Legal · Privacy
Privacy, clearly explained.
MathCoder uses optional, consent-based PostHog statistics and no advertising trackers or profiling. This notice explains that choice and the limited processing needed to deliver the site, handle enquiries and present project work.
Controller and scope
The controller is Dimitris Tsoukalos (MathCoder), based in Patras, Greece. This notice applies to the public website at mathcoder.com. Privacy questions and rights requests can be sent to tsoukalos@mathcoder.com.
Separate mobile applications and external services have their own privacy information.
Visiting the website
Before you make a choice, or after you reject analytics, the website sends no analytics request to PostHog. It does not use advertising pixels, fingerprinting, third-party embeds or PostHog browser storage. Your browser still sends technical request data to the hosting infrastructure so a page or file can be delivered. This may include your IP address, date and time, requested URL, response status, browser or user-agent information and a referring address if your browser supplies one.
This information is processed to deliver the website, maintain availability, prevent abuse and investigate faults or security incidents. The legal basis is the legitimate interest in providing a secure, reliable and deliberately minimal public website (Article 6(1)(f) GDPR).
Contact enquiries
If you open and use the contact form, MathCoder processes the email address and message you provide, the optional name, the page or button from which you opened the form, and ordinary delivery metadata. Email and message are required so the enquiry can be sent and answered; the name is optional. There is no statutory or contractual obligation to provide these details, but without the required fields MathCoder cannot receive or respond through the form. Please do not include sensitive personal data unless it is genuinely necessary for your request.
The purposes are to deliver and answer your enquiry, discuss a possible project, provide requested services and send a short acknowledgement to the submitted email address. The legal basis is taking steps at your request before a contract, or performing a contract, when you are personally the prospective or existing contracting party (Article 6(1)(b)). If you write on behalf of an organisation, or your message is ordinary correspondence rather than a contractual request, the basis is MathCoder's legitimate interest in receiving and answering relevant correspondence (Article 6(1)(f)). The separate security processing described below is based on the legitimate interest in preventing misuse of the form.
Necessary contact-form session
Opening the form creates a first-party cookie named
mathcoder_contact_session. It binds a short-lived anti-forgery token to
your browser so the requested form can operate securely. The cookie is restricted to
the contact endpoint, is HttpOnly and SameSite=Strict, and is marked
Secure on the production HTTPS site. It expires when the browser session ends; the
server-side anti-forgery token is valid for no more than one hour, and the session is
destroyed after a successful submission. It is not used for analytics or advertising.
Because it is strictly necessary for a service you request, it is used without consent.
See the Cookie Notice.
The server limits form-token requests and accepted submissions per IP address and also limits repeated acknowledgements to the same email address. It stores keyed, pseudonymous representations of the relevant IP or email address with timestamps in non-public temporary storage; the raw value is not placed in the rate-limit filename. A record stops being considered after ten minutes. Expired files are removed during periodic form requests or by server temporary-storage maintenance. The purpose and legal basis are abuse prevention and the legitimate interest in protecting the service and third parties from unwanted messages (Article 6(1)(f)).
Your analytics choice
When you accept or reject analytics, MathCoder stores one first-party preference cookie
named mathcoder_consent. It contains the choice, a timestamp and the
applicable banner/notice version, but no name, email address or PostHog identifier. It
lasts for 180 days for both acceptance and rejection, after which the site asks again.
It is necessary to remember and honour your choice and to demonstrate the consent flow,
so it is used without separate consent. The corresponding GDPR bases are compliance
with the consent-accountability duty in Article 7 (Article 6(1)(c)) and MathCoder's
legitimate interest in avoiding repeated prompts (Article 6(1)(f)).
If you accept, the consent timestamp and notice version are also included in a PostHog consent event. A rejected choice stays only in the first-party preference cookie and is never sent to PostHog.
Optional PostHog analytics
PostHog analytics remains completely off unless you select “Accept analytics”. After acceptance, a first-party MathCoder script sends a limited event to PostHog EU Cloud for a page view, project or filter selection, contact-form open, successful submission or technical error, and an external-link click. For an external link, only the destination hostname is sent. Contact-form names, email addresses, messages and other field contents are never included.
Each event contains the event type, a fixed route label selected from MathCoder's
published-page allowlist, the consent-notice version and a random identifier held only
in memory for that page. Unknown or not-found addresses are sent only as
/404, never as the address entered by the visitor. The PostHog request
necessarily exposes ordinary network information such as
the IP address and user-agent while it is delivered. MathCoder asks PostHog not to
enrich events with GeoIP data, does not create a person profile and does not use the
PostHog SDK, cookies, localStorage, session replay, autocapture, surveys, heatmaps or
advertising features.
The purpose is to understand aggregate use of pages and projects and improve the site. The legal basis is your consent (Article 6(1)(a) GDPR and the applicable electronic- communications rules). Refusing has no effect on the website or contact form. You can withdraw consent at any time through the “Cookie settings” button in every page footer; the script stops future analytics requests immediately. Withdrawal does not affect processing carried out before it.
A prior site version collected limited PostHog events before this consent control was available. Those historical events are not used for measurement and must be deleted before this notice becomes effective. Only a minimal private deletion record may then be retained for accountability and legal claims; the historical event dataset itself is not retained for that purpose. This does not change the legal requirements that applied when the events were collected.
Project imagery
Portfolio pages may show identifiable people. The MyVoice case study includes images of a child using the application and smaller images visible within the tablet interface; the UPRAISE case study also includes event participants. The images are used to present the relevant project. Before publishing an identifiable person, MathCoder must record permission covering the exact image, context, placements, audience and publication period. The legal basis is that recorded consent (Article 6(1)(a)); for a child, consent is provided by a parent or legal guardian. Where the context reveals or supports an inference about health or disability, explicit consent under Article 9(2)(a) is required. An image is not published if the necessary permission cannot be demonstrated.
These images are accessible to website visitors worldwide. Search engines, browsers and other services may receive or cache them, although MathCoder requests that the relevant child images are not indexed and does not use them as social-preview metadata. Consent may be withdrawn at any time by emailing the controller. MathCoder will then remove controlled copies and request feasible cache removal; withdrawal does not affect processing that was lawful before it.
Recipients and international transfers
Personal data is not sold and is not shared with advertisers. Limited data may be handled by Hostinger and the subprocessors actually used for web hosting, CDN delivery, PHP execution, access logs, email delivery, mailbox operation, backups, spam prevention and security. The email provider serving the address you submit receives the delivery metadata and generic acknowledgement addressed to you. Professional advisers or public authorities receive information only where necessary and lawfully required. PostHog Inc. processes consented analytics events as MathCoder's processor.
Hostinger states that its services may process customer data in the United Kingdom, the Netherlands, Lithuania, Cyprus and, depending on the selected service and subprocessor, other jurisdictions. For a transfer from the EEA to a country without an applicable European Commission adequacy decision, the controller-to-processor Standard Contractual Clauses incorporated into Hostinger's Data Processing Addendum apply, together with supplementary safeguards where required. PostHog's EU Cloud stores analytics event data in Frankfurt, while PostHog Inc. and its listed subprocessors may process data outside the EEA, including in the United States, to provide the service. PostHog states that it participates in the EU–US Data Privacy Framework; its customer data-processing agreement also incorporates the controller-to-processor Standard Contractual Clauses as an additional transfer safeguard. You may request a copy or information about the safeguard relevant to your data using the contact address above.
Google Play, the Apple App Store, LinkedIn, YouTube and linked project websites receive data only after you choose to follow an external link. Their own privacy information then applies.
Retention
- Hosting access logs: recent identifiable access records are available to MathCoder in the Hostinger dashboard for a rolling period of up to seven days. A relevant record is isolated for longer only when needed to investigate a specific security incident, and is then deleted when that investigation and any related claim period end. Processor-side security logs and disaster-recovery copies follow the fixed schedules for the services selected in the Hostinger account.
- Contact security data: the form token is valid for up to one hour, the cookie lasts for the browser session or until a successful submission, and rate-limit entries are active for ten minutes as described above.
- Analytics choice: acceptance and rejection are each remembered for 180 days. A materially changed purpose or notice requires a new choice sooner.
- Consented PostHog events: MathCoder's retention policy, including for the minimal acceptance event, is a maximum of 12 months after collection. This version must not be released until the matching PostHog project setting has been verified.
- General enquiries: normally deleted within 12 months after the last meaningful exchange from the inbox, sent and deleted folders and other copies or exports controlled by MathCoder. If an earlier deletion is requested, it is carried out unless an overriding lawful reason applies. A residual copy in an isolated disaster-recovery backup is overwritten at the end of the provider's next fixed backup-rotation cycle and is not used for ordinary purposes.
- Enquiries connected to a dispute or claim: the relevant correspondence may be retained until the matter is resolved and the applicable limitation period has expired, based on MathCoder's legitimate interest in establishing, exercising or defending legal claims (Article 6(1)(f)). If an enquiry becomes a client engagement, additional contract and statutory record-keeping information is provided when the different processing begins.
- Identifiable portfolio imagery: kept online for the agreed publication period and while the relevant consent remains valid. Evidence of consent is retained while the image is published and afterwards until the applicable limitation period expires, based on MathCoder's legitimate interest in demonstrating compliance and establishing, exercising or defending legal claims (Article 6(1)(f)).
- Historical PostHog events: this version must not be released until their deletion has been completed and verified.
Your rights
Depending on the circumstances, you may request access to, correction or deletion of your personal data, restriction of processing, or portability of data you provided. You may object to processing based on legitimate interests. Where processing is based on consent, you may withdraw that consent at any time without affecting earlier lawful processing.
Send requests to tsoukalos@mathcoder.com. MathCoder responds without undue delay and normally within one month, requesting only information reasonably necessary to verify identity. You may also lodge a complaint with the Hellenic Data Protection Authority or the supervisory authority where you live or work.
Automated decisions and security
MathCoder does not profile website visitors and does not make decisions about them by automated means. Data minimisation, encrypted HTTPS delivery and proportionate access controls are used, but no internet transmission or storage method can be guaranteed completely secure.
Changes
This notice will be updated before materially different processing begins. Version dated 4 September 2026; effective when this version is released to production.