Privacy
Privacy statement
Last updated: 25 September 2026
Who we are
Norrsken Advisory and Consulting BV is responsible for the personal data described in this statement. We are registered with the Dutch Chamber of Commerce (KVK) under number 42166029. For any privacy question, email info@norrskenadvisory.nl. We don’t have a data protection officer; we don’t need one given the size and nature of our work.
What we use your data for
Below you’ll find, per purpose, which data we use, why we’re allowed to, and how long we keep it.
Answering your question
- Data: name, email address, organisation (optional) and your message, sent via the contact form or by email.
- Legal basis: our legitimate interest in answering you, or steps you ask us to take before an agreement.
- Kept for: 12 months after our last contact, unless it leads to working together.
Carrying out coaching and advisory work
- Data: contact details, role and organisation, agreements we make, and notes from sessions.
- Legal basis: performing our agreement with you or your organisation.
- Kept for: up to 2 years after the assignment ends. Session notes are confidential and are never shared with your employer without your permission.
Invoicing and financial records
- Data: name, organisation, billing details and invoices.
- Legal basis: legal obligation (Dutch tax law).
- Kept for: 7 years, as required by the Dutch Tax Administration.
Website statistics
- Data: IP address, browser and device type, pages visited, referring website and approximate location.
- Legal basis: our legitimate interest in understanding how the site is used.
- Kept for: handled by WordPress.com; server logs are kept for about 30 days. We only see totals, not individual visitors.
We don’t ask for sensitive data, such as health information. If you choose to share something like that during coaching, we only use it for our work together and treat it as strictly confidential. We don’t use automated decision-making or profiling.
Who we share it with
We never sell your data or use it for marketing. We only share it with service providers who help us run our business, and only as far as needed:
- WordPress.com (Automattic): website hosting, contact form and statistics.
- TransIP: domain names and email hosting.
- Microsoft 365 (Outlook): email and documents.
- Our accountant: for financial records.
These providers process data on our behalf and are bound by agreements to protect it. We only share data with others if the law requires it.
Data outside the EU
TransIP is a Dutch company and stores our email and domain data in the Netherlands. Automattic and Microsoft are US companies, so some data may be processed outside the EU. Both are certified under the EU–US Data Privacy Framework, which the European Commission considers to offer adequate protection. Microsoft keeps most customer data within the EU (EU Data Boundary).
Cookies
Our site only uses cookies that are needed for it to work and cookies for basic visit statistics that have little impact on your privacy. Under Dutch law, these don’t require consent. We don’t use advertising or tracking cookies, and we don’t share data with social media platforms.
How we protect your data
The site uses an encrypted connection (HTTPS). Our accounts are protected with strong passwords and two-factor authentication, and only we have access to your data.
Your rights
You have the right to see, correct or delete your data, to limit how we use it, to object to how we use it, and to receive your data in a usable format. Send your request to info@norrskenadvisory.nl. We respond within one month. We may ask you to confirm your identity first.
Not happy with how we handle your data? Let us know, so we can try to fix it. You can also file a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.
Changes
We may update this statement when our work or the law changes. The date at the top shows the latest version.