Privacy Policy | Men-Taal

Privacy Policy

men-taal.com

At Men-Taal, trust is central — in ourselves, in each other, and in the process. That trust begins with transparency about how we handle your personal data. This privacy policy explains what data we collect, why, how long we retain it, and what rights you have.

Version1.0
Effective date30 April 2026
Applies tomen-taal.com
LegislationGDPR (EU 2016/679)
Article 1

Who are we?

Men-Taal is a sole proprietorship specialising in personal coaching, ceremonies, and retreats. Our services focus on mental wellbeing, personal growth, and self-awareness — both online and on location in the Netherlands, Morocco, the Sahara, the Amazon, and the Andes.

  • Trading name: Men-Taal
  • Website: men-taal.com
  • Coach: Ibrahim
  • Email: info@men-taal.com

Men-Taal is the data controller within the meaning of the General Data Protection Regulation (GDPR). This means we determine which personal data are processed, for what purpose, and in what manner.

Article 2

What personal data do we process?

We only process personal data that is necessary for the provision of our services.

Contact and identification data

  • First and last name
  • Email address
  • Phone number
  • Place of residence / country of origin

Coaching-related data

  • Motivation for participating in a session, ceremony, or retreat
  • Personal goals, challenges, and themes you wish to explore
  • Health information where relevant to safety during ceremonies or retreats (e.g. medication use, contraindications)
  • Notes and records of coaching sessions (confidential files)
  • Progress and evaluations throughout the trajectory

Payment and contract data

  • Invoice details (name, address, IBAN for refunds)
  • Proof of payment and booking confirmations
  • Agreements and assignments

Website data

  • IP address (anonymised via cookie consent if Google Analytics is active)
  • Browser and device data
  • Pages visited and click behaviour (via cookies)
  • Submitted contact forms

Communication data

  • Email correspondence
  • Messages via WhatsApp or social media
  • Newsletter or mailing list sign-ups

We do not process special categories of personal data (such as ethnicity, political views, or national identification numbers) unless strictly necessary for safety during ceremonies or retreats and with your explicit consent.

Article 3

For what purposes and on what legal basis do we process your data?

We always process personal data on the basis of one of the six legal grounds under the GDPR.

Purpose of processingLegal basis (GDPR)
Delivering a coaching trajectory, session, ceremony, or retreatPerformance of a contract (Art. 6(1)(b))
Assessing suitability for a ceremony (safety information)Consent (Art. 6(1)(a)) + vital interests (Art. 6(1)(d))
Scheduling appointments and sending confirmationsPerformance of a contract (Art. 6(1)(b))
Invoicing and financial administrationLegal obligation (Art. 6(1)(c))
Responding to enquiries via contact form or emailLegitimate interest (Art. 6(1)(f))
Sending newsletters or offersConsent (Art. 6(1)(a))
Improving the website (statistics)Consent (Art. 6(1)(a)) via cookie consent
Complying with legal obligations (e.g. tax retention requirements)Legal obligation (Art. 6(1)(c))
Website security and fraud preventionLegitimate interest (Art. 6(1)(f))

We never process more data than necessary (data minimisation). If we intend to use your data for a different purpose, we will inform you in advance.

Article 4

How long do we retain your data?

CategoryRetention periodReason
Coaching file and session notes2 years after last sessionContinuity of support; destroyed thereafter
Financial administration (invoices, payments)7 yearsStatutory retention obligation (tax authority)
Contact form submissions and email correspondence1 year after last contactLegitimate interest; follow-up and archiving
Newsletter subscriptionsAs long as consent is activeAutomatically deleted upon unsubscribing
Website statistics (anonymised)26 monthsWebsite usage analysis
Health information (ceremonies/retreats)1 year after the activitySafety and liability; destroyed thereafter
Business contacts1 yearIn accordance with GDPR guidelines

Upon expiry of the retention period, data is securely destroyed or anonymised.

Article 5

Do we share your data with third parties?

Men-Taal never sells or rents your personal data to third parties. In certain cases we engage carefully selected parties to support our services:

Processors

  • Hosting provider (Cloud86): storage on secured servers in the Netherlands/EU.
  • Booking system (Amelia Plugin): processing of appointment bookings.
  • Email marketing service: sending newsletters, only with your consent.
  • Payment services (e.g. Mollie, iDEAL): we do not store payment card data ourselves.
  • Google Analytics: anonymised statistics, only after cookie consent.

We have signed a data processing agreement with all processors in accordance with Article 28 GDPR.

Transfers outside the EU/EEA

Where data is processed outside the European Economic Area, this only takes place with appropriate safeguards (Standard Contractual Clauses, an adequacy decision, or prior anonymisation).

Legal obligation

In exceptional cases we may be required to disclose data to government authorities on the basis of a legal provision or court order. We will always limit this to the minimum necessary.

Article 6

Your rights as a data subject

Under the GDPR you have the following rights. You can exercise them by contacting us using the details at the bottom of this page.

Right of access

Know what personal data we hold about you and request a copy.

Right to rectification

Have inaccurate or incomplete data corrected or supplemented.

Right to erasure

Request deletion of your data, unless we have a legal obligation to retain it.

Right to restriction

Ask us to temporarily limit the processing of your data in certain circumstances.

Right to data portability

Receive your data in a readable format to transfer to another provider.

Right to object

Object to processing based on legitimate interest or for direct marketing purposes.

Withdrawal of consent

Withdraw any consent you have given (e.g. for the newsletter) at any time without giving a reason.

Right to lodge a complaint

Lodge a complaint with the Dutch Data Protection Authority via autoriteitpersoonsgegevens.nl.

We will respond to your request within 30 days in principle. We are entitled to verify your identity before processing a request.

Article 7

How do we secure your data?

We implement appropriate technical and organisational measures to protect your data:

  • SSL/TLS encryption for all connections via men-taal.com (HTTPS)
  • Password protection and restricted access to systems containing personal data
  • Regular backups at Cloud86 on secured EU servers
  • Use of GDPR-compliant plugins and services
  • Data minimisation: never more data than strictly necessary
  • Confidential handling of all coaching content

In the event of a data breach that poses a risk to your rights, we will notify the Dutch Data Protection Authority and — where applicable — you as the data subject within 72 hours.

Article 8

Cookies and website tracking

Necessary cookies

Essential for the functioning of the website (session management, security, cookie preferences). These do not require consent.

Analytical cookies (optional)

With your consent we use Google Analytics for anonymised statistics. Consent can be withdrawn at any time via the cookie banner.

Marketing and tracking cookies

We do not place tracking or advertising cookies without explicit consent. Should we do so in the future, this will be indicated separately in the cookie banner.

Article 9

Confidentiality of coaching sessions

Everything you share during a session, ceremony, or retreat is treated with the utmost confidentiality:

  • The content of conversations is never shared with third parties without your explicit consent.
  • Session notes and records are only accessible to Ibrahim and yourself upon request.
  • Testimonials or case descriptions are only used in anonymised form and solely with your written consent.
  • At group retreats, a mutual confidentiality agreement applies; participants are informed of this at the start.

Exceptions apply only in situations of acute danger to you or others, in accordance with the statutory duty of care.

Article 10

Minors

Our services are not intended for persons under the age of 16. We do not knowingly process personal data of minors without the consent of a parent or legal guardian. If you suspect we have inadvertently received data relating to a minor, please notify us immediately — we will delete such data without delay.

Article 11

Changes to this privacy policy

We reserve the right to amend this privacy policy. The most current version is always available at men-taal.com/privacy-policy. In the event of significant changes affecting your rights, we will notify active clients by email.

Contact

Questions or a request?

Do you have questions about this privacy policy or would you like to exercise a right? Get in touch — we will respond within 30 days.

Not satisfied with our response? You can lodge a complaint with the Dutch Data Protection Authority via autoriteitpersoonsgegevens.nl.