cursor

Privacy Policy

Privacy Policy, ISH Dance Collective, last updated 20 July 2026

1. Introduction

ISH Dance Collective (“ISH”, “we”, “us”) attaches great importance to the protection of your personal data. In this privacy policy we explain which personal data we process, for what purpose, on what legal basis and for how long we retain it. You can also read which rights you have and how to exercise them. We process personal data in accordance with the General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act.

2. Who is responsible for the processing?

The controller for the processing of your personal data is:

  • Stichting ISH (trading as ISH Dance Collective)
  • Meer en Vaart 290
  • 1068 LE Amsterdam, The Netherlands
  • Telephone: +31 (0)20 46 85 422
  • Email: info@ishdancecollective.com
  • Chamber of Commerce no.: 34318021 · VAT no.: NL820136918B01
  • ISH has not appointed a Data Protection Officer (DPO). For privacy questions you can contact us at info@ishdancecollective.com.

3. Which personal data do we process?

Depending on your relationship with ISH, we process the following categories of personal data, among others:

  • Contact and identification data: name, email address, telephone number, (postal) address;
  • Order and payment data when purchasing tickets or webshop products;
  • Enrolment, attendance and progress data of participants in ISH Academy, school programmes and projects, and for all participants the contact details of a parent/guardian (an emergency contact for adult participants);
  • Image material (photo and video) taken during classes, performances and events;
  • Data of business relations, partners and programmers;
  • Donation data of friends and donors;
  • Job application data;
  • Responses from visitor and user research;
  • Technical and usage data of website visits (see the section on cookies).

4. Purposes and legal bases

We process personal data solely for the purposes set out below and always on the basis of a valid legal ground under the GDPR:

Purpose of processing

Categories of data

Legal basis (GDPR art. 6)

Sending our newsletter and invitations

Name, email address, preferences

Consent

Sale and delivery of tickets and webshop orders

Name, contact details, order and payment data

Performance of the contract

Registration and organisation of Community and Talent activities (incl. Open Podia, ISH Open Nights)

Name, contact details, Instagram account, motivation and plans

Performance of the contract and/or consent

Enrolment and delivery of ISH Academy classes, school programmes and projects

Name, date of birth, contact details, attendance and progress; for all participants also contact details of a parent/guardian (or emergency contact)

Performance of the contract; for minors, parental/guardian consent

Safeguarding the safety and wellbeing of participants (e.g. allergies)

Special category data (health), only if provided by you

Explicit consent

Photo and video recording during classes, performances and events for promotion and archiving

Image material

Consent (and, for minors, parental/guardian consent); see section 6

Visitor and user research to improve our website, performances and programming

Usage and device data, survey responses, audience data

Consent and/or legitimate interest

Analysis and segmentation of our audience for programming and marketing

Contact, order and usage data, possibly enriched with general (demographic) data

Legitimate interest (and consent for cookies)

Managing relationships with partners, programmers and business contacts

Name, role, organisation, business contact details

Legitimate interest

Handling donations and friend-recruitment (ISH Foundation / ANBI)

Name, contact details, donation data

Performance of contract and/or legitimate interest

Handling job applications

Name, contact details, CV, motivation

Consent and pre-contractual phase

Analysis and improvement of our website

IP address, device and usage data, cookie identifiers

Consent (cookies)

Compliance with legal obligations (incl. tax administration)

Administrative and financial data

Legal obligation

5. Children’s data

Some of our activities — including ISH Academy, school programmes and youth programmes — are aimed at children and young people. For the processing of personal data of children under the age of 16 we ask for the consent of a parent or guardian; young people aged 16 and over we ask for their own consent. For making and publishing photo and video material in which a minor is recognisably depicted, we additionally ask for the consent of a parent or guardian. A parent or guardian, or the young person, can view, change or withdraw the consent given at any time via info@ishdancecollective.com.

We record consent for making and using photo and video material when registering for ISH Academy (Studio ISH, Young ISH and Junior ISH) through a mandatory choice on the registration form: the participant or, for minors, the parent or guardian indicates whether image material may be made and used for promotional purposes (website, newsletter, social media and print) during auditions and participation, or refuses this. For all Academy participants we also collect the contact details of a parent/guardian (for adult participants as an emergency contact); for participants under 16 the parent or guardian gives the consent, while participants aged 16 and over may do so themselves. The choice made is stored with the registration. You can change or withdraw a given choice later via info@ishdancecollective.com.

6. Photo and video material

During classes, performances and events we take photos and video recordings for archiving, promotion and communication. This image material may be published on the website and social media channels of ISH and of our partners.

Would you prefer not to be recognisably depicted? Please let the photographer, videographer or an ISH staff member know beforehand, or contact us in advance at info@ishdancecollective.com. For image material of children, the consent of the parent or guardian applies (see section 5). Please note that we have no control over recordings made by others, such as fellow visitors. You can also withdraw consent given earlier via email.

7. Cookies and similar techniques

Our website uses cookies and similar techniques, including via Google Tag Manager. We distinguish the following categories:

  • Functional cookies — necessary for the website to work; no consent required;
  • Analytical cookies — including Google Analytics (GA4), to measure website visits and improve the site;
  • Statistics and session cookies — including Microsoft Clarity, which we use to analyse visitors’ mouse, click and scroll behaviour to improve the website;
  • Social media cookies — placed via embedded content from YouTube, TikTok and Instagram (third-party cookies);
  • Marketing and advertising cookies — including the Meta pixel, the TikTok pixel and the Snapchat pixel, to tailor advertising to your interests and measure reach;

For analytical, social media and marketing cookies we ask for your prior consent via the cookie notice. You can adjust or withdraw your consent at any time via our website. A complete and up-to-date overview of the cookies used can be found in our reference to the separate cookie statement.

8. With whom do we share data?

We only share your personal data with third parties where this is necessary for the purposes described above or where we are legally required to do so. We conclude a data processing agreement with parties that process data on our behalf (processors).

Recipient / processor

Purpose

Notes

Notion

Central workspace and storage of contacts, participants and project data

Processor; outside the EEA (US)

Dropbox

File storage (incl. HR and participant data)

Processor; outside the EEA (US); in use until 31 December 2026, then replaced by Google Drive

MailerLite

Sending the newsletter

Processor

Ticket Tailor

Sale and management of tickets

Processor; based in the UK (EU adequacy decision)

Google (Workspace, Tag Manager, Analytics)

Communication, document storage and website analysis

Processor; outside the EEA (US)

Microsoft Clarity

Analysis of user behaviour on the website (heatmaps, session recordings)

Processor; outside the EEA (US)

Make.com

Automation and integrations between systems

Processor; based in the EU (EU hosting)

Anthropic (Claude)

AI support within internal workflows (e.g. summaries, invoice assistance)

Processor; outside the EEA (US)

Granola

AI meeting notes for internal and external meetings

Processor; outside the EEA (US)

Meta, TikTok, Snapchat, YouTube/Google (advertising and social media platforms)

Social media, advertising and reach

Partly independent controllers; outside the EEA

Studio TOMIS (ProcessWire)

Hosting and maintenance of the website

Processor; based in the Netherlands

Rabobank

Processing of payments

Independent controller; based in the Netherlands

Twinfield / Zenvoices

Bookkeeping and invoice processing

Processor; based in the EU

Bookkeeping office Ozcar

Financial administration and bookkeeping

Processor; based in the Netherlands

Accountancy firm Kamphuis & Berghuizen

Statutory audit and annual accounts

Independent controller for statutory tasks

9. Transfer outside the European Economic Area (EEA)

Several of our service providers (such as Google, Meta, TikTok, Snapchat, Notion and Anthropic) are based in, or process data outside, the EEA. When personal data is processed outside the EEA, we ensure appropriate safeguards, for example via the EU-US Data Privacy Framework or the European Commission’s Standard Contractual Clauses.

10. How long do we retain data?

We do not retain personal data longer than necessary for the purposes for which it was collected, or for as long as we are legally required to. For inactive relations we apply a maximum retention period of five years. We apply the following retention periods, among others:

Type of data

Retention period

Inactive relations (no use of our services during that period)

Maximum of 5 years; you will receive a notification before deletion

Financial and administrative data (invoices, orders)

7 years (statutory tax retention obligation)

Newsletter data

Until consent is withdrawn (unsubscribe)

Job application data

Up to 1 year after the procedure (with the applicant’s consent)

Data of Academy participants

Duration of participation plus 1 year

Image material

Indefinitely, as part of our (cultural-historical) archive; you can always object or request erasure.

11. Security

We take appropriate technical and organisational measures to protect your personal data against loss, misuse and unauthorised access, such as access controls, secure connections and arrangements with our suppliers. In the unlikely event of a data breach, we act in accordance with our statutory notification obligations.

12. Your rights

Under the GDPR you have the following rights regarding your personal data:

  1. The right of access to the data we process about you;
  2. The right to rectification of inaccurate or incomplete data;
  3. The right to erasure (“right to be forgotten”);
  4. The right to restriction of processing;
  5. The right to object to processing;
  6. The right to data portability;
  7. The right to withdraw previously given consent at any time.

You can send a request to exercise these rights to info@ishdancecollective.com. We will respond within one month in principle. To verify that the request was made by you, we may ask you to identify yourself in a way that respects your privacy.

13. Filing a complaint

If you disagree with how we handle your personal data, we would like to hear from you at info@ishdancecollective.com. You also always have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) via www.autoriteitpersoonsgegevens.nl.

14. Links to other websites

Our website may contain links to third-party websites. We have no control over these websites and are not responsible for their content or privacy protection. We recommend that you read the privacy policy of those websites.

15. Automated decision-making

We do not make decisions with legal or similarly significant effects based solely on automated processing.

16. Changes to this privacy policy

We may amend this privacy policy from time to time, for example in the event of changes to our practices or to laws and regulations. The most current version is always available on this page. This policy was last amended on 20 July 2026.

Show: