Privacy Statement

Why this privacy statement?

NHL Stenden is responsible for processing your personal data. In this privacy statement, we explain how we handle your personal data, what your rights are, and what you need to know about your privacy.

Privacy is not just anything, it is a fundamental right. In a data-driven society, the protection of personal data is a top priority for educational institutions. We therefore attach great importance to protecting your personal data. You can rest assured that they are in good hands with us.

This privacy statement informs you about how we use your data in the context of the creatingwhatsnext platform. In this statement, we only discuss the processing of personal data that is directly related to this platform.

The general NHL Stenden privacy statement can be found on the general NHL Stenden website under the Privacy Statement button at the bottom of the page.

What is creatingwhatsnext?

We prefer to talk about a platform instead of a website.

It’s not only a website about Hotel Management School Leeuwarden (HMSL), it has a broader approach; it is an ‘online meeting place’ for HMSL and the industry.

This perfectly fits the philosophy of Hotel Management School Leeuwarden: giving the hospitality industry a major role in our study programmes. Because working closely together is the only way we can educate Game Changers who are ready for the hospitality industry of tomorrow.

From whom, and in what way, do we process personal data?

Visitors of the platform

The platform creatingwhatsnext.com processes cookies for the functionality of the website, and to measure certain information. For more information please check out our Cookie Policy.

Users of our contact form

When you fill out our contact form, the information you share in that is processed by us for the duration it takes to answer your question(s). No other information about you is saved to our servers than the information you fill out in the form. This means that if you choose to use the form, your name, surname, email address and message are being processed by us.

We need this information to be able to adequately answer the questions you may have.

We don’t process your data any longer than is necessary for the goal of the processing. After you receive an answer, your information is deleted from our server within 6 months.

Why do we process your personal data?

The GDPR stipulates that we may only process your personal data if we need it to achieve a clearly defined goal. The goal of the contact information is to provide you with an answer to the questions you ask us. An objective alone is not enough to be allowed to process data; there must also be a basis for doing so as defined in the GDPR. The bases are listed in Article 6 of the GDPR. For processing your contact information, we rely on so-called ‘legitimate interest’ (article 6 sub f GDPR).

Which other parties do we work with and why?

NHL Stenden also engages third parties for the processing of personal data, the so-called processors. For creatingwhatsnext, this concerns MINSK B.V. They design, build and maintain the website. We have concluded a so-called data processing agreement with this party, as prescribed by the GDPR.

How do we secure your personal data?

NHL Stenden has taken appropriate technical and organisational measures to protect your data. Check for the measures the website: Privacyverklaring | NHL Stenden.

Our third party, MINSK B.V is securing our data as follows: all data exchanged between your browser and our website is encrypted using secure HTTPS connections. Our website uses a valid SSL/TLS certificate issued by Let’s Encrypt and supports the latest security protocols, including TLS 1.3 and TLS 1.2. This ensures that your data is transmitted securely and cannot be intercepted by other parties.

In addition, they use strong cipher suites and Perfect Forward Secrecy (PFS), which ensures that even if encryption keys were ever compromised, previously transmitted data would remain protected.

Other measures MINSK takes to protect your data include:

  • Regular updates and security patches on our servers
  • Continuous monitoring for vulnerabilities and unauthorized access
  • Strict configuration of our web infrastructure to meet industry best practices
  • Use of trusted service providers that adhere to high security standards

But what if a data breach does occur?

NHL Stenden has a procedure for reporting and handling data breaches. The procedure and the report button can be found under the Privacy and Security tile on the intranet and under the Privacy and Security tile in Topdesk (the self-service portal of NHL Stenden’s service desk). If you do not have an NHL Stenden account but need to report a data breach, you can contact our Data Protection Officer through their email address: fg@nhlstenden.com.

What are your rights?

The GDPR gives you a number of rights. For example, you have the right to ask us which of your data we process, and if they are incorrect, you can have them corrected. In addition, in some situations you can request that your data be deleted or that the processing of your data be limited. You can also object to the processing of your data.

You can read more about your rights in the general Privacy Statement of NHL Stenden. Would you like to directly invoke one of these rights? Then click here and fill in the form. We will contact you within a few working days and your request will be dealt with within a month, if possible.

Questions or complaints?

If you have any questions or complaints about the way in which NHL Stenden handles your personal data, you can email or call our Data Protection Officer.

Email
fg@nhlstenden.com

Phone
+ 31 6 571 86075

If, after reading this document and a conversation with the Data Protection Officer, you still have complaints about how NHL Stenden handles your privacy, you can file a complaint with the Dutch Data Protection Authority.