What I collect, and what I don’t.
This site has no cookies, no analytics and no trackers. The only personal data I hold is what you type into the contact form, and this page says exactly what happens to it.
Last updated: 14 August 2026.
Who is responsible
Perqli is a one-person business, and that person is me. I am the controller of any personal data described here, which means the decisions about it are mine and so is the responsibility for them.
- Robin van Golen, trading as Perqli
- Beresteinseweg 58D, 1217 TK Hilversum, Noord-Holland, Nederland
- KVK 89677722
- BTW NL004758944B24
- hello@perqli.com
I have no data protection officer, and I am not required to have one. Write to the address above and you reach the person who makes the decisions.
What I collect
Only two things are required to send the contact form: an email address and a message. Without them I cannot reply, so the form will not submit. Everything else is optional and the form works perfectly well if you leave it empty.
- Required: your email address, and whatever you write in the brief.
- Optional: your name, your company, a timeline, a budget band.
- Optional: your answers to the three fit questions, and the indicative price band they produce, if you choose to answer them.
- Automatic: which page you sent the form from, so I know what you had been reading.
My hosting provider also keeps ordinary server logs, which include IP addresses and request details. I do not use those logs to build any picture of a visitor. They exist so the site can be operated and kept secure.
The form is protected from bots by a hidden field and a timing check. Both run on my own server. There is no captcha, so no third party is watching you fill the form in.
Why, and on what legal basis
If you contact me about work, I use what you send to answer you and, if it goes further, to scope the job. The legal basis is Article 6(1)(b) of the GDPR: steps taken at your request before entering into a contract. If your message turns out not to be about hiring me, the basis is Article 6(1)(f), my legitimate interest in replying to people who write to me.
Server logs rest on Article 6(1)(f) as well: running a website securely is a legitimate interest, and reading logs does not meaningfully intrude on anyone.
I do not send marketing email. I will not add you to a list. If I reply to you, it is because you wrote to me first.
Automated processing
The fit questions calculate an indicative price band from your three answers. That is automated, and I would rather say so than not. It is not a decision about you, it has no legal or similarly significant effect, and it changes nothing except which number you see on screen. A real price comes out of a conversation.
Who else touches it
I run this site on services that process data on my instructions and nobody else’s. Each is bound by a data processing agreement, and none of them may use what you send for their own purposes.
- Vercel hosts the site and runs the code that receives the form.
- Neon provides the database the submission is stored in, hosted in Frankfurt, in the EU.
- Resend delivers the email that tells me you wrote. That email carries your brief in full, not just a note that something arrived.
- Cloud86 hosts my mailbox, in the Netherlands. So the message rests there as well, the same way anything you email anybody rests on a mail server.
That is the list. No advertising network, no analytics provider, no CRM, no lead scoring service, nobody buying or enriching what you sent.
Where it goes
Submissions are stored in the EU, and my mailbox sits in the Netherlands. Vercel, Neon and Resend are United States companies, however, and some processing happens on servers in the United States, so your data does leave the EU on its way to me. Each of the three is certified under the EU-US Data Privacy Framework and additionally relies on the European Commission’s standard contractual clauses. Those are the mechanisms the GDPR provides for exactly this situation.
I would rather write that plainly than bury it. If it matters to you, say so in the form, or email me instead of using it.
How it is kept safe
Everything between your browser and this site travels over HTTPS, and the database is encrypted where it sits. The contact form is the only route from the public site into that database, and it can only write to it, never read back out. The administration area is behind a login that only I hold. Database and mail credentials live as environment variables on the host, never in the code and never in the repository.
No arrangement is perfect and I would rather not pretend otherwise. If personal data of yours is exposed, I will report it to the Autoriteit Persoonsgegevens within 72 hours of finding out, and I will tell you directly if the breach is likely to leave you at real risk. That is what the law asks, and I would rather commit to it here than leave you guessing.
How long I keep it
Contact submissions are kept for 24 months from the day they arrive, and then deleted. Two years is roughly how long it takes for a conversation that went nowhere to come back around, and after that the record is of no use to either of us. I clear them out by hand rather than on a timer, so a record may outlast its date by a little. Ask me to delete yours sooner and I will, without asking why.
If we end up working together, the project records that follow are kept for as long as Dutch tax law requires me to keep them, which is seven years for anything touching an invoice.
Server logs are kept by my hosting provider under its own retention policy, which runs in days rather than months, and are rotated away after that. The length of that window is Vercel’s to set rather than mine, and I keep no copies of my own.
Your rights
The GDPR gives you a set of rights over your own data, and you do not need a reason to use them. You can ask me to:
- show you what I hold about you
- correct it, if it is wrong
- delete it
- restrict what I do with it, or object to my processing it
- send you a copy in a portable format, or send it on to someone else
Email hello@perqli.com and I will deal with it, and it costs you nothing. The law gives me a month, and lets me take two more if a request turns out to be genuinely complicated; in practice this is a one-person business with a small database, so it will not take that long. If I cannot tell that a request is coming from the person whose data it concerns, I will ask you something that settles it first. The alternative is handing your data to whoever asks for it.
Cookies and tracking
There are none. This site sets no cookies, stores nothing in your browser, and loads no analytics, tag manager, heatmap, session recorder, advertising pixel or social widget. Fonts are served from this domain rather than fetched from Google. There is no consent banner because there is nothing to consent to.
The administration area behind this site uses a session cookie, but only for me, after logging in. It is never set for a visitor.
If you are unhappy
Tell me first, and I will try to put it right. You also have the right to complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl. You do not have to raise it with me before you go to them.
Changes
If what this site does with data changes, this page changes first, and the date at the top moves with it.
If I stop trading, contact submissions get deleted rather than passed on to anybody. If the business is ever sold or transferred, whatever is still held would go with it, and this page would say so before that happened.
Questions about any of this go to hello@perqli.com, or through the contact form.