Privacy policy

Last updated: July 2026

Dune Callantsoog attaches great importance to protecting your personal data. In this privacy statement we explain which data we collect, why we do so and what rights you have. We process personal data in accordance with the General Data Protection Regulation (GDPR).

Draft — please have this text reviewed by a lawyer before publication. Everything in [square brackets] still needs to be completed.

1. Who are we?

Data controller:

  • [Company name / owner name]
  • [Address], [Postcode] Callantsoog
  • KvK number: [number]
  • Email: [email address]
  • Phone: [phone number]

2. Which personal data do we process?

Depending on your use of our website and services, we process the following.

For a booking or booking request:

  • first and last name;
  • address and place of residence;
  • email address and phone number;
  • date of birth [if required for tourist tax / guest register];
  • number of guests and stay dates;
  • payment details (bank account number for transfers; we do not store credit card details);
  • any preferences or particulars you pass on to us yourself.

When using the contact form or email: name, email address, phone number and the content of your message.

When visiting our website: IP address, browser type, device data and browsing behaviour on our site (via cookies, see article 8).

We do not process special categories of personal data (such as health data), unless you provide these voluntarily yourself (for example information about a disability in connection with accessibility).

3. Why do we use your data and on what legal basis?

Handling and confirming your booking, communication about your stay Performance of the contract (art. 6(1)(b))
Payment processing and invoicing Performance of the contract (art. 6(1)(b))
Remitting tourist tax and [keeping a guest register] Legal obligation (art. 6(1)(c))
Tax administration and retention obligation Legal obligation (art. 6(1)(c))
Answering questions via contact form, email or phone Legitimate interest (art. 6(1)(f))
Sending a newsletter or offers [if applicable] Consent (art. 6(1)(a))
Asking for a review after your stay [if applicable] Legitimate interest (art. 6(1)(f))
Analytical cookies and website improvement Consent, or legitimate interest with privacy-friendly settings (art. 6(1)(a)/(f))
Handling damage, complaints or disputes Legitimate interest (art. 6(1)(f))

You are not obliged to provide your data, but without the data required for the booking we cannot enter into an agreement with you.

4. How long do we keep your data?

We do not keep personal data longer than necessary:

  • Booking and invoice data: 7 years (Dutch tax retention obligation);
  • [Guest register data]: [statutory municipal period, usually 1 year];
  • Contact form / correspondence without a booking: no more than [1 year] after the last contact;
  • Newsletter data: until you unsubscribe;
  • Cookie data: see the retention periods in article 8.

After the retention period has expired, data is deleted or anonymised.

5. Who do we share your data with?

We never sell your data to third parties. We only share data insofar as necessary with:

  • [Booking platform/system] – for processing reservations;
  • [Payment service provider, e.g. Mollie/bank] – for processing payments;
  • [Website host] – for hosting our website and email;
  • [Accountant/administration office] – for financial administration;
  • Municipality of [Schagen] – for remitting tourist tax, insofar as legally required;
  • Government authorities – only if we are legally obliged to do so.

With parties acting as processors on our behalf, we conclude a data processing agreement in accordance with the GDPR.

Transfer outside the EEA: in principle we process your data within the European Economic Area. Insofar as service providers process data outside the EEA [e.g. Google Analytics], this only takes place on the basis of appropriate safeguards, such as an adequacy decision (including the EU-US Data Privacy Framework) or standard contractual clauses of the European Commission.

6. How do we secure your data?

We take appropriate technical and organisational measures to protect your data against loss, misuse and unauthorised access, including:

  • a secure website connection (SSL/https);
  • secure storage of records with restricted access;
  • strong passwords and two-factor authentication where possible;
  • data processing agreements with external service providers.

Despite these measures, no processing can be 100% secure. Do you suspect misuse of your data? Please contact us immediately at [email address].

7. Your rights

Under the GDPR you have the following rights:

  • Access: request which data we process about you;
  • Rectification: have incorrect or incomplete data corrected;
  • Erasure: have your data deleted, insofar as no statutory retention obligation applies;
  • Restriction: have the processing temporarily restricted;
  • Objection: object to processing based on legitimate interest and to direct marketing;
  • Portability: receive your data in a common, machine-readable format;
  • Withdraw consent: withdraw consent given earlier (e.g. for the newsletter) at any time, without affecting the lawfulness of earlier processing.

You can send your request to [email address]. We respond within one month. To make sure the request was made by you, we may ask for additional information to verify your identity; never send an unsolicited copy of your ID.

Are you unhappy with how we handle your data? You have the right to lodge a complaint with the Dutch Data Protection Authority (www.autoriteitpersoonsgegevens.nl). We would appreciate it if you contact us first, so that we can look for a solution together.

8. Cookies

Our website uses cookies: small text files stored on your device.

Functional cookies (always active) — necessary for the website to work properly, for example for the booking form. No consent is required for these.

Analytical cookies [if applicable] — we use [Google Analytics, configured privacy-friendly: IP addresses anonymised, data sharing disabled, processing agreement concluded] to understand how visitors use our website. Retention period: [X months].

Marketing/tracking cookies [if applicable] — third-party cookies, such as the [Facebook/Instagram pixel], are only placed with your prior consent via the cookie banner.

You can adjust your cookie preferences at any time via [link to cookie settings] and delete cookies via your browser settings.

9. Third-party websites

Our website may contain links to third-party websites (such as booking platforms or social media). This privacy statement does not apply to those websites. Please consult the privacy statement of the party concerned.

10. Minors

Our services are aimed at persons aged 18 and over. We do not knowingly collect data from minors without the consent of a parent or guardian. Do you believe we have processed data of a minor without such consent? Please contact us and we will delete this data.

11. Changes

We may amend this privacy statement from time to time, for example in the event of changes to our services or legislation. The current version is always available on our website. In the event of substantial changes we will inform you actively. This version was last amended on [date].

12. Contact

Questions about this privacy statement or about your data?

  • Dune Callantsoog
  • [Address] • [Postcode] Callantsoog
  • [email address] • [phone number]

Please take a moment to read this. Any questions? Feel free to get in touch.