How this website is built
This site is a static export. Every page is a plain HTML file generated ahead of time and served from a content delivery network. There is no application server, no database, no content management system and no administrative login attached to it. That removes most of the attack surface a marketing site usually carries, and it means the site holds no personal data at rest.
- No database
- Nothing to query, inject into or exfiltrate.
- No user accounts
- No credentials to steal, no session state to hijack.
- No forms
- Nothing is submitted from this site. Contact runs over email.
- No third party scripts
- No analytics, no tag manager, no advertising or tracking code.
- Self hosted assets
- Fonts, images and styles are served from our own domain, so loading a page shows your IP address to no external provider. One exception: if a request fails, your browser may send a network error report to a Cloudflare endpoint, our processor named in section 6 of the privacy notice.
Transport and platform security
All traffic is served over HTTPS with TLS, and plain HTTP requests are redirected. HTTP Strict Transport Security instructs browsers to refuse an unencrypted connection to this domain.
The site is delivered through Cloudflare, which provides denial of service mitigation, a web application firewall and bot filtering at the network edge, ahead of our origin.
- Content-Security-Policy allowing scripts, styles, fonts and network calls only from our own origin, and images from our own origin plus inline data URIs, with no external frame, plugin or cross origin form post permitted. Inline scripts and inline style attributes are allowed because the framework needs them and a static site cannot issue per request nonces.
- Strict-Transport-Security, so browsers refuse to downgrade to HTTP
- X-Content-Type-Options: nosniff, so browsers do not guess content types
- X-Frame-Options: DENY, so the site cannot be framed by another party
- Referrer-Policy: strict-origin-when-cross-origin, limiting what we leak on outbound links
- Permissions-Policy denying access to camera, microphone and geolocation
Where investor data actually lives
No investor data is collected on this website. Identity verification, know your customer and anti money laundering checks, suitability assessments and subscription documents are not handled here. They will be handled in the separate investor platform, which is being built to sit behind authentication with its own privacy notice, access controls and retention schedule. It is not part of this website.
That separation is deliberate. A public marketing site and a system holding identity documents have different threat models and should not share infrastructure.
Data protection framework
We process personal data under the Swiss Federal Act on Data Protection, in its revised version in force since 1 September 2023. Because this website addresses investors in Germany and elsewhere in the EU, the EU General Data Protection Regulation applies to that processing under its Article 3(2). Where the two differ, we apply the stricter standard.
The privacy notice linked in the footer sets out what we process, on what legal basis, who receives it, how long we keep it and how to exercise your rights, including complaint to the Swiss Federal Data Protection and Information Commissioner or to your own EU supervisory authority.
Regulatory framework for the platform
GM Data Centers AG holds no authorisation as a financial institution and does not currently provide financial services requiring authorisation under Swiss financial market law. Investment structures are prepared per project and per jurisdiction, and each is described on this website as in preparation until the applicable regulatory step is complete.
- German market
- A Wertpapier-Informationsblatt (WIB) under section 4 of the German Securities Prospectus Act. Per the notices section 4(5) WpPG requires: the substantive accuracy of a WIB is not subject to review by BaFin, and no BaFin-approved securities prospectus has been filed for the security. Publication of a WIB is not an approval or endorsement of the security or the offering.
- The instrument
- Tokenised Swiss Wertrechte: uncertificated shares conferring a capital participation in a Swiss stock corporation. Under German law they are digital, non-certificated securities within the meaning of section 4(3a) WpPG and are treated as securities sui generis. They are expressly NOT electronic securities under the German Electronic Securities Act (eWpG) and are not entered in a German crypto securities register.
- Project vehicles
- Swiss special purpose vehicles holding individual sites, so that project risk is ring fenced from the holding company.
Corporate standing
GM Data Centers AG is a stock corporation under Swiss law, UID CHE-200.150.787, with its registered office at Dammstrasse 16, 6300 Zug. It was incorporated on 22 February 2022 and has been entered in the commercial register of the Canton of Zug since 3 October 2023, when the registered office was transferred there. Full company details, representation and register data are set out in the imprint, linked in the footer, and can be checked against the federal commercial register index at zefix.ch.
Reporting a security issue
If you find a vulnerability in this website or in any system we operate, tell us at hi@gm-data-centers.com before disclosing it elsewhere. Give us enough detail to reproduce the issue. We will confirm receipt, keep you informed while we investigate, and will not pursue anyone who reports in good faith and does not access, alter or exfiltrate other people's data.
Scope of this page
This page describes controls that are in place for this website and the framework the platform's structures are being prepared under. It is a description, not a warranty, and not a certification. It is a marketing communication and not an offer, a solicitation or investment advice. Structures, providers and controls change, and this page is updated when they do.