Privacy Policy
Last Updated: March 12, 2026
This Privacy Policy explains how EOH Pilates Studio (“we”, “us”, or “our”) collects, uses, and protects personal data when you visit this website and when you contact us about Pilates classes and private sessions in Utrecht, Netherlands. This policy is written to be practical and readable. If anything is unclear, you can contact us using the details in Section 18.
For the purposes of the General Data Protection Regulation (“GDPR”) and the Dutch GDPR implementation (Uitvoeringswet AVG), the data controller is EOH Holding B.V., operating as EOH Pilates Studio.
1. Introduction & Controller Identity
This Privacy Policy applies to personal data collected through this website, including via our contact form, and to basic technical data processed when you browse pages. It also applies to cookie-based preferences stored in your browser (for example, whether you have accepted analytics cookies).
Data Controller (GDPR): EOH Holding B.V.
Trade name: EOH Pilates Studio
Registered address: Melkmeisjeslaan 24, 3454 WV Utrecht, Netherlands
Email: [email protected]
Telephone: +31 30 254 6789
We do not appoint a Data Protection Officer (“DPO”) for this website because our activities do not include large-scale systematic monitoring or large-scale processing of special-category data. If our obligations change, we will update this page.
Effective date: March 12, 2026.
2. Personal Data We Collect
The categories below describe what we may collect depending on how you use the site. You can browse most pages without telling us who you are, but some technical identifiers are still processed as part of normal website operation.
- Identity and contact details: name, email address, phone number.
- Form content: the message you submit, including scheduling preferences, training context, and any details you choose to share.
- Technical data: IP address, browser type and version, device type, operating system, language settings, and approximate location derived from IP (city/region level).
- Usage data: pages visited, time on page, referrer information, click paths, and interaction events (for example, a contact-form view or submission event) when analytics is enabled by consent.
- Cookies and identifiers: first-party cookies required for site functionality and optional analytics/marketing cookies when you consent.
- Conversion events: events indicating that a visitor performed an action (for example, submitted a form). These may be measured with analytics or marketing tools only when those categories are enabled by your consent.
We do not intentionally collect special-category data (such as health data), financial account details, or government-issued identification numbers through this website. Please avoid including medical details in messages. If you voluntarily include such information, we will handle it with care and limit access, but we still encourage you to keep messages practical (availability, class preferences, and training background at a general level).
3. Why We Process Your Data & Legal Basis (GDPR Art. 6)
GDPR requires that each use of personal data has a legal basis. Below is how we typically rely on GDPR Article 6 for our website and studio communications.
- Responding to contact requests and coordinating services: We use your submitted details to respond to questions, recommend an appropriate class type, and coordinate next steps. Legal basis: Art. 6(1)(b) (steps at your request prior to entering into a contract) and, where required for optional processing, Art. 6(1)(a) (consent).
- Analytics to improve the site (optional): When you enable analytics cookies, we measure page performance and understand what content is useful. Legal basis: Art. 6(1)(a) (consent).
- Marketing and remarketing (optional): When you enable marketing cookies, we may measure ad performance and build audiences for remarketing or lookalike targeting. Legal basis: Art. 6(1)(a) (consent).
- Security and fraud prevention: We process technical signals (such as IP address and request metadata) to protect the site and prevent abuse. Legal basis: Art. 6(1)(f) (legitimate interests) in running a secure website.
- Legal obligations: If required, we may process data to comply with applicable laws (for example, responding to lawful requests). Legal basis: Art. 6(1)(c) (legal obligation).
Automated decision-making (GDPR Art. 22): We do not engage in automated decision-making or profiling that produces legal effects or similarly significant effects for you. If we use advertising audience tools, they are used for measurement and targeting in a marketing context and do not determine eligibility for services.
4. Cookies & Tracking
Cookies are small text files stored on your device. Some cookies are essential for the site to function; others are optional and are only used if you give consent. This section summarizes categories and common examples. For a dedicated explanation, see our Cookie Policy.
Essential (always active)
Essential cookies support core functionality such as session continuity and storing your cookie choices. These cookies do not require consent because the site cannot operate reliably without them.
- _site_session (first-party): helps maintain basic session continuity.
- cookie_consent (first-party): stores whether you have enabled analytics and/or marketing cookies.
- Security/anti-abuse signals (may include CSRF-style tokens depending on how forms are served): used to protect the site and the form endpoint.
Typical retention: session to 12 months for essential cookies, and up to 12 months for the consent record in your browser.
Analytics (consent required)
If you opt in, we may use Google Analytics 4 (“GA4”) to understand traffic and improve content. Analytics is configured to minimize data where possible, including IP anonymization. Example cookies include _ga and _ga_XXXXXXXXXX. Analytics retention is typically set to 14 months.
Marketing (consent required)
If you opt in, we may use marketing cookies to measure advertising performance and to build remarketing audiences. Common examples include Google Ads conversion-linker cookies (_gcl_au) and Meta Pixel identifiers (_fbp, _fbc where applicable). These tools help attribute conversions (such as contact form submissions) back to campaigns.
In addition to browser cookies, marketing and analytics integrations may use pixel tags (such as scripts loaded from the provider) and, where configured by the site operator later, server-side event forwarding (for example, Meta Conversion API or server-side Google Tag Manager). When server-side tracking is used, data may include event timestamps, page URLs, and hashed identifiers (such as hashed email) where permitted and only after consent for the relevant category.
5. Consent (EEA/UK)
Users in the EEA and the UK receive a consent notice under GDPR/UK GDPR. Marketing and analytics cookies activate only after explicit, informed, freely given consent (GDPR Art. 6(1)(a)). Your consent choice is recorded in the cookie_consent browser cookie (stored for up to 12 months).
You can withdraw consent at any time by selecting “Manage cookie preferences” in the footer or by clearing cookies in your browser. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
6. Sharing With Advertising & Service Partners
We share personal data only where it is necessary to operate the website, respond to requests, and (if you consent) measure marketing performance. We do not sell personal data. We also do not allow providers to use site data for their own independent commercial purposes.
- Google LLC (Google Analytics 4, Google Ads, Google Tag Manager, remarketing): cookie identifiers, usage data, and conversion events if enabled by consent. Privacy information: https://policies.google.com/privacy
- Meta Platforms, Inc. (Meta Pixel, custom/lookalike audiences, Conversion API where configured): page views, conversions, and audience membership if enabled by consent. Privacy information: https://www.facebook.com/privacy/policy
- Cloudflare, Inc. (CDN and security): IP-based threat detection and performance optimization. Privacy information: https://www.cloudflare.com/privacypolicy/
Some of these partners act as “processors” on our behalf, while others may act as “independent controllers” for certain processing they perform. Where required, we rely on appropriate contractual protections.
7. International Transfers
Our service partners may process data outside the European Economic Area (“EEA”) and the UK, including in the United States. When personal data is transferred internationally, we rely on recognized transfer mechanisms such as:
- The EU–US Data Privacy Framework (DPF) (primary mechanism where applicable, in effect since July 2023), including the UK Extension to the DPF and the Swiss–US DPF where relevant.
- Standard Contractual Clauses (EU Commission Decision 2021/914) as a fallback mechanism.
- UK International Data Transfer Agreement (IDTA) as a fallback mechanism where applicable.
We also apply practical safeguards such as data minimization and consent controls for optional cookies.
8. Data Retention
We keep personal data only for as long as necessary for the purposes described in this policy, unless a longer period is required by law. Typical retention periods are:
- Contact submissions: up to 2 years from the last interaction (to maintain continuity and context in communications).
- Analytics data: typically 14 months (when analytics is enabled by consent).
- Marketing cookie data: according to cookie lifetime (commonly 90 days for certain identifiers), and as configured in the advertising platform (when marketing is enabled by consent).
- Email correspondence: duration of the relationship plus 1 year (unless a longer retention is needed for legal reasons).
- Server and security logs: typically 90 days (to investigate incidents and prevent abuse).
- Cookie consent record: up to 3 years for audit purposes (where stored outside the browser), and up to 12 months in the browser cookie.
- Legal and tax records: as required by applicable law (often 6–10 years for invoices and accounting records, where relevant).
If you request deletion, we will delete data where we are able to do so, subject to legal obligations and legitimate retention needs (for example, keeping minimal records needed to demonstrate compliance or handle disputes).
9. Your Rights (GDPR & UK GDPR)
If GDPR applies to you, you have rights regarding your personal data, including:
- Access (Art. 15): request a copy of your personal data.
- Rectification (Art. 16): correct inaccurate or incomplete data.
- Erasure (Art. 17): request deletion in certain circumstances.
- Restriction (Art. 18): restrict processing in certain circumstances.
- Data portability (Art. 20): receive data in a structured, commonly used format.
- Objection (Art. 21): object to processing based on legitimate interests.
- Withdraw consent (Art. 7(3)): withdraw consent where processing is based on consent.
- Lodge a complaint (Art. 77): complain to a supervisory authority.
To exercise rights, email [email protected]. We respond within 30 days, which can be extended by 60 days for complex requests. We may ask for additional information to verify identity before fulfilling a request.
Supervisory authority: In the Netherlands, the lead authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). For general EU guidance, see the European Data Protection Board: https://edpb.europa.eu.
10. Children
This site is not directed at individuals under 16. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a child under 16 without verifiable parental consent, we will delete it promptly.
11. Do Not Track
This website does not respond to “Do Not Track” (DNT) browser signals. Third-party providers may have their own DNT handling.
12. Data Deletion Requests
To request deletion, email [email protected] with the subject line “Data Deletion Request”. We will confirm what information we can locate and delete. Deletion is completed within 30 days after identity verification, unless an extension is required by law or the request is complex.
Please note that some minimal data may be retained where it is required to meet legal obligations or to establish, exercise, or defend legal claims.
13. Business Transfers
In a merger, acquisition, asset sale, financing, insolvency, or similar transaction, personal data may be transferred to a successor entity. If a transfer materially changes how data is used, we will provide notice on the site.
14. California (CCPA/CPRA)
Although we are based in the Netherlands, this section provides additional disclosure for visitors who may be California residents. Over the last 12 months, we may have collected the following categories:
- Identifiers: name, email, IP address, cookie IDs.
- Internet/network activity: browsing interactions, page views, and referring URLs (when analytics/marketing cookies are enabled by consent).
- Inferences: interests or preferences inferred from site use for advertising measurement (when marketing cookies are enabled by consent).
We do not sell personal information as defined by CCPA. We do share information for cross-context behavioral advertising when marketing cookies are enabled; California residents may opt out by using the cookie preferences panel and disabling Marketing Cookies.
California rights may include: Right to Know, Right to Delete, Right to Correct, Right to Opt-Out of sale/sharing, and Non-Discrimination. To submit a request, email [email protected] with the subject line “California Privacy Request”. We will verify identity before responding.
15. Virginia (VCDPA)
If you are a Virginia resident, you may have rights to access, correct, delete, and obtain a copy of personal data, and to opt out of targeted advertising. We do not sell personal data or engage in profiling that produces legal or similarly significant effects.
To submit a request, email [email protected] with the subject line “Virginia Privacy Request”. If we deny a request, you may appeal by emailing with the subject line “Appeal of Refusal — Privacy Request”. Appeals are responded to within 60 days, and unresolved matters may be referred to the Virginia Attorney General.
16. Nevada
Nevada residents may submit a verified opt-out request by emailing [email protected] with the subject “Nevada Do Not Sell Request”. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes are announced on the homepage for at least 14 days before taking effect. The “Last Updated” date at the top will be refreshed whenever this policy is revised.
18. Contact
If you have questions about this Privacy Policy or how your data is handled, contact:
EOH Holding B.V. (EOH Pilates Studio)
Melkmeisjeslaan 24, 3454 WV Utrecht, Netherlands
Email: [email protected]
Phone: +31 30 254 6789