ColorAptitude™

Privacy Notice

Version 1.0 · Effective: April 2026

1. Introduction

This Privacy Notice describes how we, Stichting Xconea (operating the ColorAptitude product), process personal data in connection with the ColorAptitude website, the ColorAptitude assessment platform, the dealer programme, and related services. It applies to all personal data we process in our role as data controller within the meaning of Article 4(7) of the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR").

We have written this notice to be readable. Where information is technical, we explain the practical effect first.

2. Who We Are

The data controller responsible for processing your personal data is:

Stichting Xconea

Trading as: ColorAptitude

Operating the product: ColorAptitude

Allenstraat 110, Krommenie, The Netherlands

Privacy contact: privacy@coloraptitude.com

General contact: support@coloraptitude.com

We do not have a statutory obligation to appoint a Data Protection Officer, but the privacy contact above handles all privacy-related queries.

3. Whose Data We Process

We process personal data of four broad groups of people. The remainder of this notice describes how we treat each.

  • Website visitors — anyone visiting coloraptitude.com or related pages.
  • Customers and end users — individuals who take a ColorAptitude assessment, complete training, or hold an account on the platform, whether on a personal subscription or through a business account.
  • Business contacts — administrators, billing contacts and other commercial contacts within customer organisations.
  • Reseller contacts — primary, billing and commercial contacts at organisations that participate in the ColorAptitude reseller programme.

4. What Data We Process and Why

4.1 Website visitors

Categories of data

  • IP address, device type, browser, operating system, referring page, pages visited, timestamps.
  • Information you provide via contact forms (name, email, message).
  • Mini-scan inputs and results (if you complete the free mini-scan).

Purposes

  • Providing the website and ensuring its security and proper operation.
  • Understanding aggregate website usage to improve content and structure.
  • Responding to contact form enquiries.
  • Operating the free mini-scan and showing you indicative results.

Legal basis

  • Legitimate interest under Article 6(1)(f) GDPR for security, operation and aggregate analytics.
  • Consent under Article 6(1)(a) for non-essential cookies and tracking — see our Cookie Policy.

4.2 Customers and end users (paid platform)

Categories of data

  • Identification: name, email address.
  • Demographic for normalisation: age (used to compare your score against the age-corrected professional norm).
  • Optional professional context: industry, role, organisation.
  • Account data: login identifier, hashed password, login timestamps.
  • Assessment data: responses, scores, the 3×3 competency matrix output, certificates issued, training progress.
  • Subscription and payment data: subscription tier, dates, status, payment method tokens (full payment card data is held by Stripe, not by us).
  • Communications: support tickets, correspondence, email content where you contact us.
  • Marketing consent state (where applicable).

Purposes

  • Operating your account and delivering the assessment, certification and training services.
  • Calculating, displaying and storing your scores and certificates.
  • Processing subscription payments and renewals.
  • Maintaining audit documentation in line with ASTM E1499-16 and ISO/IEC 17025 references.
  • Providing customer support.
  • Sending service communications (renewal reminders, certificate issuance, security notices).
  • Sending marketing communications, where you have given consent.

Legal basis

  • Performance of contract under Article 6(1)(b) GDPR for account, assessment, certification and payment processing.
  • Legal obligation under Article 6(1)(c) for tax, accounting and statutory record retention.
  • Legitimate interest under Article 6(1)(f) for security, fraud prevention, service improvement, and audit documentation.
  • Consent under Article 6(1)(a) for marketing communications, which can be withdrawn at any time.

4.3 Business contacts

Categories of data

  • Name, business email address, role, telephone.
  • Organisation, address, registration number, VAT number.
  • Communications and account access logs.

Purposes

  • Managing the business account on behalf of the customer organisation.
  • Invoicing, payment, and tax administration.
  • Commercial communications regarding the subscription.

Legal basis

  • Performance of contract under Article 6(1)(b) GDPR with the customer organisation.
  • Legal obligation under Article 6(1)(c) for invoicing and tax records.
  • Legitimate interest under Article 6(1)(f) for relationship management with business contacts.

4.4 Reseller contacts

Categories of data

  • Name, role, business email, telephone of primary, billing and commercial contacts at the reseller organisation.
  • Reseller organisation details: legal name, address, registration number, VAT number, IBAN.
  • Reseller activity data: code attribution, commission calculation records, dashboard usage logs.

Purposes

  • Operating the reseller programme and the reseller dashboard.
  • Calculating and paying commission.
  • Communications regarding the reseller relationship.

Legal basis

  • Performance of contract under Article 6(1)(b) GDPR with the reseller organisation.
  • Legal obligation under Article 6(1)(c) for tax and accounting.
  • Legitimate interest under Article 6(1)(f) for programme administration.

4.5 Sharing of commercial data with resellers

Where a customer purchases a subscription using a reseller code, we share a limited set of commercial data (organisation name and address; billing and commercial contact details; subscription tier, seat count, dates, status, contract value; invoice and payment records relevant to commission; attribution data) with the relevant reseller, through the reseller dashboard.

We rely on legitimate interest under Article 6(1)(f) GDPR for this sharing. Resellers act as independent data controllers for the limited commercial data (Category A) they receive — they are not data processors within the meaning of Article 28 GDPR and no data processing agreement is required between ColorAptitude and its resellers. Resellers are contractually prohibited from accessing assessment data, certificates, training progress, or any individual user information.

5. Automated Decision-making and Profiling

The ColorAptitude assessment generates scores and a competency profile through automated calculation against established colour-difference metrics (OKLCH / CIEDE2000) using a three-layer scoring framework (Discrimination, Attribution and Communication layers) with provisional competence profiles. The result is a descriptive profile, not a decision with legal or similarly significant effect within the meaning of Article 22 GDPR.

Where you use the assessment within an employment, qualification or compliance context (for example, observer qualification under ASTM E1499-16), the use of your score by your employer or organisation is the responsibility of that organisation, not of ColorAptitude. We do not make hiring, promotion, or other employment decisions on your behalf.

We do not engage in profiling for advertising or behavioural prediction outside the assessment service itself.

6. Who Receives Your Data

6.1 Within BNK Foundation

Personal data is accessed within our organisation only by personnel for whom such access is necessary for their role, on a need-to-know basis.

6.2 Service providers (sub-processors)

We rely on a limited number of established service providers, each bound by appropriate data protection terms. The current list of sub-processors is:

ProviderPurposeLocation of processing
StripePayment processing and subscription billingEEA / United States (under SCCs)
ResendTransactional email deliveryEEA / United States (under SCCs)
ActiveCampaignMarketing automation and CRMEEA / United States (under SCCs)
MoneybirdInvoicing and accounting administrationNetherlands (EEA)
VercelHosting of the ColorAptitude website and platformEEA / United States (under SCCs)
NeonDatabase hostingEEA / United States (under SCCs)

An up-to-date list is available on request from privacy@coloraptitude.com.

6.3 Resellers (independent controllers, limited data only)

As described in section 4.5, where you purchase via a reseller code, a limited set of commercial data is made available to that reseller in their capacity as independent controller for programme administration purposes. Resellers are contractually prohibited from accessing assessment results, certificates, or any individual user information, and are bound to confidentiality, security, and use restrictions consistent with our reseller agreement.

6.4 Other recipients

We may disclose personal data to competent authorities where we are required to do so by law. We do not sell personal data and we do not share it for the marketing purposes of unrelated third parties.

7. International Transfers

We process personal data primarily within the European Economic Area (EEA). Where transfer to a country outside the EEA is necessary — typically because a service provider operates from outside the EEA — we rely on appropriate safeguards under Chapter V GDPR.

In practice, transfers to non-EEA service providers are covered by Standard Contractual Clauses (SCCs) adopted by the European Commission, supplemented where necessary by additional technical and contractual measures. You may request a copy of the relevant safeguards from privacy@coloraptitude.com.

8. How Long We Keep Your Data

We retain personal data only as long as needed for the purposes described in this notice, plus the legal retention periods that apply to us.

Data categoryRetention period
Account data (active subscriptions)For the duration of the subscription and account.
Account data after cancellationUp to 24 months after end of subscription, then deleted or anonymised, except where longer retention is required by law.
Assessment results and certificatesFor the duration of the subscription. After cancellation, retained in anonymised form for normative comparison; identifiable records deleted within 24 months unless required for legal claims or audit obligations.
Invoices, payment records, accounting dataSeven (7) years from the end of the relevant fiscal year, in line with Dutch tax law.
Reseller commercial dataFor the duration of the reseller agreement. Records relevant to invoicing and commission retained for 7 years.
Marketing data (consented)Until consent is withdrawn or no engagement for 24 months, whichever comes first.
Support and correspondenceThree (3) years after the last interaction.
Website analytics (aggregate)Up to 26 months in identifiable form; aggregated thereafter.
Server logs (security and operations)Up to 12 months.

9. Your Rights

Under the GDPR, you have the rights set out below. To exercise any of these rights, contact us at privacy@coloraptitude.com. We respond within one month of a verifiable request, extendable by a further two months for complex requests.

Right of access
You may obtain confirmation of whether we process your personal data and a copy of the data we hold.
Right to rectification
You may have inaccurate or incomplete data corrected.
Right to erasure
You may have your personal data deleted where the legal grounds in Article 17 GDPR apply, in particular when the data is no longer necessary for the purposes for which it was collected.
Right to restriction of processing
You may have processing restricted in the cases listed in Article 18 GDPR.
Right to data portability
For data we process based on your consent or in performance of a contract, you may obtain a copy in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible.
Right to object
You may object to processing based on legitimate interest, including profiling, on grounds relating to your particular situation. Where you object, we cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims.
Right to withdraw consent
Where processing is based on consent, you may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). You may also lodge a complaint with the supervisory authority of the EU member state where you live or work.

To verify your identity before responding to a rights request, we may ask you to confirm details that match what we hold, in line with Article 12(6) GDPR. We do not charge for handling requests except where requests are manifestly unfounded or excessive.

10. Security

We apply appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration or disclosure, in line with Article 32 GDPR. Measures include access control with role-based permissions, multi-factor authentication on administrative access, encryption of data in transit (TLS) and at rest where applicable, regular backups, security patching, logging, and a documented incident response procedure.

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we notify the Autoriteit Persoonsgegevens within 72 hours, in line with Article 33 GDPR. Where the risk is high, we also notify you directly, in line with Article 34 GDPR.

11. Children

ColorAptitude is a professional service intended for adults. We do not knowingly collect personal data from individuals under 16 years of age. Where we become aware that data of a person under 16 has been collected without an appropriate legal basis, we delete it without undue delay.

12. Cookies and Similar Technologies

We use cookies and similar technologies for essential site operation, security, and (with your consent) for analytics. Detailed information on the cookies we use, their purpose, and your choices is available in our Cookie Policy.

13. Changes to this Notice

We may update this Privacy Notice from time to time, for example to reflect changes in our services, in our service providers, or in applicable law. The version date at the top of this notice indicates when the notice was last updated.

Material changes — those that significantly affect the way your data is processed or your rights — will be communicated to active customers and resellers by email at least 30 days before the effective date. Non-material changes (clarifications, corrections, additions to the sub-processor list) take effect on publication.

14. Contact

For any privacy-related question, request, or concern, contact us at:

BNK Foundation

Trading as: Xconea

Operating: ColorAptitude

Allenstraat 110, Krommenie, The Netherlands

privacy@coloraptitude.com