Privacy Policy
1. Data Controller
The controller within the meaning of the General Data Protection Regulation is:
Asset Allocation Aktiengesellschaft
Investment and Consulting
Widenmayerstraße 15
80538 Munich
Germany
Phone: +49 89 9973 8050
Fax: +49 89 9973 8055
Email: info@assetallocation.de
Website: www.assetallocation.de
Represented by: Dr. Christian Dinzl, Member of the Executive Board
2. General Information on Data Processing
We process personal data only to the extent necessary to provide our website, process inquiries, register user accounts, send our newsletter, or fulfill legal, contractual, and regulatory obligations.
Personal data refers to any information relating to an identified or identifiable natural person. This includes, for example, name, email address, phone number, IP address, or information submitted via forms.
3. Categories of Data
Depending on how you use our website, we process the following categories of personal data in particular:
First and last name
Company
Position within the company
Email address
Phone number
Subject and content of messages
Registration data for user accounts
Username and user status, if a WordPress user account is created
Date and time of registration
Newsletter subscription data
Date and time of newsletter subscription and confirmation
IP address when visiting the website, form submission, registration, and newsletter confirmation
technical access data, such as browser type, operating system, referrer URL, date and time of access
usage data related to the newsletter, in particular opens and clicks
4. Website Hosting and Server Log Files
When you visit our website, we process data that is technically necessary to deliver the website, ensure its stable operation, and protect it from misuse. This may include, in particular, your IP address, the date and time of your visit, the pages you viewed, the amount of data transferred, your browser, operating system, and referrer URL.
The purpose of the processing is to ensure the technical operation of the website, system security, error analysis, and the prevention of misuse.
The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in ensuring the secure, stable, and functional operation of our website.
Server log files are stored for 30 days and then deleted or anonymized, unless longer storage is necessary to investigate security incidents.
Our website is hosted by netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany. The server is located in Vienna. We have a contract with netcup for data processing in accordance with Article 28 of the GDPR.
5. WordPress and Technically Required Features
Our website is powered by WordPress. Technically necessary cookies or similar technologies may be used to enable basic website functions. These include, in particular, login functions, form functions, page display, security, and session management.
The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in providing our website in a secure and user-friendly manner.
The fonts used on the website are loaded locally. As a result, no personal data is transmitted to external font providers.
6. Contact Form and Contacting Us
If you contact us via the contact form, by email, phone, fax, or any other means, we will process the data you provide in order to handle your inquiry.
The following data is processed via the contact form:
- First Name and Last Name
- Email address
- Phone number
- Subject
- Message
The purpose of the processing is to handle and respond to your inquiry, as well as to document the communication.
Data processing is carried out pursuant to Article 6(1)(f) of the GDPR. Our legitimate interest lies in the efficient handling and documentation of inquiries.
We store the data from contact requests for as long as is necessary to process the request. If the request results in a business relationship or if there are legal retention requirements, we store the data in accordance with the statutory retention periods.
Data submitted via the form plugin is stored in WordPress in addition to being forwarded by email. This data is stored for internal processing, traceability, and documentation of incoming contact, registration, and newsletter requests. The stored form submissions are not automatically deleted; instead, they are manually reviewed at regular intervals and deleted as soon as they are no longer required for the respective purposes and there are no legal, contractual, or regulatory retention obligations that prevent their deletion.
7. Registration and User Account
On our website, you can register by filling out a registration form. After submitting the form, a WordPress user account can be created for you. The account is not created or activated automatically; it is done only after an internal review.
As part of the registration process, we process the following data:
- First Name and Last Name
- Company
- Role within the company
- Email address
- Phone number
- Message
- Date of Registration
- IP address
- Registration Status
- if applicable, the username and user role in the WordPress system
The purpose of the processing is to verify registration, create and manage the user account, provide access to restricted areas of the website, and communicate with the user regarding the user account.
To the extent that processing is carried out for the purpose of securely managing the website and preventing misuse, the legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in the secure and controlled provision of protected content.
User accounts and the associated data are stored for as long as the user account exists or as long as statutory retention requirements apply. Users may request the deletion of their user account, provided that no statutory, contractual, or regulatory retention requirements prevent it.
Registered users have access to information about Asset Allocation AG’s product partners, as well as documents, podcasts, and webcasts on the strategies offered by those partners. This information consists of research, market analyses, and strategy papers in the context of portfolio management. The target audience is institutional investors who qualify as eligible counterparties.
Documents that explicitly describe specific products from product partners are published only for products approved for public distribution in the EU.
8. Newsletter
You can sign up for our newsletter on our website. We use a dedicated form for sign-up. The data is transmitted via an API to the newsletter service provider Brevo.
When you sign up for our newsletter, we process the following data:
- First Name
- Last Name
- Email address
- Date of Registration
- Date of Confirmation
- IP Address Upon Login
- and the confirmation status of the consent
Subscription is handled via the double opt-in process. This means that after you sign up, you will receive an email asking you to confirm your subscription. Your newsletter subscription will not become active until you have confirmed it.
The purpose of the processing is to send our newsletter, to verify your consent, and to manage subscriptions and unsubscriptions.
The legal basis for sending the newsletter is your consent pursuant to Article 6(1)(a) of the GDPR. The storage of proof of registration is based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in being able to provide evidence of the consent given.
You may withdraw your consent at any time, effective for the future. To do so, you can use the unsubscribe link in the newsletter or contact us using the contact information provided above. Withdrawal of consent does not affect the lawfulness of the processing that took place prior to the withdrawal.
9. Sending Newsletters with Brevo and Tracking Newsletter Performance
We use Brevo to send out and manage our newsletter.
The provider is:
Brevo GmbH
126 Köpenicker Street
10179 Berlin
Germany
Brevo processes personal data on our behalf. A contract for data processing must be entered into or has been entered into with Brevo in accordance with Article 28 of the GDPR.
As part of our newsletter distribution process, we use anonymized data to analyze opens and clicks. This involves processing statistical information about whether newsletters were opened and which links were clicked. The analysis is conducted anonymously and is not used to evaluate individual recipients personally or to create individual user profiles. The analysis serves solely to better assess and improve the reach, technical delivery, and relevance of our newsletter content.
The legal basis for sending the newsletter is your consent pursuant to Article 6(1)(a) of the GDPR. The anonymized statistical analysis is conducted on the basis of our legitimate interest pursuant to Article 6(1)(f) of the GDPR to improve the technical aspects and content of our newsletter.
You may revoke your consent to receive the newsletter at any time, effective for the future, by using the unsubscribe link in the newsletter or by contacting us. Revocation does not affect the lawfulness of the processing that took place prior to the revocation.
10. Email Communication via Outlook / Exchange Online
We use Outlook / Exchange Online as part of Microsoft 365 for email communication.
The provider is:
Microsoft Ireland Operations Ltd.
Carmanhall Road
Sandyford Industrial Estate
Dublin 18
Ireland
In this process, personal data such as name, email address, communication content, metadata, calendar entries, and attachments may be processed by Microsoft. This processing is carried out for the purpose of providing, securing, and managing email communication.
A data processing agreement with Microsoft has been entered into for the use of Exchange Online in accordance with Article 28 of the GDPR.
The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in ensuring reliable, secure, and efficient email communication.
Microsoft generally processes data within the European Union or the European Economic Area as part of Microsoft 365, to the extent that this is intended for the respective service. However, in connection with the operation, maintenance, security, and support of the services, processing or access outside the EU or the EEA cannot be completely ruled out. To the extent that personal data is transferred to third countries in this context, such transfers are made on the basis of appropriate safeguards within the meaning of the GDPR, in particular based on EU Standard Contractual Clauses or other applicable data protection mechanisms.
11. No web analytics or marketing tracking on the website
As of now, we do not use any web analytics tools such as Google Analytics or any comparable marketing tracking tools on our website.
Any content not authored by AAA is embedded without web analytics or marketing tracking tools.
External content used for web analytics or marketing tracking is generally not included. In particular, no external fonts, maps, social media plugins, or similar third-party content is loaded.
Should we use analytics, marketing, remarketing, or tracking services, or external content in the future, this Privacy Policy will be updated accordingly. If consent is required for such use, we will obtain it in advance.
12. Cookies and Technically Necessary Technologies
Our website currently uses only technically necessary cookies and similar technologies, to the extent that they are necessary for the operation of the website. These may include, in particular, cookies for login, security, session management, and form functions.
The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in ensuring the technically error-free and secure operation of our website.
13. Recipients and Data Processors
We disclose personal data only if it is necessary to fulfill the stated purposes, if there is a legal obligation to do so, if consent has been given, or if there is another legal basis for doing so.
Recipients or categories of recipients may include, in particular:
- Web Hosting Providers
- IT Service Provider and Website
- Maintenance Service Provider
- Email service provider
- Newsletter service provider Brevo
Form and website systems, particularly WordPress and Formidable Forms - Tax advisors, certified public accountants, legal advisors, as needed
- Government agencies, regulatory bodies, and courts, to the extent that there is a legal obligation to do so
Where necessary, we enter into data processing agreements with data processors in accordance with Article 28 of the GDPR.
14. Transfer to Third Countries
Personal data will only be transferred to countries outside the European Union or the European Economic Area if there is an appropriate legal basis for such a transfer under data protection law, such as an adequacy decision by the European Commission, EU Standard Contractual Clauses, or explicit consent.
As of now, the website itself does not include any external content, externally loaded fonts, or web tracking services that would trigger a transfer to a third country.
When using service providers—in particular Microsoft Exchange Online, Brevo, hosting providers, and their subprocessors—processing or access outside the EU or the EEA cannot be completely ruled out. To the extent that personal data is transferred to third countries, this is done only on the basis of appropriate safeguards within the meaning of the GDPR, in particular based on EU Standard Contractual Clauses, an adequacy decision, or other applicable data protection mechanisms.
Where necessary, contracts for data processing in accordance with Article 28 of the GDPR have been entered into with the data processors used.
15. Data Processing Based on Legal Obligations
As a financial services company, we may be subject to legal obligations regarding documentation, proof, retention, and cooperation. To the extent that personal data is processed due to legal obligations, this is done pursuant to Article 6(1)(c) of the GDPR.
This may relate, in particular, to obligations under commercial, tax, regulatory, and anti-money laundering laws.
16. Retention Period
We store personal data only for as long as is necessary for the respective purposes or as required by statutory retention periods.
Contact requests are deleted as soon as the request has been fully processed and there are no legal retention requirements that prevent this.
Registration data and user accounts are stored for as long as the user account remains active or as long as statutory, contractual, or regulatory retention requirements apply.
Newsletter data is stored for as long as the newsletter subscription remains active. After unsubscribing, data required to verify consent may continue to be stored for as long as necessary to defend against or assert claims.
17. Obligation to Provide Personal Data
Providing personal data is generally not required by law to use the website. However, certain information is required for specific features, such as the contact form, registration, or newsletter.
Without this data, we cannot provide the relevant feature, process the request, verify a user account, or send a newsletter.
18. Automated Decision-Making and Profiling
We do not use automated decision-making, including profiling, on this website that produces legal effects concerning you or similarly significantly affects you.
Newsletter tracking is used for statistical analysis and to optimize our newsletter communications. This does not involve any automated decision-making with legal consequences.
19. Data Security
We take appropriate technical and organizational measures to protect personal data from loss, misuse, unauthorized access, disclosure, alteration, or destruction.
Our website uses an encrypted connection via TLS/SSL. You can usually tell that a connection is encrypted when the browser’s address bar begins with “https://.”
To protect user accounts and restricted areas of the website, we use two-factor authentication via email for the login process. In addition to the password, this requires an additional security factor, such as a time-limited verification code.
20. Your Rights
Under the GDPR, you have the following rights:
Right to access personal data processed by us
Right to rectification of inaccurate personal data
Right to erasure of personal data
Right to restriction of processing
Right to data portability
Right to object to certain processing activities
Right to withdraw consent with future effect
Right to lodge a complaint with a data protection supervisory authority
To exercise your rights, you may contact us at any time using the contact information provided above.
21. Right to Object
Many data processing operations are only possible with your explicit consent. To the extent that we process personal data on the basis of Article 6(1)(f) of the GDPR, you have the right to object to such processing at any time for reasons arising from your particular situation. To do so, simply send us an informal email. The lawfulness of the data processing carried out prior to the withdrawal remains unaffected by the withdrawal.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.
22. Right to File a Complaint with the Supervisory Authority
You have the right to file a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection law. Data protection supervisory authorities may be contacted, in particular, in the Member State of your habitual residence, your place of work, or the location of the alleged violation. For non-public entities in Bavaria, the competent authority is:
Bavarian State Office for Data Protection Supervision
Promenade 18
91522 Ansbach
Germany
Mailing Address:
P.O. Box 1349
91504 Ansbach
Germany
Phone: +49 981 180093-0
Fax: +49 981 180093-800
Email: poststelle@lda.bayern.de
The BayLDA requests that you primarily use the online forms for complaints and consultations.
23. Right to Data Portability
You have the right to have data that we process automatically—based on your consent or in fulfillment of a contract—provided to you or to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another data controller, this will be done only to the extent that it is technically feasible.
24. General Information
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with applicable data protection laws and this Privacy Policy.
Please note that data transmission over the Internet (e.g., when communicating via email) may be subject to security vulnerabilities. It is not possible to completely protect data from access by third parties.
25. Validity and Changes to This Privacy Policy
This Privacy Policy is currently in effect and is valid as of July 2026.
We reserve the right to update this Privacy Policy in the event of technical, legal, or organizational changes.