Maastrichter

Privacy Policy

Last updated: 6 August 2026

This Privacy Policy explains how Maastrichter processes personal data when you visit or use the websites maastrichter.com, maastrichter.nl, and maastrichter.eu (together, the “Website”), contact us, subscribe to our newsletter, create or use an account, subscribe to the Maastrichter Card, or otherwise use our services.

We process personal data in accordance with the General Data Protection Regulation (“GDPR”), the Dutch GDPR Implementation Act (Uitvoeringswet AVG), and applicable Dutch and EU cookie rules.

This Privacy Policy does not apply to third-party websites, services, events, booking platforms, payment providers, or social-media platforms linked from the Website. Please review the privacy information provided by those third parties before providing them with personal data.

1. Who is responsible for your personal data?

The controller responsible for processing personal data under this Privacy Policy is:

Goldenrod Consultancy (KVK number 72878584)
Trading as: Maastrichter
Havenstraat 14B
6211 GJ Maastricht
The Netherlands
Email: info@maastrichter.nl

2. Personal data we process

Depending on how you use the Website or our services, we may process the following categories of personal data:

  • Contact details, such as your name, email address, telephone number, and postal address where you provide them.

  • Information submitted through contact forms, newsletter subscriptions, account registration, competitions, promotions, reservations, or other service-related forms.

  • Communications between you and Maastrichter, including enquiries, support requests, and related correspondence.

  • Account information, such as your account credentials, account settings, login activity, and membership or card status.

  • Subscription information, such as your selected subscription, subscription status, start date, renewal date, cancellation status, and Maastrichter Card status.

  • Transaction and billing information, such as payment status, amount, currency, invoices, VAT information where applicable, refunds, chargebacks, and payment reference numbers.

  • Payment-provider information received from our payment service provider, such as payment confirmation, payment method type, transaction reference, and subscription status.

  • Fraud-prevention and account-security information, where necessary to protect accounts, prevent payment abuse, and investigate suspicious activity.

  • Technical and usage data, such as IP address, browser type, device information, pages viewed, date and time of access, referring website, and security or server-log information.

  • Cookie and consent-preference information, where applicable.

We do not intend to collect or store full payment-card numbers, card security codes, or CVV numbers. Payments should be processed through our payment provider’s hosted or embedded payment solution.

Please do not provide special-category personal data, such as health information, biometric data, political opinions, or information about religious beliefs, unless we specifically ask for it and provide an appropriate legal basis.

3. Why we process personal data and our legal bases

We process personal data only where we have a valid legal basis under the GDPR.

Purpose Categories of data Legal basis
Operating, maintaining, securing, and improving the Website Technical data, server logs, cookie preferences Legitimate interests in operating a secure, reliable, and user-friendly Website
Responding to messages, enquiries, and requests Contact details and correspondence Legitimate interests in responding to you; or taking steps at your request before entering into a contract
Creating and administering accounts, Maastrichter Card subscriptions, recurring payments, renewals, cancellations, customer support, and access to subscriber benefits Contact details, account information, subscription information, billing and transaction information, and relevant correspondence Performance of a contract; taking steps at your request before entering into a contract; and compliance with legal obligations where applicable
Issuing invoices, maintaining financial records, handling payment disputes, and meeting tax, accounting, or other legal obligations Billing, transaction, invoice, and account information Compliance with legal obligations and, where necessary, our legitimate interests in establishing, exercising, or defending legal claims
Preventing payment fraud, account misuse, and security incidents Account, technical, transaction, and fraud-prevention information Legitimate interests in protecting our users, services, and business; and compliance with legal obligations where applicable
Sending newsletters and promotional communications Name and email address, where collected Your consent
Measuring Website use through optional analytics technologies Technical and usage data Your consent, unless an applicable legal exemption applies
 

You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew consent.

4. Newsletter and marketing

We send newsletters and promotional communications only where you have subscribed or otherwise given valid consent, unless another lawful basis applies.

You may unsubscribe at any time by using the unsubscribe link in the relevant email or by contacting us at info@maastrichter.nl.

We may keep limited information, such as your email address and opt-out status, after you unsubscribe where necessary to ensure that we respect your request not to receive further marketing communications.

We do not use payment information for marketing unless you have separately consented to receive marketing communications or another valid legal basis applies.

5. Subscription, payments, and recurring billing

When you subscribe to the Maastrichter Card, we process the personal data necessary to create and manage your account, provide your subscription, collect recurring subscription payments, issue invoices where applicable, handle renewals and cancellations, provide customer support, and prevent fraud or misuse.

Payments are processed by Stripe. That payment provider processes payment information in accordance with its own privacy notice and terms. Maastrichter does not store full payment-card numbers or security codes where payments are processed through the provider’s hosted or embedded payment service.

We receive payment-related information necessary to administer your subscription, such as payment status, transaction reference, subscription status, amount paid, and relevant billing information.

Your subscription will renew automatically only where this has been clearly presented to you before you subscribe and is set out in the applicable subscription terms. You can manage or cancel your subscription through Membership Account – Maastrichter, subject to those terms.

6. Cookies and similar technologies

The Website uses cookies and similar technologies.

Strictly necessary cookies are used to operate, secure, and remember essential Website functions. These cookies do not require consent.

Optional cookies, including analytics, social-media, advertising, or similar technologies, are used only where you have given consent through our cookie settings, unless a specific technology is configured and used in a manner that does not require consent under applicable law.

You can accept, reject, or change your optional-cookie choices at any time through the Cookie Settings link or button on the Website. Rejecting optional cookies will not prevent you from accessing the core functions of the Website.

Optional Google Analytics, Meta/Facebook, Instagram, X/Twitter, or similar third-party technologies will not be activated before valid consent where consent is required.

Our cookie settings provide current details of each optional technology, including:

  • Provider;

  • Purpose;

  • Cookie category;

  • Duration; and

  • Whether data may be processed outside the European Economic Area (“EEA”).

7. Recipients and service providers

We may share personal data with carefully selected service providers where necessary to operate the Website and provide our services. These may include providers of:

  • Website hosting and technical support;

  • Email and newsletter delivery;

  • Website analytics;

  • Payment processing;

  • Invoicing, accounting, tax, and subscription management;

  • Account, card, booking, event, or reservation services;

  • Security, backup, and fraud-prevention services; and

  • Professional advisers, where necessary.

These providers may process personal data only on our instructions where they act as processors, unless they are independently responsible for their own processing.

Where a payment provider acts as an independent controller, it processes personal data according to its own privacy notice. Where a provider processes personal data on our behalf, we use an appropriate data-processing agreement where required by law.

We may also disclose personal data where required by law, a court order, or a competent public authority, or where disclosure is necessary to establish, exercise, or defend legal claims.

We do not sell personal data.

8. International data transfers

Where personal data is transferred outside the EEA, we will use an appropriate transfer mechanism required by applicable law. This may include an adequacy decision issued by the European Commission, the European Commission’s Standard Contractual Clauses, or another lawful safeguard.

Where relevant, you may request further information about applicable transfer safeguards by contacting us at info@maastrichter.nl.

9. How long we keep personal data

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

In general:

  • Website security and server logs are retained for 90 days, unless needed longer for a security investigation.

  • Contact requests and related correspondence are retained for 6 months after resolution.

  • Newsletter subscription information is kept until you unsubscribe or withdraw consent, subject to retaining minimal opt-out information where necessary.

  • Account, card, subscription, booking, event, and service information is retained for the duration of the relevant relationship and thereafter only for as long as necessary for customer support, payment disputes, fraud prevention, legal claims, and legal, accounting, or tax obligations.

  • Ordinary account and profile data should be deleted or anonymised after 24 months following account closure, unless longer retention is necessary for a stated purpose.

  • Invoices and legally required financial and tax records are retained for the applicable statutory retention period. In the Netherlands, relevant business-administration records are generally retained for 7 years.

  • Cookie data is retained for the period stated in the Cookie Settings tool.

10. Your privacy rights

Subject to the conditions and limits set out in the GDPR, you have the right to:

  • Request access to your personal data;

  • Request correction of inaccurate or incomplete personal data;

  • Request deletion of your personal data;

  • Request restriction of processing;

  • Object to processing based on our legitimate interests;

  • Withdraw consent where processing is based on consent;

  • Request data portability where applicable; and

  • Lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens.

To exercise your rights, contact us at info@maastrichter.nl.

We may ask for additional information only where reasonably necessary to verify your identity and protect your personal data. Do not send a copy of your passport or identity card unless we specifically explain why it is necessary and how it should be safely provided.

11. Security

We take appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure.

No internet-based service can guarantee absolute security. If we become aware of a personal-data breach that is likely to create a risk to individuals’ rights and freedoms, we will take the steps required under applicable law, including notification to the relevant authority and affected individuals where required.

12. Children

The Website and our services are not intended for children under the age of 16 unless we clearly state otherwise for a particular service or event and have an appropriate lawful basis for processing their personal data.

If you believe that a child has provided personal data to us without appropriate permission, please contact us at info@maastrichter.nl.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our processing activities, Website functionality, legal requirements, or security practices.

The most current version will always be available on the Website. Where a change is material, we will take appropriate steps to inform users where required by law.

14. Contact

For questions about this Privacy Policy or the processing of your personal data, contact:

Goldenrod Consultancy / Maastrichter
Havenstraat 14B
6211 GJ Maastricht
The Netherlands
Email: info@maastrichter.nl

Exit mobile version