Privacy Policy
Last updated: 24 October 2025
1. Introduction & scope
We at TangoMJ (a trade name of Het Waterwerk Rimburg V.O.F.) value your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website or use our services, in accordance with the EU General Data Protection Regulation (“GDPR”) and Dutch data protection laws (including the GDPR Implementation Act). This Policy applies to all visitors, users, and others who access or use our website or services.
2. Who is responsible for your data (the “Controller”)
Controller / Data Controller:
- Het Waterwerk Rimburg
- Address: Kapelweien 2A, 6374LX, Landgraaf, Netherlands
- Contact email: info@hetwaterwerkrimburg.nl
- Telephone: +31 6 21710803
3. Which personal data we collect & when
We may collect and process the following categories of personal data:
| Purpose | Categories of Personal Data | Source (if not from you) |
|---|---|---|
| Registration / enrolment for classes, workshops, or events | Name, email, phone number, address, date of birth (if needed) | You, via forms |
| Payment / invoicing | Name, billing address, VAT number (if applicable), transaction data | You or payment provider |
| Communication (email, messaging) | Email address, name, correspondence content | You |
| Website usage / analytics | IP address, browser type, device, pages visited, referrer | Automatically via our website tools |
| Marketing / newsletters (with consent) | Email, name, preferences | You, via opt-in |
| Photo / video media | Images, videos (if captured during events) | You / event participants |
Special / Sensitive Personal Data: We generally do not collect “special categories” of personal data (e.g. health data, racial or ethnic origin, political opinions) unless you explicitly provide it (e.g. for special workshop content). If we do, we will only do so where strictly necessary and with a clear legal basis and consent.
4. Legal basis for processing
We rely on one or more of the following legal bases under GDPR:
- Consent – When you have given clear consent (e.g. subscribing to a newsletter, consenting to photographs).
- Performance of a contract – To fulfill our obligations under an agreement (e.g. providing you classes or events you enrolled in).
- Legal obligations – To comply with laws (e.g. bookkeeping, tax, statutory records).
- Legitimate interests – For our legitimate business interests (such as improving our services, fraud prevention), as long as they don’t override your rights.
Where processing is based on consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of prior processing.
5. How and when we share or disclose personal data
We may share or disclose your personal data in the following cases:
- Service providers / processors – We engage third parties (e.g. payment processors, email services, web hosting, analytics) who process data on our behalf. We ensure they comply with data protection requirements (via data processing agreements).
- Legal obligations / authorities – When required by law or in response to lawful requests by public authorities.
- With your consent – When you expressly permit us to do so.
- Business transfer – In the event of merger, acquisition, restructuring, or sale of company assets, your data might be among transferred assets (under confidentiality safeguards).
If we ever transfer your personal data outside the European Economic Area (EEA), we will ensure adequate safeguards (e.g. Standard Contractual Clauses) or rely on an EU-approved adequacy decision.
6. Retention period (how long we store your data)
We will retain your personal data only for as long as necessary to fulfill the purposes described in this Policy, including satisfying legal, accounting, or reporting requirements. Typical retention periods may include:
- Enrolment / invoice records: 10 years
- Marketing / newsletters: until you unsubscribe or withdraw consent
- Analytics / logs: 3 years, unless longer is needed for security or legal reasons
- Media / photos: for the period relevant to the event or promotion, unless you request deletion
After expiration of these periods, we will securely delete or anonymize the data.
7. Data security & protection
We use appropriate technical and organizational security measures to protect personal data from unauthorized access, loss, alteration, or disclosure. Measures may include encryption (SSL/TLS), secure servers, access controls, regular audits, and staff training. While no system is completely safe, we continuously review and update our security measures in line with evolving threats.
In case of a data breach that poses a risk to individuals’ rights and freedoms, we will notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours and, where required, the affected individuals.
8. Your rights as a data subject
Under the GDPR and Dutch data protection law, you have the following rights (where applicable):
- Right of access – Request a copy of your personal data we process.
- Right to rectification – Request correction of inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”)– Request deletion of your data when there is no lawful basis to continue processing.
- Right to restrict processing – Request limiting the use of your data in certain contexts.
- Right to object – Against processing based on legitimate interests or direct marketing.
- Right to data portability – Receive your data in a structured, commonly used format or have it transmitted to another controller.
- Right to withdraw consent – If processing is based on consent, you can withdraw at any time.
- Right to lodge complaint – With the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if you believe your rights have been violated.
If you wish to exercise any of these rights, please contact us atinfo@tangomj.nl, and we’ll respond without undue delay (within legal time limits).
9. Cookies, tracking & analytics
We and third-party providers may use cookies, web beacons, and similar technologies to collect usage data, personalize content, and analyze visitor behavior.
- Essential / functional cookies: Required for basic website functionality (e.g. session cookies).
- Analytical / performance cookies: For usage analytics (e.g. Google Analytics or similar).
- Marketing / tracking cookies: For advertising, retargeting, or cross-site tracking.
We will request your prior consent before using non-essential cookies, in line with Dutch guidelines (no cookie walls, clear accept/reject options). You can manage or revoke cookie preferences via your browser settings or via our cookie banner settings.
10. Automated decision-making / profiling
We do not currently use automated decision-making or profiling that produces legal or similarly significant effects on individuals. If in future we adopt such processes, we will obtain consent or provide information and opt-outs as required by law.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal changes, or new services. The revised version will carry a new “Last Updated” date. We encourage you to check this page periodically for updates. If changes are significant, we may notify you via email or via a prominent notice on our website.
12. Contact & further information
If you have any questions, requests, or complaints about this Privacy Policy or our data practices, you may contact:
- Tango MJ
- Contact email: info@tangomj.nl
- Address: Kapelweien 2A, 6374LX, Landgraaf, Netherlands
If you’re not satisfied with our response, you also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens):
- Website:autoriteitpersoonsgegevens.nl
