Legal
Privacy Policy
Last updated: 4 September 2026 · Effective: 4 September 2026
The short version. We sell nothing about you and we share nothing for advertising. We collect what you type into our forms, plus the ordinary technical data any website receives. We run no Google trackers of any kind, including Analytics, Fonts, and reCAPTCHA. Blog comments are switched off, so we collect no comment data.
We ask one thing of you. Please do not upload confidential, medical, financial, or personal data about other people through this Site. Section 12 and our Terms of Service explain why.
- Scope and who we are
- Notice at collection
- Information we collect
- Where the information comes from
- How and why we use it
- Cookies, analytics, and tracking signals
- Who we disclose information to
- We do not sell or share your personal information
- How long we keep it
- Security
- Your privacy rights
- Files and materials you upload
- Email you receive from us
- Children
- No automated decision-making
- Third-party links
- Visitors outside the United States
- Changes to this Policy
- Contact
1. Scope and who we are
This Privacy Policy explains how Philip Sarajlic, sole proprietor, doing business as QuantHorizon (“we”, “us”, “our”, or the “Owner”), handles personal information in connection with the website at philipsarajlic.com (the “Site”). It applies to the Site and to inquiries you send us through it. It does not apply to services delivered under a signed engagement agreement, which are governed by that agreement, nor to any third-party website we link to.
The Owner is established in Philadelphia, Pennsylvania, United States. The Site is directed to a professional audience in the United States, and it is hosted and operated there. We do not target the Site to residents of the European Economic Area or the United Kingdom, and we do not monitor the behavior of individuals located there. Section 11.3 nevertheless sets out rights we extend to visitors outside the United States as a matter of practice.
For any privacy question, or to exercise a right, write to info@philipsarajlic.com with “Privacy Request” in the subject line.
2. Notice at collection
This section gives a notice at collection in the form prescribed by the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”). It summarizes what we collect, why, and for how long. Sections 3 to 9 give the detail.
We provide this notice, and the rights described in Section 11, as a matter of practice and good faith. The Owner is a small practice that does not meet the revenue, volume, or data-sale thresholds at which the CCPA and comparable state privacy statutes apply. Nothing in this Policy is an admission or acknowledgment that any of those statutes applies to us, and we reserve all rights and defenses in that regard. We honor the rights below regardless.
| Category collected | Examples | Why we collect it | How long we keep it |
|---|---|---|---|
| Identifiers | Name, email address, IP address, organization name | Answering your inquiry, preparing a quote, security, keeping business records | Inquiries: up to 3 years. Scorecard: up to 24 months. Server and security logs: up to 12 months. |
| Commercial information | The service you are asking about, stage of the work, budget or scope indications you volunteer | Assessing and scoping possible services, preparing a quote | Up to 3 years from last contact |
| Internet or network activity | Pages viewed, referring page, date and time, browser and device type, request and error logs | Operating and securing the Site, understanding aggregate traffic | Up to 12 months |
| Professional information | Your role, employer, and anything about your work you choose to tell us | Understanding your inquiry and whether we can help | Up to 3 years from last contact |
| Scorecard answers | Your answers to thirty questions about how a system you work on was built, evaluated, documented, and monitored, and to three questions about the setting it runs in | Computing the readiness score you asked us to compute, and deciding how best to reply if you contact us | Up to 24 months from completion |
| Content you send us | Message text, uploaded files and supporting materials, proposed meeting times | Reviewing and responding to your request | Uploaded files: up to 12 months. Message text: up to 3 years. |
| Inferences | Our own notes on whether an inquiry is a fit for our services | Deciding whether and how to respond | Up to 3 years from last contact |
Sensitive personal information. We do not ask for, and do not want, sensitive personal information as the CCPA defines it. That category covers government identifiers, financial-account credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, health or genetic data, biometric data, or the contents of your private communications with others. We do not use or disclose any such information for any purpose that would give rise to the right to limit its use. If you send it to us anyway, see Section 12.
Selling and sharing. We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA. See Section 8.
3. Information we collect
3.1 Information you give us
The Site has three kinds of form, and we collect exactly the fields they contain.
- Contact form. Your name, your email address, your organization, and your message.
- Consultation quote-request form. Your name, your work email address, your organization, the stage the work is at, a description of what you would like to discuss, and optionally any supporting materials you upload, your preferred meeting format, and meeting times you propose.
- Model Validation Readiness Scorecard. Your answers to thirty scored questions and three setting questions about a system you work on, every one of them chosen from a fixed list of options, together with your email address. If you tick the optional box on that form, we also record your consent to receive occasional email, with the date, the time, your IP address, and a one-way digest of the exact wording you were shown.
The scorecard in particular. Every question on it is answered by choosing from a fixed list, and it has no free-text box anywhere, so no patient data, client material, or other confidential information can reach us through it even by accident. Its answers describe a system you work on rather than describing you. Your finished report lives at a long, unguessable web address, which means anyone you send that address to can open it, and you can ask us to withdraw it at any time.
If you email us directly, we receive whatever you put in the message and its attachments, together with the ordinary email headers.
3.2 Information collected automatically when you submit a form
Our form software records the IP address and browser user-agent string of the device used to submit a form, together with the date and time and the page the form was submitted from, and stores them with the entry. We use this to investigate abuse, to distinguish genuine inquiries from automated spam, and to evidence when a request was received. Submissions our spam filter rejects are also retained for a period so that a wrongly filtered genuine inquiry can be recovered.
The readiness scorecard is a partial exception. It records a short one-way digest of the submitting IP address and browser string rather than the values themselves, together with how long the assessment took. If you tick the optional mailing-list box, we do record the submitting IP address itself, as evidence of when and from where that consent was given.
3.3 Information collected automatically when you browse
- Server logs, kept by our host, recording your IP address, the pages and files requested, response status, referring page, browser and operating system, and the date and time.
- Security data, processed by our web-application firewall, which inspects incoming requests and consults IP-reputation data to block attacks, brute-force attempts, and malicious traffic.
- Scorecard progress, if you begin the readiness scorecard, recording which question number you reached and when, against a random identifier your own browser generates for that sitting, and never the answers themselves
- Aggregate traffic statistics, described in Section 6.
3.4 What we do not collect
To be explicit, because these are common on other sites and absent here.
- No Google services. The Site runs no Google Analytics, no Google Tag Manager, no Google Ads or remarketing tags, no reCAPTCHA, and no Google Fonts. Our typefaces are served from our own server, so browsing the Site sends nothing to Google.
- No advertising or marketing trackers, and no third-party advertising cookies. We do not operate any advertising network, retargeting pixel, or social-media tracking pixel.
- No blog comments. Comments are disabled across the entire Site, so we collect no commenter names, email addresses, or comment IP data, and no avatar lookup is performed for them.
- No user accounts. The Site has no public registration, so we hold no visitor account credentials.
- No payments. The Site takes no payments and collects no card or bank details.
If any of this changes, we will update this Policy before the change takes effect.
4. Where the information comes from
You give us personal information directly when you complete a form or email us. Your device and browser supply some automatically when you visit, as described in Sections 3.2, 3.3, and 6. Our hosting, security, and statistics providers also pass it to us while acting on our behalf. We do not buy personal information, and we do not obtain it from data brokers.
5. How and why we use it
We use personal information for these business purposes, and for no others.
- to read, assess, and answer your inquiry, and to prepare and send a quote
- to arrange, confirm, and hold a consultation, and to scope and deliver professional services
- to send you service messages about a request you have made, such as an acknowledgment or a confirmed meeting time
- to compute the readiness score you asked us to compute, and to send you the report
- to operate, maintain, debug, and improve the Site
- to keep the Site secure, and to detect, investigate, and prevent spam, fraud, abuse, and attacks
- to understand aggregate traffic patterns, such as which articles are read
- to keep business, accounting, and tax records
- to establish, exercise, or defend legal claims, and to comply with law and lawful requests.
We do not use your information for automated advertising, behavioral targeting, cross-context profiling, or any scoring of you as a person, and we do not use the content of your inquiries to train machine-learning models.
The one calculation we do run. If you complete the Model Validation Readiness Scorecard, we compute a readiness score from the answers you give us about your own system, because computing it is the thing you asked us for. The arithmetic is published in full on our methodology page. It uses no machine-learning model and no language model, no third-party service takes any part in it, and it scores the system you described rather than scoring you. Where you go on to contact us, we also read the result to work out how best to reply.
6. Cookies, analytics, and tracking signals
6.1 Cookies
A cookie is a small file a site stores in your browser. The Site uses cookies in two categories.
- Strictly necessary. Set by WordPress and by our caching and security layers so that pages load correctly, forms submit safely, spam is filtered, and administrator sessions work. The Site cannot function without them.
- Statistics. Set or read in connection with the aggregate traffic measurement described in Section 6.2.
- Scorecard. If you unlock a readiness report, one cookie records which report is yours so that this browser can reopen it. It lasts 30 days, scripts running on the page cannot read it, and it holds a random reference rather than anything about you.
The scorecard also keeps your answers in your own browser’s local storage while you work through it, so that a refresh, a closed tab, or a locked phone does not lose your progress. That storage stays on your device, it is not sent to us while you answer, and it is cleared as soon as your report is delivered. Clearing your browsing data removes it.
You can block or delete cookies in your browser settings, and most browsers let you refuse them by site. Blocking strictly necessary cookies will stop parts of the Site working, including the forms.
6.2 Traffic statistics
We measure aggregate traffic using Jetpack Stats, a service of Automattic Inc. When you view a page, it records the page viewed, the referring page, and general browser and device information, and it processes your IP address to approximate location at country level and to avoid counting the same visitor twice. We use this only to see which articles are read and how many people read them. We do not use it to build a profile of you, we do not combine it with your inquiry, and we make no attempt to identify you from it.
Automattic also provides the login-protection service that blocks brute-force attempts against the Site’s administrator account, which involves processing the IP addresses of login attempts. Automattic’s privacy notice is at automattic.com/privacy.
6.3 Do Not Track and Global Privacy Control
Our traffic statistics are configured to honor the “Do Not Track” browser signal. If your browser sends it, your visit is excluded from measurement. Because we do not sell or share personal information, there is nothing for a Global Privacy Control signal to opt you out of. We nevertheless treat an incoming GPC signal the same way as Do Not Track. Most browsers let you enable one or both in their privacy settings.
7. Who we disclose information to
The Owner is a one-person practice. Personal information is accessible to the Owner and, where necessary, to the service providers below. Each processes information in connection with the service it supplies to us, under its own terms of service and privacy notice, which we have reviewed and which you can read for yourself at the links given. We instruct them to process information only for the purposes of providing their service to us.
| Provider | Role | What it processes |
|---|---|---|
| Hostinger International Ltd privacy notice |
Web hosting, database, email delivery, backups | Everything stored on or transmitted through the Site, including form entries, uploaded files (in encrypted form), and server logs |
| Automattic Inc. privacy notice |
Jetpack (traffic statistics and login protection) | Page views, referring page, browser and device data, IP address |
| Defiant, Inc. (Wordfence) privacy notice |
Web-application firewall and malware scanning | IP address and request data of incoming traffic, IP-reputation lookups |
| Awesome Motive, Inc. (WPForms) privacy notice |
Form and anti-spam software | Runs on our own server. Form entries are stored in our own database and are not sent to the vendor |
Outbound email is sent through our host’s mail service. For each message the Site sends we keep a log of the recipient, subject, date, and status in our own database, so that we can confirm delivery and investigate failures.
Beyond those providers, we disclose personal information only in the situations below.
- to professional advisers such as accountants, insurers, and lawyers, where they need it and are bound by confidentiality
- where required by law, regulation, subpoena, court order, or other lawful request, or to respond to a government or law-enforcement demand we reasonably consider valid
- to establish, exercise, or defend legal claims, or to enforce our Terms of Service
- to protect the rights, property, or safety of the Owner, our visitors, or the public, including to prevent fraud or a security incident
- to a successor in a merger, reorganization, incorporation, or sale of the business or its assets, in which case we will require the recipient to honor this Policy or give you notice and a choice before any materially different use.
Where the law allows, we will make reasonable efforts to notify you before disclosing your information in response to a legal demand.
8. We do not sell or share your personal information
We have never sold personal information, and we do not sell it. We do not share personal information for cross-context behavioral advertising. We have not sold or shared the personal information of any consumer, including any consumer under 16 years of age, in the preceding twelve months. We do not disclose personal information to third parties for their own direct-marketing purposes, and we do not participate in any advertising exchange or data co-operative.
Disclosures to the service providers listed in Section 7 are made for business purposes under contracts that prohibit them from retaining, using, or disclosing the information for anything other than performing the service for us.
9. How long we keep it
We keep personal information only as long as we need it for the purposes in Section 5, and then delete or anonymize it. Our retention schedule:
| What | How long |
|---|---|
| Inquiry and quote-request entries, and the correspondence about them | Up to 3 years from our last contact with you, then deleted |
| Files and supporting materials you upload | Up to 12 months from submission, then deleted, unless an engagement agreement provides otherwise |
| Entries filtered as spam | Up to 90 days, then deleted |
| Outbound email logs (delivery metadata only, with no message bodies and no attachments) | Up to 12 months |
| Server, firewall, and security logs | As configured by our host and firewall, typically up to 12 months, or longer for a specific record under active investigation |
| Aggregate traffic statistics | Retained in aggregate form indefinitely. It identifies no individual |
| Readiness scorecard answers, and the report built from them | Up to 24 months from completion, then deleted |
| Scorecard assessments that were never unlocked with an email address | Up to 90 days, then deleted |
| Scorecard progress records | Up to 12 months, then deleted |
| Records of client engagements, invoices, and tax records | As long as tax, accounting, and limitation law requires, currently up to 7 years |
| Backups | Deleted information persists in rolling backups until those backups are overwritten in the ordinary cycle, typically within 90 days |
We may keep information longer where we need it to establish, exercise, or defend a legal claim, to comply with a legal obligation, or to give effect to a request you have made.
10. Security
We take reasonable and appropriate technical and organizational measures to protect personal information. As at the date of this Policy they include the following.
- encrypted HTTPS connections across the whole Site
- a web-application firewall, malware scanning, and automated blocking of brute-force login attempts
- files you upload are stored outside the public web root, are not reachable over the internet at any address, and are encrypted at rest using AES-256-GCM authenticated encryption, with the key held separately from the files
- uploaded files are decrypted only on request by a signed-in administrator with permission to view entries, and links to them are stripped out of notification emails
- email addresses given to the readiness scorecard are encrypted at rest using AES-256-GCM authenticated encryption, with the key derived from secrets held in the Site configuration rather than stored beside the data
- administrative activity on the Site is logged
- the Site has no public account registration, so there are no visitor credentials to compromise
- outbound email logs record delivery metadata only, with no message bodies and no attachments
- software is kept current and the Site is backed up regularly.
No method of transmission over the internet and no method of electronic storage is completely secure. We cannot guarantee absolute security, and we do not warrant that our measures will prevent every unauthorized access, loss, or misuse. You send information to us at your own risk, and you are responsible for the security of the device, network, and email account you use. If we become aware of a breach affecting your personal information, we will notify you and any regulator to the extent and within the time that applicable law requires.
11. Your privacy rights
11.1 If you are a United States resident
If you live in a state with a comprehensive privacy law, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana, you may have the rights below.
- Know and access. Confirm whether we process your personal information, and obtain the categories and specific pieces we hold, the categories of source, the business purposes, and the categories of recipient.
- Delete. Ask us to delete personal information we collected from you, subject to the exceptions the law allows.
- Correct. Ask us to fix inaccurate personal information.
- Portability. Receive a copy in a portable, readily usable format where technically feasible.
- Opt out of the sale or sharing of personal information, of targeted advertising, and of profiling with legal or similarly significant effects. We do none of these, so there is nothing to opt out of.
- Limit the use of sensitive personal information. We do not collect it for any purpose that triggers this right.
- Non-discrimination. We will not deny you service, charge you a different price, or give you a lesser quality of service because you exercised a privacy right. We offer no financial incentive for personal information.
How to make a request. Email info@philipsarajlic.com with “Privacy Request” in the subject line, and tell us what you would like us to do. Because the Site has no accounts, this is the only channel we operate.
Verification. We will ask you to give us enough information to match you to the records we hold, typically the email address you used and the approximate date of your inquiry. We use that information only to verify the request. If we cannot verify you to a reasonable degree of certainty, we will tell you why and, where the law requires it, we may decline to act.
Authorized agents. You may use an authorized agent. We will ask for written permission signed by you, and we may ask you to verify your identity with us directly.
Timing and appeals. We acknowledge requests within 10 business days and respond within 45 days, extending by a further 45 days where reasonably necessary and telling you if we do. There is no charge unless a request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or decline, and will explain why. If we decline your request, you may appeal by replying to our decision with “Privacy Appeal” in the subject line. We will respond to the appeal within 45 days with a written explanation. If we deny the appeal, you may complain to your state Attorney General.
California “Shine the Light”. California Civil Code § 1798.83 lets California residents ask about personal information disclosed to third parties for their direct-marketing purposes. We make no such disclosures.
11.2 Nevada residents
Nevada law gives residents the right to direct a business not to sell certain personal information. We do not sell personal information as Nevada law defines it, but you may submit a request to the address in Section 19.
11.3 If you are outside the United States
As set out in Section 1, the Site is directed to a United States audience and we do not offer goods or services to, or monitor the behavior of, individuals in the European Economic Area or the United Kingdom. Nothing in this Policy is an admission that the EU or UK General Data Protection Regulation applies to our processing.
That said, we will honor a request from anyone, wherever they live, to access, correct, delete, or receive a copy of the personal information we hold about them, to object to or restrict our processing of it, or to withdraw a consent they previously gave. Use the same channel and process as Section 11.1. Where we do process information about an individual to whom the GDPR applies, we rely on the legal bases below.
- Our legitimate interests in operating, securing, and promoting our practice.
- The necessity of taking steps at your request before entering into a contract, and of performing one.
- Your consent, where we have asked for it.
- Compliance with a legal obligation.
If you are unhappy with how we have handled your information, please tell us first so we can try to put it right. You may also complain to your local data-protection authority where one exists.
12. Files and materials you upload
Please do not upload confidential or regulated material through this Site. Unless we have signed a non-disclosure agreement with you, material sent through the Site is not treated as confidential.
The consultation form lets you attach supporting materials. Uploads are stored in a protected directory on our server that is not publicly listed or directly reachable by URL, and access is restricted to the Owner. The readiness scorecard accepts no uploads and contains no free-text box, so nothing can be sent to us through it.
Section 6.3 of our Terms of Service sets out what you must not send, and you should read it before uploading anything. In summary, do not send trade secrets, health or patient data, payment-card or bank details, government identifiers, education or consumer-financial records, biometric data, export-controlled material, or personal data about other people. If a dataset or document contains information about identifiable individuals, anonymize, aggregate, or redact it before you upload it. You are responsible for having the right to send us anything you send, and for obtaining any consent required from the people it concerns.
If you send us material in breach of that section, we may delete it without notice. Where we agree to process personal data on behalf of a client as part of an engagement, that processing is governed by the engagement agreement and any data-processing terms in it, rather than by this Policy.
13. Email you receive from us
If you contact us, we will reply, and we may send messages relating to your request, such as an acknowledgment, a quote, a confirmed meeting time, or a follow-up. These are service messages about a request you made.
If you complete the readiness scorecard, we email you your report. That is a service message about something you asked us for, and it goes to everyone who unlocks a report. It carries your result and a permanent link to the full report.
We operate one optional mailing list, and the only way onto it is to ask. The box that joins it appears on the readiness scorecard, it is never ticked for you, and it sits beside the exact wording it commits you to. We record what that wording said on the day you ticked it, so that a consent can always be checked against the words that produced it rather than against today’s words.
Every message we send to that list carries a working unsubscribe link. Following it takes effect immediately, with no confirmation step and nothing further to click, and it also deletes your email address from our records. We keep only a one-way digest of the address, which lets us recognize that this address asked not to be contacted without letting us read the address itself. We honor an unsubscribe promptly and in any case within 10 business days as the CAN-SPAM Act requires, and we do not sell or rent the list. Unsubscribing does not stop service messages about an active inquiry or engagement, and it does not affect a report you have already been given. You can also simply ask us to stop contacting you altogether.
14. Children
The Site is intended for a professional adult audience. It is not directed to children, and we do not knowingly collect personal information from anyone under 18, or from anyone under 13 within the meaning of the Children’s Online Privacy Protection Act. We have not sold or shared the personal information of consumers under 16, because we do not sell or share personal information at all. If you believe a child has given us personal information, write to info@philipsarajlic.com and we will delete it promptly.
15. No automated decision-making
We make no decision about you by automated means that produces a legal or similarly significant effect. Nothing on this Site decides anything about your access to a service, what you are charged, your employment, or your credit. Every inquiry is read and answered by a person.
Two things here are automated, and neither of them is a decision about you. Automated spam filtering is applied to form submissions, and a filtered submission is retained for a period so that it can be recovered if it was filtered in error. The readiness scorecard computes a score from the answers you supply about a system you work on, by arithmetic that is published in full, and returns that score to you. It is the service you asked for rather than a judgment we have formed about you, and no part of it is performed by a machine-learning model.
16. Third-party links
The Site links to third-party websites, repositories, datasets, and professional profiles. We do not control them and are not responsible for their content or their privacy practices. Following a link takes you outside this Policy, and the destination site’s own policy governs what it collects about you. We encourage you to read it.
17. Visitors outside the United States
The Site is hosted and administered in the United States, and our service providers process information in the United States and other countries. If you access the Site or send us an inquiry from outside the United States, your information will be transferred to, stored in, and processed in the United States, where data-protection law may differ from and offer less protection than the law of your country. By using the Site or sending us an inquiry, you understand that this transfer is necessary to provide the Site and to respond to you.
18. Changes to this Policy
We may update this Policy as the Site or the law changes. The revised Policy takes effect when posted on this page, and the “Last updated” date above will reflect the change. Where a change materially affects how we handle information we already hold about you, we will take reasonable steps to bring it to your attention before it takes effect, such as a notice on the Site or, if we hold your email address in connection with an active inquiry, an email. Your continued use of the Site after the revised Policy takes effect means you accept it. We keep prior versions and will provide one on request.
19. Contact
Philip Sarajlic, sole proprietor, doing business as QuantHorizon
Philadelphia, Pennsylvania, United States
Email: info@philipsarajlic.com
For a privacy request, put “Privacy Request” in the subject line. We will acknowledge it within 10 business days. A postal address for formal notices is available on request.
This Policy should be read together with our Terms of Service, which governs your use of the Site. Last updated 4 September 2026.















