Privacy Policy for ReallyDoing.It by Results Project Management (RPM)

Last updated: March 1st, 2026

This Privacy Policy applies between you, the User of this website, and Results Project Management (RPM), the owner and provider of this website and the RPM e‑learning platform. It explains how we collect, use and protect personal data in connection with your use of the website, our Services and AI‑powered features, in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and Dutch privacy laws (AVG – Algemene Verordening Gegevensbescherming).

"Results Project Management", "RPM", "we", "us" or "our" refers to: Results Project Management (RPM), Kraatsweg 10 A, 6721 NS, Bennekom, The Netherlands.

1. Definitions and Interpretation

In this Policy the following terms shall have the following meanings:

  • "Account": The personal information, payment information, and credentials used by Users to access materials and/or any communication systems on the website or platform.
  • "AI Systems": Software that can, for a given set of human‑defined objectives, generate outputs such as content, predictions, recommendations or decisions, as defined in the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), including AI used for chatbots, content creation and custom AI agents/GPTs.
  • "Content": Any text, graphics, images, audio, video, software, data compilations, and other information stored or displayed on the website.
  • "Cookie": A small text file placed on your device when visiting the website, used to identify returning visitors and analyse browsing behaviour.
  • "Data" / "Personal Data": Any information relating to an identified or identifiable natural person, submitted to or collected through the website, platform or AI features.
  • "Service(s)": Any online tools, services, e‑learning materials, AI‑assisted functionalities or information provided through the website or platform.
  • "System": Any online communication or technical infrastructure made available on the website or platform, including chat, forums, AI chatbots and APIs.
  • "User/Users": Any third party accessing the website or platform who is not employed by RPM and acting in their professional capacity.
  • "Website": The website you are currently using (www.reallydoing.it) and its sub‑domains, as well as the associated e‑learning platform.

2. Data We Collect

We may collect and process the following categories of personal data:

  • Identification and contact data: name, email address, job title, organisation, country/region.
  • Account and access data: username, password (hashed), account settings, enrolment in courses or programmes.
  • Demographic data: postal code, industry, preferences, and interests where provided.
  • Payment and transaction data: transaction identifiers, amounts, dates and limited payment details (full card data is processed by secure third‑party payment providers, not stored by RPM).
  • Technical data: IP address, browser type and version, device identifiers, operating system, time zone, and similar technical information.
  • Usage data: pages visited, features used, clickstream data, session duration, referring and exit pages, learning progress and completion data.
  • Communication data: messages sent through contact forms, email, support requests, and interactions via our communication tools.

AI interaction data:

  • Messages and prompts you send to our AI chatbot or AI assistant.
  • AI system responses and feedback.
  • Metadata about AI interactions (timestamps, context, feature used).
  • Content contribution data: content you provide for use with AI content creation (e.g. text, outlines, course materials, prompts for AI to generate learning content).

We may also process pseudonymised or aggregated data for statistics and service improvement, which is not considered personal data.

3. Purposes and Legal Bases for Processing

We process personal data only where we have a valid legal basis under the GDPR. Depending on the context, we may rely on:

  • Contractual necessity: To create and manage your Account, provide access to courses and AI‑powered features, process payments, and deliver support.
  • Legal obligation: To comply with tax, accounting, and other mandatory record‑keeping or regulatory requirements.
  • Legitimate interests: To improve and secure our Services, understand how our platform and AI features are used, prevent abuse or fraud, and personalise the user experience in a balanced way that does not override your rights and freedoms.
  • Consent: For certain optional activities such as direct marketing communications, non‑essential cookies/tracking, and specific AI‑related data uses where required by law.

We use your personal data for the following purposes:

  1. Service delivery and account management
    • Creating and managing Accounts.
    • Providing access to the e‑learning platform, courses and related resources.
    • Providing AI‑assisted features (chatbot, AI assistants, recommendations, content suggestions).
  2. AI chatbot and assistant functionality
    • Enabling you to interact with AI‑driven chatbots or assistants for guidance, explanations, and support.
    • Processing your prompts/questions and generating responses.
    • Maintaining logs of interactions for troubleshooting, security and quality improvement, with appropriate safeguards and retention limits.
  3. AI‑based content creation and support
    • Using AI to generate or assist in generating learning content (e.g. summaries, practice questions, feedback, draft materials) based on your prompts or course context.
    • Where applicable, storing AI‑generated outputs in your account or course space so you and, if relevant, your organisation's administrators can reuse them.
  4. Custom AI GPTs on third‑party platforms
    • Operating custom AI GPTs or similar agents hosted on trusted third‑party platforms which may process data you provide when interacting with those GPTs.
    • Where interactions happen on such external platforms, you should also review the privacy policy of the relevant platform. RPM configures such GPTs to limit personal data processing where possible and to comply with GDPR and contractual safeguards.
  5. Improvement and security of Services and AI systems
    • Analysing platform and AI usage (often in aggregated or pseudonymised form) to improve functionality, performance, and user experience.
    • Monitoring for misuse, abuse, or security incidents and taking appropriate protective measures.
  6. Communication and support
    • Responding to enquiries and support requests.
    • Sending service‑related notifications, such as important updates, security alerts or changes to terms and policies.
  7. Marketing (with consent where required)
    • Sending newsletters, invitations to webinars, and information about new courses or features, only where you have given consent or where permitted by applicable law.
    • You can withdraw consent or opt out of marketing at any time.

RPM does not use AI systems to take decisions that produce legal effects or similarly significant effects concerning you without meaningful human involvement.

4. AI Transparency and the EU AI Act

RPM uses certain AI Systems that fall within the "limited‑risk" category as defined under the EU Artificial Intelligence Act. In that context:

  • When you interact with an AI chatbot, AI assistant or similar feature, we will inform you that you are interacting with an AI‑driven system, unless this is obvious from the context and interface.
  • Where content (such as explanations, practice questions, summaries or feedback) is generated or significantly modified by an AI System, we will make reasonable efforts to label or otherwise indicate that it has been AI‑generated, unless such content has been reviewed and published under RPM's editorial responsibility.
  • We do not use emotion recognition or biometric categorisation systems for end users.
  • We design and use AI Systems in a way that respects GDPR principles (lawfulness, fairness, transparency, data minimisation, purpose limitation, accuracy, storage limitation, integrity and confidentiality) and fundamental rights.

This Privacy Policy works together with our Terms and Conditions, which describe how AI is used functionally within the Services.

5. Third‑Party Service Providers (Including AI Providers)

We may engage third‑party processors to provide certain services, such as:

  • Hosting, cloud infrastructure and content delivery.
  • Payment processing and billing.
  • Email delivery, CRM and marketing tools.
  • Analytics and performance monitoring.
  • AI service providers (e.g. API‑based models or platforms that host custom GPTs).

These providers only process personal data on our instructions and under written data processing agreements that meet GDPR requirements. We do not sell, lease, or otherwise disclose your personal data to unauthorised third parties.

Where you interact with our custom GPTs or AI agents on third‑party platforms, those platforms may act as separate controllers for certain processing they carry out. In such cases, their privacy policies apply in addition to this Policy.

6. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy, or as required by law. In general:

  • Account data: kept while your account is active and for a limited period thereafter (e.g. up to 3 years) for support, dispute handling and record‑keeping, unless we are required by law to retain it longer.
  • Transaction and invoicing data: retained for the statutory retention period under Dutch law (typically up to 7 years).
  • Communication data: stored for up to 1 year after resolution of the enquiry, unless further retention is necessary for legal purposes.
  • AI interaction logs: retained for a period necessary for security, quality improvement and audit (for example 6–24 months), after which they are either deleted, anonymised or aggregated.
  • Marketing data: retained until you withdraw consent or object to processing, or after a period of inactivity in line with our internal policies.

We may retain anonymised or aggregated data indefinitely, as it no longer identifies individuals.

7. Cookies and Tracking Technologies

Our website and platform use cookies and similar technologies to:

  • Enable essential site functionality and secure login.
  • Remember your preferences and improve user experience.
  • Analyse usage and performance of the website and AI features.
  • Support marketing and analytics where you have consented to such cookies.

You can manage cookie preferences via our Cookie Banner/Tool and in your browser settings. For more detail, please refer to our separate Cookie Policy.

8. Security Measures

RPM implements appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, including:

  • Encryption of data in transit and, where appropriate, at rest.
  • Secure hosting environments with access controls and monitoring.
  • Role‑based access and least‑privilege principles for staff and contractors.
  • Regular updates, vulnerability management and security testing.
  • Internal policies and training regarding data protection and information security.

While we strive to protect your personal data, no system can be guaranteed as 100% secure.

9. International Data Transfers

Some of our service providers, including AI service providers and cloud hosting providers, may be located outside the European Economic Area (EEA) or may store data in other jurisdictions.

Where personal data is transferred outside the EEA, we ensure that an adequate level of protection is in place, for example by:

  • Using countries that have been recognised by the European Commission as providing an adequate level of protection; and/or
  • Entering into EU Standard Contractual Clauses (SCCs) with the relevant recipients; and
  • Implementing additional technical and organisational safeguards, where appropriate.

You can contact us for more information about the specific safeguards used for international transfers.

10. Your Rights Under GDPR / AVG

As a data subject in the EU and the Netherlands, you have the following rights:

  • Right of access: Obtain confirmation whether we process your personal data and receive a copy of such data.
  • Right to rectification: Request correction of inaccurate or incomplete personal data.
  • Right to erasure ("right to be forgotten"): Request deletion of your personal data in certain circumstances.
  • Right to restriction of processing: Request that we limit how we use your data under certain conditions.
  • Right to data portability: Receive your personal data in a structured, commonly used and machine‑readable format, and transmit it to another controller where technically feasible.
  • Right to object: Object to processing based on legitimate interests, including profiling, and to direct marketing.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw that consent at any time, without affecting the lawfulness of processing before withdrawal.

Where our AI Systems process your personal data, these rights also apply to that processing. On request, we can provide additional information about the main logic involved in AI‑supported processing where required by law, while protecting trade secrets and intellectual property.

To exercise any of your rights, please contact us using the details in section 13 below. We may need to verify your identity before fulfilling your request.

You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority.

11. Children's Data

Our Services are intended for users who are at least 18 years old, or who use the Services under the supervision and consent of a parent or legal guardian where permitted by law. We do not knowingly collect personal data from children under the age of 16 without appropriate consent mechanisms as required by the GDPR and Dutch law.

If you believe that a child has provided us with personal data without appropriate consent, please contact us so we can take appropriate steps to delete such data.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time, for example in response to legal, technical or business developments, or changes in our use of AI Systems.

When we update the Policy, we will revise the "Last updated" date at the top and, where appropriate, notify you through the website, by email, or within the platform. We encourage you to review this Policy periodically to stay informed about how we process your personal data.

13. Contact Information

For any questions about this Policy, our use of personal data, or to exercise your rights, please contact:

  • Results Project Management (RPM)
  • Email: privacy@reallydoing.it
  • Address: Kraatsweg 10 A, 6721 NS, Bennekom, The Netherlands

Supervisory authority in the Netherlands: