Version of 28 August 2026. Replaces all earlier versions.
This statement describes which personal data we process when you visit our website, contact us, work with us or are approached by us, and what you can do about it.
When we build or maintain software for a client, we do not process the data in that system for ourselves but on that client's instruction. The client is then the controller and decides what happens with your data; we act as processor. For that data you turn to that client. This statement is about the data we process for ourselves.
1. Who we are
- Controller
- Verschoote Consultancy BV
- Address
- Doornzelestraat 66, 9000 Gent, Belgium
- Company and VAT number
- BE 1005.571.482
- Website
- www.jeromverschoote.com
We have not appointed a data protection officer. For a company of this size and with these activities that is not required. Questions about this statement reach the director, at the address above.
2. What we process, why, and on what ground
2.1 Your message through the contact form
When you fill in the form on the contact page, we process your first name, your last name, your email address, the sector you indicate, the language you are reading the website in and the content of your message.
We use that to answer your question and, where a collaboration follows from it, to prepare it. The ground is the performance of a contract or the steps preceding it (article 6.1.b GDPR), and otherwise our legitimate interest in being able to answer a question (article 6.1.f GDPR).
Your message ends up in Notion, where we track contact requests, and a notification goes to Slack so that we know something came in. Both are listed under point 4.
2.2 Protecting that same form
To keep the form from being abused for bulk sending, we count how many requests arrive from one visitor in a short window. We use the IP address the request arrives with as the key of that counter, at Upstash. No profile is built and the address is not attached to your message.
The ground is our legitimate interest in a working, unabused form (article 6.1.f GDPR).
2.3 Statistics about the use of the website
When you allow it in the cookie banner, we measure how the website is used: which pages are viewed, in what order, on what kind of device and from which referring source. We use PostHog for that, which runs for us on servers in Frankfurt and does not take the data outside the European Economic Area.
The ground is your consent (article 6.1.a GDPR). You can withdraw it at any time; how, is in the cookie policy. Without your consent the website works exactly as it does with it.
2.4 When we approach you ourselves
We approach companies we believe have something to gain from our work. For that we process business contact details that are publicly available or that you gave us: your name, your role, the company you work for, your business email address, your LinkedIn profile and public information about that company, such as job openings and announcements.
The ground is our legitimate interest in offering our services to professional contacts (article 6.1.f GDPR). We approach you in your professional capacity, not privately. If you ask us to stop, we stop, and we then keep only the fact that you asked, so that we do not contact you again.
2.5 Carrying out an assignment
From clients, partners and suppliers we process what we need in order to work and to invoice: name, role, contact details, the correspondence about the file and the details that belong on an invoice.
The ground is the performance of the contract (article 6.1.b GDPR) and, for the accounting records, a legal obligation (article 6.1.c GDPR).
2.6 Access to a client's system
Building, repairing or migrating a system can bring our access into contact with data of third parties held in that system. That happens only where the work requires it, and we process such data solely on the client's instruction. What we may and must do is set out in the data processing agreement with that client.
3. How long we keep it
| What | How long |
|---|---|
| A contact request without a follow-up | Twenty-four months after the last contact |
| A contact request that led to a collaboration | With the client file |
| The counter protecting the form | A few hours, for as long as the window runs |
| Website usage statistics | Twelve months |
| Contact details from prospection | Twenty-four months after the last contact, or erased immediately on request |
| Client files and correspondence | Ten years after the end of the collaboration, given the statutory liability periods |
| Invoices and accounting records | Seven years, as the law prescribes |
Where a period expires, we erase the data or make it irreversibly anonymous.
4. Who gets to see your data
We do not sell data and we do not pass it on for anyone else's purposes. To be able to work we do rely on service providers who process on our instruction. At the time of this version those are:
| Service | For what | Processed where |
|---|---|---|
| Vercel Inc. | Hosting of the website and its server logs | United States |
| Notion Labs, Inc. | Tracking contact requests and prospects | United States |
| Slack Technologies (Salesforce) | Notification of a new contact request | United States |
| Upstash, Inc. | The counter that protects the form | European Union |
| PostHog Inc. | Website usage statistics | Frankfurt, Germany |
| Apple Distribution International Ltd. | Our business email | European Union |
| Billit NV | Invoicing | Belgium |
| Our accountant | The statutory accounting work | Belgium |
Beyond that we disclose data where a law or a court decision obliges us to.
Transfer outside the European Economic Area
Vercel, Notion and Slack process in the United States. That transfer rests on the European Commission's adequacy decision for the EU-US Data Privacy Framework, and additionally on the standard contractual clauses of Implementing Decision (EU) 2021/914 where the terms of the service in question include them. PostHog, Upstash and our email processor work within the European Economic Area.
5. How we secure it
Access to our systems runs through personal accounts with two-factor authentication where the service allows it, and with the rights someone needs and no more. Passwords sit in a password manager, never in code or in a message. Traffic to and from the website is encrypted, backups are encrypted and kept in a separate location, and workstations are encrypted and lock automatically. Development, test and production are separate environments.
If you notice a weak spot, we would rather hear it, at the address under point 1. We handle such a report carefully and we take no action against anyone who warns us in good faith.
6. What you can ask
You have the right to ask for access to the data we process about you, to have it corrected, to have it erased, to have the processing restricted, and to receive it in a common format or have it transferred.
Where we process on the ground of a legitimate interest, as with prospection, you can object. Against direct marketing you can object at any time, without giving a reason. Where we process on your consent, you can withdraw it, and what happened before remains valid.
Send a request to hello@jeromverschoote.com. We answer within a month. Where we cannot establish who the request comes from, we ask for further details before releasing anything.
We take no decisions about you based solely on automated processing, and we build no profiles.
7. When you disagree with us
Contact us first. If we do not get there, you can lodge a complaint with the Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussel, contact@apd-gba.be, www.gegevensbeschermingsautoriteit.be. You can also go to court.
8. Changes
We adjust this statement when something changes about what we process or about who processes it for us. The date at the top says which version you are reading. A change that affects your rights is announced on the website.