Privacy Policy
What personal data we process, why we are allowed to, who we share it with, how long we keep it, and the rights you have.
Last Updated: August 31, 2026
Who We Are
GoBeyondDutch ("we," "our," or "us") is an online Dutch language school based in Amsterdam, Netherlands. We are the controller responsible for the personal data described in this policy, within the meaning of Article 4(7) of the General Data Protection Regulation (GDPR).
GoBeyondDutch
GoBeyondDutch.nl
Amsterdam, Netherlands
KvK: 74612123
BTW: NL002499321B96
Email: [email protected]
Phone: +31 85 333 5559
Information We Collect
Information you give us
We collect personal information that you voluntarily provide when you:
- Register for our courses or create an account
- Fill out contact forms or request information
- Subscribe to our newsletter
- Communicate with us via email or other channels
This can include your name, email address, phone number, and payment information. Payment card details are entered directly with our payment processor, Stripe — they never touch our servers.
Information collected automatically
When you visit our website, our hosting and security providers process technical information needed to serve the pages: your IP address, browser type, and request metadata. Analytics cookies are placed only after you consent — see the cookie policy.
How We Use Your Information
Under the GDPR, every use of your data needs a legal basis. This table lists each purpose and the Article 6 basis we rely on:
| We process your data to… | Legal basis (Art. 6 GDPR) |
|---|---|
| Create and manage your account and course enrollment | Performance of a contract (Art. 6(1)(b)) |
| Deliver classes, communicate about schedules, and provide course materials | Performance of a contract (Art. 6(1)(b)) |
| Process payments and issue invoices | Performance of a contract and legal obligation (Art. 6(1)(b) + (c)) |
| Send transactional emails (enrollment confirmations, class reminders) | Performance of a contract (Art. 6(1)(b)) |
| Send marketing emails about new cohorts and offers | Your consent, which you can withdraw at any time (Art. 6(1)(a)) |
| Prevent fraud and protect the security and integrity of our services | Our legitimate interest in running a secure business (Art. 6(1)(f)) |
| Improve our website and services through analytics | Our legitimate interest, balanced against your privacy (Art. 6(1)(f)) |
| Measure which marketing campaigns bring visitors and enrollments (campaign-level attribution) | Our legitimate interest in knowing which marketing works (Art. 6(1)(f)) — you can object at any time (Art. 21) |
| Respond to your class request or level-check enquiry and tell you when a class matching your request opens | Steps taken at your request before entering a contract (Art. 6(1)(b)) |
| Record which campaign link led to an enquiry and, where it results in an enrolment, to that enrolment | Our legitimate interest in knowing which marketing works (Art. 6(1)(f)) — you can object at any time (Art. 21) |
| Comply with legal obligations (tax, accounting, consumer protection) | Legal obligation (Art. 6(1)(c)) |
Marketing Attribution
We use short campaign links (for example in our Instagram bio) to count how many visits each marketing campaign brings. Clicking one records an aggregate counter on our own servers — a number per campaign per day. It stores nothing about you: no IP address, no device fingerprint, no identifier.
We do not do this yet. When personal links launch, a link we send you in a direct message will — with your consent — set a first-party cookie (gbd_t, see the cookie policy) so that our own server can see that the link was used and which pages that visit viewed. That measurement will stay entirely on our own systems: never sent to Google, Stripe, Meta, or any other third party, and deleted after 30 days (a purchase-attribution record after at most 90 days). We describe it here in advance so this policy is already accurate on the day it launches.
We rely on our legitimate interest in knowing which marketing works (Art. 6(1)(f) GDPR). You can object at any time under Article 21 — email us at [email protected], or simply decline in the cookie banner and no measurement cookie is set. Nothing we measure this way ever affects the price you pay or the service you receive.
Who We Share Your Information With
We share the minimum personal data necessary with the following processors, each bound by a written Data Processing Agreement (Art. 28 GDPR). Where a processor is located outside the European Economic Area, the transfer safeguard column shows the mechanism used under Articles 44–46 GDPR (checked against the EU-U.S. Data Privacy Framework participant list on 2026-08-23):
| Processor | Purpose | Data categories | Location | Transfer safeguard |
|---|---|---|---|---|
| Neon, Inc. | Production database hosting | All service data (account, enrollment, and course records) | Data hosted in the EU (Frankfurt, AWS eu-central-1) | Data Processing Agreement; data at rest stays in the EEA |
| Stripe, Inc. | Payment processing | Name, email, payment method, billing country | United States | EU-U.S. Data Privacy Framework (self-certified) + Standard Contractual Clauses |
| Brevo (Sendinblue SAS) | Transactional and marketing email delivery | Name, email address, enrollment status | EU (France) | Intra-EEA processing |
| Zoom Video Communications, Inc. | Live online class delivery | Name, email address, class join timestamps | United States | EU-U.S. Data Privacy Framework (self-certified) + Standard Contractual Clauses |
| Vercel Inc. | Website hosting and edge delivery | IP address, request metadata | United States (global edge network) | EU-U.S. Data Privacy Framework (self-certified) + Standard Contractual Clauses |
| Cloudflare, Inc. | Content delivery network, security, tag management (Zaraz), consent management, and cookieless web analytics | IP address, request metadata, your cookie-consent choices | United States (global network) | EU-U.S. Data Privacy Framework (self-certified) + Standard Contractual Clauses |
| Google Ireland Ltd / Google LLC | Website analytics (Google Analytics 4), loaded only after you consent | Online identifiers (cookie IDs), page views, approximate location | Ireland / United States | EU-U.S. Data Privacy Framework (self-certified) + Standard Contractual Clauses |
| Functional Software, Inc. (Sentry) | Error monitoring and performance diagnostics | Error and diagnostic data; all page text, form input, and media are masked before anything is sent | United States | EU-U.S. Data Privacy Framework (self-certified) + Standard Contractual Clauses |
An up-to-date processor list is available on request at [email protected]. We will notify enrolled students before adding a processor that materially changes the data flow.
Beyond these processors, we disclose personal data only when required by law or in response to valid requests by public authorities, or — in the event of a merger, acquisition, or sale of assets — to the acquiring entity. We do not sell your personal information.
How Long We Keep Your Data
| Data category | Retention period | Reason |
|---|---|---|
| Account data (name, email, course history) | Duration of the account + 2 years after last login | So returning students can re-enroll without re-registering |
| Invoices and payment records | 7 years from issue date | Dutch tax law (fiscale bewaarplicht, Art. 52 AWR) |
| Contact-form submissions | 12 months | To follow up on inquiries |
| Class requests and level-check enquiries | 90 days after our last contact; reduced to a campaign label if you enrol (the link to your enrolment is removed after 12 months) | To reply, and to plan new class groups around real demand |
| Do-not-contact record | Kept indefinitely (minimal: email address and date only) | So we can honour your request not to be contacted |
| Marketing email subscription | Until you unsubscribe + 30 days | To process the unsubscribe request |
| Server and access logs | 30 days | Security and debugging |
| Campaign measurement counters | Indefinite (aggregate numbers only — no personal data) | Counting clicks per campaign involves no individual records |
| Personal-link visit measurement (see the cookie policy: gbd_t)Not in use yet | 30 days; a purchase-attribution record at most 90 days (once this launches) | Short measurement window for which marketing conversation led to an enrollment |
| Analytics data (Google Analytics 4) | 14 months | Year-over-year comparison of website traffic |
We do not record live classes. If we ever introduce recordings, we will update this policy first and ask for your consent before any class you attend is recorded.
How We Protect Your Data
We apply the security measures required by Article 32 GDPR. These include:
- TLS encryption for all data in transit
- AES-256-GCM encryption at rest for sensitive data fields (such as access tokens and meeting links)
- Role-based access control for staff accounts
- Regular encryption-key rotation
- Signed, verified webhooks for payment events
No system is perfectly secure, but we work to keep your data as safe as is reasonably possible.
Your Rights
Under the GDPR you have the right to:
- Access and receive a copy of your personal information (Art. 15)
- Correct inaccurate or incomplete information (Art. 16)
- Have your personal information deleted (Art. 17)
- Restrict our processing of your information (Art. 18)
- Receive your data in a portable format (Art. 20)
- Object to processing based on our legitimate interest, including marketing attribution (Art. 21)
- Withdraw any consent at any time, without affecting processing that already happened (Art. 7(3))
How to exercise your rights. Email [email protected]. We will respond within one month, as required by Article 12 GDPR. If your request is complex, we may extend this by two further months and will tell you why.
Right to complain. If you believe we have not handled your personal data in line with the GDPR, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl. You also have the right to an effective judicial remedy.
Cookies
We use four categories of cookies. Cookies that are not strictly necessary are placed only after you give consent via the cookie banner, and you can change or withdraw your choice at any time on the cookie policy page, where every cookie is listed individually.
- Strictly necessary (no consent needed): Required for the site to function — signing in, protecting forms. The site cannot work without them, so they are placed without consent (Art. 11.7a lid 3 Telecommunicatiewet). [__Secure-authjs.session-token, __Host-authjs.csrf-token, __Secure-authjs.callback-url]
- Consent preferences (no consent needed): Remembers the cookie choices you made in the consent banner, so we do not ask you again on every page. [cf_consent]
- Analytics (only after you consent): Set via Cloudflare Zaraz only after you accept analytics in the consent banner. Used to understand how visitors use the site. [_ga, _ga_*]
- Marketing attribution (only after you consent): Not in use yet. When personal links launch, these are set only if you arrive via a personal link we sent you in a direct message, and only with your consent — measured entirely on our own servers and never shared with any third party. [gbd_t, gbd_tm]— not set today; listed in advance.
We do not use advertising cookies and we do not share cookie data with ad networks.
Age Restriction
Our courses are offered only to adults aged 18 and over, as a matter of service policy. We do not knowingly create accounts for anyone under 18 — if you become aware that a minor has registered, please contact us and we will delete the account. Where a minor aged 16 or over does lawfully interact with our services, we rely on their own consent in line with Article 8 GDPR and Article 5 UAVG.
Automated Decision-Making
We do not make decisions that significantly affect you solely through automated processing or profiling within the meaning of Article 22 GDPR.
Privacy Contact
We are not required to appoint a Data Protection Officer under Article 37 GDPR given our size and processing activities. For any privacy-related question, reach us at [email protected] with "Privacy" in the subject line, and we will route your request to the responsible person.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the new version on this page and update the "Last Updated" date; for material changes affecting enrolled students, we will also notify you by email. You are advised to review this Privacy Policy periodically.
Contact Us
If you have any questions about this Privacy Policy or our privacy practices, please contact us:
GoBeyondDutch
GoBeyondDutch.nl
Location: Amsterdam, Netherlands
KvK: 74612123
Email: [email protected]
Phone: +31 85 333 5559
