How we handle your information
We ask for as little as we can, we keep it no longer than we must, and only the board ever reads it.
Last updated 14 September 2026
1. Who is responsible
YFSS is not a registered organisation. It is a private initiative by a group of Yemeni professionals living in the Netherlands, who pool small monthly contributions so that any of them facing an urgent need can borrow without interest. There is no company, foundation or charity behind it, and no supervisory authority.
That means the people who run the initiative — the volunteers the members call the board — are together responsible for the information described here. Under the General Data Protection Regulation they act as joint controllers, personally, rather than on behalf of a legal entity. They are reachable at the address below, and one of them answers.
For anything in this policy — a question, a correction, or a request to delete something — write to yfss.yemen@gmail.com. A member of the board answers these personally.
2. What we collect, and why
Everything below reaches us because you typed it into a form on this website, or because your browser sent it as part of making the request. We do not buy information about you, we do not track you across other websites, and we run no analytics.
When you ask to become a member
| What | Why | On what legal basis |
|---|---|---|
| Your name, email address, city, and phone number if you give one | To reply to you, set up your membership and keep in touch about it | Steps taken at your request before joining, and your consent |
| The monthly amount you choose and when you want to start | To record what you have committed to and to reconcile contributions | Steps taken at your request; later, the membership itself |
| Anything you write in the message box | Because you chose to tell us | Your consent |
When you ask the board for support
| What | Why | On what legal basis |
|---|---|---|
| Your name, email, phone and city | To identify you as a member and reach you quickly | Steps taken at your request before a loan agreement |
| The amount you need, what it is for, when you need it, and how you expect to repay | So the board can decide, and agree a repayment plan with you | Steps taken at your request before a loan agreement |
| The description of your situation | So the board understands what it is being asked to help with | Your explicit consent (see section 3) |
What your browser sends with either form
| What | Why | On what legal basis |
|---|---|---|
| Your IP address, the name it resolves to, a short description of your browser and device, and the time | To recognise abuse of the forms, to limit how often one connection can submit, and to look into anything suspicious | Our legitimate interest in keeping the fund's forms usable and honest |
| An approximate location and network operator, worked out from that IP address | The same reason: a request that appears to come from far outside the fund's community is worth a second look | Our legitimate interest in preventing fraud and abuse |
That location is the location of your connection, not of you. A mobile network routinely places a person in a different city and a VPN in a different country. The board treats it as a hint that something may need checking, never as a fact about where anyone lives.
The web server also keeps ordinary access logs — the address, the page requested and the time — for every visitor, as almost every web server does. Those exist to keep the site running and secure.
3. Sensitive details in a support request
A request for support often has to explain something private: an illness, a bereavement, a family emergency, money trouble. Information about health and similar matters gets special protection in European law, and we may only handle it if you clearly agree.
That is what the confirmation box on the support form is for. By ticking it you consent to the board reading and keeping the details you have written in order to decide on your request. You can withdraw that consent at any time by writing to us; if you do, we stop processing the request and delete what you sent, unless a loan has already been agreed and the record is needed for the fund's accounts.
You do not have to write more than the board needs. A short, factual description is enough.
4. Who else can see it
Inside the fund: only board members. Support requests are never discussed with the membership, and reports to members show totals, never names.
Outside the fund, a small number of services necessarily handle the information in order for the website and its email to work:
| Service | What it handles | Where |
|---|---|---|
| Hetzner Online GmbH | The server this website runs on, and therefore everything stored on it | Germany (EU) |
| Cloudflare (Turnstile) | The “I am human” check on both forms; it sees your IP address and how your browser behaves | EU/United States |
| ipwho.is | Turns an IP address into an approximate location for the board's copy of a request | Outside the fund's control |
| Google (Gmail) | The fund's mailbox, so it holds the emails these forms generate | EU/United States |
We do not sell your information, we do not use it for advertising, and we do not pass it to anyone else unless the law requires it.
5. Cookies and tracking
This website sets no cookies of its own, stores nothing in your browser, and carries no analytics or advertising scripts. The fonts and images are served from this domain rather than from a third party, so simply reading the page tells nobody but our own server that you were here.
The one exception is the “I am human” check by Cloudflare, and it only appears once you start filling in a form. Reading the page does not load it, so a visitor who never writes to us never meets a third party at all. When it does run it may store a short-lived technical value in your browser; it is there to keep automated submissions out, not to follow you.
You can see the full list, and change anything that is optional, from cookie settings — also linked in the footer of every page. Today that list holds nothing optional: there is no statistics or advertising technology on this site to switch off. If that ever changes, you will be asked before it runs.
6. How long we keep it
- Form records on the server: deleted after twelve months.
- Emails in the fund's mailbox: kept while they are relevant to your membership or your loan, then deleted.
- Membership and loan records: kept while you are a member and for as long afterwards as the fund's accounting obligations require.
- A request that is refused or withdrawn: deleted once the decision has been communicated and any appeal period in the fund's statutes has passed.
7. Your rights
You can ask us to:
- show you what we hold about you;
- correct anything that is wrong;
- delete what we hold, where we are not obliged to keep it;
- stop using it for a particular purpose, or object to our using it at all;
- hand you a copy in a portable form;
- withdraw consent you have given, at any time.
Write to yfss.yemen@gmail.com and we will answer within one month. If you are not satisfied with how we handle it, you may complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.
8. How we protect it
- The whole site is served over an encrypted connection, and plain connections are redirected to it.
- Form records are stored so that only the web server account can read them, on a server whose access is limited to the people who maintain it.
- Passwords and keys live in server configuration outside the website's own files, never in the pages, never in a database, and never in anyone's inbox.
- The forms are rate-limited and protected against automated submission, so the fund's inbox cannot be flooded.
9. Changes to this policy
If we change how we handle information, this page changes with it and the date at the top is updated. The fund's statutes, and the loan agreement you sign, take precedence over this page wherever they say something different.