Privacy Policy
Last Updated: March 14, 2026
1. Introduction & Controller Identity
This Privacy Policy explains how Atelier Noord Art Courses (“we”, “us”, or “our”) collects, uses, and protects your personal data when you visit this website and when you contact us about our studio-led art courses in the Netherlands. It is written to be practical: what we collect, why we collect it, how long we keep it, and what choices you have.
For the purposes of the General Data Protection Regulation (GDPR), the data controller is:
- Legal entity: Atelier Noord Art Courses B.V.
- Address: Botterstraat 3, 3028 RL Rotterdam, Netherlands
- Email: [email protected]
- Phone: +31 10 261 9847
We do not appoint a Data Protection Officer (DPO) for the activities described in this policy. If you have questions about privacy or data protection, contact us using the details above and we will route the request to the appropriate person.
Effective Date: March 14, 2026.
2. Personal Data We Collect
We collect personal data in three main ways: (a) data you provide directly, (b) data collected automatically when you use the website, and (c) data derived from cookies and similar technologies when you consent to them.
2.1 Identity and contact details
- Name (as provided in our contact form)
- Email address
- Phone number (optional, if you provide it)
2.2 Form content and course-related context
When you contact us, we collect the content you send. This can include your preferred course track (drawing, painting, mixed media, portfolio development), preferred format (Rotterdam studio sessions or online learning in the Netherlands), schedule constraints, and any other details you choose to share in the message field.
2.3 Technical data
- IP address (which may be used to infer approximate location)
- Browser type and version
- Device type, operating system, and language settings
- Date/time of access and basic request metadata
- Referral source (the page that brought you to our website)
2.4 Usage and interaction data
When you consent to analytics or marketing cookies, we may collect information about how you use the site: which pages you view, time on page, scroll and click events used for site improvement, and conversions such as submitting a contact request.
2.5 Cookies and identifiers
We use cookies and similar identifiers as described in Section 4 (“Cookies & Tracking”). Some are essential for site operation (for example, remembering consent choices), and others are optional and depend on your consent.
2.6 What we do not intentionally collect
Our services are educational art courses. We do not intentionally collect special-category data (for example, health data, religious beliefs, or political opinions), financial account details, or government identification numbers. Please do not include sensitive information in your message.
3. Why We Process Personal Data & Legal Basis (GDPR Art. 6)
We process personal data only when we have a lawful basis under the GDPR. The specific basis depends on the purpose:
3.1 Responding to contact requests
- Purpose: to respond to your inquiry, confirm availability, recommend a starting course track, and coordinate next steps.
- Legal basis: GDPR Art. 6(1)(b) (steps prior to entering into a contract) and Art. 6(1)(a) (consent, where required by how you submit information and preferences).
3.2 Analytics (optional)
- Purpose: to understand how the website is used so we can improve content, navigation, and clarity of course information.
- Legal basis: GDPR Art. 6(1)(a) (consent).
3.3 Marketing and remarketing (optional)
- Purpose: to measure advertising performance, attribute conversions, build remarketing audiences, and show relevant offers to people who have interacted with our website.
- Legal basis: GDPR Art. 6(1)(a) (consent).
3.4 Security, fraud prevention, and service reliability
- Purpose: to protect the website, diagnose issues, prevent abuse, and maintain service continuity.
- Legal basis: GDPR Art. 6(1)(f) (legitimate interests).
3.5 Legal obligations
- Purpose: to comply with applicable laws, enforce agreements, or respond to lawful requests from authorities.
- Legal basis: GDPR Art. 6(1)(c) (legal obligation).
3.6 Automated decision-making (GDPR Art. 22)
We do not engage in automated decision-making or profiling that produces legal effects or similarly significant effects for you.
4. Cookies & Tracking
Cookies are small text files stored on your device. We also use similar technologies that can function like cookies, such as pixel tags. Our website groups cookies into three categories: Essential, Analytics, and Marketing. Only Essential cookies are active by default. Analytics and Marketing cookies activate only if you give explicit consent using our cookie banner or preference panel.
4.1 Essential cookies (always active)
Essential cookies are required for the website to function and to remember your privacy choices. These cookies do not require consent under applicable EU ePrivacy rules when they are strictly necessary.
- Examples: _site_session and cookie_consent.
- Retention: session to 12 months (depending on the cookie).
- Purpose: session continuity, security measures (including CSRF protection where applicable), and storing consent preferences.
4.2 Analytics cookies (consent required)
If you consent, we may use Google Analytics 4 (GA4) to understand website usage. Where supported, we apply IP anonymization and configure analytics to focus on aggregate insights (for example, which course pages are most visited and whether people find the contact form).
- Examples: _ga (2 years), _ga_XXXXXXXXXX (2 years; GA4 property-specific identifier), and similar GA4 cookies.
- Data retention in GA4: 14 months (configuration target).
- What is collected: device and browser information, pages visited, approximate location (derived from IP), and interaction events.
4.3 Marketing cookies (consent required)
If you consent, Marketing cookies help us measure advertising performance and show relevant offers. This can include remarketing (showing an ad to people who previously visited our site) and conversion attribution (understanding whether an ad led to a contact request).
- Examples: _gcl_au (Google Ads; 90 days), _fbp (Meta Pixel; 90 days), _fbc (Meta click ID; 90 days when a click ID is present).
- Beyond cookies: pixel tags (for example, via gtag.js or Meta Pixel) and, where configured later, server-side signals such as Meta Conversion API or server-side tag management. These may use hashed identifiers and device signals such as IP address and User-Agent for attribution.
You can manage your cookie preferences at any time using the “Manage cookie preferences” link in the footer.
5. Consent (EEA/UK)
Users in the European Economic Area (EEA) and the United Kingdom receive a consent notice under GDPR/UK GDPR. Analytics and marketing cookies activate only after explicit, informed, freely given consent (GDPR Art. 6(1)(a)). Your consent choice is recorded in the cookie_consent browser cookie for up to 12 months.
You can withdraw consent at any time via “Manage cookie preferences” in the footer or by clearing cookies in your browser. Withdrawal does not affect the lawfulness of processing based on consent before it was withdrawn.
6. Sharing With Advertising & Service Partners
We use reputable service providers to operate and improve the website and (if you consent) to measure advertising and analytics. Depending on your settings, personal data may be shared with:
6.1 Google LLC
Services may include Google Analytics 4, Google Ads, Google Tag Manager, and remarketing. Data can include cookie identifiers, usage data, conversion events, and audience signals. Google’s privacy information: https://policies.google.com/privacy.
6.2 Meta Platforms
Services may include Meta Pixel, Custom Audiences/Lookalike Audiences, and (where configured later) server-side conversion APIs. Data can include page views, conversions, audience membership, and hashed identifiers. Meta’s privacy information: https://www.facebook.com/privacy/policy.
6.3 Cloudflare
We may use Cloudflare for content delivery and security. Cloudflare can process IP-based threat and performance data to protect the site. Cloudflare’s privacy information: https://www.cloudflare.com/privacypolicy/.
We do not sell personal data. These providers may not use site data for their own independent commercial purposes outside providing services to us, subject to their contractual and legal obligations.
7. International Transfers
Some providers may process data outside the European Economic Area, including in the United States. Where applicable, we rely on transfer mechanisms such as the EU–US Data Privacy Framework (DPF) (since July 2023) and the UK Extension to the DPF, with Standard Contractual Clauses (EU 2021/914) and UK IDTA as fallback mechanisms where needed.
We implement reasonable safeguards intended to protect personal data during international transfers, including contractual protections and configuration settings that limit unnecessary data collection.
8. Retention
We keep personal data only as long as necessary for the purposes described in this policy and for legal, accounting, or security requirements. Typical retention periods:
- Contact submissions: 2 years from the last interaction, unless a longer period is required to manage an ongoing relationship or resolve disputes.
- Analytics data: 14 months (configuration target within GA4), subject to provider settings and your consent status.
- Marketing cookies: per cookie lifetime (for example, 90 days), subject to consent status and provider settings.
- Email correspondence: for the duration of the relationship plus 1 year where needed for continuity and accountability.
- Server logs: typically up to 90 days for security and troubleshooting.
- Cookie consent record: up to 3 years for audit and compliance purposes.
- Legal/tax records: retained as required by applicable law (often 6–10 years for invoices and accounting records).
9. Your Rights (GDPR & UK GDPR)
If GDPR applies to your personal data, you may have the following rights:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (“right to be forgotten”) (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Right to withdraw consent at any time (Art. 7(3))
- Right to lodge a complaint with a supervisory authority (Art. 77)
To exercise your rights, email [email protected]. We aim to respond within 30 days. For complex requests, the response time may be extended by up to 60 additional days as permitted by GDPR.
If you want to complain to a supervisory authority, you may contact the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). You can also find general guidance via the European Data Protection Board: https://edpb.europa.eu/.
10. Children
This site is not directed at individuals under 16. We do not knowingly collect personal data from minors. If we learn that we have collected personal data from a child under 16 without appropriate consent, we will delete it promptly.
11. Do Not Track
This website does not respond to “Do Not Track” (DNT) signals. Third-party providers may have their own DNT handling.
12. Account & Data Deletion Requests
We do not require user accounts for contacting us about courses. If you want us to delete personal data associated with your contact request, email us with the subject line Data Deletion Request and include enough information for us to locate your record (for example, the email address used in the form).
We will complete deletion requests within 30 days after verifying identity, unless we must retain certain data to comply with legal obligations or to establish, exercise, or defend legal claims.
13. Business Transfers
If we are involved in a merger, acquisition, asset sale, financing, reorganization, or insolvency, personal data may be transferred to a successor or affiliate as part of that transaction. If such a transfer materially changes how personal data is used, we will provide notice on the website.
14. California (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, may provide additional rights. In the past 12 months, we may have disclosed the following categories of information for business purposes:
- Identifiers: name, email, IP address, cookie IDs (shared with service providers and, if you consent, advertising partners).
- Internet/network activity: pages viewed and interactions (used for analytics and, if you consent, advertising measurement).
- Inferences: interests and preferences derived from interactions (used for advertising optimization if you consent).
We do not sell personal information as defined by CCPA. We do share personal information for cross-context behavioral advertising if you enable marketing cookies. California residents may opt out through our cookie preferences panel.
To submit a request, email [email protected] with the subject California Privacy Request. We may need to verify your identity before responding. Authorized agents must provide proof of authorization.
We do not discriminate against users for exercising privacy rights.
15. Virginia (VCDPA)
If you are a Virginia resident, you may have rights to access, correct, delete, obtain a copy of personal data, and opt out of targeted advertising. We do not sell personal data and we do not engage in profiling that produces legal or similarly significant effects.
To submit a request, email [email protected] with the subject Virginia Privacy Request.
If we decline to act on your request, you may appeal by emailing with the subject Appeal of Refusal — Privacy Request. We will respond to appeals within 60 days. If the appeal is denied, you may contact the Virginia Attorney General.
16. Nevada
Nevada residents may submit a verified opt-out request by emailing [email protected] with the subject line Nevada Do Not Sell Request. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will post a notice on the website at least 14 days before the changes take effect. The “Last Updated” date at the top of this page will reflect the current version.
18. Contact
For privacy-related questions or requests, contact:
- Atelier Noord Art Courses B.V.
- Botterstraat 3, 3028 RL Rotterdam, Netherlands
- [email protected]
- +31 10 261 9847