Privacy Policy
Last Updated: March 18, 2026
1. Introduction & Controller Identity
This Privacy Policy explains how Bizonder B.V. ("Bizonder", "we", "us", or "our") collects, uses, and protects personal data when you visit this website and when you contact us about our online professional education programs. Bizonder B.V. operates from the Netherlands and provides online education services to learners across Canada. The scope of our services is educational only.
Data Controller (GDPR): Bizonder B.V., Eendenparkweg 8, 3852 LK Ermelo, Netherlands. For privacy questions or requests, contact us at [email protected]. We do not appoint a Data Protection Officer (DPO) because our processing does not involve large-scale processing of special-category data. If this changes, we will update this policy and provide appropriate contact details.
This policy applies to personal data processed through our website, including inquiries, registration requests, and cookie-based preferences. Where this policy references "GDPR", it refers to the EU General Data Protection Regulation as implemented in the Netherlands.
2. Personal Data We Collect
We collect only the information needed to operate the website, respond to inquiries, and support registration for educational programs and workshops. Depending on how you interact with the site, we may collect the following categories of personal data:
- Identity and contact data: your name, email address, and phone number when you submit a form.
- Form content: messages you send to us, program selection, preferred workshop topic (if provided), and any details you include about learning goals or scheduling preferences.
- Technical data: IP address, browser type and version, device type, operating system, and language settings.
- Usage data: pages viewed, time spent on pages, referrer information, and interaction events (such as clicks) collected through analytics tools if you consent.
- Cookies and identifiers: cookie values and similar identifiers, including your cookie consent choices (see Section 4).
- Conversion events: events such as form submissions or other actions that indicate interest in an educational program, where enabled and where you have provided consent for marketing cookies.
We do not intentionally collect special-category data (such as health information, religious beliefs, or political opinions), financial account details, or government identification numbers through this website. Please do not include such information in free-text fields. If you choose to provide sensitive details in a message, we will treat it with care, but you should avoid sharing information that is not necessary for an education inquiry.
3. Why We Process Personal Data & Legal Basis (GDPR Art. 6)
We process personal data for specific purposes and rely on lawful bases under Article 6 of the GDPR:
- Responding to inquiries and registration requests (contact form and email): GDPR Art. 6(1)(b) (steps prior to entering into a contract) and Art. 6(1)(a) (consent where required for particular communications).
- Website analytics (improving content and user experience): GDPR Art. 6(1)(a) (consent).
- Marketing and remarketing (advertising measurement and audience building): GDPR Art. 6(1)(a) (consent).
- Security, abuse prevention, and fraud detection (protecting the website and systems): GDPR Art. 6(1)(f) (legitimate interests), balanced against your rights and expectations.
- Legal obligations (compliance and record-keeping when required): GDPR Art. 6(1)(c) (legal obligation).
Automated decision-making (GDPR Art. 22): We do not engage in automated decision-making or profiling that produces legal or similarly significant effects for you. If we use advertising audiences (for example, remarketing lists), they are used for ad delivery and measurement and are not used to make decisions with legal effect.
4. Cookies & Tracking Technologies
Our website uses cookies and similar technologies to provide core site functionality, remember your privacy choices, understand site usage, and (if you consent) measure and improve advertising performance. Cookies are small text files stored on your device. We also reference pixel tags (small snippets that communicate browser events) and may use server-side event forwarding where implemented by us or our service partners.
Essential (always active)
Essential cookies are required for the website to function and cannot be switched off in our systems. These include a site session cookie and your cookie preference record. Essential cookies help with security, basic navigation, and maintaining user choices. Retention ranges from session duration up to 12 months for consent storage.
Analytics (consent required)
If you opt in to analytics cookies, we may use Google Analytics 4 (GA4) to understand how the site is used. We configure analytics with IP anonymization where applicable. Analytics cookies help us see which pages are visited, how long users stay on a page, and how users navigate the website. We use this information to improve course descriptions, learning resources, and general site clarity. Analytics data retention is set to 14 months.
Marketing (consent required)
If you opt in to marketing cookies, we may use technologies from advertising partners such as Google Ads and Meta to measure conversions, build remarketing lists, and improve campaign targeting. Marketing cookies can help us understand which ads lead to actions like contacting us. Where implemented, pixels and server-side conversion events may process identifiers such as cookie IDs and technical signals (for example, IP address and User-Agent) to match conversions and measure performance.
Our cookie categories match the options available in the cookie preference panel. You can change your choices at any time by using the "Manage cookie preferences" link in the footer.
5. Consent (EEA/UK)
Users in the EEA and UK receive a consent notice under GDPR/UK GDPR. Analytics and marketing cookies activate only after explicit, informed, freely given consent (GDPR Art. 6(1)(a)). Your choice is recorded in the cookie_consent browser cookie (retention: 12 months). You may withdraw or change consent at any time via "Manage cookie preferences" in the footer or by clearing cookies in your browser. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
6. Sharing With Advertising & Service Partners
We share personal data only as needed to operate the website, respond to requests, and (where consented) run analytics and marketing. We do not sell personal data. The following categories of partners may receive data depending on your cookie choices and interactions:
- Google LLC (Google Analytics 4, Google Ads, Google Tag Manager, remarketing): may process cookie identifiers, usage data, and conversion events. Privacy information: https://policies.google.com/privacy.
- Meta Platforms, Inc. (Meta Pixel, Custom/Lookalike Audiences, Conversion API where used): may process page views, conversions, audience membership, and (in some setups) hashed identifiers for matching. Privacy information: https://www.facebook.com/privacy/policy.
- Cloudflare, Inc. (content delivery and security): may process IP addresses and technical signals for threat detection and performance. Privacy information: https://www.cloudflare.com/privacypolicy/.
These providers act as processors or independent controllers depending on the service. We configure and use these services to support our business operations. We do not permit these providers to use site data for their own independent commercial purposes outside of providing services to us, subject to their terms and applicable law.
7. International Transfers
Bizonder B.V. is based in the Netherlands. Some service providers we use (such as Google, Meta, and Cloudflare) may process data in countries outside the European Economic Area (EEA), including the United States. Where such transfers occur, we rely on appropriate safeguards, such as:
- EU-U.S. Data Privacy Framework (DPF) where applicable, including the UK Extension and Swiss-U.S. DPF where relevant.
- Standard Contractual Clauses (EU 2021/914) as a fallback mechanism when needed.
- UK International Data Transfer Agreement (IDTA) as a fallback when needed for UK transfers.
We also apply organizational and technical measures appropriate to the risks, such as access controls and minimizing data shared where possible.
8. Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law. Typical retention periods are:
- Contact submissions and registration requests: up to 2 years from last interaction.
- Analytics data: 14 months (where analytics consent is provided).
- Marketing cookies: retained according to cookie lifetimes (see cookie policy) and only where marketing consent is provided.
- Email correspondence: for the duration of the relationship and typically up to 1 additional year for continuity.
- Server logs: typically 90 days for security and troubleshooting.
- Cookie consent record: up to 3 years for audit and compliance evidence.
- Legal and tax records: where applicable, retained as required by Dutch law (often 6 to 10 years depending on the document type).
9. Your Rights (GDPR & UK GDPR)
If GDPR applies to your data, you have rights including: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), and the right to withdraw consent (Art. 7(3)). You also have the right to lodge a complaint with a supervisory authority (Art. 77).
To exercise your rights, email [email protected]. We aim to respond within 30 days. This period may be extended by up to 60 days for complex requests. We may ask for additional information to verify your identity before responding.
Supervisory authority information:
- Netherlands (primary): Dutch Data Protection Authority (Autoriteit Persoonsgegevens) via https://autoriteitpersoonsgegevens.nl/.
- EU guidance: European Data Protection Board via https://edpb.europa.eu/.
- UK: Information Commissioner's Office via https://ico.org.uk/.
10. Children
This website is not directed at individuals under 16. We do not knowingly collect personal data from minors. If you believe a child under 16 has provided personal data without verifiable parental consent, contact us and we will delete the information promptly.
11. Do Not Track
This website does not respond to "Do Not Track" (DNT) browser signals. Some third-party services may have their own handling of DNT or similar settings. You can control cookie behavior using our cookie preference tools and your browser settings.
12. Data Deletion Requests
You may request deletion of your personal data by emailing us with the subject line "Data Deletion Request". We will take reasonable steps to verify your identity and complete the request within 30 days where GDPR applies, unless we must retain certain information to comply with legal obligations or to establish, exercise, or defend legal claims.
13. Business Transfers
If Bizonder B.V. is involved in a merger, acquisition, asset sale, financing, or insolvency, personal data may be transferred to a successor entity. If a transfer materially changes how personal data is used, we will provide notice on the website.
14. California (CCPA / CPRA)
This section is provided for visitors from California. In the past 12 months, we may have collected the following categories of information: identifiers (such as name, email, IP address, and device identifiers), internet/network activity (such as page views and interactions), and inferences (such as interests derived from page interactions where marketing cookies are enabled).
We do not sell personal information as defined by the CCPA. We may share information for cross-context behavioral advertising where marketing cookies are enabled; California residents may opt out by disabling marketing cookies in our cookie preferences panel.
California privacy rights may include: the right to know, delete, correct, and opt out of sale/sharing, and the right to non-discrimination. Requests can be submitted by emailing [email protected] with the subject "California Privacy Request". We will verify identity before completing a request. Authorized agents must provide proof of authorization.
15. Virginia (VCDPA)
Virginia residents may have rights to access, correct, delete, and obtain a copy of personal data, and to opt out of targeted advertising. We do not sell personal data and we do not engage in profiling that produces legal or similarly significant effects. To submit a request, email [email protected] with the subject "Virginia Privacy Request".
If you believe your request has been improperly denied, you may appeal by emailing with the subject "Appeal of Refusal — Privacy Request". We will respond within 60 days. If the appeal is denied, you may contact the Virginia Attorney General.
16. Nevada
Nevada residents may submit a verified opt-out request by emailing us with the subject "Nevada Do Not Sell Request". We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. Material changes will be announced on the website at least 14 days before taking effect. The "Last Updated" date at the top of this page reflects the most recent revision.
18. Contact
For questions, requests, or concerns about this Privacy Policy or our data handling practices, contact:
- Legal entity: Bizonder B.V.
- Address: Eendenparkweg 8, 3852 LK Ermelo, Netherlands
- Email: [email protected]
- Phone: +31 341 491 782
Privacy inquiries
For GDPR requests (access, deletion, correction) or cookie questions, email [email protected]. Include enough detail to help us locate your data, and we will respond within the applicable legal timeframe.