Privacy Policy
This Privacy Policy explains how your personal data is handled when you use the Voussa website and the free tools we offer on it. We keep it in plain language and collect as little as we can.
1. Who we are
Voussa is operated by Abdullah Al-zomi, an individual sole trader based in Istanbul, Turkey, trading as "Voussa" ("Voussa", "we", "us", "our"). For the purposes of the EU/UK General Data Protection Regulation (GDPR) and Turkey's Personal Data Protection Law No. 6698 (KVKK), Abdullah Al-zomi is the data controller (KVKK: veri sorumlusu) responsible for your personal data.
You can reach us about anything in this policy — including to exercise your rights — at privacy@voussa.co. A postal address is available on request.
2. Scope of this policy
This policy covers the public Voussa website and the free tools on it, including the Structural Integrity Report. Paid engagements — client work, preset purchases, and subscriptions — are also governed by the separate written agreement we provide at purchase or onboarding; where that agreement covers the handling of your data, it applies alongside this policy.
3. What we collect and why
We only collect data you give us or that is needed to run the site securely. By activity:
- The Structural Integrity Report (free tool). Your email address, the answers you submit, your consent choice and its timestamp, and — if you provide it — a video URL. We use this to generate and send your report and, only if you consent, to follow up.
- Applications. The details you enter in the Apply form, used to assess whether we're a fit to work together.
- Contact. Your email address and message, used to reply to you.
- Orders (preset and catalogue purchases). The details needed to fulfil an order and the payment record (amount and status). Payments are handled manually by bank transfer — no card details ever reach us or this website.
- Client portal accounts. Your account identity (we prefer passwordless sign-in, so we do not store passwords), the deliverables prepared for you, and invoice records.
- Automatically, for security and operation. Privacy-first, aggregate usage analytics that do not track you across other sites; and technical logs (such as IP address and request metadata) used to protect the site against abuse, rate-limit forms, and diagnose errors.
We do not sell your personal data, and we do not use it for advertising or cross-site tracking.
4. Legal bases for processing
Under the GDPR we rely on:
- Performance of a contract (Art. 6(1)(b)) — to deliver a service, order, or account you have asked for.
- Consent (Art. 6(1)(a)) — for optional follow-up email after the Report. You can withdraw consent at any time.
- Legitimate interests (Art. 6(1)(f)) — to keep the site and our clients' data secure, prevent abuse and fraud, and run our business — balanced against your rights.
- Legal obligation (Art. 6(1)(c)) — where we must keep records, for example for tax and accounting.
Under the KVKK we process personal data on the basis of your explicit consent where required, and otherwise within the conditions set out in Articles 5 and 6 (including the performance of a contract and our legitimate interests where the law allows).
5. Cookies
We use only strictly-necessary cookies — the ones the site needs to function and stay secure. These include your authentication session (in the client portal), the Cloudflare Turnstile check that protects our forms from bots, and a short-lived security token used during sign-in. We do not use advertising or cross-site tracking cookies, so no cookie-consent banner is required. You can block cookies in your browser, but parts of the portal will not work without the session cookie.
6. Service providers (subprocessors)
We use a small number of trusted providers to run the site. They process personal data only on our instructions and under data-processing terms. Your account and client data are hosted in the European Union (Frankfurt).
| Provider | Purpose | Primary location | | --- | --- | --- | | Vercel | Website hosting and delivery | USA / global edge | | Supabase | Database, authentication, file storage | EU (Frankfurt) | | Cloudflare | DNS, security/WAF, bot protection (Turnstile) | Global | | Resend | Transactional email delivery | USA | | Upstash | Rate limiting (abuse protection) | EU / global | | Sentry | Error monitoring | EU |
If and when we introduce card payments, our payment processor (Stripe) will be added here before it goes live.
7. International data transfers
Some of our providers are located outside Turkey and the European Economic Area (for example, in the United States). Where personal data is transferred internationally, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses or an adequacy decision — and, under the KVKK, on the conditions for cross-border transfer in Article 9. You can ask us for more detail at privacy@voussa.co.
8. How long we keep data
We keep personal data only for as long as we need it:
- Report and enquiry data: up to 24 months after your last interaction, then deleted — sooner if you ask or withdraw consent.
- Client account and deliverables: for the life of the engagement and a reasonable period afterwards.
- Invoices and financial records: for as long as Turkish tax and commercial law require us to keep them.
- Security and error logs: short-lived, and kept no longer than needed to protect the site.
9. Your rights
Under the GDPR and the KVKK you have the right to: access the personal data we hold about you; have it corrected; have it deleted; receive a copy in a portable format; object to or restrict certain processing; and withdraw consent at any time (without affecting processing already carried out). Under the KVKK (Article 11) you also have the right to learn whether your data is processed and to request that the consequences be remedied.
To exercise any of these, email privacy@voussa.co — we will respond within the time the law requires. You also have the right to complain to a supervisory authority: in Turkey, the Personal Data Protection Authority (KVKK Kurumu); in the EU, your local data protection authority.
10. How we protect your data
Security is built into how the site is made. Data is encrypted in transit and at rest, client data is isolated so one client can never reach another's, access is tightly controlled, and files are served only through short-lived, owner-scoped links. We hold client data in the EU and design deletion in from the start. No system is perfectly secure, but we take our responsibility here seriously.
11. Children
The Voussa website and services are intended for businesses and professionals and are not directed at anyone under 18. We do not knowingly collect personal data from children.
12. Changes to this policy
We may update this policy as the site and our services change. When we do, we update the "Last updated" date at the top of this page. Material changes will be made clear.
13. Contact
Questions, requests, or complaints about this policy or your personal data: privacy@voussa.co. Postal address available on request.