Skip to main content

Home / Privacy Policy

Privacy Policy

Last Updated: March 12, 2026

1. Introduction & Controller Identity

This Privacy Policy explains how Pigisakka B.V. (“we”, “us”, “our”) collects, uses, and protects personal data when you visit our website and when you contact us about our online workplace education programs and virtual workshops. This website is operated from the Netherlands, and our services are delivered online to learners throughout Canada.

Data Controller (GDPR): Pigisakka B.V.
Address: Gebroken Meeldijk 45, 2991 VB Barendrecht, Netherlands
Email: [email protected]
Phone: +31 10 223 4876

We do not appoint a Data Protection Officer (DPO) because we do not carry out large-scale processing of special-category data. If your enquiry includes information you would prefer not to share, please keep your message limited to education and registration questions.

Effective Date: March 12, 2026.

2. Personal Data We Collect

We collect personal data when you browse our site, submit a form, or communicate with us. The types of data we may collect include:

  • Identity and contact details: name, email address, phone number, and any contact details you choose to provide.
  • Form content: messages, selected program, preferred workshop (if provided), timing preferences, and other details you include in your enquiry.
  • Technical data: IP address, browser type and version, device type, operating system, language settings, and approximate location derived from IP (coarse, not precise).
  • Usage data: pages viewed, time spent on pages, referral source, and click paths used to navigate the site.
  • Cookies and identifiers: identifiers stored in cookies (see Section 4), including consent state and, if enabled, analytics and marketing identifiers.
  • Conversion events: actions such as submitting a registration or enquiry form, which may be measured to understand which content helps users find the right educational program.

We do not intentionally collect special-category data (such as health information, religious beliefs, or political opinions), financial account details, or government-issued identification numbers through our website. Please do not send such information in your message.

3. Why We Process Personal Data & Legal Basis

We process personal data only for clear, limited purposes that support our education services and the operation of our website. Our legal bases under the GDPR (Article 6) include:

  • Contact and registration requests: to respond to enquiries and administer registrations. Legal basis: Article 6(1)(b) (steps prior to entering a contract) and, where required, Article 6(1)(a) (consent).
  • Analytics: to understand how the site is used so we can improve content structure, navigation, and clarity. Legal basis: Article 6(1)(a) (consent).
  • Marketing and remarketing: to measure advertising performance and show relevant messages to interested audiences. Legal basis: Article 6(1)(a) (consent).
  • Security and fraud prevention: to protect the website, limit abuse, and maintain service integrity. Legal basis: Article 6(1)(f) (legitimate interests).
  • Legal obligations: to comply with applicable law, respond to lawful requests, and maintain necessary records. Legal basis: Article 6(1)(c) (legal obligation).

Automated Decision-Making (GDPR Article 22): We do not engage in automated decision-making or profiling that produces legal or similarly significant effects for you. Any advertising audiences created by third-party platforms are used for measurement and delivery, and do not determine eligibility for essential services.

4. Cookies & Tracking

We use cookies and similar technologies to ensure the site works properly, remember your cookie choices, and (if you opt in) help us understand performance and measure advertising. Cookies are small text files stored on your device. Some tracking may also occur through pixel tags and server-side events, depending on your consent.

Essential cookies (always active)

These cookies are required for basic site functionality, such as maintaining a session and remembering consent settings. They do not require consent.

  • _site_session (first-party): supports session continuity. Retention: session to 7 days (depending on browser behavior).
  • cookie_consent (first-party): stores your consent choice. Retention: 12 months.
  • Security/CSRF mechanisms (first-party): may be used to help prevent malicious submissions. Retention varies by session.

Analytics cookies (optional)

If you consent, we may use Google Analytics 4 (GA4) to understand usage patterns such as page views, navigation paths, and content engagement. Where applicable, IP anonymization is used. Analytics retention is typically 14 months for reporting settings.

  • _ga (third-party): GA4 user identifier. Retention: 2 years.
  • _ga_XXXXXXXXXX (third-party): GA4 session state (GA4 property-specific). Retention: 2 years.

Marketing cookies (optional)

If you consent, marketing cookies may be used to measure advertising performance and support remarketing. These cookies help attribute conversions (for example, a registration enquiry) to an advertising campaign and enable audience measurement.

  • _gcl_au (third-party): Google Ads conversion linker. Retention: 90 days.
  • _fbp (third-party): Meta Pixel browser identifier. Retention: 90 days.
  • _fbc (third-party): Meta click identifier (when present). Retention: 90 days.

Beyond cookies, third-party tags may use device identifiers derived from information such as IP address and User-Agent. If server-side measurement is enabled later (for example, Meta Conversion API or Google server-side tagging), identifiers may be hashed before transfer where supported. Your cookie preferences control whether optional analytics or marketing tracking is activated.

For more detail on cookies, see our Cookie Policy.

5. Consent (EEA/UK)

Users in the EEA and UK receive a consent notice under GDPR/UK GDPR. Analytics and marketing cookies activate only after explicit, informed, freely given consent (Article 6(1)(a)). Your consent choice is recorded in the cookie_consent cookie and is stored for 12 months.

You can withdraw consent at any time by using “Manage cookie preferences” in the footer or by clearing cookies in your browser settings. Withdrawal does not affect the lawfulness of processing based on consent before it was withdrawn.

6. Sharing With Advertising & Service Partners

We may share limited data with vendors that help us operate the website, understand usage, and measure advertising—only in line with your consent settings and applicable law. We do not sell personal data.

  • Google LLC (Google Analytics 4, Google Ads, Google Tag Manager, remarketing): cookie identifiers, usage data, and conversion events (where enabled and consented). Privacy: https://policies.google.com/privacy
  • Meta Platforms (Meta Pixel, Custom/Lookalike Audiences, Conversion API where enabled): page views, conversions, audience membership signals, and hashed identifiers (where supported and consented). Privacy: https://www.facebook.com/privacy/policy/
  • Cloudflare (CDN and security): IP-based threat detection and performance delivery. Privacy: https://www.cloudflare.com/privacypolicy/

These providers act as service providers/processors in relation to website operations and measurement. We do not permit them to use site data for their own independent commercial purposes outside of providing the contracted services and improving their security and reliability features in a general way.

7. International Transfers

Some service providers are located outside the European Economic Area (EEA), including in the United States. When personal data is transferred internationally, we rely on appropriate safeguards, which may include:

  • EU–US Data Privacy Framework (DPF), where applicable (primary mechanism, since July 2023).
  • UK Extension to the EU–US DPF, where applicable.
  • Swiss–US DPF, where applicable.
  • Standard Contractual Clauses (EU 2021/914) as a fallback.
  • UK International Data Transfer Agreement (IDTA) as a fallback.

We take reasonable steps to ensure transfers are handled with an appropriate level of protection and that contractual terms limit use of data to the purposes described in this policy.

8. Data Retention

We keep personal data only for as long as needed for the purposes described in this Privacy Policy, unless longer retention is required by law. Typical retention periods are:

  • Contact and registration submissions: up to 2 years from the last interaction, unless a longer period is required to handle ongoing matters.
  • Email correspondence: for the duration of the relationship plus 1 year.
  • Analytics data: typically 14 months (depending on configuration), if analytics cookies are enabled by consent.
  • Marketing cookies: retained according to the cookie lifetime (for example, 90 days for some marketing identifiers), if enabled by consent.
  • Server logs: typically up to 90 days for security and troubleshooting.
  • Cookie consent record: up to 3 years for audit and compliance purposes.
  • Legal/tax records: as required by applicable law (often 6–10 years for certain records where relevant).

When retention is no longer necessary, we delete or anonymize data in a reasonable timeframe, subject to technical and legal constraints.

9. Your Rights (GDPR & UK GDPR)

If you are in the EEA or UK, you may have the following rights, subject to conditions and exceptions in applicable law:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)
  • Right to withdraw consent at any time (Article 7(3))
  • Right to lodge a complaint with a supervisory authority (Article 77)

To exercise your rights, contact us at [email protected]. We typically respond within 30 days. For complex requests, the response period may be extended by up to an additional 60 days, as permitted by law.

Supervisory authority information: In the Netherlands, the competent authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). You can also consult general EU guidance at https://edpb.europa.eu.

10. Children

This site is not directed at individuals under 16. We do not knowingly collect personal data from minors. If we learn that we have collected personal data from a child under 16 without appropriate authorization, we will delete it promptly.

11. Do Not Track

This website does not respond to Do Not Track (DNT) browser signals. Third-party providers may have their own policies for handling DNT signals or similar preferences.

12. Data Deletion Requests

You may request deletion of your personal data by emailing [email protected] with the subject line “Data Deletion Request”. We may need to verify your identity before completing the request. We will aim to complete deletion within 30 days after verification, unless we must retain certain information to comply with legal obligations or to establish, exercise, or defend legal claims.

13. Business Transfers

In a merger, acquisition, asset sale, financing, or insolvency, personal data may be transferred to a successor entity. If such a transfer materially changes how personal data is used, we will provide notice on the website.

14. California (CCPA / CPRA)

If you are a California resident, you may have rights under the California Consumer Privacy Act (CCPA) as amended by the CPRA. Over the past 12 months, we may have collected the following categories of personal information:

  • Identifiers: name, email address, IP address, cookie IDs.
  • Internet/network activity: browsing interactions on our site (pages visited, click paths).
  • Inferences: interests or preferences inferred from browsing activity, used for advertising measurement where consented.

We do not sell personal information as defined by the CCPA. We may share data for cross-context behavioral advertising when you enable marketing cookies; California residents can opt out by using our cookie preferences panel (Manage cookie preferences in the footer).

California rights may include the right to know, delete, correct, and opt out of sale/sharing, and the right not to be discriminated against for exercising privacy rights. To submit a request, email [email protected] with the subject “California Privacy Request”. We may require identity verification. Authorized agents must provide proof of authorization.

15. Virginia (VCDPA)

If you are a Virginia resident, you may have rights under the Virginia Consumer Data Protection Act (VCDPA), including rights to access, correct, delete, and obtain a copy of personal data, and to opt out of targeted advertising.

We do not sell personal data and we do not engage in profiling that produces legal or similarly significant effects. To exercise rights, email [email protected] with the subject “Virginia Privacy Request”. If you wish to appeal a decision, email with the subject “Appeal of Refusal — Privacy Request”. We will respond to appeals within 60 days as required by law. If unresolved, you may contact the Virginia Attorney General.

16. Nevada

Nevada residents may submit a verified opt-out request by emailing us with the subject “Nevada Do Not Sell Request”. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If changes are material, we will display a notice on the homepage at least 14 days before the changes take effect, where feasible. The “Last Updated” date at the top of this page shows when this policy was last revised.

18. Contact

If you have questions about this Privacy Policy or want to exercise your privacy rights, contact:

Pigisakka B.V.
Gebroken Meeldijk 45
2991 VB Barendrecht, Netherlands
Email: [email protected]
Phone: +31 10 223 4876

Privacy questions

For privacy-related questions, you can email us directly. If you prefer, you can also use the registration form on the homepage to contact our team, but we recommend email for privacy requests so your message is routed correctly.