Skip to content
AI Business Academy

Privacy Policy

AI Business Academy attaches great importance to the careful processing of personal data. This policy explains which data we process, on what basis, how long we retain it and which rights you have as a data subject. The Dutch-language version of this policy is the binding legal text.

Last updated: 12 June 2026

This is the English version of our privacy policy, provided for the convenience of English-speaking visitors. The Dutch version is the legally binding text.

01Data controller

AI Business Academy, based at the A20 Trade Center in Nieuwerkerk aan den IJssel, registered with the Dutch Chamber of Commerce under number 87755106, VAT number NL004471708B98, is the data controller within the meaning of the General Data Protection Regulation (GDPR). For questions about this policy or about data processing you may contact us at info@ai-businessacademy.nl or by phone on +31 10 322 0009.

02Data we process

Depending on how you interact with AI Business Academy we process:

  • Identification data: name, job title, organisation, business email address and phone number.
  • Programme-related data: discipline, organisation size, desired programme, answers submitted in the AI Practice Scan.
  • Contractual data: participation agreement, invoicing details, payments.
  • Communication: email correspondence, notes of conversations, work material submitted within the Cohort Programme.
  • Technical data: IP address (hashed), browser and device type, anonymised usage statistics.

03Purposes and legal bases

We process personal data exclusively for the following purposes:

  • Performance of the agreement (Article 6(1)(b) GDPR): enrolment, admission, delivery and invoicing of programme participation.
  • Legal obligation (point (c)): fiscal retention obligations and sector obligations under, among others, HACCP, FSSC 22000, BRC, IFS, GMP+ and GlobalG.A.P., where applicable.
  • Legitimate interest (point (f)): quality assurance, security of our systems, prevention of fraud and misuse, improvement of the curriculum.
  • Consent (point (a)): sending substantive updates to people who have signed up for the reading list. Consent can be withdrawn at any time.

04Retention periods

We apply the following principles:

  • Practice Scan answers are retained for as long as necessary for follow-up, with a maximum of twelve months.
  • Contractual and invoicing data are retained for seven years in accordance with the fiscal retention obligation.
  • Work material within the Cohort Programme is deleted within six months after the end of the programme term, unless you expressly request longer retention for your own records.
  • Communication is deleted after three years, unless longer retention is reasonably necessary for an ongoing mandate.
  • Technical data and server logs are pseudonymised within thirty days and thereafter retained in aggregated form.

05Recipients and processors

We share personal data exclusively with parties that act as processors on our behalf, and only to the extent necessary for the purpose. A data processing agreement compliant with Article 28 GDPR has been concluded with every processor.

At the time of publication these include:

  • Hosting provider within the European Union (Vercel, Frankfurt region).
  • Email service provider for transactional messages and correspondence (Resend, EU region).
  • Accounting and invoicing software.
  • Product analytics provider (PostHog EU), exclusively for anonymised usage insights.
  • Provider(s) of AI services used strictly for the operation of the internal tools, with explicit safeguards against the use of input for model training.

06Transfers outside the EEA

Our infrastructure is hosted within the European Economic Area. If a transfer to a processor outside the EEA becomes necessary, it takes place exclusively on the basis of a valid adequacy decision of the European Commission or Standard Contractual Clauses supplemented with additional safeguards.

07Security

We apply appropriate technical and organisational measures to protect your data, including encryption of data at rest and in transit, an append-only audit log, role-based access at row level, periodic vulnerability scans, automated backups and a formal procedure for reporting data breaches.

08Your rights

Under the GDPR you have the right to:

  • access your data (Article 15 GDPR);
  • have your data corrected or completed (Article 16);
  • have your data erased (Article 17);
  • restrict the processing (Article 18);
  • have your data transferred (Article 20);
  • object to processing based on legitimate interest (Article 21);
  • withdraw previously given consent at any time.

You can exercise your rights by sending a request to info@ai-businessacademy.nl. We respond within one month. If a request is complex or if there are multiple requests, we may extend this period by two months, stating the reasons.

09Complaint with the supervisory authority

If you believe we are not processing your data carefully, we would like to hear from you. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) via autoriteitpersoonsgegevens.nl.

10Cookies and analytics

The website only places functional cookies that are necessary for the operation of the platform. For product analytics we use PostHog (EU cloud) with the following privacy settings: no autocapture, no session recording, respect for the Do Not Track header, and pseudonymisation of the IP address, which is truncated for geographic analysis.

11Changes

We reserve the right to amend this privacy policy. Changes are published on this page. In the event of material changes, active participants are informed by email.