What is and is not collected
This site sets no cookies and runs no analytics package of any kind, first-party or third-party. Every asset a page needs, whether fonts, images, styles or scripts, is served from this domain, so opening a page here does not tell any other company that you did. There is no login, no registration, no newsletter and no form, which means there is no field anywhere on the site into which personal data could be entered.
That list is short because the site is genuinely simple: it is pre-built static HTML, CSS, a small amount of inline JavaScript, self-hosted fonts and images. There is no application, no database and no server-side code processing a request. Most of what a privacy policy normally has to disclose does not exist here.
What the web server necessarily records
Serving a page requires receiving a request, and a request contains information that cannot be served without. In standard web-server logs that is: the IP address the request came from, the date and time, the address requested, the HTTP status returned, the number of bytes sent, the referring page if the browser sent one, and the user-agent string identifying the browser and operating system. This is the ordinary technical record every web server keeps, and it exists to serve the page, to detect faults and to identify abuse.
It is not combined with anything else, not used to build a profile, not enriched with third-party data, not used for advertising, and not sold or shared for any commercial purpose. It is retained only as long as it is useful for the operational reasons above and then discarded in the ordinary course of log rotation. Because there is no cookie, no identifier and no account, there is nothing to link one visit to another.
Content delivery and the hosting layer
The site is served through standard hosting infrastructure, which may sit behind a content-delivery network for reliability and transport security. Where that is the case, the network's edge servers process the same request data described above in order to route and deliver the response, and they apply their own security filtering. That processing is inherent in delivering a website over the public internet, and it is disclosed here rather than omitted because it happens on every site including the ones that do not mention it.
The inline JavaScript, and what it touches
There is a small amount of JavaScript on these pages, all of it inline and all of it presentational: it reveals elements as they enter the viewport, moves a light gradient toward the cursor inside certain panels, counts three figures up on the homepage, and draws one chart line. It reads nothing, stores nothing, sends nothing and makes no network request of any kind. If it is blocked or disabled, every page remains complete and readable: the content is in the HTML, not assembled by script.
Nothing on the site uses local storage, session storage or any other browser storage mechanism, and nothing attempts device fingerprinting. Visitors who have asked their system for reduced motion get static pages, which is a preference the site reads from the browser and does not record.
Your rights, and the practical difficulty with them
Where data-protection law applies, you have rights of access, correction, erasure, restriction and objection in respect of personal data held about you. The practical position here is that no identifiable record of an individual visitor is held: without cookies, accounts or identifiers, a request in server logs cannot be tied to a person by this site, and an access request could not be answered without you supplying more information than the site holds.
That is stated plainly rather than dressed up, because a policy claiming an elaborate rights process over data that does not exist would be misleading. If you have a specific concern about a specific page, contact explains what that address handles, including takedown requests concerning personal data inside the archived material itself, which is a real category and is dealt with there rather than here.
Archived material and third parties
The dispatches are reproductions of trade journalism published between 2011 and 2016, and they name companies, exchanges, institutions and public officials as the original reporting did. Where a page mentions a person, it is because that person was named in a published dispatch in a public capacity. No new personal information has been added to any dated page, and no byline has been added to one: the desk was the attribution, and that is how the pages read.
Outbound links in the reference layer point to other websites, whose own policies govern what happens when you follow them. This site has no relationship with them and receives nothing for the link.
Changes
If this policy changes, the changed version replaces this one at the same address. Given that the site is static and carries no tracking, material change is unlikely; anything that did add a cookie, an analytics package or a third-party request would be described here before it was added, because the absence of all three is the substance of this page.