Privacy Policy
men-taal.com
At Men-Taal, trust is central — in ourselves, in each other, and in the process. That trust begins with transparency about how we handle your personal data. This privacy policy explains what data we collect, why, how long we retain it, and what rights you have.
Who are we?
Men-Taal is a sole proprietorship specialising in personal coaching, ceremonies, and retreats. Our services focus on mental wellbeing, personal growth, and self-awareness — both online and on location in the Netherlands, Morocco, the Sahara, the Amazon, and the Andes.
- Trading name: Men-Taal
- Website: men-taal.com
- Coach: Ibrahim
- Email: info@men-taal.com
Men-Taal is the data controller within the meaning of the General Data Protection Regulation (GDPR). This means we determine which personal data are processed, for what purpose, and in what manner.
What personal data do we process?
We only process personal data that is necessary for the provision of our services.
Contact and identification data
- First and last name
- Email address
- Phone number
- Place of residence / country of origin
Coaching-related data
- Motivation for participating in a session, ceremony, or retreat
- Personal goals, challenges, and themes you wish to explore
- Health information where relevant to safety during ceremonies or retreats (e.g. medication use, contraindications)
- Notes and records of coaching sessions (confidential files)
- Progress and evaluations throughout the trajectory
Payment and contract data
- Invoice details (name, address, IBAN for refunds)
- Proof of payment and booking confirmations
- Agreements and assignments
Website data
- IP address (anonymised via cookie consent if Google Analytics is active)
- Browser and device data
- Pages visited and click behaviour (via cookies)
- Submitted contact forms
Communication data
- Email correspondence
- Messages via WhatsApp or social media
- Newsletter or mailing list sign-ups
We do not process special categories of personal data (such as ethnicity, political views, or national identification numbers) unless strictly necessary for safety during ceremonies or retreats and with your explicit consent.
For what purposes and on what legal basis do we process your data?
We always process personal data on the basis of one of the six legal grounds under the GDPR.
| Purpose of processing | Legal basis (GDPR) |
|---|---|
| Delivering a coaching trajectory, session, ceremony, or retreat | Performance of a contract (Art. 6(1)(b)) |
| Assessing suitability for a ceremony (safety information) | Consent (Art. 6(1)(a)) + vital interests (Art. 6(1)(d)) |
| Scheduling appointments and sending confirmations | Performance of a contract (Art. 6(1)(b)) |
| Invoicing and financial administration | Legal obligation (Art. 6(1)(c)) |
| Responding to enquiries via contact form or email | Legitimate interest (Art. 6(1)(f)) |
| Sending newsletters or offers | Consent (Art. 6(1)(a)) |
| Improving the website (statistics) | Consent (Art. 6(1)(a)) via cookie consent |
| Complying with legal obligations (e.g. tax retention requirements) | Legal obligation (Art. 6(1)(c)) |
| Website security and fraud prevention | Legitimate interest (Art. 6(1)(f)) |
We never process more data than necessary (data minimisation). If we intend to use your data for a different purpose, we will inform you in advance.
How long do we retain your data?
| Category | Retention period | Reason |
|---|---|---|
| Coaching file and session notes | 2 years after last session | Continuity of support; destroyed thereafter |
| Financial administration (invoices, payments) | 7 years | Statutory retention obligation (tax authority) |
| Contact form submissions and email correspondence | 1 year after last contact | Legitimate interest; follow-up and archiving |
| Newsletter subscriptions | As long as consent is active | Automatically deleted upon unsubscribing |
| Website statistics (anonymised) | 26 months | Website usage analysis |
| Health information (ceremonies/retreats) | 1 year after the activity | Safety and liability; destroyed thereafter |
| Business contacts | 1 year | In accordance with GDPR guidelines |
Upon expiry of the retention period, data is securely destroyed or anonymised.
Do we share your data with third parties?
Men-Taal never sells or rents your personal data to third parties. In certain cases we engage carefully selected parties to support our services:
Processors
- Hosting provider (Cloud86): storage on secured servers in the Netherlands/EU.
- Booking system (Amelia Plugin): processing of appointment bookings.
- Email marketing service: sending newsletters, only with your consent.
- Payment services (e.g. Mollie, iDEAL): we do not store payment card data ourselves.
- Google Analytics: anonymised statistics, only after cookie consent.
We have signed a data processing agreement with all processors in accordance with Article 28 GDPR.
Transfers outside the EU/EEA
Where data is processed outside the European Economic Area, this only takes place with appropriate safeguards (Standard Contractual Clauses, an adequacy decision, or prior anonymisation).
Legal obligation
In exceptional cases we may be required to disclose data to government authorities on the basis of a legal provision or court order. We will always limit this to the minimum necessary.
Your rights as a data subject
Under the GDPR you have the following rights. You can exercise them by contacting us using the details at the bottom of this page.
Know what personal data we hold about you and request a copy.
Have inaccurate or incomplete data corrected or supplemented.
Request deletion of your data, unless we have a legal obligation to retain it.
Ask us to temporarily limit the processing of your data in certain circumstances.
Receive your data in a readable format to transfer to another provider.
Object to processing based on legitimate interest or for direct marketing purposes.
Withdraw any consent you have given (e.g. for the newsletter) at any time without giving a reason.
Lodge a complaint with the Dutch Data Protection Authority via autoriteitpersoonsgegevens.nl.
We will respond to your request within 30 days in principle. We are entitled to verify your identity before processing a request.
How do we secure your data?
We implement appropriate technical and organisational measures to protect your data:
- SSL/TLS encryption for all connections via men-taal.com (HTTPS)
- Password protection and restricted access to systems containing personal data
- Regular backups at Cloud86 on secured EU servers
- Use of GDPR-compliant plugins and services
- Data minimisation: never more data than strictly necessary
- Confidential handling of all coaching content
In the event of a data breach that poses a risk to your rights, we will notify the Dutch Data Protection Authority and — where applicable — you as the data subject within 72 hours.
Cookies and website tracking
Necessary cookies
Essential for the functioning of the website (session management, security, cookie preferences). These do not require consent.
Analytical cookies (optional)
With your consent we use Google Analytics for anonymised statistics. Consent can be withdrawn at any time via the cookie banner.
Marketing and tracking cookies
We do not place tracking or advertising cookies without explicit consent. Should we do so in the future, this will be indicated separately in the cookie banner.
Confidentiality of coaching sessions
Everything you share during a session, ceremony, or retreat is treated with the utmost confidentiality:
- The content of conversations is never shared with third parties without your explicit consent.
- Session notes and records are only accessible to Ibrahim and yourself upon request.
- Testimonials or case descriptions are only used in anonymised form and solely with your written consent.
- At group retreats, a mutual confidentiality agreement applies; participants are informed of this at the start.
Exceptions apply only in situations of acute danger to you or others, in accordance with the statutory duty of care.
Minors
Our services are not intended for persons under the age of 16. We do not knowingly process personal data of minors without the consent of a parent or legal guardian. If you suspect we have inadvertently received data relating to a minor, please notify us immediately — we will delete such data without delay.
Changes to this privacy policy
We reserve the right to amend this privacy policy. The most current version is always available at men-taal.com/privacy-policy. In the event of significant changes affecting your rights, we will notify active clients by email.
Questions or a request?
Do you have questions about this privacy policy or would you like to exercise a right? Get in touch — we will respond within 30 days.
- Email: info@men-taal.com
- Website: men-taal.com/contact
Not satisfied with our response? You can lodge a complaint with the Dutch Data Protection Authority via autoriteitpersoonsgegevens.nl.
