
Version 1.0 · Effective: April 2026
This Privacy Notice describes how we, Stichting Xconea (operating the ColorAptitude product), process personal data in connection with the ColorAptitude website, the ColorAptitude assessment platform, the dealer programme, and related services. It applies to all personal data we process in our role as data controller within the meaning of Article 4(7) of the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR").
We have written this notice to be readable. Where information is technical, we explain the practical effect first.
The data controller responsible for processing your personal data is:
Stichting Xconea
Trading as: ColorAptitude
Operating the product: ColorAptitude
Allenstraat 110, Krommenie, The Netherlands
Privacy contact: privacy@coloraptitude.com
General contact: support@coloraptitude.com
We do not have a statutory obligation to appoint a Data Protection Officer, but the privacy contact above handles all privacy-related queries.
We process personal data of four broad groups of people. The remainder of this notice describes how we treat each.
Categories of data
Purposes
Legal basis
Categories of data
Purposes
Legal basis
Categories of data
Purposes
Legal basis
Categories of data
Purposes
Legal basis
Where a customer purchases a subscription using a reseller code, we share a limited set of commercial data (organisation name and address; billing and commercial contact details; subscription tier, seat count, dates, status, contract value; invoice and payment records relevant to commission; attribution data) with the relevant reseller, through the reseller dashboard.
We rely on legitimate interest under Article 6(1)(f) GDPR for this sharing. Resellers act as independent data controllers for the limited commercial data (Category A) they receive — they are not data processors within the meaning of Article 28 GDPR and no data processing agreement is required between ColorAptitude and its resellers. Resellers are contractually prohibited from accessing assessment data, certificates, training progress, or any individual user information.
The ColorAptitude assessment generates scores and a competency profile through automated calculation against established colour-difference metrics (OKLCH / CIEDE2000) using a three-layer scoring framework (Discrimination, Attribution and Communication layers) with provisional competence profiles. The result is a descriptive profile, not a decision with legal or similarly significant effect within the meaning of Article 22 GDPR.
Where you use the assessment within an employment, qualification or compliance context (for example, observer qualification under ASTM E1499-16), the use of your score by your employer or organisation is the responsibility of that organisation, not of ColorAptitude. We do not make hiring, promotion, or other employment decisions on your behalf.
We do not engage in profiling for advertising or behavioural prediction outside the assessment service itself.
Personal data is accessed within our organisation only by personnel for whom such access is necessary for their role, on a need-to-know basis.
We rely on a limited number of established service providers, each bound by appropriate data protection terms. The current list of sub-processors is:
| Provider | Purpose | Location of processing |
|---|---|---|
| Stripe | Payment processing and subscription billing | EEA / United States (under SCCs) |
| Resend | Transactional email delivery | EEA / United States (under SCCs) |
| ActiveCampaign | Marketing automation and CRM | EEA / United States (under SCCs) |
| Moneybird | Invoicing and accounting administration | Netherlands (EEA) |
| Vercel | Hosting of the ColorAptitude website and platform | EEA / United States (under SCCs) |
| Neon | Database hosting | EEA / United States (under SCCs) |
An up-to-date list is available on request from privacy@coloraptitude.com.
As described in section 4.5, where you purchase via a reseller code, a limited set of commercial data is made available to that reseller in their capacity as independent controller for programme administration purposes. Resellers are contractually prohibited from accessing assessment results, certificates, or any individual user information, and are bound to confidentiality, security, and use restrictions consistent with our reseller agreement.
We may disclose personal data to competent authorities where we are required to do so by law. We do not sell personal data and we do not share it for the marketing purposes of unrelated third parties.
We process personal data primarily within the European Economic Area (EEA). Where transfer to a country outside the EEA is necessary — typically because a service provider operates from outside the EEA — we rely on appropriate safeguards under Chapter V GDPR.
In practice, transfers to non-EEA service providers are covered by Standard Contractual Clauses (SCCs) adopted by the European Commission, supplemented where necessary by additional technical and contractual measures. You may request a copy of the relevant safeguards from privacy@coloraptitude.com.
We retain personal data only as long as needed for the purposes described in this notice, plus the legal retention periods that apply to us.
| Data category | Retention period |
|---|---|
| Account data (active subscriptions) | For the duration of the subscription and account. |
| Account data after cancellation | Up to 24 months after end of subscription, then deleted or anonymised, except where longer retention is required by law. |
| Assessment results and certificates | For the duration of the subscription. After cancellation, retained in anonymised form for normative comparison; identifiable records deleted within 24 months unless required for legal claims or audit obligations. |
| Invoices, payment records, accounting data | Seven (7) years from the end of the relevant fiscal year, in line with Dutch tax law. |
| Reseller commercial data | For the duration of the reseller agreement. Records relevant to invoicing and commission retained for 7 years. |
| Marketing data (consented) | Until consent is withdrawn or no engagement for 24 months, whichever comes first. |
| Support and correspondence | Three (3) years after the last interaction. |
| Website analytics (aggregate) | Up to 26 months in identifiable form; aggregated thereafter. |
| Server logs (security and operations) | Up to 12 months. |
Under the GDPR, you have the rights set out below. To exercise any of these rights, contact us at privacy@coloraptitude.com. We respond within one month of a verifiable request, extendable by a further two months for complex requests.
To verify your identity before responding to a rights request, we may ask you to confirm details that match what we hold, in line with Article 12(6) GDPR. We do not charge for handling requests except where requests are manifestly unfounded or excessive.
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration or disclosure, in line with Article 32 GDPR. Measures include access control with role-based permissions, multi-factor authentication on administrative access, encryption of data in transit (TLS) and at rest where applicable, regular backups, security patching, logging, and a documented incident response procedure.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we notify the Autoriteit Persoonsgegevens within 72 hours, in line with Article 33 GDPR. Where the risk is high, we also notify you directly, in line with Article 34 GDPR.
ColorAptitude is a professional service intended for adults. We do not knowingly collect personal data from individuals under 16 years of age. Where we become aware that data of a person under 16 has been collected without an appropriate legal basis, we delete it without undue delay.
We use cookies and similar technologies for essential site operation, security, and (with your consent) for analytics. Detailed information on the cookies we use, their purpose, and your choices is available in our Cookie Policy.
We may update this Privacy Notice from time to time, for example to reflect changes in our services, in our service providers, or in applicable law. The version date at the top of this notice indicates when the notice was last updated.
Material changes — those that significantly affect the way your data is processed or your rights — will be communicated to active customers and resellers by email at least 30 days before the effective date. Non-material changes (clarifications, corrections, additions to the sub-processor list) take effect on publication.
For any privacy-related question, request, or concern, contact us at:
BNK Foundation
Trading as: Xconea
Operating: ColorAptitude
Allenstraat 110, Krommenie, The Netherlands