How We Protect Your Data
Last updated: 09/09/2026
Version 1.0 · 9
1. Who we are
Nexact S.à r.l. is the controller for the personal data described in this notice, except where section 3 says we act as a processor.
Company
Nexact S.à r.l.
Registered office
17 rue Glesener, L-1631 Luxembourg
Company number
RCS Luxembourg B305664
VAT number
LU37714855
Business permit
Autorisation d'établissement N° 10193400/0, activity: comptable
Privacy contact
Telephone
(+352) 621 420 182
We have not appointed a data protection officer. We are not required to. Our privacy contact is COO, Daniel Hauptfleisch.
2. What this notice covers
This notice covers personal data we handle when you visit our website, when you enquire about our services, when we accept you as a client, and when we deliver accounting, payroll, tax and advisory work.
3. The one distinction that explains everything else
We handle personal data in two different capacities, and your rights work differently in each.
Where we are the controller. Our own business: enquiries, marketing, client relationship management, billing, our legal and professional obligations, and our anti money laundering duties. We decide why and how this data is processed.
Where we are a processor. Personal data inside a client's books, records and payroll. The client decides why that data is processed. We process it on their instruction, under a written data processing agreement. If your data appears in a client's accounting records because you are their employee, customer or supplier, that client is the controller and you should contact them first. We will help them respond to you.
4. What we collect and why
4.1 Website visitors
What
Why
Legal basis
Pages visited, approximate location, device and browser
Keeping the site working and secure
Legitimate interests
Analytics data
Understanding how the site is used
Consent, through the cookie banner
4.2 Enquiries and prospective clients
What
Why
Legal basis
Name, company, email, telephone, what you asked about
Responding to you and preparing a proposal
Steps prior to entering a contract, and legitimate interests
Notes from calls and meetings
Understanding your requirements and scoping the work
Legitimate interests
4.3 Clients, their people and their counterparties
What
Why
Legal basis
Identity and contact details of directors, managers and authorised signatories
Delivering the engagement and knowing who may instruct us
Contract
Payroll data: salary, working time, leave, social security number, tax identifiers, bank details
Running payroll and filing social security and tax returns
Contract with our client, and our client's legal obligation
Financial and transactional data, including invoices, expenses and counterparty details
Bookkeeping, accounts preparation, VAT and tax compliance
Contract with our client
Accounting records generally
Meeting statutory filing and retention duties
Legal obligation
4.4 Anti money laundering: our heaviest processing
We are a professional subject to the amended Luxembourg law of 12 November 2004 on the fight against money laundering and terrorist financing. Our supervisory authority for these obligations is the Administration de l'enregistrement, des domaines et de la TVA (AED). We do this processing as controller, in our own name, and we cannot switch it off at a client's request.
What
Why
Legal basis
Identity documents, proof of address, date of birth, nationality
Identifying and verifying you and your beneficial owners
Legal obligation
Shareholding and control information, register extracts
Identifying beneficial ownership
Legal obligation
Sanctions, politically exposed person and adverse media screening results
Screening we are required to perform
Legal obligation, and substantial public interest for any special category or criminal offence data involved
Source of funds and source of wealth evidence
Risk assessment where required
Legal obligation
Risk rating, monitoring records, internal reports
Ongoing monitoring and record keeping
Legal obligation
Special category and criminal offence data. We do not seek it. Payroll records may incidentally reveal health, through sickness absence, or trade union membership, through subscription deductions. We restrict who can see it and we do not extract or separately analyse it. Screening may reveal criminal or sanctions related information, which we process only because the law requires it.
5. Who we share data with
We do not sell personal data and we do not share it for anyone else's marketing.
Our delivery partner. Preparation work is carried out by Outsourced CFO (Pty) Ltd in South Africa, under our instruction and supervision. They prepare, we review, approve, communicate and file. They have role based access to the client files they are assigned to, no standing access to our client base, and no access to our anti money laundering file or screening outputs.
Our sub processors. The current list, with locations and transfer mechanisms, is published at
\[LINK TO /sub-processors]
. It includes Xero, Google Workspace, Dext, Syft Analytics, our electronic signature provider, our website form provider and our payroll provider.
Others, where required. Luxembourg tax and social security authorities and the RCS, for filings we make for clients. The Cellule de Renseignement Financier, where we are required to report a suspicion. The AED, as our supervisory authority. Our professional advisers, insurers and auditors. A successor, if the business is transferred.
6. Where your data goes
Some of our providers, and our delivery partner, are outside the European Economic Area. That is normal for cloud accounting and it is lawful provided the right mechanism applies to each transfer.
Destination
Why
How it is made lawful
Xero — United States, with processing in New Zealand and Australia
Our cloud accounting platform
Xero's data processing terms apply automatically and include the EU Standard Contractual Clauses. New Zealand has an EU adequacy decision. Xero also uses its own sub processors outside the EEA, including cloud infrastructure, data extraction and AI assisted features, and publishes that list.
Google Workspace — European Union and United States
Email, documents, shared drives
Google's data processing terms and the EU Standard Contractual Clauses
Outsourced CFO (Pty) Ltd — South Africa
Preparation of bookkeeping and draft reporting
South Africa has no EU adequacy decision. The transfer is governed by a written intra group data processing agreement incorporating the EU Standard Contractual Clauses, with additional technical and organisational safeguards.
Other sub processors
See the sub processor list
Adequacy decision, or the EU Standard Contractual Clauses, as recorded on that list
You can ask us for a copy of the safeguards that apply to any of these transfers.
7. Artificial intelligence
Some of the platforms we use include AI assisted features that help with capturing, sorting and reconciling data.
We use these features only under the providers' business or enterprise terms, which prevent your data from being used to train publicly available models, and we do not consent to such use. We do not use free or personal consumer accounts with client data. We hold an internal policy governing which tools are approved and on what terms.
AI assisted features support our work. They do not make decisions about you or your affairs on their own, and a qualified person reviews every output before it reaches a client or a filing. We do not carry out automated decision making producing legal effects, and we do not profile.
8. How long we keep things
Data
Retention
Accounting records and supporting documents
10 years, under Luxembourg commercial law
Anti money laundering records
5 years after the relationship ends, or longer if the AED requires
Client engagement and contractual records
10 years after the engagement ends
Payroll records
As required by Luxembourg employment and social security law
Enquiries that do not become clients
24 months from last contact
Website analytics
As set out in the cookie information
Anything relevant to a live claim or enquiry
Until it is resolved
9. Your rights
You have the right to be informed, to access your data, to have inaccurate data corrected, to have data erased, to restrict processing, to data portability, to object to processing based on legitimate interests, and to withdraw consent where we rely on it.
To exercise a right, email privacy@nexact.lu. We respond within one month, and will tell you if we need longer. We may need to verify your identity first.
If your data is in a client's records, that client is the controller. Contact them. If you contact us instead, we will pass your request on promptly and help them answer it.
The one place your rights are restricted
Where anti money laundering law applies, some rights are limited. We are prohibited by law from telling anyone that a suspicious transaction report has been made, is being considered, or that an investigation may be underway. In that situation we cannot confirm or deny whether a report exists, and the rights of access and erasure are restricted.
This is imposed by law. It is not a choice we make, and it applies to every professional in our position. We also cannot delete anti money laundering records before the statutory period expires.
Complaints. If you are unhappy with how we handle your data, please tell us first so we can put it right. You also have the right to complain to the Luxembourg supervisory authority at any time:
\\Commission nationale pour la protection des données (CNPD)\\ 15 Boulevard du Jazz, L-4370 Belvaux, Luxembourg www.cnpd.lu
10. Security
We apply role based access and least privilege, multi factor authentication on every system holding client data, encryption in transit and at rest, activity logging, restrictions on local copies and personal accounts, a documented joiner mover leaver procedure, and a quarterly access review. Access to a client's records is limited to the people assigned to that engagement.
If a personal data breach occurs, we follow a documented procedure, notify the CNPD within 72 hours where required, and notify affected individuals where the law requires it.
11. Cookies
Our site is built on Wix, which sets strictly necessary cookies and may set analytics cookies. Strictly necessary cookies do not require consent. Everything else must be blocked until you consent, and you can withdraw consent at any time through the cookie settings.
12. Children
Our services are for businesses. We do not knowingly collect data from children through this site.
13. Changes
We update this notice when our processing changes. The version and date at the top tell you which one you are reading. Material changes are flagged on the site, and clients are notified by email.
14. Contact
Nexact S.à r.l. 17 rue Glesener, L-1631 Luxembourg privacy@nexact.lu · (+352) 621 420 182