Inburgering.org

Privacy Policy

Last updated: July 1, 2025

1. Data Controller Information

kirilof

Vaartweg 17-4

1211 JC Hilversum

Netherlands

Email: kirill@inburgering.org

Website: inburgering.org

2. Introduction

This Privacy Policy explains how we collect, use, and protect your personal data when you use our inburgering exam preparation service. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

3. Personal Data We Collect

3.1 Information You Provide Directly

  • Account Information: Name, email address, password (encrypted)

  • Profile Information: Language level, learning goals, preferences

  • Payment Information: Billing address, payment method details (processed by our payment provider)

  • Communication Data: Messages you send us, support requests, feedback

3.2 Information We Collect Automatically

  • Usage Data: Pages visited, exercises completed, time spent on activities

  • Performance Data: Exercise scores, progress metrics, learning patterns

  • Technical Data: IP address, browser type, device information, operating system

  • Cookies and Tracking: As described in our Cookie Policy below

  • Social Media Data: When using Facebook Login, we receive your public profile information and email address

3.3 Information We Do Not Collect

  • We do not collect sensitive personal data such as health information, political opinions, or religious beliefs

  • We do not record audio for speaking exercises (when implemented)

  • We do not track your activity outside our website

4. Legal Basis for Processing

4.1 Contract Performance (Article 6(1)(b) GDPR)

  • Providing our educational services

  • Managing your subscription and account

  • Processing payments

4.2 Legitimate Interests (Article 6(1)(f) GDPR)

  • Improving our service quality and user experience

  • Analyzing learning patterns to enhance content

  • Preventing fraud and ensuring security

  • Direct marketing (with opt-out option)

4.3 Consent (Article 6(1)(a) GDPR)

  • Marketing communications (where required)

  • Optional cookies and analytics

  • Newsletter subscriptions

4.4 Legal Obligations (Article 6(1)(c) GDPR)

  • Retaining financial records for tax purposes

  • Responding to legal requests from authorities

5. How We Use Your Personal Data

5.1 Service Provision

  • Creating and managing your user account

  • Providing access to exercises and learning materials

  • Tracking your learning progress and performance

  • Customizing content based on your level and preferences

  • Processing subscription payments

5.2 Communication

  • Sending important service updates and notifications

  • Responding to your support requests and feedback

  • Sending marketing communications (with your consent)

  • Notifying you of new features or course updates

5.3 Service Improvement

  • Analyzing user behavior to improve our platform

  • Identifying popular content and learning patterns

  • Developing new features and exercises

  • Ensuring technical performance and security

5.4 Legal and Security

  • Preventing fraud and unauthorized access

  • Complying with legal obligations

  • Protecting our intellectual property rights

  • Resolving disputes

6. Data Sharing and Recipients

6.1 We Share Data With:

  • Payment Processors: Stripe or similar services for processing subscriptions

  • Email Service Providers: For sending notifications and marketing emails

  • Analytics Services: Google Analytics (anonymized data only)

  • Cloud Storage Providers: AWS or similar for hosting and data storage

  • Customer Support Tools: For managing support requests

6.2 We Do Not:

  • Sell your personal data to third parties

  • Share your learning progress with employers or government agencies

  • Use your data for purposes other than stated in this policy

  • Transfer data outside the EU without appropriate safeguards

6.3 Legal Disclosure

We may disclose your data if required by law, court order, or to protect our legal rights and safety.

7. Data Retention

7.1 Active Accounts

  • Account data: Retained while your account is active

  • Learning progress: Retained while your account is active

  • Payment records: 7 years (legal requirement)

7.2 Account Deletion

  • User-initiated deletion: 7-day confirmation period, then permanent deletion

  • Inactive accounts: May be deleted after 3 years with prior notification

  • Data retention during deletion process: Account remains accessible during 7-day confirmation period

  • Social media disconnection: Automatic deletion when you remove our app from Facebook/social platforms

7.3 Inactive Accounts

  • Accounts inactive for more than 3 years may be deleted after email notification

  • You can reactivate your account at any time before deletion

7.4 Marketing Data

  • Unsubscribe from marketing: Data removed within 30 days

  • Consent withdrawal: Processing stops immediately

8. Your Rights Under GDPR

8.1 Right of Access (Article 15)

  • Request a copy of all personal data we hold about you

  • Receive information about how we process your data

8.2 Right to Rectification (Article 16)

  • Correct inaccurate or incomplete personal data

  • Update your profile information at any time

8.3 Right to Erasure (Article 17)

  • Request deletion of your personal data ("right to be forgotten")

  • Delete your account through account settings with email confirmation

  • 7-day cancellation period before permanent deletion

  • Immediate deletion available upon request for legal compliance

8.4 Right to Restrict Processing (Article 18)

  • Limit how we process your data in certain circumstances

  • Temporarily suspend data processing

8.5 Right to Data Portability (Article 20)

  • Receive your data in a machine-readable format

  • Transfer your data to another service provider

8.6 Right to Object (Article 21)

  • Object to processing based on legitimate interests

  • Opt out of direct marketing at any time

8.7 Right to Withdraw Consent (Article 7)

  • Withdraw consent for any consent-based processing

  • Does not affect the lawfulness of previous processing

8.8 How to Exercise Your Rights

Contact us at kirill@inburgering.org or use your account settings for account deletion (includes 7-day confirmation period). For Facebook Login users: You can also request data deletion by removing our app from your Facebook account settings. We will automatically process the deletion and provide you with a confirmation number and status URL. We will respond to other requests within 1 month of receiving them.

9. International Data Transfers

9.1 Within the EU

Most of our data processing occurs within the European Union.

9.2 Outside the EU

If we transfer data outside the EU, we ensure adequate protection through:

  • Adequacy decisions by the European Commission

  • Standard Contractual Clauses (SCCs)

  • Certification schemes or codes of conduct

9.3 Third-Party Services

Our third-party service providers (like payment processors) may be located outside the EU but provide adequate data protection guarantees.

10. Data Security

10.1 Technical Measures

  • Encryption of data in transit and at rest

  • Secure HTTPS connections for all communications

  • Regular security updates and patches

  • Access controls and authentication systems

10.2 Organizational Measures

  • Staff training on data protection

  • Regular security audits and assessments

  • Incident response procedures

  • Data breach notification protocols

10.3 Data Breach Notification

In case of a data breach that poses a risk to your rights and freedoms, we will:

  • Notify the Dutch Data Protection Authority within 72 hours

  • Inform affected users without undue delay

  • Provide information about the breach and remedial actions

11. Cookies and Tracking Technologies

11.1 Essential Cookies

  • Authentication and session management

  • Security and fraud prevention

  • Basic functionality and user preferences

11.2 Analytics Cookies

  • Google Analytics (anonymized IP addresses)

  • Performance monitoring and error tracking

  • User behavior analysis for service improvement

11.3 Marketing Cookies

  • Retargeting and advertising (with consent)

  • Social media integration

  • Conversion tracking

11.4 Cookie Management

You can control cookies through:

  • Your browser settings

  • Our cookie consent banner

  • Opt-out tools provided by analytics services

12. Children's Privacy

12.1 Age Restrictions

  • Users under 16 require parental consent

  • Users under 13 are not permitted to create accounts

  • We do not knowingly collect data from children under 13

12.2 Parental Rights

Parents can:

  • Request access to their child's data

  • Request deletion of their child's account

  • Withdraw consent for data processing

13. Changes to This Privacy Policy

13.1 Updates

  • We may update this policy to reflect legal changes or service improvements

  • Significant changes will be notified via email and website notices

  • Continued use after changes indicates acceptance

13.2 Version Control

  • Each update includes a "last updated" date

  • Previous versions available upon request

14. Supervisory Authority

You have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens):

Autoriteit Persoonsgegevens

Website: autoriteitpersoonsgegevens.nl

Phone: +31 70 8888 500

15. Social Media Integration

15.1 Facebook Login

  • We offer login through Facebook to simplify account creation

  • We collect only basic profile information and email address from Facebook

  • Your Facebook data is handled according to both our Privacy Policy and Facebook's Data Policy

15.2 Data Deletion via Social Media

  • Automatic deletion: When you remove our app from Facebook settings, we automatically delete your data

  • Confirmation process: You receive a unique confirmation code and status URL to track deletion

  • Response time: Social media deletion requests are processed immediately

  • Scope: This deletes all data associated with your social media account, including learning progress

15.3 Data Deletion Request Callback

  • We implement Facebook's required data deletion callback system

  • When you disconnect our app, Facebook notifies us automatically

  • We process these requests within 24 hours of receiving them

  • You can check deletion status using the provided confirmation code

16. Contact Information

16.1 General Inquiries

Email: kirill@inburgering.org

Address: kirilof, Vaartweg 17-4, 1211 JC Hilversum, Netherlands

16.2 Data Protection Officer

For data protection matters, contact us at: kirill@inburgering.org

16.3 Response Time

We aim to respond to all privacy-related inquiries within 1 month.

This Privacy Policy is designed to be transparent and comprehensive. If you have any questions about how we handle your personal data, please don't hesitate to contact us.

For questions about this document, please contact us at kirill@inburgering.org