Privacy Policy — Hartings Coaching
Last updated: 26 September 2026
This privacy policy explains which personal data I use about you, why I do so and what rights you have. "I" or "me" means Hartings Coaching. "You" means anyone who books a session, contacts me or visits my website.
1. Who is responsible for your data?
Hartings Coaching is responsible (the "controller") for the use of your personal data.
Hartings Coaching, sole proprietorship (eenmanszaak)
Address: Baroniestraat 28, 4876 VS Etten-Leur, the Netherlands
Email: contact@robinhartings.com
Website: robinhartings.com
Chamber of Commerce (KvK) number: registration in progress (expected October 2026)
Do you have a question about your data or about this policy? Send an email to contact@robinhartings.com.
I do not have a data protection officer. This is not required for my practice. You can come to me with all your questions.
2. Which data do I use, for what purpose and on what legal basis?
I only use the data I really need. For each part below, you can read which data it is, what I use it for and on what legal basis (under the General Data Protection Regulation, the GDPR).
2.1 Booking and scheduling sessions
Data: name, email address, phone number (if you give it to me), chosen date and time, whether the session is at the practice or online, and any comments you give me when booking.
Purpose: to make, confirm, reschedule or cancel your appointment, and to hold the session (including online via Google Meet).
Legal basis: this is necessary to perform our agreement (Article 6(1)(b) GDPR).
2.2 Contact with you
Data: name, email address, phone number (if you give it to me) and the content of your messages.
Purpose: to answer your questions and to stay in touch with you about your appointments.
Legal basis: if your question is about a (possible) booking, this is necessary for the agreement or to prepare it (Article 6(1)(b) GDPR). If it is about another question, I use your data because I have an interest in answering your question (legitimate interest, Article 6(1)(f) GDPR).
Please do not send me sensitive information by email, for example about your health. We would rather discuss that during a session.
2.3 Payment, invoices and records
Data: name, email address, your address (if it needs to be on the invoice), what you bought, amount, date, payment status and payment reference. If you pay online, the payment provider also processes the data needed for the payment. I do not see your full card number myself.
Purpose: to receive your payment, to refund money if necessary, and to keep my accounts.
Legal basis: for the payment: performance of the agreement (Article 6(1)(b) GDPR). For keeping my records: a legal obligation (Article 6(1)(c) GDPR), because Dutch tax law requires me to keep my records for 7 years.
2.4 What you tell me during sessions
During our conversations, information may come up that the law gives extra protection. For example, about your religion or beliefs, or about your physical or mental health. This is called special category personal data.
I do not record sessions, not even online.
I prefer not to take notes about what you tell me. What you tell me stays in the conversation.
Would you like me to take brief notes, for example so we can pick up where we left off in the next session? I will only do so if you give your explicit consent. I ask for that consent separately, on paper or by email, before I write anything down.
If you do not give consent, you can still have sessions with me. Consent is not a condition for my service.
You can withdraw your consent at any time, just as easily as you gave it. Send an email to contact@robinhartings.com or tell me during a session. I will then destroy the notes as soon as possible. What I did with the notes before you withdrew your consent remains lawful.
Legal basis for notes: your consent (Article 6(1)(a) GDPR) and, for special category personal data, your explicit consent (Article 9(2)(a) GDPR).
My notes are brief and factual. I keep them separately and securely. I do not share them with anyone.
2.5 If a dispute arises
Data: the data needed to handle a complaint or dispute, such as booking and payment details and our correspondence.
Purpose: to handle a complaint properly and to be able to defend myself if a legal dispute arises.
Legal basis: my legitimate interest in handling a complaint or dispute (Article 6(1)(f) GDPR). If special category personal data are needed for this, the legal basis is that this is necessary for a legal claim (Article 9(2)(f) GDPR).
2.6 Website
Data: technical data that the server automatically records when you visit the website (server logs), such as your IP address, the time of your visit, the pages you request and your browser type.
Purpose: to keep the website working properly and securely, and to detect faults and misuse.
Legal basis: my legitimate interest in a properly working and secure website (Article 6(1)(f) GDPR).
2.7 Content from other parties on my website
Data: your IP address and technical data from your browser (such as browser type and the page you are on).
Purpose: to show a map of my practice on the contact page (Google Maps) and photos and a video on my website (Pexels and Unsplash). Your browser loads this content directly from these parties. As a result, they receive your IP address.
Legal basis: my legitimate interest in showing where my practice is and in a clear, attractive website (Article 6(1)(f) GDPR).
Who is responsible: for loading this content and passing on your IP address to these parties, I may be jointly responsible with them. What these parties do with your data afterwards is their own responsibility. You can exercise your rights against me or against them.
2.8 Free introductory call
Data: name, email address, chosen date and time, the Google Meet link for the call, and — only if you choose to answer — your answer to "How did you find me?".
Purpose: to plan and hold a free 15-minute introductory call, so that you can decide whether you want to book a session.
Legal basis: this is necessary to take steps at your request before a possible agreement (Article 6(1)(b) GDPR). For the optional question "How did you find me?": my legitimate interest in knowing how people find my practice (Article 6(1)(f) GDPR). You do not have to answer this question.
I use Hostinger Appointments for this booking. The "Book a session" and "Free 15-minute intro call" buttons on my website both lead to this booking. The appointment is also added to my Google Calendar, and the call takes place via Google Meet.
3. Do you have to give me your data?
For a booking, I need your name and email address. If you do not provide them, I cannot make an appointment with you. For payment, the data requested by the payment provider is required. You do not have to give consent for notes (see 2.4).
For the free introductory call, I need your name and email address. Answering the question "How did you find me?" is optional.
4. Who do I share your data with?
I never sell your data. I only share it with parties I need for my work, or if the law requires me to.
PartyWhat does this party do for me?GoogleCalendar (Google Calendar), email, online sessions and introductory calls (Google Meet) and storage of my records (Google Drive and Google Sheets).Google (Google Maps)Shows the map on my contact page. See 2.7.HostingerHosting of my website (including server logs), the booking tool for the free introductory call (Hostinger Appointments) and email for contact@robinhartings.com.CloudflareNetwork provider used by Hostinger to deliver and protect my website. It processes your IP address for this.Pexels and UnsplashProvide photos and a video shown on my website. See 2.7.The payment provider I use for payment links (named in my offer)Processing online payments. My accountantHelp with my accounts and tax returns. Tax and Customs Administration (Belastingdienst) and other government authoritiesOnly if the law requires me to provide data.
Parties that process data on my behalf only process it for the purposes described in this privacy policy, under the terms of that provider.
I do not share notes from sessions (see 2.4) with anyone.
5. Is your data transferred to countries outside Europe?
Some parties I use, such as Google, may also process data outside the European Economic Area (EEA), for example in the United States.
This is only allowed if your data is properly protected there. This may be the case, for example:
on the basis of a decision by the European Commission that the country offers an adequate level of protection. For the United States, such a decision applies to companies that participate in the EU-U.S. Data Privacy Framework; or
on the basis of standard contractual clauses adopted by the European Commission.
You can ask me for more information about the safeguards that apply per party, or for a copy of these arrangements.
6. How long do I keep your data?
I do not keep your data longer than necessary.
DataHow longInvoices, payment details and other records7 years (statutory retention obligation)Booking and calendar data2 years after your last sessionIntroductory call (if you do not book a session afterwards)3 months after the call. Your answer to "How did you find me?" is then only kept as an anonymous count.Emails and other messages2 years after our last contact, unless they form part of my records (then 7 years)Notes from sessions (only with your consent)3 months after your last session, or earlier if you withdraw your consentProof of your consent to notes2 years after your last sessionData relating to a complaint or disputeuntil the complaint or dispute has been resolved, plus 1 yearWebsite server logsas long as my hosting provider keeps them; I do not keep these logs myself
After these periods, I delete the data or make it anonymous.
7. How do I protect your data?
I take appropriate measures to protect your data against loss, theft and unauthorised use. For example:
my accounts are protected with a strong password and two-step verification;
my computer and phone are protected with a password or code;
only I have access to your data;
I keep notes (if you consented to them) separately and protected;
I do not record sessions.
No security is perfect. If something does go wrong with your data (a data breach) and it poses a risk to you, I will act as the law requires. If the risk is high, I will let you know as soon as possible.
8. What are your rights?
You have the following rights:
Access: you may know which data I hold about you and receive a copy.
Rectification: if your data is incorrect, you may ask me to correct or complete it.
Erasure: you may ask me to delete your data. Sometimes I am not allowed to, for example if the law requires me to keep it.
Restriction: you may ask me to temporarily restrict the use of your data.
Objection: if I use your data on the basis of my legitimate interest, you may object to this.
Portability: you may ask to receive data that you gave me yourself in a commonly used digital file, or to have it sent to someone else.
Withdrawing consent: if you have given consent, you may withdraw it at any time.
Would you like to exercise one of these rights? Send an email to contact@robinhartings.com. I will respond within one month. Sometimes I need more time; if so, I will let you know within one month. It costs you nothing. If I am unsure whether the request really comes from you, I may ask you to show who you are.
9. Making a complaint
Are you not satisfied with how I handle your data? Please let me know first via contact@robinhartings.com. We will then look for a solution together.
You may also always lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, www.autoriteitpersoonsgegevens.nl). Do you live or work in another country of the European Union? Then you may also lodge a complaint with the data protection authority in that country.
10. Automated decisions
I do not make decisions about you that are taken solely by a computer. I also do not create profiles of you.
11. Cookies
My website itself does not set any cookies and does not store anything on your device. I do not use analytics, advertising or tracking cookies, and no tracking pixels. That is why there is no cookie banner. Some other parties are involved when you use the website:
Security cookie from my hosting provider's network. My hosting provider's network (CDN) uses Cloudflare to protect its service against bots and misuse. As a result, the Cloudflare security cookie __cf_bm (valid for a maximum of 30 minutes) may be placed on your device. This cookie is needed only for security. I do not ask for your consent for it.
Cookies from the video provider. The video on my home page is loaded from Pexels (see 2.7). Pexels uses Cloudflare to protect its service against bots and misuse. As a result, when you open the home page, the Cloudflare cookies __cf_bm (valid for a maximum of 30 minutes) and _cfuvid (valid for the browser session) may be placed on your device. These cookies are placed by Pexels, not by my website.
Google Maps on the contact page. The contact page contains an embedded Google Maps map. When you open that page, your browser loads the map directly from Google, and your IP address is sent to Google. See 2.7.
12. Changes
I may update this privacy policy, for example if my way of working or the law changes. The latest version is always available on my website. If there are major changes and you are a client of mine, I will let you know.
This version is dated 26 September 2026.
contact@robinhartings.com
© 2026. All rights reserved.
Hartings Coaching · Baroniestraat 28, 4876 VS Etten-Leur · contact@robinhartings.com · KvK: registration in progress