Skip to main content

Privacy Policy

Last Updated: March 18, 2026

This Privacy Policy explains how Welkoop Verolme Holding B.V. (“we”, “us”, or “our”) collects, uses, shares, and protects personal data when you visit our website and when you submit information through our registration and contact forms. Welkoop Verolme Holding B.V. operates as an independent provider of online professional workplace education serving learners throughout Canada. Our registered address is Achterstrypseweg 15, 3235 NB Rockanje, Netherlands, and our main contact email is [email protected].

1. Introduction and controller identity

Welkoop Verolme Holding B.V. is the data controller for the personal data processed through this website. That means we determine why and how your personal data is used in connection with website access, programme registration requests, workshop enquiries, and learner support communications.

Controller details:

We do not appoint a Data Protection Officer (DPO) for this website because we do not conduct large-scale systematic monitoring or large-scale processing of special categories of personal data. If you have privacy questions, contact us using the details above and we will route your request appropriately.

Effective date: March 18, 2026.

2. Personal data we collect

We collect personal data that you choose to provide and data that is generated when you use the website. The categories below describe what we may collect depending on how you interact with the site.

  • Identity and contact data: name, email address, phone number, and any other contact details you provide.
  • Form submission content: selected programme, preferred workshop (if provided), and any comments or questions you include. This can include scheduling preferences, learning goals, and context that helps us respond.
  • Technical data: IP address, browser type and version, device information, operating system, language settings, and approximate location derived from IP (country/region level).
  • Usage data: pages viewed, time spent on pages, referring source, and basic interaction data such as navigation paths or clicks. This category is collected only if you consent to analytics cookies.
  • Cookies and identifiers: first-party cookies needed for site function and consent storage, and (if you opt in) analytics and marketing identifiers used for measurement and advertising (see Section 4).
  • Conversion events: when you submit a form or complete a specific interaction that is treated as a conversion event for measurement purposes. If marketing consent is enabled, these events may be linked to advertising identifiers.

We do not intentionally collect special categories of personal data (such as health information, biometric data, political opinions, religious beliefs, or union membership), financial account details, or government identification numbers through this website. Please do not include such information in free-text fields. If such information is provided inadvertently, we will take reasonable steps to remove it or limit its use where practicable.

3. Why we process personal data and legal basis (GDPR)

As a Netherlands-based organization, our processing is governed by the General Data Protection Regulation (GDPR) and applicable Dutch implementation laws. We process personal data only when there is a lawful basis under Article 6 GDPR.

  • Programme registration and contact enquiries: We process your form submissions to respond to your request, provide registration guidance, and communicate next steps. Legal basis: Article 6(1)(b) (performance of a contract or steps at your request prior to entering a contract) and, where required for specific communications, Article 6(1)(a) (consent).
  • Learner support communications: If you contact us by email or phone, we use your details to manage correspondence and support questions. Legal basis: Article 6(1)(b) and/or Article 6(1)(f) (legitimate interests in running an effective support channel).
  • Analytics measurement: If you opt in to analytics cookies, we process usage data to understand how content is used and to improve navigation and learning information. Legal basis: Article 6(1)(a) (consent).
  • Marketing and advertising measurement: If you opt in to marketing cookies, we may process identifiers and conversion events to measure advertising performance and to run remarketing and similar audience activities. Legal basis: Article 6(1)(a) (consent).
  • Security, abuse prevention, and troubleshooting: We process technical data and server logs to protect the website, detect malicious activity, and maintain availability. Legal basis: Article 6(1)(f) (legitimate interests in securing our systems and services).
  • Legal obligations: We may process data to comply with legal requirements, such as responding to lawful requests and meeting record-keeping obligations. Legal basis: Article 6(1)(c) (legal obligation).

Automated decision-making and profiling: We do not engage in automated decision-making or profiling that produces legal effects or similarly significant effects for you under Article 22 GDPR.

4. Cookies and tracking technologies

We use cookies and similar technologies to keep the site functional, to measure usage, and (if you consent) to support advertising measurement. Cookies are small text files stored on your device. We also reference “pixel tags” or “tags”, which are small pieces of code that can send information such as page views or conversions to a provider.

4.1 Categories of cookies

Our consent system uses three categories. These categories match the categories described in our Cookie Policy.

  • Essential cookies (always active): Required for the site to function and to store your consent selection. These do not require consent under applicable cookie rules because they are strictly necessary.
  • Analytics cookies (consent required): Used to understand how visitors use the site. We plan for analytics to be implemented via Google Analytics 4 (GA4) with IP anonymization where supported by configuration.
  • Marketing cookies (consent required): Used to measure conversions from ads, build remarketing audiences, and improve relevance of advertising. This category may include Google Ads and Meta technologies when enabled.

4.2 Examples, typical cookies, and retention

The exact cookies present in your browser depend on your consent choices and on whether analytics and marketing tools are enabled. Typical cookie names and retention periods include:

  • Essential: _site_session (session), cookie_consent (12 months).
  • Analytics (GA4): _ga (2 years), _ga_XXXXXXXXXX (2 years). Analytics data retention is typically configured to 14 months.
  • Marketing: _gcl_au (90 days), _fbp (90 days), _fbc (90 days when click parameters are present).

4.3 Beyond cookies

Some measurement systems also use device and request metadata (for example, IP address and User-Agent) and may support server-side event forwarding. Where used, we treat these technologies as analytics or marketing tools, and we activate them only based on the preferences stored in the cookie_consent cookie.

5. Consent and how to withdraw it

Users in the European Economic Area (EEA) and the United Kingdom receive a consent notice under GDPR/UK GDPR standards. Analytics and marketing cookies are disabled unless you provide explicit, informed, freely given consent (Article 6(1)(a) GDPR).

Your choices are stored in the browser cookie named cookie_consent for up to 12 months. You may withdraw or change your consent at any time by using “Manage cookie preferences” in the website footer, or by clearing cookies in your browser. Withdrawal does not affect processing that occurred before the withdrawal took effect.

6. Sharing with advertising and service partners

We use service providers to operate and secure the website and, depending on your consent, to measure usage and advertising effectiveness. We do not sell personal data. When providers process data on our behalf, they do so under contracts that require appropriate safeguards.

  • Google LLC (Google Analytics 4, Google Ads, and tag management when enabled): may receive cookie identifiers, usage events, and conversion events depending on your consent. Privacy information: https://policies.google.com/privacy.
  • Meta Platforms, Inc. (Meta Pixel, Custom/Lookalike Audiences, Conversion API when enabled): may receive page views and conversion events linked to browser identifiers depending on your consent. Privacy information: https://www.facebook.com/privacy/policy.
  • Cloudflare, Inc. (content delivery and security): may process IP addresses and request metadata for threat detection, performance, and reliability. Privacy information: https://www.cloudflare.com/privacypolicy/.

We do not permit these providers to use site data for their own independent commercial purposes beyond providing services to us and operating their platforms as described in their policies. Where advertising tools are used, providers may act as separate controllers for certain processing (for example, their own measurement and security). We encourage you to review their privacy policies for details.

7. International transfers

Because we work with global service providers, personal data may be processed outside the European Economic Area, including in the United States. When transfers occur, we rely on appropriate safeguards such as:

  • EU-U.S. Data Privacy Framework (DPF) where applicable (since July 2023), including the UK Extension where relevant.
  • Standard Contractual Clauses (EU 2021/914) as a fallback mechanism when needed.
  • Additional contractual and technical measures appropriate to the risk and the transfer context.

You can request further information about transfer safeguards by contacting us at [email protected].

8. Retention

We keep personal data only as long as necessary for the purposes described in this policy, unless a longer period is required by law. Typical retention periods are:

  • Contact and registration submissions: up to 2 years from the last interaction, to support follow-up and learner support.
  • Email correspondence: for the duration of the relationship, and typically up to 1 year thereafter, unless a longer period is justified by an ongoing request or a legal need.
  • Server logs and security records: typically up to 90 days, unless an incident requires longer investigation.
  • Analytics data: typically 14 months (configuration level), subject to provider settings and your consent.
  • Marketing cookies: per cookie lifetime, typically up to 90 days for common marketing identifiers.
  • Cookie consent record: up to 3 years for audit and compliance purposes (where needed to demonstrate consent history), though the browser cookie may expire sooner.
  • Legal and tax records: retained as required by applicable law (often 6 to 10 years for certain documents).

9. Your rights

If GDPR applies to your personal data, you may have the right to request:

  • Access (Article 15)
  • Rectification (Article 16)
  • Erasure (Article 17)
  • Restriction of processing (Article 18)
  • Data portability (Article 20)
  • Objection (Article 21)
  • Withdraw consent at any time (Article 7(3)) for processing based on consent
  • Lodge a complaint with a supervisory authority (Article 77)

To exercise your rights, email [email protected]. We may request information to verify your identity. We aim to respond within 30 days, with the possibility of a 60-day extension for complex requests.

Supervisory authority: Because Welkoop Verolme Holding B.V. is established in the Netherlands, you may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). Information: https://autoriteitpersoonsgegevens.nl/. If you are in another EEA country, you can also contact your local authority; an overview is available via the European Data Protection Board: https://edpb.europa.eu/.

10. Children

This website is not directed at individuals under 16. We do not knowingly collect personal data from minors. If you believe a child under 16 has provided personal data without verifiable parental consent, contact us at [email protected] and we will take steps to delete the information promptly.

11. Do Not Track

Some browsers offer a “Do Not Track” (DNT) setting. This website does not respond to DNT signals. Third-party providers may have their own DNT handling; their tools are controlled on this site through our cookie consent choices.

12. Account and data deletion requests

We do not provide user accounts on this website. If you would like us to delete personal data you submitted through a form or via email, contact us at [email protected] with the subject line “Data Deletion Request”. We may ask you to confirm details needed to locate your submission and to verify identity. We aim to complete deletion within 30 days, except where limited retention is required by law or for the establishment, exercise, or defence of legal claims.

13. Business transfers

In the event of a merger, acquisition, asset sale, financing, restructuring, or insolvency, personal data may be transferred to a successor entity or advisers as part of that transaction. If such a transfer materially changes how personal data is used, we will provide notice on the website.

14. California (CCPA / CPRA)

If you are a California resident, you may have rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). In the last 12 months, we may have collected the following categories of information:

  • Identifiers: name, email, IP address, cookie identifiers.
  • Internet or network activity: interactions with our website, subject to consent for analytics and marketing.
  • Inferences: broad interests derived from page interactions when marketing tools are enabled.

We do not sell personal information as defined by CCPA. We may share personal information for cross-context behavioral advertising if you consent to marketing cookies. You may opt out by using the cookie preferences panel.

California rights may include: right to know, right to delete, right to correct, right to opt out of sale/sharing, and right to non-discrimination. To submit a request, email [email protected] with the subject line “California Privacy Request”. We will verify your identity before completing the request. Authorized agents must provide documentation showing authority to act on your behalf.

15. Virginia (VCDPA)

If you are a Virginia resident, you may have rights under the Virginia Consumer Data Protection Act (VCDPA), including access, correction, deletion, portability, and the ability to opt out of targeted advertising. We do not sell personal data or engage in profiling that produces legal or similarly significant effects.

To submit a request, email [email protected] with the subject line “Virginia Privacy Request”. If we deny your request, you may appeal by emailing with the subject line “Appeal of Refusal — Privacy Request”. We will respond to appeals within 60 days.

16. Nevada

Nevada residents may submit a verified opt-out request by emailing [email protected] with the subject line “Nevada Do Not Sell Request”. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.

17. Changes to this policy

We may update this Privacy Policy from time to time. If changes are material, we will provide a notice on the website at least 14 days before the changes take effect where feasible. The “Last Updated” date at the top of this page indicates when the policy was last revised.

18. Contact

For questions, requests, or complaints regarding privacy, contact: