Skip to content
Multiplicity
  • About
  • Projects
  • Build
P
Multiplicity · Legal notice

Privacy

How multiplicity.dev handles personal data, including processors used for hosting, email, contact enquiries, reader submissions, GDPR rights, and controller information.

Updated 19 July 2026

Controller

Controller for the processing of personal data on this website:

David Cole
Im Bachwinkel 11
66113 Saarbrücken
Germany
Email: hello@multiplicity.dev

Purpose of this website

multiplicity.dev is a professional website for editorial content, professional background information, project information, and historical material about a closed Executive AI cohort. The website provides:

  • informational pages
  • professional and editorial content
  • paper comments and selected project submission forms
  • contact options by email and an online enquiry form
  • inquiries about projects and professional services

Contact by email

If you contact us by email, we process the information you provide, such as:

  • your name
  • your email address
  • your message
  • any other information you choose to send

We process this data to respond to your inquiry and to handle any follow-up communication.

Legal basis:

  • Article 6(1)(b) GDPR where the communication relates to pre-contractual steps or a contract
  • Article 6(1)(f) GDPR for general business communication and response handling

Contact form

The online contact form at /contact/ provides a direct route for general enquiries. If you use it, the following data is processed:

  • your name, if you provide it
  • your email address
  • your message
  • the date and time of submission
  • a salted hash of your IP address, used only for short-term rate limiting and abuse prevention

The message is stored in the site’s Cloudflare D1 database and is not published. Ordinary site-administrator access is through the Cloudflare Access-protected administration area; Cloudflare also processes the data as the site’s infrastructure provider. Cloudflare Turnstile processes technical data, including IP address and browser characteristics, to distinguish people from automated abuse. Its token and any security-cookie behavior are described under “Cookies and similar technologies” below.

The site may send an internal notification through Resend when a new enquiry arrives. The notification contains no name, email address, or message text; it only points the administrator to the protected contact inbox. Replies are sent by email through Google Workspace.

Contact-form data is not added to a marketing list and is not used for advertising, profiling, or unrelated analytics.

Legal basis:

  • Article 6(1)(b) GDPR where the enquiry concerns pre-contractual steps or a contract
  • Article 6(1)(f) GDPR for general business communication, response handling, service security, and abuse prevention

Retention: the contact system deletes messages more than 12 months old and clears salted IP hashes after 48 hours. Cleanup runs when the system next receives a submission or the protected inbox is opened, so deletion may occur after the stated period rather than at an exact minute if the system has no intervening traffic. If an enquiry results in a contract, legal claim, or another record subject to a longer legal retention requirement, the necessary record may be retained separately for that purpose.

Do not use the form to send passwords, health records, confidential client information, or other sensitive personal data.

Registration and paid offers

The Executive AI page is a historical document about a closed cohort. It does not advertise an active course or registration. There is currently no active payment checkout on this website.

If you inquire by email about a current or future paid offer, personal data may be processed for:

  • registration or interest-list handling
  • pre-contractual communication
  • billing and accounting if a paid arrangement is agreed separately
  • fulfillment and customer communication

Legal basis:

  • Article 6(1)(b) GDPR for contract performance and pre-contractual steps
  • Article 6(1)(c) GDPR where retention is required by tax or commercial law
  • Article 6(1)(f) GDPR for security and business administration

If a future web checkout or payment processor is added, this privacy notice and any required consent or legal information will be updated before that flow goes live.

Cookies and similar technologies

The website is intended to operate without non-essential analytics, marketing tags, or comparable third-party tracking technologies unless this privacy notice and any legally required consent mechanism are updated accordingly.

If you use the light/dark theme control, multiplicity.dev stores one entry in this browser’s local storage: theme, with the value light or dark. It is used only to restore the display theme you selected on later pages and visits. The value remains in this browser until another selection overwrites it or you clear this site’s stored data. It contains no identifier or history, is not submitted to Multiplicity’s server, and is not used by Multiplicity for analytics, profiling, advertising, or experimentation. If you do not use the control, no theme value is stored; on mobile-width screens the site may follow your device’s color-scheme preference without storing it. No language preference is stored.

Cloudflare Turnstile normally returns a single-use verification token rather than setting a cookie. Cloudflare’s optional pre-clearance or security-challenge functionality can also issue a cf_clearance cookie. If Cloudflare issues that cookie, it is used only to establish security clearance and prevent automated abuse; Multiplicity does not use it for analytics, profiling, or marketing.

One project page (/projects/formative-grapher/) offers an embedded YouTube tutorial. The video is not loaded when you visit the page. A static preview image is shown instead, served from this site. Only if you explicitly click the play button does the embed load from YouTube’s privacy-enhanced domain (youtube-nocookie.com), which contacts Google’s servers and may set cookies on Google’s domains. If you do not click play, no request is made to YouTube or Google.

If non-essential analytics, advertising tools, embedded third-party services, or comparable tracking technologies are added later, this privacy notice and any legally required consent mechanism must be updated before those changes go live.

Reader comments and benchmark submissions

Paper pages on this site (/papers/*) may include a comment form where readers can submit a short public note on the article.

The AI behavior-analysis benchmark page (/projects/ai-behavior-analysis-benchmark/) may include an open-call submission form where readers can submit challenge cases, examples, or related notes. The same underlying submission system is used for these forms.

If you submit a paper comment or benchmark/open-call contribution, the following data is processed:

  • your name, if you provide it (published alongside an approved public submission; otherwise shown as “Anonymous”)
  • your email address (optional; not published; used only if we need to follow up about the submission or its moderation)
  • the text of your comment or contribution
  • whether you marked the submission private or suitable for public posting
  • a salted hash of your IP address (not the IP itself), stored solely to rate-limit submissions and deter abuse
  • the date and time of submission
  • the version, date, and source of your processing consent

Submissions are not published automatically. Each submission is held for manual review. The form asks separately for consent to process the submission and permission to publish it. Public paper comments may be displayed if approved. Benchmark/open-call submissions are used for editorial review and benchmark or challenge development; they are published only if you selected the publication option and the submission is approved. Rejected, private, or deleted submissions are not displayed publicly.

Benchmark cases should be synthetic or de-identified. Do not submit real names, contact details, health records, or confidential or identifying client details.

The form is protected against automated abuse by Cloudflare Turnstile. Turnstile may process technical data (including IP address and browser characteristics) to verify that a submission is not automated. Its token and possible security-cookie behavior are described above. This processing is provided by Cloudflare, Inc. under its own terms and privacy policy.

The site may send an internal moderation notification through Resend, Inc. when a new submission is awaiting review. These notifications are configured not to include the submitter’s name, email address, or submission body.

Legal basis:

  • Article 6(1)(a) GDPR (consent) for processing a voluntary submission and, separately, for publishing the contribution and any name you provide
  • Article 6(1)(f) GDPR for abuse prevention, rate limiting, and Turnstile verification

Retention: published comments and public benchmark/open-call contributions are retained as part of the site’s public record until deletion is requested. Optional email addresses are removed when a submission is approved. Unpublished and private submissions are deleted after 90 days through routine submission-system cleanup. Salted IP hashes are used only for short-term rate limiting, become eligible for deletion after 48 hours, and are not retained with published content. Cleanup runs when the submission system next handles traffic, so deletion may occur shortly after the stated period rather than at an exact minute.

To request deletion of a comment or contribution you submitted, or to withdraw consent to processing or publication, contact hello@multiplicity.dev. Withdrawal does not affect processing that was lawful before withdrawal.

Web fonts

This website uses the Newsreader and Roboto Mono typefaces. Web fonts are intended to be self-hosted and served directly from this site’s infrastructure, meaning no request to an external font provider (such as Google Fonts) is made when you visit a page.

If the technical implementation changes and fonts are loaded from an external provider, this privacy notice and any required consent mechanism will be updated before that change goes live.

Hosting and technical delivery

This website is hosted and delivered using Cloudflare services. In the course of operating and delivering the site, technical data may be processed, including for example:

  • IP address
  • request metadata
  • browser and device information
  • access logs
  • security and performance data

This processing is used to provide the website securely and reliably.

Legal basis:

  • Article 6(1)(f) GDPR for secure and reliable website operation

Email infrastructure

Business email is handled through Google Workspace. If you contact us by email, your communication is therefore processed through Google’s infrastructure for email delivery, storage, and administration.

Legal basis:

  • Article 6(1)(b) GDPR where relevant to pre-contractual or contractual communication
  • Article 6(1)(f) GDPR for efficient and secure business communications

Recipients

Personal data may be disclosed to service providers used to operate the website and business, in particular:

  • Cloudflare for hosting and technical delivery
  • Google Workspace for email handling
  • Resend for internal submission and contact notifications that do not include submitter contact details or message text

Data may also be disclosed where legally required or where necessary to establish, exercise, or defend legal claims.

International transfers

Cloudflare and Resend may process personal data outside the European Union or European Economic Area, including in the United States. Their data-processing terms incorporate the European Commission’s Standard Contractual Clauses for restricted EEA transfers that are not covered by an adequacy decision. See the Cloudflare Data Processing Addendum and Resend Data Processing Addendum.

Retention

We retain personal data only for as long as needed for the relevant purpose, including:

  • responding to inquiries
  • performing contracts
  • maintaining business records
  • meeting legal retention obligations

Where statutory retention obligations apply, the relevant data may be stored for the legally required period.

Your rights

Under the GDPR, you may have the right to:

  • access your personal data
  • rectify inaccurate data
  • erase data
  • restrict processing
  • object to processing
  • receive data portability where applicable
  • lodge a complaint with a supervisory authority

To exercise these rights, use the online contact form or email hello@multiplicity.dev.

Mandatory provision of data

You are not generally required to provide personal data to browse the informational pages of this site. However, certain data may be necessary if you contact us or register for a paid offer.

Changes

This privacy notice may be updated if the site, business structure, processors, or legal requirements change.

Multiplicity

Editorial · Operator notes · Practical AI

© 2026 David M. Cole · multiplicity.dev

Sections

  • Front Page
  • Projects
  • Build
  • Executive AI archive

Masthead

  • About
  • Contact
  • Impressum
  • Privacy
  • Terms