Pagina wordt geladen…
Naar hoofdinhoud
Niet beschikbaar
Privacy

Your data, handled properly

Transparent about what I collect, why and for how long. No small print, just a readable policy.

  • 01

    Who I am

    This privacy policy applies to the website ferhat.io, operated by:

    • Ferhat Remory. Sole proprietorship under Belgian law.
    • Registered office. [street and number, postal code, city], Belgium (pending).
    • Company number (KBO). BE 0XXX.XXX.XXX (volgt).
    • VAT number. BE 0XXX.XXX.XXX (volgt).
    • Jurisdiction. RPR Gent, afdeling Dendermonde.
    • Email. hello@ferhat.io
    • Phone. +32 483 11 29 95
    • Future structure (TR). Ferhat.io will continue its activities as a Turkish sole proprietorship (şahıs şirketi). The Turkish details below follow once that structure is established, alongside the Belgian identification above.
    • Trade name (TR). (pending).
    • Legal form (TR). Sole proprietorship (şahıs şirketi), subject to Turkish law.
    • Address (TR). (pending).
    • Vergi Kimlik Numarası (VKN) — Turkish tax number. (pending).
  • 02

    Data controller

    Ferhat Remory is the controller for the personal data collected through this website and in the course of the services provided, within the meaning of the General Data Protection Regulation (GDPR).

    Because clients are typically based in the European Union (mainly Belgium and the Netherlands) and ferhat.io's activities are also (to be) carried out from Turkey, personal data is processed in compliance with both the GDPR and Turkish Law No. 6698 on the Protection of Personal Data (Kişisel Verilerin Korunması Kanunu, KVKK).

  • 03

    What data I collect

    • Contact details. Name, email address, phone number and company name. Provided directly by you via form, email or phone.
    • Project information. Briefings, objectives, attachments and access credentials you share. Provided directly by you.
    • Billing details. Company details, company number and address. Provided directly by you.
    • Technical data. IP address, browser type, device and pages visited. Collected automatically through your visit to the site.
    • Cookies. Automatically, with your consent where required. See the cookie policy.
  • 04

    Why and on what legal basis I process them

    • Handling your request or briefing, preparing a quote. Pre-contractual measures taken at your request.
    • Performing an agreement (project, annual contract). Performance of the contract.
    • Billing and accounting. Legal obligation.
    • Improving and securing the site and services. Legitimate interest.
    • Analytics cookies. Consent (opt-in).
    • Marketing cookies and communication. Consent (opt-in).

    I never process more data than necessary for these purposes, and never use it for purposes incompatible with the purpose for which it was collected.

  • 05

    How long I retain data

    • Contact details of (potential) clients. For as long as a client relationship or ongoing contact exists, plus 3 years after the last contact.
    • Billing details. 7 years, statutory accounting retention period.
    • Project data and access credentials. For as long as the agreement (including an annual contract) runs, plus the time needed for follow-up or dispute resolution. Access to client systems is deleted when the collaboration ends.
    • Unsuccessful job or collaboration applications. Maximum 1 year.
  • 06

    Who I share data with

    Data is only shared with third parties necessary to deliver the services, such as hosting providers, email and accounting software, payment providers (for example Mollie or Stripe) and analytics tools. A data processing agreement (art. 28 GDPR) is in place with every processor handling personal data on my behalf.

    Data is never sold or passed on to third parties for commercial purposes.

    Transfers outside the EEA: some processors, for example analytics or cloud services, may process data outside the European Economic Area. In that case, this is done exclusively on the basis of an adequacy decision of the European Commission or with appropriate safeguards, such as Standard Contractual Clauses (SCCs).

  • 07

    Security

    I take appropriate technical and organisational measures to protect your data: SSL/TLS encryption, strong passwords and two-factor authentication where possible, limited and controlled access to systems, and regular updates of software and security measures. No system is completely watertight, but I take the measures that can reasonably be expected from a professional service provider.

    In the event of a data breach that poses a risk to your rights and freedoms, I report it within the statutory timeframe to the Data Protection Authority and, where required, to you.

  • 08

    Automated decision-making

    No automated decision-making or profiling takes place that produces legal effects concerning you or similarly significantly affects you.

  • 09

    Your rights

    Under the GDPR, and where applicable under the Turkish KVKK (art. 11), you have the right to:

    • Access. Know what data I process about you.
    • Rectification. Have inaccurate or incomplete data corrected.
    • Erasure. Have data deleted, insofar as no statutory retention obligation applies.
    • Restriction. Have the processing of your data restricted.
    • Objection. Object to processing based on legitimate interest.
    • Data portability. Receive your data in a structured, commonly used format or have it transferred.
    • Withdrawal of consent. Where processing is based on consent, withdraw it at any time without affecting prior processing.

    The rights under article 11 of the Turkish KVKK largely overlap with the GDPR rights listed above and are exercised through the same contact channel.

  • 10

    Exercising your rights

    You can exercise these rights via the contact page or via hello@ferhat.io. I respond within one month of receiving your request, and may ask for proof of identity for verification if necessary.

  • 11

    Complaints

    Do you have a complaint about how I handle your data? Please contact me first, most issues can be resolved directly. If you are not satisfied with my response, you can file a complaint with the Belgian Data Protection Authority (GBA), Drukpersstraat 35, 1000 Brussels, gegevensbeschermingsautoriteit.be, or, where the Turkish KVKK applies, with the Kişisel Verilerin Korunması Kurulu (KVKK Kurulu), kvkk.gov.tr.

  • 12

    Changes to this policy

    This privacy policy may be updated, for example in response to changes in the services or in regulations. The most recent version is always available on this page, with the date of the last revision.

Last revised: August 2026 · Questions? Get in touch

Laten we jouw plan scherp krijgen

Boek een gratis kennismaking van dertig minuten. Je hoort snel wat je nodig hebt, wat het vraagt, en of we een match zijn.

Antwoord binnen één werkdag