Skip to main content

Legal

Privacy statement

Version of 28 August 2026. Replaces all earlier versions.

This statement describes which personal data we process when you visit our website, contact us, work with us or are approached by us, and what you can do about it.

When we build or maintain software for a client, we do not process the data in that system for ourselves but on that client's instruction. The client is then the controller and decides what happens with your data; we act as processor. For that data you turn to that client. This statement is about the data we process for ourselves.

1. Who we are

Controller
Verschoote Consultancy BV
Address
Doornzelestraat 66, 9000 Gent, Belgium
Company and VAT number
BE 1005.571.482
Website
www.jeromverschoote.com

We have not appointed a data protection officer. For a company of this size and with these activities that is not required. Questions about this statement reach the director, at the address above.

2. What we process, why, and on what ground

2.1 Your message through the contact form

When you fill in the form on the contact page, we process your first name, your last name, your email address, the sector you indicate, the language you are reading the website in and the content of your message.

We use that to answer your question and, where a collaboration follows from it, to prepare it. The ground is the performance of a contract or the steps preceding it (article 6.1.b GDPR), and otherwise our legitimate interest in being able to answer a question (article 6.1.f GDPR).

Your message ends up in Notion, where we track contact requests, and a notification goes to Slack so that we know something came in. Both are listed under point 4.

2.2 Protecting that same form

To keep the form from being abused for bulk sending, we count how many requests arrive from one visitor in a short window. We use the IP address the request arrives with as the key of that counter, at Upstash. No profile is built and the address is not attached to your message.

The ground is our legitimate interest in a working, unabused form (article 6.1.f GDPR).

2.3 Statistics about the use of the website

When you allow it in the cookie banner, we measure how the website is used: which pages are viewed, in what order, on what kind of device and from which referring source. We use PostHog for that, which runs for us on servers in Frankfurt and does not take the data outside the European Economic Area.

The ground is your consent (article 6.1.a GDPR). You can withdraw it at any time; how, is in the cookie policy. Without your consent the website works exactly as it does with it.

2.4 When we approach you ourselves

We approach companies we believe have something to gain from our work. For that we process business contact details that are publicly available or that you gave us: your name, your role, the company you work for, your business email address, your LinkedIn profile and public information about that company, such as job openings and announcements.

The ground is our legitimate interest in offering our services to professional contacts (article 6.1.f GDPR). We approach you in your professional capacity, not privately. If you ask us to stop, we stop, and we then keep only the fact that you asked, so that we do not contact you again.

2.5 Carrying out an assignment

From clients, partners and suppliers we process what we need in order to work and to invoice: name, role, contact details, the correspondence about the file and the details that belong on an invoice.

The ground is the performance of the contract (article 6.1.b GDPR) and, for the accounting records, a legal obligation (article 6.1.c GDPR).

2.6 Access to a client's system

Building, repairing or migrating a system can bring our access into contact with data of third parties held in that system. That happens only where the work requires it, and we process such data solely on the client's instruction. What we may and must do is set out in the data processing agreement with that client.

3. How long we keep it

WhatHow long
A contact request without a follow-upTwenty-four months after the last contact
A contact request that led to a collaborationWith the client file
The counter protecting the formA few hours, for as long as the window runs
Website usage statisticsTwelve months
Contact details from prospectionTwenty-four months after the last contact, or erased immediately on request
Client files and correspondenceTen years after the end of the collaboration, given the statutory liability periods
Invoices and accounting recordsSeven years, as the law prescribes

Where a period expires, we erase the data or make it irreversibly anonymous.

4. Who gets to see your data

We do not sell data and we do not pass it on for anyone else's purposes. To be able to work we do rely on service providers who process on our instruction. At the time of this version those are:

ServiceFor whatProcessed where
Vercel Inc.Hosting of the website and its server logsUnited States
Notion Labs, Inc.Tracking contact requests and prospectsUnited States
Slack Technologies (Salesforce)Notification of a new contact requestUnited States
Upstash, Inc.The counter that protects the formEuropean Union
PostHog Inc.Website usage statisticsFrankfurt, Germany
Apple Distribution International Ltd.Our business emailEuropean Union
Billit NVInvoicingBelgium
Our accountantThe statutory accounting workBelgium

Beyond that we disclose data where a law or a court decision obliges us to.

Transfer outside the European Economic Area

Vercel, Notion and Slack process in the United States. That transfer rests on the European Commission's adequacy decision for the EU-US Data Privacy Framework, and additionally on the standard contractual clauses of Implementing Decision (EU) 2021/914 where the terms of the service in question include them. PostHog, Upstash and our email processor work within the European Economic Area.

5. How we secure it

Access to our systems runs through personal accounts with two-factor authentication where the service allows it, and with the rights someone needs and no more. Passwords sit in a password manager, never in code or in a message. Traffic to and from the website is encrypted, backups are encrypted and kept in a separate location, and workstations are encrypted and lock automatically. Development, test and production are separate environments.

If you notice a weak spot, we would rather hear it, at the address under point 1. We handle such a report carefully and we take no action against anyone who warns us in good faith.

6. What you can ask

You have the right to ask for access to the data we process about you, to have it corrected, to have it erased, to have the processing restricted, and to receive it in a common format or have it transferred.

Where we process on the ground of a legitimate interest, as with prospection, you can object. Against direct marketing you can object at any time, without giving a reason. Where we process on your consent, you can withdraw it, and what happened before remains valid.

Send a request to hello@jeromverschoote.com. We answer within a month. Where we cannot establish who the request comes from, we ask for further details before releasing anything.

We take no decisions about you based solely on automated processing, and we build no profiles.

7. When you disagree with us

Contact us first. If we do not get there, you can lodge a complaint with the Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussel, contact@apd-gba.be, www.gegevensbeschermingsautoriteit.be. You can also go to court.

8. Changes

We adjust this statement when something changes about what we process or about who processes it for us. The date at the top says which version you are reading. A change that affects your rights is announced on the website.

Cookies

We use analytics cookies to see how the site is used and to improve it.

Read the cookie policy