Last updated 7 September 2026
Privacy & Cookies
This notice explains how European Paradox Academy BV handles personal data when you visit this website, contact us, or subscribe to our communications. It also explains the choices and rights available to you.
1. Who is responsible
European Paradox Academy BV is the controller of the personal data described in this notice. This means that we decide why and how that data is used.
European Paradox Academy BV Begijnenvest 88, 2000 Antwerp, BelgiumTo ask a privacy question or exercise a right, email niky.dieben@hotmail.com or use the contact form and say that it is a privacy or data-protection request. Please do not send sensitive information through the form. We may need enough information to confirm your identity before acting on a request.
2. Data we use, why we use it, and our legal bases
The data we receive depends on how you use the website. We do not ask for special-category data through our public forms.
You provide contact and subscription data directly. Information in published biographies, highlights, or images may come from the person concerned, an author, a public source, or another approved editorial source. Our website, browser technologies, and service providers generate the technical, security, analytics, and campaign data described below when the relevant feature is used.
| Activity and data | Purpose | Legal basis |
|---|---|---|
| Using the website: IP address, requested pages, date and time, referral information, browser, device, operating system, and technical or security logs. | Deliver the website, keep it reliable, diagnose errors, prevent abuse, and protect the service. | Our legitimate interests in operating and securing the website (GDPR Article 6(1)(f)). |
| Published people and editorial content: names, biographies, professional information, quotations, photographs or other media, source and editorial records, and related delivery/cache metadata. | Review, publish, maintain, correct, and deliver Academy content and preserve necessary editorial accountability. | The applicable basis is determined and documented for the particular item before publication: consent (Article 6(1)(a)), a contract or steps requested by the person (Article 6(1)(b)), or documented legitimate interests in relevant editorial and educational publication (Article 6(1)(f)). Any special-category or children's data requires a separate documented condition and safeguards. |
| Contacting us: name, email address, message, and related delivery and security information. | Receive, route, and respond to your inquiry and maintain a record where needed for follow-up. | Steps at your request before entering a contract, where applicable (Article 6(1)(b)); otherwise our legitimate interest in answering inquiries (Article 6(1)(f)). |
| Privacy and rights requests: the privacy-request purpose set automatically by the dedicated form, email address, optional name, message, delivery metadata and, during secure follow-up, proportionate identity or authority evidence, request scope, correspondence, search results, decisions and response records. | Route the request to restricted privacy staff, verify identity where needed, investigate and answer the request, and demonstrate how it was handled. | Compliance with our data-protection obligations (Article 6(1)(c)) and, where applicable, our legitimate interests in secure administration and legal claims (Article 6(1)(f)). Additional conditions apply if a case contains special-category data. |
| Newsletter: email address, subscription status, confirmation time and reference, notice version, notice language and source-bundle identifier, source, delivery status, unsubscribe status, and a short-lived pseudonymous confirmation state. | Send the communications you requested, administer your subscription, and honour unsubscribe requests. | Your consent (Article 6(1)(a)). You can withdraw it at any time through our unsubscribe link in any newsletter email . |
| Webinar registration: email address, event key and human-readable event label, registration status, confirmation time and reference, notice version, notice language and source-bundle identifier, source, delivery status, and a short-lived pseudonymous confirmation state. | Register you and send messages strictly needed to administer the webinar you requested. | Steps at your request to provide the registration (Article 6(1)(b)), or our legitimate interest in fulfilling that request (Article 6(1)(f)). Any unrelated marketing requires a separate opt-in. |
| Optional analytics: page views, events, approximate location derived from network information, device and browser details, and performance measurements. | Understand aggregate website use and improve performance and content. | Your consent (Article 6(1)(a)). Optional analytics do not load until you allow the Analytics category. |
| Optional marketing site tracking: a browser identifier, pages visited, campaign interactions, and associated contact information where ActiveCampaign can match the identifier to a subscriber. | Measure marketing and support campaign automations. | Your consent (Article 6(1)(a)). This tracking does not load until you allow the Marketing category. |
| Form security: reCAPTCHA token and interaction, device, browser, IP address, and risk signals received or assessed by Google. Rate-limit counters use keyed, pseudonymous representations of IP addresses and, for subscription forms, email addresses. | Detect automated submissions and protect our forms and systems from spam and abuse. | Our legitimate interest in service security and abuse prevention (Article 6(1)(f)). After you submit a protected form, the site first checks its own readiness without sending your form contents; reCAPTCHA starts only if that check succeeds. |
We may also use information when necessary to comply with a legal obligation (Article 6(1)(c)) or establish, exercise, or defend legal claims. We do not use the website data described here for decisions based solely on automated processing that produce legal or similarly significant effects.
Providing information is voluntary. The online contact and privacy request forms require a return email address and message; you can instead use the postal contact in section 1. We cannot create a newsletter subscription without an email address and confirmation, or register you for a webinar without an email address, event selection, and required registration acknowledgement. A name is optional. The security check is required to submit a protected form. Optional Analytics and Marketing tracking are not required to use the website or send a form.
After an accepted newsletter request, the screen says: “If the address can receive email, a confirmation link will arrive shortly. You are not subscribed unless you confirm within 24 hours.” The webinar screen uses the same conditional first sentence and says that registration is not active unless you confirm within 24 hours. This deliberately does not confirm that an address exists or that an email was delivered: the same accepted outcome can be shown after an email-delivery rejection or a private address-based request limit, or if the link token cannot be created. After the security check succeeds, these outcomes and a successful send are held behind the same minimum 17-second response period. The application waits for the email provider up to its bounded delivery deadline, so a slower send can take longer; it does not automatically retry an uncertain send. Nothing is activated unless a link arrives and you explicitly confirm it. An email-delivery or token-creation failure emits only a fixed operational signal for restricted monitoring; its payload excludes your email address, token, confirmation link, provider error, and caller-supplied context.
3. Service providers, recipients, and transfers
Access is limited to European Paradox Academy BV and vendors that need the data to provide their services. Those vendors may act as processors for us and, for some of their own activities, as independent controllers. Current services include:
- Contentful for website content management and delivery, including original assets served through its content delivery network;
- Combell for SMTP and email delivery when you contact us or request a newsletter subscription, webinar registration, or newsletter-withdrawal confirmation;
- ActiveCampaign for newsletter subscriptions and withdrawals, suppression and consent evidence, webinar registration, delivery administration, and optional consent-based site tracking;
- Vercel for website hosting and delivery and, where you consent, analytics and performance insights, including edge and optimized-image caching; and
- Upstash for short-lived, pseudonymous form abuse-prevention counters; confirmation replay, subject-lease, withdrawal-cutoff, and privacy-operation retry state; and encrypted subscription-reconciliation records shared across application instances;
- Google reCAPTCHA for form security and abuse detection after you interact with a protected form.
We may also disclose data where the law requires it, to competent authorities, or where necessary to protect legal rights. We do not sell personal data.
International transfers
Some vendors or their sub-processors may process data outside the European Economic Area. Where applicable, transfers must rely on a lawful safeguard such as an adequacy decision or Standard Contractual Clauses, together with supplementary measures where required. The location and safeguard can vary with each provider, sub-processor, and account configuration.
You can ask us which transfer safeguard applies to your data and how to obtain a copy by using the privacy contact details in section 1. Copies may be redacted where necessary to protect confidential information or the rights of others.
Controller responsibility: European Paradox Academy BV remains responsible for verifying vendor roles and locations, putting appropriate data-processing and transfer terms in place, configuring each service, and reviewing its retention and security settings. Naming a vendor or safeguard here does not claim that a vendor is certified, that every production setting has been independently audited, or that a particular transfer mechanism applies in every case.
4. How long we keep data
We keep personal data only for as long as needed for the purpose for which it was collected, taking account of legal, accounting, security, and dispute-resolution requirements. In particular:
- Contact inquiries are kept while we handle and resolve the inquiry, and afterwards only for as long as reasonably necessary for follow-up, legal obligations, or possible legal claims.
- Unconfirmed email links and browser state are accepted for no more than 24 hours after the request. The encrypted fragment link can be used during that window, while the temporary browser cookie is kept across a temporary retry response received before that request starts its update, so you can try again without requesting another email. Once an update starts, an error is terminal because repeating an update whose result is uncertain could be unsafe. The cookie is then cleared and you must request a fresh link. It is also cleared on success or a terminal missing, invalid, expired, or revoked result. Every temporary cookie expires with its link. The email itself and related SMTP, mailbox, security, and delivery logs follow their separately configured retention periods.
- Subscription-reconciliation records are created when a final subscription, webinar-registration, or newsletter-withdrawal update begins so an uncertain provider result can be resolved without blindly repeating the update. Each authenticated-encrypted record can contain your normalised email address, confirmation identifier, relevant list and consent or withdrawal details, and timestamps. A separate keyed-HMAC subject index lets authorised privacy staff find and delete these records without putting the raw email address in that index. A record is deleted after verified completion, an authorised subject purge, or expiry. Unresolved pending records use a configured period of 2–30 days; records moved to reviewed quarantine use a configured period of 7–90 days from that move. The exact production periods require documented approval, and encryption does not make these records anonymous.
- Newsletter records are needed while the subscription remains active. After you unsubscribe, delivery must stop; we may retain a minimal suppression or proof record for an approved period so that we respect your choice and do not re-add you unintentionally. The self-service unsubscribe changes only the newsletter-list delivery status and preserves the existing consent evidence; it does not create or reactivate a contact, erase other records, or change webinar registration or browser-tracking choices.
- Optional marketing-tracking records are separate from newsletter status. New collection stops when you withdraw Marketing consent. Previously collected provider-side history must be assessed under the approved marketing retention rule and any applicable erasure request; withdrawing consent does not by itself prove that historic provider data has already been deleted.
- Webinar registration records are kept while needed to administer the event and afterwards only for operational follow-up, legal obligations, or possible claims. They are not used to create a newsletter subscription.
- Your optional tracking preference is accepted for no more than six months, after which we ask again. An expired local-storage record may remain physically present until your next ordinary visit or until you clear browser storage, but the site ignores and removes it when the consent component next runs.
- Analytics, performance, security, and technical logs are retained for the shortest period needed for their purpose, subject to the retention options and operational requirements of the relevant provider account.
- Published content and images may remain in caches after correction or removal at the source. Our application invalidates its published-text cache when Contentful reports a change and also marks it stale after five minutes as a fallback; the first later request that triggers a refresh may still receive the prior version. Contentful delivery caches, Vercel/Next optimized-image or edge caches, and visitors' browser caches can have different periods. Where required, our erasure process must address controllable copies and record any remaining cache or backup period.
- Request and security rate-limit counters for forms, confirmation steps, restricted preview, and privacy operations expire within one hour. Redis keys contain keyed HMAC digests rather than raw IP or email addresses.
- Confirmation replay and revocation state uses purpose-separated, HMAC-keyed Redis records rather than raw email addresses or confirmation or privacy-operation IDs. A claimed link keeps a replay-prevention marker through its expiry, or through the later end of a fifteen-minute settlement window when it starts near expiry. A separate subject-mutation lease lasts no more than fifteen minutes and is removed after verified completion. While that lease exists, another final request is told when it may retry. If the lease is gone but the claim marker remains, the earlier result is treated as uncertain: the old link is not replayed, its cookie is cleared, a fixed identifier-free operational event is emitted, and a fresh link is required. Successful consumed state never outlives the link. A privacy operation may retain an email-derived cutoff until 24 hours after its five-minute clock-skew-adjusted effective time to reject older opt-in links, without blocking a newsletter withdrawal from deactivating a remaining contact. Its HMAC-keyed retry record contains pseudonymous operation and subject references, four timestamps, purge status, and the cumulative aggregate deletion count. It remains until 24 hours after the unchanged fifteen-minute final-settlement point so an uncertain retry cannot accidentally broaden the erasure scope. The API timestamps do not extend during that grace. This retry record remains personal data and must be covered by an approved retention rule. Stable retry and conflict detection end when it expires, so we never reuse an expired operation identifier and start any final purge retry with at least the fifteen-minute processing lease plus its one-minute route budget still available. Starting a valid final self-service newsletter-withdrawal attempt keeps a separate email-derived, newsletter-only cutoff until 24 hours after its five-minute clock-skew-adjusted effective time, including when later provider work fails. That cutoff rejects older newsletter opt-in links but does not block webinar confirmations.
- Backups and provider systems may retain limited copies for a further period before they are overwritten or deleted under the applicable provider schedule.
When data is no longer needed under an approved retention rule, our process requires deletion or irreversible anonymisation where supported, subject to documented legal holds and bounded provider backup periods. Actual provider periods depend on the production account settings that we are responsible for maintaining, verifying, and reviewing.
5. Cookies and similar browser technologies
A cookie is a small file stored by a website in your browser. Similar technologies include local storage and identifiers sent with network requests. Essential technologies support the service or remember your privacy choice. Analytics and marketing technologies are optional and remain off unless you consent.
| Technology or service | Category and purpose | When used and duration |
|---|---|---|
Privacy preference record (epa-tracking-consent-v3 local storage, epa_optional_tracking_denied cookie, and epa-optional-tracking-denied-session-v1 session storage) | Essential preference. Stores your category choices, an expiry time, and an identifier for the optional vendors and tracking account/host configuration covered by that choice. Denial-only cookie and session markers keep tracking off if browser storage cannot safely replace an older choice. | Created after you make a choice. The choice is accepted for no more than six months. The cookie expires within that period, while an expired local-storage record may remain until the next ordinary visit or browser clearing; it is then ignored and removed. The session marker ends when the browser session or that choice expires, whichever comes first. These records can be replaced when you change your settings. |
Email confirmation tokens (email-link fragment and request-specific HttpOnly cookies prefixed epa_subscription_confirmation_ for opt-in or epa_newsletter_unsubscribe_ for newsletter withdrawal) | Essential request processing. The encrypted, authenticated request reaches your browser in the email link's URL fragment, which is not sent with the link page's initial HTTP request. The page reads and removes that fragment, then sends it in a same-origin preparation request before storing it in a request-specific cookie. | The fragment is removed when the page prepares the request. Its matching cookie is created only after valid preparation and expires within 24 hours of the original request. It is kept across a temporary retry response and cleared on success or a terminal missing, invalid, expired, or revoked result. A failure after the request has started its update, or an old claimed link whose result can no longer be determined, also clears the cookie and requires a fresh link. Every such cookie expires with its link. |
Content preview session (__prerender_bypass cookie) | Essential restricted-editor session. Allows authorised users to view unpublished Contentful content. | Created only after valid preview authentication and cleared through Exit preview or at browser-session end, subject to the deployed Next.js cookie behaviour. |
| Vercel Analytics and Speed Insights | Optional Analytics. Sends usage and performance telemetry needed to measure visits and diagnose performance. The application removes URL query strings and fragments and drops telemetry for preview, subscription-confirmation, and newsletter-withdrawal paths. | Only after Analytics consent. Identifier use and telemetry retention depend on the deployed Vercel configuration. |
| ActiveCampaign site tracking | Optional Marketing. May set or read identifiers to connect website activity with campaigns and, where recognised, a contact record. | Only after Marketing consent. Identifier names and lifetimes are controlled by the deployed ActiveCampaign configuration and may change. |
| Google reCAPTCHA | Form security. Google may use cookies, local storage, and device or interaction signals to assess whether a submission is automated. It is not used here for optional Analytics or Marketing tracking. | Starts only after interaction with a protected form. Once loaded, Google's script and runtime can remain in that browser document until it is fully reloaded or closed. The exact post-token network and storage behaviour must be verified in the deployed service. Google controls the names and durations of its browser technologies under its policies and service settings. |
| Hosting and security technologies | Essential. Vercel and network providers process request information needed to deliver and protect the site. | During a request or session; related logs follow provider settings and the retention criteria above. |
Vendor updates and browser context can change the exact cookie or storage names. Your browser developer tools provide the current technical values for your visit.
Manage your choices
Use the Tracking preferences control at the bottom of the website to allow, reject, or later change optional categories. Withdrawing consent does not affect processing that was lawful before withdrawal. You can also remove stored browser data in your browser settings. These controls apply to this browser, device, and website origin; repeat the choice on other browsers, devices, or site origins. Blocking essential technologies may prevent a protected form from working.
Tracking preferences are separate from newsletter delivery. To stop newsletter delivery, use the unsubscribe link in any newsletter email . Every newsletter we send carries that link. Links from ordinary site pages use a fresh document load so previously enabled telemetry cannot carry into the withdrawal flow.
6. Your data protection rights
Subject to the GDPR conditions and exceptions, you may ask us to:
- give you access to your personal data;
- correct inaccurate or incomplete data;
- erase data;
- restrict how data is used;
- provide portable data where applicable;
- object to processing based on legitimate interests;
- object at any time to direct marketing; and
- withdraw consent at any time.
To withdraw newsletter consent, use the unsubscribe link in any newsletter email . To exercise another right, use our contact form, marking it as a privacy request. We normally respond within one month, although the GDPR permits an extension for complex or numerous requests. We will tell you if an extension applies. These rights are not absolute, and we will explain any lawful reason for refusing or limiting a request.
You may also lodge a complaint with the Belgian Data Protection Authority. See its official complaint guidance (opens in a new tab). You may contact another competent supervisory authority where the GDPR allows it.
7. Security and changes
We take proportionate technical and organisational measures to protect personal data. No website, transmission, or storage system can be guaranteed completely secure, so please do not send confidential or special-category information through the public contact form.
We will update this notice when our processing, providers, or legal obligations materially change. The date at the top shows the latest revision. This notice is a transparency statement; it is not a claim of regulatory or vendor certification.