Privacy policy

Last updated: 3 September 2026

1. Introduction — when this policy applies

This privacy policy describes how we handle the personal data of visitors, members and participants of the Clean Language Nederland platform.

It applies when you:

We work from the assumption that you are the owner of your own data. For every field on your profile you decide for yourself whether it is publicly visible — the default is not public. None of these fields are required, and you can clear them at any time.

2. Who we are

The data controller for the data on this platform is:

Pascal Clarkson, trading as Art o’ Craft Muldersdreef 335 7328 EH Apeldoorn KvK: 08118323

For any questions about your personal data, to exercise your rights (see §8), or for complaints:

Email me at privacy@cleanlanguage.nl

Clean Language Nederland is a community initiative; Art o’ Craft manages the technical infrastructure on behalf of the community and carries the legal responsibility for the data processing on this platform.

3. What personal data we process

We only process the data needed for the platform to function and for the services you actively use. We distinguish the following categories:

Authentication

Via Supabase Auth we process:

So we do not store passwords.

Community profile

When you create a profile on the platform we may store the following data, based on what you choose to enter:

For each item you decide whether it is publicly visible via My profile. The default is not public.

Community role

The role you fulfil in the community: admin, facilitator or participant. This role determines what you can access on the platform. In the community admin overview, admins can see members’ login email addresses so that they can manage accounts correctly (for example making someone an admin).

Admins can also view and change a member’s profile: the profile text, the per-field visibility settings, the profile photo, and whether your participation in an event appears on the participants list. This serves two purposes:

These examples are not exhaustive. An admin can in principle change any profile field that you can change yourself. Two things an admin explicitly cannot do: change your login email address, and change your display email address — how you can be reached remains yours. An admin can change the visibility of your display email address, so that a leaked or misused address can be hidden immediately.

Every change an admin makes to your profile is recorded internally (see Admin change log below). You receive no automatic notification of such a change. For significant changes — removing your profile photo, for instance — we will contact you personally. You can always request which changes were made to your profile via privacy@cleanlanguage.nl.

Admin change log

When an admin changes another member’s profile, we record:

We deliberately do not store what a field contained before or after: only that a field changed, not what it changed to. The log is visible to admins only and is never shown publicly. If you delete your account, the log entries referring to you are deleted with it.

Event participation

Per event you attend: the role you fulfil there (participant, facilitator, trainer, organiser, volunteer, etc.), whether you want to appear publicly in the participants list of that event (checkbox on My profile), and the moment of signing up, cancelling and your attendance. This participation record (including sign-up/cancel moments and attendance) is retained as part of the historical overview of an event, even if you delete your profile; it disappears when you fully delete your account.

To organise and run an event, its facilitators and administrators can view and record your attendance. This access is limited to facilitator of the event and administrators.

Ticket purchases and payments

If you buy a paid ticket through the platform, we keep an order record: your email address, the event, the amount paid, the payment status (paid / (partially) refunded), and a reference to your invoice. Your payment details themselves (card number, iDEAL bank details) are processed exclusively by our payment provider Stripe and never reach our systems. If you opt for a business purchase at checkout, Stripe additionally collects your company name, VAT number, and billing address; these appear on the invoice Stripe issues on our behalf. The order record is part of our bookkeeping (see §5 for the retention period).

Save-the-Date

If you leave your email address via the Save-the-Date form on an event page, we store your email address plus the reference to that specific event so we can let you know when the event opens for registration, or if there is other useful information to share about the event.

Pending invitations

When an admin invites you to an event by email, or when you sign up for an event via Ticket Tailor before you have an account, we temporarily record your email address, the invited role, and the source of the invitation. This data is linked to your profile the first time you log in.

Files

Per category we use the following legal basis under GDPR art. 6:

ProcessingPurposeLegal basis
AuthenticationGranting access to the platformPerformance of the contract
Community profileIntroducing yourself to the communityPerformance / consent
Community roleAccess to admin or facilitator functionsPerformance of the contract
Profile management by adminsSupport at the member’s request; platform securityPerformance of the contract (support) + legitimate interest (security)
Admin change logAccountability for changes an admin makes to another member’s profileLegitimate interest
Event participationTracking who takes part in which eventPerformance of the contract
Ticket purchases and paymentsProcessing your payment, issuing your ticket and invoice, bookkeepingPerformance of the contract + legal obligation (fiscal administration)
Visibility of profile elementsShowing on public pagesConsent
Save-the-DateKeeping you informed about a specific eventConsent
Pending invitationsCompleting the invitation processLegitimate interest
Newsletter / Kit tagsTopical updates per subjectConsent
Abuse prevention (rate limiting on IP address + honeypot)Preventing spam and automated abuse of the websiteLegitimate interest

You can withdraw your consent at any time by changing a setting, deleting your profile, or contacting us at privacy@cleanlanguage.nl.

5. Retention periods

On request (via privacy@cleanlanguage.nl) we delete your data within 30 days, unless a statutory retention obligation prevents this.

6. Sharing with third parties

For the platform to function we work with a number of external service providers under their standard processor terms:

Supabase

Data stays within the European Economic Area; no further transfer outside the EEA.

Resend

Transfer to the United States takes place under the EU-US Data Privacy Framework (DPF) and/or Standard Contractual Clauses (SCCs).

Cloudflare

Transfer to the United States takes place under the EU-US Data Privacy Framework (DPF) and/or Standard Contractual Clauses (SCCs).

Kit (formerly ConvertKit)

Transfer to the United States takes place under the EU-US Data Privacy Framework (DPF) and/or Standard Contractual Clauses (SCCs).

Stripe

Transfers to the United States take place under the EU-US Data Privacy Framework (DPF) and/or Standard Contractual Clauses (SCCs).

Ticket Tailor

Transfer to the United Kingdom falls under the European Commission’s adequacy decision for the UK.

Operational service provider without access to personal data

For periodically triggering internal, automated tasks we use cron-job.org (Germany). This service does not process personal data of platform users — only technical requests to our own platform endpoints.

7. Transfers outside the EEA

Some of the providers listed above are based outside the European Economic Area.

For transfers to the United States (Resend, Cloudflare, Kit, and Stripe insofar as processing is performed by Stripe, Inc.) we rely on:

For transfers to the United Kingdom (Ticket Tailor) we rely on the European Commission’s adequacy decision for the UK.

Supabase and cron-job.org are based within the EEA; no additional safeguards are required there.

8. Your rights as a data subject

Under the GDPR you have the following rights regarding your personal data:

To make a request, send an email to privacy@cleanlanguage.nl. We will respond within one month.

9. Cookies and local storage

The platform does not use tracking or analytics cookies. We categorise the cookies and local storage into three groups:

These items are necessary for the platform to work:

Embedded third parties

At this time we do not use any analytics or marketing services (no Google Analytics, Plausible, or Cloudflare Web Analytics). If that changes in the future, we will update this privacy policy before the change goes live.

10. Security

We have taken the following measures to protect your data:

11. Changes to this policy

We update this privacy policy when our data processing changes — for example when we add a feature that processes new categories of data, or when we add or remove an external service provider.

The date at the top of this page (“Last updated”) indicates when we last amended this policy. Material changes are announced in advance through the community channels (email, Community page).

12. Contact

For all questions, requests or complaints regarding your personal data:

Email: privacy@cleanlanguage.nl

Post: Art o’ Craft Muldersdreef 335 7328 EH Apeldoorn

We typically respond within one working day, and at the latest within one month for formal GDPR requests.