FNDMNTL Basketball · Legal

Privacy Policy

KVK 93377797  ·  Effective: May 2026  ·  Houten, NL

01

Introduction

This Privacy Policy explains how FNDMNTL Basketball ("We/Us"), located at Gruttoweide 29, 3993DK, Houten, registered with the Dutch Chamber of Commerce under KVK 93377797, collects, uses, and protects your personal data ("Personal Data") in accordance with the General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (Uitvoeringswet AVG / UAVG).

We collect Personal Data when you request, purchase, use, or access our services and websites. For a detailed breakdown of data types, legal bases, retention periods, and third-party sharing, see Annex A.

FNDMNTL Basketball is a small-scale sports training business. We are not required to appoint a formal Data Protection Officer (DPO) under Article 37 GDPR. Data protection queries are handled by our designated Privacy Officer — see Section 16 for contact details.

02

Legal Basis for Processing Personal Data

We process Personal Data under the following legal bases as defined in Article 6 GDPR:

  • Contractual necessity — To provide our services (e.g., training sessions, user accounts, payments).
  • Legitimate interest — To improve services, conduct analytics, and prevent fraud, where these interests are not overridden by your rights.
  • Legal obligation — To comply with applicable Dutch and EU law, including tax obligations, court orders, and government requests.
  • Consent — For marketing communications, non-essential cookies, and the processing of personal data of minors. Where we rely on consent, you may withdraw it at any time without affecting prior processing.

Health and training-related data constitutes a special category of personal data under Article 9 GDPR. We process such data solely on the basis of your explicit consent, given for the purpose of delivering safe and appropriate training services. Where required by applicable law or where processing poses a high risk to your rights, we may carry out a Data Protection Impact Assessment (DPIA) prior to processing.

03

When & Why We Share Personal Data

We do not sell Personal Data. We share data only where necessary and only with the following categories of recipients:

  • Basketball Clubs — Where clubs provide player data to us, they warrant that they have obtained the required legal basis, including explicit consent where data relates to minors or special categories. Clubs fully indemnify FNDMNTL Basketball for any unauthorised data sharing.
  • Contractors & Service Providers — Including payment processors, IT security providers, cloud storage providers, and, where applicable, advertising networks. All providers are contractually required to comply with GDPR security standards and may only process data on our documented instructions.
  • Legal Authorities — To comply with applicable laws, court orders, or legitimate government requests.

See Annex A for full details of data-sharing arrangements.

04

International Data Transfers

If we transfer Personal Data outside the European Economic Area (EEA), we ensure adequate safeguards are in place, including:

  • EU Standard Contractual Clauses (SCCs) as approved by the European Commission
  • Transfers to countries covered by a European Commission Adequacy Decision

We do not transfer data to third countries without first verifying that the recipient provides an equivalent level of data protection.

05

Cookies & Tracking Technologies Updated

We use cookies and similar technologies on our websites. In line with the Dutch Telecommunications Act (Telecommunicatiewet) and the Autoriteit Persoonsgegevens cookie guidelines, we distinguish between:

  • Functional cookies — Essential for the website to operate. These do not require consent.
  • Analytical cookies — Used to measure performance and improve user experience (e.g., Google Analytics with IP anonymisation enabled and Consent Mode active). These require your prior consent. Analytics data is only collected after you have actively opted in.
  • Marketing cookies — Used for targeted advertising (e.g., Facebook Pixel). These require your explicit opt-in consent before being placed. Facebook Pixel is only activated after consent is given and cannot be used to track you prior to that point.
No non-essential cookies are placed before you have actively given consent. You may withdraw or change your cookie preferences at any time via our cookie settings. Refusing marketing or analytical cookies does not affect your ability to use our services.

For full details, refer to our Cookie Policy.

06

Data Retention

We retain Personal Data only as long as necessary for the purpose it was collected, or as required by law:

  • Customer & participant accounts — 3 years after last activity
  • Health & training data — Duration of the active training relationship, then deleted within 30 days unless explicit consent is given for longer retention
  • Payment records — 7 years (Dutch tax law, Article 52 AWR)
  • Marketing data — Until you opt out or withdraw consent
  • Website analytics — 24 months

When data is no longer required, we securely delete or anonymise it. See Annex A for the full retention schedule.

07

Security Measures

We implement appropriate technical and organisational measures to protect Personal Data against unauthorised access, loss, alteration, or misuse. Our measures include:

  • Role-based access controls and authorisation restrictions
  • Encrypted storage and transmission (TLS/SSL)
  • Regular security reviews and vulnerability assessments
  • Staff awareness and data handling procedures

Where we use automated tools or AI-assisted systems (e.g., for performance analytics), we ensure these comply with applicable EU AI Act requirements, including obligations around transparency and risk documentation.

08

Data Breach Notification Added

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR.

Where the breach is likely to result in a high risk to affected individuals, we will also notify those individuals directly without undue delay, providing a clear description of the breach, its likely consequences, and the measures taken or proposed to address it.

09

Your Rights

Under the GDPR, you have the following rights regarding your Personal Data. We will respond to all verified requests within one month of receipt (extendable by a further two months for complex requests, with prior notice):

AccessRequest a copy of the Personal Data we hold about you.
RectificationCorrect inaccurate or incomplete data.
ErasureRequest deletion of your data where no legal ground exists to retain it.
RestrictionLimit how we process your data under certain conditions.
PortabilityReceive your data in a structured, machine-readable format.
Withdraw ConsentWithdraw consent at any time where processing is consent-based.
ObjectObject to processing based on legitimate interest or direct marketing.
ComplaintLodge a complaint with the Autoriteit Persoonsgegevens.

To exercise any of these rights, contact us at [email protected]. We may ask for verification of your identity before processing your request.

10

Opt-Out & Marketing Preferences

You may opt out of marketing communications at any time by following the unsubscribe link in any marketing email or by contacting us directly. Opting out of marketing does not affect service-related communications (e.g., booking confirmations, session reminders).

11

Minors' Data Protection

Our services may be used by participants under the age of 18. In accordance with the UAVG, individuals under 16 years of age require verifiable parental or guardian consent before their personal data is processed, including for account creation, service delivery, and any health or training-related data.

Parents or legal guardians may request access to, rectification of, or deletion of their child's data at any time by contacting us at [email protected].

12

Third-Party Links & Content

Our websites may contain links to third-party websites or embed third-party content. We are not responsible for the privacy practices of those third parties. We recommend reviewing the relevant privacy policy before sharing Personal Data on any external platform.

13

Limitation of Liability Updated

To the extent permitted by applicable Dutch and EU mandatory law, FNDMNTL Basketball is not liable for indirect or consequential damages arising from Personal Data processing, unauthorised third-party access, or data misuse resulting from circumstances outside our reasonable control.

Nothing in this section limits or excludes any liability that cannot be excluded under applicable law, including your right to compensation for damages caused by a GDPR infringement under Article 82 GDPR.

14

Force Majeure Updated

We are not responsible for delays, security breaches, or data loss resulting from force majeure events beyond our reasonable control, including but not limited to:

  • Natural disasters or extreme weather events
  • War, armed conflict, terrorism, civil unrest, or acts of a foreign enemy
  • Cyberattacks or infrastructure failures by third-party providers
  • Pandemics or public health emergencies
  • Government restrictions, sanctions, or regulatory changes
This clause does not limit or override any obligations imposed on us by the GDPR or Dutch law, including our duty to notify the Autoriteit Persoonsgegevens and affected individuals in the event of a personal data breach. We will take all reasonable steps to contain and mitigate any data security impact and comply with applicable notification requirements, even in force majeure circumstances.
15

Changes to This Privacy Policy Updated

We may update this Privacy Policy as required by changes in law, our services, or data processing activities. The current effective date is always shown at the top of this page.

For material changes — particularly those affecting the purposes for which we process your data, the legal bases we rely on, or your rights — we will notify active users with at least 14 days' advance notice before the change takes effect. Where the change affects processing based on your consent, we will seek a renewed opt-in rather than treating continued use as acceptance.

For minor or non-material updates (e.g., clarifications, formatting, or contact detail corrections), we will update the effective date and publish the revised policy. We encourage you to review this page periodically.

16

Contact Us

For questions about this Privacy Policy, to exercise your rights, or to raise a data protection concern, contact our Privacy Officer:

FNDMNTL Basketball — Privacy Officer
Email: [email protected]
Address: Gruttoweide 29, 3993DK Houten, Netherlands
KVK: 93377797

You also have the right to file a complaint with the Dutch supervisory authority: Autoriteit Persoonsgegevens.

A

Annex A: Data Processing Overview Updated

The table below summarises the categories of personal data we process, the purpose, legal basis, retention period, and parties with whom data is shared. Scroll horizontally on mobile.

Category Purpose Legal Basis Retention Shared With
Account Data Service delivery, security Contractual Necessity 3 yrs after last use Internal, IT Providers
Health & Training Data Safe & appropriate training delivery Explicit Consent (Art. 9 GDPR) Duration of training + 30 days Internal only
Payment Data Billing, fraud prevention Legal Obligation 7 yrs (tax law) Payment Processors
Marketing Data Promotions, newsletters Consent Until opt-out Advertising Partners
Player Data (Clubs) Review Training coordination Legitimate InterestWhere data relates to minors or special categories, explicit consent from the club (warranted) is required. Legal basis should be reviewed per engagement. Duration of contract Basketball Clubs
Website Analytics Performance monitoring ConsentGoogle Analytics with IP anonymisation & Consent Mode active. 24 months Google Analytics
Media / Images Coaching feedback, social media Consent (portretrecht) Until consent withdrawn Internal, Social Platforms

⚑ Rows marked Review indicate areas where the stated legal basis may require verification with a legal advisor depending on the specific data and engagement context.

Search