Last updated: 6 September 2026
Dutch Experiences B.V. respects your privacy and is committed to protecting your personal data.
This Privacy Policy explains how we collect, use, store and share personal data when you visit www.dutchexperiences.com, contact us, make a booking or participate in one of our experiences.
1. Who is responsible for your data?
The data controller is:
Dutch Experiences B.V.
Registered office: Keizersgracht 481-1, 1017 DL Amsterdam, Netherlands
Chamber of Commerce number (KVK): 56504330
VAT number: NL852158907B01
Email: info@dutchexperiences.com
Telephone: +31 6 83 66 83 90
Our experiences currently take place at Restaurant Morlang, Keizersgracht 451, 1017 DK Amsterdam, unless otherwise stated in your booking confirmation.
For questions about this Privacy Policy or how we use your personal data, please contact us using the details above.
2. Personal data we collect
Depending on how you interact with us, we may collect the following information.
Identity and contact information
This may include:
-
your name;
-
email address;
-
telephone number;
-
home or billing address, where required;
-
booking reference; and
-
the name and contact details of the person making a group booking.
Booking information
This may include:
-
the date and time of your booking;
-
number and type of participants;
-
selected experience;
-
booking source;
-
special requests;
-
correspondence concerning your booking;
-
cancellation, rescheduling and refund information; and
-
attendance or no-show information.
Dietary, allergy and accessibility information
If you choose to provide it, we may process information about:
-
food allergies;
-
food intolerances;
-
dietary preferences;
-
accessibility requirements; and
-
health-related information necessary to provide the experience safely.
Some of this information may constitute special-category personal data under the GDPR.
Please provide only information that is relevant to your participation. If you provide information about another participant, you must have their permission to do so.
Payment and transaction information
We may receive information such as:
-
the amount paid;
-
payment status;
-
transaction reference;
-
payment method; and
-
billing or refund information.
Payments may be processed by Wix or another authorised payment provider. Dutch Experiences does not ordinarily receive or retain complete payment-card details.
Enquiry and communication information
When you contact us, we may collect:
-
the content of your email, telephone call, form submission or message;
-
your contact preferences;
-
complaints or feedback; and
-
records of our response.
Website and device information
When you visit our website, certain technical information may be collected automatically, including:
-
IP address;
-
browser and device type;
-
operating system;
-
approximate location;
-
pages viewed;
-
referral source;
-
date and time of access;
-
cookie identifiers; and
-
information about how you interact with the website.
The precise information collected will depend on your cookie choices and the technologies active on the website.
Marketing information
If you subscribe to marketing or agree to receive updates, we may record:
-
your email address;
-
marketing preferences;
-
date and method of consent;
-
engagement with marketing communications; and
-
when you unsubscribe.
Photographs, videos and reviews
We may process photographs, video recordings, testimonials or reviews where:
-
you submit them to us;
-
you give us permission to create or use them;
-
you tag or mention Dutch Experiences publicly; or
-
they are published on a review or social-media platform.
We will obtain appropriate permission before using an identifiable guest as the focus of our promotional material.
Affiliate information
If you apply to or participate in our affiliate programme, we may collect:
-
your name and contact details;
-
business or social-media information;
-
affiliate account and referral details;
-
commission and payment information;
-
tax information where required; and
-
activity associated with your referral link or code.
3. How we collect personal data
We may collect personal data:
-
directly from you when you book, contact us or attend an experience;
-
from someone who makes a booking on your behalf;
-
through our website, booking forms and cookies;
-
from booking platforms such as GetYourGuide or Viator;
-
through our affiliate platform;
-
from payment providers;
-
from social-media and review platforms;
-
from publicly available sources; and
-
from business partners where you have authorised them to share information with us.
Where you book through another platform, that platform may act as a separate data controller and will process your information under its own privacy policy.
4. Why we use your personal data
We process personal data only where we have a lawful basis under the GDPR.
PurposeTypes of dataLegal basis
Processing and administering bookingsIdentity, contact, booking and transaction dataPerformance of a contract
Taking and confirming paymentIdentity, booking, payment and transaction dataPerformance of a contract
Delivering the experienceIdentity, booking and participation dataPerformance of a contract
Managing cancellations, changes and refundsContact, booking and transaction dataPerformance of a contract
Responding to enquiries and complaintsIdentity, contact and communication dataContractual necessity or legitimate interests
Accommodating dietary or accessibility requestsDietary, allergy, accessibility and booking dataPerformance of a contract and, where required, explicit consent
Protecting someone in an emergencyRelevant identity or health informationVital interests
Maintaining financial and tax recordsBooking, identity and transaction dataLegal obligation
Preventing fraud and protecting our systemsTransaction, device and technical dataLegal obligation or legitimate interests
Improving our website and servicesTechnical, usage, booking and feedback dataLegitimate interests or consent, depending on the technology
Sending promotional communicationsIdentity, contact and marketing dataConsent or legitimate interests where permitted
Operating our affiliate programmeIdentity, contact, referral and payment dataPerformance of a contract
Establishing or defending legal claimsRelevant booking, communication and transaction dataLegitimate interests and legal obligations
Using promotional photographs or testimonialsPhotograph, video, review and identity dataConsent or legitimate interests, depending on the circumstances
Where we rely on legitimate interests, we consider whether our interests are proportionate and whether your rights and freedoms override those interests.
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect processing that took place lawfully before consent was withdrawn.
5. Dietary and health information
Information about an allergy, medical condition or accessibility need may reveal health information and therefore receive additional protection under the GDPR.
We use this information only to:
-
determine whether we can safely accommodate your requirements;
-
prepare or serve suitable food and drinks;
-
make reasonable accessibility arrangements;
-
communicate necessary instructions to relevant staff or suppliers; and
-
respond appropriately in an emergency.
Access is limited to people who reasonably need the information. We will not use dietary or health information for advertising.
Where appropriate, our booking process should ask for your explicit consent before this type of information is submitted.
6. Marketing communications
We may send marketing communications where:
-
you have actively subscribed;
-
you have otherwise given your consent; or
-
applicable law permits us to contact an existing customer about similar services.
You can unsubscribe at any time by:
-
using the unsubscribe link in an email; or
-
contacting info@dutchexperiences.com.
Unsubscribing from marketing will not prevent us from sending essential service messages concerning an existing booking.
We may retain limited information on a suppression list to ensure that we continue to respect your decision not to receive marketing.
7. Cookies and similar technologies
Our website may use cookies and similar technologies to:
-
operate essential website and booking functions;
-
remember preferences;
-
maintain website security;
-
understand website performance and visitor behaviour;
-
measure referrals and affiliate activity; and
-
support advertising or social-media functions.
Strictly necessary cookies may be used without consent where they are essential to provide the website or a service requested by you.
Non-essential analytics, advertising and tracking cookies will be used only with consent where required. You should be able to accept, reject or manage these cookies through the website’s cookie banner or preference settings.
Your choice can normally be changed or withdrawn at any time through the cookie settings on the website.
Dutch guidance permits certain limited analytics cookies without consent only where they have little or no effect on visitors’ privacy. Other non-essential cookies require a valid choice. Dutch Data Protection Authority
8. Who we share personal data with
We may share personal data with carefully selected organisations where necessary, including:
-
Wix, which hosts and supports the website and may provide booking functionality;
-
payment processors and banks;
-
GetYourGuide, Viator and other booking partners;
-
affiliate-management providers;
-
Restaurant Morlang and relevant venue personnel;
-
food and drink suppliers where necessary to meet confirmed dietary requirements;
-
email, hosting, analytics and IT service providers;
-
marketing and communications providers;
-
accountants, insurers, lawyers and professional advisers;
-
fraud-prevention and cybersecurity providers; and
-
government bodies, regulators, courts or law-enforcement authorities where disclosure is required.
We share only information reasonably necessary for the relevant purpose.
Service providers acting on our behalf must use personal data only in accordance with our instructions and applicable data-protection requirements.
Some third-party booking, social-media and payment services determine independently how they process personal data. Their own privacy policies will apply to that processing.
We do not sell personal data.
9. International data transfers
Some service providers may process personal data outside the European Economic Area.
Where personal data is transferred internationally, we will use an appropriate legal safeguard where required. This may include:
-
transfer to a country recognised as providing adequate data protection;
-
European Commission-approved Standard Contractual Clauses; or
-
another transfer mechanism permitted under the GDPR.
You may contact us for further information about safeguards relevant to your personal data.
10. How long we retain personal data
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, tax, insurance and dispute-resolution requirements.
Our typical retention approach is:
-
Booking and transaction records: retained for the period required under applicable tax and accounting laws.
-
General enquiries: normally retained for up to two years after the last substantive contact.
-
Complaints and disputes: retained until the matter is resolved and for any applicable legal limitation period.
-
Allergy and health information: normally deleted or anonymised shortly after the experience unless required in relation to an incident, complaint or legal obligation.
-
Marketing records: retained until you unsubscribe, withdraw consent or the information is no longer useful, subject to periodic review.
-
Suppression records: limited information may be retained to ensure that marketing preferences continue to be respected.
-
Affiliate records: retained for the duration of the relationship and afterwards where necessary for payment, tax or legal purposes.
-
Website security logs: retained only for an appropriate security and troubleshooting period.
-
Photographs and promotional content: retained until consent is withdrawn or the material is no longer required, subject to any lawful continued use.
Actual periods may vary where information is needed to establish, exercise or defend a legal claim.
11. Data security
We use appropriate technical and organisational measures designed to protect personal data against:
-
unauthorised access;
-
loss or destruction;
-
alteration;
-
improper disclosure; and
-
unlawful processing.
Measures may include access controls, password protection, secure service providers, software updates, backups and restrictions on who can access personal data.
No internet-based system is completely secure. If we become aware of a personal-data breach, we will investigate it and notify affected individuals and the relevant authority where legally required.
12. Your GDPR rights
Depending on the circumstances, you may have the right to:
-
request access to your personal data;
-
ask us to correct inaccurate or incomplete data;
-
request deletion of your personal data;
-
ask us to restrict its use;
-
object to processing based on legitimate interests;
-
object to direct marketing;
-
receive certain information in a portable format;
-
withdraw consent at any time; and
-
lodge a complaint with a data-protection authority.
These rights are not absolute. We may need to retain or continue using certain information where required by law or where another valid legal basis applies.
To exercise a right, email info@dutchexperiences.com. Please state that your request concerns data protection and describe what you would like us to do.
We may request information necessary to verify your identity. We will normally respond within one month, although this may be extended where a request is particularly complex or numerous.
13. Complaints
Please contact us first if you have a concern about how your personal data has been handled. We will try to resolve the matter promptly.
You also have the right to complain to the Dutch supervisory authority:
Autoriteit Persoonsgegevens
www.autoriteitpersoonsgegevens.nl
If you live in another EEA country, you may also be entitled to contact the supervisory authority in that country.
14. Children’s data
Our website and booking service are intended to be used by adults.
Where a child attends an experience, booking and dietary information should be supplied by their parent, guardian or another responsible adult.
We do not knowingly use children’s personal data for direct marketing or behavioural advertising.
15. Social media and external websites
Our website may link to Instagram, Tripadvisor, GetYourGuide, Viator and other external services.
If you visit or interact with these services, the relevant provider may collect personal data independently. Dutch Experiences does not control how third-party websites process your information.
You should review the privacy settings and privacy policy of the relevant provider.
16. Automated decision-making
We do not currently use personal data to make decisions that produce legal or similarly significant effects solely through automated processing.
If this changes, we will update this Privacy Policy and provide any information required by law.
17. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to our website, services, suppliers or legal obligations.
The latest version will be published on this page with a revised “last updated” date. Where appropriate, we may provide additional notice of a significant change.
18. Contact us
For questions, concerns or requests relating to personal data, contact:
Dutch Experiences B.V.
Keizersgracht 481-1
1017 DL Amsterdam
Netherlands
Email: info@dutchexperiences.com
Telephone: +31 6 83 66 83 90

