Privacy Policy
ICAN Coaching is a sole proprietorship of Iris Schotsman, located in Uithoorn. This privacy policy has been prepared in accordance with the General Data Protection Regulation (GDPR).
Last Updated
2026-06-22
1. Who are we?
ICAN Coaching is a sole proprietorship of Iris Schotsman, located in Uithoorn.
Chamber of Commerce number: 54411378
Address: Noorse Lijster 12, 1423 RZ Uithoorn
Email: iris@liefdesadvies.com
Phone: +31 (0)6 16 326 271
2. What personal data do we collect?
We collect the following data through our contact form:
- Name
- Email address
- Phone number (optional)
- Message (optional)
- Selected subject template (optional)
In addition, we automatically collect certain technical data when you visit our website:
- IP address and browser user agent (browser type and version) — these are hashed before being stored (see Contact form data below)
- Visited pages and time of visit
3. Why do we collect this data?
For the contact form, we process your personal data based on legitimate interest (Article 6(1)(f) GDPR): we need your data to contact you in response to your request and to be able to offer our services. There is no sale or marketing purpose — only the answering of your message.
For Google Analytics 4, the legal basis is consent (Article 6(1)(a) GDPR). For visitors from the 32 European markets, consent is denied by default via Google Consent Mode v2. Until you grant consent, only cookieless pings are sent (no _ga cookie, no identifiable IP address).
4. How long do we retain your data?
Contact form — both the structured record (database) and the text log file are retained for 24 months, counted from the moment of submission. After that, your data is automatically deleted (daily sweep at 03:00, server local time).
Google Analytics 4 — default 14 months in Google Analytics, reducible in the GA4 admin (we aim for 2 months).
Erasure audit log — when you submit an erasure request, the audit entry recording that deletion is also retained for 24 months and then automatically deleted by the same sweep.
5. With whom do we share your data?
We share your data with the following parties, only for the purposes described in this policy:
- Our email provider — processes name and email address as necessary to deliver our email.
- Google LLC — processes anonymized IP addresses and visit data for Google Analytics 4, as a processor under the EU-US Data Privacy Framework. Data may be processed on servers in the European Union and the United States.
We do not use Google Analytics 4 for marketing purposes and do not share data with third parties for marketing.
For contact form submissions, the set of recipients has not changed; only the storage shape has. From this update onward, submissions are stored both as a structured database record (queryable by submission ID and email) and as a monthly text log file, both with hashed IP and User-Agent values.
6. Cookies
What are cookies?
Cookies are small text files placed on your computer or mobile device when you visit a website.
Essential cookies
We use essential cookies that are necessary for:
- The functioning of the contact form
- The security of the website
- Remembering your preferences (such as language and theme) while browsing
Google Analytics 4 cookies
We use Google Analytics 4 to understand which pages are visited. The processor is Google LLC, which processes this data under the EU-US Data Privacy Framework. IP anonymization is enabled, so IP addresses are stripped before reaching Google.
Google Analytics 4 sets the following cookies:
_ga— distinguishes visitors (2 years)_ga_<id>— maintains session state (2 years)
For visitors from the 32 European markets (EU/EEA + United Kingdom + Switzerland), Google Consent Mode v2 is set to denied by default. Until you grant consent, only cookieless pings are sent: these contain no _ga cookie and no identifiable IP address. Only after you grant consent via the cookie banner are the GA4 cookies set.
Contact form conversion — when you successfully submit the contact form, a generate_lead event is sent to Google Analytics 4 with the submission ID, your locale (NL/EN) and — only if you selected a canonical subject from the list — the corresponding subject key. This event contains no name, email address, IP address, or other personal data. Under denied consent, this event is recorded cookielessly for statistical modeling, without you being trackable as an individual.
Retention period: default 14 months in Google Analytics, reducible in the GA4 admin (we aim for 2 months).
Opt out: you can install the Google Analytics Opt-out Browser Add-on, or email iris@liefdesadvies.com to be manually deleted.
Future changes
The current implementation uses Google Consent Mode v2 with default-denied for European visitors and cookieless pings before consent. If this changes in the future, we will inform you clearly and, if necessary, ask for your consent again.
7. Contact form data
When you submit the contact form, the following data is recorded:
Structured record
Each submission is stored as a record in our secured database, queryable by submission ID and by email address. The record contains: name, email address, optional phone number, message, selected subject template, locale, hashed IP address, hashed User-Agent, a flag indicating whether the email was sent successfully, and the submission timestamp.
Hashing of IP and User-Agent
IP addresses and User-Agent strings are hashed with HMAC-SHA256 using a unique, per-deployment salt before being stored — both in the database record and in the text log file. This materially reduces the personal-data surface while preserving basic deduplication and spam-pattern recognition (via repeated IP hashes). The salt is never written to the database row or to the log line.
Retention period
Both the structured record and the text log file are retained for 24 months, counted from the submission timestamp. After that, your data is automatically deleted by a daily background task.
Right to erasure (Article 17 GDPR)
You can request deletion of your submission(s) at any time. Send an email to iris@liefdesadvies.com. Iris Schotsman processes your request by deleting the structured record and the matching log lines, and writes an audit entry without storing your email address in cleartext (the email in the audit entry is hashed).
Google Analytics conversion
As described in §6, a successful submission sends a generate_lead event to Google Analytics 4. This event contains only the submission ID, your locale, and — if a canonical subject was selected — the subject key. Your name, email address, IP address, and message are never included in this event.
8. Your rights
You have the right to:
- Access your personal data
- Have your data corrected
- Have your data deleted
- Object to the processing
To exercise your rights, please send an email to iris@liefdesadvies.com or call +31 (0)6 16 326 271.
9. Security
We take appropriate technical and organizational measures to protect your data against loss, misuse, or unauthorized access.
10. Complaints
If you have a complaint about the processing of your personal data, you can contact Iris Schotsman at iris@liefdesadvies.com.
You also have the right to file a complaint with the supervisory authority:
Dutch Data Protection Authority (Autoriteit Persoonsgegevens)
Website: https://www.autoriteitpersoonsgegevens.nl
11. Contact
For questions about this privacy policy, you can contact:
ICAN Coaching
Iris Schotsman
Noorse Lijster 12
1423 RZ Uithoorn
Netherlands
Email: iris@liefdesadvies.com
Phone: +31 (0)6 16 326 271