Privacy Policy

1. Privacy Policy

Why do we process personal data?

The relationship with our supporters, our donors and volunteers, and with our other stakeholders is essential to realising our shared mission. To keep in touch with our supporters and stakeholders and to mobilise them, we need to process personal data under certain circumstances. Below we explain how, when and for what specific purpose we do this.

Careful handling of your personal data is very important to us. The General Data Protection Regulation (GDPR) and the and the Dutch GDPR Implementation Act (Uitvoeringswet Algemene verordening gegevensbescherming, “UAVG”) is our starting point and we aim to provide full transparency.

Who is responsible for your data?

The Controller within the meaning of the GDPR is:

Justice for Prosperity Foundation
UN SDG House, Mauritskade 64
1092 AD Amsterdam, The Netherlands

Email: [email protected]

How and when do we process personal data?

When accessing the website

When you access our website, our hosting provider Hostnet BC (Amsterdam, The Netherlands) processes technical data that is technically necessary, in particular your IP address, browser type, operating system, date and time of access, requested pages and server log files.

We process this data to ensure the website is provided securely and reliably and to detect misuse. The legal basis for this is our legitimate interest in the secure operation of the website in accordance with Article 6(1)(f) of the GDPR.

This data is stored internally by us for a maximum of 7 days for security reasons (e.g. to investigate cases of misuse or fraud) and is then deleted. Data which must be retained for further evidence purposes is exempt from deletion until the relevant incident has been fully clarified.

Our hosting provider separately retains technical server logs for several weeks as part of the hosting service.

When making a donation

To process a donation or regular contributions and to manage volunteer activities, we may process, in particular, names, contact details, addresses, payment details and, where necessary, further information required for the activity in question.

The legal basis is the performance of the relevant legal relationship in accordance with Article 6(1)(b) of the GDPR and, where applicable, compliance with legal obligations in accordance with Article 6(1)(c) of the GDPR.

For payments, we use Mollie BV (Amsterdam, The Netehrlands). The payment service provider processes the data required for payment processing within the scope of its own data protection responsibilities. Depending on the chosen payment method, other payment service providers may be involved.

When contacting us or applying for a job with us

When you contact us or apply for a job with us, we process the data you provide only to the extent necessary to deal with your enquiry, organise the event or carry out the recruitment process.

Depending on the circumstances, the legal basis is Article 6(1)(b) of the GDPR, your consent in accordance with Article 6(1)(a) of the GDPR, or our legitimate interest in communicating with our stakeholders in accordance with Article 6(1)(f) of the GDPR.

Who receives your data?

We only disclose personal data to the extent necessary for the purposes stated. This may include, in particular, our hosting and other technical service providers, as well as payment service providers.

Data processors process data exclusively on the basis of our instructions and a contract in accordance with Article 28 of the GDPR. Furthermore, we may disclose data if we are legally obliged to do so or if this is necessary to establish, exercise or defend legal claims.

We do not sell or rent out your personal data.

Is data processed outside the European Economic Area?

We aim to keep the processing of your personal data within the European Economic Area (EEA). Where service providers or their sub-contractors process personal data outside the EEA, such transfers take place only in accordance with the conditions set out in Articles 44 et seq. of the GDPR, in particular on the basis of an adequacy decision or appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

How long do we keep personal data?

We keep personal data only for as long as is necessary for the relevant purpose or as requiered by statutory retention obligations. In particular, the following retention periods apply:

  • Server log data: generally for a maximum of 7 days; in the event of security incidents, until the matter has been fully resolved.
  • Donation, payment and accounting data: insofar as they form part of our tax-related administration, generally for 7 years in accordance with statutory Dutch retention obligations.
  • Contact data: until the relevant enquiry or event has been concluded and the data is no longer required for the associated purposes, provided there are no statutory retention obligations or other legitimate grounds for further storage.
  • Application data: in principle, until no later than four weeks after the conclusion of the application process; with the data subject’s consent, it may be retained for up to one year for future recruitment purposes.

Once the relevant retention period has expired, the data will be deleted or anonymised, provided there is no legal obligation or other legitimate reason for its continued storage.

Do you have to provide us with your personal data?

Providing your personal data is, in principle, voluntary. However, without the information required for a specific service, we will not be able to process, for example, a donation, registration or job application.

How do we protect your data?

We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access and any other unlawful processing. Access to personal data is restricted to individuals and service providers who require it for the purposes of their work.

What rights do you have?

Under the GDPR you have, provided the relevant legal conditions are met, the following rights:

  • Right of access (Art. 15 GDPR). You can ask us what personal data we hold about you.
  • Right to rectification (Art. 16 GDPR). You can ask us to correct inaccurate or incomplete data.
  • Right to erasure (Art. 17 GDPR). You can ask us to delete your data, insofar as we are not required to retain it, for example to meet a legal retention period.
  • Right to restriction of processing (Art. 18 GDPR). You can ask us to limit the processing of your data in certain circumstances.
  • Right to data portability (Art 20 GDPR) . You can ask us to provide the data you gave us in a structured, commonly used and machine-readable format.
  • Right to object (Art. 21(1) GDPR). You can object at any time to the processing of your personal data based on legitimate interests, for reasons relating to your particular situation. We will then stop the processing unless we have compelling legitimate grounds to continue or the processing is necessary for legal claims.
  • Right to object (Art. 21(2) GDPR). You can object to the processing of your data for direct marketing purposes at any time.

If processing is based on your consent, you may withdraw this consent at any time with effect for the future. The lawfulness of the processing carried out up to the point of withdrawal remains unaffected.

To exercise these rights, please send your request to [email protected]. Please make clear that your request concerns your rights under the GDPR. To verify your identity we may ask you to provide a copy of proof of identity. We advise you to black out your citizen service number (BSN), the document number and the Machine-Readable Zone (MRZ) on any copy you send.

You also have the right to lodge a complaint with a data protection supervisory authority. The Dutch data protection authority (Autoriteit Persoonsgegevens) is the competent authority for us.

Links and Social media

Our website contains links to our social media profiles. These are ordinary links and not social media plugins. No cookies from social media platforms are set and no personal data is transmitted to those platforms when you merely visit our website.

If you click on a social media link, you will leave our website and be redirected to the relevant social media platform. The relevant platform may then process your personal data in accordance with its own privacy policy and cookie policy. We have no control over that processing.

Where can you send your questions or comments?

If you have any questions or comments, please contact us. You can use the contact form on the website or send an email to [email protected].

This Privacy Policy was last updated on September 14th, 2026. To continue to comply with the latest developments in privacy protection, we make changes to this Privacy Policy from time to time. You will always find the most recent version on this page.

2. Cookie Policy

What are cookies?

Cookies are small text files used to store small pieces of information. They are stored on your device when the website is loaded in your browser. Similar technologies may also be used to store or access information on your device. Depending on there prpose, these technologies can help us make the website function properly, make it more secure, provide a better user experience, and understand how the website performs so that we can improve it.

How do we use cookies?

Our website uses cookies and similar technologies for a limited number of purposes. Cookies and similar technologies that are necessary for the website to function correctly do not collect personally identifiable data. We collect website statistics using a privacy-friendly tool that does not use cookies and does not store personal data, so it does not require your consent (see “Website statistics” below).

Our donation form is embedded on our website. If you make a donation or select a payment method, cookies or similar technologies may be used by our payment service providers, including Mollie and, depending on the payment method selected, other payment providers. These technologies may be used, for example, to maintain the payment session, process the transaction securely, prevent fraud, authenticate the payment and record the payment status.

What types of cookies do we use?

Essential. These cookies are essential for the full functionality of our site. They allow us to maintain user sessions and prevent security threats. They do not collect or store personal information.

Functional. These cookies enable certain non-essential functionalities, such as embedding content like videos or sharing content on social media platforms.

Preferences. These cookies store your settings and browsing preferences, such as language, so that you have a better experience on future visits.

We do not use marketing cookies. Our website does not display advertisements.

Website statistics

We collect aggregated, anonymous statistics about how our website is used, such as the number of visitors and which pages are viewed. This is done with a privacy-friendly tool that runs on our own servers, does not use cookies, and anonymises visitor data so that it cannot be traced back to an individual. Because no personal data is stored, this does not rely on cookies and does not require your consent.

How can you control cookie preferences?

Different browsers provide different methods to block and delete cookies. You can change your browser settings to block or delete cookies.