Privacy & Data Protection
This page explains what personal data we collect through fus.today, why we collect it, who it is shared with, how long we keep it, and how you can exercise your rights under the GDPR.
Last updated: 31 July 2026
This notice is maintained by the FUS team and describes our actual practices. Legal entity details marked in brackets are being finalised.
Access, correction, deletion, or withdrawal of consent — we answer within 30 days.
1. Who is responsible for your data
The data controller is The Forces of the Ukrainian Spirit (FUS), [legal address — to be confirmed by the site owner].
For any privacy question or request, write to privacy@fus.today, or use the data request form linked on this page.
2. What we collect and why
- Newsletter subscription — email, and optionally name, phone, country and language. Purpose: sending you the movement's updates. Legal basis: your consent.
- Contact form — name, email, and optionally phone, country, organisation, and your message. Purpose: answering you. Legal basis: your consent and our legitimate interest in responding.
- Prayer wall — your prayer text, and optionally name, country, confession, email and phone; you may submit anonymously. Purpose: publishing approved prayers and praying together. Legal basis: your consent.
- Movement, prayer circle and Spiritual Bridge applications — name, email, and optionally phone, country, city, confession, church or organisation, role, skills, availability and motivation. Purpose: reviewing and coordinating your participation. Legal basis: your consent.
- DAR applications (Detective · Author · Researcher) — contact details, languages, occupation, experience, portfolio links, motivation and any files you upload. Purpose: assessing your application and coordinating DAR work. Legal basis: your consent.
- DAR story submissions — the story you send, supporting links and files, and your contact details unless you submit anonymously. Purpose: reviewing and, with your permission, publishing. Legal basis: your consent.
- Account sign-in (staff only) — email and profile name provided by Google when signing in to the admin area. Purpose: authenticating administrators. Legal basis: contract / legitimate interest.
- Technical data — anti-spam verification data processed by Cloudflare Turnstile and standard server logs from our hosting provider. Purpose: security and abuse prevention. Legal basis: legitimate interest.
3. Cookies and local storage
We do not use advertising or tracking cookies, and we do not run third-party analytics profiling.
We use only what is necessary for the site to work: your chosen language, your consent choice for this notice, a sign-in session for administrators, and short-lived storage set by Cloudflare Turnstile to tell humans from bots.
4. Who your data is shared with
- Mailchimp (Intuit) — email list management and mailing delivery for the addresses that consented.
- Cloudflare — Turnstile anti-spam verification.
- Our hosting and database provider — storage of the site's data and secure file uploads.
- Our email delivery provider — sending notifications and confirmations.
Some of these providers operate outside the EU/EEA. Transfers rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard offered by the provider.
We never sell personal data and never share it for advertising.
5. How long we keep it
- Newsletter subscribers — until you unsubscribe or ask for deletion.
- Contact messages — up to 24 months after the matter is handled.
- Prayer requests not approved for publication — up to 12 months, then deleted.
- Applications (movement, bridges, DAR) — while your participation is active; rejected applications up to 12 months.
- DAR story submissions — for as long as needed for the research work they support, unless you ask for removal.
- Suppressed / unsubscribed email addresses — kept indefinitely, in hashed-purpose form, solely so we never email you again.
6. How we protect it
Data is stored in a managed database with row-level access rules: public visitors can read only what is explicitly published (approved prayers, published articles, country list without coordinator contacts). Personal submissions are readable only by authorised staff.
Administrator access is restricted to approved accounts and protected by Google sign-in. Uploaded files live in private storage and are never publicly listed.
7. Your rights
- Access — get a copy of the data we hold about you.
- Rectification — correct anything inaccurate.
- Erasure — ask us to delete your data.
- Restriction and objection — ask us to stop or limit certain processing.
- Portability — receive your data in a machine-readable format.
- Withdraw consent — at any time, without affecting processing done before.
- Complain — to your national data protection authority.
Use the data request form on this page, or write to us directly. We reply within 30 days. We may ask you to confirm your identity from the same email address before acting on a deletion request.
8. Children
The site is not directed at children under 16. If you believe a child has sent us personal data, contact us and we will delete it.
9. Changes
If this notice changes materially, we will update this page and the date above.
