Privacy policy and cookie declaration

1. APPLICABLE LEGISLATION

This Personal Data Protection Policy (hereinafter the ” Policy ) is made pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (hereinafter the ” General Data Protection Regulation ” or ” GDPR “) and the Act of 30 July 2018 on the protection of individuals with regard to the processing of personal data and the Act of 1 August 2018.

2. DATA CONTROLLER

The data controller is Up Luxembourg SARL with registered office at 9 rue du Laboratoire L-1911 Luxembourg, and registered in the register of legal entities under VAT number LU34961018, hereinafter “UP LUX“.

3. DATA PROTECTION OFFICER / CONTACT

UP LUX has appointed a Data Protection Officer (hereinafter the “DPO“).

For any information concerning the processing of personal data by UP LUX, please contact our DPO :

  • By post: UP LUX – DPO – 9 rue du Laboratoire L-1911 Luxembourg

Via email: privacy@up-luxembourg.lu

4. PURPOSE OF THE PRIVACY POLICY

The Policy governs the data processing carried out in connection with the supply by UP LUX of regulated cheques known in particular as “Chèque-repas”, and associated services, in particular online services and mobile applications (hereinafter the ” Products ” and the ” Services “).

5. PERSONS CONCERNED

The persons concerned by the processing carried out by UP LUX under the conditions defined below are :

  • « Employer Prospect Representatives » :
    • Individuals acting on behalf of prospective customers or holding a corporate office within the prospect.
  • « Employer Customer Representatives » :
    • Individuals acting on behalf of customers or holding a corporate office within customer entities.
  • The « Users» and/or « Beneficiaries » :
    • The natural persons benefiting from the Products and/or Services provided by UP LUX ;
    • Individuals creating a personal space and using an online service or mobile application provided by UP LUX.
  • The « Visitors » :
    • Individuals visiting a website or mobile application published by UP LUX.
  • « Suppliers and Partners » :
    • Individuals who are suppliers of UP LUX or who have a business relationship with UP LUX or who are partners of UP LUX;
    • Individuals acting on behalf of legal entities supplying UP LUX or having business relations with UP LUX or partners of UP LUX, or exercising a corporate mandate within these entities.

6. TREATMENTS USED

Processing carried out for the purpose of providing Products and Services

Purposes of processing Type of data processed Legal basis for processing Data retention periods
Produce and make available regulated cheques User’s surname, first name, gender, date of birth, national registration number, postal address Contract performance and legal obligations 10 years from January 1 after the end of the relationship
Authenticate and enable Users to access the Services provided (including my UP LUX, UP LUX mobile applications, UP LUX Account) to create a personal space, place orders for Products or Services, and track the status and history of their orders. E-mail address, cell phone number Contract performance 10 years from January 1 after the end of the relationship
Ensure the validity of transactions linked to the use of regulated cheques Payment card data, purchase history and transaction details, account balance. Contract performance and legal obligations 10 years from January 1 after the end of the relationship
Assist and manage user requests Surname, first name, e-mail address, mobile and/or landline telephone number, and information on User requests Contract performance 5 years from the first of January following processing of the request
Data analysis, audit, control and fraud prevention Surname, first name, e-mail address, title, position/mandate

Connection data

UP LUX’s legitimate interest in protecting its service and activities. 5 years from January 1 after file closure
Combating money laundering and the financing of terrorism Surname, first name, e-mail address, nationality, date and place of birth, postal address, economic and financial data Legal obligation Personal data relating to the fulfilment of a legal obligation is kept for as long as this obligation justifies it, up to a maximum of 5 years.

Processing for commercial communication and canvassing purposes

Purposes of processing Type of data processed Legal basis for processing Data retention periods
To ensure that those with whom UP LUX is in contact or intends to enter into contact (Employer Customers, Employer Prospects, Suppliers and Partners) are informed about its offers. Last name, first name, cell phone number, business telephone number, business e-mail. UP LUX’s legitimate interest in carrying out commercial prospecting activities. 5 years after the last interaction.

Processing for non-commercial communication to Users

As part of its contractual and regulatory obligations, UP LUX may communicate with Users by mailing, post or SMS:

  • or when the Employer Customer has provided the data enabling the implementation of this processing at the time of ordering the Products and/or Services;
  • or when the User opens a personal space on an online service or mobile application associated with the Products and/or Services.

The sole purpose of these communications is to inform Users about :

  • The management of their account and in particular, without the list below being exhaustive:
    • Card management (activation, balance and transaction tracking, stop payment, etc.);
    • Expiry dates and account balances ;
    • Management and security of their personal space;
    • Incidents and unavailability of Products and/or Services;
    • The presentation of the functioning of the Products and/or Services, of the personal area or of their evolutions;
  • Regulatory changes affecting the use of Products and/or Services or their cards.

This treatment can take place :

  • For the duration of the contractual relationship ;
  • And beyond the contractual relationship, as long as the following conditions are not met:
    • The end of validity of the User’s card ;
    • Exhausting the account balance ;

Processing of data collected from Visitors

Purposes of processing Type of data processed Legal basis for processing Data retention periods
Respond to Visitors’ requests for information and/or comments. “Last name, first name, e-mail, telephone number, postal address, company name, company BCE number, position.

IP address, browser type and version, operating system used, functions used, pages visited, time stamps of visits and search terms.”

Consent of the User and legitimate interests of UP LUX to study the use of its online services and application in order to improve them. 5 years
Improve the functionalities and quality of Visitors’ browsing experience on our sites and applications by carrying out tests, research and analysis. 3 years
Determine the impact of UP LUX’s promotional operations and evaluate its commercial performance by identifying trends in the use of our sites and applications. 3 years

7. DATA RECIPIENTS

Personal data is processed by UP LUX’s internal departments, by persons authorized to have access to it. Processing conditions are strictly controlled, and all employees are made aware of how to handle personal data.

Data may be transmitted to other companies of the UpCoop Group, to which UP LUX belongs, involved in the supply of Products or Services.

UP LUX uses external service providers to supply Products and Services offered to its Employer Customers, Users, Partners, including card manufacturing and delivery, transaction authorization, data hosting, security and call centers. These companies may be subcontractors within the meaning of the RGPD. Personal data may be transmitted to these service providers.

UP LUX ensures that its subcontractors have implemented technical and organizational measures to ensure the protection of processed data.

In accordance with the regulations in force, personal data may also be transmitted to the competent authorities upon request, and in particular to public bodies, judicial auxiliaries, legal officers and bodies responsible for debt collection, exclusively to meet legal obligations, as well as in the case of the search for the perpetrators of offences.

8. DATA TRANSFERS OUTSIDE THE EUROPEAN UNION

Personal data is hosted in the European Union.

9. SHELF LIFE

Data is kept for the periods specified in article 6, depending on the type of processing used.

Some data may be kept for an additional period necessary to meet UP LUX’s legal or regulatory obligations or to exercise UP LUX’s legal rights.

Beyond this period, certain anonymized data may be kept for archiving or statistical purposes.

10. RIGHTS OF PERSONS CONCERNED

Each data subject has the right to access, rectify, erase, limit, oppose, port their data, or withdraw their consent under the conditions and limits set out in the General Data Protection Regulation.

The data subject may exercise his or her rights at any time by contacting the UP LUX DPO at the contact details given in Article 3.

In the interests of confidentiality and the protection of personal data, UP LUX may ask the person concerned to enclose a copy of an official identity document, such as a valid identity card or passport, in support of his/her request.

All requests will be processed as quickly as possible and in accordance with applicable law. In some cases, personal data may only be deleted after a certain period of time imposed by applicable regulations and statutes of limitation. In such cases, UP LUX will retain the data until the permitted deletion date.

The data subject is informed that in the event of refusal to provide his/her personal data or exercise of his/her right to erasure, restriction or objection, UP LUX may be required to suspend or discontinue in whole or in part the supply of Products and Services to the data subject or to the person on whose behalf the data subject is acting.

In the event of a dispute regarding the use of his or her data, the data subject has the right to lodge a complaint with the Data Protection Authority.

11. UNSUBSCRIBING FROM COMMERCIAL COMMUNICATIONS

Any recipient of UP LUX commercial communications may decide to unsubscribe at any time, even if they have previously expressed a different choice, either by clicking on the unsubscribe link included in said communications, or by setting their choices differently in their personal online space.

12. COOKIES

A cookie is a computer file which does not allow the person concerned to be identified directly, but stores information on their computer and/or equipment relating in particular to the pages consulted, the dates and times of consultation, and the information entered and retained to avoid subsequent entry.

When connecting for the first time to a website published by UP LUX, the Visitor is informed that UP LUX and/or its partners may deposit cookies via the website. Only the sender of a cookie is likely to read the information contained therein and UP LUX has no access to the cookies that its partners may use.

The Visitor can manage the deposit of cookies in the following way:

  • The deposit of strictly necessary technical cookies is activated by default and cannot be deactivated by the Visitor, as these cookies are essential to the operation of the site;
  • The Visitor can deactivate or activate the installation of cookies subject to his consent (audience measurement cookies, behavioral analysis cookies, advertising cookies, etc.) via the following manager: Cookiepro

Detailed list of cookies used by UP LUX or its partners.

12.1.
Cookies strictement nécessaires

  • Key : OptanonConsent
  • Domain : .up-luxembourg.lu
  • Path : /
  • Cookie type : First party
  • Expiration : 1 year
  • Description : This cookie is set by the OneTrust cookie compliance solution. It stores information on the cookie categories used by the site and indicates whether visitors have given or withdrawn their consent to the use of each category. This enables site owners to prevent cookies of each category from being installed in the user’s browser, where consent has not been given. The cookie has a normal lifetime of one year, so returning visitors will have their preferences remembered. It does not contain any information that could identify the site visitor.

12.2.
Cookies de performance

  • Key : _ga_867VJZCE63
  • Domain : .up-luxembourg.lu
  • Path : /
  • Cookie type : First party
  • Expiration : 1 year 1month
  • Description : This cookie is used by Google Analytics to keep track of session status.

  • Key : _ga
  • Domain : .up-luxembourg.lu
  • Path : /
  • Cookie type : First party
  • Expiration : 1 year 1month
  • Description :This cookie name is associated with Google Universal Analytics – which is a major upgrade to Google’s most commonly used analytics service. This cookie is used to distinguish unique users by assigning a randomly generated number as a customer ID. It is included in every page request on a site and used to calculate visitor, session and campaign data for site analytics reports.

12.3.
Cookies de ciblage

  • Key : _lfa
  • Domain : .up-luxembourg.lu
  • Path : /
  • Cookie type : First party
  • Expiry date : 1 year
  • Description :The Leadfeeder cookie collects behavioral data from all visitors to the website. This includes the pages consulted, the origin of visitors and the time spent on the site.

12.4.
Functionality cookies

  • Key : wp-wpml_current_language
  • Domain : .up-luxembourg.lu
  • Path : /
  • Cookie type : First party
  • Expiration : Session
  • Description : Stores the current language. By default, this cookie is only set for logged-in users. If you enable the language cookie to support AJAX filtering, this cookie will also be set for users who are not logged in.

13. UPDATING

UP LUX may modify this policy from time to time.

The person concerned will be informed of the change by any means, such as e-mail or notification on the UP LUX website.

The current version of the Policy is always available upon request to the UP LUX contact details mentioned in article 3.

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.