Menu
Version 1.0.0

Privacy Policy

Last updated: 2 July 2026

Stichting INFAK attaches great importance to the protection of your personal data. In this privacy policy, we explain which data we collect via www.stichtinginfak.nl, what we use it for, with whom we share it and what rights you have. We process your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable laws and regulations.

1. Who we are

Stichting INFAK is the controller for the processing of personal data via the website www.stichtinginfak.nl. Stichting INFAK is established in the Netherlands and registered with the Dutch Chamber of Commerce (KvK) under number 97212482. Stichting INFAK supports people in need with food, water, education and emergency aid, anywhere in the world. Through our website, you can donate to donation projects, create an account and contact us. For questions about this privacy policy or about the processing of your personal data, you can contact us at info@stichtinginfak.nl.

2. Which personal data we process

We process only personal data that you provide to us yourself or that is collected automatically when you use our website. Depending on the situation, this concerns the following data: • When making a donation: your full name, email address, telephone number (optional), the donation amount and the project to which you are donating, your confirmation that you are 18 years of age or older, your agreement to the privacy terms and your optional choice to receive updates about new projects. • When creating an account: your email address and password (stored solely in hashed, unreadable form), the data required for email verification, two-factor authentication (2FA) and password recovery, and the overview of your donations and the projects you follow. • Via the contact form: your name, email address, telephone number (optional), the project your question relates to (optional) and the content of your message. • Automatically collected data: your IP address, data about your browser and device and usage data about your visit to the website (such as the pages visited), including via the functional login cookies accessToken and refreshToken, Google Analytics cookies (including _ga and _ga_*) and Google reCAPTCHA. We do not process any special categories of personal data, such as data on health or religious beliefs, and we do not use any advertising or tracking cookies for marketing purposes. We also request that you do not provide such special data to us via the contact form.

3. What we use your data for

We use your personal data solely for the following purposes: • Processing and administering your donations, including handling the payment via our payment service providers Mollie and Stripe. • Creating, securing and managing your account, including email verification, two-factor authentication (2FA) and password recovery. • Answering questions and messages that you send us via the contact form or by email. • Sending updates about new projects, solely if you have given your consent to do so. You can unsubscribe from these at any time. • Compiling website statistics and improving and securing our website, including with the help of Google Analytics and Google reCAPTCHA. • Complying with legal obligations, such as the statutory tax retention obligation. We do not take decisions based solely on automated processing, including profiling, that have legal effects for you or otherwise significantly affect you.

4. On which legal bases we process your data

We process your personal data solely on the basis of the legal grounds set out in the GDPR: • Performance of a contract: for processing and administering your donation and for creating and managing your account. Without this data, we cannot process your donation or provide your account. • Consent: for sending updates about new projects and, where legally required, for placing cookies. You can withdraw your consent at any time; this does not affect the lawfulness of the processing carried out prior to the withdrawal. • Legitimate interest: for securing our website against spam and misuse (including the use of Google reCAPTCHA), answering your questions and keeping website statistics in order to improve our website. In doing so, we always carefully weigh our interest against your privacy interest. • Legal obligation: for retaining donation and payment data on the basis of the statutory tax retention obligation and for complying with other legal obligations.

5. Payments via Mollie and Stripe

Payments on our website are processed through the external payment service providers Mollie and Stripe. When you donate, you are redirected to the secure payment environment of Mollie or Stripe, where you complete the payment. Mollie and Stripe are independent controllers for the personal data they process in the context of the payment. Stichting INFAK itself does not receive or store any full payment details, such as card numbers. We receive only the data necessary to process and administer your donation. For more information about how these parties handle your data, we refer you to the privacy statements of Mollie and Stripe, which you can consult on their own websites.

6. Google services

On our website, we use the following Google services: • Google Analytics: for keeping website statistics, so that we gain insight into the use of the website and can improve it. This involves placing cookies, including _ga and _ga_*. We use this data solely for statistical purposes and not for marketing. • Google Search Console: for insight into how our website is found in search results. This service does not place any cookies on our website and processes only aggregated search data. • Google reCAPTCHA: to secure the contact form against spam and misuse. In doing so, reCAPTCHA may place cookies and process data such as your IP address. The processing of personal data by Google is subject to Google's privacy policy, which you can consult on Google's website.

7. With whom we share your data

We share your personal data only with parties that need it to enable our services: • Mollie and Stripe, for the handling of payments (as independent controllers). • Google, for Google Analytics, Google reCAPTCHA and Google Search Console. • The hosting provider of our website, for hosting the website and the data stored on it. With parties that act as processors on our behalf, we conclude a data processing agreement where required, setting out arrangements for the careful and secure handling of your data. We never sell your personal data to third parties. We disclose your data to other parties only if we are legally obliged to do so, for example to competent authorities.

8. Transfer outside the EEA

Some of the service providers we use, including Google, are established in the United States or process data outside the European Economic Area (EEA). The transfer of personal data to the United States takes place on the basis of the EU-US Data Privacy Framework and/or the standard contractual clauses adopted by the European Commission. This ensures that your personal data enjoys an adequate level of protection even outside the EEA. You can request more information about these safeguards from us at info@stichtinginfak.nl.

9. How long we retain your data

We do not retain your personal data for longer than necessary for the purposes for which it was collected, or for as long as a legal retention obligation applies. We apply the following retention periods: • Donation and payment data: 7 years, on the basis of the statutory tax retention obligation. • Account data: for as long as your account exists. If you delete your account, we delete your account data, unless and to the extent that a legal retention obligation applies. • Messages via the contact form: no longer than 2 years after your question or request has been handled. Once the retention period has expired, your data is deleted or anonymised.

10. How we secure your data

We take appropriate technical and organisational measures to protect your personal data against loss, misuse and unauthorised access. These include, among other things: • TLS encryption of the traffic between your browser and our website. • Storage of passwords in hashed form, so that they are not readable. • Two-factor authentication (2FA) as additional security for accounts. • Access to personal data restricted to persons who are authorised to do so and who need the data to carry out their tasks. If you suspect a security problem or a data breach, we ask you to report this to us immediately at info@stichtinginfak.nl.

11. Your rights

Under the GDPR, you have the following rights with regard to your personal data: • Right of access: you can request which personal data we process about you. • Right to rectification: you can have inaccurate or incomplete data corrected or supplemented. • Right to erasure: you can request us to erase your data, unless we are required to retain it under a legal obligation. • Right to restriction of processing: in certain cases, you can request us to restrict the processing of your data temporarily. • Right to object: you can object to processing that takes place on the basis of our legitimate interest. • Right to data portability: you can receive the data you have provided to us in a structured, commonly used and machine-readable format. • Right to withdraw consent: if you have given consent, for example to receive project updates, you can withdraw it at any time. This does not affect the lawfulness of the processing carried out prior to the withdrawal. You can submit a request free of charge at info@stichtinginfak.nl. To be certain that the request has been made by the right person, we may ask you to verify your identity. We will respond to your request within one month. For complex or extensive requests, this period may be extended by a maximum of two months; in that case, we will inform you of this within the first month.

12. Minors and complaints

Donations via our website are intended solely for persons aged 18 or older. When making a donation, you must confirm that you are 18 years of age or older. We do not deliberately process the personal data of children. If we establish that we have processed the data of a minor without the required consent, we will delete this data as soon as possible. If you disagree with the way we handle your personal data, we ask you to contact us first at info@stichtinginfak.nl, so that we can look for a solution together. In addition, you always have the right to lodge a complaint with the supervisory authority, the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority), via autoriteitpersoonsgegevens.nl.

13. Changes and contact

We may amend this privacy policy from time to time, for example in the event of changes to our services or to laws and regulations. The current version is always available on our website, www.stichtinginfak.nl, stating the date of the most recent change. We advise you to consult this policy regularly. If you have questions about this privacy policy or about the processing of your personal data, you can contact Stichting INFAK at info@stichtinginfak.nl.