Skip to content
Legal Information

Privacy Policy

What personal data we process, why we are allowed to, who we share it with, how long we keep it, and the rights you have.

Last Updated: August 31, 2026

Who We Are

GoBeyondDutch ("we," "our," or "us") is an online Dutch language school based in Amsterdam, Netherlands. We are the controller responsible for the personal data described in this policy, within the meaning of Article 4(7) of the General Data Protection Regulation (GDPR).

GoBeyondDutch

GoBeyondDutch.nl

Amsterdam, Netherlands

KvK: 74612123

BTW: NL002499321B96

Email: [email protected]

Phone: +31 85 333 5559

Information We Collect

Information you give us

We collect personal information that you voluntarily provide when you:

  • Register for our courses or create an account
  • Fill out contact forms or request information
  • Subscribe to our newsletter
  • Communicate with us via email or other channels

This can include your name, email address, phone number, and payment information. Payment card details are entered directly with our payment processor, Stripe — they never touch our servers.

Information collected automatically

When you visit our website, our hosting and security providers process technical information needed to serve the pages: your IP address, browser type, and request metadata. Analytics cookies are placed only after you consent — see the cookie policy.

How We Use Your Information

Under the GDPR, every use of your data needs a legal basis. This table lists each purpose and the Article 6 basis we rely on:

We process your data to…Legal basis (Art. 6 GDPR)
Create and manage your account and course enrollmentPerformance of a contract (Art. 6(1)(b))
Deliver classes, communicate about schedules, and provide course materialsPerformance of a contract (Art. 6(1)(b))
Process payments and issue invoicesPerformance of a contract and legal obligation (Art. 6(1)(b) + (c))
Send transactional emails (enrollment confirmations, class reminders)Performance of a contract (Art. 6(1)(b))
Send marketing emails about new cohorts and offersYour consent, which you can withdraw at any time (Art. 6(1)(a))
Prevent fraud and protect the security and integrity of our servicesOur legitimate interest in running a secure business (Art. 6(1)(f))
Improve our website and services through analyticsOur legitimate interest, balanced against your privacy (Art. 6(1)(f))
Measure which marketing campaigns bring visitors and enrollments (campaign-level attribution)Our legitimate interest in knowing which marketing works (Art. 6(1)(f)) — you can object at any time (Art. 21)
Respond to your class request or level-check enquiry and tell you when a class matching your request opensSteps taken at your request before entering a contract (Art. 6(1)(b))
Record which campaign link led to an enquiry and, where it results in an enrolment, to that enrolmentOur legitimate interest in knowing which marketing works (Art. 6(1)(f)) — you can object at any time (Art. 21)
Comply with legal obligations (tax, accounting, consumer protection)Legal obligation (Art. 6(1)(c))

Marketing Attribution

We use short campaign links (for example in our Instagram bio) to count how many visits each marketing campaign brings. Clicking one records an aggregate counter on our own servers — a number per campaign per day. It stores nothing about you: no IP address, no device fingerprint, no identifier.

We do not do this yet. When personal links launch, a link we send you in a direct message will — with your consent — set a first-party cookie (gbd_t, see the cookie policy) so that our own server can see that the link was used and which pages that visit viewed. That measurement will stay entirely on our own systems: never sent to Google, Stripe, Meta, or any other third party, and deleted after 30 days (a purchase-attribution record after at most 90 days). We describe it here in advance so this policy is already accurate on the day it launches.

We rely on our legitimate interest in knowing which marketing works (Art. 6(1)(f) GDPR). You can object at any time under Article 21 — email us at [email protected], or simply decline in the cookie banner and no measurement cookie is set. Nothing we measure this way ever affects the price you pay or the service you receive.

Who We Share Your Information With

We share the minimum personal data necessary with the following processors, each bound by a written Data Processing Agreement (Art. 28 GDPR). Where a processor is located outside the European Economic Area, the transfer safeguard column shows the mechanism used under Articles 44–46 GDPR (checked against the EU-U.S. Data Privacy Framework participant list on 2026-08-23):

ProcessorPurposeData categoriesLocationTransfer safeguard
Neon, Inc.Production database hostingAll service data (account, enrollment, and course records)Data hosted in the EU (Frankfurt, AWS eu-central-1)Data Processing Agreement; data at rest stays in the EEA
Stripe, Inc.Payment processingName, email, payment method, billing countryUnited StatesEU-U.S. Data Privacy Framework (self-certified) + Standard Contractual Clauses
Brevo (Sendinblue SAS)Transactional and marketing email deliveryName, email address, enrollment statusEU (France)Intra-EEA processing
Zoom Video Communications, Inc.Live online class deliveryName, email address, class join timestampsUnited StatesEU-U.S. Data Privacy Framework (self-certified) + Standard Contractual Clauses
Vercel Inc.Website hosting and edge deliveryIP address, request metadataUnited States (global edge network)EU-U.S. Data Privacy Framework (self-certified) + Standard Contractual Clauses
Cloudflare, Inc.Content delivery network, security, tag management (Zaraz), consent management, and cookieless web analyticsIP address, request metadata, your cookie-consent choicesUnited States (global network)EU-U.S. Data Privacy Framework (self-certified) + Standard Contractual Clauses
Google Ireland Ltd / Google LLCWebsite analytics (Google Analytics 4), loaded only after you consentOnline identifiers (cookie IDs), page views, approximate locationIreland / United StatesEU-U.S. Data Privacy Framework (self-certified) + Standard Contractual Clauses
Functional Software, Inc. (Sentry)Error monitoring and performance diagnosticsError and diagnostic data; all page text, form input, and media are masked before anything is sentUnited StatesEU-U.S. Data Privacy Framework (self-certified) + Standard Contractual Clauses

An up-to-date processor list is available on request at [email protected]. We will notify enrolled students before adding a processor that materially changes the data flow.

Beyond these processors, we disclose personal data only when required by law or in response to valid requests by public authorities, or — in the event of a merger, acquisition, or sale of assets — to the acquiring entity. We do not sell your personal information.

How Long We Keep Your Data

Data categoryRetention periodReason
Account data (name, email, course history)Duration of the account + 2 years after last loginSo returning students can re-enroll without re-registering
Invoices and payment records7 years from issue dateDutch tax law (fiscale bewaarplicht, Art. 52 AWR)
Contact-form submissions12 monthsTo follow up on inquiries
Class requests and level-check enquiries90 days after our last contact; reduced to a campaign label if you enrol (the link to your enrolment is removed after 12 months)To reply, and to plan new class groups around real demand
Do-not-contact recordKept indefinitely (minimal: email address and date only)So we can honour your request not to be contacted
Marketing email subscriptionUntil you unsubscribe + 30 daysTo process the unsubscribe request
Server and access logs30 daysSecurity and debugging
Campaign measurement countersIndefinite (aggregate numbers only — no personal data)Counting clicks per campaign involves no individual records
Personal-link visit measurement (see the cookie policy: gbd_t)Not in use yet30 days; a purchase-attribution record at most 90 days (once this launches)Short measurement window for which marketing conversation led to an enrollment
Analytics data (Google Analytics 4)14 monthsYear-over-year comparison of website traffic

We do not record live classes. If we ever introduce recordings, we will update this policy first and ask for your consent before any class you attend is recorded.

How We Protect Your Data

We apply the security measures required by Article 32 GDPR. These include:

  • TLS encryption for all data in transit
  • AES-256-GCM encryption at rest for sensitive data fields (such as access tokens and meeting links)
  • Role-based access control for staff accounts
  • Regular encryption-key rotation
  • Signed, verified webhooks for payment events

No system is perfectly secure, but we work to keep your data as safe as is reasonably possible.

Your Rights

Under the GDPR you have the right to:

  • Access and receive a copy of your personal information (Art. 15)
  • Correct inaccurate or incomplete information (Art. 16)
  • Have your personal information deleted (Art. 17)
  • Restrict our processing of your information (Art. 18)
  • Receive your data in a portable format (Art. 20)
  • Object to processing based on our legitimate interest, including marketing attribution (Art. 21)
  • Withdraw any consent at any time, without affecting processing that already happened (Art. 7(3))

How to exercise your rights. Email [email protected]. We will respond within one month, as required by Article 12 GDPR. If your request is complex, we may extend this by two further months and will tell you why.

Right to complain. If you believe we have not handled your personal data in line with the GDPR, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl. You also have the right to an effective judicial remedy.

Cookies

We use four categories of cookies. Cookies that are not strictly necessary are placed only after you give consent via the cookie banner, and you can change or withdraw your choice at any time on the cookie policy page, where every cookie is listed individually.

  • Strictly necessary (no consent needed): Required for the site to function — signing in, protecting forms. The site cannot work without them, so they are placed without consent (Art. 11.7a lid 3 Telecommunicatiewet). [__Secure-authjs.session-token, __Host-authjs.csrf-token, __Secure-authjs.callback-url]
  • Consent preferences (no consent needed): Remembers the cookie choices you made in the consent banner, so we do not ask you again on every page. [cf_consent]
  • Analytics (only after you consent): Set via Cloudflare Zaraz only after you accept analytics in the consent banner. Used to understand how visitors use the site. [_ga, _ga_*]
  • Marketing attribution (only after you consent): Not in use yet. When personal links launch, these are set only if you arrive via a personal link we sent you in a direct message, and only with your consent — measured entirely on our own servers and never shared with any third party. [gbd_t, gbd_tm]— not set today; listed in advance.

We do not use advertising cookies and we do not share cookie data with ad networks.

Age Restriction

Our courses are offered only to adults aged 18 and over, as a matter of service policy. We do not knowingly create accounts for anyone under 18 — if you become aware that a minor has registered, please contact us and we will delete the account. Where a minor aged 16 or over does lawfully interact with our services, we rely on their own consent in line with Article 8 GDPR and Article 5 UAVG.

Automated Decision-Making

We do not make decisions that significantly affect you solely through automated processing or profiling within the meaning of Article 22 GDPR.

Privacy Contact

We are not required to appoint a Data Protection Officer under Article 37 GDPR given our size and processing activities. For any privacy-related question, reach us at [email protected] with "Privacy" in the subject line, and we will route your request to the responsible person.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the new version on this page and update the "Last Updated" date; for material changes affecting enrolled students, we will also notify you by email. You are advised to review this Privacy Policy periodically.

Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us:

GoBeyondDutch

GoBeyondDutch.nl

Location: Amsterdam, Netherlands

KvK: 74612123

Email: [email protected]

Phone: +31 85 333 5559