Beyond IQ
Privacy and Cookie Policy
How Beyond IQ collects, uses and protects personal data.
Effective date: 27 August 2026 | Last updated: 27 August 2026
1. Who we are
This policy applies to Beyond IQ and the website https://beyond-iq.com. The service is operated by Beyond IQ, trading as Beyond IQ, at Neuweg 330, 1215 JH Hilversum, the Netherlands. KVK: 77754581. VAT identification number: NL003237675B89.
Privacy enquiries may be sent to info@beyond-iq.com or made by telephone on +31 (0)6 383 36 422. You may also use the contact option published on https://beyond-iq.com. Beyond IQ is the controller of personal data described in this policy unless a contract expressly states that it acts as a processor for a school or another organisation.
2. Personal data we collect
- Identity and contact information, including name, organisation, role, email address, telephone number and correspondence.
- Transaction and administration information, including the service purchased, payment status, invoice details and tax records. Payment card details are processed by the payment provider and are not stored by Beyond IQ.
- Website and device information, including IP address, browser/device details, cookie identifiers, consent choices and website interaction data.
- Communication, feedback, survey responses, testimonials and preferences, including newsletter choices.
- Professional information supplied in enquiries, quotations, consultations, workshops and school projects.
- Participant information for live or recorded workshops, including attendance and questions.
- Information about a child only where a parent/guardian or school provides it for a clearly stated educational purpose.
3. Why we use personal data and our legal bases
- To answer enquiries, prepare quotations, manage registrations, deliver services, provide materials and customer support, and administer accounts: necessary to take steps at your request or perform a contract.
- To invoice, keep financial records and comply with safeguarding, tax, accounting or other legal duties: compliance with a legal obligation.
- To operate securely, prevent misuse, maintain service quality, understand aggregated website use and protect legal rights: legitimate interests, balanced against individual rights.
- To send optional marketing, place non-essential cookies, publish identifiable testimonials or media, or process information where consent is the appropriate basis: consent, which may be withdrawn.
- To protect a person's vital interests in a genuine emergency, where applicable.
4. Children and school-provided information
Beyond IQ services may concern gifted and high-potential children, but the website and purchasing process are intended for adults. Parents, guardians and schools should share only information reasonably necessary for the requested service. Beyond IQ does not knowingly rely on consent given directly by a child under 16 for optional online processing.
5. Sharing information
We share personal data only when needed for the purposes above, under appropriate contractual and security arrangements. Recipients may include:
- Lovable and its infrastructure providers, for website hosting and technical delivery.
- Stripe, for Beyond IQ website payments and payment administration. Stripe receives payment and transaction information under its own privacy terms.
- Google Fonts, for website typography. The implementation should be configured to minimise unnecessary transfer of visitor data.
- YouTube in privacy-enhanced mode (youtube-nocookie.com), for embedded video. The player must remain blocked until consent if it stores or accesses non-essential information.
- Microsoft 365/Teams and Google Workspace/Drive where agreed with a school for secure educational collaboration, document storage or temporary processing.
- Zoom where used for live online workshops or consultations.
- Professional advisers, insurers, auditors, public authorities or courts where necessary or legally required.
- Schools, parents/guardians and program partners where necessary for the agreed educational service and consistent with the information given to the individuals concerned.
We do not sell personal data. If a provider processes data outside the European Economic Area, we use an available lawful transfer mechanism, such as an adequacy decision or approved Standard Contractual Clauses, and apply additional safeguards where required.
6. Retention
- Enquiries that do not lead to a contract: normally up to 24 months after the last meaningful contact.
- Contracts, invoices and core financial administration: normally 7 years, or longer where Dutch law requires.
- Workshop and service administration: the contract period plus up to 2 years, unless a longer period is needed for a dispute or legal claim.
- Student program records: normally up to 2 years after participation ends; safeguarding or incident records may be retained longer where necessary and lawful.
- Newsletter records: until consent is withdrawn, plus a minimal suppression record to honour the opt-out.
- Consent and media-release records: while the material is used and for an appropriate period afterwards to demonstrate consent.
- Cookie consent records and cookie durations: as stated in the live cookie settings; consent should be renewed when required and at least after material changes.
7. Your rights
Subject to the GDPR and any applicable limitations, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier lawful processing. You may also object to direct marketing at any time.
Send requests to info@beyond-iq.com. We may ask for information reasonably necessary to verify identity, but do not send an unredacted passport or BSN unless specifically and lawfully required. We normally respond within one month. You may complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
8. Security
We use proportionate technical and organisational measures, including access controls, secure service providers, limited access, backups and staff/contractor confidentiality. No system is completely secure. If a personal-data breach creates a legally reportable risk, we will follow the applicable notification duties.
10. Changes
We may update this policy when our services, providers or legal obligations change. The current version and effective date will be published on this page. Material changes will be highlighted where appropriate.
Beyond IQ
Neuweg 330, 1215 JH Hilversum, The Netherlands
KVK: 77754581 · VAT: NL003237675B89
info@beyond-iq.com · +31 (0)6 383 36 422
