Your data protection rights under European law
Last updated: August 2026
Zen Utrecht is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements and how you can exercise your rights.
Zen Utrecht acts as the data controller for personal information collected through our services and website. We are responsible for deciding how your personal data is processed and for what purposes.
Contact details:
Zen Utrecht
Oudegracht 287
3511 PD Utrecht
Netherlands
Email: [email protected]
Under GDPR, you have the following rights regarding your personal data:
You have the right to know how we collect, use, and share your personal data. This information is provided in our Privacy Policy.
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of your request.
If you believe any personal data we hold about you is inaccurate or incomplete, you have the right to request correction. We will update your information within one month.
Also known as the "right to be forgotten," you can request deletion of your personal data in certain circumstances, including:
Note that we may need to retain certain information for legal or administrative purposes.
You can request that we limit how we use your personal data in certain situations:
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transfer it to another controller when:
You can object to processing of your personal data when:
You have the right not to be subject to decisions based solely on automated processing that produces legal or similarly significant effects. We do not currently use automated decision-making or profiling.
To exercise any of your GDPR rights, please contact us at [email protected] with your request. Please include:
We will respond to your request within one month. In complex cases, we may extend this period by two additional months, and we will inform you if this is necessary.
We only process your personal data when we have a lawful basis to do so:
We implement appropriate technical and organizational measures to ensure data security, including:
If we transfer your personal data outside the European Economic Area, we ensure appropriate safeguards are in place, such as:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you without undue delay. We will also report the breach to the relevant supervisory authority within 72 hours of becoming aware of it.
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with a supervisory authority. In the Netherlands, this is:
Autoriteit Persoonsgegevens
Postbus 93374
2509 AJ Den Haag
Netherlands
Website: autoriteitpersoonsgegevens.nl
We regularly review our GDPR compliance procedures. Any significant changes will be communicated through our website and, where appropriate, directly to you.
If you have questions about our GDPR compliance or how we process your personal data, please contact us at [email protected]