Privacy Policy

How personal data is handled on the frequentist.org website, in our newsletter, in our contact form, and in our business outreach.
Published

20 September 2026

Last updated: 20 September 2026

This Privacy Policy explains how personal data is collected and used in connection with the frequentist.org website, our newsletter, our contact form, and the business-to-business outreach we carry out.

If you engage us for a consulting project, any personal data we process while delivering that project — for example, data within the systems or datasets you give us access to — is governed by the individual agreement for that engagement, and by a separate data processing agreement where one is required, not by this policy.

1. Who is responsible

The controller responsible for data processing under the General Data Protection Regulation (GDPR) is:

Aleksei Prishchepo, operating as a freelancer (Freiberufler) Romain-Rolland-Str. 72 13089 Berlin, Germany Email: privacy@frequentist.org

You can contact us at any time using the email address above for any question about this policy or your personal data.

2. The data we process, and why

a. Visiting this website

When you visit frequentist.org, the hosting provider automatically records technical connection data (such as your IP address, the pages requested, and your browser type) in server logs. This is necessary to deliver the website securely and reliably. Legal basis: our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).

b. Analytics and cookies

With your consent, we use analytics tools — Google Analytics and PostHog — to understand how the website is used and to improve it. These tools set cookies and process usage data (such as pages viewed, approximate location derived from IP, device and browser information, and interactions on the site).

These analytics cookies are not set unless you agree to them. You can give or withdraw your consent at any time through the Cookie Preferences control in the site footer; withdrawing consent does not affect processing that took place before you withdrew it. Legal basis: your consent (Art. 6(1)(a) GDPR, and § 25(1) TDDDG for storing information on your device).

c. Newsletter

If you sign up to our newsletter, we process your email address and, if you provide them, your first name and company name. We use a double opt-in procedure: after you submit the form, we send a confirmation email, and we only add you to the list once you click the confirmation link. We log your sign-up and confirmation so we can demonstrate your consent.

We use this data to send you occasional updates — for example, new articles or news about our services. Every email contains an unsubscribe link, and you can withdraw your consent at any time with effect for the future. Legal basis: your consent (Art. 6(1)(a) GDPR).

d. Contact form

If you use our contact form, we process the information you provide (such as your name, email address, and message) in order to respond to your enquiry. Legal basis: our legitimate interest in responding to enquiries and, where your enquiry concerns a possible contract, the steps taken at your request prior to entering into a contract (Art. 6(1)(f) and Art. 6(1)(b) GDPR).

e. Business outreach (information obtained from other sources)

As part of our business-to-business marketing, we contact professionals at companies — such as data and analytics consultancies — for whom our freelance BI and analytics services may be relevant. Where we did not obtain your data directly from you, the following applies under Article 14 GDPR:

  • Categories of data: your name, business email address, job title, and the name and public details of your employer.
  • Source of the data: business-contact data providers and publicly available professional sources, including professional networks such as LinkedIn. We currently use Apollo.io as such a source.
  • Purpose: to contact you about a possible freelance collaboration where your professional role suggests our services may be relevant.
  • Legal basis: our legitimate interest in direct B2B marketing (Art. 6(1)(f) GDPR). Where local law requires it, we contact you only through channels that permit it.

You have an absolute right to object to this use of your data at any time, and to ask us to stop contacting you and to erase your data — see Section 6. Every outreach email also contains a way to opt out. If you opt out, we keep the minimum data needed (your email address) on a suppression list solely to ensure we do not contact you again.

3. Recipients and processors

We use carefully selected service providers who process personal data on our behalf under data processing agreements. The main recipients are:

Provider Role Location
Brevo (Brevo SAS) Newsletter delivery and sign-up form France (EU)
HubSpot, Inc. Customer relationship management (contacts, outreach) USA
Apollo.io Source of business-contact data for outreach USA
Google (Google Ireland Ltd / Google LLC) Website analytics (Google Analytics) Ireland (EU) / USA
PostHog, Inc. Website analytics USA
GitHub, Inc. (a Microsoft company) Website hosting (GitHub Pages) USA

We do not sell your personal data.

4. International data transfers

Some of the providers above are located in the United States. Where personal data is transferred outside the EU/EEA, we ensure an adequate level of protection — in particular through the EU–U.S. Data Privacy Framework, where the provider is certified, and/or through the European Commission’s Standard Contractual Clauses together with additional safeguards where required.

5. How long we keep data

  • Newsletter data: until you unsubscribe or withdraw your consent.
  • Contact-form data: for as long as needed to handle your enquiry, and up to 6 months afterwards, unless a longer period is required (for example, if it leads to a contract).
  • Outreach data: only while there is a legitimate interest in contacting you; erased promptly if you object or request erasure. Opt-out records are retained on a suppression list for the sole purpose of honouring your opt-out.
  • Analytics data: for the retention period configured in each tool (Google Analytics: up to 14 months; PostHog: per our configuration).
  • Server logs: kept only for a short period for security and diagnostics.

6. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15);
  • have inaccurate data rectified (Art. 16);
  • have your data erased (Art. 17);
  • restrict processing (Art. 18);
  • receive your data in a portable format (data portability, Art. 20);
  • object to processing based on legitimate interests (Art. 21) — including an absolute right to object to direct marketing at any time; and
  • withdraw consent at any time (Art. 7(3)), without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, contact privacy@frequentist.org.

7. Right to complain

If you believe your data is being processed unlawfully, you have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit Alt-Moabit 59–61, 10555 Berlin, Germany www.datenschutz-berlin.de

8. Changes to this policy

We may update this Privacy Policy to reflect changes to our website, tools, or legal requirements. The current version is always available on this page, with the “last updated” date shown at the top.

Back to top