1. Introduction
VCATalen respects your right to privacy. We process personal data in accordance with EU Regulation 2016/679 (GDPR), applicable Dutch laws including tax law (Belastingdienst), and best security practices.
This applies to all users visiting https://vcaedu.nl.
2. Data Controller
VCATalen B.V.
Registered Address: Kerkenbos 1097 B, 6546 BB Nijmegen, The Netherlands
Phone: +31 24 373 0654
Email: administratie@vcatalen.nl
KvK: 17173133
3. Data Protection Officer (DPO)
Appointed DPO: Marzena Domańska
Email: administratie@vcatalen.nl
4. What Personal Data Do We Process?
We collect and process the following personal data:
- Full name
- Company name (if applicable)
- Email address
- Phone number
- IP address, browser and system data
- Data entered via contact/order forms
- Invoice details: address, VAT/Btw number (if applicable)
- Payment details (via third-party providers)
- Cookie-related data
- Technical logs (e.g., errors, access)
5. Purpose and Legal Basis of Processing
| Purpose | Legal Basis (GDPR) |
|---|---|
| Service delivery (courses, invoicing) | Art. 6(1)(b) |
| Responding to inquiries | Art. 6(1)(f) |
| Accounting/tax obligations | Art. 6(1)(c) |
| Marketing (newsletter, consent-based) | Art. 6(1)(a) |
| Ensuring system security | Art. 6(1)(f) |
6. Hosting, Infrastructure, and Processors
- Hosting: Cloud server at Hetzner (Germany) – data stored in the EU, GDPR-compliant.
- Domain registration: GoDaddy – registration data only, no user data access.
- Security: SSL encryption, firewalls, access control.
- Accounting system: We use SnelStart for financial data, which is GDPR-compliant (Art. 28 & 32), stores data in the EU, and applies appropriate safeguards.
7. Cookies and Logs We use cookies for:
- Essential (technical) purposes
- Analytics – e.g. Google Analytics (with IP anonymization)
- Functional – e.g. language preferences
Consent is requested upon your first visit. See our [cookie policy – link]. Server logs are collected automatically for security and diagnostics.
8. Data Retention Periods
| Data Type | Retention Period |
| Invoices and accounting data | 7 years (Dutch law) |
| Contact form data | up to 12 months |
| Marketing data (e.g. email) | until consent withdrawn |
| Server logs & cookies | max. 3 months |
9. Data Sharing Data may be shared only with:
- Trusted service providers (Hetzner, GoDaddy)
- Accounting system SnelStart
- Payment providers (e.g. iDEAL, banks)
- Public authorities (e.g. Belastingdienst) when required by law
We do not transfer data outside the EEA unless appropriate safeguards (e.g. standard contractual clauses) are in place.
10. Your Rights You have the right to:
- Access your data
- Rectify your data
- Erase your data (“right to be forgotten”)
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent (without affecting previous lawful processing)
To exercise these rights, contact: administratie@vcatalen.nl
You may also file a complaint with the relevant authority:
- Autoriteit Persoonsgegevens (Netherlands): https://autoriteitpersoonsgegevens.nl
11. Data Security We apply appropriate technical and organizational measures:
- SSL connection encryption
- Restricted system access
- Server monitoring and firewalls
- Regular backups
- Collaboration only with GDPR-compliant partners
- Two-Factor Authentication (2FA) for admin/editor accounts
12. Changes to this Policy We reserve the right to update this policy. Changes will be posted on our website. Please review it regularly.
Last updated: 21 July 2025
