Privacy Notice
SAX Investments Ltd, trading as GS Invest, respects the confidentiality of everyone who contacts us. This notice explains what personal data we collect through this website and in the course of our advisory work, why we hold it, how long we keep it, and the rights you can exercise over it.
Last updated 26 July 2026
1. Who is responsible for your data
SAX Investments Ltd is the data controller for the personal data described in this notice, which means we decide why and how it is processed. We have not appointed a Data Protection Officer, as we are not required to; privacy questions are handled directly by the partners.
2. The personal data we collect
We only collect what we actually need. In practice that is:
- 01Enquiry details — the name, email address, company name (optional) and message you submit through our contact form, or that you send us by email, telephone, or messaging apps.
- 02Correspondence and engagement records — notes, documents, and communications exchanged while we scope or deliver an advisory mandate, including the details of counterparties and representatives you introduce to us.
- 03Compliance data — where a mandate requires customer due diligence, identity and source-of-funds documentation collected to meet anti-money-laundering and know-your-client obligations.
- 04Technical data — IP address, browser type, approximate location, referring page, and pages viewed. This is logged automatically by our hosting provider for security and reliability purposes.
- 05Cookie data — the identifiers described in our Cookie Policy, which are only set beyond what is strictly necessary if you consent.
We do not knowingly collect special-category data (such as health or political opinions), and we ask that you do not send it to us unless it is genuinely necessary for a mandate. This website is not directed at children and we do not knowingly collect data from anyone under 16.
3. Why we use it, and our legal basis
Under Article 6 of the UK and EU General Data Protection Regulation we must have a lawful basis for every use of your data. Ours are:
- 01To respond to your enquiry and scope a mandate — steps taken at your request prior to entering a contract, and performance of that contract once agreed (Art. 6(1)(b)).
- 02To deliver advisory services and manage the client relationship — performance of our contract with you (Art. 6(1)(b)).
- 03To keep the site secure and working, prevent abuse of our forms, and maintain business records — our legitimate interests in running a secure and well-administered practice (Art. 6(1)(f)).
- 04To set non-essential cookies and, where applicable, send occasional updates about our work — your consent, which you may withdraw at any time (Art. 6(1)(a)).
- 05To meet anti-money-laundering, tax, and accounting obligations — compliance with a legal obligation to which we are subject (Art. 6(1)(c)).
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
4. Who we share it with
We never sell personal data. We disclose it only to the following categories of recipient, each bound by confidentiality and, where they act as processors, by a written data processing agreement:
- 01Netlify — hosting of this website and receipt of contact-form submissions.
- 02Google Maps — only if you enable the optional functional cookies that load the embedded map on our contact section.
- 03Email, storage, and productivity providers used to run the practice.
- 04Professional advisers — lawyers, accountants, and auditors, where needed for a mandate or to protect our legal position.
- 05Regulators, courts, and law enforcement — where we are legally required to disclose.
- 06A buyer or successor — if our business is reorganised, merged, or transferred, subject to equivalent protections.
5. International transfers
Some of our providers process data outside the European Economic Area, including in the United States. Where that happens we rely on an adequacy decision of the European Commission, or on the Commission's Standard Contractual Clauses together with any additional safeguards the transfer requires. You may request a copy of the relevant safeguards by writing to us at info@gsinvest.net.
6. How long we keep it
We keep personal data only as long as it serves the purpose it was collected for:
- 01Enquiries that do not lead to a mandate — up to 24 months from the last contact, then deleted.
- 02Client and engagement records — for the duration of the relationship and then generally for six years, to cover limitation periods for legal claims.
- 03Anti-money-laundering records — five years from the end of the business relationship or the completion of the transaction, as required by Cyprus law.
- 04Server logs — a short rolling window kept by our hosting provider for security monitoring.
- 05Your cookie choice — twelve months, after which we ask again.
7. Your rights
Subject to the conditions in the GDPR, you have the right to:
- 01Be informed about how your data is used — the purpose of this notice.
- 02Access a copy of the personal data we hold about you.
- 03Rectify data that is inaccurate or incomplete.
- 04Erase your data where we no longer have grounds to keep it.
- 05Restrict our processing while a concern is investigated.
- 06Port data you gave us to another provider in a structured, machine-readable format.
- 07Object to processing based on our legitimate interests, and to direct marketing at any time.
- 08Withdraw consent at any time, without affecting processing carried out before withdrawal — for cookies, use the .
To exercise any of these, email info@gsinvest.net. We respond within one month and will not charge a fee unless a request is manifestly unfounded or excessive. We may ask you to verify your identity first.
8. Complaints
If you believe we have handled your data improperly, please tell us first so we can put it right. You also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus, or with the supervisory authority in the EU or UK country where you live or work.
9. Security
This site is served over HTTPS. We apply access controls, encryption in transit, and a need-to-know rule internally, and we select providers that maintain recognised security standards. No system is perfectly secure, so we also keep the amount of data we hold to a minimum — the strongest protection available for information that was never collected.
10. Changes to this notice
We review this notice periodically and will update the date at the top whenever it changes. Material changes affecting how we use your data will be communicated directly to clients where we hold contact details for that purpose.