Skip to content
Your data, your control

Privacy Policy

This Privacy Policy explains what personal data we collect when you use enricovandelaar.com, why we collect it, and what rights you have. We aim to say this in plain language, no fine-print games.

Last updated: 8 July 2026

1. Who we are

The controller of your personal data is:

E van de Laar Holding B.V. (trading as Enrico van de Laar) located in Drachten, The Netherlands under the KvK (Chamber of Commerce) number: 69961697 Contact: enrico@enricovandelaar.com

If you have any question about this policy or your data, email us at the address above.

2. The data we collect and why

We only collect what we need for the purposes below. We do not sell your data, and we do not use it for advertising profiling.

a) Newsletter subscription

When you sign up for the newsletter, we collect your email address, and a source tag (which talk or page you signed up from) so we know how you found us and can keep content relevant. We also record your consent (when and how you gave it).

Purpose: to send you the newsletter you asked for.
Legal basis: your consent (Art. 6(1)(a) GDPR), confirmed via double opt-in.

b) Bonus / session materials

If you request bonus content tied to a talk, we collect your email address (and the relevant session tag) to deliver that material and, where you’ve agreed, add you to the newsletter.

Legal basis: your consent.

c) Contact and “For teams” enquiries

When you contact us or submit a training enquiry, we collect what you provide — your email address and, for a training enquiry, your team size, timeline, topic of interest, and the message/details you send.

Purpose: to respond to you and, for training enquiries, to scope and discuss possible work.
Legal basis: steps taken at your request prior to entering a contract, and our legitimate interest in responding to enquiries (Art. 6(1)(b) and 6(1)(f) GDPR).

d) Website analytics

We use privacy-friendly, cookieless analytics (Plausible) to understand aggregate traffic and pages viewed, rough referrer/entry point, country-level location. This data is aggregated and does not identify you personally, and we do not build individual profiles.

Legal basis: our legitimate interest in understanding and improving the site (Art. 6(1)(f) GDPR).

e) Server logs

Our hosting provider mijndomein processes standard technical logs (including IP address) as part of serving and securing the website.

Legal basis: our legitimate interest in operating a secure, functioning site.

3. The services (processors) we use

We use a small number of trusted providers who process data on our behalf, under data-processing agreements:

  • MailerLite — our email service provider, used for the newsletter, the signup and bonus-request forms, and consent records. It stores your email address, source tag, and consent data. See MailerLite’s own privacy documentation for how it processes data and where.

  • Plausible — privacy-first, cookieless website analytics. Aggregated, non-identifying.

  • mijndomein — hosts the website and processes technical server logs. Receives and stores the emails generated by the contact and enquiry forms so we can reply.

4. Cookies and tracking

Our analytics are cookieless, so we don’t set tracking or advertising cookies for analytics.

5. International transfers

None of our providers process data outside the European Economic Area (EEA). All providers are EU-based and store and process data in the EEA.

6. How long we keep your data

  • Newsletter — we store your email address, the source tag (which talk or page you signed up from), and your consent record. We keep these until you unsubscribe or ask us to remove you. You can unsubscribe from any email at any time.
  • Enquiries — we store your email address and any details you provide (for a training enquiry, that’s your team size, timeline, topic of interest, and message). We keep these for as long as needed to handle your request and any resulting relationship, then up to 12 months unless a longer period is legally required.
  • Analytics — aggregated data retained per our provider’s settings; it does not identify you.
  • Server logs — 30 days as set by our host.

7. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate or incomplete data;
  • erase your data (“right to be forgotten”);
  • restrict or object to our processing;
  • data portability (receive your data in a portable format);
  • withdraw consent at any time, where processing is based on consent (this doesn’t affect processing already carried out).

To exercise any of these, contact us through our contact form. We’ll respond within the timeframe required by law (normally within one month).

You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or your local EU data-protection authority.

8. Security

We take reasonable technical and organisational measures to protect your data, and we work with providers who do the same. No method of transmission or storage is completely secure, but we act to keep the risk low.

9. Children

This website and our services are not directed at children, and we do not knowingly collect data from anyone under 16.

10. Changes to this policy

We may update this policy from time to time. When we make material changes, we’ll update the “Last updated” date above and, where appropriate, let you know.

11. Contact

Questions about your privacy or this policy? Contact us through our contact form and we’ll help.