Privacy Policy
Last Updated: March 18, 2026
1. Introduction & Controller Identity
This Privacy Policy explains how ClipperCraft Barber Academy ("we", "us", or "our") collects, uses, and protects your personal data when you visit this website and when you contact us about barber courses delivered in the Netherlands. This policy is written to help you understand what information we process, why we process it, and what rights you have under the General Data Protection Regulation (GDPR) and applicable Dutch privacy rules.
Data Controller: CVP Finco I B.V. (operating as ClipperCraft Barber Academy). Registered/office address: Wilhelminakade 300, Kop van Zuid, 3072 AR Rotterdam, Netherlands. Contact email: [email protected]. Contact telephone: +31 10 241 3589.
We do not appoint a dedicated Data Protection Officer (DPO) because we do not conduct large-scale processing of special categories of data. If you have a privacy question, you can reach us using the contact details above and we will respond as described in Section 9.
2. Personal Data We Collect
We collect only the data that is reasonably needed to operate the website, answer enquiries, and improve our content. The categories below describe what we may collect depending on how you interact with the site.
- Identity and contact data: name, email address, and phone number when you choose to provide them via our contact form or when you contact us by email or phone.
- Form content and enquiry details: the content you submit in message fields (for example: your experience level, course interests, scheduling constraints, and the outcome you want from training).
- Technical data: IP address, browser type and version, device type, operating system, language settings, and approximate location derived from IP (city/region level). This is typically collected via server logs and, if enabled by consent, analytics tools.
- Usage data: pages viewed, time spent on pages, referring page, interaction events (such as clicks), and navigation paths. This may be collected through analytics cookies if you consent.
- Cookies and identifiers: first-party cookies required for session continuity and to store your cookie preferences, and (if consent is given) third-party cookie identifiers used for analytics and marketing attribution.
- Conversion events: signals that a visitor performed an action such as submitting a form. These events may be measured on-site and, if marketing consent is provided, may be shared in aggregated/attributed form with advertising platforms.
We do not intentionally collect special-category data (such as health information, political opinions, religious beliefs), financial account details, or government-issued identification numbers through this website. Please avoid sending such data in free-text form fields.
3. Why We Process Personal Data & Legal Basis (GDPR Art. 6)
We process personal data only where we have a lawful basis. The table below describes the main purposes and the GDPR legal basis we rely on.
- Responding to contact requests and providing course recommendations: We use your contact details and message content to reply and to recommend a suitable course track. Legal basis: GDPR Art. 6(1)(b) (steps prior to entering into a contract) and, where required by the form design, Art. 6(1)(a) (consent).
- Operating and securing the website: We process technical data and server logs to keep the site stable, prevent abuse, and detect suspicious activity. Legal basis: GDPR Art. 6(1)(f) (legitimate interests in security and fraud prevention).
- Analytics and performance measurement (if enabled): We use analytics tools to understand how visitors use the website and to improve content and page performance. Legal basis: GDPR Art. 6(1)(a) (consent).
- Marketing, remarketing, and audience measurement (if enabled): We may use marketing cookies/pixels to measure ad performance and build audiences for relevant advertising. Legal basis: GDPR Art. 6(1)(a) (consent).
- Legal compliance: We may process limited data to meet legal obligations (for example, responding to lawful requests or retaining invoice-related information where applicable). Legal basis: GDPR Art. 6(1)(c) (legal obligation).
Automated decision-making: We do not engage in automated decision-making or profiling that produces legal or similarly significant effects within the meaning of GDPR Art. 22.
4. Cookies & Tracking
Cookies are small text files stored on your device. We also use similar technologies (such as pixel tags) where permitted. Our cookie categories align with our Cookie Policy at /cookie-policy/.
Essential cookies (always active)
Essential cookies are required for the site to function and to remember your cookie choices. These cookies do not require consent. Examples include:
- _site_session (first-party): helps maintain basic session continuity. Retention: session.
- cookie_consent (first-party): stores your consent preferences. Retention: 12 months.
- CSRF / security cookies (first-party): used to protect forms and site integrity where applicable. Retention: session to short-lived persistent.
Analytics cookies (consent required)
If you consent to analytics cookies, we may use Google Analytics 4 (GA4) with IP anonymization features. These cookies help us understand site usage and improve content. Common GA4 cookies include:
- _ga: GA4 user identifier. Typical retention: 2 years.
- _ga_XXXXXXXXXX: GA4 session state cookie (GA4 property-specific identifier). Typical retention: 2 years.
Analytics data retention in GA4 is typically configured for 14 months, after which it is deleted or aggregated.
Marketing cookies (consent required)
If you consent to marketing cookies, we may use technologies such as Google Ads conversion linking and Meta Pixel measurement to understand advertising performance and to create remarketing or lookalike audiences. These cookies may include:
- _gcl_au (Google Ads): conversion linker. Typical retention: 90 days.
- _fbp (Meta): browser identifier. Typical retention: 90 days.
- _fbc (Meta): click identifier (when a click ID is present). Typical retention: 90 days.
Beyond cookies, marketing measurement may include pixel tags (for example via gtag.js or Meta Pixel) or server-side measurement (for example Meta Conversion API or server-side tag management). Where server-side measurement is used, identifiers may be hashed before transmission, and activation depends on your marketing consent choice.
5. Consent (EEA/UK)
Users in the EEA and UK receive a consent notice under GDPR/UK GDPR. Analytics and marketing cookies activate only after explicit, informed, freely given consent (GDPR Art. 6(1)(a)). Your consent choice is recorded in the cookie_consent browser cookie and kept for 12 months unless you change it earlier.
You can withdraw consent at any time via âManage cookie preferencesâ in the footer of the website or by clearing cookies in your browser settings. Withdrawal does not affect the lawfulness of processing that took place before you withdrew consent.
6. Sharing With Advertising & Service Partners
We share personal data only when needed to operate the website, deliver requested communications, or measure and improve our marketing (where consent is provided). Depending on your cookie preferences and how you contact us, recipients may include:
- Google LLC (Google Analytics 4, Google Ads, tag management and remarketing): cookie identifiers, usage data, conversions, and remarketing list membership when enabled by consent. Privacy information: https://policies.google.com/privacy.
- Meta Platforms, Inc. (Meta Pixel, Custom/Lookalike Audiences, Conversion API where enabled): page view and conversion events, cookie identifiers, and potentially hashed identifiers when enabled by consent. Privacy information: https://www.facebook.com/privacy/policy.
- Cloudflare, Inc. (CDN and security): IP-based threat detection and site delivery security. Privacy information: https://www.cloudflare.com/privacypolicy/.
We do not sell personal data. Where we use service providers, they process data on our instructions as processors/service providers. These providers may not use site data for their own independent commercial purposes.
7. International Transfers
Some of our service partners (for example Google and Meta) may process data outside the European Economic Area (EEA) and the United Kingdom, including in the United States. When transfers occur, we rely on appropriate safeguards, such as:
- EUâUS Data Privacy Framework (DPF) (primary mechanism where applicable, available since July 2023), including the UK Extension and SwissâUS DPF where relevant.
- Standard Contractual Clauses (EU 2021/914) as a fallback mechanism.
- UK International Data Transfer Agreement (IDTA) as a fallback mechanism for UK transfers where applicable.
We take reasonable steps to ensure that transferred personal data is protected in line with GDPR requirements.
8. Retention
We retain personal data only as long as needed for the purposes described in this policy, unless a longer retention period is required by law. Typical retention periods are:
- Contact submissions: up to 2 years from the last interaction, so we can follow up on training enquiries and provide continuity if you return later.
- Email correspondence: for the duration of the relationship plus 1 year, unless longer retention is required for legal reasons.
- Server logs: typically up to 90 days for security and troubleshooting.
- Analytics data: generally 14 months in analytics tools (where enabled by consent), then deleted or aggregated.
- Marketing cookies: retained for the cookie lifetime (for example 90 days for certain marketing cookies) unless you withdraw consent earlier.
- Cookie consent record: up to 3 years for audit and compliance purposes.
- Legal and tax records (where applicable): retained as required by Dutch and EU law, commonly 6â10 years for invoices and accounting records.
9. Your Rights (GDPR & UK GDPR)
If GDPR applies to your data, you have the right to request access to your personal data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and to object to processing (Art. 21). Where processing is based on consent, you can withdraw consent at any time (Art. 7(3)).
To exercise your rights, email [email protected]. We may ask for additional information to verify your identity and to clarify your request. We generally respond within 30 days; for complex requests, this may be extended by up to 60 days as permitted by GDPR.
You also have the right to lodge a complaint with a supervisory authority. In the Netherlands, the competent authority is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority): https://autoriteitpersoonsgegevens.nl. For EU guidance on supervisory authorities, see: https://edpb.europa.eu.
10. Children
This site is not directed at individuals under 16. We do not knowingly collect personal data from minors. If you believe a child under 16 has provided personal data without verifiable parental consent, please contact us and we will take steps to delete the information promptly.
11. Do Not Track
This website does not respond to âDo Not Trackâ (DNT) browser signals. Third-party providers may have their own approaches to DNT signals and similar controls.
12. Data Deletion Requests
To request deletion of personal data, email us at [email protected] with the subject line âData Deletion Requestâ. We will confirm receipt, verify your identity as appropriate, and complete deletion within 30 days when possible. We may retain limited information where required by law or where necessary to establish, exercise, or defend legal claims.
13. Business Transfers
If CVP Finco I B.V. is involved in a merger, acquisition, asset sale, financing, reorganization, insolvency, or similar event, personal data may be transferred to a successor or affiliated entity as part of that transaction. If such a transfer materially changes how personal data is used, we will provide notice on the website.
14. California (CCPA / CPRA)
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (as amended by the CPRA). Over the past 12 months, we may have collected the following categories of personal information: identifiers (such as name, email, IP address, online identifiers), internet/network activity information (such as browsing interactions on our website), and inferences about preferences (for example, interest in certain course areas) derived from website interactions.
We do not sell personal information as defined by CCPA. We may share personal information for cross-context behavioral advertising if you enable marketing cookies. California residents may opt out of sharing for targeted advertising by using our cookie preferences panel (Manage cookie preferences in the footer) and disabling marketing cookies.
California rights may include: the right to know, delete, correct, and the right to opt out of sale/sharing, as well as the right to non-discrimination. To submit a request, email [email protected] with the subject âCalifornia Privacy Requestâ. We will verify your request as required. Authorized agents may submit requests with written permission and identity verification.
15. Virginia (VCDPA)
If you are a Virginia resident, you may have rights to access, correct, delete, and obtain a copy of personal data, and to opt out of targeted advertising. We do not sell personal data and we do not engage in profiling that produces legal or similarly significant effects. To submit a request, email [email protected] with the subject âVirginia Privacy Requestâ.
If we decline your request, you may appeal by emailing us with the subject âAppeal of Refusal â Privacy Requestâ. We will respond to appeals within 60 days. If the appeal is denied, you may contact the Virginia Attorney General.
16. Nevada
Nevada residents may submit a verified opt-out request by emailing [email protected] with the subject âNevada Do Not Sell Requestâ. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.
17. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, technologies, or legal requirements. If we make material changes, we will provide a notice on the homepage at least 14 days before changes take effect where feasible. The âLast Updatedâ date at the top of this policy indicates when it was last revised.
18. Contact
If you have questions about privacy or this policy, contact:
- Legal entity: CVP Finco I B.V.
- Brand: ClipperCraft Barber Academy
- Address: Wilhelminakade 300, Kop van Zuid, 3072 AR Rotterdam, Netherlands
- Email: [email protected]
- Phone: +31 10 241 3589