Home / Privacy Policy
Privacy Policy
Last Updated: March 12, 2026
1. Introduction & Controller Identity
This Privacy Policy explains how Canal Vertex Guitar Studio (“we”, “us”, “our”) collects, uses, and protects personal data when you visit our website, contact us, or request guitar lessons in Zwolle and across the Netherlands. We provide modern guitar instruction and related scheduling and support services. This document is written to be readable and practical, while reflecting our obligations under the General Data Protection Regulation (GDPR) and Dutch privacy rules.
Data Controller (responsible party under GDPR): CVP Beheer B.V., operating as Canal Vertex Guitar Studio.
Registered address: Hoogstraat 91, 8011 AV Zwolle, Netherlands. Email: [email protected]. Phone: +31 38 202 3187.
We do not currently appoint a Data Protection Officer (DPO), because we do not conduct large-scale systematic monitoring and we do not process special-category data at scale. If your request suggests we should treat certain information as sensitive, we will ask you not to include it in the form and we will handle the message carefully.
2. Personal Data We Collect
We collect only the data needed to respond to lesson enquiries, schedule sessions, operate the website safely, and improve our content. Depending on how you interact with the site, we may collect the following categories of personal data:
- Identity and contact data: name, email address, phone number (if you provide it), and preferred contact method.
- Form content: the message you write, lesson focus selection, availability notes, and any other information you choose to submit.
- Technical data: IP address, browser type and version, device type, operating system, language settings, and approximate location inferred from IP (country/city level).
- Usage data: pages visited, time on page, referrer, click paths, and interaction events (for example, whether a page was scrolled or a button was clicked), when you consent to analytics cookies.
- Cookies and identifiers: cookie IDs and consent signals stored in your browser (details in Section 4).
- Conversion events: when you consent to marketing cookies, we may record non-sensitive events like “form submitted” or “page viewed” to measure advertising performance.
We do not intentionally collect special-category data (such as health information, religious beliefs, political opinions), financial account details, or government identification numbers through our website. Please do not include such data in your message. If you send it anyway, we will limit access and handle it only to the extent necessary to respond to you.
3. Why We Process Your Data & Legal Basis (GDPR Article 6)
Under GDPR, we must have a valid legal basis to process personal data. We rely on the following bases depending on the activity:
3.1 Contact and lesson scheduling
When you contact us through a form, by email, or by phone, we process your details to respond and (if requested) schedule lessons in Zwolle or online within the Netherlands. Legal basis: GDPR Art. 6(1)(b) (steps at your request prior to entering into a contract) and, where applicable, GDPR Art. 6(1)(a) (consent) when you explicitly ask us to contact you.
3.2 Analytics and site improvement
If you consent to analytics cookies, we process usage data to understand which pages are helpful and where visitors get stuck. This helps us improve lesson information, scheduling clarity, and the general experience for visitors across the Netherlands. Legal basis: GDPR Art. 6(1)(a) (consent).
3.3 Marketing measurement and remarketing
If you consent to marketing cookies, we may process identifiers and event data to measure ads, attribute conversions, and build remarketing or lookalike audiences. Legal basis: GDPR Art. 6(1)(a) (consent).
3.4 Security, fraud prevention, and service reliability
We process certain technical data (such as IP address and server logs) to maintain security, prevent abuse (including automated spam submissions), and keep the site reliable. Legal basis: GDPR Art. 6(1)(f) (legitimate interests). Our legitimate interest is to protect the website, our business operations in the Netherlands, and visitors from malicious traffic.
3.5 Legal obligations
If we must comply with a legal obligation (for example, tax or accounting requirements related to invoicing, or responding to lawful requests), we may process relevant personal data. Legal basis: GDPR Art. 6(1)(c) (legal obligation).
3.6 Automated decision-making (GDPR Article 22)
We do not engage in automated decision-making or profiling that produces legal or similarly significant effects for you. Any scheduling decisions or lesson recommendations are made by humans based on the information you provide.
4. Cookies & Tracking
We use cookies and similar technologies to run the site, remember your consent choices, and (only if you consent) measure usage and advertising performance. Cookies are small text files stored by your browser. We also reference pixel tags and server-side conversion events; these are controlled through the same consent categories.
4.1 Essential cookies (always active)
Essential cookies are required for basic functionality and security. They do not require consent under EU ePrivacy rules when limited to what is strictly necessary for the service you request. Examples include:
- _site_session: keeps session continuity and basic site operations stable (session retention).
- cookie_consent: stores your cookie preferences (up to 12 months).
- CSRF-related tokens: help protect forms and requests against abuse (session to short-term retention).
4.2 Analytics cookies (consent required)
Analytics cookies help us understand how the site is used. If enabled, we may use Google Analytics 4 (GA4) with IP anonymization features to reduce identifiability. We use aggregated reports to improve pages like lesson descriptions, pricing clarity, and contact flow for visitors in the Netherlands.
Example cookies: _ga (2 years), _ga_XXXXXXXXXX (2 years). Analytics data retention is typically configured for 14 months.
4.3 Marketing cookies (consent required)
Marketing cookies support advertising measurement, conversion attribution, and remarketing. If enabled, identifiers such as _gcl_au (Google Ads, 90 days), _fbp (Meta, 90 days), and _fbc (Meta, 90 days, when click ID is present) may be used.
Beyond cookies, marketing measurement may involve pixel tags (such as Google Ads or Meta Pixel) and, if configured, server-side events (for example via Meta Conversion API or server-side tag management). When used, these are enabled only after consent and may include hashed identifiers (like email) solely for matching and attribution.
For details about cookie categories and management, see our Cookie Policy.
5. Consent (EEA / UK)
Users in the EEA and UK receive a consent notice under GDPR/UK GDPR. Analytics and marketing cookies activate only after explicit, informed, freely given consent (GDPR Art. 6(1)(a)). Your consent choice is recorded in the cookie_consent browser cookie (stored for 12 months).
You may withdraw consent at any time by using “Manage cookie preferences” in the footer or by clearing cookies in your browser. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
6. Sharing With Advertising & Service Partners
We use trusted service providers to run the website and, if you consent, measure or improve marketing. We share data only as needed for the relevant purpose, and we do not sell personal data. Depending on your consent choices and how the site is configured, recipients may include:
- Google LLC (Google Analytics 4, Google Ads, Google Tag Manager, remarketing): cookie identifiers, usage events, and conversion events, if enabled by consent. Privacy policy: https://policies.google.com/privacy
- Meta Platforms, Inc. (Meta Pixel, Custom/Lookalike Audiences, Conversion API): page events, conversion events, audience membership signals, and (if enabled) hashed identifiers for matching, based on consent. Privacy policy: https://www.facebook.com/privacy/policy
- Cloudflare (CDN and security): IP and request metadata for threat detection, rate limiting, and performance. Privacy policy: https://www.cloudflare.com/privacypolicy/
We do not permit these providers to use site data for their own independent commercial purposes beyond providing services to us, subject to their roles as processors or service providers and their contractual obligations. Some providers may process data as independent controllers for certain activities (for example, ad platforms), and they provide additional controls in their own settings.
7. International Transfers
We are based in the Netherlands, but some of our service providers may process data outside the EEA/UK, including in the United States. Where international transfers occur, we use appropriate safeguards, such as:
- EU–US Data Privacy Framework (DPF) (primary mechanism, since July 2023) and the UK Extension to the DPF, where applicable.
- Standard Contractual Clauses (SCCs) (EU Commission Decision 2021/914) as a fallback safeguard.
- UK International Data Transfer Addendum (IDTA) as a fallback for UK-related transfers.
We also apply practical measures such as minimizing data shared, limiting retention, and enabling privacy settings where available.
8. Data Retention
We keep personal data only as long as necessary for the purposes described in this Privacy Policy. Typical retention periods are:
- Contact submissions: up to 2 years from the last interaction, to support scheduling, follow-ups, and continuity.
- Email correspondence: duration of the relationship plus 1 year, unless a longer period is needed for legal reasons.
- Analytics data: typically 14 months (when enabled by consent), subject to the analytics configuration.
- Server logs: typically 90 days, unless needed longer for security investigations.
- Cookie consent record: up to 3 years for audit and compliance documentation, where applicable.
- Legal and tax: where we must retain invoices or accounting records, we keep data for the period required by law (commonly 6–10 years).
When retention ends, we delete or anonymize data unless we must keep it for a lawful reason.
9. Your Rights (GDPR & UK GDPR)
If GDPR applies to your data, you may have the following rights, subject to certain conditions and exceptions:
- Right of access (Art. 15): request a copy of your personal data and information about how we process it.
- Right to rectification (Art. 16): correct inaccurate or incomplete data.
- Right to erasure (Art. 17): request deletion of your data in certain situations.
- Right to restriction (Art. 18): limit processing in certain situations.
- Right to data portability (Art. 20): receive data you provided in a structured, commonly used format.
- Right to object (Art. 21): object to processing based on legitimate interests.
- Right to withdraw consent (Art. 7(3)): withdraw consent at any time for processing based on consent.
- Right to lodge a complaint (Art. 77): submit a complaint to a supervisory authority.
To exercise your rights, email us at [email protected]. We respond within 30 days. For complex requests, we may extend the deadline by up to 60 additional days and will inform you of the reason.
Supervisory authorities: In the Netherlands, the competent authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). In the EU generally, you can also consult the European Data Protection Board resources: https://edpb.europa.eu.
10. Children
This website is not directed at individuals under 16. We do not knowingly collect personal data from minors. If we learn that we received personal data from a child under 16 without verifiable parental consent, we will delete it promptly.
11. Do Not Track
This website does not respond to “Do Not Track” (DNT) browser signals. Some third-party providers may have their own DNT handling and opt-out mechanisms. Where required, we rely on the cookie consent tool on this site to control analytics and marketing technologies.
12. Data Deletion Requests
To request deletion of your data, email [email protected] with the subject line “Data Deletion Request”. To protect your data, we may ask for limited verification to ensure the request is legitimate. We aim to complete deletion within 30 days after verification, unless we must retain certain information to comply with a legal obligation or to establish, exercise, or defend legal claims.
13. Business Transfers
If CVP Beheer B.V. is involved in a merger, acquisition, reorganization, asset sale, financing, or insolvency, personal data may be transferred to a successor entity or counterparty as part of that transaction. If the transfer materially changes how personal data is used, we will provide notice on the website.
14. California (CCPA / CPRA)
Although we are based in the Netherlands, visitors may access this site from the United States. This section describes disclosures relevant to the California Consumer Privacy Act (CCPA), as amended by the CPRA, for California residents.
Categories of personal information disclosed in the past 12 months may include: identifiers (such as name, email, IP address, and cookie identifiers), internet or network activity information (such as page interactions), and inferences (such as interest categories used for advertising). We disclose this information to service providers and, if you consent to marketing cookies, to advertising partners for cross-context behavioral advertising.
We do not sell personal information as defined by CCPA. We do share personal information for cross-context behavioral advertising when marketing cookies are enabled. California residents may opt out of sharing for this purpose using our cookie preferences panel (Manage cookie preferences in the footer).
California rights may include the right to know, delete, correct, and opt out of sale/sharing, and the right to non-discrimination. To submit a request, email [email protected] with the subject “California Privacy Request”. We may need to verify your identity. Authorized agents may submit requests with written proof of authorization.
15. Virginia (VCDPA)
If you are a Virginia resident, you may have rights under the Virginia Consumer Data Protection Act (VCDPA), including access, correction, deletion, portability, and the right to opt out of targeted advertising. We do not sell personal data and we do not engage in profiling that produces legal or similarly significant effects.
To submit a request, email [email protected] with the subject “Virginia Privacy Request”. If we decline your request, you may appeal by emailing with the subject “Appeal of Refusal — Privacy Request”. We respond to appeals within 60 days. If the appeal is denied, you may contact the Virginia Attorney General.
16. Nevada
Nevada residents may submit a verified opt-out request by emailing [email protected] with the subject “Nevada Do Not Sell Request”. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the site, our services in the Netherlands, or legal requirements. Material changes will be announced via a notice on the website at least 14 days before taking effect, when feasible. The “Last Updated” date at the top shows when this Policy was last revised.
18. Contact
If you have questions about this Privacy Policy or want to exercise your rights, contact:
CVP Beheer B.V.
Hoogstraat 91
8011 AV Zwolle, Netherlands
Email: [email protected]
Phone: +31 38 202 3187