Last Updated: January 21, 2026
The data controller responsible for your personal data is:
LuxSign
Electronic Signature Platform
Grand Duchy of Luxembourg
Luxembourg
RCS: A46705
LuxSign ("we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our electronic signature service ("Service"). We process your data based on the legal grounds described in Section 3 below.
Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:
| Processing Activity | Legal Basis | Details |
|---|---|---|
| Account creation and management | Contract Performance (Art. 6(1)(b)) | Necessary to provide the Service you requested |
| Document signing and storage | Contract Performance (Art. 6(1)(b)) | Core functionality of the e-signature service |
| Audit trail creation | Legal Obligation (Art. 6(1)(c)) and Legitimate Interest (Art. 6(1)(f)) | Required under eIDAS Regulation and for dispute resolution |
| Email notifications | Contract Performance (Art. 6(1)(b)) | Essential service communications |
| Analytics and service improvement | Legitimate Interest (Art. 6(1)(f)) | Improving service quality and user experience |
| Marketing communications | Consent (Art. 6(1)(a)) | Only with your explicit consent; can be withdrawn anytime |
| Security and fraud prevention | Legitimate Interest (Art. 6(1)(f)) | Protecting our Service and users from threats |
| Payment processing | Contract Performance (Art. 6(1)(b)) | Processing subscription payments |
| Cookie-based tracking (non-essential) | Consent (Art. 6(1)(a)) | Only with your explicit consent via cookie banner |
We use your information to:
Your data is stored on secure servers located in the European Union. We implement industry-standard encryption for data at rest and in transit. However, no method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
We may share your information:
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
Subject to applicable law, you have the right to:
To exercise these rights, contact our Data Protection Officer at contact@luxsign.lu. We will respond to your request within one month. This period may be extended by two further months where necessary, taking into account the complexity and number of requests.
Supervisory Authority: You have the right to lodge a complaint with the Commission Nationale pour la Protection des Donnees (CNPD), the Luxembourg supervisory authority for data protection.
CNPD Contact:
15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg
Tel: (+352) 26 10 60 - 1
Website: cnpd.public.lu
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected. The specific retention periods are as follows:
| Data Category | Retention Period | Justification |
|---|---|---|
| Account information | Duration of account + 3 years | Contractual obligations and legal requirements |
| Signed documents | 10 years from signing date | Luxembourg commercial law requirements and eIDAS compliance |
| Audit trail data | 10 years from document completion | Legal evidence requirements under eIDAS Regulation |
| Payment records | 10 years | Luxembourg tax and commercial law requirements |
| Support communications | 3 years from resolution | Quality assurance and dispute resolution |
| Server logs | 90 days | Security monitoring and troubleshooting |
| Analytics data | 26 months | Service improvement (anonymized where possible) |
| Cookie consent records | 12 months | GDPR and ePrivacy Directive compliance |
| Marketing consent records | Duration of consent + 3 years | Proof of consent under GDPR |
Upon expiration of the retention period, personal data will be securely deleted or anonymized. Data may be retained longer if required by law or for the establishment, exercise, or defense of legal claims.
We use cookies and similar technologies to operate and improve the Service. Cookies are small data files stored on your device. You can control cookies through your browser settings, but disabling cookies may affect Service functionality. For more information, see our Cookie Policy.
Your data is stored and processed in the European Union. If you access the Service from outside the EU, your data will be transferred to and processed in the EU. Luxembourg is a member of the European Union and subject to EU data protection laws.
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at contact@luxsign.lu, and we will take steps to delete such information.
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any information to them.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Your continued use of the Service after changes are posted constitutes acceptance of the updated Privacy Policy. We encourage you to review this Privacy Policy periodically. For material changes, we will provide notice via email or through the Service.
If you have questions or concerns about this Privacy Policy or our data practices, contact us at:
Contact: contact@luxsign.lu
Technical Support: support@luxsign.lu