Legal
Privacy policy
Last updated: 8 September 2026
This privacy policy explains how Depole.io BV (“Depole”, “we”, “us”) processes personal data when you use FESIT. Depole.io BV is established at Hondsstraat 16, 3700 Tongeren, Belgium, company / VAT number BE 0805.029.130. Contact: hello@depole.io.
Depole is the controller for personal data processed to operate FESIT accounts and the public website. For organisation content you enter (for example which tools your organisation uses), your organisation typically determines the purposes of that processing; we act as processor for that content under a data processing relationship with the organisation that holds the account.
1. Data we process
- Account data: email address, display name, password (stored as a hash), organisation name and membership role.
- Service data: stacks, tool selections, notes, policy weights, reports and similar content you create in FESIT.
- Technical data: security and session logs reasonably needed to run and protect the Service (for example timestamps and IP addresses in server logs).
- Communication data: messages you send us (for example support requests to hello@depole.io).
We do not sell personal data. We do not use third-party advertising or analytics cookies on FESIT today. See the Cookie policy for cookies we do use.
2. Purposes and legal bases (GDPR)
- Provide the Service (create accounts, authenticate, store your stacks and policies) — performance of a contract (Art. 6(1)(b)).
- Secure and operate the platform (abuse prevention, debugging, backups) — legitimate interests (Art. 6(1)(f)), balanced against your rights.
- Legal obligations (for example accounting or responding to lawful requests) — Art. 6(1)(c).
- Respond to enquiries — legitimate interests or pre-contractual steps (Art. 6(1)(f) or (b)).
3. Retention
Account and organisation data are kept while your account remains active. After closure or a deletion request we remove or anonymise personal data within a reasonable period, unless we must retain it longer for legal claims, security or statutory retention. Server logs are kept only as long as needed for security and operations, then deleted or aggregated.
4. Recipients and processors
Personal data may be processed by trusted service providers that host or support FESIT (for example infrastructure and email delivery), under contracts that require appropriate confidentiality and security. We do not share your account data with unrelated third parties for their own marketing.
If a provider processes data outside the EEA, we use an appropriate transfer mechanism (such as an adequacy decision or Standard Contractual Clauses) where required.
5. Your rights
Under the GDPR you may request:
- access to your personal data;
- rectification of inaccurate data;
- erasure (“right to be forgotten”) where applicable;
- restriction of processing;
- data portability for data you provided;
- objection to processing based on legitimate interests.
To exercise these rights, email hello@depole.io. You may also lodge a complaint with the Belgian Data Protection Authority (gegevensbeschermingsautoriteit.be) or your local supervisory authority in the EEA.
6. Security
We apply appropriate technical and organisational measures, including hashed passwords, session-based authentication, HTTPS in production deployments, and access limited to people who need it to operate the Service. No method of transmission or storage is completely secure; please choose a strong unique password.
7. Children
FESIT is aimed at organisations and their staff. It is not directed at children under 16. If you believe we hold data of a child inappropriately, contact us and we will delete it.
8. Changes
We may update this policy when the Service or the law changes. The “Last updated” date will be revised. Material changes will be highlighted on the Service or by email where appropriate.
9. Contact
Depole.io BV
Hondsstraat 16, 3700 Tongeren, Belgium
BE 0805.029.130
hello@depole.io