FNDMNTL Basketball · Legal
Privacy Policy
KVK 93377797 · Effective: May 2026 · Houten, NL
Contents
- Introduction
- Legal Basis for Processing
- When & Why We Share Data
- International Transfers
- Cookies & Tracking
- Data Retention
- Security Measures
- Data Breach Notification
- Your Rights
- Opt-Out & Marketing
- Minors' Data Protection
- Third-Party Links
- Limitation of Liability
- Force Majeure
- Changes to This Policy
- Contact Us
- Annex A: Data Processing
Introduction
This Privacy Policy explains how FNDMNTL Basketball ("We/Us"), located at Gruttoweide 29, 3993DK, Houten, registered with the Dutch Chamber of Commerce under KVK 93377797, collects, uses, and protects your personal data ("Personal Data") in accordance with the General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (Uitvoeringswet AVG / UAVG).
We collect Personal Data when you request, purchase, use, or access our services and websites. For a detailed breakdown of data types, legal bases, retention periods, and third-party sharing, see Annex A.
FNDMNTL Basketball is a small-scale sports training business. We are not required to appoint a formal Data Protection Officer (DPO) under Article 37 GDPR. Data protection queries are handled by our designated Privacy Officer — see Section 16 for contact details.
Legal Basis for Processing Personal Data
We process Personal Data under the following legal bases as defined in Article 6 GDPR:
- Contractual necessity — To provide our services (e.g., training sessions, user accounts, payments).
- Legitimate interest — To improve services, conduct analytics, and prevent fraud, where these interests are not overridden by your rights.
- Legal obligation — To comply with applicable Dutch and EU law, including tax obligations, court orders, and government requests.
- Consent — For marketing communications, non-essential cookies, and the processing of personal data of minors. Where we rely on consent, you may withdraw it at any time without affecting prior processing.
Health and training-related data constitutes a special category of personal data under Article 9 GDPR. We process such data solely on the basis of your explicit consent, given for the purpose of delivering safe and appropriate training services. Where required by applicable law or where processing poses a high risk to your rights, we may carry out a Data Protection Impact Assessment (DPIA) prior to processing.
When & Why We Share Personal Data
We do not sell Personal Data. We share data only where necessary and only with the following categories of recipients:
- Basketball Clubs — Where clubs provide player data to us, they warrant that they have obtained the required legal basis, including explicit consent where data relates to minors or special categories. Clubs fully indemnify FNDMNTL Basketball for any unauthorised data sharing.
- Contractors & Service Providers — Including payment processors, IT security providers, cloud storage providers, and, where applicable, advertising networks. All providers are contractually required to comply with GDPR security standards and may only process data on our documented instructions.
- Legal Authorities — To comply with applicable laws, court orders, or legitimate government requests.
See Annex A for full details of data-sharing arrangements.
International Data Transfers
If we transfer Personal Data outside the European Economic Area (EEA), we ensure adequate safeguards are in place, including:
- EU Standard Contractual Clauses (SCCs) as approved by the European Commission
- Transfers to countries covered by a European Commission Adequacy Decision
We do not transfer data to third countries without first verifying that the recipient provides an equivalent level of data protection.
Cookies & Tracking Technologies Updated
We use cookies and similar technologies on our websites. In line with the Dutch Telecommunications Act (Telecommunicatiewet) and the Autoriteit Persoonsgegevens cookie guidelines, we distinguish between:
- Functional cookies — Essential for the website to operate. These do not require consent.
- Analytical cookies — Used to measure performance and improve user experience (e.g., Google Analytics with IP anonymisation enabled and Consent Mode active). These require your prior consent. Analytics data is only collected after you have actively opted in.
- Marketing cookies — Used for targeted advertising (e.g., Facebook Pixel). These require your explicit opt-in consent before being placed. Facebook Pixel is only activated after consent is given and cannot be used to track you prior to that point.
For full details, refer to our Cookie Policy.
Data Retention
We retain Personal Data only as long as necessary for the purpose it was collected, or as required by law:
- Customer & participant accounts — 3 years after last activity
- Health & training data — Duration of the active training relationship, then deleted within 30 days unless explicit consent is given for longer retention
- Payment records — 7 years (Dutch tax law, Article 52 AWR)
- Marketing data — Until you opt out or withdraw consent
- Website analytics — 24 months
When data is no longer required, we securely delete or anonymise it. See Annex A for the full retention schedule.
Security Measures
We implement appropriate technical and organisational measures to protect Personal Data against unauthorised access, loss, alteration, or misuse. Our measures include:
- Role-based access controls and authorisation restrictions
- Encrypted storage and transmission (TLS/SSL)
- Regular security reviews and vulnerability assessments
- Staff awareness and data handling procedures
Where we use automated tools or AI-assisted systems (e.g., for performance analytics), we ensure these comply with applicable EU AI Act requirements, including obligations around transparency and risk documentation.
Data Breach Notification Added
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR.
Where the breach is likely to result in a high risk to affected individuals, we will also notify those individuals directly without undue delay, providing a clear description of the breach, its likely consequences, and the measures taken or proposed to address it.
Your Rights
Under the GDPR, you have the following rights regarding your Personal Data. We will respond to all verified requests within one month of receipt (extendable by a further two months for complex requests, with prior notice):
To exercise any of these rights, contact us at [email protected]. We may ask for verification of your identity before processing your request.
Opt-Out & Marketing Preferences
You may opt out of marketing communications at any time by following the unsubscribe link in any marketing email or by contacting us directly. Opting out of marketing does not affect service-related communications (e.g., booking confirmations, session reminders).
Minors' Data Protection
Our services may be used by participants under the age of 18. In accordance with the UAVG, individuals under 16 years of age require verifiable parental or guardian consent before their personal data is processed, including for account creation, service delivery, and any health or training-related data.
Parents or legal guardians may request access to, rectification of, or deletion of their child's data at any time by contacting us at [email protected].
Third-Party Links & Content
Our websites may contain links to third-party websites or embed third-party content. We are not responsible for the privacy practices of those third parties. We recommend reviewing the relevant privacy policy before sharing Personal Data on any external platform.
Limitation of Liability Updated
To the extent permitted by applicable Dutch and EU mandatory law, FNDMNTL Basketball is not liable for indirect or consequential damages arising from Personal Data processing, unauthorised third-party access, or data misuse resulting from circumstances outside our reasonable control.
Nothing in this section limits or excludes any liability that cannot be excluded under applicable law, including your right to compensation for damages caused by a GDPR infringement under Article 82 GDPR.
Force Majeure Updated
We are not responsible for delays, security breaches, or data loss resulting from force majeure events beyond our reasonable control, including but not limited to:
- Natural disasters or extreme weather events
- War, armed conflict, terrorism, civil unrest, or acts of a foreign enemy
- Cyberattacks or infrastructure failures by third-party providers
- Pandemics or public health emergencies
- Government restrictions, sanctions, or regulatory changes
Changes to This Privacy Policy Updated
We may update this Privacy Policy as required by changes in law, our services, or data processing activities. The current effective date is always shown at the top of this page.
For material changes — particularly those affecting the purposes for which we process your data, the legal bases we rely on, or your rights — we will notify active users with at least 14 days' advance notice before the change takes effect. Where the change affects processing based on your consent, we will seek a renewed opt-in rather than treating continued use as acceptance.
For minor or non-material updates (e.g., clarifications, formatting, or contact detail corrections), we will update the effective date and publish the revised policy. We encourage you to review this page periodically.
Contact Us
For questions about this Privacy Policy, to exercise your rights, or to raise a data protection concern, contact our Privacy Officer:
Email: [email protected]
Address: Gruttoweide 29, 3993DK Houten, Netherlands
KVK: 93377797
You also have the right to file a complaint with the Dutch supervisory authority: Autoriteit Persoonsgegevens.
Annex A: Data Processing Overview Updated
The table below summarises the categories of personal data we process, the purpose, legal basis, retention period, and parties with whom data is shared. Scroll horizontally on mobile.
| Category | Purpose | Legal Basis | Retention | Shared With |
|---|---|---|---|---|
| Account Data | Service delivery, security | Contractual Necessity | 3 yrs after last use | Internal, IT Providers |
| Health & Training Data | Safe & appropriate training delivery | Explicit Consent (Art. 9 GDPR) | Duration of training + 30 days | Internal only |
| Payment Data | Billing, fraud prevention | Legal Obligation | 7 yrs (tax law) | Payment Processors |
| Marketing Data | Promotions, newsletters | Consent | Until opt-out | Advertising Partners |
| Player Data (Clubs) Review | Training coordination | Legitimate InterestWhere data relates to minors or special categories, explicit consent from the club (warranted) is required. Legal basis should be reviewed per engagement. | Duration of contract | Basketball Clubs |
| Website Analytics | Performance monitoring | ConsentGoogle Analytics with IP anonymisation & Consent Mode active. | 24 months | Google Analytics |
| Media / Images | Coaching feedback, social media | Consent (portretrecht) | Until consent withdrawn | Internal, Social Platforms |
⚑ Rows marked Review indicate areas where the stated legal basis may require verification with a legal advisor depending on the specific data and engagement context.
