GDPR Compliance HELVILUX

Last Updated: December 2025

1. Our Commitment to GDPR

Helvilux is fully committed to complying with the General Data Protection Regulation (GDPR) and maintaining the highest standards of data protection for all visitors, users, and clients, particularly within the European Union.

2. Legal Basis for Data Processing

We process personal data based on the following legal grounds under GDPR:

  • Contract Performance (Art. 6(1)(b)) – Processing necessary to provide Helvilux services and communication.
  • Legitimate Interests (Art. 6(1)(f)) – Website functionality, analytics, security, and service improvement.
  • Legal Obligation (Art. 6(1)(c)) – Compliance with bookkeeping, tax, and regulatory requirements.
  • Consent (Art. 6(1)(a)) – Newsletter subscriptions, optional cookies, and other consent-based features.

3. Your GDPR Rights

3.1 Right of Access (Art. 15)

You may request confirmation of whether we process your data and receive a copy of that data.

3.2 Right to Rectification (Art. 16)

You can request correction of inaccurate or incomplete personal data.

3.3 Right to Erasure (Art. 17)

You may request deletion of your personal data under certain conditions (“right to be forgotten”).

3.4 Right to Restriction of Processing (Art. 18)

You may request that we limit the processing of your personal data.

3.5 Right to Data Portability (Art. 20)

You may request your data in a structured, commonly used, machine-readable format.

3.6 Right to Object (Art. 21)

You may object to processing based on legitimate interests or for direct marketing.

3.7 Right to Withdraw Consent (Art. 7(3))

Where processing is based on consent, you may withdraw it at any time.

4. How to Exercise Your Rights

To exercise your GDPR rights, please contact us:

Data Protection Contact
Helvilux
Email: helvilux@gmail.com
Phone: +41 78 250 36 99

We respond within one month, extendable by two months depending on request complexity.

5. Data Protection Measures

We implement appropriate technical and organizational measures, including:

  • Encrypted transmission (HTTPS)
  • Secure and encrypted data storage
  • Access control and authentication
  • Regular security updates
  • Logging and monitoring for security
  • Data minimization practices
  • Staff awareness and training (if applicable)

6. Data Processing Agreements

When we work with third-party service providers, we ensure they:

  • Offer sufficient guarantees of GDPR compliance
  • Sign Data Processing Agreements (DPAs) under Art. 28
  • Process data only on our instructions
  • Maintain strong security practices

7. International Data Transfers

If personal data is transferred outside the EEA, we apply one or more of the following safeguards:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions
  • Additional technical and organizational safeguards as required

8. Data Breach Notification

In the event of a personal data breach, we will:

  • Notify the relevant supervisory authority within 72 hours when required
  • Inform affected individuals if there is a high risk to their rights
  • Document all breaches in accordance with Art. 33 GDPR
  • Implement measures to reduce further risk

9. Data Retention

We retain personal data only as long as necessary:

  • Contact / Communication Data: Up to 24 months
  • Account or Service Data: Duration of service + statutory retention
  • Technical Logs / Security Logs: Typically 12–24 months
  • Marketing Data: Until consent withdrawal or 3 years of inactivity
  • Cookies: As defined in the Cookie Policy

(You can adjust these periods depending on your actual practices.)

10. Children’s Data

Helvilux does not target or knowingly collect personal data from individuals under 16.
If such data is discovered, it will be deleted unless parental consent is provided.

11. Supervisory Authority

You may lodge a complaint with your local supervisory authority or with Luxembourg’s authority:

Commission Nationale pour la Protection des Données (CNPD)
15, Boulevard du Jazz
L-4370 Belvaux, Luxembourg
Phone: (+352) 26 10 60 – 1
Email: info@cnpd.lu
Website: cnpd.public.lu

12. Contact Information

Helvilux
Data Protection Contact
Address: Luxembourg, European Union
Email: helvilux@gmail.com
Phone: +41 78 250 36 99