Skip to main content

Privacy Policy

Last Updated: March 18, 2026

1. Introduction & Controller Identity

This Privacy Policy explains how Pimugo B.V. (“Pimugo”, “we”, “us”) collects, uses, and protects your personal data when you visit this website and when you contact us about our online education programs and workshops. Pimugo B.V. operates this website as an independent provider of online professional education for learners across Canada. Our services are delivered entirely online and are focused on workplace learning topics such as business administration, workplace communication, leadership development, project management, productivity improvement, organizational effectiveness, digital workplace competencies, and career development.

Data Controller (GDPR): Pimugo B.V., Veldwezeltstraat 82 A, 6215 JC Maastricht, Netherlands. You can contact us about privacy matters at [email protected] or by telephone at +31 43 782 1946.

Effective Date: March 18, 2026. This policy applies to the processing of personal data through this website, including any forms you submit to request information or registration support.

2. Personal Data We Collect

We collect personal data that you choose to provide and data that is collected automatically when you use the website. The exact data depends on how you interact with us (for example, reading content versus submitting a registration request).

  • Identity and contact data: name, email address, phone number, and any other contact details you provide.
  • Form submission content: the selected program, your message, questions, preferred timing, and any information you include in an “Additional comments” field.
  • Technical data: IP address, browser type and version, device information, operating system, language settings, and approximate location derived from IP (country/region level).
  • Usage data: pages viewed, time spent, referrer, click paths, and interactions such as opening navigation or reading page sections.
  • Cookies and identifiers: cookie identifiers and preference records as described in Section 4.
  • Conversion events: events such as form submissions or visits to specific pages (for example, a confirmation page after submission).

We do not request special-category data (such as health data, religious beliefs, political opinions), financial account details, or government identification numbers through our standard registration and contact forms. Please do not include such information in your messages.

3. Why We Process Data & Legal Basis (GDPR Article 6)

We process personal data only where we have a lawful basis under the GDPR. The purpose and basis may differ depending on whether the data is necessary for communication and registration support, or whether it is related to optional analytics or marketing activities.

  • Responding to contact and registration requests: We use your submission to answer questions, provide program information, and support registration steps. Legal basis: GDPR Art. 6(1)(b) (contract steps) and Art. 6(1)(a) (consent) where you provide information and request contact.
  • Website analytics (optional): If enabled based on your cookie preferences, we use analytics to understand how content is used so we can improve clarity, navigation, and educational information. Legal basis: GDPR Art. 6(1)(a) (consent).
  • Marketing and remarketing (optional): If enabled based on your cookie preferences, we may use marketing cookies to measure advertising performance and show relevant messages to users who have previously visited the website. Legal basis: GDPR Art. 6(1)(a) (consent).
  • Security and fraud prevention: We process technical data and logs to protect the website, prevent abuse, and maintain availability. Legal basis: GDPR Art. 6(1)(f) (legitimate interests).
  • Legal compliance: We may process information when required to comply with legal obligations. Legal basis: GDPR Art. 6(1)(c) (legal obligation).

Automated Decision-Making (GDPR Art. 22): We do not engage in automated decision-making or profiling that produces legal or similarly significant effects for you.

4. Cookies & Tracking

Cookies are small text files stored on your device. We use cookies and similar technologies (such as pixel tags) to keep the site functional, remember preferences, and—if you consent—measure usage and advertising performance. This section summarizes categories; the Cookie Policy provides a more detailed overview.

Essential cookies (always active)

Essential cookies are required for the website to function. They include cookies that maintain session continuity, store your cookie consent choice, and support basic security measures. These cookies do not require consent.

  • _site_session (session to 12 months depending on configuration): supports session continuity.
  • cookie_consent (12 months): stores your cookie preference selection.
  • CSRF and security controls: may be used to protect forms and prevent malicious requests.

Analytics cookies (consent required)

If you enable analytics cookies, we may use Google Analytics 4 (GA4) with IP anonymization features to understand site usage (for example, which pages are most read and how users navigate). Example cookies include _ga and _ga_XXXXXXXXXX. Analytics data retention is typically 14 months.

Marketing cookies (consent required)

If you enable marketing cookies, we may use cookies and pixel tags to measure advertising performance and to support remarketing. Example cookies include _gcl_au (Google Ads), _fbp (Meta), and _fbc (Meta, when a click identifier is present). These tools may also use device signals derived from IP address and browser information. Marketing cookies are used to attribute conversions and build audiences for advertising messages.

Beyond cookies: In addition to cookies, certain providers may use pixel tags (for example, Google tags or Meta Pixel) and server-side signals (for example, via Meta Conversion API or server-side tagging). Where used, these are governed by your consent choices for analytics and marketing.

5. Consent (EEA/UK)

Users in the EEA and UK receive a consent notice under GDPR/UK GDPR. Marketing and analytics cookies activate only after explicit, informed, freely given consent (GDPR Art. 6(1)(a)). Your choice is recorded in the cookie_consent browser cookie (12 months). You may withdraw consent at any time via “Manage cookie preferences” in the footer or by clearing cookies in your browser. Withdrawal does not affect the lawfulness of processing before the withdrawal.

6. Sharing With Advertising & Service Partners

We share data only as needed to operate the site, respond to requests, and—if you consent—run analytics and marketing measurement. We do not sell personal data.

  • Google LLC (Google Analytics 4, Google Ads, tagging/remarketing, where enabled by consent): cookie identifiers, usage data, and conversion events. Privacy policy: policies.google.com/privacy.
  • Meta Platforms (Pixel, Custom/Lookalike Audiences, Conversion API, where enabled by consent): page views, conversions, audience membership signals, and in some cases hashed identifiers for matching. Privacy policy: facebook.com/privacy/policy.
  • Cloudflare (CDN and security): IP-based threat detection and performance delivery. Privacy policy: cloudflare.com/privacypolicy.

We do not permit these providers to use site data for their own independent commercial purposes. Where third parties act as processors, they process personal data under contractual terms designed to protect data and limit use.

7. International Transfers

Pimugo B.V. is based in the Netherlands. Some of our service partners may process data outside the EEA/UK, including in the United States (for example, Google and Meta). When personal data is transferred internationally, we rely on appropriate safeguards, which may include:

  • EU–US Data Privacy Framework (primary, since July 2023), where applicable.
  • UK Extension to the EU–US Data Privacy Framework, where applicable.
  • Standard Contractual Clauses (EU 2021/914) as a fallback safeguard.
  • UK International Data Transfer Agreement (IDTA) as a fallback safeguard.

8. Retention

We keep personal data only for as long as needed for the purposes described in this policy, unless a longer retention period is required or permitted by law.

  • Contact and registration submissions: typically up to 2 years from last interaction, unless you request deletion earlier or we must keep records for legal reasons.
  • Email correspondence: typically for the duration of the relationship plus 1 year for continuity and reference.
  • Server and security logs: typically up to 90 days, unless needed for investigating abuse or incidents.
  • Analytics data: typically 14 months (where enabled by consent).
  • Marketing cookies: per cookie lifetime (for example, 90 days for certain marketing cookies), where enabled by consent.
  • Cookie consent records: typically up to 3 years for audit and compliance evidence.
  • Legal/tax: where required by law, typically 6–10 years for invoice-related records.

9. Your Rights (GDPR & UK GDPR)

If GDPR applies, you have rights regarding your personal data, including: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), and the right to withdraw consent (Art. 7(3)). You also have the right to lodge a complaint with a supervisory authority (Art. 77).

To exercise your rights, email [email protected]. We aim to respond within 30 days. For complex requests, the response time may be extended by up to 60 additional days where permitted by law.

Supervisory authority information (general references): European Data Protection Board: edpb.europa.eu. For the Netherlands, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) is the relevant supervisory authority for many cases.

10. Children

This website is not directed at individuals under 16. We do not knowingly collect personal data from minors. If we learn that we have collected personal data from a child under 16 without verifiable parental consent, we will delete it promptly.

11. Do Not Track

This website does not respond to “Do Not Track” (DNT) browser signals. Third-party providers may have their own handling of DNT and similar signals.

12. Data Deletion Requests

You can request deletion of your personal data by emailing [email protected] with the subject line “Data Deletion Request”. We may need to verify your identity before completing the request. We aim to complete deletion within 30 days, except where we must retain certain information to comply with legal obligations.

13. Business Transfers

If Pimugo B.V. is involved in a merger, acquisition, asset sale, financing, reorganization, insolvency, or similar event, personal data may be transferred to a successor entity. If such a transfer materially changes how personal data is used, we will provide notice on the website.

14. California (CCPA / CPRA)

Although Pimugo B.V. is based in the Netherlands, this section is provided for visitors from California where applicable. In the past 12 months, we may have collected: identifiers (such as name, email, IP address), internet/network activity (such as pages viewed), and inferences (such as interests derived from interactions). We disclose these categories to service providers and, where consent is given, to advertising partners for measurement and remarketing.

We do not sell personal information as defined by CCPA. We may share information for cross-context behavioral advertising when marketing cookies are enabled; California residents can opt out via our cookie preferences panel.

California rights may include: right to know, delete, correct, and opt-out of sale/sharing, and the right to non-discrimination. To submit a request, email [email protected] with the subject “California Privacy Request”. We will verify your identity before processing the request. Authorized agents must provide proof of authorization.

15. Virginia (VCDPA)

Where applicable, Virginia residents may have rights to access, correct, delete, and obtain a copy of their personal data, and to opt out of targeted advertising. We do not sell personal data or engage in profiling that produces legal or similarly significant effects.

To submit a request, email [email protected] with the subject “Virginia Privacy Request”. To appeal a refusal, use the subject “Appeal of Refusal — Privacy Request”. We respond to appeals within 60 days. If unresolved, you may contact the Virginia Attorney General.

16. Nevada

Nevada residents may submit a verified opt-out request by emailing [email protected] with the subject “Nevada Do Not Sell Request”. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. Material changes will be announced via a website notice at least 14 days before the updated policy takes effect. The “Last Updated” date at the top of this page will reflect the most recent revision.

18. Contact

If you have questions about this Privacy Policy or how we process personal data, contact:

Educational scope reminder

Pimugo B.V. provides educational services only. Website materials and program content are for educational and informational purposes and are not consulting, financial advice, legal advice, accounting, recruitment, employment placement, investment services, or regulated professional services.