FSI Europe / Privacy

Privacy Notice

This notice explains how FSI Europe handles personal data when you use our website, newsletter, events and donation services, or contact us directly.

Last updated: 7 October 2026

1. Who we are

Freedom and Sovereignty Initiative Europe vzw (“FSI Europe”, “we”, “us” or “our”) is a Belgian non-profit association.

Freedom and Sovereignty Initiative Europe vzw
Wetstraat 62, 1040 Brussel
Rue de la Loi 62, 1040 Bruxelles
Belgium

Enterprise number: 1041321823
VAT number: BE1041321823

For the personal data described in this notice, FSI Europe is the data controller unless stated otherwise.

For privacy questions or to exercise your rights, contact contact@fsieurope.org.

This notice applies to personal data collected through fsieurope.org, through forms and other website features, in connection with our newsletter, events and donations, and when you contact us directly.

Website features may change over time. Where we introduce a new activity involving materially different uses of personal data, we will provide appropriate information and update this notice where necessary.

2. Personal data we collect

The information we collect depends on how you interact with FSI Europe.

Website forms and supporter interactions

Where you provide information through a website form, we may collect:

  • your first and last name;
  • your email address;
  • the choices or interests you select;
  • information showing whether you asked to subscribe to our newsletter or receive information about an event or activity;
  • relevant submission and consent timestamps;
  • the version of the relevant consent wording and Privacy Notice; and
  • administrative timestamps relating to the record.

If you begin entering information into a form but do not submit or complete the relevant process, FSI Europe does not receive a supporter submission from that form.

Newsletter

If you choose to subscribe to our newsletter, we process your name, email address and information needed to record and administer your subscription and consent.

Subscribing to the newsletter is always a separate, affirmative choice. It is not a condition of using another website feature, registering interest in an event or making a donation.

Events

Event registrations and ticket payments are handled through Eventbrite. We receive the registration information and payment-status or transaction details needed to manage attendance and administer the event. Eventbrite may process information both on our behalf for event registration and payment services and for its own purposes under its Privacy Policy.

Photographs, audio or video may be recorded at events and published in FSI Europe communications. The legal bases, permissions, objections and retention criteria are explained in section 6 below.

If you ask us to keep you informed about an event, we process your contact details and your expression of interest so that we can send you information relating to that event and administer it.

Donations

You may make a donation through Stripe Checkout, including through a donation route that does not require you to complete another FSI Europe website form.

In connection with a donation, Stripe may collect and process information required to complete and administer the payment. Depending on the payment method and information you provide, this can include your name, email address, billing or contact information and payment information.

FSI Europe receives customer and transaction information made available to us by Stripe, such as contact information and information concerning the amount, date, currency and status of a donation and associated transaction identifiers. We may use this information to administer and record the donation and to acknowledge it directly.

FSI Europe does not store full payment-card numbers or bank-account credentials in the website database.

Website operation and security

When you visit the website, technical information may be processed in order to deliver and protect it. This can include your IP address, browser and device information, request and connection information, timestamps, and technical or security events.

Cloudflare services are used for website hosting, database services, delivery and security. To protect website forms from automated submissions, we use Cloudflare Turnstile. Cloudflare may process security signals such as your IP address, User-Agent, browser and TLS-related information. We do not send your name, email address or other form contents to Turnstile, and do not use it for advertising or analytics.

Phase 1 first-party website analytics

The site records limited first-party measurement from successful HTML document requests. A per-request HTML document-load row and outbound-click record are kept for 90 days. Raw referring hostnames and safe paths, where supplied, are also kept only within that 90-day window. If consented enhanced mode is enabled in future, enhanced session and event detail would be kept for 90 days; enhanced mode is currently disabled in production. Privacy-safe one-dimensional daily aggregates remain available indefinitely and do not reconstruct users or sessions. They cover canonical public pages, acquisition source, registered UTM campaigns, referring domains, country and coarse device, browser and operating-system categories. Raw records cover the current Europe/Brussels reporting day and the previous 89 days. Recent reports use those records directly. A sanitised campaign slug is shown by name only after registration; otherwise it is grouped as other. Campaign and referring-domain daily totals are finalised once before their raw reporting day is deleted. Campaigns registered before finalisation are preserved by name. Referring domains with at least five requests on that day are preserved by name, limited to the top 250 by request count, with alphabetical ordering for ties; remaining domains are grouped as other. Later registration or popularity changes do not rewrite finalised history. Known crawler traffic is excluded where it can be identified safely. Server collection covers HTML document loads only: client-side route transitions and framework RSC navigations are not included.

The separate analytics database does not contain names, email addresses, supporter or donor information, Stripe or customer information, full or hashed IP addresses, full User-Agent strings, request bodies or Cloudflare Access identities. Analytics records are not joined to supporter, donation, event-registration or newsletter identities, and are not used to infer an individual’s political opinion.

Communications and privacy requests

If you contact us directly, we process the contact details and information contained in your communication, together with any information reasonably required to respond to you or deal with your request.

Direct outreach to selected professional contacts

In limited circumstances, we may use a person’s name, professional contact details and publicly available information about their professional role to send a one-off or limited number of communications about a specific FSI Europe event, publication or news item that is objectively relevant to that role. This is separate from our newsletter and does not subscribe the recipient.

3. Why we use your personal data

We process personal data only where we have an appropriate legal basis.

Acknowledging that you have read this notice confirms it was made available to you; it is not, by itself, consent to the processing described here. We identify the legal basis for each purpose below and ask for separate consent where we rely on consent.

Newsletter communications

If you choose to receive FSI Europe news, research, event updates or similar communications, we process your details on the basis of your consent.

The newsletter choice is separate from this Privacy Notice and from any other choice you make on the website. Reading or submitting a form containing this Privacy Notice does not by itself subscribe you to the newsletter. Our newsletter sign-up uses an affirmative opt-in and is not preselected. You can withdraw your consent at any time, free of charge.

Event communications

We process registration details to take steps you request when registering and to administer attendance and the event. We use information needed for payment records to meet applicable legal obligations. A request for information about a particular event is limited to that event and does not subscribe you to our newsletter. General news and event marketing require a separate, optional newsletter subscription.

Direct outreach to selected professional contacts

Where we rely on legitimate interests for this limited direct outreach, we assess and document the necessity and proportionality of the outreach. Each message identifies FSI Europe, explains the relevant source and purpose, and provides a free and simple way to object to further direct outreach. On objection, we stop marketing use and keep only a minimal suppression record where needed to prevent re-contact. Where prior consent is legally required, we obtain it first.

Donations

We process information necessary to receive, administer and acknowledge a donation and to deal with matters arising from it. Depending on the processing involved, our legal bases include taking steps at your request and administering the donation, compliance with legal obligations applying to FSI Europe, and our legitimate interests in properly administering our donor relationships and records.

Website operation and security

We process technical and security information where necessary for our legitimate interests in operating, maintaining and protecting the website and its systems.

First-party website analytics

We use the first-party measurements described above to understand page use, acquisition sources and broad technical trends and to improve the website. This server-side measurement does not require a non-essential analytics cookie or browser identifier.

Legal obligations and rights requests

We process information where necessary to comply with legal obligations, including data-protection, accounting and other applicable legal requirements. We may also process information where necessary for our legitimate interests in establishing, exercising or defending legal rights.

4. Political opinions and other sensitive information

The GDPR gives additional protection to certain types of personal data, including information revealing political opinions or philosophical beliefs.

FSI Europe is a non-profit think tank with particular political and philosophical aims. A person’s relationship with an organisation of this nature may, depending on the circumstances, permit inferences to be drawn about political or philosophical opinions.

We do not ask supporters to state their political opinions through the website, and we do not use supporter information to classify or profile individuals according to political opinion. Subscribing to our newsletter, attending an event or making a donation should not be understood as a declaration that you agree with any particular political position.

Where information processed in connection with our legitimate non-profit activities nevertheless constitutes special-category personal data under Article 9 GDPR, and the processing concerns members, former members or people in regular contact with FSI Europe in connection with its purposes, we rely where applicable on Article 9(2)(d) GDPR and apply appropriate safeguards.

We do not use this provision as a basis for unrelated processing or for political profiling.

5. Newsletter and unsubscribing

If you positively choose to subscribe to the FSI Europe newsletter, your contact details may be transferred to an external newsletter provider that stores subscriber information, sends FSI Europe communications and operates unsubscribe functionality on our behalf.

The provider is authorised to use those details for providing the newsletter service to FSI Europe. We do not authorise it to use our subscribers’ addresses for its own marketing, audience matching or unrelated purposes. FSI Europe does not sell subscribers’ addresses.

Every newsletter will provide an easy way to unsubscribe. You may also withdraw your consent by contacting contact@fsieurope.org. Withdrawal is free of charge and does not affect the lawfulness of processing carried out before consent was withdrawn.

The newsletter provider maintains unsubscribe or suppression information so that an address which has unsubscribed is not inadvertently subscribed again through a later import or update.

6. Events

When you register or buy a ticket through Eventbrite, it collects registration and, where relevant, payment information and shares with FSI Europe the details needed to administer the event. Eventbrite may also process personal data as a controller for its own purposes. Its Privacy Policy explains that processing.

Event-registration details are used to manage the registration, attendance and related event administration. An optional newsletter subscription is separate: registering for or attending an event does not sign you up for FSI Europe news or general event marketing. If you choose that option, you can withdraw your consent at any time as explained above.

Photographs, audio or video may be taken at FSI Europe events and published in FSI Europe communications, including our website and social-media channels. A required acknowledgement that recording may take place is a notice, not consent. We may use wide contextual images for event reporting under legitimate interests only where a case-specific balance supports that use; that basis alone does not permit processing special-category data. As our subject matter may mean that identifiable attendance reveals or invites inferences about political opinions or philosophical beliefs, we will not capture or use identifiable attendee media revealing or likely to reveal such information unless an Article 6 legal basis and an Article 9 GDPR condition both apply. For focused attendee images, interviews and recorded contributions, we will ask for separate, freely given permission to record and publish; where we rely on consent for special-category data, it will be explicit. Permission is not a condition of attending. Tell us at the event if you object, and we will take reasonable steps to avoid identifiable coverage. Any event-specific recording arrangements will be explained to attendees.

Information held solely because of an event-interest request is deleted after the relevant event has concluded and related administration is complete. Registration and transaction information is kept for as long as needed for event administration and any applicable legal or accounting obligations. Unpublished event recordings are retained only for as long as reasonably needed to select and prepare event coverage. Published media are retained only while they remain relevant to FSI Europe’s public record of the event.

7. Donations and Stripe

Donations are processed using Stripe Checkout in accordance with the Stripe Services Agreement and Stripe’s Prohibited and Restricted Businesses policy.

Stripe processes information necessary to provide payment services and may also process information for purposes for which Stripe has its own legal responsibilities, including payment security, fraud prevention and compliance with financial or regulatory requirements.

Depending on the activity concerned, Stripe may act as a service provider processing information on FSI Europe’s instructions or may process information for purposes for which Stripe determines its own legal obligations and means of processing. Stripe’s own privacy information, including its Privacy Policy, applies to processing for which Stripe is independently responsible.

FSI Europe uses information it receives in connection with a donation to administer the donation, maintain appropriate records and send acknowledgements or other communications directly connected with it. We do not use a donation to subscribe you automatically to our newsletter.

FSI Europe raises funds solely on its own behalf to support the non-profit purposes set out in its statutes. We do not collect donations on behalf of third parties or forward donations to other organisations or countries.

We currently accept donations only from donors located in the following countries:

Austria; Belgium; Bulgaria; Croatia; Cyprus; Czech Republic; Denmark; Estonia; Finland; France; Germany; Greece; Hungary; Iceland; Ireland; Italy; Latvia; Liechtenstein; Lithuania; Luxembourg; Malta; Netherlands; Norway; Poland; Portugal; Romania; Slovakia; Slovenia; Spain; Sweden; Switzerland; United Kingdom; United States; Canada; Australia; New Zealand.

We will not accept transactions involving jurisdictions or persons prohibited under Stripe’s policies, including sanctioned persons and jurisdictions. Stripe may decline or restrict a transaction where required by its policies or applicable law.

8. Service providers and access to information

Personal data may be accessed where necessary by authorised people involved in operating FSI Europe, including relevant employees, directors, contractors and people responsible for website administration, communications, events or fundraising.

We also use external services where necessary to operate the website and the activities described in this notice. These currently include:

  • Cloudflare, for website hosting, database, delivery and security services;
  • Eventbrite, for event registration, ticketing and payment services;
  • an external newsletter provider, for subscriber storage, newsletter delivery and unsubscribe management; and
  • Stripe, for donation and payment processing.

These services receive only the information relevant to the functions for which they are used. Where a service provider processes personal data on our instructions, it is required to process the data for the relevant service and not for unrelated purposes.

We may also disclose personal data where required by law, a competent authority or court, or where reasonably necessary for the establishment, exercise or defence of legal claims. We do not sell personal data.

9. International processing

FSI Europe’s production Cloudflare D1 database is configured with an EU jurisdiction so that the database itself runs and stores its data within the European Union. This does not mean that every technical processing activity carried out by Cloudflare or another service provider necessarily occurs only in the European Economic Area (“EEA”).

Cloudflare, Eventbrite, Stripe and other service providers may operate internationally. An external newsletter provider may also process information in more than one country.

Where personal data subject to the GDPR are transferred outside the EEA in circumstances requiring an international-transfer mechanism, we require the transfer to be covered by a lawful mechanism applicable to the destination and provider. Depending on the circumstances, this may include a European Commission adequacy decision or appropriate contractual safeguards such as the European Commission’s Standard Contractual Clauses.

You may contact contact@fsieurope.org if you would like further information about safeguards applicable to a particular processing activity.

10. Browser storage, cookies and external services

Phase 1 server analytics does not set an analytics cookie, use analytics local storage or session storage, generate a persistent visitor or session identifier, fingerprint users, or send analytics to a third-party analytics provider. It is collected from normal server requests and does not run client-side behavioural analytics. The enhanced analytics mode remains disabled in production.

During certain website flows, such as proceeding from a supporter form to Stripe Checkout, information entered into the website may be held temporarily in first-party browser session storage so that the process can continue correctly. Such session storage is temporary and is not used for cross-site advertising or profiling.

If enhanced mode is enabled later, it will require an explicit choice in the analytics consent controls. The optional first-party measurement may then record client-side route transitions, active time, bounded scroll depth, outbound clicks and selected success events, using a temporary session identifier. It will not start before consent, and withdrawing consent stops future enhanced events and removes the browser session state used for them.

Strictly necessary cookies or similar technologies may be used where required for core website functionality, security or to remember a choice made by the user.

The website may contain ordinary links to external websites and services, including X, Instagram, YouTube and external publications. FSI Europe does not currently load their tracking scripts merely because such links appear on our website. Once you leave our website, the relevant external service processes information under its own privacy terms.

11. How long we keep personal data

We keep personal data only for as long as it is reasonably needed for the purpose for which it was collected, subject to any longer period required by law.

As a general rule, ordinary supporter and website-form records are deleted within one year of the last relevant interaction unless you remain involved in an active FSI Europe activity or relationship.

  • Event-interest information held solely for a particular event is deleted after related administration is complete. Event-registration and transaction information is kept for as long as needed for event administration and any applicable legal or accounting obligations. Unpublished event recordings are retained only for as long as reasonably needed to select and prepare event coverage. Published media are retained only while they remain relevant to FSI Europe’s public record of the event.
  • Newsletter subscription information is retained while you remain subscribed.
  • Information used only for direct outreach is kept only for as long as reasonably needed for the relevant event, publication or news item and to respect any objection.
  • Information needed to record consent or respect an unsubscribe may be retained for as long as reasonably necessary for those purposes.
  • Per-request HTML document-load rows, outbound-click records, enhanced session and event rows if enabled, and temporary UTM dimension state cover the current Europe/Brussels reporting day and the previous 89 days, and are removed by scheduled clean-up. Enhanced mode is currently disabled in production. Privacy-safe one-dimensional daily analytics aggregates and named referrer history are retained indefinitely; they do not reconstruct users or sessions. Weekly report status is retained as an operational record.
  • Donation and accounting information may be retained for longer where required by accounting, tax or other legal obligations.
  • Information may be retained for longer where reasonably necessary to establish, exercise or defend legal claims.

When information is deleted from a live system, copies may remain in backups for up to one further year under the applicable backup deletion cycle.

12. Your rights

Subject to the conditions and exceptions in applicable data-protection law, you may have the right to:

  • ask whether we process personal data about you and obtain access to it;
  • have inaccurate information corrected or incomplete information completed;
  • ask for personal data to be erased;
  • ask us to restrict processing;
  • receive personal data you provided in a structured, commonly used and machine-readable format where data portability applies;
  • object to processing based on legitimate interests;
  • object at any time to processing of your personal data for direct-marketing purposes; and
  • withdraw consent at any time where we rely on consent.

Withdrawal of consent does not affect processing lawfully carried out before the withdrawal.

To exercise any of these rights, contact contact@fsieurope.org. We may request information reasonably necessary to identify the relevant records and verify that a request is being made by the correct person.

You also have the right to lodge a complaint with a competent supervisory authority. FSI Europe’s supervisory authority in Belgium is the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données).

13. Children

Where we rely on consent and applicable law requires the consent or authorisation of a parent or legal representative because of a person’s age, the relevant processing may take place only where those requirements have been met.

14. Automated decision-making

FSI Europe does not use the personal data described in this notice for automated decision-making producing legal or similarly significant effects, or to profile individuals according to their political opinions.

15. Changes to this notice

We may update this notice where our activities, website functionality, service providers or legal obligations change. A change to this Privacy Notice does not by itself create or extend a person’s consent. Where a new or changed activity requires consent, we will obtain the necessary consent separately. The date at the top of this notice identifies the current version.

16. Contact

For questions about this notice, the way FSI Europe processes personal data, or to exercise a data-protection right, contact:

Freedom and Sovereignty Initiative Europe vzw
Wetstraat 62, 1040 Brussel
Rue de la Loi 62, 1040 Bruxelles
Belgium

Enterprise number: 1041321823
VAT number: BE1041321823

contact@fsieurope.org

Terms and conditions · Back to FSI Europe ↑