We're here to help - Privacy Policy and more
Last updated: July 15, 2026
Effective date: January 1, 2024
Who we are
CinderMonkey B.V. ("CinderMonkey", "we", "us") is a team strategy and culture partner registered in the Netherlands under KvK number 42082087, with its registered office at Wilgenweg 18B, 1031 HV Amsterdam. Our work is delivered primarily from Amsterdam. VAT/BTW number: NL003910187B87
CinderMonkey B.V. is the data controller for the personal data described in this policy. We have not appointed a formal Data Protection Officer, as our processing does not meet the scale or nature threshold that requires one under Article 37 GDPR; questions about this policy or your data can be directed to the CinderMonkey Operational Team at getstarted@cindermonkey.agency
Who this policy covers
This policy applies to: visitors to cindermonkey.agency; prospective and current clients and the individuals within client organisations who take part in our diagnostics, workshops, or programmes (including APE-X Rootdigging, MonkeyDojo, and META Teams); newsletter subscribers; and job applicants.
What personal data we collect
Provided directly by you: name, email address, phone number, job title and organisation, billing details, and the content of any messages you send us.
Collected through our services: responses to diagnostic surveys and questionnaires (for example the Team Performance Profiler, 360° feedback, or cultural/organisational assessments), workshop and session notes, and feedback forms.
Booking data: when you schedule a call through our booking tool, we collect the name, email, and any details you provide at that time.
Collected automatically: website usage data via cookies and similar technologies, pages viewed, referring/exit pages, approximate location derived from IP address, and device/browser information. See our Cookie Policy for full detail.
Why we process your data, and on what legal basis
To deliver our services and fulfil our contracts with clients. legal basis: performance of a contract (Art. 6(1)(b) GDPR).
To respond to enquiries and provide client support. legal basis: contract, or our legitimate interest in maintaining client relationships (Art. 6(1)(f)).
To send the Monthly Two's newsletter and other marketing communications. legal basis: your consent (Art. 6(1)(a)), which you can withdraw at any time.
To understand and improve how our website is used. legal basis: our legitimate interest in operating and improving our business (Art. 6(1)(f)).
To meet our legal and tax obligations, including financial record-keeping. legal basis: legal obligation (Art. 6(1)(c)).
Artificial intelligence — what we do not do
CinderMonkey does not process, input, or upload any client personal data - including diagnostic and survey responses, 360° feedback, workshop or session notes, or the personal details of any individual participant - into any AI system, including generative AI or large-language-model tools such as ChatGPT, Claude, or Gemini, for the purpose of delivering our services. All analysis, facilitation, and reporting on client and participant data is carried out by our human team.
Where members of our team use AI tools internally for general purposes unrelated to a specific client (for example, drafting non-personal marketing copy or internal research), no client personal data is ever entered into those tools. If this practice changes in the future, we will update this policy in advance of the change and, where the change requires it, obtain your consent first.
Separately: we do not currently operate an AI chatbot or publish AI-generated content on our website. If we introduce either, we will clearly label AI-generated content and disclose AI-driven interactions, in line with Article 50 of the EU AI Act.
Who we share data with
We use a small number of external service providers ("processors") to run our business. We do not sell personal data to anyone.
Provider
Purpose
Location
Notes
Google (Analytics, Appointments/Calendar)
Website analytics; call booking
United States
DPA in place via Google's standard terms
Stripe
Payment processing
Ireland / United States
DPA in place via Stripe's standard terms
ActiveCampaign
Newsletters and email journeys
United States
DPA in place via ActiveCampaign's standard terms
Notion Labs, Inc.
Internal CRM and client records
United States
DPA in place via Notion's standard terms
Typeform
Diagnostic and assessment surveys
Spain / United States
DPA in place via Typeform's standard terms
Monday.com
META Teams delivery — Team Performance Profiler diagnostic and team journey data
Israel / United States
DPA in place via Monday's standard tems and additions through the Meta Team
Enzuzo
Cookie consent management
Canada
DPA in place via Enzuzo's standard terms
International data transfers
Several of our service providers are based outside the European Economic Area. Where personal data is transferred to the United States, we rely on the EU-US Data Privacy Framework for providers certified under it, or the European Commission's Standard Contractual Clauses where a provider is not DPF-certified. Monday.com is headquartered in Israel, which has held a European Commission adequacy decision since 2011 (Decision 2011/61/EU).
How long we keep your data
Financial and administrative records: 7 years, as required by Dutch tax law (Art. 52 AWR).
Marketing and newsletter data: until you unsubscribe or withdraw consent.
Website analytics: up to 14 months (Google Analytics default retention setting).
Diagnostic and assessment responses: 2 years in identifiable form; aggregated or anonymised benchmark data may be retained longer for research purposes
Job applications: 4 weeks after the recruitment process ends, or up to 1 year with your explicit consent to be considered for future roles.
Automated decision-making
We do not make any decision about you based solely on automated processing (including profiling) that produces a legal effect or similarly significantly affects you. Aggregated results from diagnostics (for example, team-level survey summaries) may be shared with a client's leadership team, but individual responses are not used to make automated decisions about any individual.
Your rights
Under the GDPR, you have the right to access, correct, or request erasure of your personal data; to restrict or object to certain processing; to receive your data in a portable format; and to withdraw consent at any time where we rely on consent. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) if you believe we have not handled your data lawfully. To exercise any of these rights, contact getstarted@cindermonkey.agency.
Security
We apply appropriate technical and organisational measures to protect personal data, including encrypted connections, access controls limiting data access to those who need it, and limited retention periods as set out above.
Children
Our services are directed at organisations and working professionals. We do not knowingly collect personal data from individuals under 18.
Changes to this policy
We may update this policy from time to time. The "last updated" date at the top reflects the most recent revision. Material changes will be communicated to active clients directly.