Privacy Policy
Last Updated: March 12, 2026
1 — Introduction and Controller Identity
This Privacy Policy explains how The-Re B.V. (“The-Re”, “we”, “our”, or “us”) collects, uses, discloses, and protects personal data when you visit this website, make an inquiry, or participate in our educational, consulting, and professional development services delivered to clients throughout Canada. We are committed to lawful, fair, and transparent processing and to meeting our obligations under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Dutch Implementation Act (Uitvoeringswet AVG).
Data Controller: The-Re B.V., Ridder Thibaldstraat 19, 6444 ED Brunssum, Netherlands. Contact email: [email protected]. For the purposes described in this Policy, The-Re B.V. determines the purposes and means of processing personal data. We operate online programs and remote consultations that serve Canadian clients from our base in the Netherlands.
Scope: This Policy applies to personal data processed when you browse our website, submit a form, correspond with us, or engage with our services. It supplements any program-specific notices you may receive at enrollment or contract signature.
2 — Personal Data We Collect
We collect only the data that is necessary for the purposes outlined below. The categories include:
- Identity and contact details: name, email address, phone number, organization, role, and province/territory where relevant.
- Inquiry and enrollment information: your message, service or course selection, objectives, timelines, preferences, and any details you choose to provide in free-text fields.
- Technical data: IP address, device and browser type, operating system, language settings, approximate location inferred from IP, and timestamped server logs for security and reliability.
- Usage data: pages visited, time on page, navigation paths, clicks, referring pages, and interactions with on-page components (e.g., opening an FAQ item).
- Cookies and identifiers: essential session cookies, your consent choices, and—subject to consent—analytics and marketing identifiers as described in Section 4.
- Conversion and delivery data: program enrollment confirmations, attendance records (for virtual sessions), assignment submissions, and completion status where applicable.
We do not intentionally collect special categories of personal data (such as data concerning health, political opinions, religious beliefs, or union membership), government ID numbers, or payment card details via this website. If a lawful business need arises later (for example, invoicing data required by law), we will provide an appropriate notice at the time of collection.
3 — Purposes and Legal Bases (GDPR Article 6)
- Responding to inquiries and providing proposals: processing is necessary to take steps at your request prior to entering into a contract (Art. 6(1)(b)) and, where forms include a consent box, on the basis of your consent (Art. 6(1)(a)).
- Delivering educational and consulting services, administering attendance, assignments, and completion: performance of a contract (Art. 6(1)(b)).
- Analytics to improve performance and content quality: consent (Art. 6(1)(a)).
- Marketing, remarketing, and measurement: consent (Art. 6(1)(a)).
- Security, abuse prevention, and service reliability (e.g., rate limiting, log retention, fraud detection): our legitimate interests in keeping services secure and reliable (Art. 6(1)(f)).
- Legal compliance (e.g., tax and accounting records): legal obligation (Art. 6(1)(c)).
Automated decision-making: We do not perform automated decision-making or profiling that produces legal or similarly significant effects within the meaning of GDPR Article 22.
4 — Cookies and Tracking Technologies
We use cookies and similar technologies to operate this site, understand performance, and—only if you consent—support advertising and measurement. Cookie categories are:
- Essential (no consent required): _site_session (session continuity), cookie_consent (your choices), anti-CSRF tokens, and basic infrastructure cookies. Retention: session to 12 months.
- Analytics (consent): Google Analytics 4 with IP anonymization. Examples: _ga (2 years), _ga_XXXXXXXXXX (2 years). Aggregated usage statistics help us refine program information architecture and page performance.
- Marketing (consent): identifiers used for advertising, remarketing, and conversion measurement such as _gcl_au (90 days), _fbp (90 days), and _fbc (90 days when a click ID is present).
Beyond cookies, marketing and analytics ecosystems may use pixel tags and server-side signals (for example, hashed identifiers). We activate analytics and marketing categories only after you provide explicit consent via our cookie banner or preferences panel. You can review or change your choices at any time via the “Manage cookie preferences” link in the footer. For further detail about specific cookies, see our Cookie Policy.
5 — Consent Management (EEA and UK)
Users in the European Economic Area and the United Kingdom receive a consent notice that allows enabling or disabling analytics and marketing categories. Consent is specific, informed, and freely given (GDPR Art. 6(1)(a)). Your preferences are stored in the cookie_consent cookie for up to 12 months. You may withdraw consent at any time by opening the banner from the footer link or by clearing cookies in your browser. Withdrawal will not affect the lawfulness of processing based on consent before its withdrawal.
6 — Sharing with Service and Advertising Partners
We do not sell personal data. We share limited data with service providers strictly for our purposes and under appropriate contractual safeguards. Typical partners and purposes include:
- Cloud hosting, content delivery, and security providers (e.g., CDN and firewall) to ensure availability and protect against attacks.
- Analytics provider (e.g., Google Analytics 4) for site usage metrics and performance insights—active only after consent.
- Advertising and measurement partners (e.g., Google Ads and Meta) for remarketing, conversion tracking, and audience analytics—active only after consent.
- Video, conferencing, or e-learning tools used to deliver virtual sessions, with only the data necessary to operate the sessions.
- Professional advisors (legal, accounting) and public authorities where required by law.
These providers act as processors or independent controllers depending on the service. Contracts restrict their use of data and require security measures proportionate to the risks involved.
7 — International Data Transfers
Some partners are located outside the EEA, including in the United States. Where transfers occur, we rely on appropriate safeguards such as the EU–US Data Privacy Framework (and the UK Extension or Swiss–US frameworks where applicable). If a provider is not certified, we use the European Commission’s Standard Contractual Clauses (EU 2021/914) and, if needed, the UK International Data Transfer Addendum, along with supplementary technical and organizational measures.
8 — Retention Periods
- Inquiry and correspondence records: up to 2 years from the last meaningful interaction.
- Contract and service delivery records (including attendance and completion data): for the term of the engagement plus the applicable statutory limitation period.
- Analytics data: typically 14 months (as configured with the analytics provider).
- Marketing identifiers: per cookie lifetime or until you withdraw consent.
- Server logs: generally up to 90 days, unless investigation or legal needs require a longer period.
- Cookie consent records: up to 3 years for audit purposes.
- Invoices and tax documents: per Dutch legal requirements (commonly 7–10 years).
9 — Your Rights under GDPR
Subject to conditions and exemptions in the GDPR, you have the following rights regarding your personal data:
- Access (Art. 15) — receive a copy of your data and related information about processing.
- Rectification (Art. 16) — correct inaccurate or incomplete data.
- Erasure (Art. 17) — request deletion where legal grounds apply.
- Restriction (Art. 18) — limit processing in certain circumstances.
- Portability (Art. 20) — obtain data in a structured, commonly used, machine-readable format.
- Objection (Art. 21) — object to processing based on legitimate interests and to direct marketing at any time.
- Withdraw consent (Art. 7(3)) — where processing is based on consent, withdraw it at any time.
To exercise your rights, email [email protected] with sufficient details to identify you and your request. We may ask for additional information to verify your identity. We aim to respond within 30 days, extendable by up to 60 days for complex or multiple requests.
Supervisory authority: You may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if you believe your rights have been infringed. You can also seek a remedy before the competent courts in the Netherlands.
10 — Children’s Data
Our website and services are not directed at children under 16 years of age. We do not knowingly collect personal data from individuals under 16. If you believe a child has provided data to us without appropriate consent, please contact us and we will take reasonable steps to delete such data promptly.
11 — Do Not Track
Some browsers offer a “Do Not Track” (DNT) signal. There is no industry consensus on how to respond to DNT, and our website does not respond to these signals. Consent choices made through our banner and preferences panel control analytics and marketing technologies on this site.
12 — Account and Data Deletion Requests
If you would like us to delete personal data we hold about you, email [email protected] with the subject “Data Deletion Request.” We will verify your identity and respond within 30 days, subject to lawful grounds for continued retention (for example, legal obligations or establishment, exercise, or defense of legal claims). Where deletion is not possible, we will explain the reasons and offer restriction where appropriate.
13 — Business Transfers
In the event of a merger, acquisition, asset transfer, financing, or insolvency event involving The-Re B.V., personal data may be transferred to a successor or affiliate as part of the transaction, subject to this Privacy Policy and any applicable legal requirements. If a material change in processing occurs, we will provide a prominent site notice and, where required, seek your consent.
14 — California Residents (CCPA/CPRA)
Although The-Re B.V. is established in the Netherlands and primarily serves Canadian clients, residents of California who interact with our website may have rights under the California Consumer Privacy Act as amended by the CPRA. Over the past 12 months, we may have processed the following categories: identifiers (name, email, IP address, device identifiers), internet or network activity (browsing, usage), and inferences used for advertising. We do not sell personal information as defined by the CCPA. We may share personal information for cross-context behavioral advertising with your consent, which you can manage via our cookie preferences panel.
California rights include: the right to know, delete, correct, and opt out of sale or sharing; and the right to non-discrimination. Submit requests by emailing [email protected] with “California Privacy Request” in the subject. We will verify your identity and respond within the timeframes set by California law. Authorized agents must provide written proof of authorization.
15 — Virginia Residents (VCDPA)
If Virginia law applies to your interaction with our site, you may have rights of access, correction, deletion, portability, and to opt out of targeted advertising. We do not sell personal data or use personal data for profiling that produces legal or similarly significant effects. To exercise rights, email [email protected] with “Virginia Privacy Request.” If we deny your request, you may appeal by sending “Appeal of Refusal — Privacy Request” within 30 days of our response. Unresolved concerns may be raised with the Virginia Attorney General.
16 — Nevada
Nevada residents may submit a verified request to opt out of the sale of personal information by emailing [email protected] with “Nevada Do Not Sell Request.” We do not currently sell personal information as defined by Nevada law (NRS 603A).
17 — Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, technology, or our operations. Material changes will be announced via a homepage notice at least 14 days before they take effect, unless immediate implementation is required by law or security considerations. The “Last Updated” date at the top of this page reflects the latest revision.
18 — Contact
If you have questions about this Policy, our data practices, or your rights, please contact us:
- The-Re B.V.
- Ridder Thibaldstraat 19, 6444 ED Brunssum, Netherlands
- Email: [email protected]
- Service area: Canada (online delivery)
- Governing law and jurisdiction for this website: Laws of the Netherlands; courts of Limburg, the Netherlands. Consumers in the EU retain rights under mandatory local consumer protection law.