Privacy Policy
Last updated: July 1, 2025
1. Data Controller Information
kirilof
Vaartweg 17-4
1211 JC Hilversum
Netherlands
Email: kirill@inburgering.org
Website: inburgering.org
2. Introduction
This Privacy Policy explains how we collect, use, and protect your personal data when you use our inburgering exam preparation service. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
3. Personal Data We Collect
3.1 Information You Provide Directly
Account Information: Name, email address, password (encrypted)
Profile Information: Language level, learning goals, preferences
Payment Information: Billing address, payment method details (processed by our payment provider)
Communication Data: Messages you send us, support requests, feedback
3.2 Information We Collect Automatically
Usage Data: Pages visited, exercises completed, time spent on activities
Performance Data: Exercise scores, progress metrics, learning patterns
Technical Data: IP address, browser type, device information, operating system
Cookies and Tracking: As described in our Cookie Policy below
Social Media Data: When using Facebook Login, we receive your public profile information and email address
3.3 Information We Do Not Collect
We do not collect sensitive personal data such as health information, political opinions, or religious beliefs
We do not record audio for speaking exercises (when implemented)
We do not track your activity outside our website
4. Legal Basis for Processing
4.1 Contract Performance (Article 6(1)(b) GDPR)
Providing our educational services
Managing your subscription and account
Processing payments
4.2 Legitimate Interests (Article 6(1)(f) GDPR)
Improving our service quality and user experience
Analyzing learning patterns to enhance content
Preventing fraud and ensuring security
Direct marketing (with opt-out option)
4.3 Consent (Article 6(1)(a) GDPR)
Marketing communications (where required)
Optional cookies and analytics
Newsletter subscriptions
4.4 Legal Obligations (Article 6(1)(c) GDPR)
Retaining financial records for tax purposes
Responding to legal requests from authorities
5. How We Use Your Personal Data
5.1 Service Provision
Creating and managing your user account
Providing access to exercises and learning materials
Tracking your learning progress and performance
Customizing content based on your level and preferences
Processing subscription payments
5.2 Communication
Sending important service updates and notifications
Responding to your support requests and feedback
Sending marketing communications (with your consent)
Notifying you of new features or course updates
5.3 Service Improvement
Analyzing user behavior to improve our platform
Identifying popular content and learning patterns
Developing new features and exercises
Ensuring technical performance and security
5.4 Legal and Security
Preventing fraud and unauthorized access
Complying with legal obligations
Protecting our intellectual property rights
Resolving disputes
6. Data Sharing and Recipients
6.1 We Share Data With:
Payment Processors: Stripe or similar services for processing subscriptions
Email Service Providers: For sending notifications and marketing emails
Analytics Services: Google Analytics (anonymized data only)
Cloud Storage Providers: AWS or similar for hosting and data storage
Customer Support Tools: For managing support requests
6.2 We Do Not:
Sell your personal data to third parties
Share your learning progress with employers or government agencies
Use your data for purposes other than stated in this policy
Transfer data outside the EU without appropriate safeguards
6.3 Legal Disclosure
We may disclose your data if required by law, court order, or to protect our legal rights and safety.
7. Data Retention
7.1 Active Accounts
Account data: Retained while your account is active
Learning progress: Retained while your account is active
Payment records: 7 years (legal requirement)
7.2 Account Deletion
User-initiated deletion: 7-day confirmation period, then permanent deletion
Inactive accounts: May be deleted after 3 years with prior notification
Data retention during deletion process: Account remains accessible during 7-day confirmation period
Social media disconnection: Automatic deletion when you remove our app from Facebook/social platforms
7.3 Inactive Accounts
Accounts inactive for more than 3 years may be deleted after email notification
You can reactivate your account at any time before deletion
7.4 Marketing Data
Unsubscribe from marketing: Data removed within 30 days
Consent withdrawal: Processing stops immediately
8. Your Rights Under GDPR
8.1 Right of Access (Article 15)
Request a copy of all personal data we hold about you
Receive information about how we process your data
8.2 Right to Rectification (Article 16)
Correct inaccurate or incomplete personal data
Update your profile information at any time
8.3 Right to Erasure (Article 17)
Request deletion of your personal data ("right to be forgotten")
Delete your account through account settings with email confirmation
7-day cancellation period before permanent deletion
Immediate deletion available upon request for legal compliance
8.4 Right to Restrict Processing (Article 18)
Limit how we process your data in certain circumstances
Temporarily suspend data processing
8.5 Right to Data Portability (Article 20)
Receive your data in a machine-readable format
Transfer your data to another service provider
8.6 Right to Object (Article 21)
Object to processing based on legitimate interests
Opt out of direct marketing at any time
8.7 Right to Withdraw Consent (Article 7)
Withdraw consent for any consent-based processing
Does not affect the lawfulness of previous processing
8.8 How to Exercise Your Rights
Contact us at kirill@inburgering.org or use your account settings for account deletion (includes 7-day confirmation period). For Facebook Login users: You can also request data deletion by removing our app from your Facebook account settings. We will automatically process the deletion and provide you with a confirmation number and status URL. We will respond to other requests within 1 month of receiving them.
9. International Data Transfers
9.1 Within the EU
Most of our data processing occurs within the European Union.
9.2 Outside the EU
If we transfer data outside the EU, we ensure adequate protection through:
Adequacy decisions by the European Commission
Standard Contractual Clauses (SCCs)
Certification schemes or codes of conduct
9.3 Third-Party Services
Our third-party service providers (like payment processors) may be located outside the EU but provide adequate data protection guarantees.
10. Data Security
10.1 Technical Measures
Encryption of data in transit and at rest
Secure HTTPS connections for all communications
Regular security updates and patches
Access controls and authentication systems
10.2 Organizational Measures
Staff training on data protection
Regular security audits and assessments
Incident response procedures
Data breach notification protocols
10.3 Data Breach Notification
In case of a data breach that poses a risk to your rights and freedoms, we will:
Notify the Dutch Data Protection Authority within 72 hours
Inform affected users without undue delay
Provide information about the breach and remedial actions
11. Cookies and Tracking Technologies
11.1 Essential Cookies
Authentication and session management
Security and fraud prevention
Basic functionality and user preferences
11.2 Analytics Cookies
Google Analytics (anonymized IP addresses)
Performance monitoring and error tracking
User behavior analysis for service improvement
11.3 Marketing Cookies
Retargeting and advertising (with consent)
Social media integration
Conversion tracking
11.4 Cookie Management
You can control cookies through:
Your browser settings
Our cookie consent banner
Opt-out tools provided by analytics services
12. Children's Privacy
12.1 Age Restrictions
Users under 16 require parental consent
Users under 13 are not permitted to create accounts
We do not knowingly collect data from children under 13
12.2 Parental Rights
Parents can:
Request access to their child's data
Request deletion of their child's account
Withdraw consent for data processing
13. Changes to This Privacy Policy
13.1 Updates
We may update this policy to reflect legal changes or service improvements
Significant changes will be notified via email and website notices
Continued use after changes indicates acceptance
13.2 Version Control
Each update includes a "last updated" date
Previous versions available upon request
14. Supervisory Authority
You have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens):
Autoriteit Persoonsgegevens
Website: autoriteitpersoonsgegevens.nl
Phone: +31 70 8888 500
15. Social Media Integration
15.1 Facebook Login
We offer login through Facebook to simplify account creation
We collect only basic profile information and email address from Facebook
Your Facebook data is handled according to both our Privacy Policy and Facebook's Data Policy
15.2 Data Deletion via Social Media
Automatic deletion: When you remove our app from Facebook settings, we automatically delete your data
Confirmation process: You receive a unique confirmation code and status URL to track deletion
Response time: Social media deletion requests are processed immediately
Scope: This deletes all data associated with your social media account, including learning progress
15.3 Data Deletion Request Callback
We implement Facebook's required data deletion callback system
When you disconnect our app, Facebook notifies us automatically
We process these requests within 24 hours of receiving them
You can check deletion status using the provided confirmation code
16. Contact Information
16.1 General Inquiries
Email: kirill@inburgering.org
Address: kirilof, Vaartweg 17-4, 1211 JC Hilversum, Netherlands
16.2 Data Protection Officer
For data protection matters, contact us at: kirill@inburgering.org
16.3 Response Time
We aim to respond to all privacy-related inquiries within 1 month.
This Privacy Policy is designed to be transparent and comprehensive. If you have any questions about how we handle your personal data, please don't hesitate to contact us.
For questions about this document, please contact us at kirill@inburgering.org