Last updated: 15 July 2026
1. Introduction
Protecting your privacy is important to us. Professional coaching is built on trust, and the same principle applies to the way we handle personal information. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, how long we retain it, and what rights you have under the General Data Protection Regulation (GDPR) and applicable Dutch privacy law.
2. Who is responsible for your data?
The data controller is:
Tünde Sensen
Trading as: Sensen Procurement Consultancy Services / Tünde Sensen Coaching
Sole proprietorship (eenmanszaak)
Liebetehofstraat 35
6002 CM Weert
The Netherlands
Website: https://tundesensen.com
Email: info@tundesensen.com
KVK number: 77393597
VAT ID: NL003190427B73
3. Scope of this Privacy Policy
This Privacy Policy applies when you:
- visit tundesensen.com;
- contact us by email, telephone, social media or a website form;
- subscribe to the newsletter;
- book a call through Calendly;
- make an enquiry about coaching or business services;
- become or have been a client;
- interact with us as a professional or business contact.
4. Personal data we may process
Depending on how you interact with us, we may process the following categories of personal data:
- identification and contact data, such as your name, email address and telephone number;
- professional information, such as employer, role, industry or whether you contact us as an individual or company representative;
- language preferences;
- information you voluntarily provide in an enquiry, booking form, questionnaire or email;
- appointment details, including date, time, time zone and booking responses;
- newsletter subscription information, including consent status, confirmation date, subscription source and unsubscription status;
- CRM information necessary to manage a business relationship, such as source, area of interest, status, next step, follow-up date and relevant communication notes;
- contractual, invoicing and payment information where you purchase a service;
- basic technical information necessary to operate and secure the website and online services, such as server logs or IP information processed by service providers.
We do not intentionally request special-category data (such as health information) through the newsletter or general contact forms. Please avoid including sensitive personal information unless it is genuinely necessary and has been specifically requested in an appropriate coaching context.
5. Purposes and legal bases
Processing purpose | Typical data | Legal basis | What this means |
Answering enquiries | Name, email, message, professional context | Art. 6(1)(b) GDPR – steps before a contract; and/or Art. 6(1)(f) – legitimate interests | We use the data to understand and respond to your request. |
Booking and preparing calls | Name, email, booking details and answers | Art. 6(1)(b) GDPR | Necessary to organise and prepare the requested conversation. |
Providing coaching or business services | Contact, contractual and service-related data | Art. 6(1)(b) GDPR | Necessary to perform the agreed service. |
Newsletter and promotional updates | Name, email, consent evidence and preferences | Art. 6(1)(a) GDPR – consent | We send marketing emails only after valid consent. |
Managing prospects and business contacts | Contact details, source, status, follow-up information | Art. 6(1)(f) GDPR – legitimate interests; where applicable Art. 6(1)(b) | We maintain an organised record of relevant business communication. You may object. |
Accounting, tax and legal compliance | Invoices, transaction and contract records | Art. 6(1)(c) GDPR | We retain records where the law requires us to do so. |
Website security and operation | Technical logs and security data | Art. 6(1)(f) GDPR | Necessary to provide and protect the website and systems. |
6. Contact, coaching enquiries and client relationships
If you contact us, we use the information you provide to respond, assess whether the requested service is suitable and, if appropriate, prepare or perform a coaching or business engagement. We record only information that is relevant to the relationship. Information collected for newsletter marketing is kept conceptually separate from information required for a client or business relationship.
7. Newsletter and Brevo
We use Brevo to manage newsletter subscriptions and send occasional professional insights, articles, service updates, workshop information and similar communications. The newsletter is currently intended to be sent in English.
Newsletter registration uses a double opt-in process:
- You submit the subscription form and consent to receive the newsletter.
- Brevo sends a confirmation email to the address provided.
- Your subscription becomes active only after you click the confirmation link.
- Consent evidence and subscription status are stored to demonstrate and manage your choice.
You can withdraw your consent at any time using the unsubscribe link in every newsletter. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. After unsubscribing, Brevo may retain the minimum suppression information needed to ensure that marketing emails are not sent to you again by mistake.
8. CRM and monday.com
We use monday.com as an internal customer relationship management (CRM) and workflow tool for enquiries, prospective clients, existing clients and relevant business contacts. Depending on the relationship, monday.com may contain your name, email address, company, preferred language, source of enquiry, area of interest, business status, next step, follow-up date, newsletter status and concise communication notes.
The business relationship status and newsletter status are separate. Withdrawing newsletter consent stops marketing communication but does not automatically erase records that are still necessary for an enquiry, contract, legal obligation or legitimate business relationship.
9. Appointment scheduling and Calendly
We use Calendly to allow you to book consultations. Calendly processes the information you enter, such as your name, email address, appointment details, time zone and answers to booking questions. We use this information to organise, prepare and conduct the requested appointment. Calendly may also send booking confirmations and reminders.
10. Workflow automation and Make.com
We use Make.com to automate limited administrative processes between selected systems, including Brevo, monday.com and Calendly. For example, an automation may update a newsletter status in monday.com after a subscription event. Make.com processes only the information needed for the configured workflow. We do not use these automations to make solely automated decisions that produce legal or similarly significant effects about you.
11. Website, hosting and email
The website and domain are operated using WordPress and STRATO infrastructure. STRATO also provides relevant hosting and email services. Technical logs may be processed to operate, maintain and secure the website and email environment.
12. Analytics and behavioural tracking
We currently do not use Google Analytics, Meta Pixel or similar behavioural advertising or analytics technologies. If such technologies are introduced later, this Privacy Policy and the Cookie Policy will be updated and, where required, prior consent will be requested.
13. Cookies and external services
The website may use strictly necessary cookies and may load functions supplied by WordPress plugins or external services. For details, including current cookie categories and lifetimes, please see the Cookie Policy. Optional non-essential cookies must not be activated before valid consent where consent is legally required.
14. Processors and recipients
We share personal data only where necessary with service providers acting on our behalf, professional advisers or authorities where legally required. Main service providers currently include:
Provider | Purpose | Role / relevant note |
STRATO | Domain, hosting and email services | Processor or independent controller depending on the service |
WordPress and installed plugins | Website content management and functionality | Technical platform; plugin providers must be assessed individually |
Brevo | Newsletter subscription, double opt-in and email delivery | Processor for customer newsletter data |
monday.com | CRM and workflow management | Processor for customer data stored in boards |
Calendly | Appointment booking and reminders | Processor for booking data; also acts as controller for certain account/service data |
Make.com / Celonis | Workflow automation | Processor for data handled in configured scenarios |
15. International transfers
Some providers or their subprocessors may process personal data outside the European Economic Area (EEA). Where personal data is transferred to a country without an EU adequacy decision, the provider or we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, and any additional measures required by law. Current provider DPAs and subprocessor lists should be checked periodically.
16. Retention periods
Data category | General retention approach |
Newsletter data | Until consent is withdrawn or the newsletter service is discontinued. Minimum suppression/consent evidence may be retained where necessary to respect and demonstrate the subscription choice. |
Unconfirmed newsletter registrations | Delete or anonymise after a short operational period, recommended no longer than 30–90 days, subject to Brevo configuration. |
General enquiries that do not become a client relationship | Normally up to 12 months after the last meaningful interaction, unless a longer period is justified. |
Prospective client CRM records | Review after 12 months; delete or minimise after no more than 24 months without meaningful interaction unless consent, a continuing relationship, a legal claim or another documented justification applies. |
Client and contractual records | For the duration of the relationship and thereafter as necessary for legal claims and applicable Dutch tax/accounting obligations. |
Booking information | As long as needed to manage the appointment and related relationship; review/delete when no longer relevant. |
Security logs | Only for the period reasonably necessary for security, troubleshooting and abuse prevention. |
Specific legal retention obligations take precedence over the general periods above. Internal records should document the applicable period and reason.
17. Security
We apply appropriate technical and organisational measures proportionate to the nature of the data and risks. These include, where applicable:
- encrypted connections (TLS/SSL);
- individual user accounts and role-based access;
- strong, unique passwords and multi-factor authentication where available;
- restricted access based on business need;
- secure sharing of credentials rather than storing passwords in ordinary documents;
- regular review of user access and software updates;
- trusted providers and processor agreements;
- incident identification and response procedures.
No online system can be guaranteed completely secure. We continuously seek to reduce risks and respond appropriately if an incident occurs.
18. Your GDPR rights
Subject to the conditions of applicable law, you may have the right to:
- receive information about how your data is used;
- access your personal data;
- correct inaccurate or incomplete data;
- request erasure;
- request restriction of processing;
- object to processing based on legitimate interests or to direct marketing;
- withdraw consent at any time;
- receive certain data in a portable format;
- lodge a complaint with a supervisory authority.
To exercise a right, email info@tundesensen.com. We may request proportionate information to verify your identity. We normally respond within one month, subject to the GDPR rules for complex or numerous requests.
19. Complaints
You may lodge a complaint with the Dutch supervisory authority: Autoriteit Persoonsgegevens (Dutch Data Protection Authority). Information about complaints is available at autoriteitpersoonsgegevens.nl.
20. Changes to this Privacy Policy
We may update this Privacy Policy when our services, systems or legal obligations change. The current version and update date will be published on the website. Where a change materially affects existing processing, we will provide additional notice where appropriate.
21. Contact
For privacy questions, requests or concerns:
Email: info@tundesensen.com
Postal address: Liebetehofstraat 35, 6002 CM Weert, The Netherlands