Legal

Privacy & GDPR

Back

Privacy & GDPR

Last updated: 5.10.2026

Cercle Européen Renert a.s.b.l. (“CER”, “we”, “us”) takes the protection of your personal data seriously. This notice explains what data we collect when you use cer.lu or interact with us, why we collect it, and what rights you have under Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and the Luxembourg Law of 1 August 2018 on the organisation of the National Commission for Data Protection and the general data protection framework.

1. Data controller

Cercle Européen Renert a.s.b.l.
2, Circuit de la Foire Internationale
L-1347 Luxembourg
E-mail: info@cer.lu

We have not appointed a Data Protection Officer, as we are not required to do so. Any questions about data protection can be sent to the address above.

2. What data we collect and why

2.1 Visiting the website

When you visit cer.lu, our web server automatically records technical information: your IP address, the date and time of the request, the pages viewed, the referring page, and your browser and operating system. This data is needed to deliver the website, ensure its security and diagnose technical problems.

Legal basis: Art. 6(1)(f) GDPR – our legitimate interest in operating a secure and functioning website.
Retention: server logs are deleted after 30 days.

2.2 Cookies

This website is built with Joomla, which sets a technically necessary session cookie to keep your visit working correctly (for example, to remember a login or a form submission). This cookie contains no personal information and expires when you close your browser.

We do not use analytics, advertising or tracking cookies.

2.3 Contacting us

If you contact us by e-mail or via the contact form, we process the data you provide (name, e-mail address, message content) in order to respond to your enquiry.

Legal basis: Art. 6(1)(f) GDPR – legitimate interest in handling correspondence; Art. 6(1)(b) GDPR where your request relates to membership or an event.
Retention: until your enquiry is resolved, and no longer than [e.g. 12 months] thereafter, unless legal obligations require longer storage.

2.4 Newsletter and publications

If you subscribe to our future newsletter or to receive our publications, we process your name and e-mail address to send you information about our events, papers and activities.

Legal basis: Art. 6(1)(a) GDPR – your consent. You can withdraw consent at any time by using the unsubscribe link in each e-mail or by writing to us.
Retention: until you unsubscribe.
Service provider: We do not have a Newsletter tool yet.

2.5 Event registration

When you register for one of our conferences or debates, we process the data required to organise the event (name, e-mail, organisation/function, dietary requirements where relevant). Participant lists may be shared with co-organisers and venues where necessary for the event.

Legal basis: Art. 6(1)(b) GDPR – performance of a contract or pre-contractual steps at your request.
Retention: 12 months after the event, unless you have asked to be kept informed of future events.

Photographs or recordings may be taken at public events for documentation and communication purposes. You will be informed of this at the event, and you may object at any time.

2.6 Members and partners

We process the contact and administrative data of our members, board members, speakers and partners in order to run the Association in accordance with its statutes and the Law of 7 August 2023 on non-profit associations and foundations, including legal obligations such as keeping the register of members.

Legal basis: Art. 6(1)(b) and (c) GDPR.
Retention: for the duration of membership and for the periods required by law (in general 10 years for accounting records).

3. Recipients of your data

We only share personal data where necessary: with IT and hosting providers (Amyma Web sàrl), the tools mentioned above, event co-organisers, and public authorities where required by law. All service providers act under data processing agreements in line with Art. 28 GDPR.

4. Transfers outside the EU/EEA

We aim to keep your data within the European Union.

5. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15);
  • have inaccurate data corrected (Art. 16);
  • have your data erased (Art. 17);
  • restrict processing (Art. 18);
  • receive your data in a portable format (Art. 20);
  • object to processing based on legitimate interest (Art. 21);
  • withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Art. 7(3)).

To exercise these rights, write to info@cer.lu. We will respond within one month.

You also have the right to lodge a complaint with the supervisory authority:

Commission nationale pour la protection des données (CNPD)
15, Boulevard du Jazz
L-4370 Belvaux
cnpd.public.lu

6. Security

We use appropriate technical and organisational measures to protect your data, including TLS encryption of this website (HTTPS), access controls and regular software updates.

7. External links

Our website contains links to third-party websites. We are not responsible for their content or privacy practices. Please consult their own privacy notices.

8. Changes to this notice

We may update this notice from time to time. The current version is always available on this page, with the date of the last update shown at the top.

For media inquiries or partnership opportunities, please contact info@cer.lu