Trainiq
PlatformWho it is forQuinn AITrainiq ConnectPricingBlog 085 071 1114 Free demo Nederlands

Privacy policy

Last updated: 11 May 2026

This English version is provided for convenience. The Dutch version is the binding one.

Trainiq is a software-as-a-service platform that training providers use to manage their bookings, invoicing, certificates and participant records. This document explains which personal data we collect, what we use it for, how long we keep it and which rights you have as a data subject under the General Data Protection Regulation (GDPR).

Controller: Trainiq B.V., Einsteinlaan 28, 2289 CC Rijswijk, the Netherlands, Chamber of Commerce (KvK) 42053044. Contact: info@trainiq.nl.

1. Which data do we collect?

Training provider accounts

  • Company name, Chamber of Commerce number, VAT number, address, IBAN
  • Name, e-mail address and phone number of the person who signs up and of employees
  • Logo and brand colours
  • OAuth tokens and API keys of the accounting software and the payment provider the training provider connects (for example Mollie, Stripe, Informer, Moneybird or Exact Online; the training provider chooses which)

Participant data

  • First and last name, e-mail address, phone number, date of birth
  • Where certification requires it: the Dutch citizen service number (BSN), processed only when the law demands it
  • Address details when the training provider asks for them for invoicing
  • Course participation, attendance status, certificates obtained
  • Payment status (amount, status, transaction id at the training provider's payment provider, so no card or bank account details; those stay with the payment provider)

Technical data

  • IP address, browser user agent, session cookie
  • Audit log of administrative actions (who, what, when)
  • Anonymised visitor statistics through a self-hosted analytics installation (no cross-site tracking, no personal profiles)
  • When you request a demo through trainiq.nl: where your visit came from. If you arrive through a Google Ads advert, your browser keeps the click id and the campaign name from that link until you close the tab, and the form sends them along. We only use this to see which advert led to the request. We tell Google Ads that the click produced a request, without a name, e-mail address or any other data.

2. How do we collect this data?

  • Directly from the training provider: through the sign-up form, the admin portal and the Trainiq Connect page.
  • Directly from the participant: through the booking widget on the training provider's website, the participant portal and (where used) the WordPress plugin.
  • Through connected services: OAuth tokens or API keys of the chosen accounting software or payment provider are issued to us by that party after the training provider has given explicit consent there.
  • Through Trainiq Connect: the connection between Trainiq and those providers runs per training provider on our own servers in Germany. Over that connection, payment and accounting providers send us notifications about status changes (for example "payment completed") and we place invoices in the accounting software.

3. What do we use the data for?

We only process personal data on one of the GDPR legal bases: performance of the contract, a legal obligation, legitimate interest or explicit consent.

  • Providing the service: recording bookings, issuing invoices and certificates, tracking attendance, showing the participant portal.
  • Legal obligations: the Dutch duty to keep invoices and records (art. 52 AWR, 7-year retention).
  • Quality assurance: the audit log for NRTO requirements (the Dutch trade association for training providers) and internal control.
  • Contact: sending confirmation e-mails, QR codes, reminders and certificates by e-mail.

We do not use participant data for marketing and we do not pass it to third parties for commercial purposes.

4. Retention periods

Type of dataRetention periodBasis
Invoices + payment data7 yearsArt. 52 AWR (Dutch tax law)
Certificates + course records10 yearsIndustry standard for BHV / VCA
Training provider account and everything attached to itUp to 12 months after cancellationRecovery period + any outstanding payments
Participant data without an active certificateDeletable at the training provider's requestLegitimate interest
Audit log2 yearsLegitimate interest
Session cookiesLength of the sessionFunctional (no consent needed)
"Stay logged in" cookie30 days at mostFunctional + consent (opt-in)
OAuth tokens and API keys of connected providersUntil disconnectedPerformance of the contract
Origin of a demo request (click id, campaign)In your browser until you close the tab; with us for as long as the request is keptLegitimate interest

5. Who do we share data with?

We only share personal data with the following sub-processors, all under a data processing agreement:

  • Hetzner Online GmbH (Germany, EU): hosting of servers and databases
  • Brevo (Sendinblue SA, France, EU): e-mail delivery of confirmations and certificates
  • Mistral AI (France, EU): the language model behind the AI assistant Quinn; data of participants and contact persons is blocked by a PII detector before anything is sent
  • The training provider's payment provider (for example Mollie, Stripe or Buckaroo): handling of online payments. The training provider chooses which one and holds its own contract there.
  • The training provider's accounting software (for example Informer, Moneybird, Exact Online, e-Boekhouden or SnelStart): storage of invoices and credit notes, only when the training provider activates that connection.

The connection with those providers, Trainiq Connect, runs per training provider on our own Hetzner servers in Germany. So it is not an extra sub-processor.

We do not pass data to third parties for marketing or analysis outside these sub-processors. The current overview with locations, certifications and data categories is at trainiq.nl/en/subverwerkers.

We never sell customer data. Trainiq earns its money from the software subscription. We have no advertising model, no role as a data broker and no partnerships with data sellers. The data you put into Trainiq stays yours; we only use it to deliver the Service to you.

6. Your rights (GDPR)

As a data subject you have the right to:

  • Access: ask which data we process about you
  • Rectification: have incorrect data corrected
  • Erasure ("right to be forgotten"), within the limits of our legal retention duties
  • Restriction of processing
  • Data portability: receive an export of your own data
  • Objection to processing based on legitimate interest
  • Withdrawal of consent: for any processing that is based on it

Send your request to info@trainiq.nl. We respond within 30 days. If you disagree with how we handle your request, you can lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.

7. Security measures

  • Encryption in transit: TLS 1.2+ with HSTS for all traffic to trainiq.nl and the training providers' subdomains
  • Encryption at rest: encrypted volumes at our European hosting partner, database backups encrypted as well
  • Passwordless authentication: you log in with a magic link by e-mail; we store no passwords
  • Isolation per training provider: every training provider runs on its own set of database tables (optionally on its own domain)
  • Access control: role-based authorisation (planner / employee / administrator / instructor)
  • Audit log: every change to participant and invoice data is logged
  • Regular backups: daily, with tested recovery procedures

8. Cookies

Trainiq only uses functional cookies:

  • Session cookie: to keep you logged in during one visit
  • Remember-me cookie (optional, a checkbox at login): 30 days
  • CSRF token: protection against request forgery

Analytics runs on a self-hosted installation without cookies and without cross-site tracking. No consent is required for that.

On trainiq.nl we also use Leadinfo. Leadinfo looks up which company belongs to a visitor's IP address, so we know which training providers visit our site. We see no names or individual people. We run Leadinfo without cookies, so recognition happens on the IP address alone and nothing is stored on or read from your device. It is not present in the portals where participants, client companies and instructors log in. If you would rather not be recognised, you can opt out at Leadinfo itself. More is in our cookie policy.

9. Changes

This privacy policy may change from time to time. The current version is always at trainiq.nl/en/privacybeleid, with the date of the last change at the top. We inform training providers by e-mail about substantial changes.

10. Contact

Questions, requests or complaints? E-mail us at info@trainiq.nl.

Trainiq

The platform for training providers

PlatformAll featuresPortalsPricingTrainiq ConnectQuinn
Who it is forBHV training providersVCA providersCode 95 trainersHealthcare trainingDog training schoolsCourse administration
SupportBlogLegalPrivacySecurityContact

© 2026 Trainiq B.V. · Einsteinlaan 28, 2289 CC Rijswijk, the Netherlands · Chamber of Commerce 42053044 · +31 85 071 1114