Privacy notice
Last updated: 29 September 2026
This notice explains how AcceLUX S.à r.l.-S processes personal data when you visit accelux.ai or contact us by email, in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR").
It does not cover personal data that healthcare providers process with AcceLUX products. That processing is carried out under the control of the healthcare provider and is governed by the contract and data processing terms agreed with that provider.
1. Who is responsible for your data
The controller is AcceLUX S.à r.l.-S, société à responsabilité limitée simplifiée, 15, rue de l'Industrie, L-8069 Bertrange, Luxembourg, R.C.S. Luxembourg B311758.
For any question about your personal data or to exercise your rights, write to [email protected] (subject: "Data protection request") or to the postal address above. We have not appointed a data protection officer, as this is not required for our current activities.
2. What we process, why, and on what legal basis
2.1 Visiting this website
When you open accelux.ai, our hosting and content delivery provider automatically processes technical data needed to deliver the page and protect the site against attacks and abuse: your IP address, date and time of the request, the page requested, browser and device information (user agent) and the referring page.
- Purpose: delivering the website, keeping it secure and available.
- Legal basis: our legitimate interest in operating a secure and reliable website (Article 6(1)(f) GDPR).
- Retention: technical logs are kept by the provider for a short period in line with its security and log retention practices. We do not use them to identify visitors and do not combine them with other data.
2.2 Contacting us by email
If you write to us (for example to request a pilot, to discuss an investment or partnership, or with a general question), we process your name, email address, organisation and role if you provide them, the content of your message and our correspondence with you.
- Purpose: answering your request, taking steps you ask for before a possible contract, and managing our business relationships.
- Legal basis: steps taken at your request before entering into a contract (Article 6(1)(b) GDPR) and our legitimate interest in responding to enquiries and maintaining business contacts (Article 6(1)(f) GDPR).
- Retention: up to 3 years after our last exchange, unless a contract follows. Correspondence linked to a contract is kept for as long as the contract runs and then for the periods required by law (for example 10 years for accounting records under the Luxembourg Commercial Code).
Providing your data is voluntary, but we cannot answer you without your contact details. Please do not include patient data or other health information in emails to us.
3. Cookies
We do not set any cookies and we do not use analytics, advertising or social media tracking tools on this website.
Our hosting provider may place a strictly necessary security cookie (for example __cf_bm) to tell humans apart from malicious bots. Such cookies are exempt from consent under Article 4(3)(e) of the amended Luxembourg Law of 30 May 2005 on privacy in electronic communications, as they are strictly necessary to provide the service you request.
4. Who receives your data
We do not sell your personal data. We only share it with service providers that process it on our behalf and under our instructions (processors):
| Provider | Service | Location and safeguards |
|---|---|---|
| Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA | Website hosting and content delivery (Cloudflare Pages) | Global network, including the USA. Transfers rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework and on the European Commission's standard contractual clauses. |
| Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland | Business email (Google Workspace) | Ireland (EU). Google may process data in other countries, including the USA; such transfers rely on the EU-US Data Privacy Framework and on the European Commission's standard contractual clauses. |
We may also disclose data where we are legally required to do so, for example to public authorities, or to our professional advisers (such as accountants or lawyers) who are bound by confidentiality.
5. Links to other websites
Our website links to external sites such as LinkedIn. We do not embed their content or tracking; when you follow such a link, the other site's privacy policy applies.
6. Automated decisions
We do not make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects for you.
7. Your rights
Under the GDPR you have the right to:
- access your personal data and receive a copy (Article 15);
- have inaccurate data corrected (Article 16);
- have your data erased (Article 17);
- restrict the processing of your data (Article 18);
- receive your data in a portable format (Article 20);
- object at any time to processing based on our legitimate interests, on grounds relating to your particular situation (Article 21).
To exercise these rights, contact us at [email protected]. We will reply within one month. We may ask you to confirm your identity.
You also have the right to lodge a complaint with a supervisory authority. In Luxembourg this is the Commission nationale pour la protection des données (CNPD), 15, boulevard du Jazz, L-4370 Belvaux, cnpd.public.lu.
8. Security
We use appropriate technical and organisational measures to protect personal data, including encrypted connections (HTTPS) to this website and access controls on our email accounts.
9. Changes to this notice
We may update this notice when our activities or the law change. The date at the top shows the latest version.