Skip to content

Privacy Policy

This policy explains how personal data is handled when you use this website, contact BeRef, or use the BeRef product. BeRef is a business-to-business product intended for professional use by founders, agencies, micro-SaaS makers, and consultants. We aim to collect as little personal data as possible and to be honest about what we do with it.

Who is the controller

The data controller is Ozan Ablak (Founder), the operator behind the brand BeRef, established in Türkiye (Turkey).

  • Registered address: 100. Yıl Mahallesi, Özlüce, 16120 Bursa, Türkiye
  • Turkish tax number (VKN): TR0020382830
  • Contact: beref@beref.tech

See also our Impressum for provider identification.

Controller outside the EU — extraterritorial scope

The controller is established in Turkey, which is outside the EU/EEA. Because BeRef offers a service to users in the EU, the GDPR still applies to that processing under its extraterritorial scope (GDPR Art. 3(2)). The appointment of an EU representative under GDPR Art. 27 is under review — the small-scale / occasional-processing exemption may apply at this stage. If a representative is appointed, this page will be updated with their details.

What we collect, why, and our legal basis

Account & product use

When you create a BeRef account we process your email address and the workspace data you choose to add (such as your Proof Profile, Proof Vault assets, Buyer Rooms, and consent records) so we can provide the Service. The legal basis is performance of a contract (GDPR Art. 6(1)(b)).

Contact & enquiries

When you send us a message through our contact form we process your name, email address, and the content of your message so we can read and respond to it. The legal basis is your consent (GDPR Art. 6(1)(a)) and our legitimate interest (GDPR Art. 6(1)(f)) in responding to enquiries. We do not store contact-form messages in a marketing database.

Purchases

If you buy a paid plan, we process the data needed to provide what you ordered and to keep records of the transaction. The legal basis is performance of a contract (GDPR Art. 6(1)(b)). Payment and billing details are handled by Paddle as Merchant of Record (see below); we do not store full card numbers.

Security & anti-abuse

We process limited technical data — such as server logs, IP-derived information, and request metadata — to keep the site secure, prevent abuse and spam, and maintain availability. The legal basis is our legitimate interest (GDPR Art. 6(1)(f)) in protecting the service. You can object to this processing on grounds relating to your situation (GDPR Art. 21).

Consent-tracked third-party proof & one-click revocation

Where BeRef collects proof that involves another person or company — such as a quote, milestone, logo right, or reference — that proof is published only on a stored, tracked consent basis (GDPR Art. 6(1)(a), Art. 7). That consent is revocable at any time: a one-click revoke / unpublish takes the affected proof asset down and stops further processing for that purpose, consistent with the right to withdraw consent (GDPR Art. 7(3)) and the right to erasure (GDPR Art. 17). We design this revocation as a technical guarantee, not just a promise.

Processors and service providers

We use a small number of carefully chosen providers that process personal data on our behalf under data-processing terms (GDPR Art. 28). The providers actually used are:

  • Supabase — database and storage for account, Proof Vault, and Buyer Room data.
  • Vercel — website and product hosting, including Vercel Web Analytics, which is privacy-friendly and cookieless.
  • Paddle — payments. Paddle acts as Merchant of Record (seller of record) and handles billing, tax/VAT, invoicing, and refunds. Paddle may set cookies that are necessary to operate checkout.
  • Resend — email delivery for transactional and consent-related emails. When enabled, Resend processes the recipient address on our behalf to deliver the message; any bulk message carries a one-click unsubscribe. Email sending is dormant until configured; no marketing email is sent before then.

International data transfers

Because the controller is in Turkey and our providers may process data in various regions, personal data may be transferred outside the EEA. Where that happens, transfers are covered by appropriate safeguards — such as Standard Contractual Clauses (SCCs) or another lawful transfer mechanism — in line with GDPR Art. 44–49. You can request more information about the safeguards in place by emailing us.

Your rights

Depending on your location and the applicable law, you have rights over your personal data, including the right to:

  • access your data and request a copy (GDPR Art. 15);
  • rectify inaccurate or incomplete data (GDPR Art. 16);
  • erase your data (GDPR Art. 17);
  • restrict processing (GDPR Art. 18);
  • object to processing based on legitimate interests (GDPR Art. 21);
  • data portability (GDPR Art. 20);
  • withdraw consent at any time (GDPR Art. 7(3)).

To exercise any of these rights, email beref@beref.tech. We will respond within the timeframes required by law. You also have the right to lodge a complaint with your local data-protection supervisory authority if you believe your data has been handled unlawfully.

Cookies & analytics

We use only strictly-necessary cookies: the public site is cookieless while you browse signed out, and once you sign in we set a strictly-necessary session cookie to keep you logged in — full detail is in our Cookies Policy. We do not use advertising or cross-site tracking cookies.

  • Vercel Web Analytics is cookieless and aggregates traffic without identifying you.
  • Paddle loads only when you actively start a purchase and may then set cookies strictly necessary to operate that checkout — never while you simply browse.

California & US privacy

This visible, accessible privacy policy is provided in line with CalOPPA (the California Online Privacy Protection Act). The CCPA/CPRA (California Consumer Privacy Act, as amended) applies only if we meet its statutory thresholds — at this stage we likely do not, but if and when those thresholds apply we will provide the additional disclosures and consumer rights it requires. We do not sell personal information.

Türkiye (KVKK)

Because the controller is established in Türkiye, the Law on the Protection of Personal Data (KVKK, Law No. 6698) applies to our processing. Its core requirements — a lawful basis (or, where required, explicit consent), transparency, data minimization, security, and data-subject rights to access, correct, and request deletion — run parallel to the GDPR rights described above, and we apply the same standards to all users. Electronic-commerce and consumer matters are additionally governed by the Law on the Regulation of Electronic Commerce (No. 6563) and the Consumer Protection Law (No. 6502). To exercise any KVKK right, contact beref@beref.tech.

Email & marketing

When email is enabled, transactional messages (for example a purchase receipt or a consent request you triggered) are sent so we can provide a service you requested; any further product or launch emails go out on a consent basis with an easy, one-click unsubscribe in every message. We follow:

  • US CAN-SPAM — accurate header and subject lines, a valid physical postal address, and a working opt-out;
  • EU ePrivacy Art. 13 and UK PECR — prior consent for marketing email, with the ability to object or opt out at any time.

Unsubscribing from marketing emails does not stop essential transactional messages (for example, a purchase receipt) where those are necessary to provide a service you requested.

Retention

We keep personal data only for as long as needed for the purpose it was collected. Account and product data is kept while your account is active and then deleted or anonymised on closure or request. Purchase and transaction records are kept for as long as required to meet legal, accounting, and tax obligations. Security and anti-abuse logs are kept for a limited period and then deleted or anonymised.

Buyer-room view analytics are privacy-minimised — keyed only to a room, with no email and no raw IP address — and are automatically deleted after 12 months. On a verified erasure request (GDPR Article 17), the consent record holding a referrer's email, name and quote is stripped immediately and the reference is unpublished everywhere it appeared.

Changes to this policy

We may update this policy as the product and our processing evolve. Material changes will be reflected here, and the review date shown below this page will be updated.

Contact

Questions about privacy or your data: beref@beref.tech. See also our Terms, Refund Policy, Trust & Compliance, and Impressum.

This page is general information about how BeRef is designed to operate — it is not legal advice. Last reviewed: 2026-06-22. Questions: beref@beref.tech.