World thought leaders in High Performance

Privacy Statement HPO Center

Introduction

HPO Center takes your privacy seriously and processes and uses information about you (the data subject) in a secure manner. In this privacy statement we explain which data we process and for what purpose. You can also read here what rights you have with regard to our processing of your personal data. We recommend that you read this privacy statement carefully. If you have any questions, you can always contact us at schreurs@hpocenter.com.

Who is HPO Center?

HPO Center is the trade name of Center for Organizational Performance B.V., with offices at Hugo van Woerdenstraat 25, 2332 PG Leiden, the Netherlands, registered in the trade register of the Chamber of Commerce under number 32128082.

For privacy questions you can contact us at schreurs@hpocenter.com.

When are we a controller and when are we a processor?

This distinction determines where you should go with questions about your data.

Controller. For the processing operations in which we ourselves determine why and how we use data, we are the controller. This includes our client administration, our invoicing, our newsletter, and our website. This privacy statement concerns those processing operations.

Processor. When we carry out research on the instructions of an organization, an HPO diagnosis among employees, for example, that organization determines why and how the data is processed. We then process the data solely in accordance with its instructions and act as a processor. In that case the commissioning organization is the controller, and its own privacy policy applies. If you have been approached as an employee to take part in research and have a question about your data, please direct it in the first instance to your own employer. We record the arrangements with our clients in a data processing agreement. You are of course also free to put your question to us, and we will pass it on.

Which data do we process and why?

Below you will find, for each purpose, which data we use, on which legal basis, and how long we retain it.

Services, client administration, and financial administration

PurposeDataLegal basisRetention period
Financial administration and invoicingCompany name, invoicing address, bank details (bank name, IBAN, BIC), Chamber of Commerce number, VAT number, name and position of the contact person, outstanding balancePerformance of the agreement and legal obligationSeven years after the end of the financial year, under the Dutch statutory tax retention obligation (Section 52 of the State Taxes Act)
Management of the assignmentName and address details, email address, telephone number, invoicing address, VAT number, client number, name and position of the contact personPerformance of the agreement, insofar as you are yourself a party to that agreement, and otherwise our legitimate interest in entering into, performing, and managing business relationshipsAs long as necessary for the performance and settlement of the assignment. Data forming part of our administration is retained for seven years
Providing the service itself (consultancy, lectures, workshops, presentations, training)Name and address details, email address, telephone number, data required to deliver the service and data generated during the servicePerformance of the agreement, insofar as you are yourself a party to that agreement, and otherwise our legitimate interest in performing the assignmentAs long as necessary for this purpose and insofar as longer retention is required by law
Handling questions and complaintsName and address details, email address, telephone number, client number, content of the question or complaintPerformance of the agreement, insofar as you are yourself a party to that agreement, and otherwise our legitimate interest in providing proper serviceAs long as necessary for handling and any follow-up
Payments via the web shopName, email address, invoicing address, payment details, order numberPerformance of the agreementSeven years, as part of our administration

Research and HPO diagnoses

For carrying out HPO diagnoses and other organizational research we use the research software of MWM2. Data collected during the use of this software is stored on the secure servers of MWM2.

PurposeDataLegal basisRetention period
Carrying out research or a diagnosis on the instructions of an organizationAnswers to questionnaires, scores on the HPO Factors, and, if the research so requires, name, email address, position, and departmentThe client is the controller and determines the applicable legal basis. We process the data solely on the instructions of, and in accordance with the documented instructions of, the clientSee “How long do we retain research data?” below

When we download data from the research software, we do so wherever possible without directly identifying data and we limit ourselves to what is necessary for the research. We report research results only at a level of aggregation such that individual participants are not reasonably traceable from them.

The client is itself responsible for retaining the reports delivered.

Newsletter

PurposeDataLegal basisRetention period
Sending our newsletterName, email address, organization, and positionYour consent, or our legitimate interest where you are or have been a client or business relation of ours, or have taken part in one of our eventsUntil you unsubscribe or withdraw your consent. After that we retain your email address solely on an unsubscribe list, to prevent you from being approached again

We send our newsletter on the basis of your consent, or, where you are or have been a client or business relation of ours, or have taken part in one of our events, on the basis of our legitimate interest in keeping you informed about our work and publications. In both cases you can unsubscribe at any time via the link at the bottom of every newsletter. We use MailerLite to send it.

Website and cookies

PurposeDataLegal basisRetention period
Analysis of the use of our website via Google Analytics 4Pseudonymous usage data, including pages visited, time, device type, and truncated location dataConsent, which you give via the cookie notice on our websiteIn accordance with the retention setting in Google Analytics, no longer than fourteen months
Contacting us via the contact formName, email address, organization, and the content of your messageLegitimate interest in being able to answer your questionAs long as necessary to handle your question

You will find more information about the cookies we place in our cookie statement.

Scientific research, validation, and benchmark

We use research data for scientific research, for the validation and further development of the HPO Framework and the HPO Factors, and for compiling and maintaining our benchmark. We do so exclusively with anonymized data. Once data has been anonymized it is no longer personal data and privacy legislation no longer applies to it. We retain and use that anonymized data for an indefinite period.

When we publish about research we have carried out for an organization, we do not disclose information about that organization in a recognizable form unless it has given written consent to that effect.

How long do we retain research data?

Where we act as a processor, we retain traceable research data in accordance with the arrangements and the documented instructions of the client. Unless a shorter period has been agreed, the maximum retention period is five years after delivery of the report. After that, the data is deleted or anonymized in accordance with the arrangements made.

After anonymization the data is no longer reasonably traceable to an individual participant. This also means that comparisons with earlier individual results are no longer possible. When using the data for benchmarks, research, and publications, we do not disclose information about clients in a recognizable form unless the client has given written consent to that effect.

Are you obliged to provide us with data?

Where personal data is necessary to perform an agreement with you or to comply with a legal obligation, we may be unable to provide our services, or unable to provide them in full, if you do not supply that data. Providing data for our newsletter, for example, is voluntary and has no consequences for our services.

How do we obtain your personal data?

We hold data about you because you provided it to us yourself, for example by signing up for our newsletter, contacting us, or taking part in an event, or because the organization you work for provided it to us in the context of an assignment.

How do we secure your data?

We take appropriate technical and organizational measures to protect your data against loss and against unauthorized access, alteration, or disclosure. In doing so we take account of the state of the art, the costs of implementation, and the nature and risks of the processing. We make security arrangements with the parties that process data on our behalf and record these in data processing agreements.

No security offers absolute certainty. If we identify a personal data breach in a processing operation for which we are the controller, we act in accordance with our statutory obligations and, where the law so requires, inform the Dutch Data Protection Authority and the data subjects.

Where we act as a processor in a processing operation, we inform the client concerned without undue delay after becoming aware of a personal data breach. That client then assesses, as controller, whether notification to the Dutch Data Protection Authority and to the data subjects is required.

With whom do we share your data?

Processors

These parties process personal data solely on our instructions. We have concluded a data processing agreement with each of them.

  • MWM2: research software for carrying out HPO diagnoses and other organizational research;
  • MailerLite: sending our newsletter;
  • SnelStart: our financial administration;
  • Google: analysis of the use of our website. Insofar as settings for sharing data with other Google services are enabled in Google Analytics, Google may act as an independent controller for that shared data.

In addition, we engage suppliers for the hosting of our website, our email and collaboration environment, storage and backups, and the management of our IT. We conclude data processing agreements with these parties as well.

Parties that are independent controllers

We provide personal data to some parties which they then process for their own purposes and under their own responsibility. For online payments this is Mollie B.V., which processes data independently, among other things in order to comply with statutory financial obligations and for fraud prevention. Mollie’s own privacy policy applies to that processing.

Our external trainers and the experts of Direction Europe B.V. may also be involved in the performance of an agreement between you or your organization and us.

Other disclosures

We may be obliged to provide data to a third party, for example under a statutory obligation or a court order.

We do not sell your data to third parties.

Transfers outside the European Economic Area

Our data processing takes place in principle within the European Economic Area. In a number of cases data may be transferred to a country outside it, for example where one of our suppliers or its subcontractors is established there. This applies among other things to the use of Google Analytics, where data may be transferred to Google LLC in the United States.

A transfer takes place only where an appropriate basis exists for it. That is an adequacy decision of the European Commission, including the EU-US Data Privacy Framework, under which Google LLC is certified, or the use of the standard contractual clauses adopted by the European Commission, supplemented where necessary by additional measures.

If you would like to know which safeguards we apply in a specific case, or receive a copy of them, please contact us at schreurs@hpocenter.com.

Automated decision-making

We do not take decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.

What are your rights?

Under the General Data Protection Regulation you have a number of rights with regard to your data and its processing.

Access

You can request which personal data we process about you and receive a copy of it.

Rectification

If your data is incorrect or incomplete, you can ask us to correct or complete it.

Erasure

You can ask us to erase your data. We will comply with such a request unless we still need the data or are legally obliged to retain it, for example under the statutory tax retention obligation.

Restriction of processing

Under certain conditions you can ask us to temporarily suspend the processing of your data, for example while we verify its accuracy.

Objection

If a processing operation takes place on the basis of a legitimate interest of ours or of a third party, you can object to it on grounds relating to your particular situation.

Data portability

Insofar as the processing is carried out by automated means and is based on your consent or on an agreement to which you are yourself a party, you may under certain conditions ask to receive the personal data you have provided to us yourself in a structured, commonly used, and machine-readable format, so that you can transfer it to another party.

Withdrawal of consent

If we process data on the basis of your consent, you can withdraw that consent at any time. This does not affect processing that took place before the withdrawal.

How do we respond to your request?

You can send a request to schreurs@hpocenter.com. We will respond as soon as possible and in any event within one month of receiving your request. If your request is complex, or if we receive several requests from you, we may extend that period by two months; we will inform you of this within one month. If we reject your request, we will state why.

To prevent misuse, we may ask you to provide additional information enabling us to reasonably verify your identity. We will not ask for more information than is necessary.

Cookies

Cookies are small pieces of information that are sent to your browser when you visit our website and are then stored on your computer, tablet, telephone, or other device. We place functional cookies that are necessary for the website to work; no consent is required for these. For analytical and other cookies we ask for your consent via the cookie notice you see on your first visit. You can change that choice at any time.

Our cookie statement sets out exactly which cookies we place and for what purpose.

Changes to this privacy statement

We may amend this privacy statement. We therefore advise you to read it regularly. The date of the most recent amendment is stated at the bottom of this page.

Questions and complaints

If you have questions about this privacy statement or about the way we use your data, please send an email to schreurs@hpocenter.com. You can also come to us with a complaint about the way we process your data.

If we cannot resolve the matter together, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), the Dutch supervisory authority for data protection.

Last amended: September 2026