Privacy
Your details remain yours.
This privacy notice applies to the website, initial enquiries, consumer and business engagements, MijnDiAd and public experiences of the sole proprietorship trading as Mark Paasman and Breinhart.
1. Who is responsible?
The data controller is Mark Paasman. His business is a sole proprietorship registered with the Netherlands Chamber of Commerce under number 63598817 and trades under the names Mark Paasman and Breinhart. In this notice, the controller is referred to as 'Breinhart', regardless of which trading name was used in the enquiry or Agreement. To ask a question, object or exercise a privacy right, use the contact form and begin the message with 'Privacy request'. Do not include extensive sensitive information in the first message.
2. Who does this notice apply to?
This notice applies to website visitors, people making an enquiry, individual Participants, people taking part in group or organisational programmes, organisational contacts and Business Clients, and people giving permission for a review, personal story, photograph or video.
3. What personal data do we process?
Depending on the enquiry and agreed Services, Breinhart may process a name, email address, telephone number, contact message, date of birth, address, appointment details, organisational information, invoice and payment information, communications, confirmations and consents.
During a programme, Breinhart may also process information a person provides, exercises, reflections, reports and programme notes. For public experiences, Breinhart may process an agreed name or alias, review text, rating, date and publication permission.
For form security, the website processes technical hashes and temporary security information as explained below.
4. Sensitive Information
During an introductory conversation or programme, someone may voluntarily share sensitive information about matters such as health, pressure, significant experiences, personal history, family, work, conduct or substance use.
Breinhart does not operate as a medical practice, does not diagnose and does not keep a medical record. Sensitive personal data is processed only where necessary for the agreed programme and separate explicit consent has been recorded.
The public contact form is not intended for medical records, diagnoses, Dutch citizen service numbers or extensive sensitive information.
5. Purposes and Legal Bases
Breinhart processes data to provide and secure the website, respond to an enquiry, deliver appointments and programmes, plan business engagements, communicate, invoice, maintain administration and comply with law.
The legal basis depends on the purpose: steps at a person's request before a possible Agreement, performance of an Agreement, a legal obligation, legitimate interests or separate consent. Explicit consent is used for sensitive personal data where required. Publication of reviews, personal stories and images is based on separate consent or a demonstrable publication instruction.
No automated decision-making or profiling is used. Personal data is not sold and is not used for newsletters or advertising without separate consent.
6. Contact Form and Spam Prevention
The contact form sends a name, email address, optional telephone number and message directly to Mark's protected mailbox. The content of the message is not stored in the website's security database.
To prevent abuse, the IP address and email address are converted into non-readable technical hashes. Only these hashes, a time window and request count are temporarily stored for rate limiting. Records with a time window older than 48 hours are removed when the form is next requested.
7. MijnDiAd and Further Communication
Where a follow-up conversation or programme is appropriate, Mark may invite someone to MijnDiAd. MijnDiAd may be used for practice administration, appointments, confirmations, confidential communication, programme information, reports and, where applicable, invoicing.
Depending on the agreed format, calendar, video, payment, accounting and document services may also be used. Digital communication is never completely risk-free; Breinhart takes appropriate measures and asks Participants to share sensitive information through the agreed environment.
8. Organisational Clients
For a business Engagement, the Business Client may provide information needed for planning, participation and invoicing. A Business Client does not automatically receive substantive personal information about Participants.
Substantive information is shared only with the Participant's consent or another legal basis. Attendance, planning and invoice details may be shared where necessary for the Engagement.
9. Service Providers and Recipients
For website hosting and security, Breinhart uses professional hosting and security services, including Cloudflare. A secure mail service delivers contact messages. Depending on the Services, MijnDiAd and calendar, video, payment, accounting and storage services may process data for their agreed task.
Professional advisers or competent public authorities may receive information where necessary or legally required. Service providers may process data only for their agreed task. Breinhart never sells personal data.
Where processing takes place outside the European Economic Area, Breinhart or the relevant provider uses a valid legal transfer mechanism.
10. Website and Necessary Cookies
The website does not use analytics, advertising or tracking cookies. Cloudflare may use the __cf_bm security cookie to identify automated and harmful traffic; it generally expires after about 30 minutes of inactivity.
Pages containing the contact form use mp_contact_token to protect the form from abuse. This necessary cookie is available only over a secure connection and expires after no more than two hours.
Public MijnDiAd reviews are retrieved by the website's server. A visitor's browser does not connect directly to MijnDiAd for this purpose. A visitor goes to MijnTherapeut or another external site only after following an external link.
11. Retention Periods
Breinhart keeps information no longer than necessary. Tax and administrative records are generally retained for seven years. Enquiries are kept only as long as needed to handle and follow them up.
Confirmations, appointments and evidence are retained as long as needed for performance, administration, evidence or a legal obligation. Programme notes, reports and reflections are kept no longer than needed for the programme, follow-up, evidence or legitimate business operations.
Publication material remains in use while consent and the publication purpose continue. The necessary contact cookie expires after no more than two hours. Expired anti-spam records are removed on a later form request when their time window is more than 48 hours old.
12. Reviews, Personal Stories and Aliases
Reviews, personal experiences, photographs and videos are published only where consent or a demonstrable publication instruction exists. Participation does not depend on publication consent.
The person concerned decides whether publication uses their full name, first name, an agreed alias or anonymity. Breinhart follows that instruction and does not independently replace a name.
Consent can be withdrawn for future use. Breinhart will then make reasonable efforts to remove or amend its own publications; copies already shared, search engine caches and third-party publications cannot always be recovered completely.
13. Security
Breinhart takes appropriate technical and organisational measures, including encrypted connections, restricted access, password and access security, form protection and careful handling of communications and reports.
No method is completely without risk. Breinhart limits access to what is necessary and assesses incidents under applicable privacy law.
14. Your Rights
To the extent provided by law, you may ask for access, correction, deletion, restriction or portability, object to processing and withdraw consent.
Use the contact form and begin the message with 'Privacy request'. Do not routinely send identification. Breinhart may ask for additional information where necessary to verify identity carefully.
You may also lodge a complaint with the Dutch Data Protection Authority. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
15. Minors and Data Breaches
Breinhart processes a minor's data only with the required permission of a parent or legal guardian, unless the law provides otherwise in the particular circumstances.
A data breach is assessed and, where required, reported to the Dutch Data Protection Authority and affected individuals under applicable rules.
16. Changes and Version
Breinhart may update this notice when the Services, technology or law changes. The current version is published on the website.
This is version 3.1 dated 15 August 2026.
