Privacy Policy
Last Updated: March 12, 2026
1 — Introduction & Controller Identity
This Privacy Policy explains how TIT-Master ("we", "our", "us") collects, uses, and protects personal data when you visit our website, contact us, or participate in our programs and services. We operate education, training, and consulting services for clients across Canada with administration from the Netherlands.
Data Controller: TIT-Master B.V., Vuurdoornlaan 17, 2641 CG Pijnacker, Netherlands. Contact email: [email protected]. We do not process special-category data at scale and have not appointed a Data Protection Officer. For privacy questions, email us with the subject line “Privacy Inquiry”.
By using our site or sending us information, you agree to this Privacy Policy. If you do not agree, please do not use our site or submit personal data.
2 — Personal Data We Collect
We collect only the information necessary to deliver our services, communicate with you, and improve our content. Categories include:
- Identity and contact details: name, business role or title, email address, phone number, organisation, province/territory or city.
- Inquiry and project data: objectives, audience, timelines, constraints, training topics, and other details you provide in forms or emails.
- Technical data: IP address, browser type and version, device/OS, language preferences, time zone, and general location inferred from IP.
- Usage data: pages viewed, session duration, scroll depth, referrer, and click interactions on our site.
- Cookies and identifiers: essential session cookies, consent preferences, and—when allowed—analytics and marketing identifiers (see Section 4).
- Conversion events: form submissions and subsequent interactions related to a request (e.g., proposal sent, call booked).
We do not intentionally collect sensitive personal data (e.g., health information, union membership, religion, political opinions), government ID numbers, or full payment card data through this website.
3 — Why We Process Your Data & Legal Bases (GDPR)
- Responding to contact requests, preparing proposals, and delivering services: Art. 6(1)(b) contract and pre-contract steps; Art. 6(1)(f) legitimate interest for record keeping.
- Analytics to understand site performance: Art. 6(1)(a) consent (EEA/UK users only if consented).
- Marketing, remarketing, and lookalike audiences: Art. 6(1)(a) consent (EEA/UK users only if consented).
- Security, fraud prevention, and service continuity: Art. 6(1)(f) legitimate interests.
- Legal/tax compliance and responding to lawful requests: Art. 6(1)(c) legal obligation.
Automated decision-making: we do not conduct automated decision-making or profiling that produces legal or similarly significant effects under Art. 22 GDPR.
4 — Cookies & Tracking Technologies
Cookies are small text files stored on your device. We also use similar technologies such as pixel tags and server-side identifiers. We group cookies into three categories:
- Essential (no consent required): used to keep the site running and remember your cookie choices. Examples: _site_session (session continuity), cookie_consent (your preferences). Retention: session to 12 months.
- Analytics (consent-based): help us understand traffic and content performance. Example: Google Analytics 4 identifiers such as _ga (2 years) and _ga_XXXXXXXXXX (2 years). Analytics data is typically retained for up to 14 months in reporting.
- Marketing (consent-based): used for remarketing and conversion attribution. Examples: _gcl_au (Google Ads, 90 days), _fbp and _fbc (Meta, 90 days).
You can manage preferences at any time using the “Manage cookie preferences” link in the footer. Browser settings also allow you to block or delete cookies. If you reject analytics/marketing, we will not set those cookies and we will make reasonable efforts to delete any existing analytics/marketing identifiers set earlier on this device from our site.
5 — Consent (EEA/UK)
Visitors in the EEA and UK receive a consent notice. Analytics and marketing cookies are activated only after explicit, informed, freely given consent under Art. 6(1)(a) GDPR/UK GDPR. Your choice is stored in the cookie_consent cookie for up to 12 months. You may withdraw consent at any time via the cookie preferences panel or by clearing cookies; withdrawal does not affect processing carried out before withdrawal.
6 — Sharing with Advertising & Service Partners
We do not sell personal data. We share limited data with trusted providers that help us operate the website, measure performance, and run campaigns:
- Google (Analytics 4, Google Ads, Tag Manager): cookie identifiers, usage data, and conversions for measurement and remarketing. IP addresses may be truncated/anonymised where available.
- Meta (Pixel and Conversion API, where used): page views, conversions, audience membership, and hashed identifiers for remarketing and measurement.
- Cloudflare or comparable CDN/security provider: network-level threat detection, DDoS mitigation, and performance optimisation using IP and request metadata.
These providers act as processors or independent controllers depending on the context. They must not use data from our site for their own unrelated commercial purposes under the applicable contracts and policies.
7 — International Data Transfers
When data is transferred outside the EEA/UK (for example, to the United States for Google or Meta), we rely on appropriate safeguards, including the EU–US Data Privacy Framework (and UK Extension where applicable) or Standard Contractual Clauses (EU 2021/914) and the UK IDTA. Where required, we implement supplementary technical and organisational measures to protect data subject to European law.
8 — Retention Periods
- Contact and proposal records: up to 2 years from the last interaction, unless a longer period is needed for legal claims or tax records.
- Service delivery files (e.g., training artefacts containing limited contact details): for the service relationship plus up to 1 year, unless law requires longer.
- Analytics reports: typically 14 months.
- Marketing cookies: per cookie lifetime noted above.
- Server logs: about 90 days, unless needed for security investigations.
- Cookie consent record: up to 3 years for audit purposes.
- Legal/tax documentation: as required by Dutch/EU law, commonly 7–10 years.
9 — Your Rights (GDPR & UK GDPR)
Subject to conditions and exceptions, you have the following rights regarding your personal data: access; rectification; erasure; restriction; portability; objection (including to direct marketing); and the right to withdraw consent at any time. To exercise rights, email [email protected]. We will respond within 30 days, extendable by up to 60 days for complex requests.
You may lodge a complaint with your local supervisory authority. In the Netherlands, this is the Autoriteit Persoonsgegevens. EU residents can find their authority via the European Data Protection Board. We would appreciate the chance to address your concerns first—please contact us directly.
10 — Children
Our services and website are not directed to individuals under 16. We do not knowingly collect data from children. If you believe we have collected personal data from a child under 16 without verifiable parental consent, contact us and we will delete it promptly.
11 — Do Not Track
Some browsers offer “Do Not Track” (DNT) signals. Our website does not respond to DNT signals. Consent tools and cookie preferences remain the primary method for controlling analytics and marketing technologies on this site.
12 — Account & Data Deletion Requests
We do not operate end-user accounts on this website. To request deletion of personal data related to your inquiries or communications with us, email [email protected] with the subject “Data Deletion Request”. We may ask for information to verify your identity before completing your request. We will retain only what is necessary to comply with legal obligations or to establish, exercise, or defend legal claims.
13 — Business Transfers
If we are involved in a merger, acquisition, asset sale, financing, reorganisation, or insolvency proceeding, your personal data may be transferred to a successor or affiliate as part of the transaction. Where required by law, we will provide a prominent notice on our website if a transfer results in material changes to how your data is used or to whom it is disclosed.
14 — California (CCPA/CPRA) Disclosures
While our primary service area is Canada, we may receive visits from U.S. residents. Over the past 12 months, we have disclosed the following categories of personal information to service providers and advertising partners for business purposes: identifiers (e.g., name, email, IP, device IDs); Internet or network activity (e.g., usage data, pages viewed); and inferences drawn from usage (e.g., interests for advertising). We do not sell personal information as defined by the CCPA. We may “share” personal information for cross-context behavioral advertising subject to opt-out mechanisms available via our cookie preferences panel.
California residents have the right to know, delete, correct, and opt out of the sale/sharing of personal information, and the right to non-discrimination for exercising these rights. Submit requests by emailing [email protected] with the relevant subject line (e.g., “California Privacy Request”). We will verify identity before acting on requests. Authorized agents must provide proof of authorization.
15 — Virginia (VCDPA)
Subject to scope thresholds, Virginia residents may have rights to access, correct, delete, and obtain a portable copy of personal data, and to opt out of targeted advertising. Submit requests to [email protected]. If we refuse a request, you may appeal by emailing us with the subject “Appeal of Refusal — Privacy Request”. We will respond within 60 days. Unresolved concerns can be raised with the Office of the Attorney General of Virginia.
16 — Nevada
Nevada residents may submit a verified opt-out request regarding the sale of covered information by emailing [email protected] with the subject “Nevada Do Not Sell Request”. We do not currently sell personal information as defined under Nevada law.
17 — Changes to This Policy
We may update this Privacy Policy to reflect changes in law, technology, or our operations. Material changes will be announced via a notice on our homepage at least 14 days before they take effect. The “Last Updated” date at the top of this page will be refreshed with every revision. We encourage you to review this page periodically.
18 — Contact
Data Controller: TIT-Master B.V.
Registered Address: Vuurdoornlaan 17, 2641 CG Pijnacker, Netherlands
Email: [email protected]
Postal correspondence can be sent to the registered address above. Please include enough detail to identify your records and the nature of your request.