Privacy Policy
Last updated: 9 September 2026
Who we are
Bardo Professional is a trading identity of Bardo Maritime, a business registered in the Netherlands.
Bardo Maritime is responsible for the processing of personal data described in this Privacy Policy.
For questions about this policy, your personal data, or to exercise your privacy rights:
Personal data we collect
We only collect and process personal data where it is relevant to our business activities.
Depending on how you interact with us, this may include:
- your name;
- email address and telephone number;
- position, role or organisation;
- information you provide through our website contact form;
- correspondence by email, Microsoft Teams, telephone or WhatsApp;
- information provided in connection with an enquiry, coaching engagement or leadership-development service;
- contractual, invoicing and payment information; and
- technical information associated with use of our website or submission of a form, such as IP address, browser information and cookie information.
Please avoid sending sensitive personal information through the website contact form unless it is necessary.
Why we use your personal data
We may process personal data in order to:
- respond to enquiries and requests;
- discuss or prepare a potential engagement;
- provide agreed coaching, leadership-development or related professional services;
- communicate with clients and prospective clients;
- arrange meetings and maintain appropriate records of our work;
- prepare and administer contracts, confidentiality agreements and other business arrangements;
- issue invoices, receive payments and maintain our business and tax administration;
- comply with legal and regulatory obligations;
- establish, exercise or defend legal rights; and
- maintain the security and proper functioning of our website and business systems.
Legal bases for processing
Depending on the circumstances, we process personal data because:
- it is necessary to take steps at your request before entering into a contract;
- it is necessary to perform a contract;
- we have a legitimate business interest in communicating with clients and prospective clients, administering our business and protecting our legal interests;
- we have a legal obligation to retain or process certain information; or
- you have given consent where consent is the appropriate legal basis.
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing that was lawful before consent was withdrawn.
Contact forms and enquiries
When you use the contact form on this website, the information you submit is processed through Jetpack Forms and retained as a form response within our WordPress environment. A notification or copy of the enquiry is also received through our Microsoft 365 email environment.
The form may also record technical information associated with the submission, including IP address and browser information.
General enquiries that do not develop into an ongoing business relationship are normally retained for up to 24 months after the last substantive contact. This allows reasonable follow-up on previous enquiries and conversations.
If an enquiry develops into a contractual or client relationship, relevant information may be retained for a different period as described below.
Coaching and professional engagements
In providing coaching or leadership-development services, we may process information supplied during the engagement and maintain working notes where appropriate.
Coaching working notes are normally retained for up to three years after the last substantive contact or coaching session, unless there is a legitimate or legal reason requiring particular information to be retained longer.
We distinguish these working records from financial, contractual and statutory business records, which may be subject to different retention requirements.
Financial and business administration
We process information necessary for invoicing, payments, accounting and business administration.
Our administration may involve Microsoft 365, Excel, MoneyMonk and our banking provider.
Dutch tax law requires certain business administration to be retained for prescribed periods. Relevant core business records are generally retained for seven years where required by law.
Where the law requires us to retain information, that legal requirement takes precedence over our normal deletion periods.
Contracts and confidentiality agreements
Contracts, non-disclosure agreements, confidentiality agreements and relevant supporting records may be retained for the duration of the agreement and afterwards where reasonably necessary to:
- comply with continuing contractual or confidentiality obligations;
- establish the terms under which information was provided;
- establish, exercise or defend legal claims; or
- comply with statutory record-keeping requirements.
We do not retain unrelated personal information indefinitely merely because a contract or confidentiality agreement exists.
Service providers and sharing of information
We use third-party services to operate our website and business. Depending on your interaction with us, personal information may therefore be processed through services used for:
- website hosting and website forms;
- email, file storage and business productivity;
- video meetings and communications;
- accounting and financial administration;
- banking and payment processing; and
- business communications.
These currently include services such as WordPress/Jetpack, Microsoft 365 and Teams, Dropbox, MoneyMonk and, where used for direct communications, WhatsApp and Apple services.
We may also disclose information where required by law or where reasonably necessary to establish, exercise or defend legal rights.
We do not sell personal data.
International processing
Some of the technology providers we use operate internationally. As a result, personal data may in some circumstances be processed outside the Netherlands or the European Economic Area.
Where this occurs, we rely on the safeguards applicable to the relevant service and processing arrangement, as required by data-protection law.
Cookies
This website uses cookies and similar technologies where necessary for the operation of the website and, where applicable, subject to your privacy choices.
More information about the cookies used by this website, their purposes and your choices is available in our Cookie Policy.
You can also change your cookie preferences using the consent-management function on the website.
How long we keep personal data
We do not intend to keep personal data longer than reasonably necessary for the purpose for which it was collected.
Our principal retention periods are:
- General enquiries and associated contact-form submissions: up to 24 months after the last substantive contact.
- Coaching working notes: up to three years after the last substantive contact or session.
- Financial and statutory business records: for the period required by applicable law, generally seven years for relevant Dutch business administration.
- Contracts, NDAs and confidentiality records: for the duration of their relevance and afterwards where reasonably necessary for continuing contractual obligations, statutory requirements or legal claims.
Different periods may apply where the law requires information to be retained longer or where there is a legitimate need relating to a dispute or legal claim.
Your privacy rights
Subject to the conditions provided by applicable data-protection law, you may have the right to:
- request access to your personal data;
- have inaccurate personal data corrected;
- request deletion of your personal data;
- request restriction of processing;
- object to certain processing;
- receive or transfer certain personal data where the right to data portability applies; and
- withdraw consent where processing is based on consent.
To exercise a privacy right, contact:
We may need to verify your identity before acting on a request.
You also have the right to lodge a complaint with the Autoriteit Persoonsgegevens, the Dutch supervisory authority for data protection.
Security
We take reasonable organisational and technical measures intended to protect personal information against unauthorised access, loss, misuse or disclosure.
No internet or electronic storage system can provide absolute security, but we review how information is handled and limit its use to legitimate business purposes.
Changes to this Privacy Policy
We may update this Privacy Policy when our services, systems or legal obligations change.
The current version will be published on this website with the date of the latest update shown at the top.
Working internationally.