Privacy Policy

Last updated: August 27, 2026

This policy explains how Pioneer Business Planting processes your personal data, the legal bases we rely on, how long we keep it, who we share it with, and the rights you have under the EU/EEA General Data Protection Regulation (GDPR / AVG) and comparable laws.

1. Who is responsible for your data (controllers)

Pioneer Business Planting is operated jointly by the following organisations, who act as joint controllers for the processing described here:

  • Stichting All Nations Nederland — Zwanenweide 8, 3993 EW Houten, The Netherlands (EU establishment and point of contact for this policy).
  • All Nations™ International — PO Box 901253, Kansas City, MO 64190, United States.

The joint controllers have an arrangement setting out their respective responsibilities under the GDPR/AVG. Stichting All Nations Nederland is the point of contact for this policy. Whichever controller you contact, you may exercise your rights against either. For any privacy question or to exercise your rights, contact us at support@pioneerbusinessplanting.org. We will respond within one month.

2a. Where we get your data

Most personal data comes directly from you when you register, use the platform, or contact us. For our supporter and outreach records (CRM), we may also receive contact details from you via forms and sign-ups, or from a partner or a colleague who introduces you to us. We do not buy personal data, and we do not make decisions that produce legal or similarly significant effects about you based solely on automated processing.

2. What personal data we collect

  • Account & profile — name, email, phone, country, language, and business details you provide.
  • Learning data — course progress, assignments (e.g. budgets, business plans), quiz results, certificates.
  • Coaching & training — coaching notes, training attendance and registrations.
  • Loans & finance — loan applications and related financial information, where you use those features.
  • Communications — messages you send through the in-app chat and to our team.
  • Contact & donor records (CRM) — contact details, engagement history and, for supporters, donation records.
  • Website usage & analytics — pages visited, referrer, campaign parameters and, where you consent, links between your visits and your contact record (profiling — see §3).
  • Technical & security data — IP address and related metadata recorded in security/audit logs, form submissions and one-time-code verification.
  • Consent records — the choices you make and when.

3. Why we process it and our legal bases

  • Providing your account and the learning platform — performance of a contract (GDPR Art. 6(1)(b)).
  • Coaching, training and loan administration — contract, and our legitimate interest in running the programme (Art. 6(1)(b) and (f)).
  • Security, abuse prevention and audit logging (including IP addresses and one-time codes) — legitimate interest and, where applicable, legal obligation (Art. 6(1)(f) and (c)).
  • Financial and donation records — legal obligation (e.g. accounting retention) and legitimate interest (Art. 6(1)(c) and (f)).
  • Newsletters and marketing communications — consent (Art. 6(1)(a)); you can unsubscribe at any time.
  • Statistics cookies and website analytics — consent (Art. 6(1)(a)).
  • Marketing analytics / profiling (linking website visits to your contact record and scoring engagement) — consent (Art. 6(1)(a)). You can withdraw this at any time via “Cookie settings” or by contacting us; withdrawing does not affect processing already carried out.

4. How long we keep it (retention)

  • Account and learning data — for as long as your account is active; deleted on request or after prolonged inactivity.
  • Website analytics — up to 14 months, then deleted.
  • Website-visit history on contact records — up to 24 months.
  • IP addresses in security/audit logs and form submissions — anonymised after 12 months; the underlying log entry may be kept longer for security purposes.
  • Financial and donation records — retained for the period required by applicable law (e.g. statutory accounting retention).

5. Who we share data with (processors)

We do not sell your personal data. We share it only with service providers who process it on our behalf under data-processing agreements, including:

  • Supabase — database, authentication and file storage (hosted in the EU, Ireland).
  • Vercel — application hosting and privacy-friendly analytics (EU region).
  • Brevo — transactional and marketing email (EU, France).
  • e-Boekhouden — accounting, for donation and financial administration (The Netherlands).
  • Cloudflare — bot protection (Turnstile), which processes technical data such as your IP address to distinguish humans from bots, and storage of our course videos.

6. International data transfers

Our database, authentication, storage, email and accounting are hosted within the EU. Cloudflare's Turnstile bot-protection may process technical data (such as your IP address) at global edge locations, some outside the EU. Where any transfer outside the EU occurs, it is covered by appropriate safeguards such as the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework.

7. Your rights

Under the GDPR/AVG you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected (rectification);
  • have your data deleted (erasure / “right to be forgotten”);
  • restrict or object to certain processing;
  • data portability (receive your data in a portable format);
  • withdraw consent at any time, without affecting processing done before withdrawal.

You can delete your account yourself from your profile settings, or exercise any of these rights by emailing support@pioneerbusinessplanting.org.

8. Complaints to a supervisory authority

If you believe we have not handled your data lawfully, you have the right to lodge a complaint with your data-protection authority. In the Netherlands this is the Autoriteit Persoonsgegevens. We would appreciate the chance to address your concern first.

9. Cookies

For details of the cookies we use and how to manage them, see our Cookie Policy.

10. Children

Our services are not directed at children under 16. If you believe a child has provided us personal data without appropriate consent, contact us and we will delete it.

11. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above and, where appropriate, by asking for renewed consent.