Last updated: 15 July 2026

1. Introduction

Protecting your privacy is important to us. Professional coaching is built on trust, and the same principle applies to the way we handle personal information. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, how long we retain it, and what rights you have under the General Data Protection Regulation (GDPR) and applicable Dutch privacy law.

2. Who is responsible for your data?

The data controller is:

Tünde Sensen
Trading as: Sensen Procurement Consultancy Services / Tünde Sensen Coaching
Sole proprietorship (eenmanszaak)
Liebetehofstraat 35
6002 CM Weert
The Netherlands
Website: https://tundesensen.com
Email: info@tundesensen.com
KVK number: 77393597
VAT ID: NL003190427B73

3. Scope of this Privacy Policy

This Privacy Policy applies when you:

  • visit tundesensen.com;
  • contact us by email, telephone, social media or a website form;
  • subscribe to the newsletter;
  • book a call through Calendly;
  • make an enquiry about coaching or business services;
  • become or have been a client;
  • interact with us as a professional or business contact.

4. Personal data we may process

Depending on how you interact with us, we may process the following categories of personal data:

  • identification and contact data, such as your name, email address and telephone number;
  • professional information, such as employer, role, industry or whether you contact us as an individual or company representative;
  • language preferences;
  • information you voluntarily provide in an enquiry, booking form, questionnaire or email;
  • appointment details, including date, time, time zone and booking responses;
  • newsletter subscription information, including consent status, confirmation date, subscription source and unsubscription status;
  • CRM information necessary to manage a business relationship, such as source, area of interest, status, next step, follow-up date and relevant communication notes;
  • contractual, invoicing and payment information where you purchase a service;
  • basic technical information necessary to operate and secure the website and online services, such as server logs or IP information processed by service providers.

We do not intentionally request special-category data (such as health information) through the newsletter or general contact forms. Please avoid including sensitive personal information unless it is genuinely necessary and has been specifically requested in an appropriate coaching context.

5. Purposes and legal bases

Processing purpose

Typical data

Legal basis

What this means

Answering enquiries

Name, email, message, professional context

Art. 6(1)(b) GDPR – steps before a contract; and/or Art. 6(1)(f) – legitimate interests

We use the data to understand and respond to your request.

Booking and preparing calls

Name, email, booking details and answers

Art. 6(1)(b) GDPR

Necessary to organise and prepare the requested conversation.

Providing coaching or business services

Contact, contractual and service-related data

Art. 6(1)(b) GDPR

Necessary to perform the agreed service.

Newsletter and promotional updates

Name, email, consent evidence and preferences

Art. 6(1)(a) GDPR – consent

We send marketing emails only after valid consent.

Managing prospects and business contacts

Contact details, source, status, follow-up information

Art. 6(1)(f) GDPR – legitimate interests; where applicable Art. 6(1)(b)

We maintain an organised record of relevant business communication. You may object.

Accounting, tax and legal compliance

Invoices, transaction and contract records

Art. 6(1)(c) GDPR

We retain records where the law requires us to do so.

Website security and operation

Technical logs and security data

Art. 6(1)(f) GDPR

Necessary to provide and protect the website and systems.

6. Contact, coaching enquiries and client relationships

If you contact us, we use the information you provide to respond, assess whether the requested service is suitable and, if appropriate, prepare or perform a coaching or business engagement. We record only information that is relevant to the relationship. Information collected for newsletter marketing is kept conceptually separate from information required for a client or business relationship.

7. Newsletter and Brevo

We use Brevo to manage newsletter subscriptions and send occasional professional insights, articles, service updates, workshop information and similar communications. The newsletter is currently intended to be sent in English.

Newsletter registration uses a double opt-in process:

  1. You submit the subscription form and consent to receive the newsletter.
  2. Brevo sends a confirmation email to the address provided.
  3. Your subscription becomes active only after you click the confirmation link.
  4. Consent evidence and subscription status are stored to demonstrate and manage your choice.

You can withdraw your consent at any time using the unsubscribe link in every newsletter. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. After unsubscribing, Brevo may retain the minimum suppression information needed to ensure that marketing emails are not sent to you again by mistake.

8. CRM and monday.com

We use monday.com as an internal customer relationship management (CRM) and workflow tool for enquiries, prospective clients, existing clients and relevant business contacts. Depending on the relationship, monday.com may contain your name, email address, company, preferred language, source of enquiry, area of interest, business status, next step, follow-up date, newsletter status and concise communication notes.

The business relationship status and newsletter status are separate. Withdrawing newsletter consent stops marketing communication but does not automatically erase records that are still necessary for an enquiry, contract, legal obligation or legitimate business relationship.

9. Appointment scheduling and Calendly

We use Calendly to allow you to book consultations. Calendly processes the information you enter, such as your name, email address, appointment details, time zone and answers to booking questions. We use this information to organise, prepare and conduct the requested appointment. Calendly may also send booking confirmations and reminders.

10. Workflow automation and Make.com

We use Make.com to automate limited administrative processes between selected systems, including Brevo, monday.com and Calendly. For example, an automation may update a newsletter status in monday.com after a subscription event. Make.com processes only the information needed for the configured workflow. We do not use these automations to make solely automated decisions that produce legal or similarly significant effects about you.

11. Website, hosting and email

The website and domain are operated using WordPress and STRATO infrastructure. STRATO also provides relevant hosting and email services. Technical logs may be processed to operate, maintain and secure the website and email environment.

12. Analytics and behavioural tracking

We currently do not use Google Analytics, Meta Pixel or similar behavioural advertising or analytics technologies. If such technologies are introduced later, this Privacy Policy and the Cookie Policy will be updated and, where required, prior consent will be requested.

13. Cookies and external services

The website may use strictly necessary cookies and may load functions supplied by WordPress plugins or external services. For details, including current cookie categories and lifetimes, please see the Cookie Policy. Optional non-essential cookies must not be activated before valid consent where consent is legally required.

14. Processors and recipients

We share personal data only where necessary with service providers acting on our behalf, professional advisers or authorities where legally required. Main service providers currently include:

Provider

Purpose

Role / relevant note

STRATO

Domain, hosting and email services

Processor or independent controller depending on the service

WordPress and installed plugins

Website content management and functionality

Technical platform; plugin providers must be assessed individually

Brevo

Newsletter subscription, double opt-in and email delivery

Processor for customer newsletter data

monday.com

CRM and workflow management

Processor for customer data stored in boards

Calendly

Appointment booking and reminders

Processor for booking data; also acts as controller for certain account/service data

Make.com / Celonis

Workflow automation

Processor for data handled in configured scenarios

15. International transfers

Some providers or their subprocessors may process personal data outside the European Economic Area (EEA). Where personal data is transferred to a country without an EU adequacy decision, the provider or we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, and any additional measures required by law. Current provider DPAs and subprocessor lists should be checked periodically.

16. Retention periods

Data category

General retention approach

Newsletter data

Until consent is withdrawn or the newsletter service is discontinued. Minimum suppression/consent evidence may be retained where necessary to respect and demonstrate the subscription choice.

Unconfirmed newsletter registrations

Delete or anonymise after a short operational period, recommended no longer than 30–90 days, subject to Brevo configuration.

General enquiries that do not become a client relationship

Normally up to 12 months after the last meaningful interaction, unless a longer period is justified.

Prospective client CRM records

Review after 12 months; delete or minimise after no more than 24 months without meaningful interaction unless consent, a continuing relationship, a legal claim or another documented justification applies.

Client and contractual records

For the duration of the relationship and thereafter as necessary for legal claims and applicable Dutch tax/accounting obligations.

Booking information

As long as needed to manage the appointment and related relationship; review/delete when no longer relevant.

Security logs

Only for the period reasonably necessary for security, troubleshooting and abuse prevention.

Specific legal retention obligations take precedence over the general periods above. Internal records should document the applicable period and reason.

17. Security

We apply appropriate technical and organisational measures proportionate to the nature of the data and risks. These include, where applicable:

  • encrypted connections (TLS/SSL);
  • individual user accounts and role-based access;
  • strong, unique passwords and multi-factor authentication where available;
  • restricted access based on business need;
  • secure sharing of credentials rather than storing passwords in ordinary documents;
  • regular review of user access and software updates;
  • trusted providers and processor agreements;
  • incident identification and response procedures.

No online system can be guaranteed completely secure. We continuously seek to reduce risks and respond appropriately if an incident occurs.

18. Your GDPR rights

Subject to the conditions of applicable law, you may have the right to:

  • receive information about how your data is used;
  • access your personal data;
  • correct inaccurate or incomplete data;
  • request erasure;
  • request restriction of processing;
  • object to processing based on legitimate interests or to direct marketing;
  • withdraw consent at any time;
  • receive certain data in a portable format;
  • lodge a complaint with a supervisory authority.

To exercise a right, email info@tundesensen.com. We may request proportionate information to verify your identity. We normally respond within one month, subject to the GDPR rules for complex or numerous requests.

19. Complaints

You may lodge a complaint with the Dutch supervisory authority: Autoriteit Persoonsgegevens (Dutch Data Protection Authority). Information about complaints is available at autoriteitpersoonsgegevens.nl.

20. Changes to this Privacy Policy

We may update this Privacy Policy when our services, systems or legal obligations change. The current version and update date will be published on the website. Where a change materially affects existing processing, we will provide additional notice where appropriate.

21. Contact

For privacy questions, requests or concerns:
Email: info@tundesensen.com
Postal address: Liebetehofstraat 35, 6002 CM Weert, The Netherlands