Privacy Policy
Privacy Policy, ISH Dance Collective, last updated 20 July 2026
1. Introduction
ISH Dance Collective (“ISH”, “we”, “us”) attaches great importance to the protection of your personal data. In this privacy policy we explain which personal data we process, for what purpose, on what legal basis and for how long we retain it. You can also read which rights you have and how to exercise them. We process personal data in accordance with the General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act.
2. Who is responsible for the processing?
The controller for the processing of your personal data is:
- Stichting ISH (trading as ISH Dance Collective)
- Meer en Vaart 290
- 1068 LE Amsterdam, The Netherlands
- Telephone: +31 (0)20 46 85 422
- Email: info@ishdancecollective.com
- Chamber of Commerce no.: 34318021 · VAT no.: NL820136918B01
- ISH has not appointed a Data Protection Officer (DPO). For privacy questions you can contact us at info@ishdancecollective.com.
3. Which personal data do we process?
Depending on your relationship with ISH, we process the following categories of personal data, among others:
- Contact and identification data: name, email address, telephone number, (postal) address;
- Order and payment data when purchasing tickets or webshop products;
- Enrolment, attendance and progress data of participants in ISH Academy, school programmes and projects, and for all participants the contact details of a parent/guardian (an emergency contact for adult participants);
- Image material (photo and video) taken during classes, performances and events;
- Data of business relations, partners and programmers;
- Donation data of friends and donors;
- Job application data;
- Responses from visitor and user research;
- Technical and usage data of website visits (see the section on cookies).
4. Purposes and legal bases
We process personal data solely for the purposes set out below and always on the basis of a valid legal ground under the GDPR:
|
Purpose of processing |
Categories of data |
Legal basis (GDPR art. 6) |
|
Sending our newsletter and invitations |
Name, email address, preferences |
Consent |
|
Sale and delivery of tickets and webshop orders |
Name, contact details, order and payment data |
Performance of the contract |
|
Registration and organisation of Community and Talent activities (incl. Open Podia, ISH Open Nights) |
Name, contact details, Instagram account, motivation and plans |
Performance of the contract and/or consent |
|
Enrolment and delivery of ISH Academy classes, school programmes and projects |
Name, date of birth, contact details, attendance and progress; for all participants also contact details of a parent/guardian (or emergency contact) |
Performance of the contract; for minors, parental/guardian consent |
|
Safeguarding the safety and wellbeing of participants (e.g. allergies) |
Special category data (health), only if provided by you |
Explicit consent |
|
Photo and video recording during classes, performances and events for promotion and archiving |
Image material |
Consent (and, for minors, parental/guardian consent); see section 6 |
|
Visitor and user research to improve our website, performances and programming |
Usage and device data, survey responses, audience data |
Consent and/or legitimate interest |
|
Analysis and segmentation of our audience for programming and marketing |
Contact, order and usage data, possibly enriched with general (demographic) data |
Legitimate interest (and consent for cookies) |
|
Managing relationships with partners, programmers and business contacts |
Name, role, organisation, business contact details |
Legitimate interest |
|
Handling donations and friend-recruitment (ISH Foundation / ANBI) |
Name, contact details, donation data |
Performance of contract and/or legitimate interest |
|
Handling job applications |
Name, contact details, CV, motivation |
Consent and pre-contractual phase |
|
Analysis and improvement of our website |
IP address, device and usage data, cookie identifiers |
Consent (cookies) |
|
Compliance with legal obligations (incl. tax administration) |
Administrative and financial data |
Legal obligation |
5. Children’s data
Some of our activities — including ISH Academy, school programmes and youth programmes — are aimed at children and young people. For the processing of personal data of children under the age of 16 we ask for the consent of a parent or guardian; young people aged 16 and over we ask for their own consent. For making and publishing photo and video material in which a minor is recognisably depicted, we additionally ask for the consent of a parent or guardian. A parent or guardian, or the young person, can view, change or withdraw the consent given at any time via info@ishdancecollective.com.
We record consent for making and using photo and video material when registering for ISH Academy (Studio ISH, Young ISH and Junior ISH) through a mandatory choice on the registration form: the participant or, for minors, the parent or guardian indicates whether image material may be made and used for promotional purposes (website, newsletter, social media and print) during auditions and participation, or refuses this. For all Academy participants we also collect the contact details of a parent/guardian (for adult participants as an emergency contact); for participants under 16 the parent or guardian gives the consent, while participants aged 16 and over may do so themselves. The choice made is stored with the registration. You can change or withdraw a given choice later via info@ishdancecollective.com.
6. Photo and video material
During classes, performances and events we take photos and video recordings for archiving, promotion and communication. This image material may be published on the website and social media channels of ISH and of our partners.
Would you prefer not to be recognisably depicted? Please let the photographer, videographer or an ISH staff member know beforehand, or contact us in advance at info@ishdancecollective.com. For image material of children, the consent of the parent or guardian applies (see section 5). Please note that we have no control over recordings made by others, such as fellow visitors. You can also withdraw consent given earlier via email.
7. Cookies and similar techniques
Our website uses cookies and similar techniques, including via Google Tag Manager. We distinguish the following categories:
- Functional cookies — necessary for the website to work; no consent required;
- Analytical cookies — including Google Analytics (GA4), to measure website visits and improve the site;
- Statistics and session cookies — including Microsoft Clarity, which we use to analyse visitors’ mouse, click and scroll behaviour to improve the website;
- Social media cookies — placed via embedded content from YouTube, TikTok and Instagram (third-party cookies);
- Marketing and advertising cookies — including the Meta pixel, the TikTok pixel and the Snapchat pixel, to tailor advertising to your interests and measure reach;
For analytical, social media and marketing cookies we ask for your prior consent via the cookie notice. You can adjust or withdraw your consent at any time via our website. A complete and up-to-date overview of the cookies used can be found in our 【reference to the separate cookie statement】.
8. With whom do we share data?
We only share your personal data with third parties where this is necessary for the purposes described above or where we are legally required to do so. We conclude a data processing agreement with parties that process data on our behalf (processors).
|
Recipient / processor |
Purpose |
Notes |
|
Notion |
Central workspace and storage of contacts, participants and project data |
Processor; outside the EEA (US) |
|
Dropbox |
File storage (incl. HR and participant data) |
Processor; outside the EEA (US); in use until 31 December 2026, then replaced by Google Drive |
|
MailerLite |
Sending the newsletter |
Processor |
|
Ticket Tailor |
Sale and management of tickets |
Processor; based in the UK (EU adequacy decision) |
|
Google (Workspace, Tag Manager, Analytics) |
Communication, document storage and website analysis |
Processor; outside the EEA (US) |
|
Microsoft Clarity |
Analysis of user behaviour on the website (heatmaps, session recordings) |
Processor; outside the EEA (US) |
|
Make.com |
Automation and integrations between systems |
Processor; based in the EU (EU hosting) |
|
Anthropic (Claude) |
AI support within internal workflows (e.g. summaries, invoice assistance) |
Processor; outside the EEA (US) |
|
Granola |
AI meeting notes for internal and external meetings |
Processor; outside the EEA (US) |
|
Meta, TikTok, Snapchat, YouTube/Google (advertising and social media platforms) |
Social media, advertising and reach |
Partly independent controllers; outside the EEA |
|
Studio TOMIS (ProcessWire) |
Hosting and maintenance of the website |
Processor; based in the Netherlands |
|
Rabobank |
Processing of payments |
Independent controller; based in the Netherlands |
|
Twinfield / Zenvoices |
Bookkeeping and invoice processing |
Processor; based in the EU |
|
Bookkeeping office Ozcar |
Financial administration and bookkeeping |
Processor; based in the Netherlands |
|
Accountancy firm Kamphuis & Berghuizen |
Statutory audit and annual accounts |
Independent controller for statutory tasks |
9. Transfer outside the European Economic Area (EEA)
Several of our service providers (such as Google, Meta, TikTok, Snapchat, Notion and Anthropic) are based in, or process data outside, the EEA. When personal data is processed outside the EEA, we ensure appropriate safeguards, for example via the EU-US Data Privacy Framework or the European Commission’s Standard Contractual Clauses.
10. How long do we retain data?
We do not retain personal data longer than necessary for the purposes for which it was collected, or for as long as we are legally required to. For inactive relations we apply a maximum retention period of five years. We apply the following retention periods, among others:
|
Type of data |
Retention period |
|
Inactive relations (no use of our services during that period) |
Maximum of 5 years; you will receive a notification before deletion |
|
Financial and administrative data (invoices, orders) |
7 years (statutory tax retention obligation) |
|
Newsletter data |
Until consent is withdrawn (unsubscribe) |
|
Job application data |
Up to 1 year after the procedure (with the applicant’s consent) |
|
Data of Academy participants |
Duration of participation plus 1 year |
|
Image material |
Indefinitely, as part of our (cultural-historical) archive; you can always object or request erasure. |
11. Security
We take appropriate technical and organisational measures to protect your personal data against loss, misuse and unauthorised access, such as access controls, secure connections and arrangements with our suppliers. In the unlikely event of a data breach, we act in accordance with our statutory notification obligations.
12. Your rights
Under the GDPR you have the following rights regarding your personal data:
- The right of access to the data we process about you;
- The right to rectification of inaccurate or incomplete data;
- The right to erasure (“right to be forgotten”);
- The right to restriction of processing;
- The right to object to processing;
- The right to data portability;
- The right to withdraw previously given consent at any time.
You can send a request to exercise these rights to info@ishdancecollective.com. We will respond within one month in principle. To verify that the request was made by you, we may ask you to identify yourself in a way that respects your privacy.
13. Filing a complaint
If you disagree with how we handle your personal data, we would like to hear from you at info@ishdancecollective.com. You also always have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) via www.autoriteitpersoonsgegevens.nl.
14. Links to other websites
Our website may contain links to third-party websites. We have no control over these websites and are not responsible for their content or privacy protection. We recommend that you read the privacy policy of those websites.
15. Automated decision-making
We do not make decisions with legal or similarly significant effects based solely on automated processing.
16. Changes to this privacy policy
We may amend this privacy policy from time to time, for example in the event of changes to our practices or to laws and regulations. The most current version is always available on this page. This policy was last amended on 20 July 2026.