Skip to main content

Privacy Policy

Last Updated: March 14, 2026

This Privacy Policy explains how Vbg B.V. (“we”, “us”) collects, uses, and protects personal data when you visit envarlok.site (the “Site”) and when you contact us about calligraphy practice modules, learning materials, or other educational requests. We run a small educational platform: we provide learning content and practice guidance only. We do not provide regulated professional services, and we do not request sensitive categories of personal data as part of normal learning use.

1. Introduction & Controller Identity

Under the EU General Data Protection Regulation (GDPR), Vbg B.V. is the data controller for personal data processed through the Site. That means we decide why and how personal data is processed for the purposes described in this Privacy Policy.

We do not appoint a Data Protection Officer (DPO) because we do not conduct large-scale monitoring or large-scale processing of special-category data. If you have privacy questions, you can contact us using the details above.

2. Personal Data We Collect

The Site is designed to be usable without creating an account. Personal data is collected primarily when you contact us and when your browser communicates with the Site.

2.1 Data you provide to us

  • Identity and contact details: name (if provided), email address, and phone number (only if you choose to include it).
  • Form content: the message you send, including practice details such as tools used (paper type, ink, nib), what you are observing (for example, railroading, feathering, baseline drift), and what module you want to start with.
  • Consent records: your confirmation that you agree to our Privacy Policy and consent to be contacted.

2.2 Data collected automatically

  • Technical data: IP address, browser type/version, device type, operating system, language, and approximate location derived from IP (country/region level).
  • Usage data: pages viewed, time spent, interactions (for example, which module pages are opened), referrer URL, and click paths.
  • Cookies and identifiers: essential cookies that keep the site functional and remember cookie choices, and (if you consent) analytics and marketing identifiers. See Section 4.
  • Conversion events: events that indicate that a form was submitted or a key page was reached. These are used to understand whether learning pages and requests are working as intended.

2.3 Data we do not intentionally collect

We do not intentionally collect special-category data (such as health data, religious beliefs, political opinions), financial account details, or government identification numbers through our normal learning pages or contact form. Please do not include such information in messages to us. If you accidentally provide it, we will handle it with care and delete it where feasible.

3. Why We Process Personal Data & Legal Bases (GDPR Art. 6)

We process personal data only for specific, limited purposes and based on a lawful basis under GDPR.

  • Contact and support: to read and respond to your message, suggest a starting module order, and answer questions about the learning format.
    Legal basis: Art. 6(1)(b) (steps prior to entering into a contract) and Art. 6(1)(a) (consent, where applicable).
  • Site analytics (optional): to understand how pages are used and to improve clarity of learning content.
    Legal basis: Art. 6(1)(a) (consent).
  • Marketing and remarketing (optional): to measure conversions and show relevant ads to people who have interacted with learning pages.
    Legal basis: Art. 6(1)(a) (consent).
  • Security and fraud prevention: to protect the Site from abuse, spam submissions, and suspicious traffic.
    Legal basis: Art. 6(1)(f) (legitimate interests in maintaining a secure service).
  • Legal compliance: to comply with legal obligations (for example, responding to lawful requests).
    Legal basis: Art. 6(1)(c) (legal obligation).

Automated decision-making (Art. 22): We do not engage in automated decision-making or profiling that produces legal or similarly significant effects.

4. Cookies & Tracking

Cookies are small text files stored on your device. The Site also may use similar technologies (such as pixel tags) depending on your consent choices. We group cookies into three categories: essential, analytics, and marketing. Essential cookies are always active because the Site cannot function properly without them. Analytics and marketing cookies are optional and require your explicit consent.

4.1 Essential cookies (always on)

Essential cookies enable core site functions, such as maintaining basic session continuity and remembering your cookie preferences. They do not require consent under applicable EU rules when strictly necessary for the service.

  • _site_session (first-party): continuity and basic site operation. Retention: session to 7 days depending on browser behavior.
  • cookie_consent (first-party): stores your cookie choices. Retention: 12 months.

4.2 Analytics cookies (consent required)

If you consent to analytics cookies, we may use Google Analytics 4 (GA4) to understand aggregated site usage (for example, which learning pages are most helpful, which glossary entries are confusing, or where visitors stop reading). IP anonymization is used where supported. Retention for analytics data is set to 14 months.

  • _ga (third-party): GA4 user identifier. Typical retention: 2 years.
  • _ga_XXXXXXXXXX (third-party): GA4 session state. Typical retention: 2 years.

4.3 Marketing cookies (consent required)

If you consent to marketing cookies, we may use Google Ads and Meta technologies to measure conversions and show relevant educational ads (for example, a module page you viewed). These cookies help with attribution (understanding which ad led to a contact request) and with audience creation (for example, remarketing or lookalike audiences).

  • _gcl_au (third-party): Google Ads conversion linker. Typical retention: 90 days.
  • _fbp (third-party): Meta Pixel browser identifier. Typical retention: 90 days.
  • _fbc (third-party): Meta click identifier (set when click ID is present). Typical retention: 90 days.

4.4 Beyond cookies

If enabled by consent, tracking can also occur via pixel tags and, in some setups, server-side forwarding (for example, via Meta Conversion API or server-side tag management). Where server-side forwarding is used, identifiers may be hashed and used for conversion measurement and matching. Device information may also be inferred from IP address and User-Agent strings for basic security and fraud prevention.

For more detail about cookie categories and examples, read our Cookie Policy.

5. Consent (EEA/UK)

Users in the EEA and UK receive a consent notice under GDPR/UK GDPR. Analytics and marketing cookies activate only after explicit, informed, freely given consent (Art. 6(1)(a)). Your choice is recorded in the cookie_consent browser cookie (12 months). You can withdraw or change your consent at any time by selecting “Manage cookie preferences” in the footer or by clearing cookies in your browser.

Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.

6. Sharing With Advertising & Service Partners

We share limited personal data with partners only when necessary for site operation, security, analytics, or marketing (where you consent). We do not sell personal data.

We do not permit these providers to use site data for their own independent commercial purposes beyond providing services to us. Some providers act as independent controllers for certain processing; their policies explain the details.

7. International Transfers

Some of our partners (for example, Google and Meta) may process data outside the European Economic Area (EEA), including in the United States. Where required, transfers are supported by appropriate safeguards such as:

  • EU–US Data Privacy Framework (since July 2023), where applicable.
  • UK Extension to the EU–US Data Privacy Framework, where applicable.
  • Swiss–US Data Privacy Framework, where applicable.
  • Standard Contractual Clauses (EU 2021/914) as a fallback safeguard.
  • UK International Data Transfer Agreement (IDTA) as a fallback safeguard.

8. Retention

We keep personal data only as long as needed for the purposes described in this Privacy Policy:

  • Contact submissions: up to 2 years from the last interaction, so we can follow up on learning questions and maintain continuity of educational guidance.
  • Email correspondence: for the duration of the relationship, then typically 1 additional year.
  • Server security logs: typically 90 days, unless needed longer for investigating abuse or incidents.
  • Analytics data: 14 months (where analytics consent is given).
  • Marketing cookies: retained for the cookie lifetime described in Section 4, if marketing consent is given.
  • Consent record: we may keep a record of consent choices for up to 3 years for audit and compliance.
  • Legal/tax records: where applicable, retained for the period required by Dutch or EU law (often 6–10 years for certain records).

9. Your Rights (GDPR & UK GDPR)

If GDPR applies to you, you have rights in relation to your personal data. These include:

  • Right of access (Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure (Art. 17)
  • Right to restriction of processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object (Art. 21)
  • Right to withdraw consent at any time (Art. 7(3))
  • Right to lodge a complaint with a supervisory authority (Art. 77)

To exercise your rights, email us at [email protected]. We typically respond within 30 days. For complex requests, this can be extended by up to 60 additional days as permitted by law.

Supervisory authority (Netherlands): Autoriteit Persoonsgegevens (AP).
https://autoriteitpersoonsgegevens.nl/

If you are located elsewhere in the EU, you can also find your authority via the European Data Protection Board:
https://edpb.europa.eu/

10. Children

This Site is not directed at individuals under 16. We do not knowingly collect personal data from minors. If we learn that we have collected personal data from a child under 16 without verifiable parental consent, we will delete it promptly.

11. Do Not Track

This website does not respond to “Do Not Track” (DNT) browser signals. Third-party providers may have their own DNT handling, which you can review in their privacy policies.

12. Data Deletion Requests

You can request deletion of personal data by emailing [email protected] with the subject line “Data Deletion Request”. We may ask for information needed to verify your identity. Requests are typically completed within 30 days. We may retain limited information where required by law or for legitimate security purposes.

13. Business Transfers

If Vbg B.V. is involved in a merger, acquisition, asset sale, financing, or insolvency, personal data may be transferred to a successor entity. If such a transfer materially changes how personal data is used, we will provide notice on the Site.

14. California (CCPA / CPRA)

While Vbg B.V. is established in the Netherlands, the Site may be accessed from the United States. The following information is provided for California residents where applicable.

Categories of personal information disclosed in the last 12 months:

  • Identifiers (such as name, email, IP address, cookie IDs) shared with service providers and, if you consent, advertising partners.
  • Internet or other electronic network activity (such as pages viewed, interactions) shared with analytics and, if you consent, advertising partners.
  • Inferences (such as likely interests based on pages visited) used for advertising only if you consent to marketing cookies.

We do not sell personal information as defined by the CCPA. We may share information for cross-context behavioral advertising when marketing cookies are enabled; you can opt out via our cookie preferences panel.

California residents may request to know, delete, correct, and opt out of sale/sharing, and have a right to non-discrimination. Submit requests via email with the subject “California Privacy Request” to [email protected]. We may need to verify your identity. Authorized agents must provide written proof of authorization.

15. Virginia (VCDPA)

Virginia residents may have rights to access, correct, delete, and obtain a copy of personal data, and to opt out of targeted advertising. Submit requests via email with subject “Virginia Privacy Request” to [email protected].

We do not sell personal data or engage in profiling producing legal or similarly significant effects. If we deny a request, you may appeal by emailing with subject “Appeal of Refusal — Privacy Request”. We respond within 60 days. If unresolved, you may contact the Virginia Attorney General.

16. Nevada

Nevada residents may submit a verified opt-out request by emailing with subject “Nevada Do Not Sell Request” to [email protected]. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.

17. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in how the Site works, legal requirements, or the tools we use. Material changes will be announced via a notice on the Site at least 14 days before they take effect, where feasible. The “Last Updated” date at the top of this page will change with every revision.

18. Contact

If you have questions about this Privacy Policy or how your personal data is handled, contact: