Privacy Policy
Last Updated: March 14, 2026
This Privacy Policy explains how Riko Photography Academy (“we”, “us”) collects, uses, and protects personal data when you visit our website and contact us about photography courses in the Netherlands. It also describes your choices and rights under the General Data Protection Regulation (GDPR).
1. Introduction & Controller Identity
Riko Photography Academy is a photography education business based in Haarlem, Netherlands. We provide course information, scheduling, and enrollment support through this website, and we respond to inquiries submitted by visitors. This Privacy Policy applies to personal data we process when you browse our pages, interact with site features, or contact us.
Data Controller (GDPR): Riko B.V.
Registered address: Damstraat 4, 2011 HA Haarlem, Netherlands
Contact email: [email protected]
Telephone: +31 23 205 1128
Effective Date: March 14, 2026.
We do not currently appoint a Data Protection Officer (DPO). If you have privacy questions, contact us using the details above and we will route your request to the appropriate person.
2. Personal Data We Collect
We collect personal data that you choose to provide and data that is generated automatically when you use the website. The exact data depends on how you interact with us.
- Identity and contact details: name, email address, telephone number (if provided), and any other details you include when contacting us.
- Form content: messages, course interests (such as portrait, product, lighting, or editing), and practical details you share (camera model, schedule preferences, learning goals).
- Technical data: IP address, browser type and version, device identifiers, operating system, language settings, time zone, and approximate location inferred from IP (country/region level).
- Usage data: pages viewed, time spent, clicks, scroll behavior, referral source, and navigation paths, to understand which course information is most useful.
- Cookies and identifiers: first-party cookies (such as session continuity and consent preference) and, if you consent, third-party cookies used for analytics and marketing measurement.
- Conversion events: when you submit a contact request, we record that a form submission occurred so we can respond and measure site performance.
We do not intentionally collect special-category data (such as health data, religious beliefs, political opinions), government identification numbers, or payment card details through this website. Please do not include such information in your message. If you choose to provide it, we will treat it as part of your message content and handle it with appropriate care, but we may delete or redact it where feasible.
3. Why We Process Personal Data & Legal Basis (GDPR Article 6)
We process personal data only when we have a lawful basis under GDPR. The purposes below reflect a typical lead-generation and course information workflow for a Netherlands-based academy.
-
Responding to inquiries and providing course information (e.g., answering questions about course tracks, dates in the Netherlands, prerequisites, and preparation).
Legal basis: Article 6(1)(b) (steps at your request prior to entering into a contract) and, where applicable, Article 6(1)(a) (consent) when you explicitly request follow-up. -
Operating and securing the website (maintaining stability, preventing abuse, and troubleshooting).
Legal basis: Article 6(1)(f) (legitimate interests in running a secure and reliable site). -
Analytics and performance measurement (understanding how visitors use our course pages so we can improve content and navigation).
Legal basis: Article 6(1)(a) (consent), where required for non-essential analytics cookies. -
Marketing and advertising measurement (attribution and remarketing, where enabled by your cookie preferences).
Legal basis: Article 6(1)(a) (consent). -
Legal compliance (responding to lawful requests or retaining limited records when required).
Legal basis: Article 6(1)(c) (legal obligation).
Automated Decision-Making (GDPR Article 22): We do not engage in automated decision-making or profiling that produces legal or similarly significant effects for you. If we use marketing audiences (with consent), they are used for advertising delivery and measurement, not for decisions that significantly affect you.
4. Cookies & Tracking
Cookies are small text files stored on your device. Some cookies are essential for the website to function. Others help measure performance or support advertising attribution and remarketing. Where required by applicable law in the Netherlands and the EEA/UK, analytics and marketing cookies activate only after you provide explicit consent through our cookie banner and preferences panel.
Our cookie categories and examples are:
- Essential cookies (always active): required for core site functionality, security, and storing your cookie preferences. Examples include _site_session and cookie_consent. Retention ranges from session to 12 months. Where applicable, security-related tokens (such as CSRF protection) may also be used.
- Analytics cookies (consent): used to understand usage and improve the website. We may use Google Analytics 4 (GA4) configured to reduce or anonymize IP where supported by the tool and settings. Examples include _ga and _ga_XXXXXXXXXX. Typical retention: up to 2 years for the cookie identifier, and analytics data retention set to 14 months.
- Marketing cookies (consent): used for personalized advertising, remarketing, and conversion attribution. Examples include _gcl_au (Google Ads conversion linker), _fbp, and _fbc (Meta). Typical retention: around 90 days for marketing identifiers.
Beyond cookies, advertising and analytics can involve “pixel tags” and similar technologies that transmit limited event data (such as a page view or form submission) to service providers. If server-side tracking is enabled in the future (for example, via Meta Conversion API or server-side tag management), we will do so only in a manner consistent with your cookie choices and applicable law, and we may use hashed identifiers (such as hashed email) only when you provide them and where lawful.
5. Consent (EEA/UK) and How to Withdraw It
Users in the EEA and the UK receive a consent notice under GDPR/UK GDPR. Analytics and marketing cookies are activated only after explicit, informed, freely given consent (GDPR Article 6(1)(a)). We record your choice in the cookie_consent cookie, typically for 12 months, so you do not have to choose on every visit.
You may withdraw or change consent at any time by selecting “Manage cookie preferences” in the website footer. You may also clear cookies in your browser settings. Withdrawing consent does not affect the lawfulness of processing based on consent before it was withdrawn (GDPR Article 7(3)).
6. Sharing With Advertising & Service Partners
We use a small set of service providers to run the website, measure performance, and (where you consent) measure advertising. We share only the data needed for the relevant purpose, and we do not sell personal data.
- Google LLC (Google Analytics 4, Google Ads, Tag Manager, remarketing): cookie identifiers, usage data, and conversion events (where enabled by consent). Privacy information: https://policies.google.com/privacy.
- Meta Platforms (Pixel, Custom/Lookalike Audiences, Conversion API if enabled): event data such as page views and conversions and, where applicable and lawful, hashed identifiers to improve matching. Privacy information: https://www.facebook.com/privacy/policy.
- Cloudflare (content delivery network and security): IP-based request data for traffic management and security, such as detecting abusive traffic patterns. Privacy information: https://www.cloudflare.com/privacypolicy/.
We do not permit these providers to use site data for their own independent commercial purposes beyond providing services to us under their terms and data processing arrangements. However, these providers may process data as separate controllers for certain functions; their privacy policies explain those roles.
7. International Transfers
Our business is based in the Netherlands (EEA). Some service providers (such as Google and Meta) may process data outside the EEA/UK, including in the United States. Where personal data is transferred internationally, we rely on appropriate safeguards.
Safeguards may include: the EU–US Data Privacy Framework (DPF) where applicable (since July 2023), the UK Extension to the DPF where applicable, and Standard Contractual Clauses (EU Commission Decision 2021/914) as a fallback. For the UK, the UK International Data Transfer Agreement (IDTA) may be used as a fallback where relevant.
You can request more information about the safeguards we use by contacting us at [email protected].
8. Data Retention
We keep personal data only as long as necessary for the purpose for which it was collected, and then delete or anonymize it unless we are required to keep it longer by law.
- Contact submissions: typically retained up to 2 years from the last interaction, so we can follow up on course questions and maintain continuity if you return later.
- Email correspondence: retained for the duration of the relationship and typically 1 additional year for reference and continuity.
- Server and security logs: typically retained up to 90 days, unless a longer period is needed to investigate abuse or security incidents.
- Analytics data: retention in GA4 is typically set to 14 months for user-level event data (subject to configuration), with cookies retaining identifiers for up to 2 years.
- Marketing cookies: retained according to the cookie lifetime (often around 90 days) and your consent settings.
- Cookie consent record: we may keep a record of consent status for up to 3 years for audit and compliance purposes.
- Legal and tax records: if we must retain certain records by law (for example, invoices), we keep them for the legally required period (often 6 to 10 years depending on the record type and applicable rules).
9. Your Rights (GDPR & UK GDPR)
If you are in the EEA or UK, you have the following rights under GDPR/UK GDPR, subject to conditions and exceptions:
- Right of access (Article 15).
- Right to rectification (Article 16).
- Right to erasure (“right to be forgotten”) (Article 17).
- Right to restriction of processing (Article 18).
- Right to data portability (Article 20).
- Right to object (Article 21).
- Right to withdraw consent at any time where processing is based on consent (Article 7(3)).
- Right to lodge a complaint with a supervisory authority (Article 77).
To exercise your rights, contact us at [email protected]. We aim to respond within 30 days. For complex requests we may extend by up to 60 additional days as permitted by law, and we will explain why if an extension is needed.
Supervisory authorities: In the Netherlands, the competent supervisory authority is the Autoriteit Persoonsgegevens (AP). You can also find guidance on EU supervisory authorities via the European Data Protection Board: https://edpb.europa.eu.
10. Children
This website is not directed at individuals under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data without verifiable parental consent, contact us and we will take steps to delete the data promptly.
11. Do Not Track
Some browsers offer a “Do Not Track” (DNT) signal. This website does not respond to DNT signals. Third-party providers may have their own approaches to DNT and similar mechanisms as described in their privacy policies.
12. Requests for Data Deletion
If you would like us to delete personal data that we hold about you, email [email protected] with the subject line “Data Deletion Request”. To protect your data, we may ask for reasonable information to verify identity before completing deletion. We aim to complete verified requests within 30 days, unless an exception applies (for example, if retention is required by law).
13. Business Transfers
If we are involved in a merger, acquisition, asset sale, financing, reorganization, or insolvency event, personal data may be transferred to a successor entity as part of that transaction. If such a transfer materially changes how personal data is used, we will provide a notice on the website.
14. California (CCPA/CPRA)
This section is provided for transparency for visitors from the United States, including California. In the past 12 months we may have collected the following categories of personal information: identifiers (such as name, email, IP address, and cookie identifiers), internet or other electronic network activity (such as pages viewed and interactions), and inferences (such as interests derived from browsing behavior) where marketing cookies are enabled by consent.
We do not sell personal information as defined by the CCPA. We may share information for cross-context behavioral advertising when you enable marketing cookies via our cookie preferences panel. California residents may opt out of sharing for targeted advertising through the cookie preferences controls available from the footer link “Manage cookie preferences”.
California rights may include: the right to know, delete, correct, and opt out of sale/sharing, and the right to non-discrimination for exercising privacy rights. To submit a request, email [email protected] with the subject “California Privacy Request”. We will verify your request as required. Authorized agents may submit requests with written proof of authorization.
15. Virginia (VCDPA)
For Virginia residents, this section summarizes rights under the Virginia Consumer Data Protection Act (VCDPA), where applicable. Rights may include access, correction, deletion, portability, and the ability to opt out of targeted advertising. We do not sell personal data, and we do not engage in profiling that produces legal or similarly significant effects.
To submit a request, email [email protected] with the subject “Virginia Privacy Request”. If we decline to act, you may appeal by emailing with the subject “Appeal of Refusal — Privacy Request”. We will respond to appeals within 60 days. If your appeal is denied, you may contact the Virginia Attorney General.
16. Nevada
Nevada residents may submit a verified request to opt out of the sale of certain covered information by emailing [email protected] with the subject “Nevada Do Not Sell Request”. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements or how our website operates. If we make material changes, we will provide a notice on the website at least 14 days before changes take effect where feasible. The “Last Updated” date at the top of this page indicates when the latest version was published.
18. Contact
If you have questions about this Privacy Policy or want to exercise your rights, contact:
Riko B.V.
Damstraat 4, 2011 HA Haarlem, Netherlands
Email: [email protected]
Phone: +31 23 205 1128