Privacy Statement
Last updated: 10 September 2026
Daniela Burba Consulting respects your privacy and handles personal data in line with the General Data Protection Regulation (GDPR / AVG). This statement explains what data this website and this business collect, why, on what legal basis, how long it is kept, and what you can do about it.
For cookies and similar technologies specifically, see our Cookie Statement at /cookies.
1. Who is responsible
Daniela Burba Consulting is the controller for the personal data described here.
- Business: Daniela Burba Consulting
- Based in: Amsterdam, the Netherlands
- KvK number: 88854434
- Email: info@danielaburbaconsulting.com
There is no Data Protection Officer. This is a one-person business; data protection questions come to the address above and are answered by Daniela Burba.
2. What this statement covers
This website (danielaburbaconsulting.com), the booking, enquiry and download routes on it, our Event Claim Checker — a separate site operated by us and covered by this same statement — and personal data processed in the course of client work.
3. What is collected, why, and on what basis
Visiting the website
Our hosting platform records the standard technical data needed to serve the site and keep it secure, including IP address, browser type, pages requested and time of request. This is not used to identify you or to build a profile, and we do not run analytics, advertising or tracking software on this site.
Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in operating and securing the site.
Retention: server logs are kept by the hosting platform for its standard period.
Emailing us
If you email info@danielaburbaconsulting.com, we process your name, email address, and whatever you choose to write to us.
Legal basis: steps taken at your request prior to entering a contract (Art. 6(1)(b)), or legitimate interest in responding to enquiries (Art. 6(1)(f)).
Retention: two years after our last contact, unless the exchange becomes part of a client engagement.
Booking a discovery call
Calls are booked through Calendly. When you book, Calendly collects your name, email address, time zone, and any answers you give on the booking form, and shares them with us.
Calendly is a separate company with its own privacy statement: https://calendly.com/legal/privacy-notice. When you follow the booking link you are on Calendly's platform, and their statement governs what happens there.
Legal basis: steps taken at your request prior to entering a contract (Art. 6(1)(b)).
Retention: booking records are kept for twelve months, unless the call leads to an engagement.
Downloading a guide
Some guides and resources on this site are sent to you by email. To send one, we need your email address, and we record which resource you asked for and when.
Two separate things happen when you submit that form, and you control them separately:
- Sending you the resource you asked for. Legal basis: steps taken at your request (Art. 6(1)(b)). This is not marketing — it is the delivery of the thing you requested.
- Occasional updates by email. A separate checkbox, off by default. Legal basis: your consent (Art. 6(1)(a)). You can withdraw consent at any time using the unsubscribe link in any email, or by writing to us. Withdrawing consent does not affect emails sent before you withdrew it.
We do not add you to any mailing list on the strength of a download alone.
Retention: download records for 24 months from the date you requested the resource, or until you ask us to delete them, whichever comes first. If you opted in to updates, we keep your email address and the record of your consent until you unsubscribe, and for two years after that as proof that the consent existed.
Using the free Event Claim Checker
The Event Claim Checker is a separate site, operated by us and covered by this same statement. It asks you questions and returns a written result. When you ask for your result by email, we store: your answers, any text you typed yourself, the result generated for you, your email address, whether you opted in to updates, and the date and time. The same two-part split applies as above: delivering your result is done at your request (Art. 6(1)(b)); optional updates are based on your consent (Art. 6(1)(a)).
Retention: 24 months from submission, or until you ask us to delete the record, whichever comes first.
A note on free-text fields: anything you type into the checker is stored with your result. Please do not paste confidential information, client names, or commercially sensitive material into it.
Client engagements
In the course of consultancy, audit and reporting work we process the business contact details of the people we work with, and whatever information a client supplies for the engagement. Where that information includes personal data belonging to a client's staff, attendees or suppliers, we act as a processor on that client's instructions, under a written agreement.
Legal basis: performance of a contract (Art. 6(1)(b)), and legal obligation (Art. 6(1)(c)) for invoicing and financial records.
Retention: engagement records for the duration of the engagement plus two years; invoices and financial administration for seven years, as required by Dutch tax law.
4. Cookies and similar technologies
This website does not use analytics cookies, advertising cookies, social media pixels, or cross-site tracking of any kind. See our Cookie Statement at /cookies.
5. Who else sees your data
We do not sell personal data and we do not share it for anyone else's marketing.
We use a small number of service providers who process data on our behalf, under written data processing agreements:
| Provider | What it does | Where |
|---|---|---|
| Lovable | Website hosting and publishing; sending guides, checker results and any email updates | Sweden (EU). Email delivery uses Lovable's own sub-processors, which may process data outside the EEA under the safeguards in Lovable's data processing agreement. |
| Supabase | Database storing form submissions, download records and claim checker results | EU region |
| Calendly | Scheduling for discovery calls | United States |
| Google Workspace | Business email | United States |
We may also disclose data where we are legally required to — for example to a tax authority, or in response to a lawful order.
6. Data outside the EEA
Some providers above are based in the United States. Where personal data is transferred outside the European Economic Area, that transfer is covered by an appropriate safeguard under Chapter V GDPR — the EU–US Data Privacy Framework where the provider is certified, or Standard Contractual Clauses. You can ask us which mechanism applies to a specific provider.
7. Automated decision-making
The Event Claim Checker applies a fixed set of rules to the answers you give and produces a written result. This is not a decision producing legal effects for you, or similarly significantly affecting you, within the meaning of Art. 22 GDPR: the result is directional information, not an assessment, a certification, or a decision about you. No profiling is carried out for advertising purposes.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- rectification of data that is incorrect or incomplete;
- erasure of your data, where there is no overriding reason for us to keep it;
- restriction of processing while a dispute about your data is resolved;
- object to processing based on legitimate interest;
- data portability — receive data you gave us in a structured, machine-readable format;
- withdraw consent at any time, where processing is based on consent.
To exercise any of these, email info@danielaburbaconsulting.com. We respond within one month. We may ask you to confirm your identity before acting on a request, so that we do not disclose your data to someone else.
If you are unhappy with how we have handled your data, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens — autoriteitpersoonsgegevens.nl — or to the supervisory authority in your own EU country.
9. Security
Data is held on the platforms named in section 5, which provide encryption in transit and at rest. Access is limited to Daniela Burba. Accounts are protected with strong, unique credentials and two-factor authentication where the provider supports it.
No system is perfectly secure. If a data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Autoriteit Persoonsgegevens within 72 hours and inform you where the law requires it.
10. Children
This website and these services are aimed at businesses and professionals. They are not directed at children, and we do not knowingly collect data from anyone under 16.
11. Changes
We update this statement when what we do changes. The date at the top shows the current version. Material changes affecting people already on our list will be notified by email.
12. Contact
Questions about this statement or about your data: info@danielaburbaconsulting.com · Daniela Burba Consulting · Amsterdam, the Netherlands · KvK 88854434