Privacy Policy
How we collect, use and protect your personal data, under the GDPR and Luxembourg law. Last updated: 24 July 2026.
nosliW iT SARL-S ("we", "our", "us") is committed to protecting your privacy. This policy explains how we collect, use, disclose and safeguard your information when you visit our website or use our services, in compliance with the General Data Protection Regulation (GDPR) and Luxembourg data protection law.
1. Data controller
nosliW iT SARL-S
Rue de Strasbourg, 2
L-2560 Luxembourg
Email: wilson.martins@nosliwit.com
Phone: +352 621 711 642
Company registration number: B298207
Note: nosliW iT SARL-S has not appointed a Data Protection Officer, as our processing activities do not meet the mandatory criteria under Article 37 GDPR. For all data protection enquiries, please contact us directly using the details above.
2. Information we collect
2.1 Data you provide
When you contact us through the website's form, WhatsApp, email or phone, we collect:
- Contact information — name, email address, phone number.
- Business information — company name and approximate number of users, where you provide them.
- Communication data — anything you write in your message.
2.2 Data collected automatically
- Server logs — IP address, browser type, operating system, timestamp. Generated by our host as part of delivering the site securely.
- Aggregated analytics — pages viewed, referrer and country, collected without cookies and without any identifier that could single you out. See section 10.
This website sets no cookies and does not use advertising or profiling technologies. See our Cookie Policy for detail.
3. Legal basis for processing (GDPR Article 6)
- Consent — Art. 6(1)(a): when you submit the contact form, you consent to us processing your data to answer you. You may withdraw consent at any time.
- Legitimate interest — Art. 6(1)(f): to respond to enquiries, keep the website secure, and understand aggregate usage. We have assessed that this does not override your rights.
- Contract performance — Art. 6(1)(b): where processing is necessary to deliver services you have requested, or to take pre-contractual steps.
- Legal obligation — Art. 6(1)(c): to comply with Luxembourg tax and accounting law and EU regulations.
4. How we use your information
- Respond to your enquiries and provide support.
- Prepare quotes and information about our IT services and SME Package applications.
- Prepare and submit funding dossiers on your behalf, where you have engaged us to do so.
- Comply with legal, tax and accounting obligations.
- Maintain website security and prevent abuse.
We do not use your data for automated decision-making or profiling.
5. Data retention
| Data type | Retention period | Legal basis |
|---|---|---|
| Contact form submissions (non-clients) | 2 years from last contact | Legitimate interest |
| Client data | Duration of service + 7 years | Legal obligation (tax / accounting) |
| Funding dossier documentation | 10 years from submission | Legal obligation (State aid records) |
| Server logs | Up to 12 months | Legitimate interest (security) |
Once the retention period expires, data is securely deleted or anonymised.
6. Data sharing and disclosure
We do not sell, rent or trade your personal data.
6.1 Service providers (data processors)
- Netlify, Inc. (website hosting and form handling) — US-based with EU edge infrastructure. GDPR-compliant under Standard Contractual Clauses.
- Zoho Corporation (business email) — EU data centres. GDPR-compliant, ISO 27001 certified, Standard Contractual Clauses in place.
- Plausible Analytics (website statistics) — EU-owned and EU-hosted. Cookieless and does not collect personal data.
6.2 In the course of a funding application
Where you engage us to prepare an SME Package dossier, information about your company is shared, with your instruction, with the House of Entrepreneurship or eHandwierk, and with the Ministry of the Economy through MyGuichet.lu. Your company remains the applicant and the submitting party.
6.3 Legal requirements
We may disclose data where required by Luxembourg or EU law, a court order, or a competent authority.
6.4 Business transfers
In the event of a merger, acquisition or sale of assets, your data may be transferred. You would be notified and your rights maintained.
7. International data transfers
Your data is primarily stored and processed within the EEA. Where data is transferred outside the EEA, we rely on adequacy decisions or Standard Contractual Clauses, together with technical safeguards such as encryption in transit and at rest.
8. Your rights under the GDPR
- Right of access (Art. 15) — request a copy of your personal data.
- Right to rectification (Art. 16) — correct inaccurate or incomplete data.
- Right to erasure (Art. 17) — the right to be forgotten.
- Right to restriction (Art. 18) — limit how we use your data.
- Right to data portability (Art. 20) — receive a machine-readable export.
- Right to object (Art. 21) — object to legitimate-interest processing or direct marketing.
- Right to withdraw consent (Art. 7(3)) — at any time, without affecting prior processing.
- Right not to be subject to automated decision-making (Art. 22) — we do not use it.
How to exercise your rights
Write to wilson.martins@nosliwit.com or call +352 621 711 642. We respond within 30 days, extendable to 60 for complex requests. There is no charge unless a request is manifestly unfounded or excessive.
9. Data security
Technical measures
- TLS encryption for all data in transit (HTTPS), with HSTS enforced.
- Security headers restricting framing, content sniffing and third-party resource loading.
- No third-party scripts beyond the analytics service named above.
- Role-based access, multi-factor authentication and password policies on all administrative accounts.
- Encrypted backups.
Organisational measures
- Confidentiality agreements with any contractor or partner involved in delivery.
- A documented data breach response procedure.
- Periodic review of security practices.
No method of transmission over the internet is completely secure. Where legally required, we will notify affected individuals and the CNPD of a data breach within 72 hours.
10. Analytics
We use Plausible Analytics to understand how many people visit the site and which pages are useful. It is a privacy-focused, EU-hosted service that:
- sets no cookies and uses no persistent identifiers;
- does not track you across websites or over time;
- collects only aggregated data — page, referrer, country, device type.
No personal data is processed by our analytics, which is why no consent banner is required for it.
11. Records of processing activities
In accordance with Article 30 GDPR, we maintain an internal record of processing activities covering purposes, categories of data subject, recipients, transfers, retention periods and security measures. This record is available to the CNPD on request.
12. Third-party links
This website links to third-party sites, including Guichet.lu, WhatsApp, LinkedIn and Instagram. Their privacy practices are their own — please review their policies before providing personal data.
13. Children's privacy
Our services are directed at businesses and are not intended for individuals under 18. We do not knowingly collect data from children.
14. Data protection impact assessments
Under Article 35 GDPR we conduct a DPIA where processing is likely to result in a high risk to individuals. Our current activities — a contact form and aggregated analytics — do not trigger that threshold. We reassess whenever new processing is introduced.
15. Changes to this policy
We update this policy when our processing, technologies or applicable law change. The "last updated" date at the top always reflects the current version.
16. Contact and complaints
nosliW iT SARL-S
Rue de Strasbourg, 2, L-2560 Luxembourg
wilson.martins@nosliwit.com · +352 621 711 642
You also have the right to lodge a complaint with the Luxembourg supervisory authority:
Commission Nationale pour la Protection des Données (CNPD)
15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg
Phone: (+352) 26 10 60 - 1 · Email: info@cnpd.lu
cnpd.public.lu