Privacy Policy: Radion Consulting
Privacy Policy
Last updated 2026-07-31.
Introduction
Radion Consulting is committed to protecting your privacy. This Privacy Policy explains how Radion Consulting collects, uses, discloses, and safeguards your information when you visit the website or use Radion Consulting's services.
Data Controller
The data controller responsible for your personal data is:
Radion Consulting
Europalaan 22 unit 8503
3526KS Utrecht
Netherlands
KVK Number: 91299144
Email: info@radion.consulting
Information Collected
Radion Consulting may collect information about you in a variety of ways. The information Radion Consulting may collect includes:
- Personal Data: Name, email address, phone number, company name, role, industry, and other contact information you provide when contacting Radion Consulting or requesting services.
- Booking and Payment Data: When you book either the free Discovery Call or the paid AI Operations Review, the required name, email address, and phone number, chosen slot, and booking responses are processed through the self-hosted Cal.diy service at book.radion.consulting. The phone number is used for booking administration and urgent scheduling contact; providing it is not SMS marketing consent. Google Calendar supplies availability and calendar invitations, and the call is held over Google Meet. Stripe processes payment for the paid call. When you purchase a paid event ticket, name, email, and payment details are processed by Stripe and a booking record is retained to administer the event. Radion Consulting does not operate a contact or assessment form and does not collect questionnaire responses or scores.
- Operations Review Recording: With your consent, the paid AI Operations Review is recorded (audio and video) to produce your written deliverable and internal notes. Where the call is recorded through Google Meet, the recording is stored in Radion Consulting's Google Workspace account, used only to produce your deliverable, and deleted within 30 days, or upon your acceptance of the deliverable, whichever is sooner. See “Recording & AI processing” below for full detail. This is unrelated to website session replay, which is not enabled.
- Usage Data: Information about how you access and use the website, including your IP address, browser type, and pages visited.
- Cookies and Tracking: When you consent, Radion Consulting uses PostHog to collect privacy-scoped website usage data, including pages visited, click events, and navigation patterns. Cloudflare Web Analytics is cookieless and always active for aggregate traffic measurement. See the "Cookies and Tracking Technologies" section below for detailed information.
Cookies and Tracking Technologies
What Are Cookies
Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work efficiently and provide information to site owners.
How Radion Consulting Uses Cookies
Radion Consulting uses cookies to:
- Understand how visitors use the website (analytics)
- Remember your cookie consent preferences
- Improve website performance and user experience
Types of Cookies Used
Strictly Necessary Cookies
These cookies are essential for the website to function and cannot be switched off.
| Cookie Name | Purpose | Duration | Provider |
|---|---|---|---|
| cc_cookie | Stores your cookie consent preferences | 6 months | Radion Consulting |
| __cf_bm | Bot management and security protection | 30 minutes | Cloudflare |
The __cf_bm cookie is set by Cloudflare for bot detection and platform security.
It is not used for marketing, profiling, or cross-site analytics.
Analytics and Measurement
Radion Consulting uses cookieless Cloudflare Web Analytics for aggregate measurement and consent-gated
PostHog (EU-hosted) to understand how visitors use the website. These tools collect data to help
improve services. Cloudflare Web Analytics is privacy-focused, always on, and does not use cookies.
PostHog is hosted in the European Union (Frankfurt) and stores its visitor identifier in both
a first-party cookie and browser localStorage. The PostHog configuration: (1) automatic event
capture is restricted to clicks on links and buttons only — typed-in form text is not captured;
(2) all element text content and HTML attributes are masked in autocapture events; (3) event properties
named
email, phone, name, first_name,
last_name, company, and IP address are stripped from every event
before transmission; (4) URL query strings carrying any of those property names are masked,
and additional URL query stripping is applied in a before_send hook; (5) the referring
page URL may be stored for attribution after consent; initial-referrer properties are removed
and email-like values are redacted; (6) PostHog person profiles are not created; and (7) session
replay is not enabled.
| Cookie Name | Purpose | Duration | Provider |
|---|---|---|---|
| ph_<project-id>_posthog (cookie + localStorage) | Distinguishes unique visitors for product analytics — pageviews, click events on links and buttons, funnels, retention. Form input text is not captured. All element text and attributes are masked in autocapture events. Event properties matching listed PII names (email, phone, name, etc.) and IP address are stripped before events are sent; URL query strings carrying those names are masked. No session replay. | 3 months | PostHog (EU) |
Analytics is consent-gated: when consent is denied, PostHog scripts are not loaded and analytics cookies or storage are not set. Cloudflare Web Analytics is designed to be cookieless and does not set browser identifiers, so it operates independently of this consent choice. PostHog analytics requests route through a first-party domain (z.radion.consulting) before reaching PostHog; PostHog Inc. acts as the data processor and event data is stored within the European Union (Frankfurt).
Server-confirmed conversion measurement
After a service is requested, or when a payment is completed, refunded, failed, cancelled,
disputed or flagged for potential fraud, Radion Consulting sends limited server-confirmed events
to PostHog. These include lead_created, purchase_completed,
booking_refunded, booking_payment_failed,
booking_payment_canceled, booking_chargeback, and
booking_fraud_warning. The records use a pseudonymous booking, payment or Brevo
contact identifier and limited commercial details such as the service, funnel stage, value,
currency, payment outcome and risk category. Names, email addresses, telephone numbers,
payment credentials, meeting content and free-text responses are not sent. These records are
pseudonymised personal data and are not anonymous. Where browser analytics consent was
previously given, a pseudonymous browser identifier may connect a completed purchase or
requested service to that consented browser journey; otherwise no browser activity is added
to the server record. This connection uses event properties and does not create PostHog
person profiles. The browser analytics preference does not control these server-confirmed
records because they arise from a requested service or payment event rather than observation
of website browsing. Radion Consulting relies on legitimate interests under Article 6(1)(f) GDPR
to measure requested and completed services, reconcile payment and refund outcomes, and prevent
or manage payment fraud. A person may object at any time using the contact details below; processing
will then stop unless compelling legitimate grounds apply or the record is needed for legal claims.
Error & Diagnostic Data
When you have accepted analytics cookies, the site reports JavaScript errors to PostHog (EU, Frankfurt) so faults — especially on the booking and payment flow — can be found and fixed. An error report contains the error type, an error message, and a technical stack trace (a list of code locations and function names). Before any report is sent, the site removes query-string parameters and any login credentials from URLs, redacts email-like values across the whole report, and limits the number of stack frames. The site does not intentionally send form input, payment details, or contact details; a stack trace can still contain code file paths and function names, so error reports are minimised rather than guaranteed free of all identifiers. Lawful basis: consent (GDPR Art. 6(1)(a)); withdraw any time via Cookie Settings in the site footer. Retention matches PostHog event retention (90 days). Because this is a material change to what analytics consent covers, an updated disclosure version re-prompts prior consenters to confirm or decline against this new scope.
Your Cookie Choices
You can manage your cookie preferences at any time by:
- Updating your consent preferences via the cookie consent banner when you visit the website
- Adjusting your browser settings to block cookies
- Clearing your browser cookies to reset all consent preferences
Withdrawing consent will not affect data collected before withdrawal.
International Data Transfers
Website analytics are processed within the European Union: Cloudflare Web Analytics is cookieless and aggregate, and PostHog event data is stored in the European Union (Frankfurt). Some other processors may transfer data outside the European Economic Area — in particular payment processing via Stripe and calendar-invitation and video-call services via Google (Calendar and Meet). Where this occurs, Radion Consulting relies on the EU–US Data Privacy Framework and/or Standard Contractual Clauses (SCCs) in accordance with GDPR requirements, as detailed in the Disclosure of Information section below.
Third-Party Embeds
The /contact/ page embeds the self-hosted Cal.diy booking surface. Loading the inline
calendar connects the browser to book.radion.consulting; no attendee details are
placed in the booking URL. A direct new-tab booking link remains available if the inline
calendar or JavaScript is unavailable. /booking/ redirects to
/contact/ for legacy inbound links. Dated event pages may embed an OpenStreetMap
venue map. Full processor details and international-transfer mechanisms are disclosed under the
Disclosure of Information section below.
How Information is Used
Radion Consulting uses the information collected to:
- Respond to your inquiries and provide customer support
- Deliver and improve consulting services
- Send you updates, newsletters, and marketing communications (with your consent)
- Analyze usage patterns to improve the website and services
- Comply with legal obligations and protect Radion Consulting's rights
Legal Basis for Processing
Radion Consulting processes personal data based on the following legal grounds under GDPR:
- Contract Performance: Processing necessary to deliver consulting services and fulfill contractual obligations.
- Pre-Contractual Measures: Processing booking and contact inquiries before entering into a contract.
- Consent: For analytics cookies and marketing communications, processing is based on your explicit consent which can be withdrawn at any time.
- Legitimate Interests: Privacy-minimised measurement of requested and completed services; reconciliation of payment, refund and chargeback outcomes; prevention and management of fraud; and website improvement and security, subject to the right to object under Article 21 GDPR.
- Legal Obligation: Compliance with tax, accounting, and other legal requirements.
Events — ticket sales and attendee data
Radion Consulting sells tickets to its own in-person events through the radion.consulting website. The following applies to attendees:
- What is collected: name, email address, billing address, optional company and VAT identification number, and Stripe payment-method metadata (last four digits, card brand, country) for the purchase itself. Dinner ticket holders separately provide dietary preferences and accommodation requests via a follow-up email seven days before the event.
- Lawful basis matrix:
- Ticket purchase and event delivery: Article 6(1)(b) AVG (contract performance).
- Invoice and tax retention: Article 6(1)(c) AVG combined with Article 52 Algemene wet inzake rijksbelastingen (seven-year fiscal retention).
- Post-event marketing follow-up: Article 6(1)(a) AVG (consent). A separate unticked opt-in is presented at checkout; pre-ticked consent is invalid under Article 4(11) AVG. Consent can be withdrawn at any time via the unsubscribe link in any marketing message.
- Event photography and video: Photography and video are captured at in-person events to produce an after-movie and post-event marketing content (social and promotional use) — the full talk is not published as a webinar. Article 6(1)(f) AVG (legitimate interest) for general crowd shots; explicit consent for identifiable portraits and close-ups. Attendees can wear an opt-out wristband available at the entry desk, and the private dinner is off the record. Event media is retained for up to 24 months; attendees may object or request erasure at any time.
- Processors:
- Stripe Payments Europe Ltd (payment processing; EU–US Data Privacy Framework with Standard Contractual Clauses).
- Brevo (Sendinblue SAS, France) (transactional event email, attendee list).
- Odoo Online (Odoo S.A., Belgium) (tax-compliant invoice generation under Article 35a Wet OB).
- Cloudflare (Cloudflare, Inc.) (D1 reservation database hosted in the western-Europe region for inventory and order ledger).
- Retention: operational data (attendee list, D1 order rows, Brevo contact attributes) is retained for twelve months after the event date and then deleted or anonymised. Invoice data is retained for seven years per Article 52 AWR. Marketing-consent contacts are retained until consent is withdrawn.
- Cooling-off period: ticket purchases are services for a specific date. Article 6:230p sub e Burgerlijk Wetboek excludes the statutory 14-day right of withdrawal for such services. The disclaimer is rendered above the buy button and again in the Event Terms.
- VAT reverse charge: EU business buyers established outside the Netherlands may apply reverse charge at checkout by providing a valid VAT identification number. Stripe Tax validates the number through VIES and applies Article 12 lid 2 Wet OB. The resulting invoice carries the notation "btw verlegd".
Recording & AI processing (AI Operations Review)
The paid AI Operations Review is recorded (audio and video) for the sole purpose of producing the client's written deliverable and internal notes, with AI assistance for drafting. Radion Consulting is a participant in the call, so the recording itself is lawful under Articles 139a and 139b of the Dutch Criminal Code. The recording is personal data and is processed under the AVG (GDPR) on the following terms:
- Lawful basis: explicit consent (Article 6(1)(a) AVG), confirmed verbally at the start of the call before recording begins. Consent may be withdrawn at any time.
- Platform & storage: the call is conducted over Google Meet (Google Ireland Ltd), which carries the live audio and video and acts as an independent controller for that connection. Where the call is recorded through Google Meet, the recording is captured by Google Meet and stored in Radion Consulting's Google Workspace account; for that recording Google acts as a processor under the Google Cloud / Workspace Data Processing Addendum. Any transfer to Google LLC in the United States is covered by the EU–US Data Privacy Framework (Google is DPF-certified), with Standard Contractual Clauses as a fallback. Radion Consulting uses the recording only to produce the deliverable and deletes it within the retention period below.
- Data: voice, video image, name, email, and the business content spoken during the call. Radion Consulting does not perform voice-print or biometric identification, so the recording is ordinary personal data, not special-category data under Article 9 AVG.
- Purpose & recipients: internal production of the documented read and notes only. The recording is not disclosed to any third party for that party's own purposes; the only external party involved is Google, which hosts and stores the recording as a processor on Radion Consulting's behalf (see Platform & storage above). Drafting is performed on Radion Consulting's own infrastructure; recording content is not sent to an external AI provider as part of the standard process.
- Retention: the raw recording and transcript are deleted within 30 days, or upon acceptance of the deliverable, whichever is sooner.
- Minimisation: personal identifiers are edited out of the final written script. This is data minimisation under Article 5(1)(c) AVG, not anonymisation — while the raw recording is retained it remains within scope of the AVG.
- Rights: the client may decline recording (the deliverable is then produced from contemporaneous notes), request a copy, or request deletion, by contacting info@radion.consulting.
The contractual terms of the consultation, including the withdrawal-right waiver, are set out in the Consultation Terms.
Data Retention
Radion Consulting retains personal data only as long as necessary for the purposes outlined in this Privacy Policy:
- Booking and Lead Data: 3 years from the booking or inquiry date, or until engagement completion plus one year, whichever is longer.
- Analytics and Server-Confirmed Measurement Data: PostHog browser events and server-confirmed events are retained for 3 months. PostHog person profiles are not created. Cloudflare Web Analytics is aggregate and cookieless.
- Cookie Consent Records: 6 months to maintain stored preferences.
- Client Project Data: Duration of engagement plus 7 years for tax and legal compliance.
- Event Attendee Data: 12 months after the event date for operational data (attendee lists, D1 order rows, Brevo contact attributes); 7 years for invoice data per Article 52 AWR. See the Events section above for full breakdown.
After retention periods expire, personal data is securely deleted or anonymized.
Disclosure of Information
Radion Consulting may share your information in the following circumstances:
- Service Providers: With third-party
vendors who assist in operating the website and delivering services, including:
- Brevo (Sendinblue SAS): Event ticket purchaser details and booking-originated contact information, including name, email address, and booking phone, are transmitted to Brevo for contact management, payment receipts, intake, and non-overlapping follow-up communication. Cal.diy remains responsible for booking confirmations, reminders, rescheduling, cancellation, and decline messages. Processed under a data processing agreement in accordance with GDPR.
- Cal.diy: The self-hosted scheduling service at book.radion.consulting processes the required name, email address, phone number, chosen slot, and attendee responses for both consultation offerings. It supplies the booking confirmation and booking-management lifecycle communications and passes the required calendar data to Google Calendar and Google Meet.
- Cloudflare (Cloudflare, Inc.): Website hosting, content delivery, security protection, and privacy-focused web analytics. Processed under Cloudflare's data processing addendum.
- PostHog (PostHog, Inc.): Product analytics — pageviews, click events,
funnels, and retention cohorts. Data is processed in the European Union (Frankfurt) under
a data processing agreement signed in the PostHog dashboard. Analytics data is only shared
after analytics consent is granted. Separately, server-confirmed booking and payment conversions
are sent as pseudonymous
lead_createdandpurchase_completedrecords as described above. - Stripe (Stripe Payments Europe Ltd): Payment processing for paid-event ticket sales and for the paid AI Operations Review (booked at book.radion.consulting). Stripe's role under AVG is mixed and disclosed in its own Privacy Center: Stripe acts as a processor for buyer details that Radion Consulting provides for the transaction (name, email, billing address, optional VAT identification number), and as an independent controller for fraud prevention, regulatory compliance, and payment-network obligations on the same transaction data. The EU contracting entity is Stripe Payments Europe Ltd (Dublin, Ireland). Some Stripe operations involve transfer to Stripe Inc. in the United States; transfer is covered by the EU–US Data Privacy Framework (Stripe is DPF-certified) with Standard Contractual Clauses as a fallback. Payment-method details (card last four digits, brand, country) are held by Stripe and never transmitted to Radion Consulting. Ticket buyers may use the Stripe Customer Portal to manage their own billing data, payment methods, and receipts directly with Stripe; access to the Portal is provisioned via the post-purchase email and runs entirely on Stripe's infrastructure.
- Google (Google Ireland Ltd): Google Calendar availability, calendar invitations, and Google Meet video calls. Cal.diy passes the calendar information needed to reserve the selected slot and invite the attendee; the site does not embed Google Appointment Scheduling. Both the free discovery call and the paid AI Operations Review are held over Google Meet; when a call takes place Google processes the participants' connection and meeting metadata, and the live audio and video stream, as an independent controller. Where the paid consultation is recorded through Google Meet, the recording is stored in Radion Consulting's Google Workspace account and Google additionally acts as a processor for that recording under the Google Cloud / Workspace Data Processing Addendum. The EU contracting entity is Google Ireland Ltd (Dublin); data may be transferred to Google LLC in the United States under the EU–US Data Privacy Framework (Google is DPF-certified) with Standard Contractual Clauses as a fallback. Full disclosure at policies.google.com/privacy.
- Authorized Associates: Radion Consulting may engage qualified associates or subcontractors to deliver consulting services on its behalf. Associates access client data solely for service delivery purposes and are bound by confidentiality obligations equivalent to those of Radion Consulting. Associates do not retain client data beyond the engagement period.
- Legal Requirements: When required by law or to protect Radion Consulting's rights, safety, or property
- Business Transfers: In connection with a merger, sale, or acquisition of the business
Radion Consulting does not sell your personal information to third parties.
Data Security
Radion Consulting implements appropriate technical and organizational measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction. However, no method of transmission over the internet or electronic storage is 100% secure, and Radion Consulting cannot guarantee absolute security.
Your Rights
Under GDPR and Dutch data protection law, you have the following rights regarding your personal data:
- Right of Access: Access and obtain a copy of your personal information
- Right to Rectification: Correct inaccurate or incomplete information
- Right to Erasure: Request deletion of your personal information
- Right to Restriction: Request that Radion Consulting limit how your data is processed in the circumstances set out in Article 18 GDPR
- Right to Object: Object at any time to processing based on legitimate interests (Article 21 GDPR), and to any processing for direct marketing
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Withdraw Consent: Withdraw consent where processing is based on consent
- Right to Lodge a Complaint: You have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at https://autoriteitpersoonsgegevens.nl
To exercise these rights, contact Radion Consulting using the information provided at the end of this policy. Radion Consulting will respond without undue delay and within one month of receipt, as required by Article 12(3) GDPR. Where a request is complex or you have made a number of requests, this period may be extended by up to two further months, and you will be informed of any extension.
Third-Party Links
The Radion Consulting website may contain links to third-party websites. Radion Consulting is not responsible for the privacy practices or content of these external sites. You are encouraged to review the privacy policies of any third-party sites you visit.
Children's Privacy
Radion Consulting's services are intended for business professionals and organizations. Radion Consulting does not knowingly collect personal information from individuals under the age of 16. If you believe a child has provided personal information, please contact Radion Consulting immediately for removal.
Changes to This Privacy Policy
Radion Consulting may update this Privacy Policy from time to time. Changes will be communicated by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.
Contact Information
If you have any questions or concerns about this Privacy Policy, please contact Radion Consulting:
Email: info@radion.consulting