Privacy Policy
Last Updated: March 12, 2026
1. Introduction & Controller Identity
This Privacy Policy explains how Bizon B.V. (“we”, “us”, “our”) collects, uses, and protects your personal data when you visit canadianprofessionalacademy.ca (the “Website”) and when you contact us or register interest in our online education programs.
Bizon B.V. operates this Website as an independent provider of online professional workplace education for learners across Canada. We provide educational content, virtual workshops, webinars, downloadable learning materials, and self-paced professional development programs. We do not provide consulting, legal services, financial services, accounting, recruitment, employment placement, healthcare, immigration services, engineering, or any regulated professional services.
Data Controller (GDPR): Bizon B.V.
Registered address: Kesselse Dijk 9, 5398 CA Maren-Kessel, Netherlands
Email: [email protected]
Phone: +31 412 662 981
We do not appoint a Data Protection Officer (DPO) as a mandatory role for our operations. If you have privacy questions, you can contact us using the details above and we will route your request to the appropriate person.
2. Personal Data We Collect
We collect only the personal data needed to operate the Website, respond to inquiries, and support educational program registration. Depending on how you interact with the Website, we may collect:
- Identity and contact data: name, email address, phone number, and similar contact details you provide.
- Form content: messages, program selections, workshop preferences, and any educational context you include (for example, role, learning goals, or schedule constraints).
- Technical data: IP address, browser type and version, device type, operating system, language settings, and approximate location inferred from IP (country/region level).
- Usage data: pages viewed, time on page, referring page, click paths, and interaction events (for example, a button click or a form start).
- Cookies and identifiers: small files stored in your browser that store preferences and help measure site performance, described in Section 4.
- Conversion events: whether you completed certain actions, such as submitting a registration request or visiting key pages.
We do not intentionally collect special-category personal data (such as health information, biometric data, religious or political beliefs), financial account details, or government identification numbers through this Website. Please do not include such information in free-text fields.
3. Why We Process Personal Data & Legal Basis (GDPR Art. 6)
We process personal data for specific purposes and rely on one or more lawful bases under the GDPR:
- Contact and registration requests (responding to your inquiry, confirming details, sharing next steps): Art. 6(1)(b) (steps prior to entering a contract) and, where applicable, Art. 6(1)(a) (consent).
- Analytics measurement (understanding which content is useful, improving navigation and performance): Art. 6(1)(a) (consent).
- Marketing and remarketing (measuring advertising performance and showing relevant promotions): Art. 6(1)(a) (consent).
- Security and fraud prevention (protecting the Website, rate limiting, preventing abuse): Art. 6(1)(f) (legitimate interests).
- Legal obligations (responding to lawful requests, maintaining records where required): Art. 6(1)(c) (legal obligation).
Automated decision-making and profiling (GDPR Art. 22): We do not engage in automated decision-making or profiling that produces legal or similarly significant effects. Advertising platforms may create audience segments based on consented cookie identifiers, but we do not make consequential decisions about you based on such segments.
4. Cookies & Tracking
We use cookies and similar technologies (including pixel tags and server-side events) to keep the Website functioning, measure usage, and support advertising attribution. You can manage cookie preferences at any time using the “Manage cookie preferences” link in the footer.
We group cookies into three categories:
Essential cookies (always active)
These cookies are required for basic site functionality and security. They do not require consent. Examples include:
- _site_session (session continuity and security).
- cookie_consent (stores your cookie preference choice).
- CSRF or similar security tokens (if used by the hosting stack).
Retention: from session duration up to 12 months (depending on the cookie).
Analytics cookies (consent required)
Analytics cookies help us understand how the Website is used (for example, which pages are visited most often and where people drop off). We use Google Analytics 4 (GA4) with IP anonymization where available. Analytics cookies activate only after you consent.
Examples: _ga (2 years) and _ga_XXXXXXXXXX (2 years). Analytics retention in GA4 is configured for 14 months.
Marketing cookies (consent required)
Marketing cookies support advertising measurement and relevant promotions. They help attribute conversions to ads and build remarketing audiences. Marketing cookies activate only after you consent.
Examples include _gcl_au (Google Ads, 90 days), _fbp (Meta Pixel, 90 days), and _fbc (Meta click identifier, 90 days when present).
Beyond cookies, advertising and analytics can also use pixel tags (for example, gtag.js or Meta Pixel), and may support server-side integrations such as Meta Conversion API or server-side tag management. Where used, server-side events may include hashed identifiers (for example, hashed email) and technical signals such as IP address and User-Agent to improve attribution. These integrations are only enabled for analytics/marketing after consent.
5. Consent (EEA/UK)
Users in the EEA and UK receive a consent notice under GDPR/UK GDPR. Analytics and marketing cookies activate only after explicit, informed, freely given consent (GDPR Art. 6(1)(a)). Your consent choice is stored in the cookie_consent cookie for up to 12 months.
You can withdraw consent at any time by selecting “Manage cookie preferences” in the footer, adjusting your preferences, or clearing cookies in your browser. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
6. Sharing With Advertising & Service Partners
We use trusted service providers to operate the Website, keep it secure, and measure/attribute marketing. Depending on your consent settings, we may share limited data with:
- Google LLC (Google Analytics 4, Google Ads, Google Tag Manager, remarketing): cookie identifiers, usage data, and conversion events. Privacy policy: https://policies.google.com/privacy
- Meta Platforms, Inc. (Meta Pixel, Custom/Lookalike Audiences, Conversion API): page views, conversion events, audience membership, and (where enabled) hashed identifiers. Privacy policy: https://www.facebook.com/privacy/policy
- Cloudflare, Inc. (CDN and security): IP address and request metadata used to detect malicious traffic and improve performance. Privacy policy: https://www.cloudflare.com/privacypolicy/
We do not sell personal data. We use these providers as processors/service providers to support our operations and measurement. Where advertising platforms act as independent controllers for their own purposes, they do so under their own policies and settings. We do not permit providers to use Website data for their own independent commercial purposes outside the services they provide to us.
7. International Transfers
Bizon B.V. is established in the Netherlands. Some of our service providers (including Google and Meta) may process data outside the European Economic Area (EEA), including in the United States. When we transfer personal data internationally, we rely on appropriate safeguards, which may include:
- EU-US Data Privacy Framework (DPF) as a primary transfer mechanism where applicable (since July 2023), including the UK Extension and Swiss-US DPF where relevant.
- Standard Contractual Clauses (EU 2021/914) as a fallback mechanism.
- UK International Data Transfer Agreement (IDTA) as a fallback mechanism for UK transfers.
We also apply practical safeguards where reasonable, such as limiting shared fields and respecting consent choices for analytics and marketing processing.
8. Retention
We retain personal data only as long as needed for the purposes described in this Policy:
- Contact and registration submissions: up to 2 years from the last interaction, unless a longer period is required to manage an ongoing learner relationship or resolve a dispute.
- Analytics data: 14 months in GA4 settings (where enabled by consent).
- Marketing cookies: typically 90 days per cookie (where enabled by consent), plus platform retention under their settings.
- Email correspondence: for the duration of the educational relationship and typically 1 year after the last interaction.
- Server and security logs: typically 90 days, unless extended for security investigations.
- Cookie consent record: up to 3 years for audit and compliance evidence (stored in a browser cookie and, if needed, in internal records).
- Legal and tax records: retained as required by applicable law (commonly 6–10 years depending on the record type).
Retention periods can be adjusted when legal requirements or legitimate operational needs apply, but we aim to keep storage proportionate and methodical.
9. Your Rights (GDPR & UK GDPR)
If GDPR applies to your data, you have the right to:
- Access (Art. 15)
- Rectification (Art. 16)
- Erasure (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Object to processing (Art. 21)
- Withdraw consent at any time (Art. 7(3)) where we rely on consent
- Lodge a complaint with a supervisory authority (Art. 77)
To exercise your rights, email [email protected]. We typically respond within 30 days. For complex requests, this can be extended by up to 60 additional days, as permitted by law. We may request additional information to verify identity before processing a request.
Supervisory authority: If you are in the Netherlands, you may contact the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). If you are elsewhere in the EU, you can find your authority via the European Data Protection Board: https://edpb.europa.eu. UK users can contact the ICO: https://ico.org.uk.
10. Children
This Website is not directed at individuals under 16. We do not knowingly collect personal data from minors. If you believe a child under 16 has provided personal data to us without verifiable parental consent, contact us and we will delete the data promptly.
11. Do Not Track
This Website does not respond to “Do Not Track” (DNT) browser signals. Third-party providers may have their own DNT handling and opt-out mechanisms.
12. Data Deletion Requests
You can request deletion of personal data by emailing us with the subject line “Data Deletion Request”. We will confirm receipt, verify identity where appropriate, and complete the request within 30 days unless an extension is permitted. We may retain limited information where required by law or needed to establish, exercise, or defend legal claims.
13. Business Transfers
If Bizon B.V. is involved in a merger, acquisition, asset sale, financing, or insolvency, personal data may be transferred to a successor entity. If such a transfer materially changes how personal data is used, we will provide notice on the Website.
14. California (CCPA / CPRA)
While Bizon B.V. is established in the Netherlands, the Website may be accessed from the United States. If the California Consumer Privacy Act (as amended by the CPRA) applies, the following disclosures apply for the prior 12 months:
- Identifiers (name, email, IP address, device identifiers): shared with service providers and, where consented, advertising partners for measurement.
- Internet or network activity (pages visited, interaction events): used for analytics and advertising measurement (with consent).
- Inferences (interests or preferences derived from browsing): used only in the context of advertising platforms when marketing consent is provided.
We do not sell personal information as defined by CCPA. We may share data for cross-context behavioral advertising when marketing cookies are enabled by your consent. California residents may opt out of such sharing by rejecting marketing cookies in our cookie preferences panel.
California rights may include: Right to Know, Delete, Correct, and Opt-Out of sale/sharing, and the right to non-discrimination. To submit a request, email us with the subject “California Privacy Request”. We may need to verify identity, and authorized agents must provide written proof of authorization.
15. Virginia (VCDPA)
If the Virginia Consumer Data Protection Act applies, Virginia residents may have rights to access, correct, delete, and obtain a copy of personal data, and to opt out of targeted advertising. To submit a request, email us with the subject “Virginia Privacy Request”.
We do not sell personal data or engage in profiling that produces legal or similarly significant effects. If we deny a request, you may appeal by emailing “Appeal of Refusal — Privacy Request”. We respond to appeals within 60 days. If an appeal is denied, you may contact the Virginia Attorney General.
16. Nevada
Nevada residents may submit a verified opt-out request by emailing us with the subject “Nevada Do Not Sell Request”. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.
17. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to our Website, services, or legal requirements. If changes are material, we will announce them on the homepage at least 14 days before taking effect where feasible. The “Last Updated” date at the top of this page is revised whenever we make changes.
18. Contact
For privacy questions or requests, contact:
Bizon B.V.
Kesselse Dijk 9, 5398 CA Maren-Kessel, Netherlands
Email: [email protected]
Phone: +31 412 662 981