Privacy Policy
This policy explains what personal data we collect through thefridayletter.com, why we collect it, the legal basis we rely on, and the rights you have over it. It is written to meet the requirements of the EU and UK General Data Protection Regulation (GDPR).
1. Who we are (data controller)
The Friday Letter, operated by Ethan Miller, is the controller of the personal data described in this policy.
Postal address is available on request. We are not required to appoint a Data Protection Officer, and enquiries are handled directly by Ethan Miller.
Contact: privacy@thefridayletter.com
2. What we collect
We deliberately collect as little as possible:
· The email address you enter into a form on this site, plus the date and time you gave consent.
· Anything you choose to tell us in a reply or an enquiry, such as your name or your business.
· Aggregated usage data from our analytics — pages viewed, approximate country, device type and referring site. We do not use this to build profiles of individuals.
3. Why we use it, and our legal basis
Under the GDPR we must tell you the lawful basis for every use of your data:
· Sending the free guide and the weekly newsletter — consent (Article 6(1)(a)), given when you tick the box on the form. You can withdraw it at any time.
· Replying to your enquiries and delivering anything you booked, such as a call — legitimate interests, or performance of a contract where one exists.
· Measuring how the site is used and improving it — consent for analytics cookies, collected through the banner on this site.
· Keeping records of consent and unsubscribes, and protecting the site from abuse — legal obligation and legitimate interests.
4. Cookies and analytics
Essential cookies keep the site working and need no consent. Analytics cookies only run if you press Accept on the cookie banner, and your choice is stored in your browser so we do not ask again. You can change your mind at any time by clearing this site’s data in your browser, which makes the banner reappear.
5. Who we share it with
We never sell your data. We share it only with the processors that make this service work — our email platform, our website host, our scheduling tool and our analytics provider — each under a data processing agreement that limits them to acting on our instructions. We will also disclose data where the law requires it.
6. International transfers and retention
Some of our processors are based outside the EEA and the UK, including in the United States. Where that happens, transfers are covered by the European Commission’s Standard Contractual Clauses or an equivalent safeguard. We keep your email address for as long as you stay subscribed, and for up to 24 months after you unsubscribe so we can prove consent was given and honour your unsubscribe. Analytics data is retained for 14 months.
7. Your rights under the GDPR
You have the right to access a copy of your data, to have it corrected or erased, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent at any time — the unsubscribe link in every email does exactly that. Email privacy@thefridayletter.com and we will respond within one month. If you are unhappy with our response you may complain to your national supervisory authority; in the UK that is the Information Commissioner’s Office.
8. Security
Data is held on reputable hosted platforms protected by encryption in transit, access controls and two-factor authentication on every account that can reach it. No system is perfectly secure, but if a breach ever affected your rights we would notify you and the relevant authority as the GDPR requires.
9. Changes to this policy, and contact
If we change how we use your data we will update this page and, where the change is significant, tell subscribers by email. The date below shows when this version took effect.
Questions about this policy: privacy@thefridayletter.com
Last updated 1 August 2026