Privacy policy

This page states what personal data Richport Media Inc. holds, on what lawful basis, who receives it, how long it is kept, the rights you can exercise, and the controls and assessments that do not exist.

Two routes. Either you gave us the data — you booked a call, emailed us, or loaded a page — the Article 13 route. Or we collected business contact details about you from public sources and then emailed you, the Article 14 route, set out in full at how we collect business contact data. The booking widget has its own notice at booking privacy. This page covers both.

Last updated 12 August 2026, the first version of this page. Before it, richportmedia.ai carried no privacy policy, no cookie notice and no consent mechanism.

The controller

Identity and contact details of the controller, required by Article 13(1)(a) and Article 14(1)(a).

  • ControllerRichport Media Inc., a corporation organised under the laws of the Commonwealth of Puerto Rico, United States. It determines the purposes and means of all processing described on this page.
  • Registered address1225 Ave Ponce De Leon, PH 2020, San Juan, PR 00907, United States. It is also the postal address in the footer of our commercial email, under 15 U.S.C. 7704(a)(5)(A)(iii).
  • Privacy and rights requests[email protected]. Access, correction, deletion, objection and complaints all go to this address, which reaches Richport Media Inc.
  • Business enquiries[email protected], published on the contact page. Anything covered by this page should go to the address above.
  • Data Protection OfficerNone appointed. Whether Article 37 requires one on these facts has not been assessed.
  • EU representative — Article 27 GDPRNot yet designated. Until one is, there is no EU representative to write to; use [email protected]. This line will name the representative and their EU address once one is in place.
  • UK representative — Article 27 UK GDPRNot yet designated. A UK representative is a separate appointment from the EU one. Until it is in place, write to [email protected].
On the representatives. Article 27 requires a controller established outside the EU, and separately outside the UK, to designate a representative in each place where it targets people there. Neither designation is in place.

Personal data we hold

This is the complete list. If a category is not below, we do not hold it.

  • What the analytics tag measures about your visitIf you allow analytics, Google Analytics 4 (measurement ID G-J5QWW3XMFW) sends Google the full URL of the page you are on, the page title, your screen resolution, your browser language, and User-Agent Client Hints: platform, platform version, architecture, bitness and the full browser version list. Your IP address reaches Google at the network layer. The configuration call carries no parameters, so we have set no IP anonymisation, cookie lifetime or advertising setting, and Google’s defaults apply.
  • What Cloudflare sees at the edgeCloudflare serves richportmedia.ai and receives your IP address, the URL requested and your browser’s request headers for every page and asset, browser and device signals from its measurement beacon and bot-detection script, and DMARC aggregate reports carrying sending IP addresses and volumes for mail sent using our domain.
  • What you type into the booking formThe scheduler embedded on the contact page collects the meeting type, date and time you pick, the timezone your browser reports (an approximate-location signal inferred in your browser), a required free-text field labelled Corporation Name, and your name and email address, which the app requires to create the appointment and send you a confirmation and reminders, plus anything you add in the optional notes or guest fields. The appointment is written into a Google calendar connected to the scheduler. Your IP address reaches the booking server directly, because that host is not behind Cloudflare.
  • What you send to our mailboxWhatever is in the email: your address, your name, your signature block, your attachments, and the whole thread once we reply.
  • What you send us on SignalWhere we agree to talk on Signal, as the trust page offers, the conversation is end-to-end encrypted and sits on the two devices, not on a server we control. Signal holds your phone number as an account identifier.
  • Business contact data we collected about youFor outreach to public issuers and their officers: name, job title, employer, business email address, company registration details, and the country we associate with the record. It comes from public company registers and other publicly accessible sources. Article 14(2)(f) requires the specific source to be named; field by field and source by source, it is set out at how we collect business contact data.
  • A record that you told us to stopIf you object to marketing we keep the address you told us not to use, and the fact and date you told us. Nothing else.
  • What we do not collectNo special-category data under Article 9. We do not ask for it, and it should not be typed into the booking notes. No payment card data: there is no checkout, no payment form and no card field on this website or in the booking widget. The booking app’s content-security policy names Stripe among permitted origins; the page loads nothing from Stripe and takes no payment. Card payment for an engagement, offered on the trust page, is arranged with the client directly. There is no form, input field or file upload anywhere on richportmedia.ai itself; every field you can type into sits inside the booking widget.

Purposes and lawful bases

Where the basis is consent, nothing is stored on or read from your device until you give it. Where the basis is legitimate interests, you can object.

  • Serving the site and keeping it standing upArticle 6(1)(f). Our interest is delivering pages to the people who requested them and preventing automated traffic from degrading the service. This covers Cloudflare’s edge logs, bot scoring and error reporting.
  • Measuring how the site is usedArticle 6(1)(a), consent. Nothing is stored on or read from your device for analytics unless you allow it in the banner. That storage also requires consent under TDDDG §25 in Germany and PECR regulation 6 in the UK.
  • Advertising signals to GoogleArticle 6(1)(a), consent. Advertising features are active on the analytics property, so a separate remarketing request goes to Google when advertising cookies are permitted. That is advertising infrastructure, not analytics.
  • Booking and running the introductory callArticle 6(1)(b), steps taken at your request before entering a contract. The same basis covers the confirmation and reminder emails, which carry only the meeting details.
  • Answering your emailArticle 6(1)(b) where you are asking about working with us, Article 6(1)(f) otherwise. Our interest is answering people who write to us.
  • Cold outreach to business contactsArticle 6(1)(f). The specific interest, required by Article 14(2)(b): offering an investor-awareness service to the officer of a listed or listing-track company whose role makes that offer relevant to their work. Recital 47 recognises direct marketing as capable of being a legitimate interest. It does not decide the balance. The objection right below is unconditional.
  • Keeping a record that you told us to stopArticle 6(1)(c). Article 21(3) obliges us to stop processing your data for marketing once you object, and Article 17(3)(b) lets us keep what is needed to do it. Deleting the record entirely would let the next collection run find you in the same public register.

Cookies and device storage

Our own page code sets no cookies and uses no localStorage, sessionStorage or IndexedDB. First-party storage on richportmedia.ai comes from Google Analytics and from the banner recording your consent choice. The booking host sets one cookie. The full table is at the cookie notice.

  • _ga and _ga_J5QWW3XMFW — analytics, consent requiredSet by Google Analytics 4 only if you allow analytics. Lifetime is Google’s documented two-year default, which we do not override. They are set on the whole richportmedia.ai domain, so they are also sent to cal.richportmedia.ai: the booking server receives your analytics client ID alongside your booking, joining site measurement to an identified booking record.
  • Google advertising request — consent requiredWhen advertising cookies are permitted, the analytics tag sends a remarketing request to Google’s advertising domain for your country, carrying the measurement ID and your analytics client ID. The request we observed carried npa=0, so non-personalised advertising is not enforced and personalised advertising signals are permitted. Refuse advertising in the banner and no advertising identifier is set on or read from your device.
  • _tymeslot_key — strictly necessary, no consent askedSet by the booking app at cal.richportmedia.ai on first load, before any interaction. Session cookie, Secure, HttpOnly, SameSite=Lax. It carries a cross-site-request-forgery token and a locale, nothing else. It is necessary for the form to function and is exempt from consent.
  • Cloudflare measurement beacon — not covered by the bannerCloudflare injects a real-user-measurement script at the edge on every browser page load and posts the result back to Cloudflare. The Google consent banner does not control it. Cloudflare is a second analytics recipient, in the United States, running independently of your analytics choice.
  • Cloudflare bot detection — not covered by the bannerA client-side script collects browser and device signals for bot scoring on every page, including the 404 page, where it is the only script that runs. This is fraud and abuse prevention, not measurement.
  • Cloudflare error reportingNetwork Error Logging is on across the zone. Successful requests are not reported; failed ones are, and those reports carry your IP address, the URL and the error type to a Cloudflare endpoint.
  • Cloudflare email decodingCloudflare rewrites our email address on the contact page and loads a script to decode it in your browser. With JavaScript off, a placeholder appears instead of an address. The obfuscation is incomplete: the address appears once in cleartext in the page’s copy-to-clipboard script.
  • FontsSelf-hosted. All thirteen font files are served from richportmedia.ai and the stylesheet contains no external URL, so no font CDN sees your request.
Where the analytics tag runs. Google Analytics is present on all fourteen public pages and absent from the 404 page. Referrer-Policy is set to strict-origin-when-cross-origin, so only the bare origin appears in a referer header. That does not limit what the tag itself sends, which includes the full URL of the page you are on.

Recipients

Recipients, the country where the processing sits, and what each one does.

  • Cloudflare, Inc. — United StatesHosts and serves richportmedia.ai, issues and terminates its TLS certificate, runs our authoritative DNS and the edge cache, injects the measurement beacon and the bot-detection script, obfuscates the contact address, receives network error reports, and receives DMARC aggregate reports carrying sending IP addresses and volumes. Cloudflare is not in the path for the booking app.
  • Google LLC and Google Ireland Limited — United States and IrelandGoogle Analytics 4 measurement and the associated advertising request, both consent-gated. Google Search Console, which reports search performance for the domain. The calendar account connected to the booking app by OAuth, through which Google receives the appointment data. Our SPF record authorises Google’s mail servers to send mail as richportmedia.ai alongside Proton’s.
  • Hetzner Online GmbH — German company, machine in Ashburn, VirginiaThe booking server. The contractual counterparty is a German company at Industriestrasse 25, 91710 Gunzenhausen; the machine and the booking database are in Virginia. cal.richportmedia.ai resolves straight to that server and is not proxied through Cloudflare, so booking traffic, including your IP address, reaches Hetzner infrastructure directly.
  • Proton AG — SwitzerlandProton runs the inbound mail exchangers for richportmedia.ai, so anything you email us is received and stored by Proton, not merely relayed. Proton also carries outbound mail, including booking confirmations, reminders and outreach.
  • Anthropic PBC — United StatesAn AI model reads and structures the business contact information collected for outreach. What goes to the model, and what comes back, is described at how we collect business contact data.
  • Twenty CRM — our own hardware, Puerto RicoOpen-source software we run ourselves on a machine in Puerto Rico. No CRM company holds a copy of the outreach database.
  • Signal Messenger LLC — United StatesCarries Signal conversations end-to-end encrypted and holds your phone number as an account identifier. We do not record calls, on Signal or anywhere else.
  • Internet Security Research Group — United StatesLet’s Encrypt issues the TLS certificate for cal.richportmedia.ai, renewed automatically by Caddy on that server. It sees the domain name, not personal data.
  • GitHub, Inc., a Microsoft company — United StatesHolds the site’s source code and runs the workflow that purges the cache when we deploy. No personal data passes through it.

International transfers

We are a United States controller. Data about people in Europe reaches the United States because that is where we are, not through a transfer by a European exporter.

  • United StatesPuerto Rico, for the outreach database and the machine that collects it. Virginia, for the booking server. Cloudflare, Google and Anthropic all process in the United States.
  • The Hetzner legOur contract is with Hetzner Online GmbH, a German company; the machine is in Ashburn. The Germany-to-United-States leg inside Hetzner’s group is Hetzner’s transfer to paper, not ours. Our obligations are selection diligence under Article 28(1) and sub-processor authorisation under Article 28(2).
  • SwitzerlandProton AG is established in Switzerland, which has a European Commission adequacy decision.
  • What we do not rely onWe are not certified under the EU-US Data Privacy Framework and we do not claim its protections. Nothing on this site should be read as asserting that certification. We place no standard contractual clauses under our disclosures to Cloudflare, Google or Anthropic: both ends sit in the United States and we are a controller here, not an exporter in Europe. Whether Chapter V applies to a controller caught by Article 3(2) is contested, and our position has not been tested.

Retention

Article 14(2)(a) and Article 13(2)(a) require a period or the criteria for setting one.

  • Booking recordsThere is no automatic deletion schedule on the booking database. A booking stays until it is deleted; ask us and we delete yours.
  • Booking backupsThe booking server writes a database dump and a copy of its uploads every night at 03:00 and keeps fourteen days of them, on the same disk as the server. A record you ask us to delete can survive in those backups for up to fourteen days, then rolls off.
  • Outreach recordsThere is no automatic retention clock on the outreach database. Records stay until we delete them or you ask us to.
  • The record that you objectedKept indefinitely: the marker must outlive the records it suppresses. It is maintained by hand, not by a system the collection and send jobs consult before they run.
  • EmailMail you send us stays in the Proton mailbox until it is deleted by hand. There is no automatic clear-out.
  • SignalMessages sit on the two devices, not on a server we control, until they are deleted.
  • AnalyticsCookie lifetimes are in the cookie section above. Google keeps a separate copy of the measurement data for the period set on the analytics property. We have not confirmed which period is set, so none is stated here.

Your rights

Email [email protected]. Say what you want and give us enough to find you: the address we contacted you on, or the address you booked with. No form, account or reason is required. It is free, under Article 12(5).

  • Access — Article 15A copy of the personal data we hold about you, plus the purposes, the recipients, the retention position and, under Article 15(1)(g), the source. Public company registers do not publish email addresses; if we hold one for you it came from elsewhere or was derived, and we will tell you which. Where the exact source for an older record cannot be reconstructed, we will say so.
  • Rectification — Article 16Correction of anything wrong, and completion of anything incomplete, including a stale job title or a wrongly derived email address.
  • Erasure — Article 17Deletion, where one of the Article 17(1) grounds applies. Deletion is not the way to stop marketing email: a deleted record can be found again by a later collection run.
  • Restriction — Article 18We keep the data but stop using it, for instance while a dispute about accuracy or about our legitimate interests is unresolved.
  • Objection — Article 21Two separate rights. Article 21(2), objecting to direct marketing, is absolute and is set out in its own section below. Article 21(1), objecting to any other processing based on legitimate interests, requires us to stop unless we can show compelling legitimate grounds that override your interests.
  • Portability — Article 20A machine-readable copy, and transmission to another controller where technically feasible. The right applies only to data processed by automated means on the basis of consent or of a contract. It engages for what you typed into the booking form, and not for records collected from public sources under legitimate interests.
  • Notification to recipients — Article 19Where we correct, delete or restrict something, we tell anyone we passed it to, unless that proves impossible or disproportionate, and we tell you who they were if you ask.
  • Automated decisions and profiling — Article 22Two automated steps touch you: Cloudflare scores every request for whether it looks like a bot, and an AI model structures the business contact information collected for outreach. Whether that enrichment step is profiling within the meaning of Article 4(4) has not been assessed. Ask under Article 15 and we will tell you what the model did to your record.
  • Withdrawing consent — Article 7(3)Analytics and advertising cookies run on consent. Withdraw it in the banner at any time. Withdrawal does not make the processing before it unlawful.
  • Complaining — Article 77You can complain to the supervisory authority of the EU or EEA state where you live, where you work, or where the problem happened. In the United Kingdom that is the Information Commissioner’s Office. You do not have to contact us first.
Timing. Article 12(3) gives us one month to answer, extendable by two further months for requests that are genuinely complex, in which case we have to tell you within the first month and explain why.

Objecting to direct marketing

Article 21(4) requires this right to be brought to your attention clearly and separately from the other information on this page.

The right is absolute. Under Article 21(2) you can object at any time to us processing your personal data for direct marketing. There is no balancing test, and you do not have to give a reason. On receipt of the objection we stop, and we do not resume.
How to do it. Reply to any email we sent you and say stop, or write to [email protected] from any address. We will not ask why, will not require a login or information we do not already hold, and will not charge you; 16 CFR 316.5 prohibits all three. In the United States, 15 U.S.C. 7704(a)(3) and (a)(4) give a sender ten business days to act on an opt-out.
What we keep. We do not delete every trace of you when you object: deleting the record is what allows the next collection run to find the same name in the same public register. Article 17(3)(b) permits us to keep the minimum needed to honour the objection, a marker saying do not contact this address. If you want that marker removed as well, say so.
Limit on enforcement. There is no automated suppression table. The collection job checks nothing before inserting a record, and the send job checks nothing before sending. Acting on an objection is a manual step. If you receive email from us after telling us to stop, reply and tell us.

Security measures

What is configured on each machine, and where no assessment exists.

  • Transport — the marketing siteHTTPS-only, with a certificate issued and terminated by Cloudflare. Response headers: HSTS with a one-year max-age, includeSubDomains and preload; X-Content-Type-Options nosniff; X-Frame-Options DENY; Referrer-Policy strict-origin-when-cross-origin; and a Permissions-Policy denying geolocation, microphone and camera.
  • Transport — the booking appHTTPS-only, with its certificate issued and renewed automatically by Caddy through Let’s Encrypt on the server itself.
  • Booking serverThe application container is published on the loopback interface only, so the Caddy reverse proxy is the sole way in. Inbound traffic is filtered twice, by a Hetzner cloud firewall and by a host firewall, both allowing only ports 22, 80 and 443. SSH is key-only, with root login and password authentication disabled. fail2ban and unattended security upgrades are enabled. The application image is pinned to a specific version rather than a floating tag.
  • Connected-calendar credentialsThe OAuth credentials for the connected calendar are encrypted at rest on the booking server with a dedicated key. That is credential encryption only. Booking records — names, email addresses, corporation names — are not claimed to be encrypted at rest in the database.
  • The marketing siteStatic files with no server-side application, no database and no form handler. There is no Content-Security-Policy on it.
  • The machine that holds the outreach databaseThe CRM runs on our own hardware in Puerto Rico. There is no documented security assessment of that machine.
  • BackupsNightly, fourteen days, on the same disk as the server. They do not survive loss of the server, and they are not disaster recovery.

What does not exist

Puerto Rico’s Act 39-2012 attaches a penalty to publishing a privacy policy that does not correspond to actual practice.

  • No Data Privacy Framework certificationWe are not certified under the EU-US Data Privacy Framework and we do not claim its protections.
  • No Data Protection OfficerWe have not appointed one. Whether Article 37 requires one on these facts has not been assessed.
  • No security certification of any kindNo ISO 27001, no SOC 2, no audit. Nobody outside this company has reviewed the setup.
  • No cookie consent historyAnalytics, the Google advertising request, the Cloudflare beacon and Cloudflare bot detection all ran on this site with no notice and no consent until the banner shipped with these pages.
  • No retention clockThere is no automatic deletion schedule on booking records or on the outreach database. Records stay until somebody deletes them.
  • No automated suppression listObjections are actioned by a person, not by a system the collection and send jobs consult before they run.
  • No claim of a processing agreement with every processorAn Article 28 contract is not in place with every company named above.
  • No offsite backup, and no encryption-at-rest claimThe booking backups sit on the same disk as the server, and booking records are not claimed to be encrypted at rest in the database.
  • No Content-Security-Policy on richportmedia.aiThere is none. The omission is documented in the site’s own header file, because an untested policy silently breaks the booking page.
  • No consent gate over Cloudflare’s own scriptsThe measurement beacon and the bot-detection script are injected at the edge, independently of anything the banner controls. Refusing analytics does not stop them.
  • No documented security assessment of the CRM machineThe machine holding the outreach database has never had its posture assessed in writing.
  • No profiling assessmentWe have not determined whether the AI enrichment step is profiling under Article 4(4), or whether Article 22 engages.
  • No published figure for what Google keepsWe have not confirmed the data-retention period set on the analytics property, and none is stated.
  • No tested position on Chapter VOur position is that a United States controller collecting directly is not making a restricted transfer. That position has not been tested.

Changes and related notices

This page is updated when practice changes, and the date at the top changes with it. Where a change materially affects people whose data we hold under Article 14, it is also stated in the outreach email.

  • How we collect business contact dataThe full Article 14 notice for outreach: the sources, the categories, the enrichment step, the legitimate interests, and the objection route. Read it.
  • Booking privacyThe Article 13 notice for the scheduler on the contact page: what the form takes, what is required to make a booking, and what the confirmation emails contain. Read it.
  • Cookie noticeEvery cookie and every script, with lifetimes, purposes and the consent position. Read it.
  • DisclosuresPaid-article labelling and compensation disclosure under Section 17(b) of the Securities Act, 15 U.S.C. 77q(b). Read it.
  • TermsThe terms governing use of this site. Read them.

Questions about anything on this page: [email protected], or Richport Media Inc., 1225 Ave Ponce De Leon, PH 2020, San Juan, PR 00907, United States.