Privacy Policy

noordeloos.cc Last updated: 30 July 2026

 

This policy explains what personal data I collect through this website and in the course of my work, why I collect it, and what your rights are. I have tried to write it plainly.

 

Who is responsible

The data controller is Marco Noordeloos, trading as noordeloos.cc, registered in the Denmark [CVR number: 39783843. For anything in this policy, contact me directly: marco@noordeloos.cc.

 

What I collect, and why

When you send an inquiry through the contact form. I receive what you enter: your name, email address, organisation and position if you choose to give them, your message, and any file you attach. I use this for one purpose: to respond to you. Your details are also stored in my contact management system so that I can keep track of our correspondence. They are not added to any mailing list, and you will receive no marketing as a result of sending an inquiry.

When you book an introductory call. Scheduling runs on Calendly, which collects your name, email address, and time zone to create the booking. Calendly’s own privacy policy applies to their processing; what I receive is your booking details, which I use to hold the call and follow up on it.

When you sign up for updates. If you tick the updates box on the contact form or sign up in the site footer, you will first receive a confirmation email. Only after you click the confirmation link is your email address added to my mailing list, which runs on Brevo. Every mailing includes an unsubscribe link, and unsubscribing takes effect immediately. Consent is the legal basis here, and you can withdraw it at any time.

When you download the brochure. No personal data is required and none is collected.

When we work together. Client engagements involve information that goes well beyond website data: what is discussed in coaching sessions, team sessions, and workshops, and the results of any diagnostic instruments used. Three things govern this. First, the terms of our engagement agreement, which take precedence over this policy where they are more specific. Second, confidentiality: the content of coaching conversations is not shared with anyone, including the sponsoring organisation, except as explicitly agreed with you at the start of an engagement. Third, diagnostic instruments such as the Leadership Circle Profile are administered on the providers’ own platforms under their own privacy terms; I receive the reports for use in our work and treat them with the same confidentiality as everything else.

 

Legal bases

Where the GDPR requires a legal basis, mine are: legitimate interest, for responding to inquiries and maintaining correspondence records; consent, for the mailing list; and performance of a contract, for data processed in the course of an engagement.

 

Who receives your data

I do not sell personal data, share it with advertisers, or pass it to anyone for their own marketing. The parties that process data on my behalf are service providers I use to run the practice: Brevo (email and contact management, EU-based), Calendly (scheduling), GoDaddy (website hosting and my email provider). Each processes data only on my instructions. Diagnostic providers, as described above, process assessment data under their own terms, which I share with clients before any instrument is used.

 

International transfers

Most processing happens within the European Economic Area. Where a provider processes data outside the EEA, as Calendly and GoDaddy may in the United States, the transfer is covered by recognised safeguards such as the EU–US Data Privacy Framework or standard contractual clauses.

 

How long I keep things

Inquiry correspondence is kept for two years after our last contact, then deleted, so that I can pick up a conversation where it left off if you return. Mailing list data is kept until you unsubscribe. Engagement records are kept for the period set out in the engagement agreement, and financial records for the five years Danish bookkeeping law requires. If you ask me to delete your data sooner, I will, unless a legal obligation requires me to keep a specific record.

 

Your rights

You can ask me at any time what data I hold about you, ask for it to be corrected or deleted, object to processing, ask for it in a portable format, or withdraw consent you have previously given. Write to marco@noordeloos.cc and I will respond within one month, as the GDPR requires, though usually much sooner. If you believe I have handled your data improperly, you have the right to complain to the Danish Data Protection Authority, Datatilsynet, though I would ask you to raise it with me first.

 

Cookies

This site keeps cookies to a minimum. WordPress sets functional cookies needed for the site to operate. The Calendly scheduling embed on the contact page sets Calendly’s cookies when it loads. For visitor statistics this site uses Plausible Analytics, a privacy-focused, EU-hosted service that uses no cookies and collects no personal data; what I see is aggregate numbers, never individual visitors. No advertising or cross-site tracking cookies are used.

 

Security

The site runs over HTTPS. Form submissions, correspondence, and client records are held in systems protected by access controls, and access is limited to me.

 

Changes

If I change this policy, the new version appears here with an updated date. For anything more than editorial tidying, mailing list subscribers will be told directly.

 

get in touch

It starts with
a conversation.

Coaching and facilitation for technical experts, leaders & teams in knowledge institutions.