Privacy Policy
Last updated: 20 September 2026
This Privacy Policy explains how personal data is collected and used in connection with the frequentist.org website, our newsletter, our contact form, and the business-to-business outreach we carry out.
If you engage us for a consulting project, any personal data we process while delivering that project — for example, data within the systems or datasets you give us access to — is governed by the individual agreement for that engagement, and by a separate data processing agreement where one is required, not by this policy.
1. Who is responsible
The controller responsible for data processing under the General Data Protection Regulation (GDPR) is:
Aleksei Prishchepo, operating as a freelancer (Freiberufler) Romain-Rolland-Str. 72 13089 Berlin, Germany Email: privacy@frequentist.org
You can contact us at any time using the email address above for any question about this policy or your personal data.
2. The data we process, and why
a. Visiting this website
When you visit frequentist.org, the hosting provider automatically records technical connection data (such as your IP address, the pages requested, and your browser type) in server logs. This is necessary to deliver the website securely and reliably. Legal basis: our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).
d. Contact form
If you use our contact form, we process the information you provide (such as your name, email address, and message) in order to respond to your enquiry. Legal basis: our legitimate interest in responding to enquiries and, where your enquiry concerns a possible contract, the steps taken at your request prior to entering into a contract (Art. 6(1)(f) and Art. 6(1)(b) GDPR).
e. Business outreach (information obtained from other sources)
As part of our business-to-business marketing, we contact professionals at companies — such as data and analytics consultancies — for whom our freelance BI and analytics services may be relevant. Where we did not obtain your data directly from you, the following applies under Article 14 GDPR:
- Categories of data: your name, business email address, job title, and the name and public details of your employer.
- Source of the data: business-contact data providers and publicly available professional sources, including professional networks such as LinkedIn. We currently use Apollo.io as such a source.
- Purpose: to contact you about a possible freelance collaboration where your professional role suggests our services may be relevant.
- Legal basis: our legitimate interest in direct B2B marketing (Art. 6(1)(f) GDPR). Where local law requires it, we contact you only through channels that permit it.
You have an absolute right to object to this use of your data at any time, and to ask us to stop contacting you and to erase your data — see Section 6. Every outreach email also contains a way to opt out. If you opt out, we keep the minimum data needed (your email address) on a suppression list solely to ensure we do not contact you again.
3. Recipients and processors
We use carefully selected service providers who process personal data on our behalf under data processing agreements. The main recipients are:
| Provider | Role | Location |
|---|---|---|
| Brevo (Brevo SAS) | Newsletter delivery and sign-up form | France (EU) |
| HubSpot, Inc. | Customer relationship management (contacts, outreach) | USA |
| Apollo.io | Source of business-contact data for outreach | USA |
| Google (Google Ireland Ltd / Google LLC) | Website analytics (Google Analytics) | Ireland (EU) / USA |
| PostHog, Inc. | Website analytics | USA |
| GitHub, Inc. (a Microsoft company) | Website hosting (GitHub Pages) | USA |
We do not sell your personal data.
4. International data transfers
Some of the providers above are located in the United States. Where personal data is transferred outside the EU/EEA, we ensure an adequate level of protection — in particular through the EU–U.S. Data Privacy Framework, where the provider is certified, and/or through the European Commission’s Standard Contractual Clauses together with additional safeguards where required.
5. How long we keep data
- Newsletter data: until you unsubscribe or withdraw your consent.
- Contact-form data: for as long as needed to handle your enquiry, and up to 6 months afterwards, unless a longer period is required (for example, if it leads to a contract).
- Outreach data: only while there is a legitimate interest in contacting you; erased promptly if you object or request erasure. Opt-out records are retained on a suppression list for the sole purpose of honouring your opt-out.
- Analytics data: for the retention period configured in each tool (Google Analytics: up to 14 months; PostHog: per our configuration).
- Server logs: kept only for a short period for security and diagnostics.
6. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data rectified (Art. 16);
- have your data erased (Art. 17);
- restrict processing (Art. 18);
- receive your data in a portable format (data portability, Art. 20);
- object to processing based on legitimate interests (Art. 21) — including an absolute right to object to direct marketing at any time; and
- withdraw consent at any time (Art. 7(3)), without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, contact privacy@frequentist.org.
7. Right to complain
If you believe your data is being processed unlawfully, you have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit Alt-Moabit 59–61, 10555 Berlin, Germany www.datenschutz-berlin.de
8. Changes to this policy
We may update this Privacy Policy to reflect changes to our website, tools, or legal requirements. The current version is always available on this page, with the “last updated” date shown at the top.