LEGAL

Privacy Policy

1. Who we are

This website, risingmount.com, is operated by Rising Mount Company (“Rising Mount”, “the network”, “we”). Rising Mount Company is the trading name of Rising Ember SA, a company incorporated in Switzerland with its registered office at Rue Monnier 11, 1206 Genève, Switzerland, which is the controller of personal data collected through this website under the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU/UK GDPR. Data protection contact: [email protected].

2. Scope

This policy covers personal data collected through this website and through correspondence with the network, including expressions of interest in membership. It does not cover data processed by member organisations in their own engagements; each member is an independent controller of its own client data.

3. Data we collect

(a) Data you provide — name, professional role, organisation, email address, and the contents of your correspondence when you contact us or submit an expression of interest.
(b) Data collected automatically — IP address, browser type, device information, pages visited, referring page, and approximate (city-level) location, collected through server logs and the cookies described in our Cookie Policy.
(c) Data from public sources — where an organisation enters membership evaluation, we may review publicly available information about it and its principals (corporate registries, published work, press). We do not purchase personal data from data brokers.

4. Purposes and legal bases

We process personal data to: operate, secure, and improve the website (legitimate interests); respond to correspondence (legitimate interests / steps prior to a contract); evaluate membership candidacies (steps prior to a contract; legitimate interests); meet legal and regulatory obligations (legal obligation); and, only with consent, run non-essential analytics cookies (consent, withdrawable at any time).

5. What we do not do

We do not sell personal data. We do not use personal data for advertising. We do not make automated decisions producing legal or similarly significant effects about individuals. Analytical systems described elsewhere on this site operate on business and market intelligence, not on website visitors' personal data.

6. Sharing

Personal data is shared only with: service providers that host and maintain this website and our correspondence systems, under contract and only on our instructions; professional advisers (legal, accounting) under duties of confidence; and authorities where disclosure is required by law. Membership correspondence may be shared within the network's governance function strictly for evaluation purposes.

7. International transfers

We are established in Switzerland, the network operates internationally, and our infrastructure providers may process data in other countries, including Singapore. Switzerland benefits from an EU adequacy decision, so transfers between the EU and Switzerland are permitted. Where personal data is transferred onward to countries without an adequate level of protection, we rely on appropriate safeguards such as the Standard Contractual Clauses recognised under the GDPR and the Swiss FADP.

8. Retention

Server logs: up to 13 months. General correspondence: up to 24 months after the correspondence closes. Membership candidacy records: for the duration of evaluation and, where no admission follows, up to 36 months thereafter (so that prior candidacies inform future ones). Legal and accounting records: as required by law. Data is deleted or anonymised when no longer needed.

9. Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or receive a copy of your personal data; to object to or restrict processing; to withdraw consent; and to lodge a complaint with a supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch); in the EU, your national data protection authority; in the UK, the ICO. To exercise any right, write to [email protected]. We respond within the timeframe required by applicable law and may need to verify your identity.

10. Security

We apply technical and organisational measures proportionate to the data we hold: encrypted transport (TLS), access controls, logging, and vendor due diligence. No system is perfectly secure; we notify affected individuals and regulators of breaches where the law requires it.

11. Children

This website is directed at professionals and organisations. We do not knowingly collect data from anyone under 18.

12. Changes

We revise this policy as our operations or the law change. The revision date above always reflects the current version; material changes are flagged on this page. The English version of this policy prevails over translations in case of conflict.