Your association needs its own privacy notice. onenakfa’s Privacy Policy explains what we do with personal data as your processor — it does not tell your members what you do with theirs, and it does not replace the notice section 16.3 of the Terms of Service asks you to provide.
This is a starting point, not legal advice, and not a document you can publish unchanged. Every bracketed field is a decision only your committee can make — especially the retention periods in section 10 and the ballot-secrecy statement in section 3.
Before you publish it
- Replace every [BRACKETED FIELD] — searching for
[finds them all. - Delete any section describing something your association does not actually do. A notice that claims to run elections you never hold is worse than a shorter one.
- Have someone who knows your statutes check sections 2, 10, and 11 against them.
- Publish it somewhere members can reach without signing in, and put that address in section 16.
Privacy Notice Template for Organizations Using onenakfa
This is a template. Replace every item in square brackets before publishing it.
Last updated: [DATE]
1Who is responsible for your information
The organization responsible for the processing described in this notice is:
[FULL LEGAL OR OFFICIAL ORGANIZATION NAME]
[POSTAL ADDRESS]
[POSTCODE AND CITY]
[COUNTRY]
Email: [PRIVACY OR CONTACT EMAIL]
Telephone: [OPTIONAL TELEPHONE NUMBER]
In this notice, "we," "us," and "our" refer to [ORGANIZATION NAME].
2Why we process personal data
We process personal data to administer our organization and its activities, including:
- Maintaining our member directory
- Managing membership status
- Collecting membership dues
- Recording cash and bank-transfer payments
- Processing online payments
- Issuing receipts
- Organizing events
- Issuing tickets
- Registering attendance
- Communicating with Members
- Managing branches and committees
- Preparing reports
- Conducting elections where applicable
- Complying with our statutes and legal obligations
- Protecting the organization and its Members
Our legal basis may include:
- Performance of a membership or other agreement
- Our legitimate organizational interests
- Compliance with a legal obligation
- Consent where consent is required
- Another legal basis available under applicable law
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that was lawful before withdrawal.
3Information we may collect
Depending on your relationship with us, we may process:
Membership information
- Name
- Member number
- Email address
- Telephone number
- Address
- Profile photograph
- Branch
- Committee role
- Membership status
- Joining date
- Renewal information
- Household relationships
- Information entered into custom membership fields
Payment information
- Membership-dues plan
- Amount
- Currency
- Payment method
- Payment date
- Payment status
- Cash or bank-transfer record
- Stripe transaction identifier
- Receipt number
- Refund information
We do not receive full payment-card details when Stripe processes a card payment.
Event information
- Event registration
- Ticket type
- Ticket identifier
- QR code
- Payment status
- Attendance and check-in information
- Event communications
Communications
- Email address
- Message group or branch
- Messages sent to you
- Delivery or failure information
- Your replies and requests
Elections
Where we conduct an election, we may process:
- Voter eligibility
- Candidate information
- Election participation
- Ballot information
- Vote totals
- Election audit information
[DESCRIBE WHETHER BALLOTS ARE ANONYMOUS, SECRET, OR LINKED TO A MEMBER RECORD UNDER YOUR ACTUAL ELECTION RULES.]
Technical and administrative information
- Account-access status
- Invitations
- Administrative changes
- Activity records
- Information needed to investigate errors, misuse, or disputes
4Sensitive personal data
Membership in our organization may reveal information about a person's:
- Religion
- Political or philosophical views
- Cultural or ethnic affiliation
- Community membership
- Mutual-aid participation
- Other sensitive relationships
We collect sensitive personal data only where we believe it is necessary and lawful.
[DESCRIBE ANY SENSITIVE CUSTOM FIELDS YOUR ORGANIZATION USES.]
Please do not provide unnecessary sensitive information in notes or free-text fields.
5Where we obtain information
We may obtain personal data:
- Directly from you
- From an administrator or committee member
- From a previous membership list
- From a household or family representative
- From an event organizer
- From Stripe
- From onenakfa
- From another source you authorized
If we receive your information from another person, you may contact us to ask where it came from.
6How we use onenakfa
We use onenakfa to manage membership, payments, events, communications, and other organization activities.
onenakfa is operated by:
Mustafa NOORHUSSIN
Operating under the brand onenakfa
Chemin des Lentillieres 13c
1023 Crissier
Switzerland
Email: hello@onenakfa.com
For the organization information described in this notice:
- We normally act as controller.
- onenakfa normally acts as our processor.
- We decide why information is collected and who may access it.
- onenakfa processes the information to provide the software and infrastructure.
onenakfa's own Privacy Policy applies to information it processes independently, such as account authentication, Subscription administration, security, and support.
7Other service providers
We may use:
Stripe
Stripe processes online payments and may independently process card, bank, identity-verification, fraud, and regulatory information.
Amazon Web Services SES
Email sent through onenakfa is delivered using Amazon Simple Email Service in US East (N. Virginia), United States.
Recipient names, email addresses, message content, and delivery information may therefore be processed in the United States.
Other providers
onenakfa uses additional providers for hosting, network security, authentication, and related infrastructure.
Current providers and processing locations are listed on onenakfa's Subprocessors and Third-Party Providers page.
8International transfers
Information processed through onenakfa may be transferred to or processed in:
- Switzerland
- France and other European Economic Area countries
- The United States
- Other countries used by global infrastructure providers
Where required, appropriate safeguards are used, such as adequacy decisions, recognized data-transfer frameworks, or contractual clauses.
Contact us for more information about a transfer concerning your personal data.
9Who can access your information
Within our organization, information may be accessed by people whose responsibilities require it, such as:
- Administrators
- Treasurers
- Committee members
- Event organizers
- Branch administrators
- Election administrators
- Other authorized volunteers
Access is assigned according to organizational roles.
We are responsible for reviewing access and removing it when no longer needed.
10How long we retain information
We retain personal data only for as long as needed for:
- Membership administration
- Payment and receipt records
- Events
- Elections
- Our statutes
- Accounting
- Tax
- Legal obligations
- Dispute resolution
- Legitimate historical or organizational records
Our normal retention periods are:
- Active membership records: [RETENTION RULE]
- Former-member records: [RETENTION RULE]
- Payment and accounting records: [RETENTION RULE]
- Event and attendance records: [RETENTION RULE]
- Election records: [RETENTION RULE]
- Communication records: [RETENTION RULE]
- Unsuccessful invitations: [RETENTION RULE]
Where possible, information that is no longer needed will be deleted or anonymized.
We are responsible for exporting legally required records before ending our use of onenakfa.
11Children and household members
We may record information concerning children or minors where:
- They are included in a household membership
- They attend an event
- Their parent or guardian provided the information
- Processing is otherwise lawful
[DESCRIBE WHETHER YOUR ORGANIZATION ACCEPTS MINOR MEMBERS.]
Where required, we obtain authorization from a parent or guardian.
12Your choices and rights
Depending on applicable law, you may ask us to:
- Explain how we use your information
- Provide access to it
- Correct inaccurate information
- Delete information
- Restrict processing
- Stop certain processing
- Provide certain information in a portable format
- Record an objection
- Withdraw consent
Some rights may be limited where we must retain information for accounting, legal, election, dispute, or third-party-rights reasons.
13How to submit a request
Contact:
[ORGANIZATION CONTACT NAME OR ROLE]
Email: [PRIVACY EMAIL]
Postal address: [POSTAL ADDRESS]
Please provide enough information to identify you and understand your request.
We may request identity verification before disclosing or changing information.
14Complaints
Please contact us first so we can attempt to resolve your concern.
You may also contact the competent data-protection authority.
For organizations established in Switzerland, this may include the Swiss Federal Data Protection and Information Commissioner.
15Security
We use reasonable administrative and technical measures to protect personal data.
These include:
- Limiting access by role
- Protecting administrator accounts
- Reviewing permissions
- Using onenakfa's security controls
- Avoiding shared administrator passwords
- Removing access when roles change
- Limiting unnecessary sensitive data
- Exporting records we must retain
- Reporting suspected security incidents
No system can guarantee absolute security.
16Changes to this notice
We may update this notice when:
- Our activities change
- We introduce new data fields
- Our providers change
- Our retention rules change
- Legal requirements change
The latest version will be available at:
[INSERT NOTICE LOCATION OR URL]
17Contact
[ORGANIZATION NAME]
[POSTAL ADDRESS]
[POSTCODE AND CITY]
[COUNTRY]
Email: [CONTACT EMAIL]
# Privacy Notice Template for Organizations Using onenakfa This is a template. Replace every item in square brackets before publishing it. Last updated: [DATE] ## 1. Who is responsible for your information The organization responsible for the processing described in this notice is: [FULL LEGAL OR OFFICIAL ORGANIZATION NAME] [POSTAL ADDRESS] [POSTCODE AND CITY] [COUNTRY] Email: [PRIVACY OR CONTACT EMAIL] Telephone: [OPTIONAL TELEPHONE NUMBER] In this notice, "we," "us," and "our" refer to [ORGANIZATION NAME]. ## 2. Why we process personal data We process personal data to administer our organization and its activities, including: - Maintaining our member directory - Managing membership status - Collecting membership dues - Recording cash and bank-transfer payments - Processing online payments - Issuing receipts - Organizing events - Issuing tickets - Registering attendance - Communicating with Members - Managing branches and committees - Preparing reports - Conducting elections where applicable - Complying with our statutes and legal obligations - Protecting the organization and its Members Our legal basis may include: - Performance of a membership or other agreement - Our legitimate organizational interests - Compliance with a legal obligation - Consent where consent is required - Another legal basis available under applicable law Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that was lawful before withdrawal. ## 3. Information we may collect Depending on your relationship with us, we may process: ### Membership information - Name - Member number - Email address - Telephone number - Address - Profile photograph - Branch - Committee role - Membership status - Joining date - Renewal information - Household relationships - Information entered into custom membership fields ### Payment information - Membership-dues plan - Amount - Currency - Payment method - Payment date - Payment status - Cash or bank-transfer record - Stripe transaction identifier - Receipt number - Refund information We do not receive full payment-card details when Stripe processes a card payment. ### Event information - Event registration - Ticket type - Ticket identifier - QR code - Payment status - Attendance and check-in information - Event communications ### Communications - Email address - Message group or branch - Messages sent to you - Delivery or failure information - Your replies and requests ### Elections Where we conduct an election, we may process: - Voter eligibility - Candidate information - Election participation - Ballot information - Vote totals - Election audit information [DESCRIBE WHETHER BALLOTS ARE ANONYMOUS, SECRET, OR LINKED TO A MEMBER RECORD UNDER YOUR ACTUAL ELECTION RULES.] ### Technical and administrative information - Account-access status - Invitations - Administrative changes - Activity records - Information needed to investigate errors, misuse, or disputes ## 4. Sensitive personal data Membership in our organization may reveal information about a person's: - Religion - Political or philosophical views - Cultural or ethnic affiliation - Community membership - Mutual-aid participation - Other sensitive relationships We collect sensitive personal data only where we believe it is necessary and lawful. [DESCRIBE ANY SENSITIVE CUSTOM FIELDS YOUR ORGANIZATION USES.] Please do not provide unnecessary sensitive information in notes or free-text fields. ## 5. Where we obtain information We may obtain personal data: - Directly from you - From an administrator or committee member - From a previous membership list - From a household or family representative - From an event organizer - From Stripe - From onenakfa - From another source you authorized If we receive your information from another person, you may contact us to ask where it came from. ## 6. How we use onenakfa We use onenakfa to manage membership, payments, events, communications, and other organization activities. onenakfa is operated by: Mustafa NOORHUSSIN Operating under the brand onenakfa Chemin des Lentillieres 13c 1023 Crissier Switzerland Email: hello@onenakfa.com For the organization information described in this notice: - We normally act as controller. - onenakfa normally acts as our processor. - We decide why information is collected and who may access it. - onenakfa processes the information to provide the software and infrastructure. onenakfa's own Privacy Policy applies to information it processes independently, such as account authentication, Subscription administration, security, and support. ## 7. Other service providers We may use: ### Stripe Stripe processes online payments and may independently process card, bank, identity-verification, fraud, and regulatory information. ### Amazon Web Services SES Email sent through onenakfa is delivered using Amazon Simple Email Service in US East (N. Virginia), United States. Recipient names, email addresses, message content, and delivery information may therefore be processed in the United States. ### Other providers onenakfa uses additional providers for hosting, network security, authentication, and related infrastructure. Current providers and processing locations are listed on onenakfa's Subprocessors and Third-Party Providers page. ## 8. International transfers Information processed through onenakfa may be transferred to or processed in: - Switzerland - France and other European Economic Area countries - The United States - Other countries used by global infrastructure providers Where required, appropriate safeguards are used, such as adequacy decisions, recognized data-transfer frameworks, or contractual clauses. Contact us for more information about a transfer concerning your personal data. ## 9. Who can access your information Within our organization, information may be accessed by people whose responsibilities require it, such as: - Administrators - Treasurers - Committee members - Event organizers - Branch administrators - Election administrators - Other authorized volunteers Access is assigned according to organizational roles. We are responsible for reviewing access and removing it when no longer needed. ## 10. How long we retain information We retain personal data only for as long as needed for: - Membership administration - Payment and receipt records - Events - Elections - Our statutes - Accounting - Tax - Legal obligations - Dispute resolution - Legitimate historical or organizational records Our normal retention periods are: - Active membership records: [RETENTION RULE] - Former-member records: [RETENTION RULE] - Payment and accounting records: [RETENTION RULE] - Event and attendance records: [RETENTION RULE] - Election records: [RETENTION RULE] - Communication records: [RETENTION RULE] - Unsuccessful invitations: [RETENTION RULE] Where possible, information that is no longer needed will be deleted or anonymized. We are responsible for exporting legally required records before ending our use of onenakfa. ## 11. Children and household members We may record information concerning children or minors where: - They are included in a household membership - They attend an event - Their parent or guardian provided the information - Processing is otherwise lawful [DESCRIBE WHETHER YOUR ORGANIZATION ACCEPTS MINOR MEMBERS.] Where required, we obtain authorization from a parent or guardian. ## 12. Your choices and rights Depending on applicable law, you may ask us to: - Explain how we use your information - Provide access to it - Correct inaccurate information - Delete information - Restrict processing - Stop certain processing - Provide certain information in a portable format - Record an objection - Withdraw consent Some rights may be limited where we must retain information for accounting, legal, election, dispute, or third-party-rights reasons. ## 13. How to submit a request Contact: [ORGANIZATION CONTACT NAME OR ROLE] Email: [PRIVACY EMAIL] Postal address: [POSTAL ADDRESS] Please provide enough information to identify you and understand your request. We may request identity verification before disclosing or changing information. ## 14. Complaints Please contact us first so we can attempt to resolve your concern. You may also contact the competent data-protection authority. For organizations established in Switzerland, this may include the Swiss Federal Data Protection and Information Commissioner. ## 15. Security We use reasonable administrative and technical measures to protect personal data. These include: - Limiting access by role - Protecting administrator accounts - Reviewing permissions - Using onenakfa's security controls - Avoiding shared administrator passwords - Removing access when roles change - Limiting unnecessary sensitive data - Exporting records we must retain - Reporting suspected security incidents No system can guarantee absolute security. ## 16. Changes to this notice We may update this notice when: - Our activities change - We introduce new data fields - Our providers change - Our retention rules change - Legal requirements change The latest version will be available at: [INSERT NOTICE LOCATION OR URL] ## 17. Contact [ORGANIZATION NAME] [POSTAL ADDRESS] [POSTCODE AND CITY] [COUNTRY] Email: [CONTACT EMAIL]