Who we are
This notice explains how FUTURE YOUTH GLOBAL NETWORK EVENT - FZCO ("FYGN", "we") collects, uses and protects personal data across our website, the application and registration funnel, your account area, invitation letters and our online community. FYGN is the data controller.
- Entity: FUTURE YOUTH GLOBAL NETWORK EVENT - FZCO (Licence 75038)
- Address: IFZA Business Park, DDP Premises No. 75038-001, Dubai Silicon Oasis, Dubai, UAE
- Privacy contact: privacy@fygn.org (postal address above)
We process personal data in compliance with the UAE Federal Decree-Law No. 45 of 2021 (PDPL) and, where they apply to you, the EU GDPR and UK GDPR.
What we collect
Your account. Your email address and sign-in records. Signing in works by emailed magic link; there is no password to store.
Your application. Full name, email, WhatsApp number, date of birth, country of residence, nationality, city and departure airport, gender if you choose to give it (including "prefer not to say"), the summit roles you volunteer for, your motivation, and on the scholarship track your scholarship answer. Depending on your track you may also upload a CV, a personal photograph (used for your badge and the delegate book), and a motivation video of up to 90 seconds. The video shows your face and voice; we use it only to assess your application, and it is stored in private storage.
Identity documents. Where a track or an invitation letter needs them: passport details (name as printed, number, nationality, expiry, date of birth) or national-ID details, and a scan of the document. Who is asked depends on the track: the Visa Invitation Letter track always collects them; on the delegate tracks, applicants under 18 upload an ID scan; adult delegates on the Event Access Pass provide passport details only if they later request a letter. Section 6 explains the sealed storage these fields get.
For applicants under 18. A parent or guardian's email address, the consent record (timestamp and the confirming address, captured from the signed link itself), the guardian's own identity document, and, for audit, the immediately previous guardian address if it was changed.
Payments. Stripe payment references, amounts and status. Card details are entered on Stripe's own pages; we never receive or store your card number.
Referrals. The referral code you entered or arrived with, and which affiliate it belongs to.
The online community. Your display name, optional country, the timestamp of your 16-or-over confirmation, your messages, likes, room memberships and join requests, reports you make or that concern your messages, moderation records, and operational participation counts (messages, replies, likes, reports). Articles you publish are public under your display name. Course enrolments store your name and account email with the course so organisers can run it, and are never public.
Contact and newsletter. If you write to us through the contact form: your name, email, message, IP address and browser information (kept for abuse triage). If you opt in to the newsletter on the apply form: your email, name and the IP of the sign-up. The newsletter is opt-in only.
Why we use it, and our lawful bases
| Purpose | Lawful basis |
|---|---|
| Processing your application, taking the one charge on your track, and running your registration | Contract, and steps prior to a contract |
| Deriving whether you are under 18 from your date of birth, and obtaining and recording a parent or guardian's consent to attend | Legal obligation and the guardian's consent |
| Assessing your motivation, CV, photo and motivation video as part of selection | Contract; the video is used only because you chose to upload it |
| Issuing an invitation letter from your identity details | Contract, at your request |
| Checking, from your nationality and country of residence, whether you need an invitation letter at all | Contract and our legitimate interest in accurate guidance |
| Running the online community: rooms, moderation, safety records, the labelled AI summaries described in section 4 | Contract for the service itself; legitimate interest and legal obligation for keeping the space safe |
| Publishing an article you wrote, under your display name | Your consent, given when you publish |
| Referral attribution and paying affiliate commissions | Legitimate interest, and contract with the affiliate |
| Transactional email (submission receipt, panel decision, letter ready, guardian consent messages) | Contract |
| The newsletter | Your consent; unsubscribe any time |
| Counting page views and visits, without cookies, to see which pages are used | Legitimate interests |
| Security, abuse prevention and fraud prevention (including the IP kept with contact messages) | Legitimate interests |
The community AI assistant
Our community includes an AI assistant with two jobs: it writes summaries of room conversations, and it may post short notes into a room. Everything it writes is labelled as AI-generated, may be incomplete or inaccurate, and is never a decision about you. To do this, community message text and authors' display names are processed by our AI provider, Groq (United States); your applications, identity documents and payment data are never sent there. Summaries and the assistant's notes are stored with the room. A room can have the assistant switched off entirely, and you can mute it for yourself in your community preferences. Moderation of the community is done by people, not by the assistant.
Under 18s and children
Our minimum age is 16 everywhere: applications refuse anyone younger at submission, and the community requires a 16-or-over confirmation before you can post. We do not knowingly process the data of anyone under 16. For applicants aged 16 or 17 we derive minor status from date of birth; a minor cannot self-certify. We email the parent or guardian a secure, personal confirmation link, valid for seven days, and record their confirmation with a timestamp. That consent is consent to attend the Event in person; the Parental / Guardian Consent Notice explains the whole process, including the guardian's own identification and how consent is withdrawn. We design our services with the best interests of young users in mind.
Identity documents are sealed
Passport and national-ID details, and the uploaded document scans, get our strictest handling:
- Encrypted at rest with AES-256-GCM, with keys held outside the database. In production the system refuses to store these fields unencrypted.
- Every access is logged. Reading these fields requires a recorded reason (issuing your letter, verifying eligibility, answering your own data request), and the log records who read what, when and why.
- Access is restricted to the staff who need it to issue invitation letters and verify eligibility.
- Never by email. Your invitation letter carries your passport details, so it is delivered as a download behind your sign-in; the notification email carries a link only. These details are never stored in your browser.
- Deleted on a short clock: identity documents and scans are deleted no later than 90 days after the Event ends, unless a longer period is legally required.
Who we share it with
We use a small set of providers who process data on our instructions under data-processing agreements, and we never sell, rent or trade personal data:
| Provider | What they do | What they see |
|---|---|---|
| Supabase | Database, authentication and file storage | The data this notice describes, in our own database and buckets |
| Vercel | Website hosting | Requests to the site; short-lived logs |
| Stripe (US) | Card payments | Your payment, email and name; we receive references, never card numbers |
| Resend | Transactional email | Recipient address and message content (never passport data) |
| Umami Cloud (EU) | Website analytics | The page you opened, the site that referred you, your browser and device type, and an approximate location worked out from your IP address; no cookies, no name, no email |
| Groq (US) | Community AI assistant | Community message text and display names only; never application, identity or payment data |
We also share what is strictly necessary with hotels and venues (event logistics), with embassies and immigration authorities where a visa process requires it, and with government or security authorities where the law requires it.
International transfers
Some providers process data outside your country (for example Stripe and Groq in the United States). Our website analytics is hosted in the European Union. Where data is transferred internationally we rely on appropriate safeguards, principally Standard Contractual Clauses, as required by the GDPR and UK GDPR.
How long we keep it, and your self-serve controls
| Data | Kept |
|---|---|
| Identity documents and scans (yours and a guardian's) | Deleted no later than 90 days after the Event ends, unless law requires longer |
| Applications and participation records | Up to 24 months, then deleted or redacted; aggregate and financial columns survive for audit |
| Invitation-letter records | Up to 12 months; identity fields removed |
| Payment and affiliate records | As long as tax and accounting law requires; kept without further use |
| Contact messages | Up to 12 months |
| Community content and profile | While your account is active |
| Newsletter subscription | Until you unsubscribe |
| Website analytics | Up to 12 months, as page and visit counts; the code they are grouped by is regenerated at the start of each month |
| Hosting and security logs | Roughly 30 days |
Download your data. Signed in, at /account/privacy, you can download everything you gave us as one file, immediately: your applications and every answer, invitation-letter requests, referral commissions, messages you sent us, and newsletter subscriptions. The community offers its own export covering your profile, messages and activity.
Delete your account. On the same page you can permanently delete your account. This erases the personal data in your applications, invitation-letter requests, contact messages and newsletter subscription, removes your uploaded documents from storage, deletes the articles you published and your course enrolments, and signs you out. Your community messages are replaced with "[deleted]". What is not deleted: payment records and affiliate records, the financial trail the law requires us to keep, retained without any further use. There is no undo.
Everything else. Subject to applicable law you may access, correct, delete or restrict processing, object, port your data, or withdraw consent, by emailing privacy@fygn.org. We respond within one month. You can complain to the UAE Data Office and, if you are in the EU or UK, to your local data-protection authority.
Security and breaches
We apply technical and organisational measures appropriate to the data: the sealed identity-document handling in section 6, encrypted connections, access controls and capability-gated admin surfaces, payment-webhook integrity checks, and rate limiting. No system is perfectly secure, and you are responsible for safeguarding your own devices and email account (your sign-in link is only as safe as your inbox). If a breach is likely to put you at high risk we will notify the relevant authority and affected individuals as the law requires, within 72 hours where the GDPR applies.
No automated decisions
We make no decisions producing legal or similarly significant effects about you by solely automated means. Deriving minor status from a date of birth is a fixed rule, selection decisions are made by people, and the community assistant only writes labelled, non-binding summaries and notes.
Changes and contact
We may update this notice and will change the date above when we do. Questions and data requests: privacy@fygn.org.