Pivacy policy

Last updated: 4 December 2025

This privacy policy applies to the website www.christa-maria.com and to all services offered by Nix Miss Training & Consultancy B.V., including quotation requests, customer communication via phone, e-mail or WhatsApp, and all related activities concerning the rental of our vessel.

Nix Miss Training & Consultancy B.V. is the data controller within the meaning of the General Data Protection Regulation (GDPR).

1. Contact Details

Nix Miss Training & Consultancy B.V.
De Blauwe Wereld 17, 1398EM, Muiden, The Netherlands
Phone: +31 6 5583 5580
E-mail: info@christa-maria.com
Website: www.christa-maria.com
Company registration (KvK): 34197216

2. Personal Data We Process

We only process personal data that you provide to us directly through:

  • the contact form on christa-maria.com
  • e-mail or WhatsApp
  • telephone contact
  • a quotation or booking enquiry

We may process the following information:

  • First and last name
  • E-mail address
  • Telephone number
  • Any additional details voluntarily provided by you (e.g., group size, preferred route, event information, or business details)

We do not process special categories of personal data.

3. Minors

Our website and services are not intended for individuals under the age of 16.
We do not knowingly collect data from minors.

If you believe we have collected personal data from a minor without parental consent, please contact us at info@christa-maria.com, and we will delete this information immediately.

4. Purposes and Legal Bases of Processing

We process your personal data only for legitimate purposes:

A. To contact you

For example, to respond to enquiries or provide information.
Legal basis: legitimate interest or consent.

B. To prepare and send quotations

Legal basis: performance of a contract or pre-contractual steps.

C. Administrative purposes and legal obligations

Such as maintaining invoices and financial records.
Legal basis: compliance with legal obligations (e.g., tax law).

D. Website performance and analytics

Through functional and analytical cookies.
Legal basis: legitimate interest or consent (for non-essential cookies).

We do not use automated decision-making or profiling.

5. How We Obtain Your Data

We receive your data only:

  • directly from you
  • via functional or analytical cookies on our website

We do not purchase personal data nor receive data from third parties for marketing purposes.

6. Retention of Personal Data

We retain personal data no longer than necessary:

  • Contact and enquiry details → 12 months after the last interaction
  • Quotations, invoices and financial records → 7 years (legal obligation)
  • E-mail correspondence → 12 months
  • Cookies → in accordance with our Cookie Policy

After these periods, data is deleted or anonymised.

7. Sharing Personal Data with Third Parties

We only share personal data with third parties when necessary for:

  • website hosting
  • e-mail services
  • IT security and support
  • financial administration (e.g., accountant or bookkeeper)

We conclude a Data Processing Agreement (DPA) with all third-party processors as required under Article 28 GDPR.

We never sell personal data to third parties.

8. Cookies and Similar Technologies

Our website uses the following types of cookies:

Functional cookies

To ensure proper functioning of the website.

Analytical cookies (Google Analytics 4, IP anonymised)

We use GA4 with:

  • IP anonymisation enabled
  • data-sharing disabled
  • EU-based processing where technically possible
  • a data processing agreement with Google

No marketing or tracking cookies

We do not use advertising, behavioural or remarketing cookies.

Cookie consent

Upon your first visit, you are presented with a cookie banner that allows you to:

  • accept optional cookies
  • refuse optional cookies

You may also adjust your browser settings to delete or block cookies at any time.

A complete cookie table, including cookie names, purpose and retention periods, is available in our Cookie Policy.

9. Transfers Outside the European Economic Area (EEA)

When using Google Analytics, it is possible that certain data may be processed by Google outside the EEA.

In such cases, we rely on the following safeguards:

  • Standard Contractual Clauses (SCCs)
  • supplementary technical safeguards such as IP anonymisation

This ensures compliance with GDPR requirements.

10. Security of Personal Data

We take appropriate technical and organisational measures to protect personal data, including:

  • encrypted connections (SSL/HTTPS)
  • secure EU-based servers
  • firewalls and malware protection
  • restricted access on a need-to-know basis
  • strong passwords and two-factor authentication where available

If you suspect misuse or a data breach, please contact us at info@christa-maria.com.

11. Your Rights Under the GDPR

You have the following rights:

  • Right of access
  • Right to rectification
  • Right to erasure (“right to be forgotten”)
  • Right to restriction of processing
  • Right to data portability
  • Right to object
  • Right to withdraw consent

Requests may be submitted to info@christa-maria.com.
We will respond within four weeks.

To protect your privacy, we may request identity verification.
Please redact your:

  • photo
  • MRZ
  • passport/ID number
  • citizen service number (BSN)

before sending any copy.

12. Complaints

You have the right to submit a complaint to the Dutch supervisory authority:

Data Protection Authority
https://autoriteitpersoonsgegevens.nl/en/contact-dutch-dpa/contact-us

13. Changes to This Privacy Policy

We may update this privacy policy when our services or legal requirements change.
The most recent version will always be available on this page.