Skip to main content

Home / Privacy Policy

Privacy Policy

This Privacy Policy explains how Fera Holding B.V. (“we”, “us”) collects, uses, and protects personal data when you visit derlavo.site (the “Site”) and when you contact us about our studio interview directing courses.

Last Updated: March 12, 2026

1. Introduction & Controller Identity

Fera Holding B.V. operates Derlavo as an educational platform focused on practical studio video shooting and directing, with emphasis on interview and conversation-based formats. This website provides educational information only. It does not offer production services, studio rental, equipment rental, talent booking, or career placement.

For the purposes of the General Data Protection Regulation (“GDPR”), Fera Holding B.V. is the data controller for personal data processed through this Site.

We do not appoint a Data Protection Officer for this small educational project. If you have privacy questions, contact us at the email address above and include “Privacy” in the subject line.

2. Personal Data We Collect

We collect personal data in a few clear contexts: when you visit the Site, when you interact with cookie consent controls, and when you contact us. The exact data depends on what you do on the Site and what your device sends as part of normal web requests.

  • Identity and contact data: name (if provided), email address, and phone number (if provided).
  • Form content: message text and any details you choose to include (for example: camera count, lens choices, framing questions, run-of-show concerns, or a description of your interview format).
  • Technical data: IP address, browser type, device type, operating system, language settings, and approximate location inferred from IP (country/region level).
  • Usage data: pages viewed, time spent on pages, referrer information, and interaction signals (such as clicks or scroll depth) when analytics is enabled by consent.
  • Cookies and identifiers: essential cookies to keep the site functional and a consent cookie that stores your choice. Analytics and marketing identifiers may be set only if you consent.
  • Conversion events: when you submit a contact form, we may record an event that a form was submitted (and which page it came from) for measurement, if you consent to marketing/analytics cookies.

We do not intentionally collect special-category data (such as health data, biometric identifiers, religion, or political opinions). Please do not include sensitive personal data in the message field. We also do not request government ID documents or financial account details through this Site.

3. Why We Process Personal Data & Legal Bases (GDPR Art. 6)

We process personal data only for purposes connected to operating an educational website and responding to course questions. Under the GDPR, each purpose must have a legal basis.

Contact and support

  • Purpose: respond to your course questions and provide accurate information about course scope and learning format.
  • Legal basis: Art. 6(1)(b) (steps at your request prior to entering into a contract) and Art. 6(1)(a) (consent, where you provide it through the contact form consent checkbox).

Analytics and product improvement

  • Purpose: understand which pages and lesson descriptions are most useful so we can improve navigation and clarity.
  • Legal basis: Art. 6(1)(a) (consent).

Marketing measurement and remarketing

  • Purpose: measure ad performance and show relevant course information to people who have previously visited the Site.
  • Legal basis: Art. 6(1)(a) (consent).

Security and abuse prevention

  • Purpose: protect the Site from automated abuse, malicious traffic, and security incidents.
  • Legal basis: Art. 6(1)(f) (legitimate interests in securing our services and preventing fraud).

Legal obligations

  • Purpose: comply with applicable legal obligations and respond to lawful requests.
  • Legal basis: Art. 6(1)(c) (legal obligation).

Automated decision-making (GDPR Art. 22): We do not engage in automated decision-making or profiling that produces legal or similarly significant effects.

4. Cookies & Tracking

Cookies are small text files stored on your device. We also use similar technologies such as pixel tags, and in some cases server-side event collection. Our cookie categories match what you can select in the cookie banner and preferences modal.

Essential cookies (always active)

Essential cookies are required for the Site to function. They include session continuity and storing your consent choice. These cookies do not require consent under EU rules when they are strictly necessary for the service you request.

  • _site_session — site session continuity. Retention: session to 30 days (depending on implementation).
  • cookie_consent — stores your cookie preferences. Retention: 12 months.

Analytics cookies (consent required)

If you opt in, we may use Google Analytics 4 (“GA4”) to understand how the Site is used. Where supported, IP addresses are anonymized or truncated. Analytics retention is configured for 14 months, after which data is deleted or aggregated.

  • _ga — GA4 user identifier. Typical retention: 2 years.
  • _ga_XXXXXXXXXX — GA4 session state. Typical retention: 2 years.

Marketing cookies (consent required)

If you opt in, marketing cookies may be used for conversion attribution, remarketing, and audience building (for example: showing course pages to people who previously visited the Site). These cookies help measure ad performance and reduce repeated irrelevant ads.

  • _gcl_au — Google Ads conversion linker. Typical retention: 90 days.
  • _fbp — Meta Pixel browser identifier. Typical retention: 90 days.
  • _fbc — Meta click identifier (when click ID is present). Typical retention: 90 days.

Beyond cookies, some partners may rely on event signals (for example: page view and form submission events) and device identifiers derived from IP address and browser user agent. Where server-side tracking is used in the future, it may include hashed identifiers (such as a hashed email) for matching, but only when consent is provided where required.

For more details about cookie categories and retention, read our Cookie Policy.

5. Consent (EEA / UK)

Users in the European Economic Area and the United Kingdom receive a consent notice consistent with GDPR/UK GDPR. Analytics and marketing cookies are activated only after explicit, informed, freely given consent (Art. 6(1)(a)).

Your choice is stored in the cookie_consent cookie (typically for 12 months). You can withdraw consent at any time by using “Manage cookie preferences” in the footer or by clearing cookies in your browser settings. Withdrawal does not affect processing that occurred before you withdrew consent.

6. Sharing With Advertising & Service Partners

We share data only when needed to operate the Site, respond to requests, and (when you consent) measure and improve marketing and analytics. We do not sell personal data.

  • Google LLC (Google Analytics 4, Google Ads, Google Tag Manager/remarketing where enabled): cookie IDs, usage data, conversion events. Privacy policy: https://policies.google.com/privacy
  • Meta Platforms, Inc. (Meta Pixel, Custom/Lookalike Audiences, Conversion API where enabled): page views, conversions, audience membership, and potentially hashed identifiers for matching when configured. Privacy policy: https://www.facebook.com/privacy/policy/
  • Cloudflare, Inc. (CDN and security services): IP address and request metadata for threat detection and performance. Privacy policy: https://www.cloudflare.com/privacypolicy/

These providers act as processors or independent controllers depending on the service. Where applicable, we use contractual safeguards and configuration controls. We do not permit these providers to use site data for their own independent commercial purposes beyond providing the services and complying with their legal obligations.

7. International Transfers

Some of our service providers are located outside the European Economic Area, including in the United States. When personal data is transferred internationally, we rely on appropriate safeguards, which may include:

  • EU–US Data Privacy Framework (where applicable, since July 2023) and the UK Extension to the DPF (where applicable).
  • Standard Contractual Clauses (EU 2021/914) as a fallback mechanism.
  • UK International Data Transfer Agreement (IDTA) where applicable.

You can request further details of the safeguards we use by contacting us at [email protected].

8. Data Retention

We keep personal data only for as long as needed for the purpose it was collected for, and then delete or anonymize it. Typical retention periods are:

  • Contact submissions: up to 2 years from the last interaction (to maintain context for follow-up questions).
  • Email correspondence: for the duration of the relationship plus 1 year.
  • Analytics: 14 months (GA4 retention setting), subject to aggregation.
  • Marketing cookies: according to the cookie lifetime (for example, 90 days for certain identifiers).
  • Server logs: typically up to 90 days, unless needed longer for security investigation.
  • Cookie consent record: up to 3 years for audit purposes.
  • Legal and tax records: where required by law (typically 6–10 years for invoices and accounting records).

9. Your Rights (GDPR & UK GDPR)

If the GDPR applies to you, you have rights in relation to your personal data, including:

  • Right of access (Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure (Art. 17)
  • Right to restriction of processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object (Art. 21)
  • Right to withdraw consent at any time (Art. 7(3))
  • Right to lodge a complaint with a supervisory authority (Art. 77)

To exercise your rights, email [email protected]. We aim to respond within 30 days. If a request is complex, we may extend the response period by up to 60 additional days, as permitted by law.

Supervisory authority information for EU residents is available via the European Data Protection Board: https://edpb.europa.eu/. In the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens: https://autoriteitpersoonsgegevens.nl/.

10. Children

This Site is not directed at individuals under 16. We do not knowingly collect personal data from minors. If you believe a child under 16 has provided personal data without verifiable parental consent, contact us and we will delete it promptly.

11. Do Not Track

This website does not respond to “Do Not Track” (DNT) browser signals. Third-party providers may have their own DNT handling.

12. Data Deletion Requests

You can request deletion of personal data by emailing [email protected] with the subject line “Data Deletion Request”. We may need to verify your identity before deleting data, especially if the request relates to messages that include identifying information. We aim to complete deletion within 30 days after verification, except where legal obligations require retention.

13. Business Transfers

If Fera Holding B.V. is involved in a merger, acquisition, financing, asset sale, or insolvency, personal data may be transferred to a successor entity as part of that transaction. If the transfer results in a material change to how personal data is used, we will provide notice on the Site.

14. California (CCPA / CPRA)

This section applies to California residents to the extent the California Consumer Privacy Act, as amended by the CPRA (“CCPA/CPRA”), applies to our processing.

In the past 12 months, we may have collected the following categories of personal information: identifiers (such as name and email if submitted), internet/network activity (such as pages viewed where analytics is enabled), and inferences (such as interests derived from page views where marketing is enabled).

We do not sell personal information as defined by the CCPA. We may share personal information for cross-context behavioral advertising when marketing cookies are enabled. California residents can opt out by rejecting marketing cookies in our cookie preferences panel.

Depending on applicability, you may have rights to know, delete, correct, and opt out of sale/sharing, and to be free from discrimination for exercising your rights. Requests can be submitted by emailing [email protected] with the subject “California Privacy Request”. We may request information to verify identity. Authorized agents must provide written proof of authorization.

15. Virginia (VCDPA)

If the Virginia Consumer Data Protection Act (“VCDPA”) applies, Virginia residents may have rights to access, correct, delete, obtain a copy of personal data, and opt out of targeted advertising. We do not sell personal data or engage in profiling that produces legal or similarly significant effects.

Submit requests by emailing [email protected] with the subject “Virginia Privacy Request”. If we deny a request, you can appeal by emailing with the subject “Appeal of Refusal — Privacy Request”. We respond to appeals within 60 days. Unresolved concerns may be directed to the Virginia Attorney General.

16. Nevada

Nevada residents may submit a verified opt-out request by emailing [email protected] with the subject “Nevada Do Not Sell Request”. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.

17. Changes to This Privacy Policy

We may update this Privacy Policy as our site and practices evolve. If changes are material, we will post a notice on the homepage at least 14 days before the changes take effect. The “Last Updated” date at the top of this page reflects the current version.

18. Contact

For privacy questions, requests, or complaints, contact:

Quick contact for privacy questions

For privacy-related requests, the fastest route is email: [email protected]. If you prefer phone, call +31 70 369 4827 during business hours in the Netherlands.