This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected when you use onenakfa.
It applies to:
- Visitors to onenakfa websites
- Organization administrators and treasurers
- Members who create their own accounts
- Members recorded by an organization
- Event guests and ticket purchasers
- Candidates and voters using election features
- People who contact support
1Who operates onenakfa#
The onenakfa service is operated by:
Mustafa NOORHUSSINOperating under the brand onenakfaChemin des Lentillières 13c1023 CrissierSwitzerlandEmail: hello@onenakfa.com
In this Privacy Policy, “onenakfa,” “we,” “us,” and “our” refer to Mustafa NOORHUSSIN as the individual operating the Service.
onenakfa is currently a product and trading brand. It is not a separately incorporated legal entity.
2Our different data-protection roles#
Our role depends on why personal data is processed.
2.1When we act as controller#
We act as controller when we determine why and how personal data is processed, including for:
- Account registration
- Authentication
- Subscription billing
- Service security
- Fraud and abuse prevention
- Customer support
- Legal communications
- Our own accounting and contractual records
- Website operation
- Managing acceptance of our Terms
In these situations, we are responsible for the processing described in this Privacy Policy.
2.2When we act as processor#
An organization generally acts as controller, and we act as its processor, when the organization uses onenakfa to manage information about:
- Members
- Household members
- Branches
- Membership dues
- Payments and receipts
- Events
- Tickets
- Attendance
- Messages
- Candidates
- Voter eligibility
- Election participation
- Other organization records
The organization decides why this information is collected, who may access it, how long it should be retained, and what lawful basis applies.
If your personal data was entered by an organization, you should normally contact that organization first regarding access, correction, deletion, or another data-protection request. We will assist the organization where appropriate.
Our controller-processor obligations are described in the Data Processing Addendum contained in our Terms of Service.
Organizations must provide their own privacy notice to their members. We publish a privacy notice template as a starting point.
3Personal data we collect#
3.1Account and profile information#
When you create or use an account, we may collect:
- First and last name
- Email address
- Password hash
- Preferred language
- Profile name and photograph, where provided
- Account role
- Account status
- Email-verification status
- Authentication identifiers
- Session information
- Organization memberships
- Date and time of account creation
- Last successful sign-in
- Security and account-recovery information
We do not store your password in readable form.
If you use Sign in with Google, Google may provide us with information such as your name, email address, profile image, and authentication identifier.
3.2Organization and subscription information#
When an organization is created or managed, we may process:
- Organization name
- Organization logo
- Public link or slug
- Country or location information
- Currency
- Time zone
- Default language
- Branch information
- Organization roles
- Administrator and billing contacts
- Selected Subscription plan
- Member limit
- Subscription status
- Stripe customer and Subscription identifiers
- Invoice information
- Payment status
- Subscription start, renewal, cancellation, and suspension dates
Stripe handles full payment-card details. We do not intentionally receive or store full card numbers or card security codes.
3.3Member and household information#
Organizations may enter or import:
- First and last name
- Member number
- Email address
- Telephone number
- Postal address
- Profile photograph
- Branch
- Role
- Membership status
- Joining date
- Renewal information
- Household relationships
- Notes
- Custom fields configured by the organization
- Invitation and account-access status
- Archive, restoration, merge, or anonymization records
Membership in certain organizations may reveal sensitive information, including religious, political, philosophical, cultural, ethnic, or mutual-aid affiliations.
Organizations are responsible for deciding whether it is lawful and necessary to collect such information.
3.4Membership dues and payment records#
Organizations may process:
- Dues plan
- Amount
- Currency
- Payment method
- Payment date
- Payment status
- Cash-payment record
- Bank-transfer record
- Stripe transaction identifier
- Receipt number
- Refund status
- Internal notes
- Identity of the person who recorded the payment
- Reconciliation and audit information
We do not independently verify that cash or bank-transfer payments were actually received.
3.5Events, tickets, and attendance#
We may process:
- Event name, description, location, date, and time
- Ticket type and price
- Ticket purchaser or holder name
- Email address
- Ticket identifier
- QR code
- Payment status
- Registration date
- Check-in status and time
- Attendance record
- Refund or cancellation information
- Event communications
A Guest may be able to obtain or purchase a ticket without creating an onenakfa account.
3.6Election information#
Where an organization uses election features, we may process:
- Election title and description
- Voting period
- Positions
- Candidates
- Candidate profiles
- Member eligibility
- Whether an eligible Member has participated
- Ballot and vote information
- Vote totals
- Election status
- Administrative actions and audit information
The organization is responsible for determining whether electronic voting is lawful and appropriate for its election.
Where the product separates ballot choices from ordinary Member records, we process those records according to that technical design and the organization’s instructions.
The organization remains responsible for its election rules, candidate eligibility, voter eligibility, results, disputes, and legal obligations.
3.7Messages and email-delivery information#
When an organization sends messages through onenakfa, we may process:
- Sender information
- Recipient names and email addresses
- Recipient group or branch
- Message subject
- Message body
- Language
- Date and time sent
- Delivery status
- Bounce information
- Complaint information
- Provider response
- Failure reason
Transactional emails are delivered through Amazon Simple Email Service in the US East (N. Virginia), United States region.
This means recipient information, message content, headers, and delivery metadata may be processed in the United States.
3.8Activity and audit records#
We may record actions such as:
- Account creation
- Sign-ins
- Organization creation
- Member imports
- Member edits
- Role changes
- Invitations
- Archiving and restoration
- Member merges
- Personal-data removal
- Payment recording
- Event creation
- Ticket check-in
- Election administration
- Subscription changes
- Data exports
- Organization deletion
- Support actions
These records may include:
- User identifier
- Organization identifier
- Action performed
- Date and time
- Relevant record identifier
- Previous and updated state
- IP address where appropriate
Audit records help organizations understand what happened and help us investigate errors, misuse, and security incidents.
3.9Technical and security information#
When you access the Service, we may automatically receive:
- IP address
- Browser and device type
- User-Agent information
- Operating system
- Preferred language
- Requested page or endpoint
- Date and time
- Referring page where available
- Session identifier
- Authentication events
- Error information
- Rate-limit events
- Security alerts
- Network and request metadata
We use this information to operate, protect, troubleshoot, and improve the reliability of the Service.
3.10Support and legal communications#
If you contact us, we may process:
- Your name
- Email address
- Organization
- Message content
- Attachments
- Support history
- Technical information relevant to the request
- Internal support notes
- Date and outcome of the request
Please do not send passwords, full card details, or unnecessary sensitive personal data in support messages.
3.11Information from third parties#
We may receive personal data from:
- Organizations using onenakfa
- Google, when you use Google sign-in
- Stripe, concerning subscriptions, connected accounts, and payment status
- Amazon Web Services, concerning email delivery, bounces, and complaints
- Cloudflare, concerning network and security events
- Service providers involved in investigating security or delivery issues
- Authorities where disclosure is legally required
4Why we process personal data#
We process personal data for the following purposes:
Providing the Service#
To:
- Create and manage accounts
- Authenticate users
- Display the correct organization and permissions
- Store organization records
- Process membership workflows
- Record payments
- Generate receipts
- Issue tickets
- Register attendance
- Send communications
- Operate elections
- Produce reports and exports
- Provide multilingual interfaces
Where the GDPR applies, this processing may be necessary to perform a contract or take requested steps before entering a contract.
Where an individual is not personally a contracting party, processing may be based on our legitimate interest and the organization’s legitimate interest in providing access to the Service.
Subscription administration#
To:
- Activate plans
- Process Subscription payments
- Issue invoices
- Handle renewals and cancellations
- Enforce plan limits
- Recover unpaid fees
- Maintain accounting records
This processing may be necessary for contract performance and compliance with legal obligations.
Security and abuse prevention#
To:
- Protect accounts
- Prevent unauthorized access
- Detect fraud
- Enforce rate limits
- Investigate suspicious activity
- Protect organizations and Members
- Maintain audit records
- Respond to vulnerabilities and incidents
Where the GDPR applies, this is based on our legitimate interest in protecting the Service, its users, and our infrastructure, and where applicable on legal obligations.
Communications and support#
To:
- Send verification emails
- Send password-reset messages
- Provide ticket and receipt emails
- Send operational notifications
- Answer support requests
- Inform administrators about material Service or legal changes
This processing may be necessary for contract performance or based on legitimate interests.
We do not currently use personal data for third-party advertising or behavioral advertising.
Legal compliance and claims#
To:
- Meet accounting and tax obligations
- Respond to lawful requests
- Establish and defend legal claims
- Enforce our Terms
- Preserve evidence of contractual acceptance
- Investigate unlawful activity
This processing may be required by law or based on our legitimate interest in protecting our legal rights.
Customer-controlled processing#
When we process Customer Data as a processor, the organization determines the purpose and legal basis.
We do not use Customer Data for unrelated purposes.
5Swiss and European legal bases#
We process personal data in accordance with the principles and requirements of the Swiss Federal Act on Data Protection.
Where the European Union or United Kingdom GDPR applies, we rely as appropriate on:
- Performance of a contract
- Steps requested before entering a contract
- Compliance with a legal obligation
- Legitimate interests
- Consent, where consent is required
- Another lawful basis available under applicable law
Where processing is based on consent, consent may be withdrawn at any time. Withdrawal does not affect processing that was lawful before withdrawal.
6Who may receive personal data#
Personal data may be disclosed to:
The organization#
Administrators, treasurers, organizers, and other Authorized Users may access Customer Data according to their assigned roles and permissions.
The organization controls those permissions.
Service providers#
We use providers for:
- Server hosting
- Database infrastructure
- Transactional email
- Payments
- Authentication
- DNS
- Network protection
- Technical support and security
Our current providers are listed on our Subprocessors and Third-Party Providers page.
Stripe#
Stripe processes Subscription payments and payments made to organizations.
Stripe may act as an independent controller for card, bank, identity-verification, fraud-prevention, and regulatory information it handles.
Stripe’s own terms and privacy policy apply to its processing.
Google#
If you use Google sign-in, Google processes information under its own terms and privacy policy.
Professional advisers#
Information may be disclosed to lawyers, accountants, insurers, security specialists, and other professional advisers subject to appropriate confidentiality obligations.
Business transfer#
If the onenakfa business is incorporated, reorganized, financed, sold, transferred, or merged, relevant personal data may be disclosed to the new entity, advisers, or prospective purchaser under appropriate confidentiality and data-protection safeguards.
We will update this Privacy Policy if the identity of the controller changes.
7Subprocessors and third-party providers#
Our main providers currently include:
- OVHcloud for server hosting in France
- Amazon Web Services SES for transactional email in US East (N. Virginia), United States
- Stripe for Subscription and organization payment processing
- Google for optional sign-in
- Cloudflare for DNS, network delivery, and DDoS protection
Supabase is self-hosted on our OVHcloud infrastructure. It is software used to operate the Service and is not currently a separate external hosting recipient.
Provider roles, processing locations, and data categories are described on our Subprocessors and Third-Party Providers page.
8International transfers#
Personal data may be processed in:
- Switzerland
- France and other countries in the European Economic Area
- The United States
- Other countries where our global service providers operate
In particular:
- The primary application server and database are hosted in France.
- Transactional emails are processed through Amazon Web Services SES in US East (N. Virginia), United States.
- Stripe may process payment information in Europe, the United States, and other locations.
- Google may process sign-in information in Europe, the United States, and other locations.
- Cloudflare operates a global network and may process network and security information in multiple countries.
Where a destination does not provide an adequate level of protection, we use or require an appropriate transfer mechanism where legally necessary, such as:
- The Swiss–US Data Privacy Framework for certified recipients
- The EU–US Data Privacy Framework for certified recipients
- Standard Contractual Clauses
- Swiss adaptations or additions to Standard Contractual Clauses
- Contractual data-protection guarantees
- Another legally recognized safeguard
You may contact us for more information about safeguards applicable to a particular transfer.
9How long we retain personal data#
We retain personal data only for as long as reasonably necessary for its purpose, the Customer’s instructions, legal requirements, security, and the establishment or defence of claims.
Active Customer and Member data#
Customer Data is normally stored for as long as the organization maintains an active onenakfa account.
The organization may archive, correct, export, anonymize, or delete records using available product functions, subject to its own legal obligations.
After termination#
After a paid organization account ends:
- Customer Data normally remains available for export for 30 days.
- After that period, it may be removed from active systems.
- Residual backup copies may remain until overwritten through the normal backup cycle, normally for no longer than a further 90 days.
- Backup access remains restricted.
- Information subject to a legal hold or mandatory retention obligation may be retained for longer.
Subscription and accounting records#
We may retain our own:
- Subscription invoices
- Billing records
- Business-accounting records
- Tax records
- Supporting accounting documents
for ten years or another period required by applicable law.
This retention rule applies to records concerning the onenakfa business. It does not mean that every membership-dues or event-payment record controlled by an organization is automatically retained by us for ten years after the organization leaves the Service.
Organizations are responsible for exporting and retaining the accounting and membership records they are legally required to keep.
Contractual records#
We may retain:
- Accepted Terms version
- Acceptance timestamp
- Customer identity
- Organization identity
- Related contractual notices
- Evidence concerning disputes
for as long as reasonably necessary to administer the relationship, comply with law, and establish or defend claims.
Technical and security logs#
Routine server and security logs are normally retained for up to 90 days.
Relevant logs may be retained for longer where necessary to investigate:
- A security incident
- Fraud
- Abuse
- A legal claim
- A breach of the Terms
Email-delivery events#
Bounce, complaint, and delivery-event information held in our application is normally retained for up to 90 days unless longer retention is needed to protect email deliverability, investigate abuse, or comply with a Customer instruction.
Message content stored as Customer Data follows the Customer Data retention period.
Amazon Web Services may apply its own operational retention practices.
Support communications#
Support correspondence may normally be retained for up to three years after the request is resolved.
It may be retained longer where relevant to a continuing account, dispute, security investigation, or legal obligation.
Guest tickets#
Guest ticket and attendance data is controlled by the organization that operates the event.
While the organization continues using onenakfa, that organization determines how long the information is needed, subject to available product functions and applicable law.
Following termination, the general Customer Data deletion process applies.
10Cookies and browser storage#
We currently use only technologies necessary to provide and protect the Service.
These may include:
- Authentication and session cookies
- Security and CSRF tokens
- Language-preference storage
- Organization-selection storage
- Short-lived technical identifiers
These technologies are used to:
- Keep users signed in
- Protect forms and sessions
- Remember language preferences
- Display the correct organization
- Prevent fraud and unauthorized access
We do not currently use advertising cookies or behavioral advertising trackers.
We do not currently use non-essential analytics cookies.
Because no non-essential cookies are currently used, we do not presently display a consent banner. If we introduce non-essential analytics, advertising, or similar technologies, we will update this notice and request consent where required.
Blocking necessary cookies or browser storage may prevent account and security features from working.
11Security#
We use technical and organizational measures designed to protect personal data.
Depending on the relevant system, these measures may include:
- TLS encryption in transit
- Encryption of server storage
- Password hashing
- Role-based permissions
- Organization-level data separation
- Database access controls
- Infrastructure access restrictions
- Security logging
- Rate limiting
- Backups
- Security updates
- Incident-response procedures
No internet service can guarantee absolute security.
Users and organizations also have responsibilities, including:
- Using strong passwords
- Protecting administrator accounts
- Not sharing credentials
- Removing access when it is no longer needed
- Limiting sensitive data
- Reporting suspected compromise promptly
Security concerns may be reported to hello@onenakfa.com.
Please do not publicly disclose a vulnerability before we have had a reasonable opportunity to investigate it.
12Personal-data breaches#
If we become aware of a confirmed personal-data breach affecting information for which we act as controller, we will investigate and provide legally required notifications.
Where we act as processor, we will notify the affected organization without undue delay and provide available information needed for its assessment.
The organization is responsible for determining whether it must notify affected Members, Guests, or supervisory authorities concerning Customer Data.
13Automated decision-making#
We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects for individuals.
The Service may automatically:
- Enforce account permissions
- Calculate totals
- Apply member limits
- Generate receipts
- Determine whether a voting period is open
- Detect duplicate or invalid entries
- Block suspicious or excessive requests
These are operational functions. Material membership, payment, candidate, election, and organizational decisions remain the responsibility of the relevant organization.
14Your rights#
Depending on the law that applies, you may have the right to:
- Obtain information about processing
- Request access to personal data
- Request correction
- Request deletion
- Request restriction
- Object to certain processing
- Receive certain data in a portable format
- Withdraw consent
- Request human review of an applicable automated decision
- Complain to a supervisory authority
These rights are not absolute. A request may be limited where information must be retained for legal, security, accounting, contractual, or third-party-rights reasons.
15Requests concerning organization-controlled information#
If an organization entered your information into onenakfa, the organization is generally responsible for responding to your request.
You should contact the organization first when your request concerns:
- Membership status
- Member profile
- Membership dues
- Payment records
- Receipts
- Event registration
- Attendance
- Messages
- Candidate information
- Voting eligibility
- Organization retention decisions
We may forward your request to the organization or ask you to contact it directly.
We will assist the organization where required and will not normally alter its records without its knowledge.
16Exercising your rights#
Requests may be sent to:
Please include enough information to:
- Identify you
- Locate the relevant account or organization
- Understand your request
- Verify your identity where necessary
We may request additional verification before disclosing or changing personal data.
We will respond within the period required by applicable law, generally within 30 days where that period applies.
Complex requests may require additional time where the law permits.
17Complaints#
You may contact us first so that we can attempt to address your concern.
In Switzerland, you may also contact the:
Federal Data Protection and Information Commissioner — FDPIC
If the GDPR applies, you may complain to the competent data-protection authority in the country where you live, work, or believe an infringement occurred.
18Children and minors#
The organization-administration Service is not intended for children to create or manage organization accounts independently.
An organization may record a minor as a Member, household member, or event participant where the organization has:
- A lawful purpose
- An appropriate legal basis
- Any required parental or guardian authorization
- Appropriate privacy information
- Suitable safeguards
The organization is responsible for determining the applicable age and consent requirements in its jurisdiction.
If you believe a minor’s information has been entered unlawfully, contact the responsible organization or email hello@onenakfa.com.
19External links#
Public event pages, organization content, or communications may contain links to third-party websites.
We are not responsible for the privacy practices of websites or services we do not control.
20Changes to this Privacy Policy#
We may update this Privacy Policy to reflect:
- Product changes
- Provider changes
- Legal requirements
- Security improvements
- Business restructuring
If a change materially affects how personal data is processed, we will normally notify organization administrators at least 30 days before it takes effect.
A shorter period may apply where an urgent change is required for law, security, fraud prevention, or provider requirements.
The current version and update date will remain available on this page.
21Languages#
This Privacy Policy may be available in English, Arabic, Tigrinya, or other languages.
Translations are provided to make the Policy accessible.
Unless mandatory law requires otherwise, the English version controls if there is a material inconsistency between versions.
22Contact#
For privacy questions, rights requests, security reports, or complaints:
Mustafa NOORHUSSINOperating under the brand onenakfaChemin des Lentillières 13c1023 CrissierSwitzerlandEmail: hello@onenakfa.com