Privacy Policy
Privacy Policy
Last updated 3 August 2026
1. Data controller
The controller responsible for the processing of personal data through this website is
Peter Freitag
Krongasse 3
1050 Vienna
Austria
Email: operator@proofofanalysis.com
Further legal information is available in the Legal Notice / Impressum.
2. Scope of this policy
This Privacy Policy explains how personal data is processed when visitors access Proof of Analysis, register as members, subscribe to newsletters, purchase a paid membership or contact the website operator.
Personal data means any information relating to an identified or identifiable natural person.
3. Website access and hosting
This website is hosted through Ghost(Pro), a service provided by Ghost Foundation Ltd. When the website is accessed, technical information may be processed to deliver the requested content, maintain security and diagnose errors. Such information may include the IP address, browser type, operating system, requested page, referring page, date and time of access and technical log data.
The legal basis is Article 6(1)(f) GDPR. The legitimate interests are the secure, reliable and efficient operation of the website.
Ghost Foundation processes data on behalf of the website operator where it provides hosting, membership, newsletter and publication services. Information about Ghost’s privacy and data-processing practices is available through the Ghost GDPR information and the Ghost Data Processing Agreement.
4. Membership accounts
When a visitor registers for a free or paid membership, the email address and membership status are processed. Ghost may also record the registration date, referral source, page viewed at the time of registration and membership activity required to operate the account.
This processing is necessary to create and administer the requested membership. The legal basis is Article 6(1)(b) GDPR. Where processing is required to protect the service against abuse or maintain account security, Article 6(1)(f) GDPR also applies.
Members can request access to, correction of or deletion of their account data by contacting the email address stated above. Statutory retention obligations may limit immediate deletion of individual records.
5. Newsletters
Members may receive newsletters and publication emails according to their subscription settings. The email address is used to deliver these communications and administer subscription preferences.
For free newsletter subscriptions, processing is based on consent under Article 6(1)(a) GDPR. Consent may be withdrawn at any time through the unsubscribe link included in every newsletter or through the member account. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
For paid members, service-related communications may also be processed under Article 6(1)(b) GDPR where they are necessary to provide the membership.
Ghost may measure newsletter delivery, opens and link clicks to evaluate publication performance. The legal basis is Article 6(1)(f) GDPR. The legitimate interest is improving editorial relevance and email delivery. Members may object to this processing by contacting the website operator.
6. Paid memberships and Stripe
Payments for paid memberships are processed through Stripe. When a paid subscription is initiated, Stripe processes the information required to complete the payment, prevent fraud, administer recurring billing and comply with legal obligations. This may include the email address, payment method information, billing information, transaction data, device information and IP address.
Proof of Analysis does not receive or store complete payment-card details. The website operator receives the customer, subscription and transaction information required to administer the membership and maintain accounting records.
The legal basis for payment processing is Article 6(1)(b) GDPR. Processing required for tax, accounting or anti-fraud obligations is based on Article 6(1)(c) GDPR or Article 6(1)(f) GDPR, as applicable.
Further information is available in the Stripe Privacy Policy.
7. Website analytics
Proof of Analysis uses Ghost’s native first-party analytics to understand how visitors and members interact with published content.
Ghost’s web analytics do not use cookies or persistent browser storage to identify visitors across sessions, browsers or devices. Unique visitors are counted within limited time windows. For Ghost(Pro) publications, analytics data is stored in European Union regions.
Analytics may include page views, approximate location at country level, referral source, device or browser information and content engagement. When a member is logged in, Ghost may record the member ID and whether the account is free or paid in order to understand engagement by audience segment.
The legal basis is Article 6(1)(f) GDPR. The legitimate interests are measuring publication performance, improving the website and developing relevant research products.
8. Fonts
This website loads fonts through Bunny Fonts. Bunny Fonts describes its service as privacy-focused and states that font requests are processed without cookies, tracking or storage of personal data.
Further information is available from Bunny Fonts and the bunny.net Privacy Policy.
9. Contact
When a person contacts Proof of Analysis by email, the submitted contact details and message content are processed to respond to the enquiry and manage any resulting communication.
The legal basis is Article 6(1)(b) GDPR where the enquiry concerns a contract or requested service. Other enquiries are processed under Article 6(1)(f) GDPR. The legitimate interest is responding to legitimate correspondence.
10. Cookies and local storage
The public website uses Ghost’s cookie-free first-party web analytics. Strictly necessary cookies or comparable storage may be used for member authentication, account security, payment processing and the operation of Ghost Portal. These technologies are required to provide functions expressly requested by the user.
Proof of Analysis does not currently use third-party advertising cookies or Google Analytics. If additional analytics, advertising or embedded services are introduced, this Privacy Policy and any required consent mechanism will be updated.
11. Recipients and international transfers
Personal data is disclosed only where necessary to operate the publication, provide memberships, process payments, deliver email, comply with legal obligations or protect legitimate rights.
Relevant service providers currently include Ghost Foundation Ltd and Stripe group companies. Some providers may process data outside the European Economic Area. Where required, transfers are protected through an adequacy decision, Standard Contractual Clauses or another mechanism recognised under Chapter V GDPR.
12. Retention
Personal data is retained only for as long as necessary for the relevant purpose.
Membership data is generally retained while the account remains active and for a reasonable period afterward where required for administration, dispute resolution or security. Transaction and accounting data is retained for the periods required by Austrian tax and commercial law. Correspondence is retained for as long as necessary to address the enquiry and any resulting legal obligations.
13. Data-subject rights
Subject to the conditions established by the GDPR, data subjects may request
- access to their personal data
- correction of inaccurate data
- deletion of personal data
- restriction of processing
- data portability
- objection to processing based on legitimate interests
- withdrawal of consent with future effect
Requests may be sent to operator@proofofanalysis.com. Proof of identity may be requested where necessary to protect account information.
14. Right to lodge a complaint
Data subjects may lodge a complaint with the Austrian Data Protection Authority.
Österreichische Datenschutzbehörde
Barichgasse 40–42
1030 Vienna
Austria
Further information is available at dsb.gv.at.
15. Automated decisions
Proof of Analysis does not use personal data for automated decision-making that produces legal effects or similarly significant effects within the meaning of Article 22 GDPR.
16. Changes to this policy
This Privacy Policy may be updated when legal requirements, website functions or service providers change. The current version is identified by the date stated at the beginning of the page.