1. Who is responsible?The data controller is:
This Policy covers our Amsterdam website, enquiries, trial lessons, courses, camps, workshops, events and online lessons.
2. What information do we collect?Depending on how you use our services, we may collect:
- the parent or guardian’s name, email, phone number and address;
- the child’s name, age, date of birth, course, group and attendance;
- booking, payment and invoice details;
- messages, feedback and complaints;
- emergency contacts and people allowed to collect the child;
- information needed for safe participation, such as allergies or support needs;
- projects and files created during lessons;
- online lesson and learning-platform details;
- photos or videos, where appropriate permission has been given;
- website information such as IP address, browser, pages visited and cookie choices.
Please do not send us a BSN, passport or identity-card copy unless we have explained a specific legal need and secure method.
3. Why do we use this information?We use personal data to:
- answer questions and arrange trial lessons;
- register students and provide courses;
- choose an age-appropriate group;
- manage schedules, attendance and learning progress;
- process payments and keep required business records;
- communicate with parents;
- keep children safe and respond to emergencies;
- handle complaints and protect legal rights;
- operate and secure the website;
- send marketing only where allowed;
- use promotional photos or videos only with separate permission.
Our legal reasons are usually:
- taking steps before a contract;
- performing our agreement with the parent or guardian;
- meeting a legal obligation;
- protecting someone in an emergency;
- a carefully assessed legitimate interest;
- consent, where consent is the correct legal basis.
If information is required to provide or safely organise a course, we will mark or explain this. Optional marketing, tracking and promotional-photo consent are never required to join a course.
4. Children, health information and photosChildren should not register or create an external learning account without a parent or legal guardian.
In the Netherlands, a child under 16 cannot independently give GDPR consent for an online service where consent is the legal basis. We ask the parent or guardian where consent is needed.
Health, allergy and accessibility information receives extra protection. We collect only what is needed for safe participation and limit access to staff who need it.
We ask separately before using an identifiable child’s photo, video, voice, testimonial or project for public promotion. Saying no does not affect the child’s place. Permission can be withdrawn for future use.
We do not sell children’s data or use it for behavioural advertising.
5. Service messages and marketingWe may contact you about a booking, timetable, payment, safety issue or request. These are service messages.
Promotional email, SMS, WhatsApp or similar messages are sent only where allowed. Each message will identify us and provide an easy way to stop future marketing.
Consumer telemarketing calls are made only where we have the permission required by Dutch law. You may withdraw marketing consent or object at any time.
6. CookiesWe use necessary cookies for website operation and security. Low-impact analytics may be used where Dutch law allows.
Advertising, tracking and other optional cookies are not used before consent. The website must let visitors accept or refuse optional cookies and change their choice later.
A separate Cookie Policy will list the cookies actually used, their purpose, provider and duration after the production website has been scanned.
7. Who do we share data with?We share only what is needed. Recipients may include:
- authorised teachers and staff;
- website, form and hosting providers;
- CRM and academy-administration providers;
- payment and accounting providers;
- email, messaging and video-call providers;
- cloud storage and learning platforms;
- another Impact Academies branch when a parent asks for a transfer or shared service;
- professional advisers, insurers, emergency services or authorities where necessary.
These providers do not all receive the same information. Where a provider processes data for us, we use an appropriate data-processing agreement.
Some providers may process data outside the European Economic Area. Where this happens, we use an approved safeguard such as an adequacy decision or Standard Contractual Clauses.
We do not sell personal data.
8. How long do we keep data?Our proposed retention periods are:
- enquiries and unsuccessful trial-lesson leads: up to 24 months after the last contact;
- course and contract records: up to 5 years after the service ends when needed for legal claims;
- invoices and basic financial records: at least 7 years where Dutch law requires;
- routine attendance and collection details: normally 12 months after the programme;
- health and support information: normally deleted within 3 months after the relevant programme, unless an incident or legal duty requires longer;
- marketing information: until you unsubscribe or object, with inactive records reviewed after 24 months;
- promotional images: until permission is withdrawn or the scheduled review date, proposed at least every 3 years;
- complaints and incidents: until resolved and for any applicable legal claim period.
We delete or anonymise information when it is no longer needed.
9. Your rightsDepending on the situation, you may ask us to:
- give you access to your data;
- correct inaccurate data;
- delete data;
- limit how data is used;
- provide certain data in a portable format;
- stop direct marketing;
- consider an objection to another use;
- record withdrawal of consent.
A parent or legal representative may exercise rights for a child where legally appropriate.
Email the privacy contact above. We may ask for reasonable proof of identity and authority. We normally respond within one month.
10. Security, changes and contactWe use reasonable security measures, including access controls, staff confidentiality, secured systems, backups and supplier checks. If a serious personal-data breach occurs, we will notify the regulator and affected people where the GDPR requires.
We do not currently make legally or similarly significant decisions about students using only automated systems.
We may update this Policy when our services, providers or the law change. The current date will always appear at the top. We will ask again if a change requires new consent.
For questions or privacy requests:
Impact Academies Amsterdam
contact@impact-academies.nl+31 622 952 784