Privacy declaration
Last update: 18 September 2026
Stichting UAP Coalitie Nederland (UAPCNL) is responsible for the processing of personal data as set out in this privacy statement. We attach the highest value to your privacy, the trust of our witnesses, and the careful handling of data.
1. Contact details
UAP Coalition Netherlands Foundation
Chamber of Commerce: 91846331
Website: https://uapcoalitienederland.nl
E-mail: [email protected]
2. Personal data that we process
UAPCNL processes your personal data because you use our services and/or because you provide this data to us yourself:
Donors: First and last name, email address, address details (if provided via the payment method), bank account number or credit card details (anonymized via Stripe/PayPal) and payment history.
UAP Witnesses: Name, email address, location and time details of the sighting, and the content of your testimony (including any attachments such as photos or videos).
Website visitors: IP address, browser data and browsing behavior (via functional/security cookies from Cloudflare).
Contact form: Name, email address and the content of your message.
3. Specific safeguards for UAP testimonies
We understand that an observation or testimony is a confidential matter. To safeguard your privacy and safety, we apply the following policy regarding witness data:
No substantive access by third parties: External technical service providers (such as hosting parties or security services) act solely as automated transmission and storage channels. They have neither permission nor substantive access to view or use your testimonial or personal data.
Strict access: Only expressly authorized employees and researchers of UAPCNL have access to the testimonies submitted by you.
Anonymization in research & publication: Your testimony is never made public with your identity or directly identifiable contact details, unless you have given explicit written consent for this in advance. For research purposes, personal data is separated from the observation data (pseudonymized/anonymized).
4. Purposes and legal bases of the processing
We process your data based on the following legal bases of the GDPR:
Execution of an agreement: To process your donation and communicate about it.
Legal obligation: As an ANBI foundation, we are legally required to retain financial data for 7 years for the Tax and Customs Administration.
Consent: For registering and processing UAP testimonials and answering questions via the contact form. You can withdraw your consent at any time.
Legitimate interest: For technical security, protection against attacks (DDoS), and the optimization of our website.
5. Sharing personal data with third parties (Processors)
UAPCNL sells or rents out your data never to third parties.
We use external service providers who act exclusively as processors on behalf of UAPCNL and are strictly bound by processor agreements:
TransIP: Our Dutch hosting provider for the storage and operation of the website.
Google Workspace (Non-Profit): For our internal email correspondence and encrypted, secure document storage with strictly restricted access rights.
Stripe & PayPal: For the secure processing of payments and donations. Stripe and PayPal act as data controllers for the payment transaction.
Cloudflare: For the security of the website (such as blocking malicious traffic) and ensuring speed. Cloudflare only processes technical network data (such as IP addresses) and does not use it for other purposes.
International transmission
Because we use Google, Stripe, PayPal, and Cloudflare, (technical) data may be processed on servers outside the European Economic Area (EEA), primarily in the United States. These parties are certified under the EU-US Data Privacy Framework (DPF), which ensures an appropriate and GDPR-compliant level of protection.
6. How long we retain personal data
We do not retain your data longer than strictly necessary for the purposes for which it was collected:
Donation details: 7 years (tax retention obligation).
Witness statements: The substantive observation is retained in our archive for long-term scientific/societal research. Identifying personal data (such as name and email) can be removed or anonymized at any time upon your request.
Contact form / Email: Maximum of 2 years after the last contact, unless a longer retention period is necessary for further processing.
7. Cookies and similar technologies
We use the GDPR Cookie Compliance plugin to manage your cookie preferences:
Necessary & Security cookies: For the technical operation and security of the site (Cloudflare) and fraud prevention for payments (Stripe/PayPal). These are enabled by default.
Analytical cookies: These will only be placed after you have explicitly given permission for this via our cookie banner. You can adjust your preferences at any time via the cookie settings on the website.
8. Embedded content from other websites
Pages on this site may contain embedded content (for example, videos from YouTube). Embedded content from other websites behaves exactly as if you were visiting the other website. These external websites may collect data about you, use cookies, or embed additional third-party tracking.
9. Automated decision-making
UAPCNL makes no use of automated decision-making or profiling that may have legal consequences for individuals.
10. Your rights as a data subject
Under the GDPR, you have the following rights regarding your personal data:
Right to access, correction and deletion.
Right to withdraw your consent (e.g. for processing your testimony).
Right to restriction of processing (temporarily suspending processing).
Right of objection against processing based on our legitimate interest.
Right to data portability.
You can submit a request via our contact form or by sending an email to [email protected]. To verify your identity, we may request additional information. We will respond to your request within 30 days.
You also always have the right to lodge a complaint with the national supervisory authority: the Dutch Data Protection Authority
11. Security of personal data
UAPCNL takes the protection of your data seriously and takes appropriate technical and organizational measures to prevent misuse, loss, unauthorized access, unwanted disclosure, and unauthorized modification.
Our systems and connections are actively secured and encrypted, and access to personal data is strictly limited to authorized persons. If you believe that your data is not properly secured or if there are indications of misuse, please contact us immediately.