connection attempts that the firewall blocks. It also keeps the web server's error records described in 5.1.2. These records include IP addresses, and the web server's error records also include the requested address and the browser details listed in 5.1.2.

5.10.3 Mail delivery records. The Site sends its e-mail through the WP Mail SMTP plugin, which logs in to the info@cci30.com mailbox at A2 Hosting (5.4.6) and sends from that address. The plugin keeps no copy of the messages it sends. When a send fails, it records the time, the error and the recipient's address in the Site's database. For a contact form message the recipient is info@cci30.com; your own address is in the message, not in this record. For other e-mails the Site sends, such as notices to administrators, the record shows the recipient's address. The server also has a mail program of its own, which the Site does not use while the plugin is active. That program writes a mail delivery log: for each e-mail sent through it, the time, the sender and recipient addresses used for delivery, the size of the message and the mail server's reply.

5.10.4 Monitoring alerts. An automatic monitor checks the Site every minute and sends its alerts and daily reports to the people who run the Site, through Telegram. When it finds a serious software error, it sends the text of the error line (up to 600 characters). When all the worker processes that build the Site's pages are busy, it sends one line of their process manager's log (up to 300 characters). When contact form messages are waiting under 5.2.4A, it sends their number, not their content. Its daily reports contain index values, check results and server figures, not personal data.

5.10.5 Purposes. To find and fix faults; to detect attacks; to keep the Site available.

5.10.6 Legal basis. Article 6(1)(f) GDPR, our legitimate interest in running a secure and reliable service.

5.10.7 Retention. The PHP error log and the mail delivery log are rotated every week and deleted after 8 weeks. The system log files are rotated every week and kept for about five weeks. The system journal, which holds the web server's error records (5.1.2) together with other system events, has no time limit: when it reaches its size limit, its oldest entries are deleted first. The web server's error records are also copied into the system log files, where they are kept for about five weeks.

5.10.8 Recipients. Hetzner Online GmbH (server). Telegram (alerts).

5.10.9 Transfers. See section 8.

5.11 Backups and database copies

5.11.1 What is copied. The UpdraftPlus plugin backs up the Site's WordPress database and files every day at 21:30 UTC. The database holds the administrator accounts, the Site's settings, the rate-limit counters, the MCP keys and the MCP usage counts. We keep the 14 most recent database backups and the 3 most recent file backups, so each database backup is kept for 14 days and each file backup for 3 days. Before maintenance work we also make copies of the index database, which holds the API customer records, and before software updates we make a copy of the whole Site and its database.

5.11.2 Where. All backups and copies are kept on the same server as the Site, outside the folders that the web server makes public.

5.11.3 Archive of the previous system. When the index moved to its current server in October 2026, we kept a read-only archive of the previous system's databases on the server. It contains the API customer records of the previous system, with their access tokens, the e-mail addresses and password entries of the user accounts of the previous system's calculators, and a copy of the previous WordPress database with the administrator accounts of that time and the records of their login sessions. Only the server's administrators and the index service can read it.

5.11.4 Purposes. To restore the Site and the index after a fault, an attack or a mistake; to keep a complete record of the index.

5.11.5 Legal basis. Article 6(1)(f) GDPR, our legitimate interest in being able to restore our services and records. The legal basis of the original data also applies.

5.11.6 Retention. Routine backups: 14 days for the database and 3 days for the files (5.11.1). Copies made before maintenance work or software updates: 90 days after the work is checked. The archive of the previous system: see section 9. Data deleted from the live systems remains in backups until the backup is deleted. We do not restore deleted personal data into live use, except to recover from a fault, and in that case we delete it again.

5.11.7 Recipients. Hetzner Online GmbH (server).

5.12.1 Data. We protect the CCi30 index, its data and the CCi30 marks. When we find use that may need a licence, or a dispute arises, we may process: the name of the person or organisation concerned; its website and public materials; the names and business contact details of its representatives; and our correspondence with them.

5.12.2 Sources. Public sources; the person or organisation concerned; people who report a possible infringement to us.

5.12.3 Purpose. To establish, exercise or defend legal claims, and to enforce our licences.

5.12.4 Legal basis. Article 6(1)(f) GDPR, our legitimate interest in protecting our rights.

5.12.5 Retention. Until the matter is closed, then for the limitation period that applies to it.

5.12.6 Recipients. Our lawyers; courts and tribunals; trade mark offices; the other party and its lawyers.

5.13.1 We may keep or disclose personal data where the law requires it, for example to keep tax and accounting records, or to comply with a valid court order or a request from a public authority that has the legal power to require it.

5.13.2 We check each request from an authority. We disclose only the data that the law requires, and we tell the person concerned unless the law forbids it.

5.13.3 Legal basis. Article 6(1)(c) GDPR for obligations under the law of the EU, an EU Member State or the United Kingdom. Article 6(1)(f) GDPR for obligations under other laws, such as US law: our legitimate interest in complying with the law that applies to us.

5.14 Index data contains no personal data

5.14.1 We calculate the index from cryptocurrency market prices and market capitalisations that we buy from data providers. That data contains no personal data. The index values, constituents, weights and statistics we publish contain no personal data. The index methodology is published at https://cci30.com/methodology/.

5.14.2 Each day we prepare a summary of the previous day's index values as four images and a short caption, for publication on social media. They are built from index data only. At present the summary is sent only as a preview to the Telegram accounts of the people who run the Site, and nothing is published on a social network. If we start to publish it on a social network, we will add a description of that account to this policy.

6.1 What they are. Cookies and local storage are defined in 3.1(j) and 3.1(k). Some third-party services also use other browser storage under their own domains. This section covers all of them.

6.2 What the Site uses, in brief.

(a) Our server sets no cookies for an ordinary visitor. It sets cookies only on the login page of the administration area and for administrators who log in (see (d)).

(b) The home page uses analytics cookies from Google Analytics (5.5) and security cookies and storage from Google reCAPTCHA (5.3). No other page uses them.

(c) The Site stores your choice of light or dark theme in local storage, if you make one.

(d) WordPress sets cookies for administrators who log in.

(e) The Site uses no advertising cookies and no social media plugins.

6.3 Categories.

(a) Strictly necessary: needed for a service you asked for, such as logging in, or to record a privacy choice you made. They do not need consent.

(b) Preferences: remember a setting you chose, such as the theme. They are set only when you make the choice, and do not need consent.

(c) Analytics: count visits and measure how the Site is used. The home page sets them without asking for your consent first (5.5.3). You can refuse them as described in 6.6.

(d) Security: help to tell people from automated programs on the contact form. The home page loads them without asking for your consent first (5.3.2, 5.3.7).

6.4 Table of cookies and browser storage. The table lists each cookie and each item of browser storage that the Site uses.

NameType and domainSet byPagesPurposeDurationCategory
_gaCookie, cci30.comGoogle Analytics, through ExactMetricsHome pageHolds a random number that tells one browser from another, so that visits can be counted2 years after your last visitAnalytics
_ga_3MVKTJGHP4Cookie, cci30.comGoogle AnalyticsHome pageHolds the state of the current session, such as the session number and start time2 years after your last visitAnalytics
_gd followed by a numberCookie, cci30.comExactMetricsHome pageA test that finds the right cookie domain for Google Analytics. It is deleted the moment it is setNoneAnalytics
ga-disable-G-3MVKTJGHP4Cookie, cci30.comExactMetricsHome pageRecords that Google Analytics has been switched off in this browser. While it is present, the tag sends nothing to Google. Set only if the plugin's opt-out function is used, and the Site shows no link to that function (6.6.2)Until 31 December 2099, or until you delete itStrictly necessary
_GRECAPTCHACookie, www.google.comGoogle reCAPTCHAHome pageUsed by reCAPTCHA for its risk analysisDecided by GoogleSecurity
rc::a, rc::b, rc::c, rc::d- followed by a numberBrowser storage, www.google.comGoogle reCAPTCHAHome pageUsed by reCAPTCHA to tell people from automated programsDecided by GoogleSecurity
cci30ThemeLocal storage, cci30.comUsAll pagesRemembers whether you chose the light or the dark theme. Written only when you press the theme button. Value: "light" or "dark"Until you clear itPreferences
cci30LightV1Local storage, cci30.comUsHome pageMarks that chart colour settings stored by older versions of the Site have been removed, so that this cleanup runs only once. Value: "1"Until you clear itStrictly necessary
wordpress_test_cookieCookie, cci30.comWordPressLogin pageChecks that your browser accepts cookies before you log inUntil you close the browserStrictly necessary
wordpress_sec_ followed by a codeCookie, cci30.comWordPressAdministration areaHolds the login of an administratorUntil you close the browser, or 14 days if "Remember me" was chosenStrictly necessary
wordpress_logged_in_ followed by a codeCookie, cci30.comWordPressAll pages, for administratorsShows that an administrator is logged inUntil you close the browser, or 14 days if "Remember me" was chosenStrictly necessary
wp-settings- and wp-settings-time- followed by a user numberCookie, cci30.comWordPressAdministration areaStores an administrator's interface preferences1 yearPreferences

6.5 Other Google cookies. If you are signed in to a Google account, or have used Google services before, your browser may send cookies that Google set earlier to Google when reCAPTCHA loads. Those cookies belong to Google, and Google's privacy policy governs them.

6.6 Your choices.

6.6.1 Consent. The Site does not show a cookie banner. It does not ask for your consent before it sets analytics cookies or loads reCAPTCHA. The ways to refuse them are those in 6.6.2 and 6.6.3.

6.6.2 Opting out of Google Analytics. The ExactMetrics plugin contains an opt-out function that sets the ga-disable-G-3MVKTJGHP4 cookie described in 6.4. The Site does not show a link to this function. To stop Google Analytics, use the browser add-on that Google offers, which stops Google Analytics on all websites: https://tools.google.com/dlpage/gaoptout. Blocking scripts from www.googletagmanager.com, in your browser or with a content blocker, also stops it on the Site.

6.6.3 Browser settings. You can block or delete cookies, and clear the storage that a site has left in your browser ("site data"), in your browser's settings. If you do:

(a) all public pages of the Site still work;

(b) the Site forgets your theme choice;

(c) reCAPTCHA may not work, so the contact form may refuse your message; write to info@cci30.com instead;

(d) administrators cannot log in without cookies.

6.7 Do Not Track and Global Privacy Control.

6.7.1 Do Not Track. Some browsers send a "Do Not Track" signal. There is no agreed standard for how a website should respond to it, and the Site does not change its behaviour when it receives one.

6.7.2 Global Privacy Control. We treat a Global Privacy Control signal as a request to opt out of the sale and sharing of your personal data. We do not sell or share personal data (14.4), so the signal does not change anything else. In particular, it does not switch off Google Analytics; see 6.6.2 for that.

6.8 Changes. We update the table in 6.4 when we add, change or remove a cookie or an item of browser storage.

7. Who receives personal data

7.1 We do not sell personal data. We disclose it only to the recipients in this section, and only the data each one needs.

7.2 Service providers.

RecipientRoleDataLocationSafeguard for transfers (section 8)
Hetzner Online GmbH, GermanyProcessor: server and networkAll data processed by the Site, the API and the MCP Server, the logs, the kept copies of contact form messages (5.2.4A), and the backups and archives kept on the serverUnited States, according to the RIPE network registry (5.1.11)See 8.2 to 8.4
A2 Hosting, United StatesProcessor: e-mail hosting for cci30.comE-mail sent to and from addresses at cci30.com, including contact form messagesUnited States, according to the ARIN network registry (5.4.7)See 8.2 to 8.4
GoogleProvider of Google Analytics and of reCAPTCHA, each under Google's terms for that service (5.3.9, 5.5.9)Analytics data (5.5); reCAPTCHA data (5.3)United States and other countriesSee 8.3
TelegramMessaging service used for monitoring alerts and for the preview of the daily social postText of serious error lines and of process manager warnings; the number of kept contact form messages, without their content (5.10.4); index summaries (5.14.2)Telegram's serversSee 8.3

7.3 Other recipients.

(a) Our staff and contractors who run the Site, the index and our business, and only to the extent their work requires.

(b) Our parent company, CS&P SA, Panama, if it needs personal data to oversee our business, and then only the data it needs.

(c) Professional advisers, such as lawyers, accountants and auditors, who are bound by duties of confidentiality.

(d) Courts, authorities and other parties to a legal matter, as described in 5.12 and 5.13.

(e) A buyer or successor. If all or part of our business is sold, merged or reorganised, personal data may pass to the new owner. The new owner must use it as this policy describes, or tell you before it makes a change.

7.4 Our processors. Hetzner Online GmbH and A2 Hosting process personal data for us to provide the server and the e-mail service we use, under the terms of our accounts with them.

7.5 We do not disclose personal data to data brokers or to advertisers.

8. International transfers

8.1 Where your data goes. We are in the United States. Our server is on Hetzner's network in the United States (5.1.11), and our mail server is on A2 Hosting's network in the United States (5.4.7). If you are in the EEA, the United Kingdom, Switzerland or Brazil, your personal data is processed in the United States and may be processed in other countries where our providers work. The data protection laws of those countries may give less protection than the laws where you live, and public authorities there may be able to access the data under their own laws.

8.2 Data you send to us. When you send personal data to us, you send it to a controller in the United States. We apply this policy to all personal data we hold, wherever you live, and the GDPR or the UK GDPR applies to our processing where Article 3(2) of either makes it apply.

8.3 Safeguards for onward transfers. Where we send personal data from the EEA, the United Kingdom or Switzerland to a recipient in a country without an adequacy decision, or where our contracts with a recipient require it, we use one of these safeguards:

(a) the recipient's certification under the EU-U.S. Data Privacy Framework, the UK Extension to it and the Swiss-U.S. Data Privacy Framework, where the recipient is certified and the transfer falls within its certification;

(b) the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, with the UK International Data Transfer Addendum for data from the United Kingdom and with the amendments needed for data from Switzerland;

(c) for occasional transfers only, the derogations in Article 49 GDPR, such as a transfer necessary to perform a contract with you, or to establish, exercise or defend legal claims.

8.4 Our providers. Hetzner Online GmbH is a company in Germany. The server it provides to us is on its network in the United States (5.1.11). A2 Hosting is a hosting company in the United States (5.4.6). Google processes data in the United States and other countries (5.3.10, 5.5.10).

8.5 Copies. You can ask us which safeguard applies to a transfer of your data, and for a copy of any safeguard we use (2.2). We may remove commercial terms from a copy.

8.6 Data Privacy Framework. CSP DAO LLC is not certified under the EU-U.S. Data Privacy Framework, the UK Extension to it or the Swiss-U.S. Data Privacy Framework.

8.7 Brazil. Transfers of personal data of people in Brazil follow Article 33 of the LGPD. Where a transfer needs a contractual safeguard, we use the standard contractual clauses approved by the Brazilian National Data Protection Authority (ANPD).

9. How long we keep personal data

9.1 We keep personal data only for as long as we need it for the purpose for which we collected it, or for as long as the law requires. The table below sets out each period.

DataPeriodAt the end of the period
IP address and request details when you use the Site (5.1)Not stored; held in memory while the request is handledDiscarded
Web server error records of failed requests (5.1.2, 5.10.2)In the system journal, no time limit: kept until the journal reaches its size limit. In the system log files, about five weeks (5.10.7)Deleted, oldest first, when the journal reaches its size limit; deleted by log rotation from the system log files
Contact form rate-limit counter (5.2.3)Until the daily clean-up after the counter is more than one day oldDeleted
Copies of contact form messages that the mail server refused (5.2.4A)Until delivered or forwarded, and at most 30 days after the copy was keptDeleted
Contact form messages and other e-mail (5.4)24 months after the last message in the conversation; longer if a contract follows (see licensees)Deleted
reCAPTCHA data (5.3)Not kept by usGoogle's own policies apply
Google Analytics event data (5.5)The retention period set in our Google Analytics property; for a standard property Google offers 2 months or 14 months (5.5.8)Deleted by Google
Google Analytics cookies (6.4)2 years after your last visitExpire in your browser
API account records (5.6)While the account is active, then 24 monthsDeleted
MCP rate-limit counters (5.7.2)Used for at most 2 minutes; then kept until newer counts replace them, because only the newest 200 counts are keptDeleted
MCP usage counts per licensed key (5.7.3)The most recent 60 days on which the MCP Server was usedOverwritten
MCP keys and labels (5.7.4)While the licence is in force, then 24 monthsDeleted
Licensee and business contact records (5.8)The relationship, then the limitation period for contract claims under the law that governs the contractDeleted
Invoices and accounting records (5.6, 5.8)The period that tax and accounting law requiresDeleted
Administrator accounts (5.9)While access is needed, then 30 daysDeleted
Administrator session records (5.9)Until logout, or 2 days, or 14 days with "Remember me"Deleted
Failed-login counters (5.9.3)Used for 15 minutes after the last failed attemptExpire, then deleted at the next attempt from the same address or by the daily clean-up, which also removes contact form counters more than one day old
PHP error log and mail delivery log (5.10)8 weeksDeleted by weekly log rotation
System log files and system journal (5.10)System log files: about five weeks. System journal: no time limit; kept until it reaches its size limitDeleted by weekly log rotation; journal entries deleted, oldest first, at the size limit
Routine backups (5.11)Database backups 14 days; file backups 3 daysDeleted when newer backups replace them
Copies made before maintenance work or software updates (5.11)90 days after the work is checkedDeleted
Archive of the previous system (5.11.3)Kept as the record of the previous system. No end date has been setDeleted when it is no longer needed as that record
Spam comments left in the WordPress database by the previous site (2021 and 2023)Not kept: we delete themDeleted
Records of legal matters (5.12)Until the matter is closed, then the limitation periodDeleted
Records of privacy requests and our replies (section 12)24 months after the replyDeleted

9.2 When a period ends, we delete the data or make it anonymous so that it can no longer be linked to you. Where data cannot be deleted from a backup at once, it stays in the backup until the backup is deleted, and we do not use it in the meantime.

9.3 We may keep data longer if the law requires it, or if we need it to establish, exercise or defend a legal claim. In that case we keep only the data needed, and only until the matter ends.

10. How we protect personal data

10.1 We use technical and organisational measures that fit the kind of data we hold and the risks to it. They include the following.

(a) Encrypted connections. The Site, the API and the MCP Server are reachable only over HTTPS. Plain HTTP requests are redirected to HTTPS. The Site sends a Strict-Transport-Security header that tells browsers to use HTTPS for cci30.com and all its subdomains for one year.

(b) Browser protections. The Site sends headers that stop other websites from showing our pages inside a frame, limit the information sent to other websites when you follow a link (only "https://cci30.com" is sent, not the full page address, and nothing at all is sent to a website that does not use HTTPS), and switch off camera, microphone, location, payment and USB access for our pages.

(c) Server access. A firewall admits only web traffic and administrative access. Administrative access to the server uses cryptographic keys, not passwords. The index service accepts connections only from inside the server.

(d) Login protection. Failed logins are limited to 5 per address in 15 minutes. The XML-RPC interface and application passwords are switched off. The list of user accounts is hidden from the public. A second login step (two-factor authentication) is available for administrator accounts.

(e) Secrets. The API stores tokens only as SHA-256 hashes. Licensed MCP keys are stored as issued (5.7.4). The archive of the previous system holds that system's access tokens as that system stored them (5.11.3). Passwords and keys for our services are kept in configuration files that the web server does not serve to the public, with file permissions that limit who can read them. The archive of the previous system and the copies of the index database can be read only by the server's administrators and the index service.

(f) Data minimisation. The web server keeps no access logs; it records an IP address only in the error record of a request that fails (5.1.2). IP addresses used for rate limits are stored only as hashes, and are deleted as set out in 5.2.3, 5.7.2 and 5.9.7.

(g) Access control. Only the people who run the Site and the index can reach the server and the mailboxes, and only to the extent their work requires.

(h) Monitoring. Automatic checks run every minute and alert the people who run the Site.

10.2 No system is completely secure. We cannot promise that data sent over the internet or stored on a server will never be accessed without permission.

10.3 Personal data breaches. If a breach of personal data occurs, we will:

(a) notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, where Article 33 GDPR or UK GDPR requires it;

(b) tell the people affected without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Article 34 GDPR and UK GDPR);

(c) give the notices that US state breach notification laws require;

(d) keep a record of every breach, its effects and the action we took.

10.4 Your part. Keep your API token and any licensed key secret. Do not send sensitive data by e-mail (5.4.9). Tell us at once if you think your token or key has been exposed.

11. Your rights in the EEA, the United Kingdom and Switzerland

11.1 When these rights apply. The rights in this section apply where the GDPR or the UK GDPR applies to our processing of your personal data. In general, that is the case when you are in the EEA or the United Kingdom and we offer you our services or measure your use of the Site.

11.2 Your rights.

(a) Access (Article 15). You can ask whether we process personal data about you. If we do, you can have a copy of it, and information about the purposes, the categories of data, the recipients, the retention period, the source, your rights, and the safeguards for transfers.

(b) Rectification (Article 16). You can ask us to correct inaccurate data and to complete incomplete data.

(c) Erasure (Article 17). You can ask us to delete your data, for example where we no longer need it, where you withdraw consent and no other legal basis applies, where you object and we have no overriding grounds, or where the processing is unlawful. We may refuse where the law requires us to keep the data or where we need it for a legal claim.

(d) Restriction (Article 18). You can ask us to hold your data without using it: while we check whether it is accurate, where the processing is unlawful but you prefer restriction to deletion, where we no longer need the data but you need it for a legal claim, or while we consider an objection.

(e) Notification (Article 19). When we correct, delete or restrict your data, we tell each recipient to whom we disclosed it, unless that is impossible or would need a disproportionate effort. On request, we tell you who those recipients are.

(f) Portability (Article 20). For data you gave us, which we process by automated means on the basis of your consent or a contract, you can receive the data in a structured, commonly used and machine-readable format, and ask us to send it to another organisation where this is technically feasible. For us this covers, for example, your API account record and the messages you sent us.

(g) Objection (Article 21). You can object, on grounds relating to your particular situation, to processing based on our legitimate interests (Article 6(1)(f)). We will then stop, unless we show compelling legitimate grounds that override your interests, rights and freedoms, or need the data for a legal claim. You can always object to direct marketing; we do not send any.

(h) Withdrawal of consent (Article 7(3)). Where we rely on your consent, you can withdraw it at any time, by the same means you used to give it. Withdrawal does not affect processing that took place before it.

(i) Automated decisions (Article 22). You have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you. We make no such decisions (section 18).

(j) Complaint (Article 77). You can complain to a supervisory authority (section 13).

11.3 When we cannot identify you. Some data we hold cannot be linked to you by name: the hashed rate-limit counters, and Google Analytics data, which we can find only through its random cookie identifier. If we cannot identify you in a set of data, we will tell you (Articles 11 and 12(2)). If you give us information that lets us find your data, such as the value of your _ga cookie, we will act on your request.

11.4 Limits. The law may limit a right in some cases, for example where acting on a request would reveal personal data about another person, or where the data is needed for a legal claim. If we refuse a request in whole or in part, we tell you why (12.6).

11.5 Switzerland. If you are in Switzerland, you have similar rights under the Swiss Federal Act on Data Protection, including the rights of access, correction, deletion, objection and data portability. You can complain to the Federal Data Protection and Information Commissioner (13.4).

12. How to exercise your rights

12.1 How to ask. Write to the e-mail address or the postal address in 2.2. Tell us who you are, which right you want to exercise, which data or activity your request concerns, and how we can reach you. No special form is needed.

12.2 Checking who you are. We check your identity in proportion to the request, so that we do not disclose or delete someone else's data. In most cases we reply to the e-mail address we already hold for you. For an API account, we may ask you to confirm details that only the account holder knows. We do not ask for identity documents unless there is no other way, and we delete any information we receive for this check once the check is done.

12.3 Time limits.

(a) GDPR and UK GDPR: within one month of receiving your request. Where a request is complex or one of many, we may extend this by up to two further months; if we do, we tell you within the first month and explain why.

(b) California: we confirm receipt within 10 business days and reply within 45 calendar days. Where needed, we may extend once by a further 45 calendar days; if we do, we tell you within the first 45 days.

(c) Other US states: within 45 days, extendable once by 45 days where the state's law allows.

(d) Brazil: confirmation and access at once in simplified form, or within 15 days as a complete statement (16.4).

12.4 Fees. We do not charge for a request. Where a request is manifestly unfounded or excessive, in particular because it repeats an earlier request, we may charge a reasonable fee based on our costs, or refuse to act, and we will explain why.

12.5 Agents. You may ask another person to make a request for you. We may ask for your signed permission and may check your identity with you directly.

12.6 If we refuse. If we do not act on a request, we tell you why, and tell you how to complain (section 13) or appeal (15.3).

12.7 Our record. We keep a record of each request and our reply for 24 months (section 9) to show that we handled it correctly.

13. Complaints

13.1 If you have a concern, please write to us first (2.2). We will try to resolve it. You do not have to contact us before you complain to an authority.

13.2 EEA. You can complain to the supervisory authority of the EEA Member State where you usually live, where you work, or where you think the infringement took place (Article 77 GDPR). We have no establishment in the EEA, so no single authority leads on our processing, and you may choose. The list of authorities is at https://www.edpb.europa.eu/about-edpb/our-members_en.

13.3 United Kingdom. You can complain to the Information Commissioner's Office: https://ico.org.uk/make-a-complaint/.

13.4 Switzerland. You can complain to the Federal Data Protection and Information Commissioner: https://www.edoeb.admin.ch/en.

13.5 Brazil. You can complain to the National Data Protection Authority (ANPD): https://www.gov.br/anpd.

13.6 California. You can contact the California Privacy Protection Agency (https://cppa.ca.gov) or the California Attorney General (https://oag.ca.gov/privacy).

13.7 You may also have the right to take your case to a court (Article 79 GDPR).

14. Notice for California residents

14.1 Scope. This section applies to residents of California. It follows the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (together, the "CCPA"), and the regulations made under it.

14.2 Personal information we collect. In the past 12 months we collected the categories below. This table is also our notice at collection.

CCPA categoryWhat we collectSourcesPurposesDisclosed for a business purpose toRetention
IdentifiersName, e-mail address, IP address (handled in transit; stored in clear only in web server error records and administrator session records, and otherwise only as a hash for rate limits), cookie identifier, hashed contact details (an e-mail address, telephone number or postal address) where the Google tag picks them up from a page (5.5.4(g)), API account number, MCP key labelYou; your browser or programAnswering you; providing the API and MCP Server; security; analyticsHosting provider; e-mail provider; GoogleSection 9
Personal information listed in Cal. Civ. Code § 1798.80(e)Name, postal address, telephone numberYou; your organisationContracts; billingHosting provider; e-mail providerSection 9
Commercial informationLicences and API services you obtained or asked aboutYou; our recordsContracts; accountingHosting provider; e-mail provider; professional advisersSection 9
Internet or other electronic network activity informationPages viewed, links clicked and files downloaded (analytics); interaction data for reCAPTCHA; daily usage counts per licensed MCP keyYour browser or programAnalytics; security; licence managementGoogle; hosting providerSection 9
Geolocation dataApproximate location (country, region, city) estimated by Google from your IP address. Not precise geolocationGoogle, from your IP addressAnalyticsGoogleSection 9
Professional or employment-related informationJob title and employer of business contactsYou; your organisation; public sourcesManaging business relationshipsHosting provider; e-mail providerSection 9
Sensitive personal informationAccount log-in: the e-mail address of an API account with its token (the token is stored only as a hash); administrator login name with password (stored only as a hash)YouOnly to authenticate you and provide the service you asked forHosting providerSection 9

14.3 What we do not collect. We do not collect characteristics of protected classifications, biometric information, precise geolocation, government identifiers, payment card numbers through the Site (19.8), education information, or inferences used to build a profile about you.

14.4 Sale and sharing. We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done either in the past 12 months. We have no actual knowledge of selling or sharing the personal information of consumers under 16.

14.5 Sensitive personal information. We use sensitive personal information only to authenticate you and to provide the service you asked for. We do not use it to infer characteristics about you. Because of this, the right to limit its use does not apply.

14.6 Your rights.

(a) Right to know. You can ask us to tell you the categories of personal information we collected about you, the categories of sources, the purposes, the categories of recipients, and the specific pieces of personal information we hold about you.

(b) Right to delete. You can ask us to delete personal information we collected from you, subject to the exceptions in the CCPA (for example where we must keep it to complete a transaction, for security, or to comply with a legal obligation).

(c) Right to correct. You can ask us to correct inaccurate personal information.

(d) Right to opt out of sale or sharing. We do not sell or share personal information. We treat a Global Privacy Control signal as an opt-out (6.7.2).

(e) Right to limit the use of sensitive personal information. This does not apply (14.5).

(f) Right not to be discriminated against. We will not deny you a service, charge you a different price, or give you a different quality of service because you exercised your rights.

14.7 How to exercise your rights. E-mail us at the address in 2.2. We operate online and have a direct relationship with the people whose personal information we hold, so e-mail is our method for requests. We verify requests as described in 12.2, matching information you give us with information we hold. For a request for specific pieces of information or for deletion, we may need more matching points. An authorised agent may make a request for you as described in 12.5.

14.8 Shine the Light. We do not disclose personal information to third parties for their own direct marketing purposes (Cal. Civ. Code § 1798.83).

14.9 Do Not Track. See 6.7.1. This disclosure is made under the California Online Privacy Protection Act.

14.10 Content posted by minors. The Site does not let users post content, so there is nothing for a minor to ask us to remove under Cal. Bus. & Prof. Code § 22581.

15. Residents of other US states

15.1 Several US states, among them Colorado, Connecticut, Oregon, Texas and Virginia, have consumer privacy laws. They give residents rights to confirm whether a business processes their personal data, to access, correct and delete it, to obtain a copy, and to opt out of targeted advertising, the sale of personal data and certain kinds of profiling. Each law applies to a business only above its own thresholds. We do not use personal data for targeted advertising, do not sell it, and do not carry out profiling that produces legal or similarly significant effects.

15.2 If you live in one of these states, you can make a request as described in section 12.

15.3 Appeals. If we decline your request, you can appeal by replying to our decision with "Appeal" in the subject line. We will answer within the period your state's law sets (45 to 60 days, extendable where the law allows) and explain our reasons. If we deny the appeal, you can contact your state's Attorney General.

16. Notice for people in Brazil (LGPD)

16.1 Scope. This section applies to our processing of the personal data of people in Brazil under Law No. 13,709/2018, the General Personal Data Protection Law (LGPD).

16.2 Legal bases. The legal bases in Article 7 of the LGPD apply to our processing as follows:

(a) consent (Article 7, I): none of the processing described in this policy relies on consent;

(b) performance of a contract or preliminary steps at your request (Article 7, V), for API accounts, licences and enquiries about them;

(c) compliance with a legal or regulatory obligation (Article 7, II), for records the law requires;

(d) the regular exercise of rights in judicial, administrative or arbitration proceedings (Article 7, VI), for legal claims;

(e) legitimate interests (Article 7, IX, and Article 10), for answering correspondence, security, reCAPTCHA, rate limits, analytics, logs and backups.

16.3 Your rights (Article 18). You can ask us for:

(a) confirmation that we process your personal data;

(b) access to it;

(c) correction of incomplete, inaccurate or out-of-date data;

(d) anonymisation, blocking or deletion of data that is unnecessary or excessive or that is processed in breach of the LGPD;

(e) portability of your data to another provider, under the rules of the ANPD;

(f) deletion of data processed with your consent, except where the LGPD allows us to keep it;

(g) information about the public and private entities with which we share your data;

(h) information about your option not to give consent, and what follows if you do not;

(i) withdrawal of consent.

You can also object to processing carried out on another legal basis if it breaches the LGPD, and ask for a review of decisions taken solely on automated processing (Article 20). We take no such decisions (section 18).

16.4 How to exercise your rights. As described in section 12. We confirm whether we process your data, or give access, at once in simplified form, or within 15 days as a complete statement (Article 19).

16.5 Transfers. See 8.7.

16.6 Person in charge (encarregado). Requests and questions for the person in charge of the processing of personal data (encarregado), and any other request from people in Brazil, go to the address in 2.2.

16.7 Complaints. You can complain to the ANPD (13.5).

17. Children

17.1 The Site, the API and the MCP Server are meant for adults and professional users. They are not directed at children. We do not knowingly collect personal data from anyone under 16. In the United States, we do not knowingly collect personal information from children under 13.

17.2 If you believe that a child has given us personal data, write to us (2.2) and we will delete it.

18. Automated decisions and profiling

18.1 We make no decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.

18.2 Some automated checks do run:

(a) reCAPTCHA (5.3) may cause the contact form to refuse a message;

(b) rate limits refuse requests above set numbers: 20 contact form messages per hour per address (5.2.3); 10 MCP Server requests in 10 seconds and 60 in a minute per address (5.7.2); 5 failed logins in 15 minutes per address (5.9.3).

These checks protect the service. They have no legal or similarly significant effect on you. You can always write to info@cci30.com. The MCP Server and login limits lift within minutes; the contact form limit lifts within an hour.

18.3 Google Analytics produces statistics about groups of visitors. We do not use it to evaluate or predict anything about you as a person, and we do not use it for advertising.

19. What we do not do

19.1 We do not sell or rent personal data.

19.2 We do not show advertising, and we do not use advertising cookies or advertising networks.

19.3 We do not send newsletters or marketing e-mail.

19.4 We do not ask for special categories of personal data, such as data about health, religion, political opinions or ethnic origin. Please do not send us any.

19.5 We do not use social media plugins that send data to social networks when you open a page.

19.6 We do not track logged-in administrators and editors with analytics.

19.7 We do not keep web server access logs. The web server records an IP address only when a request fails (5.1.2).

19.8 The Site does not take payments and does not collect payment card numbers.

19.9 The Site has no public user accounts and no comments.

20.1 The Site links to other websites, for example Wikipedia, LinkedIn, Google Scholar (on the academic literature page) and the websites of other index providers, such as S&P Global, CME Group and CF Benchmarks. Those websites have their own privacy policies, and we are not responsible for their practices.

20.2 When you follow a link, your browser sends the other website your IP address and browser details. Our Site tells your browser to send the other website only the address "https://cci30.com" as the referring page, not the full address of the page you were on.

20.3 If Google Analytics runs, a click on a link to another website is recorded as an event (5.5.4(c)).

21. Changes to this policy

21.1 We update this policy when our processing changes or when the law requires it.

21.2 The version number and the date at the top of the policy show when it last changed.

21.3 For a material change, we will post a notice on the Site for 30 days and e-mail our API customers and licensees. Where a change needs your consent, we will ask for it before the change applies to you.

21.4 Earlier versions are available on request (2.2).

22. Version and effective date

22.1 Version 1.0. Effective 10 October 2026. Published at https://cci30.com/privacy/.

22.2 Questions about this policy: info@cci30.com.