top of page

How We Protect Your Data

Last updated: 09/09/2026
Version 1.0 · 9

1. Who we are

Nexact S.à r.l. is the controller for the personal data described in this notice, except where section 3 says we act as a processor.

Company

Nexact S.à r.l.

Registered office

17 rue Glesener, L-1631 Luxembourg

Company number

RCS Luxembourg B305664

VAT number

LU37714855

Business permit

Autorisation d'établissement N° 10193400/0, activity: comptable

Privacy contact

admin@nexact.lu

Telephone

(+352) 621 420 182

We have not appointed a data protection officer. We are not required to. Our privacy contact is COO, Daniel Hauptfleisch.

2. What this notice covers

This notice covers personal data we handle when you visit our website, when you enquire about our services, when we accept you as a client, and when we deliver accounting, payroll, tax and advisory work.

3. The one distinction that explains everything else

We handle personal data in two different capacities, and your rights work differently in each.

Where we are the controller. Our own business: enquiries, marketing, client relationship management, billing, our legal and professional obligations, and our anti money laundering duties. We decide why and how this data is processed.

Where we are a processor. Personal data inside a client's books, records and payroll. The client decides why that data is processed. We process it on their instruction, under a written data processing agreement. If your data appears in a client's accounting records because you are their employee, customer or supplier, that client is the controller and you should contact them first. We will help them respond to you.

4. What we collect and why

4.1 Website visitors

What

Why

Legal basis

Pages visited, approximate location, device and browser

Keeping the site working and secure

Legitimate interests

Analytics data

Understanding how the site is used

Consent, through the cookie banner

4.2 Enquiries and prospective clients

What

Why

Legal basis

Name, company, email, telephone, what you asked about

Responding to you and preparing a proposal

Steps prior to entering a contract, and legitimate interests

Notes from calls and meetings

Understanding your requirements and scoping the work

Legitimate interests

4.3 Clients, their people and their counterparties

What

Why

Legal basis

Identity and contact details of directors, managers and authorised signatories

Delivering the engagement and knowing who may instruct us

Contract

Payroll data: salary, working time, leave, social security number, tax identifiers, bank details

Running payroll and filing social security and tax returns

Contract with our client, and our client's legal obligation

Financial and transactional data, including invoices, expenses and counterparty details

Bookkeeping, accounts preparation, VAT and tax compliance

Contract with our client

Accounting records generally

Meeting statutory filing and retention duties

Legal obligation

4.4 Anti money laundering: our heaviest processing

We are a professional subject to the amended Luxembourg law of 12 November 2004 on the fight against money laundering and terrorist financing. Our supervisory authority for these obligations is the Administration de l'enregistrement, des domaines et de la TVA (AED). We do this processing as controller, in our own name, and we cannot switch it off at a client's request.

What

Why

Legal basis

Identity documents, proof of address, date of birth, nationality

Identifying and verifying you and your beneficial owners

Legal obligation

Shareholding and control information, register extracts

Identifying beneficial ownership

Legal obligation

Sanctions, politically exposed person and adverse media screening results

Screening we are required to perform

Legal obligation, and substantial public interest for any special category or criminal offence data involved

Source of funds and source of wealth evidence

Risk assessment where required

Legal obligation

Risk rating, monitoring records, internal reports

Ongoing monitoring and record keeping

Legal obligation

Special category and criminal offence data. We do not seek it. Payroll records may incidentally reveal health, through sickness absence, or trade union membership, through subscription deductions. We restrict who can see it and we do not extract or separately analyse it. Screening may reveal criminal or sanctions related information, which we process only because the law requires it.

5. Who we share data with

We do not sell personal data and we do not share it for anyone else's marketing.

Our delivery partner. Preparation work is carried out by Outsourced CFO (Pty) Ltd in South Africa, under our instruction and supervision. They prepare, we review, approve, communicate and file. They have role based access to the client files they are assigned to, no standing access to our client base, and no access to our anti money laundering file or screening outputs.

Our sub processors. The current list, with locations and transfer mechanisms, is published at

\[LINK TO /sub-processors]

. It includes Xero, Google Workspace, Dext, Syft Analytics, our electronic signature provider, our website form provider and our payroll provider.

Others, where required. Luxembourg tax and social security authorities and the RCS, for filings we make for clients. The Cellule de Renseignement Financier, where we are required to report a suspicion. The AED, as our supervisory authority. Our professional advisers, insurers and auditors. A successor, if the business is transferred.

6. Where your data goes

Some of our providers, and our delivery partner, are outside the European Economic Area. That is normal for cloud accounting and it is lawful provided the right mechanism applies to each transfer.

Destination

Why

How it is made lawful

Xero — United States, with processing in New Zealand and Australia

Our cloud accounting platform

Xero's data processing terms apply automatically and include the EU Standard Contractual Clauses. New Zealand has an EU adequacy decision. Xero also uses its own sub processors outside the EEA, including cloud infrastructure, data extraction and AI assisted features, and publishes that list.

Google Workspace — European Union and United States

Email, documents, shared drives

Google's data processing terms and the EU Standard Contractual Clauses

Outsourced CFO (Pty) Ltd — South Africa

Preparation of bookkeeping and draft reporting

South Africa has no EU adequacy decision. The transfer is governed by a written intra group data processing agreement incorporating the EU Standard Contractual Clauses, with additional technical and organisational safeguards.

Other sub processors

See the sub processor list

Adequacy decision, or the EU Standard Contractual Clauses, as recorded on that list

You can ask us for a copy of the safeguards that apply to any of these transfers.

7. Artificial intelligence

Some of the platforms we use include AI assisted features that help with capturing, sorting and reconciling data.

We use these features only under the providers' business or enterprise terms, which prevent your data from being used to train publicly available models, and we do not consent to such use. We do not use free or personal consumer accounts with client data. We hold an internal policy governing which tools are approved and on what terms.

AI assisted features support our work. They do not make decisions about you or your affairs on their own, and a qualified person reviews every output before it reaches a client or a filing. We do not carry out automated decision making producing legal effects, and we do not profile.

8. How long we keep things

Data

Retention

Accounting records and supporting documents

10 years, under Luxembourg commercial law

Anti money laundering records

5 years after the relationship ends, or longer if the AED requires

Client engagement and contractual records

10 years after the engagement ends

Payroll records

As required by Luxembourg employment and social security law

Enquiries that do not become clients

24 months from last contact

Website analytics

As set out in the cookie information

Anything relevant to a live claim or enquiry

Until it is resolved

9. Your rights

You have the right to be informed, to access your data, to have inaccurate data corrected, to have data erased, to restrict processing, to data portability, to object to processing based on legitimate interests, and to withdraw consent where we rely on it.

To exercise a right, email privacy@nexact.lu. We respond within one month, and will tell you if we need longer. We may need to verify your identity first.

If your data is in a client's records, that client is the controller. Contact them. If you contact us instead, we will pass your request on promptly and help them answer it.

The one place your rights are restricted

Where anti money laundering law applies, some rights are limited. We are prohibited by law from telling anyone that a suspicious transaction report has been made, is being considered, or that an investigation may be underway. In that situation we cannot confirm or deny whether a report exists, and the rights of access and erasure are restricted.

This is imposed by law. It is not a choice we make, and it applies to every professional in our position. We also cannot delete anti money laundering records before the statutory period expires.

Complaints. If you are unhappy with how we handle your data, please tell us first so we can put it right. You also have the right to complain to the Luxembourg supervisory authority at any time:

\\Commission nationale pour la protection des données (CNPD)\\ 15 Boulevard du Jazz, L-4370 Belvaux, Luxembourg www.cnpd.lu

10. Security

We apply role based access and least privilege, multi factor authentication on every system holding client data, encryption in transit and at rest, activity logging, restrictions on local copies and personal accounts, a documented joiner mover leaver procedure, and a quarterly access review. Access to a client's records is limited to the people assigned to that engagement.

If a personal data breach occurs, we follow a documented procedure, notify the CNPD within 72 hours where required, and notify affected individuals where the law requires it.

11. Cookies

Our site is built on Wix, which sets strictly necessary cookies and may set analytics cookies. Strictly necessary cookies do not require consent. Everything else must be blocked until you consent, and you can withdraw consent at any time through the cookie settings.

12. Children

Our services are for businesses. We do not knowingly collect data from children through this site.

13. Changes

We update this notice when our processing changes. The version and date at the top tell you which one you are reading. Material changes are flagged on the site, and clients are notified by email.

14. Contact

Nexact S.à r.l. 17 rue Glesener, L-1631 Luxembourg privacy@nexact.lu · (+352) 621 420 182

bottom of page