Privacy Policy
1. Who is responsible?
The data controller is [REGISTERED BUSINESS NAME], trading as Praatpaal, operated by Pascal van Gimst, KvK [KVK NUMBER], address [BUSINESS ADDRESS]. Privacy contact: [PRIVACY EMAIL].
2. Data collected
Praatpaal may process your name, email address, message, coaching topic, appointment and correspondence details, invoicing information and limited coaching records. The website may also generate technical security logs and store your language or colour preference locally in your browser.
3. Why and on what basis?
- To respond to enquiries and take steps requested before an agreement.
- To deliver and administer coaching under a contract.
- To meet accounting and other legal obligations.
- To secure and operate the website on the basis of legitimate interests.
- For optional communications only where consent or another valid basis applies.
4. Retention
Contact enquiries are kept for [ENQUIRY RETENTION PERIOD]. Coaching notes are kept for [COACHING-NOTE RETENTION PERIOD]. Invoices are kept for the legally required period. Define retention for website logs and backups here: [LOG / BACKUP RETENTION].
5. Service providers and transfers
Data may be processed by providers needed for hosting, email, forms, video calls, scheduling, invoicing or secure storage. List the actual providers and locations here: [PROCESSORS AND COUNTRIES]. Appropriate GDPR safeguards will be used where data is transferred outside the European Economic Area.
6. Sharing and confidentiality
Personal data is not sold. It is shared only where needed to provide the service, where you instruct Praatpaal to share it, or where disclosure is legally required. Coaching confidentiality is also addressed in the coaching agreement and Terms & Conditions.
7. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent where processing relies on consent. Contact [PRIVACY EMAIL]. You may also complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
8. Security, cookies and changes
Reasonable technical and organisational measures are used to protect information. Complete the security summary here: [SECURITY MEASURES]. If analytics, marketing cookies or embedded third-party media are introduced, this policy and the consent mechanism must be updated. Version: [VERSION / DATE].