Last updated: 10 August 2026
This policy explains how Network Frequency, LLC (“Network Frequency”, “we”, “us”) handles personal information collected through workfreq.com and its inquiry forms. It is written to be read, not to be survived.
1. Who we are
Data Controller: Network Frequency, LLC
1526 Dekalb Avenue NE, Suite 29, Atlanta, GA 30307, USA
Email: info@netfreqtv.com
2. What we collect, and why
We collect what you choose to send us through an inquiry form and, only if you click Accept, measurement of how this site is used. We do not run advertising trackers, we do not sell data, and we do not build advertising profiles or link analytics to your identity.
| What | Why | Legal basis (GDPR) |
|---|---|---|
| Name, email, phone, company | To reply to your inquiry and quote the work | Legitimate interest / steps prior to a contract |
| Project details, timeline, budget | To scope the project and respond accurately | Steps prior to a contract |
| Files you upload (briefs, decks, RFPs) | To understand the requirement | Steps prior to a contract |
| A hashed form of your IP address | Anti-spam and rate limiting only. We do not store your raw IP. | Legitimate interest (security) |
| Only if you click Accept: pages viewed, referrer, approximate location, device and browser. Your IP address is sent to Google to derive that approximate location. It does not reach us, and we do not store it. | To see which pages and which channels actually bring people here | Consent (Art 6(1)(a)) — see 2a |
What we do NOT do
- We do not set advertising cookies, and we do not use analytics for advertising, remarketing, or audience building. This site sets no cookies at all until you click Accept on the banner, and none at all ever if you decline — see section 2a.
- We do not sell or share personal information with third parties for money or for cross-context behavioural advertising. Under the CCPA/CPRA, we do not “sell” or “share” your data.
- We do not use your inquiry or your uploaded files to train AI models.
2a. Cookies and analytics
Until you choose, this site contacts no third party at all and stores nothing on your device. Nothing from Google is requested, downloaded, or run before you click Accept. If you click Decline, no third-party request is ever made — and the only thing then stored on your device is the record of that refusal itself, described below.
If you click Accept, we load Google Analytics 4 to understand which pages and which channels bring people here. That sets these cookies:
| Cookie | What it is for | How long it lasts |
|---|---|---|
_ga | Distinguishes one browser from another so visits are not double-counted | 2 years |
_ga_D5WE7CSZWN | Keeps session state for this specific property | 2 years |
Legal basis: your consent under Article 6(1)(a), collected before anything is stored, as ePrivacy Article 5(3) requires. Analytics is configured for measurement only — Google Consent Mode is set to deny advertising storage, ad user data, and ad personalisation, and this property is not linked to any advertising account.
One thing we store either way. Whichever button you press, we save that answer alone in your browser’s local storage under wf_consent_v1. It records nothing but the word granted or denied. It exists so we can honour your choice instead of asking again on every page, and it is the only reason your decision survives a reload.
You can change your mind at any time, which is the withdrawal right in section 5 made operational rather than merely promised:
Declining costs you nothing. Every page, form, and link on this site behaves identically either way; there is no content behind the banner.
3. Where it goes
Form submissions are stored in our database (Supabase, hosted in the United States) and reviewed by our team in an internal, access-controlled portal. Only Network Frequency staff who need to respond to your inquiry can see it.
Our processors: Supabase (database and file storage), Amazon Web Services (hosting/CDN), and — only if you accepted analytics — Google LLC (Google Analytics 4). All three are bound by contract to process data only on our instructions.
Transfers outside the EEA and UK. Supabase, AWS, and Google are US-headquartered. Where your data reaches the United States it is transferred under the EU-US Data Privacy Framework and, where that does not apply, the European Commission’s Standard Contractual Clauses. If you decline analytics, no data about you reaches Google at all — the transfer question simply never arises.
4. How long we keep it
- Inquiries that do not become projects: retained for up to 24 months, then deleted.
- Inquiries that become projects: retained for the life of the engagement, and afterwards for as long as the engagement contract requires and any applicable claim or tax assessment period remains open. In practice that is commonly around seven years — not because a law names that figure, but because it is the conservative envelope around those periods and it is what client contracts typically specify.
- Uploaded files: deleted on request at any time, and otherwise on the schedule above.
- Faces and other biometric data: the platform does not perform biometric identification. Automatic face detection is in build and is not enabled for any client; where a client’s team manually tags a person in an image, that tag is held on a short, separate clock and deleted when the purpose is met or the retention window closes, whichever comes first. It never inherits a longer retention period from the project it sits in. If a future release enables automatic detection, it will be an opt-in a client turns on, and this policy will say so before it ships.
- Anything under legal hold: if we are told a record is relevant to a legal matter, deletion is suspended until the matter closes. This overrides the schedule above.
5. Your rights
Wherever you live, you can ask us to do the following, and we will do it — you do not need to invoke a specific statute:
- See what we hold about you.
- Correct anything that is wrong.
- Delete it (“right to erasure” / “right to delete”).
- Get a copy in a portable format.
- Object to our processing, or ask us to restrict it.
- Withdraw consent where consent was the basis.
Email info@netfreqtv.com and we will respond within 30 days. We will not charge you, and we will not discriminate against you for asking.
If you are in the EU/UK and think we have handled this badly, you may complain to your national supervisory authority. We would rather you told us first.
6. Security
Traffic is encrypted in transit (TLS, HSTS enforced). The public site sets a Content Security Policy that names every origin it is allowed to contact; analytics was added to that list deliberately and visibly rather than slipped in. The internal portal where inquiries are reviewed is access-controlled and requires multi-factor authentication. Submissions are validated and rate-limited server-side.
To report a security issue, see our security.txt or email info@netfreqtv.com.
7. Children
This is a business-to-business site. It is not directed at children under 16, and we do not knowingly collect their information. If you believe a child has sent us information, email us and we will delete it.
8. Changes
If we change this policy materially, we will update the date above. The current version always lives at workfreq.com/privacy.html.
9. Contact
Network Frequency, LLC — 1526 Dekalb Avenue NE, Suite 29, Atlanta, GA 30307
info@netfreqtv.com