Privacy Policy

Lëtzebuerg.ai

Last updated: March 16, 2026

1. Introduction

1.1 About This Policy

Lëtzebuerg.ai (“we,” “us,” “our,” or the “Company”) is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data in compliance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), Luxembourg data protection law (Loi du 1er août 2018), and other applicable privacy laws.

1.2 Scope

This Privacy Policy applies to:

  • Visitors to our website (www.letzebuerg.ai)
  • Clients and prospective clients who engage our services
  • Users of our AI solutions and platforms
  • Business partners and suppliers
  • Job applicants
  • Any other individuals whose personal data we process

1.3 Data Controller

Lëtzebuerg.ai is the data controller responsible for your personal data. Our contact details are provided in Section 13 below.

2. Personal Data We Collect

2.1 Information You Provide Directly

We collect personal data that you voluntarily provide to us, including:

a) Contact Information

  • Full name
  • Email address
  • Telephone number
  • Company name and position
  • Postal address
  • Country of residence

b) Account and Registration Information

  • Username and password
  • Profile information
  • Communication preferences
  • Security questions and answers

c) Business and Commercial Information

  • Company details and size
  • Industry sector
  • Business requirements and objectives
  • Project specifications
  • Contract and billing information

d) Client Data for AI Services

When providing AI services, you may upload or provide data sets, documents, or other information (“Client Data”) which may contain personal data. The processing of such data is governed by our Data Processing Agreement in accordance with Article 28 GDPR.

e) Communications

  • Correspondence via email, contact forms, chat, or phone
  • Feedback and survey responses
  • Support requests and inquiries

f) Job Application Information

  • CV/resume
  • Cover letter
  • Educational qualifications
  • Employment history
  • References
  • Interview notes

2.2 Information We Collect Automatically

When you visit our website or use our services, we automatically collect:

a) Technical Information

  • IP address
  • Browser type and version
  • Operating system
  • Device type and unique device identifiers
  • Screen resolution
  • Time zone settings

b) Usage Data

  • Pages visited and navigation paths
  • Time and date of visits
  • Referral source
  • Clickstream data
  • Features and functions used
  • Session duration

c) Cookies and Tracking Technologies

We use cookies and similar technologies as described in Section 10 below.

2.3 Information from Third Parties

We may receive personal data about you from:

  • Public sources (e.g., company websites, LinkedIn, business registries)
  • Marketing and analytics partners
  • Social media platforms (when you interact with us)
  • Business partners and referrals
  • Data brokers (with appropriate legal basis)

3. Legal Basis for Processing

Under the GDPR, we must have a legal basis to process your personal data. We rely on the following legal bases:

3.1 Contract Performance (Article 6(1)(b) GDPR)

Processing is necessary to:

  • Respond to your inquiries and provide requested information
  • Perform our contractual obligations under service agreements
  • Deliver AI services and solutions
  • Provide customer support
  • Process payments and manage billing

3.2 Legitimate Interests (Article 6(1)(f) GDPR)

We process personal data where necessary for our legitimate interests, including:

  • Operating and improving our website and services
  • Marketing our services to businesses (B2B marketing)
  • Analyzing usage patterns and conducting research
  • Detecting and preventing fraud and security threats
  • Managing business relationships
  • Protecting our legal rights
  • Business development and strategy

We carefully balance our legitimate interests against your rights and freedoms. You have the right to object to processing based on legitimate interests.

3.3 Consent (Article 6(1)(a) GDPR)

Where required by law, we obtain your explicit consent to:

  • Send marketing communications (where not based on legitimate interests)
  • Use non-essential cookies
  • Process special categories of personal data (if applicable)
  • Transfer data outside the EEA in certain circumstances

You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

3.4 Legal Obligations (Article 6(1)(c) GDPR)

We process personal data to comply with legal requirements, including:

  • Tax and accounting obligations
  • Anti-money laundering regulations
  • Employment law requirements
  • Responding to lawful requests from authorities

3.5 Special Categories of Personal Data

We do not intentionally collect special categories of personal data (e.g., health data, biometric data, racial or ethnic origin) except where:

  • You explicitly provide such data for specific AI projects with your informed consent
  • Processing is necessary for legal claims
  • The data is manifestly made public by you

4. How We Use Personal Data

4.1 Service Delivery

We use your personal data to:

  • Provide, deliver, and manage our AI services
  • Develop, train, and improve AI models (using appropriate safeguards)
  • Customize and optimize solutions for your needs
  • Integrate AI systems with your existing infrastructure
  • Provide technical support and troubleshooting
  • Monitor system performance and reliability

4.2 Communication

We use your personal data to:

  • Respond to inquiries and requests
  • Send service-related notifications and updates
  • Provide project status reports
  • Send invoices and payment reminders
  • Conduct customer satisfaction surveys

4.3 Marketing and Business Development

With appropriate legal basis, we may:

  • Send newsletters and marketing materials about our services
  • Invite you to events, webinars, and conferences
  • Conduct market research
  • Analyze market trends and opportunities
  • Develop new products and services

You can opt out of marketing communications at any time (see Section 8).

4.4 Website Operations and Improvement

We use personal data to:

  • Operate, maintain, and improve our website
  • Analyze website usage and performance
  • Personalize user experience
  • Conduct A/B testing
  • Fix technical issues

4.5 Security and Fraud Prevention

We process personal data to:

  • Detect, prevent, and respond to security incidents
  • Identify and prevent fraudulent activities
  • Protect our systems and networks
  • Verify identities when necessary
  • Enforce our terms and policies

4.6 Legal and Compliance

We use personal data to:

  • Comply with legal and regulatory obligations
  • Establish, exercise, or defend legal claims
  • Cooperate with law enforcement and regulatory authorities
  • Conduct internal audits and investigations

4.7 AI Model Training and Development

We may use aggregated, anonymized, or pseudonymized data derived from our services to:

  • Train and improve AI models and algorithms
  • Conduct research and development
  • Create benchmarks and performance metrics
  • Develop new AI capabilities

This processing is conducted in a manner that prevents re-identification of individuals and complies with all applicable laws.

5. Data Sharing and Disclosure

5.1 Service Providers and Processors

We engage trusted third-party service providers to support our operations, including:

  • Cloud hosting providers (e.g., infrastructure and platform services)
  • IT and cybersecurity services
  • Payment processors and financial services
  • Marketing and analytics platforms
  • Customer relationship management (CRM) systems
  • Email and communication services
  • Professional advisors (lawyers, accountants, auditors)

All service providers are carefully selected and bound by data processing agreements that comply with Article 28 GDPR. They are authorized to process personal data only as instructed by us and for the purposes specified.

5.2 Business Partners

We may share personal data with:

  • Strategic partners for joint projects or co-marketing initiatives
  • Technology partners for system integration
  • Referral partners (with your consent)

5.3 Corporate Transactions

In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, personal data may be transferred to successor entities, subject to appropriate safeguards and notice to affected individuals.

5.4 Legal Requirements and Protection of Rights

We may disclose personal data when required or permitted by law, including:

  • Compliance with legal process (subpoenas, court orders)
  • Response to lawful requests from authorities
  • Protection of our legal rights and property
  • Prevention of fraud or illegal activities
  • Protection of safety and security of individuals

5.5 With Your Consent

We may share personal data with third parties when you have provided explicit consent for specific purposes.

5.6 Aggregated and Anonymized Data

We may share aggregated, de-identified, or anonymized data that cannot reasonably be used to identify you with:

  • Business partners and clients
  • Research institutions
  • Industry analysts
  • The public (e.g., in reports, publications, presentations)

6. International Data Transfers

6.1 Transfers Outside the EEA

Lëtzebuerg.ai is based in Luxembourg (European Economic Area). However, some of our service providers and partners may be located outside the EEA, including in countries that may not provide the same level of data protection as the EEA.

6.2 Transfer Safeguards

When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, including:

  • European Commission Adequacy Decisions: Transfers to countries deemed to provide adequate protection (e.g., United Kingdom, Switzerland, Japan)
  • Standard Contractual Clauses (SCCs): EU-approved contractual terms for data transfers
  • Binding Corporate Rules: Internal rules for multinational organizations
  • Certifications: Such as EU-U.S. Data Privacy Framework (where applicable)
  • Explicit Consent: In limited circumstances with full transparency

6.3 Transfer Impact Assessment

We conduct Transfer Impact Assessments to evaluate risks and implement supplementary measures where necessary to ensure adequate protection.

6.4 Your Rights

You have the right to obtain information about safeguards in place for international transfers. Contact us using the details in Section 13.

7. Data Retention

7.1 Retention Principles

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal, regulatory, accounting, or reporting obligations.

7.2 Retention Periods

Typical retention periods include:

Data categoryRetention periodLegal basis
Client contracts and communicationsDuration of relationship + 10 yearsLegal obligations (commercial law)
Financial and tax records10 years after end of financial yearTax and accounting laws
Marketing contactsUntil consent withdrawn or 3 years of inactivityLegitimate interests
Website analytics26 monthsLegitimate interests
Job applications (unsuccessful)6–12 months after recruitment processLegitimate interests
Security logs12 monthsLegal obligations and legitimate interests
Client Data (AI projects)As specified in service agreementContract

7.3 Deletion and Anonymization

After retention periods expire, we securely delete or anonymize personal data. Anonymized data may be retained indefinitely for statistical, research, or analytical purposes.

7.4 Legal Holds

We may retain personal data beyond standard retention periods when required for legal proceedings, investigations, or regulatory matters.

8. Your Rights Under GDPR

8.1 Overview of Rights

Under the GDPR, you have the following rights regarding your personal data:

a) Right of Access (Article 15)

You have the right to obtain:

  • Confirmation whether we process your personal data
  • Access to your personal data
  • Information about processing purposes, categories, recipients, retention periods
  • A copy of your personal data

b) Right to Rectification (Article 16)

You can request correction of inaccurate or incomplete personal data.

c) Right to Erasure / “Right to be Forgotten” (Article 17)

You can request deletion of your personal data in certain circumstances:

  • Data no longer necessary for original purposes
  • You withdraw consent (where consent was the legal basis)
  • You object to processing and no overriding legitimate grounds exist
  • Data processed unlawfully
  • Legal obligation requires erasure
  • Data relates to a child

This right is not absolute and may be limited by legal obligations or legitimate interests.

d) Right to Restriction of Processing (Article 18)

You can request temporary restriction of processing when:

  • Accuracy of data is contested
  • Processing is unlawful but you oppose erasure
  • We no longer need the data but you require it for legal claims
  • You have objected to processing pending verification of legitimate grounds

e) Right to Data Portability (Article 20)

You can request to receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller where:

  • Processing is based on consent or contract
  • Processing is carried out by automated means

f) Right to Object (Article 21)

You have the right to object at any time to:

  • Processing based on legitimate interests (including profiling)
  • Direct marketing (absolute right)
  • Processing for scientific, historical, or statistical purposes (subject to exceptions)

g) Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significant effects, except where:

  • Necessary for contract performance
  • Authorized by law
  • Based on explicit consent

Where automated decision-making is used, we will inform you and provide meaningful information about the logic involved.

h) Right to Withdraw Consent

Where processing is based on consent, you may withdraw consent at any time. This does not affect the lawfulness of processing before withdrawal.

i) Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority, particularly in your country of residence, place of work, or where an alleged infringement occurred.

Luxembourg Supervisory Authority: Commission Nationale pour la Protection des Données (CNPD)

  • Address: 15, boulevard du Jazz, L-4370 Belvaux, Luxembourg
  • Website: www.cnpd.lu
  • Email: info@cnpd.lu
  • Phone: (+352) 26 10 60 1

8.2 How to Exercise Your Rights

To exercise any of these rights, please contact us using the details in Section 13. We will respond to your request within one month of receipt, or within two months for complex requests (we will inform you of any extension).

8.3 Verification

To protect your privacy, we may need to verify your identity before responding to rights requests. We will request only the minimum information necessary for verification.

8.4 No Fee

We do not charge a fee for exercising your rights unless requests are manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or refuse the request.

9. Data Security

9.1 Security Measures

We implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, including:

Technical Measures

  • Encryption of data in transit (TLS/SSL) and at rest
  • Access controls and authentication mechanisms
  • Multi-factor authentication for sensitive systems
  • Regular security assessments and penetration testing
  • Intrusion detection and prevention systems
  • Security monitoring and logging
  • Regular software updates and patch management
  • Backup and disaster recovery procedures

Organizational Measures

  • Data protection policies and procedures
  • Employee training on data protection and security
  • Confidentiality agreements with employees and contractors
  • Data breach response plan
  • Vendor security assessments
  • Privacy by design and by default principles
  • Regular internal audits

9.2 AI-Specific Security

For AI services, we implement additional safeguards:

  • Model access controls and authentication
  • Secure training environments
  • Data sanitization and anonymization techniques
  • Model testing for data leakage
  • Secure API endpoints
  • Activity logging and monitoring

9.3 Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

  • Notify the Luxembourg CNPD within 72 hours of becoming aware
  • Notify affected individuals without undue delay where the breach poses a high risk
  • Provide information about the nature of the breach, likely consequences, and mitigation measures

9.4 Limitations

While we implement robust security measures, no system is completely secure. We cannot guarantee absolute security of personal data transmitted to or stored on our systems.

10. Cookies and Tracking Technologies

10.1 What Are Cookies

Cookies are small text files stored on your device when you visit our website. We also use similar technologies such as web beacons, pixels, and local storage.

10.2 Types of Cookies We Use

a) Essential Cookies (Strictly Necessary)

Required for website operation and security. These cannot be disabled.

  • Session management
  • Authentication
  • Security features
  • Load balancing

b) Functionality Cookies

Remember your preferences and settings.

  • Language preferences
  • Display settings
  • User interface customization

c) Performance and Analytics Cookies

Help us understand how visitors use our website.

  • Google Analytics
  • Page load time monitoring
  • Error tracking
  • Usage statistics

d) Marketing and Advertising Cookies

Used to deliver relevant advertising and measure campaign effectiveness.

  • LinkedIn Insights
  • Google Ads conversion tracking
  • Retargeting pixels

10.3 Third-Party Cookies

Some cookies are placed by third-party services that appear on our pages, including:

  • Social media plugins (LinkedIn, Twitter)
  • Analytics providers (Google Analytics)
  • Advertising networks

These third parties have their own privacy policies governing their use of information. Note: Disabling cookies may affect website functionality.

10.6 Do Not Track

Some browsers have a “Do Not Track” feature. Our website does not currently respond to Do Not Track signals.

10.7 Cookie List

For a detailed list of cookies used on our website, please visit our Cookie Policy page or contact us.

11. Links to Third-Party Websites

Our website may contain links to third-party websites, applications, or services. We are not responsible for the privacy practices or content of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.

12. Updates to This Privacy Policy

12.1 Changes

We may update this Privacy Policy from time to time to reflect:

  • Changes in our practices
  • Legal or regulatory developments
  • New services or features
  • Technological changes

12.2 Notification

When we make material changes, we will:

  • Update the “Last Updated” date at the top of this policy
  • Notify you via email (for significant changes)
  • Display a prominent notice on our website
  • Request renewed consent where required by law

12.3 Review

We encourage you to review this Privacy Policy periodically. Continued use of our services after changes indicates acceptance of the updated policy.

13. Contact Information

For any questions concerning your data, please contact us at info@letzebuerg.ai

We aim to respond to all inquiries within 10 business days for general questions and within one month for data subject rights requests.

14. Acceptance

By using our website, engaging our services, or providing personal data to us, you acknowledge that you have read, understood, and agree to this Privacy Policy.

If you do not agree with this Privacy Policy, please do not use our services or provide personal data to us.

Language Versions

This Privacy Policy is provided in English. If translations are provided in other languages, the English version shall prevail in case of any inconsistency or dispute.

    Assistant