Version 1.0 — 27 July 2026
This statement sets out which personal data Part of the Narrative B.V. processes, why we do so, and what rights you have. In doing so we comply with the General Data Protection Regulation (GDPR).
This is a translation. In case of any discrepancy, the Dutch text prevails. The Dutch version is available at partofthenarrative.com/privacy.
1. Who we are
- Legal name: Part of the Narrative B.V.
- Trade name: Narrative
- Address: Vergulde Draak 2, 2342 CM Oegstgeest, the Netherlands
- Chamber of Commerce number: 42100669
- VAT identification number: NL869727382B01
- E-mail: info@partofthenarrative.com
Narrative helps event professionals put generative AI to work: workshops, training, consultancy, automations and AI agents.
We have not appointed a data protection officer; this is not mandatory for an organisation of our size and nature. We assess annually whether that remains the case. For any privacy question, contact info@partofthenarrative.com.
Two situations
In most cases we determine ourselves why and how personal data are processed. We are then the controller. This statement concerns those situations.
In addition, we sometimes process personal data on behalf of a client — for example when we build an AI assistant based on documents the client supplies. The client is then the controller and we are the processor. We conclude a separate data processing agreement for this and process those data only on the client's instructions. Where data reach us via a client, that client is your first point of contact; if you approach us directly, we will refer you and inform the client.
2. Which data we process
2.1 Clients and prospects
For contact persons at clients and prospective clients we process name, job title, business e-mail address, telephone number and meeting notes. We use these for relationship management, quotations and the performance of assignments.
2.2 Workshop and training participants
For participants we process name, e-mail address, organisation and job title. For open editions you book yourself, payment details are handled by our ticketing partner; we do not receive full payment details ourselves. We use these data for registration, planning, delivery, any certificates and follow-up.
2.3 Newsletter subscribers
If you subscribe to our newsletter we process your name and e-mail address, and we record whether you open our e-mails and click links. We also assign tags based on your interests so that we can send more relevant mail.
2.4 Correspondence
For everyone who e-mails or consults with us we process name, e-mail address and the content of the correspondence and shared documents. This is inherent to business communication.
2.5 Recordings and transcripts
For client and partner conversations we sometimes make a recording or transcript for record-keeping and follow-up. This involves name, voice and the content of the conversation. We always say when we are recording; you may object, in which case we do not record.
2.6 Internal knowledge base
We maintain an internal knowledge base containing project documentation and relationship information: name, job title, contact details, professional context and meeting notes. It is held in protected environments and accessible only to us.
We do not process special categories of personal data (such as health, religion or political opinion) and we do not carry out automated decision-making with legal effect. Our services are aimed at business clients and not at children.
3. Why we process these data
- Client administration, quotations, performance of assignments — performance of the contract
- Approaching prospects — legitimate interest (commercial operations)
- Invoicing and accounting — performance of the contract and legal obligation (statutory retention for tax purposes)
- Workshops and training — performance of the contract
- Newsletter — consent on subscription; for existing clients, legitimate interest, always with an opt-out
- Correspondence, knowledge base, meeting records — legitimate interest (business operations and service quality)
Where we rely on a legitimate interest, we weigh that interest against your privacy. If you believe that balance is wrong in your case, you may object (see §5).
4. How long we retain data
- Client and prospect data — duration of the relationship + 2 years after last contact
- Invoicing and accounting data — 7 years (statutory retention for tax purposes)
- Workshop participant data — 2 years after the workshop
- Newsletter data — until you unsubscribe; subscribers who have not opened or clicked for 2 years are removed at our annual review
- Correspondence, knowledge base, meeting records — no fixed period; retained for as long as commercially relevant, reviewed annually
For correspondence and records we deliberately apply no fixed period: they form our working memory of current and previous collaborations. We do review that relevance annually, and we honour erasure requests — the older the material, the more weight such a request carries.
5. Your rights
You have the right to:
- access your data and receive a copy;
- have inaccurate data rectified;
- have your data erased;
- have processing restricted;
- object to processing based on legitimate interest;
- have your data ported to you in a commonly used format;
- withdraw consent you have given, for example for the newsletter — this does not affect the lawfulness of processing before withdrawal.
Send your request to info@partofthenarrative.com. We respond within one month. For a complex request we may extend that period by two months; we will tell you within the first month if we do. To prevent us from disclosing data to the wrong person, we may ask for additional identification — no more than necessary.
You can unsubscribe from the newsletter at any time via the link at the bottom of every e-mail; there is no need to contact us for that.
6. Sub-processors
We engage suppliers that process personal data on our behalf as part of their services. We have a data processing agreement with each of them. These are the sub-processors we currently engage:
- Google (Google Workspace) — e-mail, calendar, documents and storage. EU entity; transfer to the US under the EU-US Data Privacy Framework
- Microsoft (Microsoft 365) — e-mail and documents. EU entity; transfer to the US under the EU-US Data Privacy Framework
- OpenAI — AI processing (ChatGPT, Custom GPTs). Transfer to the US under the Data Privacy Framework / standard contractual clauses
- Anthropic — AI processing (Claude). Transfer to the US under the Data Privacy Framework / standard contractual clauses
- Clarify — CRM and relationship management. Transfer to the US under standard contractual clauses
- Kit (ConvertKit) — newsletter and e-mail marketing. Transfer to the US under standard contractual clauses
- TicketTailor — ticketing for open workshops. United Kingdom (adequacy decision)
- Moneybird — invoicing and accounting. The Netherlands
- Webflow — website and registration pages. Transfer to the US under standard contractual clauses
- GitHub — protected storage of project documentation. Transfer to the US under standard contractual clauses
- Krisp — transcription of conversations. Transfer to the US under standard contractual clauses
- Granola — meeting records. Transfer to the US under standard contractual clauses
This list applies to all of Narrative's services. Not every sub-processor is engaged for every assignment; what applies to a specific assignment is recorded in the data processing agreement with that client.
Changes to this list. We update this overview at least fifteen (15) business days before a new sub-processor begins processing personal data. For clients with whom we have a data processing agreement, updating this list constitutes notification. If you object within that period, let us know with reasons at info@partofthenarrative.com — we will then look for a reasonable solution together.
7. Transfers outside the European Economic Area
Several of our suppliers are US companies or host in part outside the EEA. Transfers take place on the basis of an adequacy decision (including the EU-US Data Privacy Framework) or the European Commission's standard contractual clauses, supplemented by the measures the supplier concerned has in place. The list in §6 states which basis applies per sub-processor.
8. Security
We take appropriate technical and organisational measures to protect personal data. These include two-factor authentication on our accounts, encrypted storage and connections, access on a need-to-know basis, and the use of a password manager. We select our suppliers partly on the basis of their security posture.
9. Data breaches
If we discover a data breach, we assess without undue delay what happened and who is affected. Where notification to the Dutch Data Protection Authority is required, we do so within 72 hours of discovery. If the breach poses a high risk to your rights and freedoms, we will inform you directly. Where the breach concerns data we process on behalf of a client, we inform that client, as the notification obligation then rests with them.
Do you suspect a security issue in our systems? Report it to info@partofthenarrative.com. We respond to such reports and handle them with care.
10. Lodging a complaint
If you are dissatisfied with how we handle your data, please tell us first — we will try to resolve it together. You also always have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), PO Box 93374, 2509 AJ The Hague (autoriteitpersoonsgegevens.nl).
11. Changes to this statement
We may amend this statement where our services or legislation give cause to do so. The current version is always published on this page. For material changes we update the version number and date; for changes to the sub-processor list, the period in §6 applies.