Privacy Policy
www.trustyourknees.com · Last updated: 3 August 2026
1. Introduction
Trust Your Knees is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you visit our website (www.trustyourknees.com), book a consultation, or participate in any of our coaching programmes or services.
This policy is written in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and applicable Dutch data protection law. By using this website or our services, you acknowledge that you have read and understood how we handle your personal data.
2. Who we are — data controller
The data controller responsible for your personal data is:
Tim Michels
Trading as: Trust Your Knees
Website: www.trustyourknees.com
Email: [INSERT EMAIL]
Address: [INSERT ADDRESS]
KvK number: [INSERT IF APPLICABLE]
3. What personal data we collect
3.1 Data you provide directly
-
Full name and contact details (email address, phone number)
-
Health information shared voluntarily during consultations or coaching — including details about your knee condition, symptoms, and medical history
-
Personal goals, concerns, and circumstances shared during coaching sessions
-
Payment information (processed securely via a third-party provider — we do not store card details)
-
Any other information you choose to share in emails, calls, or written communications
-
3.2 Health data — special category
Information about your health — including your knee osteoarthritis, symptoms, and physical condition — is classified as special category data under GDPR. We collect and process this data only with your explicit consent, and only to the extent necessary to provide our coaching services.
Although Trust Your Knees operates as a health coaching service rather than a clinical practice, the health information you share with us is treated with the same care and confidentiality as it would be in a clinical setting.
3.3 Data collected automatically
-
IP address and browser information
-
Pages visited and time spent on site
-
Device type and referring website
This data is collected through cookies. Please see Section 9 for more information.
4. Why we collect your data — lawful basis
4.1 Contract performance
We process your contact details and relevant health information to deliver the coaching services you have booked.
4.2 Explicit consent
We process your health data on the basis of your explicit consent. You may withdraw consent at any time without affecting the lawfulness of prior processing.
4.3 Legitimate interests
We may process certain data on the basis of legitimate interests, including improving our services, responding to enquiries, and sending service-related communications.
4.4 Legal obligation
We may retain certain data where required by law — for example, for tax or accounting purposes.
5. How we use your data
-
To deliver, manage, and personalise your consultation, programme, or membership
-
To adapt your coaching plan based on your progress and feedback
-
To communicate with you about appointments, programme content, and your progress
-
To send educational content and resources you have consented to receive
-
To process payments
-
To respond to enquiries and support requests
-
To comply with legal and professional obligations
-
To improve our website and services
We do not use your personal data for automated decision-making or profiling.
6. Who we share your data with
We do not sell, rent, or trade your personal data to any third party.
We may share your data with trusted third-party service providers who help us operate our services, including:
-
Video call platforms (e.g. Zoom or Google Meet) — for delivering coaching sessions
-
Email service providers — for client communications
-
Scheduling and calendar tools — for booking management
-
Payment processors — for secure payment handling
-
Website hosting and analytics providers
All third-party providers are required to handle your data in accordance with GDPR.
7. How long we keep your data
-
Coaching and programme records — retained for 10 years after our working relationship ends
-
Health-related information — retained for 10 years in line with applicable guidance
-
Financial and payment records — retained for 7 years in line with Dutch tax law
-
Marketing communications — until you unsubscribe or withdraw consent
-
Website analytics data — anonymised or deleted after 12 months
8. Your rights under GDPR
As a data subject, you have the following rights:
-
Right of access — request a copy of the personal data we hold about you
-
Right to rectification — request correction of inaccurate or incomplete data
-
Right to erasure — request deletion of your data in certain circumstances
-
Right to restriction — request that we limit how we process your data
-
Right to data portability — receive your data in a structured, machine-readable format
-
Right to object — object to processing based on legitimate interests
-
Right to withdraw consent — withdraw consent for health data processing at any time
-
Right to complain — lodge a complaint with the Autoriteit Persoonsgegevens (www.autoriteitpersoonsgegevens.nl)
To exercise any of these rights, please contact us at [INSERT EMAIL]. We will respond within 30 days.
9. Cookies
Essential cookies
Necessary for the website to function. Cannot be disabled and do not store personally identifiable information.
Analytics cookies
Help us understand how visitors use our website. Data is aggregated and anonymised where possible. You can opt out via our cookie consent banner.
Marketing cookies
If we run advertising campaigns, third-party cookies may be placed on your device to help deliver relevant advertising. Manageable via our cookie consent banner.
10. Marketing communications
We will only send marketing emails or educational content if you have explicitly opted in. You can unsubscribe at any time by clicking the unsubscribe link in any email or by contacting us directly. Unsubscribing does not affect service-related communications for an active programme or membership.
11. Data security
We implement appropriate technical and organisational measures to protect your data, including:
-
Encrypted, password-protected platforms for video calls and communications
-
Secure, restricted-access storage of client records
-
Use of reputable, GDPR-compliant third-party tools
While we take all reasonable steps to protect your data, no internet transmission is completely secure. We are committed to responding promptly to any data breach in accordance with our legal obligations under GDPR.
12. Children's privacy
Our services are intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently done so, please contact us immediately.
13. Changes to this policy
We may update this Privacy Policy from time to time. The date at the top of this page reflects the most recent revision. Active clients will be notified of significant changes by email.
14. Contact us
For any questions or requests regarding this Privacy Policy:
Tim Michels — Trust Your Knees
Email: [INSERT EMAIL]
Address: [INSERT ADDRESS]
Website: www.trustyourknees.com
Autoriteit Persoonsgegevens: www.autoriteitpersoonsgegevens.nl