Privacy Policy
How Atelier Kazerne handles your personal data under the AVG (GDPR).
Last updated: 25 July 2026
1. Data Controller
Atelier Kazerne is the data controller responsible for processing your personal data in accordance with the Algemene verordening gegevensbescherming (AVG), the Dutch implementation of the General Data Protection Regulation (GDPR).
2. Personal Data We Collect
We may collect and process the following categories of personal data:
- Contact details: name, email address, phone number
- Booking information: workshop dates, course preferences, waitlist status, open studio membership
- Communication: messages sent via our contact form or email
- Technical data: IP address, browser type, pages visited (only with your consent via analytics cookies)
- Payment data: processed by our payment provider; we do not store full card details
3. Purposes and Legal Bases
We process your personal data for the following purposes and on the following legal bases under the AVG:
- Contract performance (Art. 6(1)(b) AVG): to manage workshop bookings, course registrations and open studio memberships
- Legitimate interest (Art. 6(1)(f) AVG): to respond to enquiries, improve our services and maintain studio safety
- Consent (Art. 6(1)(a) AVG): for analytics cookies and optional marketing communications
- Legal obligation (Art. 6(1)(c) AVG): to comply with tax and accounting requirements under Dutch law
4. Retention Periods
We retain personal data only as long as necessary:
- Contact form submissions: up to 12 months after resolution
- Booking and payment records: 7 years (statutory tax retention under Dutch law)
- Analytics data: up to 26 months (with consent only)
- Cookie consent records: up to 12 months
5. Sharing with Third Parties
We do not sell your personal data. We may share data with:
- Payment processors for transaction handling
- Email service providers for communication
- Analytics providers (only with your explicit consent)
- Authorities when required by Dutch law
All processors are bound by data processing agreements compliant with the AVG.
6. International Transfers
Where data is transferred outside the European Economic Area, we ensure appropriate safeguards such as Standard Contractual Clauses approved by the European Commission.
7. Your Rights
Under the AVG, you have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion where legally permitted
- Restriction — limit processing in certain circumstances
- Data portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
- Withdraw consent — withdraw consent at any time for consent-based processing
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
8. Complaints
If you believe we have not handled your data correctly, you may lodge a complaint with the Autoriteit Persoonsgegevens (AP), the Dutch data protection authority, at autoriteitpersoonsgegevens.nl.
9. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss or alteration. These include encrypted connections (HTTPS), access controls and regular review of our data practices.
10. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be posted on this page with an updated date. We encourage you to review this policy periodically.