These Terms of Service govern access to and use of onenakfa. Please read them carefully before creating an account, subscribing to a paid plan, administering an organization, purchasing an event ticket, or otherwise using the Service.
1Service provider#
The onenakfa service is operated by:
Mustafa NOORHUSSINOperating under the brand onenakfaChemin des Lentillières 13c1023 CrissierSwitzerlandEmail: hello@onenakfa.com
In these Terms, “onenakfa,” “we,” “us,” “our,” and “Service Provider” refer to Mustafa NOORHUSSIN as the individual operating the Service under the onenakfa brand.
onenakfa is a product and trading brand. It is not currently a separately incorporated legal entity.
2The Service#
onenakfa is a software-as-a-service platform designed to help community associations, diaspora organizations, cultural organizations, religious organizations, student groups, federations, clubs, mutual-aid groups, and similar organizations manage activities such as:
- Member and household records
- Branches and organizational roles
- Membership dues
- Cash, card, and bank-transfer payment records
- Receipts
- Events and event tickets
- Attendance and QR-code check-in
- Email and other communications
- Reports and exports
- Committee elections and voting
- Arabic, Tigrinya, and English interfaces
The features available to a Customer may depend on its plan, location, payment-provider availability, technical configuration, and applicable law.
We may improve, modify, add, remove, replace, or discontinue features as described in these Terms.
3Definitions#
For these Terms:
“Customer”means the association, organization, federation, group, or other body that creates or operates an organization account on onenakfa. Where an organization cannot legally contract in its own name, “Customer” also includes the individual or individuals accepting these Terms and operating the account on its behalf, to the extent necessary to enforce payment and compliance obligations.
“Authorized Representative” means a person who accepts these Terms or purchases a subscription on behalf of a Customer.
“Authorized User” means an administrator, treasurer, member, volunteer, organizer, or other person whom a Customer permits to access its organization account.
“Member” means a person recorded as a member or household member of a Customer.
“Guest” means a person who uses a public event page, registers for an event, claims or purchases a ticket, or otherwise uses a public feature without being an Authorized User.
“Customer Data” means information submitted to, stored in, or generated through the Service on behalf of a Customer, including member records, payments, receipts, events, tickets, attendance, messages, roles, and election records.
“Service” means the onenakfa websites, applications, documentation, interfaces, infrastructure, and related services available through onenakfa.com, app.onenakfa.com, and any successor address.
“Subscription” means a paid plan purchased by a Customer for access to the Service.
4Accepting these Terms#
By creating an account, accepting an invitation, purchasing a Subscription, or using the Service, you agree to these Terms.
If you accept these Terms for a Customer, you represent and warrant that:
- You have authority to act for and bind the Customer.
- The Customer has authorized you to create or operate its account.
- The information you submit is accurate.
- The Customer agrees to comply with these Terms.
If you do not have that authority, you must not create an organization account, purchase a Subscription, or accept these Terms on the organization’s behalf.
Paid Subscriptions are intended for organizations acting for purposes connected with their organizational, professional, charitable, cultural, religious, or community activities. They are not intended to be purchased by individuals for private consumer use.
Members and Guests may use the limited features made available to them. Sections that logically apply to end users — including acceptable use, account security, intellectual property, disclaimers, and applicable law — also apply to Members and Guests.
5Eligibility and accounts#
You must be legally capable of entering into a binding agreement to create an administrator or treasurer account.
You must provide complete and accurate account information and keep it updated.
You are responsible for:
- Keeping passwords and authentication credentials confidential
- Using unique and secure passwords
- Protecting administrator and treasurer accounts
- Restricting access to authorized people
- Promptly removing access when a person leaves the organization or changes roles
- Reviewing roles and permissions regularly
- Notifying us promptly if an account may have been compromised
Accounts are personal to the individual user. Users must not share administrator or treasurer credentials.
We will never ask you to disclose your password to support staff.
A single individual account may be associated with more than one Customer. Roles and permissions are assigned independently for each Customer.
We may require identity, authority, security, or payment verification before allowing access to sensitive functions.
6Minors and household records#
The Service is not directed at children who independently administer organizations.
A Customer may record a minor as a Member or household member only when the Customer has a valid legal basis and has obtained any parental or guardian authorization required by applicable law.
The Customer is responsible for:
- Determining whether information about minors may lawfully be collected
- Providing legally required notices
- Obtaining legally required consent
- Limiting the collected information to what is necessary
- Responding to requests concerning a minor's data
A minor must not be given an administrator or treasurer role unless permitted by applicable law and approved by the Customer.
7Customer responsibilities#
The Customer controls and is responsible for the administration of its organization account.
The Customer is responsible for:
- The accuracy and lawfulness of Customer Data
- Determining who qualifies as a Member
- Assigning and removing user roles
- Setting membership dues and membership rules
- Recording cash and bank-transfer payments accurately
- Setting ticket prices and event conditions
- Issuing refunds where required
- Managing its Stripe account
- Complying with its statutes, bylaws, internal rules, and resolutions
- Complying with accounting, tax, consumer, fundraising, election, employment, sanctions, and data-protection laws
- Giving Members and Guests appropriate privacy information
- Ensuring that messages are sent only to lawful recipients
- Exporting and retaining records the Customer is legally required to keep
The Customer must ensure that its Authorized Users comply with these Terms. The Customer is responsible for actions performed through its organization account except to the extent directly caused by our breach of these Terms.
8Administrative software only#
onenakfa provides administrative software and technical infrastructure.
We are not:
- The Customer or a member of the Customer
- An officer, director, committee member, treasurer, accountant, auditor, lawyer, election officer, fiduciary, or agent of the Customer
- The organizer or promoter of the Customer's events
- The seller of the Customer's tickets
- A bank or financial adviser
- A tax, accounting, legal, or regulatory adviser
- A guarantor that a Customer is legally constituted
- A guarantor that a payment recorded as cash or bank transfer was actually received
- A guarantor that an election complies with the Customer's statutes or applicable law
The Customer must obtain professional advice when it needs legal, accounting, tax, financial, regulatory, election, or data-protection guidance.
Reports, receipts, exports, financial summaries, and election results generated through the Service are administrative records based on information submitted to the Service. They are not independently audited or certified by onenakfa.
9Subscriptions and billing#
9.1Plans#
Available plans, member limits, prices, billing periods, and included features are displayed on the pricing page or during checkout.
The Subscription purchased by the Customer will be confirmed at checkout or in an order confirmation.
9.2Automatic renewal#
Unless stated otherwise during checkout, paid Subscriptions:
- Run monthly
- Are billed in advance
- Renew automatically at the end of each billing period
- Continue until cancelled
By purchasing a Subscription, the Customer authorizes us and our payment processor to charge the selected payment method for recurring Subscription fees, applicable taxes, and other amounts expressly agreed to during checkout.
9.3Prices and taxes#
Prices are charged in the currency displayed during checkout.
Unless expressly stated otherwise, displayed prices exclude taxes that we are legally required to collect. Any applicable VAT or similar tax may be added to the amount charged.
The Customer is responsible for taxes, duties, and governmental charges connected with its own activities, membership dues, ticket sales, and other funds it collects.
9.4Trials and free access#
We may offer free trials, free plans, promotional periods, discounts, or account credits.
We may change or withdraw such offers at any time, provided that this does not remove a paid period already purchased by the Customer.
Unless otherwise stated during registration:
- No payment card is required to begin a free trial
- A free trial does not automatically become paid unless the Customer actively selects a paid plan and provides a payment method
- Trial features or limits may differ from paid plans
9.5Failed payments#
If a Subscription payment fails, we may:
- Retry the payment
- Notify organization administrators
- Provide a reasonable grace period
- Restrict features
- Suspend the organization account
- Cancel the Subscription
Suspension for non-payment does not remove the Customer’s obligation to pay amounts already due.
9.6Upgrades and downgrades#
An upgrade may take effect immediately and may result in a prorated charge.
A downgrade normally takes effect at the next renewal date unless stated otherwise.
A Customer may not downgrade to a plan whose member limit is lower than its current number of counted Members. The Customer must first reduce its counted Members or select a plan that supports them.
9.7Cancellation#
A Customer may cancel its Subscription from the billing page or by contacting us.
Cancellation takes effect at the end of the current paid billing period unless otherwise stated.
The Customer will retain paid access until that period ends.
9.8Refunds#
Except where required by applicable law or expressly stated by us:
- Subscription fees are non-refundable
- We do not provide refunds for partial billing periods
- We do not refund unused features, inactive accounts, or unused member capacity
This does not affect any mandatory legal right that cannot be excluded.
9.9Price changes#
We may change Subscription prices by providing at least 30 days’ notice by email or in-app notification.
A price increase will apply no earlier than the Customer’s next renewal following the notice period.
The Customer may cancel before the new price takes effect. Continued use of a paid Subscription after the new price takes effect constitutes acceptance of the changed price.
10Member dues, event tickets, and Stripe#
10.1Customer collections#
Membership dues, donations, event-ticket proceeds, and other payments collected for a Customer belong to and are the responsibility of that Customer.
Except for Subscription fees and other fees expressly payable to us, onenakfa does not claim a percentage of the amounts a Customer collects through the Service.
10.2Stripe#
Card and supported online payments are processed through Stripe.
The Customer may be required to create, connect, verify, and maintain its own Stripe account.
Payment processing is subject to Stripe’s terms, privacy notice, verification requirements, fees, geographic availability, reserves, dispute procedures, and restrictions.
Depending on the Customer’s Stripe configuration, member dues and ticket proceeds are processed for the Customer and paid to the Customer’s configured Stripe account.
Except for amounts payable to onenakfa, we do not intend to receive or hold the Customer’s membership-dues or event-ticket funds.
We do not guarantee that Stripe will:
- Approve a Customer account
- Support a particular country, currency, or payment method
- Process a transaction
- Release funds within a particular period
- Reverse a chargeback
- Continue providing services to a Customer
10.3Merchant and event-organizer responsibility#
The Customer, not onenakfa, is responsible for the goods, services, membership, or event connected with a payment.
For event tickets, the Customer is the event organizer and ticket seller.
The Customer is responsible for:
- Event descriptions
- Event legality and safety
- Prices
- Admission rules
- Cancellations and postponements
- Refund policies
- Refunds
- Taxes
- Chargebacks and payment disputes
- Customer-service questions from ticket buyers
- Compliance with local event and consumer laws
A Guest’s contract concerning an event, ticket, admission, cancellation, or refund is with the Customer organizing the event, not with onenakfa.
10.4Cash and bank-transfer records#
The Service allows Customers to record payments received outside the Service, including cash and bank transfers.
onenakfa:
- Does not receive or hold that cash
- Does not verify that the Customer received it
- Does not verify the identity of the payer
- Does not verify the accuracy of the recorded amount
- Does not reconcile the Customer's bank account
- Is not responsible for a false, duplicate, missing, or incorrectly recorded payment
The Customer is responsible for establishing internal cash-handling and reconciliation procedures.
10.5Receipts#
The Service may generate numbered receipts based on data entered by the Customer or received from payment providers.
The Customer is responsible for determining whether a generated receipt satisfies its accounting, tax, charitable, or regulatory obligations.
onenakfa does not certify a receipt as a legally compliant tax invoice, charitable-donation certificate, or audited accounting document.
11Events and public pages#
Customers may create public event pages and permit Guests to register for or purchase tickets without creating an onenakfa account.
The Customer is responsible for ensuring that public-event content is accurate and lawful.
The Customer must not publish:
- Misleading event information
- Events that are unlawful
- Content that infringes third-party rights
- Fraudulent fundraising
- Dangerous or prohibited activities
- Discriminatory admission terms that violate applicable law
onenakfa may remove or restrict an event page if we reasonably believe it violates these Terms, applicable law, payment-provider rules, or the rights or safety of others.
We are not responsible for:
- Whether an event takes place
- Changes to the date, time, location, speakers, or program
- Entry refusal by the organizer
- Physical safety at an event
- Losses caused by event cancellation
- Travel or accommodation expenses
- Goods or services provided at an event
12Elections and voting#
The Service may provide tools for committee elections, candidate management, voter eligibility, ballot submission, counting, and results.
These tools are administrative tools only.
The Customer is solely responsible for:
- Determining whether electronic voting is permitted
- Complying with its statutes, bylaws, election rules, and applicable law
- Determining voter eligibility
- Approving candidates
- Setting voting periods
- Choosing whether provisional results are visible during voting
- Addressing ties, disputes, recounts, and challenges
- Preserving legally required election records
- Communicating election rules to Members
- Confirming and adopting final results
Although we design the Service to separate ballot choices from ordinary member records where specified, no electronic system can be guaranteed to be perfectly anonymous, uninterrupted, or immune from every technical or security risk.
The Customer must not describe the Service as independently certifying an election unless a separate written certification service has been expressly agreed.
13Messaging and communications#
Customers may use the Service to send email or other communications to Members, Guests, and other recipients.
The Customer is responsible for:
- Having a lawful basis to contact each recipient
- Providing legally required information
- Honoring opt-outs and objections
- Maintaining accurate recipient lists
- Avoiding spam and deceptive messages
- Complying with anti-spam, telecommunications, marketing, and data-protection laws
- Ensuring the message content is lawful
- Avoiding misleading sender identities
The Customer must not use the Service to send purchased, scraped, harvested, or unlawfully obtained contact lists.
We do not guarantee delivery of any message. Messages may be delayed, rejected, filtered, bounced, rate-limited, or blocked by email providers, telecommunications providers, or recipients.
We may suspend messaging features to protect deliverability, infrastructure, recipients, or the reputation of the Service.
14Acceptable use#
You must not use the Service to:
- Violate any applicable law or regulation.
- Infringe another person's privacy, intellectual property, confidentiality, contractual, or other rights.
- Commit fraud, deceptive fundraising, phishing, identity theft, or payment abuse.
- Finance or facilitate terrorism, sanctions evasion, money laundering, or prohibited organizations.
- Harass, threaten, stalk, exploit, or unlawfully discriminate against another person.
- Upload malware or malicious code.
- Attempt to bypass authentication, roles, payment controls, member limits, rate limits, or security controls.
- Access or attempt to access another Customer's data.
- Probe, scan, test, or exploit vulnerabilities without prior written permission.
- Interfere with the Service or impose unreasonable technical load.
- Reverse-engineer, decompile, copy, scrape, frame, mirror, resell, sublicense, or commercially exploit the Service except where mandatory law permits it.
- Use automated systems to extract data without written authorization.
- Impersonate another person or organization.
- Manipulate elections, create false voters, cast unauthorized votes, or falsify results.
- Record payments that you know are false or misleading.
- Send spam or unlawful communications.
- Upload personal data without a valid legal basis or authority.
- Upload unnecessary sensitive personal data.
- Misrepresent onenakfa as the organizer, payment recipient, auditor, legal adviser, regulator, or certifier of the Customer.
- Use the Service in a way that risks harm to Members, Guests, other Customers, infrastructure providers, or the reputation of the Service.
We may investigate suspected violations and cooperate with lawful requests from authorities.
15Customer Data#
15.1Customer rights#
As between the parties, the Customer retains all rights it holds in Customer Data.
Nothing in these Terms transfers ownership of Customer Data to us or limits the rights of individuals under applicable data-protection law.
15.2Licence to operate the Service#
The Customer grants us a non-exclusive, worldwide, limited licence to:
- Host
- Store
- Copy
- Back up
- Transmit
- Organize
- Format
- Display
- Process
- Secure
- Export
- Delete
Customer Data only to the extent reasonably necessary to provide, maintain, secure, support, and improve the operation and reliability of the Service, comply with documented Customer instructions, or comply with applicable law.
This licence ends when Customer Data is deleted, except for temporary backup copies and records we must lawfully retain.
15.3Customer warranties#
The Customer represents and warrants that:
- It has authority and an appropriate legal basis to submit Customer Data.
- Its collection and use of Customer Data complies with applicable law.
- It has provided required privacy notices.
- It has obtained required consent where consent is necessary.
- Its instructions to us are lawful.
- It will not knowingly upload inaccurate, excessive, or unlawfully obtained data.
- It will respond to rights requests from its Members and Guests where it acts as controller.
15.4Sensitive personal data#
Membership in a religious, political, cultural, ethnic, mutual-aid, or other organization may reveal sensitive information about an individual.
The Customer must:
- Collect only information necessary for a defined purpose
- Restrict sensitive fields to authorized users
- Establish an appropriate legal basis
- Use enhanced safeguards where appropriate
- Avoid recording sensitive information in free-text fields unless necessary
- Conduct any legally required data-protection impact assessment
The Service is not intended to store medical records, government intelligence, criminal-investigation files, full payment-card details, passwords belonging to other services, or other unusually sensitive information unless we expressly agree in writing.
16Data-protection roles#
16.1When onenakfa acts as controller#
We act as controller for personal data we determine the purposes and means of processing, including:
- Account registration
- Authentication
- Subscription billing
- Service security
- Abuse prevention
- Support communications
- Our own legal and accounting records
- Service-administration records
Our processing as controller is described in the Privacy Policy.
16.2When onenakfa acts as processor#
The Customer generally acts as controller, and we act as processor, for Customer Data the Customer submits or manages concerning:
- Members
- Household members
- Event attendees
- Guests
- Payment records
- Tickets
- Attendance
- Messages
- Candidates
- Voter eligibility
- Other organization records
The data-processing terms in Section 17 apply whenever we process personal data on behalf of a Customer.
16.3Customer privacy notice#
The Customer must provide its own privacy notice to Members, Guests, and other affected individuals where required.
Our Privacy Policy does not replace the Customer’s privacy notice. A privacy notice template is available as a starting point.
17Data Processing Addendum#
This Section 17 forms a data processing agreement between the Customer as controller and the Service Provider as processor.
It applies where Swiss data-protection law, the GDPR, UK GDPR, or another applicable law requires controller-processor terms.
17.1Processing instructions#
We will process Customer personal data only:
- To provide the Service
- In accordance with these Terms
- In accordance with the Customer's documented instructions
- As required by applicable law
The Customer’s use and configuration of the Service constitutes documented instructions.
If we believe an instruction violates applicable data-protection law, we may suspend that instruction and notify the Customer unless legally prohibited.
17.2Purpose, nature, and duration#
The purpose and nature of processing are to provide membership, payment-recording, event, ticketing, communications, reporting, election, authentication, support, storage, security, and export features.
Processing continues for the duration of the Customer’s use of the Service and any limited retention period described in these Terms.
17.3Data subjects#
Data subjects may include:
- Authorized Representatives
- Administrators
- Treasurers
- Members
- Household members
- Volunteers
- Event organizers
- Guests and attendees
- Candidates
- Eligible voters
- Message recipients
- Customer contacts
17.4Categories of personal data#
Processed personal data may include:
- Names
- Member numbers
- Email addresses
- Telephone numbers
- Addresses
- Profile photographs
- Branches
- Roles
- Membership status
- Join dates
- Household relationships
- Payment amounts and methods
- Stripe transaction identifiers
- Receipt numbers
- Event registrations
- Tickets
- Attendance records
- Communication content and delivery information
- Candidate and election-participation records
- Authentication and technical-log information
- Custom fields created by the Customer
The Service does not intentionally receive full card numbers from Stripe.
17.5Confidentiality#
We will ensure that people authorized to process Customer personal data:
- Are bound by confidentiality obligations
- Receive access only where necessary
- Are informed of relevant security obligations
- Do not use Customer personal data for unauthorized purposes
17.6Security#
We will implement and maintain appropriate technical and organizational measures designed to protect Customer personal data against:
- Unauthorized access
- Unlawful processing
- Accidental loss
- Destruction
- Alteration
- Disclosure
Measures may include, where appropriate:
- TLS encryption in transit
- Encryption of server storage
- Password hashing
- Role-based access controls
- Organization-level data separation
- Logging
- Backups
- Rate limiting
- Infrastructure access restrictions
- Security updates
- Incident-response procedures
No security system is perfect, and we do not guarantee that every security incident can be prevented.
17.7Security incidents#
We will notify the Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer personal data.
Where reasonably available, the notification will include:
- The nature of the incident
- The categories of affected data
- The categories or approximate number of affected individuals
- The likely consequences
- Measures taken or proposed
- A contact point for further information
The Customer is responsible for determining whether it must notify individuals or authorities.
Our notification of an incident is not an admission of fault or liability.
17.8Subprocessors#
The Customer gives us general authorization to use subprocessors necessary to provide the Service.
Current subprocessors or third-party providers may include services for:
- Hosting
- Databases and storage
- Payment processing
- Transactional email
- Authentication
- DNS
- Network security
- Error monitoring
- Customer support
The current providers are identified in our Privacy Policy or a separate subprocessor list.
We will require subprocessors processing Customer personal data on our behalf to accept data-protection obligations appropriate to their services.
We may add or replace subprocessors. Where required by applicable law, we will provide reasonable advance notice of a material new subprocessor.
A Customer with a reasonable data-protection objection may contact us during the notice period. We will attempt to provide a reasonable solution. If no reasonable solution is available, either party may terminate the affected Service.
17.9International transfers#
Customer personal data may be processed in Switzerland, the European Economic Area, and other countries used by our providers.
Where an international transfer requires safeguards, we will use an appropriate legal mechanism, which may include:
- An adequacy decision
- The Swiss-US or EU-US Data Privacy Framework where applicable
- Standard Contractual Clauses
- Swiss adaptations to Standard Contractual Clauses
- Another legally recognized transfer mechanism
17.10Assistance with rights requests#
Taking into account the nature of the processing, we will provide reasonable assistance to the Customer with requests concerning:
- Access
- Correction
- Deletion
- Restriction
- Objection
- Data portability
If we receive a request concerning Customer Data for which the Customer is controller, we may direct the requester to the Customer.
We will not independently change Customer-controlled records without the Customer’s knowledge unless legally required.
17.11Compliance assistance#
Taking into account the nature of processing and information available to us, we will provide reasonable assistance with:
- Security obligations
- Personal-data breach assessments
- Data-protection impact assessments
- Consultations with supervisory authorities
Additional work outside ordinary Service functionality may be subject to reasonable fees.
17.12Compliance information and audits#
On reasonable request, we will provide information reasonably necessary to demonstrate compliance with this Section.
The Customer must first use available documentation and remote review procedures.
An on-site audit may occur only where legally required or where documentation is reasonably insufficient, subject to:
- Reasonable advance notice
- Confidentiality
- Minimal disruption
- Reasonable security restrictions
- Reimbursement of reasonable costs where permitted
Audits may not expose another Customer’s data or compromise Service security.
17.13Return and deletion#
During the Subscription, the Customer may export available Customer Data using the Service.
Following termination:
- Customer Data will normally remain available for export for 30 days after paid access ends.
- The Customer is responsible for completing all required exports during that period.
- After the export period, we may delete Customer Data from active systems.
- Residual backup copies may remain until overwritten through the normal backup cycle, normally no longer than 90 additional days.
- Access to retained backup data will remain restricted.
- We may retain data where required by law, court order, dispute, fraud prevention, security investigation, or legal hold.
- Data retained for legal reasons will no longer be used for ordinary product purposes.
The Customer is responsible for retaining membership, accounting, payment, event, and election records it is legally required to keep.
We may retain our own Subscription invoices, payment records, tax records, contractual records, security logs, and evidence of acceptance for as long as legally or reasonably required.
18Confidentiality#
Each party may receive confidential information from the other.
Confidential information includes non-public technical, financial, organizational, member, security, pricing, and business information.
The receiving party will:
- Use confidential information only for the agreement
- Protect it using reasonable care
- Disclose it only to people and providers who need it and are bound by confidentiality
- Not disclose it to third parties except as permitted by these Terms or required by law
Confidentiality obligations do not apply to information that:
- Is publicly available without breach
- Was already lawfully known
- Is independently developed
- Is lawfully received from another source
- Must be disclosed by law or binding authority
Where legally permitted, the receiving party will give reasonable notice before compelled disclosure.
19Third-party services#
The Service depends on third-party providers.
These may include:
- Stripe
- Hosting providers
- Database and storage providers
- Transactional email providers
- Google sign-in
- DNS and network-security providers
- Telecommunications providers
Some third-party features require the Customer or user to accept separate third-party terms.
We are not responsible for a disruption caused solely by a third-party provider outside our reasonable control.
However, nothing in this Section removes our obligations concerning processors and subprocessors under Section 17 or applicable law.
We may replace a provider, change infrastructure, or discontinue an integration when reasonably necessary for security, compliance, performance, cost, or product development.
20Intellectual property#
20.1Our rights#
The Service, including its software, source code, object code, databases, interfaces, visual design, documentation, workflows, branding, logos, text, and underlying technology, is owned by or licensed to the Service Provider.
These Terms do not transfer ownership of the Service to the Customer.
20.2Customer licence#
Subject to payment and compliance with these Terms, we grant the Customer a limited, non-exclusive, non-transferable, non-sublicensable, revocable right to access and use the Service during its Subscription for its internal organizational activities.
This right does not permit the Customer to resell, reproduce, copy, or create a competing service from onenakfa.
20.3Customer branding and content#
The Customer retains its rights in its name, logo, event descriptions, messages, photographs, and other content.
The Customer grants us a limited licence to display and process that content as needed to provide the Service.
The Customer represents that it has permission to use the content it uploads.
20.4Feedback#
If you provide suggestions, ideas, or feedback about the Service, we may use them without restriction or payment, provided that we do not publicly identify you or disclose your confidential information without permission.
21Support, maintenance, and availability#
We will use reasonable efforts to operate and support the Service.
Unless a separate written service-level agreement states otherwise:
- No guaranteed uptime applies
- Support is provided on a reasonable-efforts basis
- No guaranteed response or resolution time applies
- Maintenance may occur without advance notice in urgent cases
- Features may occasionally be unavailable
We may perform maintenance, security work, migrations, updates, or infrastructure changes.
Where practical, we will provide advance notice of significant planned disruption.
The Customer should maintain its own exports of records that are particularly important to its legal, accounting, or operational obligations.
22Suspension#
We may temporarily restrict or suspend an account, organization, public page, payment integration, event, election, or messaging feature if we reasonably believe:
- These Terms have been materially breached
- Fees are overdue
- The account creates a security risk
- The account is compromised
- The activity is unlawful or fraudulent
- Continued use could harm users, third parties, providers, or the Service
- A payment, hosting, email, or infrastructure provider requires the restriction
- A competent authority requires it
- The Customer has exceeded technical or plan limits
- Immediate action is necessary to prevent ongoing harm
Where reasonable, we will notify the Customer and provide an opportunity to correct the problem.
We may act without prior notice in urgent security, legal, fraud, abuse, or safety situations.
Suspension does not automatically terminate payment obligations for an active Subscription.
23Termination#
23.1Termination by the Customer#
The Customer may stop using the Service or cancel its Subscription at any time.
Cancellation of a paid Subscription is governed by Section 9.
23.2Termination by us#
We may terminate the agreement or an organization account if:
- The Customer materially breaches these Terms
- The Customer fails to cure a remediable breach after reasonable notice
- Subscription fees remain unpaid
- The Customer repeatedly violates acceptable-use rules
- The Customer uses the Service unlawfully or fraudulently
- Continued service creates unacceptable security or legal risk
- The Customer becomes insolvent or ceases operating
- We are required to terminate by law or a provider
- We permanently discontinue the Service
Where reasonable, we will provide advance notice and an opportunity to export Customer Data.
23.3Effect of termination#
When the agreement ends:
- The Customer's right to use the Service ends
- Authorized Users may lose access
- Public pages may be disabled
- Messaging and payment functions may stop
- Outstanding fees remain due
- Data will be handled under Section 17.13
23.4Survival#
Sections that by their nature should continue after termination will survive, including provisions concerning:
- Outstanding payments
- Intellectual property
- Confidentiality
- Data retention
- Disclaimers
- Liability
- Indemnification
- Governing law
- Dispute resolution
- General contractual provisions
24Service changes#
We may modify the Service to:
- Improve functionality
- Add or remove features
- Address security issues
- Comply with law
- Replace providers
- Improve performance
- Prevent abuse
- Reflect product development
We will not intentionally remove the essential value of a paid Subscription during a paid billing period without providing a reasonable alternative, credit, cancellation right, or other appropriate remedy.
We may discontinue the Service by providing reasonable advance notice where practicable.
25Disclaimers#
To the fullest extent permitted by law, the Service is provided “as is” and “as available.”
We do not warrant that:
- The Service will always be available
- The Service will be uninterrupted or error-free
- Every defect will be corrected
- Every message will be delivered
- Every payment will succeed
- Every record will be accurate
- Every event or election will proceed as planned
- The Service will satisfy every legal, accounting, tax, regulatory, or organizational requirement
- The Service will be compatible with every device, provider, country, or integration
- The Service will be immune from every security incident
The Customer is responsible for reviewing important records, maintaining internal controls, and exporting information it must retain.
Nothing in these Terms excludes warranties or rights that cannot legally be excluded.
26Limitation of liability#
To the fullest extent permitted by law:
- We are not liable for indirect, incidental, special, exemplary, punitive, or consequential damages.
- We are not liable for lost profits, lost revenue, lost opportunity, reputational loss, lost donations, lost membership fees, lost ticket sales, or loss of anticipated savings.
- We are not liable for actions or omissions of a Customer, Member, Guest, event organizer, Stripe, or another third party outside our reasonable control.
- We are not liable for inaccurate Customer Data, cash records, bank-transfer records, membership decisions, election decisions, event cancellations, or refund decisions made by the Customer.
- We are not liable for data loss caused by the Customer, its users, unauthorized credential sharing, or third-party integrations.
Our total aggregate liability arising from or relating to the Service, these Terms, or a Subscription will not exceed the greater of:
- The Subscription fees paid by the affected Customer to us during the 12 months immediately before the event giving rise to the claim; or
- CHF 100.
This cap applies in aggregate to all claims, regardless of the legal basis of the claim.
Nothing in these Terms excludes or limits liability to the extent it cannot lawfully be excluded or limited, including liability for intentional misconduct or gross negligence.
27Indemnification#
To the extent permitted by law, the Customer will defend, indemnify, and hold the Service Provider harmless against third-party claims, damages, penalties, costs, and reasonable legal fees arising from:
- Customer Data
- The Customer's events
- The Customer's membership rules
- Membership dues, donations, or ticket sales
- Refunds, taxes, chargebacks, or payment disputes
- Messages sent by the Customer
- The Customer's election administration
- The Customer's infringement of third-party rights
- The Customer's unlawful processing of personal data
- The Customer's breach of Stripe or third-party terms
- The Customer's breach of these Terms
- Fraudulent, unlawful, or misleading activity by the Customer or its Authorized Users
This obligation does not apply to the extent a claim is caused by our intentional misconduct, gross negligence, or infringement committed independently of Customer Data or Customer instructions.
We will:
- Notify the Customer reasonably promptly of a covered claim
- Allow the Customer reasonable control of the defence
- Provide reasonable cooperation at the Customer's expense
The Customer may not settle a claim in a way that admits fault by us, imposes obligations on us, or affects our rights without our written consent.
28Force majeure#
Neither party is liable for delay or failure caused by circumstances outside its reasonable control, including:
- Natural disasters
- War
- Civil unrest
- Government action
- Internet or telecommunications failure
- Power failure
- Cyberattacks
- Provider outages
- Labour disputes
- Epidemics
- Fire
- Flood
- Changes in law
- Payment-network disruption
This Section does not excuse payment obligations for Service already provided.
29Changes to these Terms#
We may update these Terms.
For a material change, we will normally give organization administrators at least 30 days’ notice by email or in-app notification.
A shorter notice period may apply where a change is required urgently for:
- Law or regulation
- Security
- Fraud prevention
- Abuse prevention
- Third-party provider requirements
If a change materially and adversely affects a paid Customer, the Customer may cancel before the change takes effect.
Continued use after the effective date constitutes acceptance of the revised Terms.
We may retain previous versions and evidence showing which version a Customer accepted.
30Privacy Policy#
Our Privacy Policy explains how we process personal data when acting as controller and provides transparency concerning providers, transfers, cookies, retention, security, and individual rights.
The Privacy Policy is incorporated into these Terms for transparency, but it does not replace the controller-processor obligations in Section 17.
If there is a conflict concerning processing performed on the Customer’s behalf, Section 17 takes priority.
31Governing law and disputes#
These Terms are governed by the substantive laws of Switzerland, excluding conflict-of-law principles and the United Nations Convention on Contracts for the International Sale of Goods.
Before beginning formal proceedings, the parties will attempt in good faith to resolve the dispute by contacting hello@onenakfa.com.
Unless urgent relief is required, each party should allow at least 30 days for an amicable resolution.
Subject to mandatory legal jurisdictions, the courts having jurisdiction at the Service Provider’s domicile in the Canton of Vaud, Switzerland, will have exclusive jurisdiction.
Nothing in this Section removes a mandatory right or jurisdiction that cannot legally be waived.
32Notices#
We may send operational or legal notices to:
- The email address associated with an account
- Organization administrators
- The Customer's billing contact
- The Service interface
The Customer must keep its contact information current.
Legal notices to us must be sent to:
Mustafa NOORHUSSINChemin des Lentillières 13c1023 CrissierSwitzerlandEmail: hello@onenakfa.com
Email notice is considered received when successfully delivered without an automated failure message, subject to proof to the contrary.
33Assignment#
The Customer may not transfer these Terms, its Subscription, or its organization account without our prior written consent.
We may transfer these Terms and the operation of the Service to:
- A company formed to operate onenakfa
- A successor business
- An acquirer of the Service or substantially all related assets
- An affiliated entity under common control
We will notify Customers of a transfer where reasonably required.
A transfer will not reduce applicable data-protection rights.
34Independent parties#
The parties are independent contractors.
These Terms do not create:
- A partnership
- Joint venture
- Employment relationship
- Agency
- Fiduciary relationship
- Franchise
The Customer cannot bind the Service Provider, and the Service Provider cannot bind the Customer, except where expressly agreed in writing.
35No third-party beneficiaries#
Except where mandatory law provides otherwise, these Terms do not give contractual enforcement rights to a person who is not a party to the applicable agreement.
Members and Guests may have independent statutory rights and may have separate rights against the Customer, Stripe, or another provider.
36Entire agreement and order of priority#
These Terms, any accepted order or checkout confirmation, the applicable data-processing terms, and policies expressly incorporated by reference form the entire agreement concerning the Service.
If documents conflict, the following order applies:
- A signed written agreement or order form
- Section 17 for controller-processor matters
- These Terms
- Policies incorporated by reference
The Privacy Policy remains the controlling description of processing where it does not conflict with Section 17.
37Severability#
If a provision is invalid, illegal, or unenforceable, it will be modified only to the minimum extent necessary to make it enforceable.
If modification is not possible, the affected provision will be removed without affecting the remaining provisions.
38No waiver#
Failure or delay in enforcing a right does not waive that right.
A waiver is effective only if made in writing by the party granting it.
39Language#
These Terms may be made available in English, Arabic, Tigrinya, or other languages.
The translations are provided for accessibility.
Unless mandatory law requires otherwise, the English version controls if there is a conflict or material difference between language versions.
40Contact#
For legal, contractual, billing, privacy, security, or support questions, contact:
Mustafa NOORHUSSINOperating under the brand onenakfaChemin des Lentillières 13c1023 CrissierSwitzerlandEmail: hello@onenakfa.com