Legal
Privacy, in plain English.
The short version: we collect as little as possible, never sell it, and you can ask us to delete it at any time. Last updated October 2026.
At a glance
Cookies only if you agree
Analytics cookies are set only after you click “Accept”. Decline, and nothing is tracked.
No ads, no selling
No advertising pixels or social media trackers, and we never sell your data.
Only what we need
We only process data you actively send us, like an email or a chat message.
You stay in control
Ask us at any time to see, correct or delete your data — we answer within 30 days.
01Who is responsible
Inferly Labs is operated by Metehan Kuscu, an independent software developer. There is currently no registered company behind this website; the operator named here is personally responsible for it.
For anything related to your personal data, email [email protected]. We do not have a data protection officer, as we are not legally required to appoint one, but every request is handled personally by the operator.
02What this policy covers
This policy explains how we handle personal data when you visit inferlylabs.com, message or email us, or become a client. We process personal data in line with the EU General Data Protection Regulation (GDPR), the UK GDPR and the Turkish Personal Data Protection Law No. 6698 (KVKK).
03Visiting this website
When you open a page, our web server automatically records technical information in a log file:
- your IP address
- date and time of the request
- the page requested and the referring page
- browser type and operating system
We use these logs only to deliver the website, keep it secure and investigate errors or attacks. They are deleted automatically after 30 days at the latest, unless a specific security incident requires us to keep them longer.
Legal basis: our legitimate interest in operating a secure, working website (Art. 6(1)(f) GDPR).
Fonts, images and scripts are served from our own server. The website is delivered through Cloudflare, which acts as our processor to protect the site against attacks and speed up delivery; it processes connection data such as your IP address for this purpose.
05When you email us
If you write to us, we process your name, email address, and whatever you choose to include in your message — for example details about your company or project.
We use this information only to reply to you and, if you ask for it, to prepare a proposal. We do not add you to any mailing list.
Legal basis: steps prior to entering into a contract (Art. 6(1)(b) GDPR), or our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR).
Retention: enquiries that do not lead to a project are deleted after 12 months. Correspondence with clients is kept for as long as the law requires (see below).
06When you message us on WhatsApp or Telegram
The WhatsApp and Telegram buttons on this website are plain links. Nothing is sent to WhatsApp or Telegram when you load a page — only when you click a button and choose to start a conversation.
If you message us, we receive your profile name, your phone number or username (depending on your privacy settings in the app), and the content of your messages. We use them only to answer you and, if you ask, to prepare a proposal.
These messaging services are operated by WhatsApp (Meta Platforms) and Telegram, who process your data as independent controllers under their own terms: see the WhatsApp privacy policy and the Telegram privacy policy. If you prefer not to use them, email us instead.
Legal basis: steps prior to entering into a contract (Art. 6(1)(b) GDPR), or our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR).
Retention: chats that do not lead to a project are deleted after 12 months.
07If you become a client
To deliver a project we process contact details of the people we work with, project communication, and billing information such as company name, address and VAT number.
Payments are made by bank transfer or through our payment provider (Payoneer), which processes payment data as an independent controller under its own privacy policy. We never see or store your full card details.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and legal obligations such as tax and accounting rules (Art. 6(1)(c) GDPR).
Retention: invoices and accounting records are kept for the period required by applicable tax law (generally 5 to 10 years). Other project data is deleted or returned to you when it is no longer needed.
09International transfers
We are based in Türkiye, which is outside the European Economic Area. When you send us personal data from the EU or UK, it is therefore transferred to Türkiye. Some of our service providers may also process data in other countries, such as the United States.
Where required, these transfers are protected by appropriate safeguards — in particular the European Commission’s Standard Contractual Clauses — or take place because they are necessary to answer your request or perform a contract with you (Art. 49(1)(b) GDPR).
10How we protect your data
The website is served exclusively over encrypted HTTPS connections. Access to email, scheduling and project tools is protected with strong, unique passwords and two-factor authentication wherever available. We keep the amount of personal data we hold as small as possible — data we do not have cannot be lost.
11Your rights
You have the right to:
- Access — get a copy of the personal data we hold about you
- Rectification — have incorrect data corrected
- Erasure — have your data deleted, unless we must keep it by law
- Restriction — limit how we use your data
- Portability — receive your data in a common, machine-readable format
- Objection — object to processing based on our legitimate interests
- Withdraw consent — where processing is based on consent, at any time and with effect for the future
To use any of these rights, email [email protected]. We respond within 30 days and may ask you to confirm your identity first.
You also have the right to complain to a data protection authority — in the EU, usually the authority in your country of residence; in Türkiye, the Personal Data Protection Authority (KVKK).
12Changes to this policy
We will update this policy whenever we change how we handle personal data — for example when we add a contact form or new service provider. The date at the top always shows the latest version. For significant changes affecting existing clients, we will let you know by email.
Questions about your data?
We answer every privacy request personally, usually within a few days.