Search here…

Search here…

Search here…

We're here to help - Privacy Policy and more

Last updated: July 15, 2026
Effective date: January 1, 2024

Who we are

CinderMonkey B.V. ("CinderMonkey", "we", "us") is a team strategy and culture partner registered in the Netherlands under KvK number 42082087, with its registered office at Wilgenweg 18B, 1031 HV Amsterdam. Our work is delivered primarily from Amsterdam. VAT/BTW number: NL003910187B87

CinderMonkey B.V. is the data controller for the personal data described in this policy. We have not appointed a formal Data Protection Officer, as our processing does not meet the scale or nature threshold that requires one under Article 37 GDPR; questions about this policy or your data can be directed to the CinderMonkey Operational Team at getstarted@cindermonkey.agency

Who this policy covers

This policy applies to: visitors to cindermonkey.agency; prospective and current clients and the individuals within client organisations who take part in our diagnostics, workshops, or programmes (including APE-X Rootdigging, MonkeyDojo, and META Teams); newsletter subscribers; and job applicants.

What personal data we collect

  • Provided directly by you: name, email address, phone number, job title and organisation, billing details, and the content of any messages you send us.

  • Collected through our services: responses to diagnostic surveys and questionnaires (for example the Team Performance Profiler, 360° feedback, or cultural/organisational assessments), workshop and session notes, and feedback forms.

  • Booking data: when you schedule a call through our booking tool, we collect the name, email, and any details you provide at that time.

  • Collected automatically: website usage data via cookies and similar technologies, pages viewed, referring/exit pages, approximate location derived from IP address, and device/browser information. See our Cookie Policy for full detail.

Why we process your data, and on what legal basis

  • To deliver our services and fulfil our contracts with clients. legal basis: performance of a contract (Art. 6(1)(b) GDPR).

  • To respond to enquiries and provide client support. legal basis: contract, or our legitimate interest in maintaining client relationships (Art. 6(1)(f)).

  • To send the Monthly Two's newsletter and other marketing communications. legal basis: your consent (Art. 6(1)(a)), which you can withdraw at any time.

  • To understand and improve how our website is used. legal basis: our legitimate interest in operating and improving our business (Art. 6(1)(f)).

  • To meet our legal and tax obligations, including financial record-keeping. legal basis: legal obligation (Art. 6(1)(c)).

Artificial intelligence — what we do not do

CinderMonkey does not process, input, or upload any client personal data - including diagnostic and survey responses, 360° feedback, workshop or session notes, or the personal details of any individual participant - into any AI system, including generative AI or large-language-model tools such as ChatGPT, Claude, or Gemini, for the purpose of delivering our services. All analysis, facilitation, and reporting on client and participant data is carried out by our human team.

Where members of our team use AI tools internally for general purposes unrelated to a specific client (for example, drafting non-personal marketing copy or internal research), no client personal data is ever entered into those tools. If this practice changes in the future, we will update this policy in advance of the change and, where the change requires it, obtain your consent first.

Separately: we do not currently operate an AI chatbot or publish AI-generated content on our website. If we introduce either, we will clearly label AI-generated content and disclose AI-driven interactions, in line with Article 50 of the EU AI Act.

Who we share data with

We use a small number of external service providers ("processors") to run our business. We do not sell personal data to anyone.

Provider

Purpose

Location

Notes

Google (Analytics, Appointments/Calendar)

Website analytics; call booking

United States

DPA in place via Google's standard terms

Stripe

Payment processing

Ireland / United States

DPA in place via Stripe's standard terms

ActiveCampaign

Newsletters and email journeys

United States

DPA in place via ActiveCampaign's standard terms

Notion Labs, Inc.

Internal CRM and client records

United States

DPA in place via Notion's standard terms

Typeform

Diagnostic and assessment surveys

Spain / United States

DPA in place via Typeform's standard terms

Monday.com

META Teams delivery — Team Performance Profiler diagnostic and team journey data

Israel / United States

DPA in place via Monday's standard tems and additions through the Meta Team

Enzuzo

Cookie consent management

Canada

DPA in place via Enzuzo's standard terms

International data transfers

Several of our service providers are based outside the European Economic Area. Where personal data is transferred to the United States, we rely on the EU-US Data Privacy Framework for providers certified under it, or the European Commission's Standard Contractual Clauses where a provider is not DPF-certified. Monday.com is headquartered in Israel, which has held a European Commission adequacy decision since 2011 (Decision 2011/61/EU).

How long we keep your data

  • Financial and administrative records: 7 years, as required by Dutch tax law (Art. 52 AWR).

  • Marketing and newsletter data: until you unsubscribe or withdraw consent.

  • Website analytics: up to 14 months (Google Analytics default retention setting).

  • Diagnostic and assessment responses: 2 years in identifiable form; aggregated or anonymised benchmark data may be retained longer for research purposes

  • Job applications: 4 weeks after the recruitment process ends, or up to 1 year with your explicit consent to be considered for future roles.

Automated decision-making

We do not make any decision about you based solely on automated processing (including profiling) that produces a legal effect or similarly significantly affects you. Aggregated results from diagnostics (for example, team-level survey summaries) may be shared with a client's leadership team, but individual responses are not used to make automated decisions about any individual.

Your rights

Under the GDPR, you have the right to access, correct, or request erasure of your personal data; to restrict or object to certain processing; to receive your data in a portable format; and to withdraw consent at any time where we rely on consent. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) if you believe we have not handled your data lawfully. To exercise any of these rights, contact getstarted@cindermonkey.agency.

Security

We apply appropriate technical and organisational measures to protect personal data, including encrypted connections, access controls limiting data access to those who need it, and limited retention periods as set out above.

Children

Our services are directed at organisations and working professionals. We do not knowingly collect personal data from individuals under 18.

Changes to this policy

We may update this policy from time to time. The "last updated" date at the top reflects the most recent revision. Material changes will be communicated to active clients directly.