Privacy Policy

Last updated: 30 October 2025

Business name: ftre.co — Jonathan Lafer

Address: Denneweg 7, 2514 CB Den Haag, Zuid-Holland, Netherlands

Email: [email protected]

Phone: +31 6 16 14 23 49

VAT ID: NL005198378B02

KvK: 96260238


Summary

At ftre.co, I respect your privacy and handle your data with care.

This notice explains which personal data I collect, why I collect it, the legal bases under the GDPR, how long I keep it, and what your rights are.

It applies to all visitors of ftre.co, clients using my portal, and anyone communicating with me.


1.  Who I Am and Scope

ftre.co is operated by Jonathan Lafer, a sole proprietor (ZZP) based in The Hague, Netherlands.

I provide design, branding, digital, film, and interactive services to clients worldwide.

This Privacy Policy applies to:

  • The public website https://ftre.coAttachment.tiff

  • The client portal hosted under the same domain

  • Any form submissions, emails, or other communications with me


2.  Categories of Personal Data

Depending on your interaction, I may process the following categories:

Context

Data processed

Contact or inquiry form                

Name, email address, phone number, company name, message content

Client portal account

Name, username, email, password (hashed), project files, messages, shared links, payment information

Payments

Name, billing address, transaction details, partial payment information via Stripe / PayPal

Website analytics

IP address (truncated), browser type, device type, pages visited, time spent, referring site

Technical logs

Server logs including IP, timestamp, and request data

Embedded content

Interaction data with YouTube videos, Spline scenes, and other third-party embeds


3.  Legal Bases for Processing (Article 6 GDPR)

I process personal data only when a lawful basis applies:

  1. Performance of a contract – managing and delivering client projects, maintaining the client portal, issuing invoices, providing support.

  2. Legitimate interest – maintaining website security, preventing abuse, improving services.

  3. Legal obligation – bookkeeping and tax administration under Dutch fiscal law.

  4. Consent – when you opt in to cookies, analytics, or newsletters (future).

You can withdraw your consent at any time by emailing [email protected]Attachment.tiff or using the cookie settings banner.


4.  Purpose of Processing

  • Responding to messages and project inquiries

  • Creating and managing client accounts

  • Providing access to project materials via the client portal

  • Managing financial administration and compliance

  • Monitoring site performance and usage statistics

  • Securing the website and detecting misuse

  • Maintaining communication records for service continuity

No data is used for automated decision-making or profiling.


5.  Data Processors and Third Parties

I only share data with trusted processors necessary to run my business.

Each has a GDPR-compliant data-processing agreement (DPA) in place.

Processor

Purpose

Location / Safeguards

DigitalOcean LLC

Website and portal hosting

Amsterdam (NL) data center; SCCs for US support

WordPress / Automattic Inc.

CMS functionality

EU servers + SCCs for US processing

Google LLC (Google Analytics 4)

Site statistics

Data may transfer to US under SCCs and IP anonymisation

Stripe Payments Europe Ltd / PayPal (Europe)

Payment processing

EEA-based; SCCs for US data access

Spline / YouTube (Alphabet Inc.)

Embedded interactive content

US-based; user consent required before loading

Email and cloud backup providers

Secure communication and storage

EU or SCC-protected locations

I do not sell, lease, or trade your information to any third party.


6.  International Data Transfers

When personal data leaves the EEA, it is protected by:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, or

  • The EU–US Data Privacy Framework (for participants such as Google LLC or PayPal Inc.).

You can request a copy of the relevant transfer safeguards by contacting me.


7.  Data Retention

Data type

Retention period

Inquiries

12 months after last contact

Client projects

As long as the project is active or required by the client

Invoices / administration

7 years (minimum Dutch tax law)

Analytics data

14 months (Google Analytics 4 default)

Backups

Rotating encrypted copies kept up to 90 days

Portal accounts

Deleted within 30 days after contract termination or on request


8.  Client Portal Data

Portal accounts are protected by unique credentials and encrypted connections (HTTPS + TLS).

Passwords are stored using secure hashing.

You are responsible for keeping login details confidential.

If a client requests deletion, I will remove portal data and backups (except invoices and legal records) within 30 days.


9.  Security Measures

I implement:

  • HTTPS encryption across all domains

  • Role-based access control

  • Automatic security updates on WordPress

  • Encrypted local and cloud backups

  • Firewalls and brute-force protection

  • Multi-factor authentication for admin accounts

While I take extensive precautions, no system is entirely immune to intrusion.

If a data breach occurs, I will notify the Autoriteit Persoonsgegevens and affected individuals as required by Articles 33–34 GDPR.


10  Children’s Privacy

My services are not directed toward persons under 16 years.

I do not knowingly collect data from children.

If you believe I have unintentionally done so, please contact me to remove it.


11.  Your Rights Under the GDPR

You may at any time:

  • Request access to your data (Art. 15)

  • Request rectification (Art. 16) or erasure (Art. 17)

  • Request restriction of processing (Art. 18)

  • Object to processing (Art. 21)

  • Request data portability (Art. 20)

  • Withdraw consent (Art. 7 §3)

  • Lodge a complaint with the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nlAttachment.tiff)

Requests can be sent to [email protected]Attachment.tiff.

I may ask for identification to ensure data security.


12.  Complaints and Supervision

If you believe your data has been misused, you may first contact me.

If unresolved, you have the right to complain directly to:

Autoriteit Persoonsgegevens

Postbus 93374, 2509 AJ Den Haag, Nederland

https://autoriteitpersoonsgegevens.nlAttachment.tiff


13.  Changes to This Policy

I may update this statement when services or laws change.

The latest version is always published on this page.

If material changes affect your rights, I will notify active clients directly.


14.  Contact

For all privacy-related questions:

Jonathan Lafer

ftre.co — Denneweg 7, 2514 CB Den Haag, Netherlands

Email: [email protected]

Phone: +31 6 16 14 23 49





Privacyverklaring (Nederlands)

Last update: 30 oktober 2025

Bedrijfsnaam: ftre.co — Jonathan Lafer

Adres: Denneweg 7, 2514 CB Den Haag, Zuid-Holland, Nederland

E-mail: [email protected]

Telefoon: +31 6 16 14 23 49

BTW-nr: NL005198378B02

KvK: 96260238


Samenvatting

Bij ftre.co hecht ik veel waarde aan privacy.

Deze verklaring legt uit welke persoonsgegevens ik verwerk, waarom, op welke rechtsgrond, hoe lang ik ze bewaar en wat jouw rechten zijn volgens de AVG.

De verklaring geldt voor bezoekers van ftre.co, gebruikers van het klantportaal en alle overige communicatie.


1  Wie ik ben en toepassingsgebied

ftre.co is een eenmanszaak van Jonathan Lafer in Den Haag.

Ik lever ontwerp- en digitale diensten aan klanten in binnen- en buitenland.

Deze privacyverklaring geldt voor de openbare website, het klantportaal en alle contactmomenten.


2  Categorieën van persoonsgegevens

Afhankelijk van het gebruik van de website verwerk ik onder meer:

  • Naam, e-mail, telefoonnummer, bedrijfsnaam, berichtinhoud

  • Inloggegevens voor het klantportaal (gebruikersnaam, versleuteld wachtwoord, projectgegevens)

  • Betaalgegevens (naam, factuuradres, transactiedetails via Stripe of PayPal)

  • Analytische en technische gegevens zoals IP-adres (verkort), browser, apparaat, tijdstip, bezochte pagina’s

  • Logbestanden van de server en ingesloten inhoud (YouTube, Spline e.d.)


3  Rechtsgronden voor verwerking (artikel 6 AVG)

Ik verwerk alleen persoonsgegevens wanneer een rechtsgrond van toepassing is:

  1. Uitvoering van een overeenkomst — voor het uitvoeren van opdrachten en beheer van het klantportaal.

  2. Gerechtvaardigd belang — websitebeveiliging, dienstverbetering en fraudepreventie.

  3. Wettelijke verplichting — boekhouding en belastingwetgeving.

  4. Toestemming — voor cookies, analyses en nieuwsbrieven.

Toestemming kan altijd worden ingetrokken via [email protected]


4  Doelen van de verwerking

  • Reageren op berichten en aanvragen

  • Klantaccounts aanmaken en beheren

  • Projectmateriaal delen via het klantportaal

  • Administratie en facturatie

  • Website en dienstverlening optimaliseren

  • Beveiliging en misbruikpreventie

  • Wettelijke verplichtingen nakomen

Er wordt geen gebruik gemaakt van automatische besluitvorming of profilering.


5  Verwerkers en derden

Ik deel gegevens alleen met partijen die noodzakelijk zijn voor mijn werk.

Met alle verwerkers is een verwerkersovereenkomst gesloten.

Verwerker

Doel

Locatie / waarborg

DigitalOcean LLC

Hosting van website en portaal

Amsterdam (NL); SCC’s voor US-ondersteuning

WordPress / Automattic Inc.

CMS-functionaliteit

EU servers + SCC’s

Google LLC (GA4)

Statistieken

Gegevens kunnen naar VS worden verzonden; IP-anonimisering

Stripe / PayPal

Betalingen

Binnen EER; SCC’s voor VS-toegang

Spline / YouTube

Ingesloten inhoud

VS; laden na toestemming

Cloud- en e-mailproviders

Communicatie en back-ups

EU of SCC-beschermd


6  Doorgifte buiten de EER

Wanneer gegevens naar landen buiten de EER worden verzonden, gebeurt dit met toepassing van de standaardcontractbepalingen (SCC’s) of binnen het EU-VS Data Privacy Framework.

Een kopie van deze maatregelen is op verzoek beschikbaar.


7  Bewaartermijnen

Gegevenstype

Bewaartermijn

Contactaanvragen

12 maanden na laatste contact

Klantprojecten

Zolang actief of verzocht door klant

Facturen / administratie

7 jaar (volgens fiscale wet)

Analytische data

14 maanden

Back-ups

Maximaal 90 dagen

Portaalaccounts

Verwijderd binnen 30 dagen na beëindiging of verzoek


8  Klantportaal

Toegang tot het portaal gebeurt via unieke inloggegevens en een versleutelde verbinding.

Wachtwoorden worden veilig gehasht opgeslagen.

Klantgegevens worden verwijderd op verzoek of na beëindiging van de overeenkomst, behoudens wettelijke bewaarplichten.


9  Beveiliging

Ik pas technische en organisatorische maatregelen toe, waaronder:

  • HTTPS-versleuteling

  • Sterke wachtwoorden en toegangsbeheer

  • Automatische updates en firewall

  • Versleutelde back-ups

  • Twee-stapsverificatie voor beheer

Bij een datalek meld ik dit aan de Autoriteit Persoonsgegevens en aan betrokkenen volgens artikelen 33 en 34 AVG.


10  Privacy van kinderen

Mijn diensten zijn niet gericht op personen jonger dan 16 jaar.

Indien toch gegevens van minderjarigen worden verwerkt, zal ik deze op verzoek verwijderen.


11  Jouw rechten

Je hebt onder de AVG recht op:

  • Inzage, rectificatie en verwijdering

  • Beperking van verwerking

  • Overdraagbaarheid

  • Bezwaar tegen verwerking

  • Intrekking van toestemming

  • Klacht bij de Autoriteit Persoonsgegevens

Verzoeken kunnen worden gericht aan [email protected]

Ter beveiliging kan ik vragen om identificatie.


12  Klachten en toezicht

Bij onopgeloste geschillen kun je een klacht indienen bij:

Autoriteit Persoonsgegevens

Postbus 93374

2509 AJ Den Haag

https://autoriteitpersoonsgegevens.nlAttachment.tiff


13  Wijzigingen

Deze verklaring kan worden aangepast wanneer wetgeving of dienstverlening wijzigt.

De meest recente versie is altijd te vinden op ftre.co

Bij belangrijke wijzigingen worden actieve klanten geïnformeerd.


14  Contact

Jonathan Lafer

ftre.co — Denneweg 7, 2514 CB Den Haag, Nederland

E-mail: [email protected]

Telefoon: +31 6 16 14 23 49