Privacy policy.
How Kramer Consulting SARL-S handles your personal data — what we process, why, who we share it with, and the rights you hold under the GDPR.
1. Who we are
Kramer Consulting SARL-S is a Luxembourg-registered consultancy providing EU regulatory advisory, learning and development, and project management services.
| Detail | Information |
|---|---|
| Legal name | Kramer Consulting SARL-S |
| Registration | RCS Luxembourg B284903 |
| VAT number | LU35729347 |
| Registered address | 18, rue du Nord, L-7242 Helmsange, Grand Duchy of Luxembourg |
| Role under GDPR | Data controller (Article 4(7) GDPR) |
| Privacy contact | [email protected] |
| Data Protection Officer | Not appointed — scale and processing type do not trigger the Art. 37 GDPR requirement |
2. How we obtain personal data
We collect personal data in the following ways:
- Direct contact: proposal requests, consultancy enquiries, and email or telephone correspondence
- Service delivery: workshop, webinar, or training event attendance
- Website interaction: browsing kramerconsulting.lu or tomaszkramer.com via standard web technologies
- Booking: scheduling a meeting or call via our online booking tool (Calendly)
- Professional networking: LinkedIn and similar platform interactions where you engage with our content or contact us directly
- Marketing: voluntary subscription to our mailing list or download of a lead magnet (when active)
3. Categories of personal data we process
| Category | Examples |
|---|---|
| Identity and contact | Name, job title, organisation, email address, telephone number, postal address |
| Professional information | Sector, project role, areas of interest, training attendance records |
| Contract and billing | Purchase orders, VAT numbers, invoice references, bank transfer details |
| Marketing preferences | Mailing list subscription status, email engagement (when active) |
| Website usage | IP address, browser type, pages visited, session duration (aggregated and anonymised where possible) |
| Booking data | Meeting preferences, scheduling information collected via Calendly |
| Testimonials and endorsements | First name, surname, role or organisation, your quote, an optional photograph, an optional email address, and any private feedback you submit via our testimonials form |
We do not intentionally collect special-category personal data (Article 9 GDPR), including health data, biometric data, political opinions, or religious beliefs. Please do not send us such data unless we have specifically requested it for a defined purpose.
4. Legal bases for processing
| Legal basis | When we rely on it |
|---|---|
| Contract (Art. 6(1)(b)) | Preparing, performing, or managing a consultancy or training services contract |
| Legitimate interests (Art. 6(1)(f)) | CRM maintenance and contact management; follow-up communications with existing clients and prospects; fraud prevention; AI-assisted business operations (see Section 6) |
| Legal obligation (Art. 6(1)(c)) | Luxembourg tax, accounting, and commercial law compliance (10-year retention obligation) |
| Consent (Art. 6(1)(a)) | Voluntary mailing list subscription; non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing. |
5. Purposes for which we use your data
- Service delivery: preparing proposals, delivering workshops and training, producing reports and deliverables
- Client relationship management: follow-up communications, scheduling, and project coordination
- Financial and compliance: invoicing, bookkeeping, tax filings, and audit records
- Marketing and thought leadership: newsletters, event invitations, and LinkedIn outreach (when active; consent-based)
- Security and fraud prevention: protecting our systems and clients from unauthorised access or misuse
- AI-assisted business operations: see Section 6 for full disclosure
6. AI-assisted processing
Kramer Consulting uses AI tools to support internal business operations, including drafting, research, and workflow automation. We are transparent about this use and apply strict data hygiene rules.
Tools in use
| Tool | Provider | Purpose | Personal data involved? | Safeguard |
|---|---|---|---|---|
| Claude / Claude Code | Anthropic (US) | AI-assisted drafting, research, and internal automation. Integration provides limited access to business email, calendar, and Drive for workflow support. | Business correspondence metadata; no client personal data entered without pseudonymisation | Anthropic API terms and Data Processing Agreement; SCCs for international transfer |
| ChatGPT | OpenAI (US) | General research and capability demonstrations only | No personal data or client-confidential content entered — consumer tier policy only | OpenAI training opt-out confirmed; no DPA — consumer use only |
We do not enter client personal data, special-category data, or confidential client documents into AI tools without pseudonymisation. Outputs from AI tools are always reviewed by a human before use in any client-facing deliverable.
7. Data sharing and third-party processors
We share personal data only where necessary. The following third-party processors and service providers may process data on our behalf:
| Vendor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Cloudflare, Inc. (Cloudflare Pages) | Website hosting, content delivery, and cookieless analytics (Cloudflare Web Analytics) | US | Cloudflare Data Processing Addendum; SCCs |
| Google Workspace (incl. Gemini) | Email, calendar, document storage, and AI-assisted productivity | EU (primary); Google infrastructure (US parent) | Google Workspace Data Processing Amendment; SCCs |
| Calendly | Meeting scheduling and booking | US | SCCs; DPA in Calendly terms |
| Asana (free tier) | Internal task management — no client personal data stored | US | SCCs |
| GitHub (private repositories) | Code and document version control — internal use only | US (Microsoft) | Microsoft SCCs |
| External accountant | Financial reporting, tax filings, audit support | Luxembourg | Article 28 GDPR contract in place |
| myGuichet.lu | Invoicing and official business filings | Luxembourg (government) | Not applicable — Luxembourg public authority |
We do not sell personal data to third parties. We do not share personal data with any third party for their own marketing purposes.
We may disclose personal data where required by law, court order, or regulatory authority, or where necessary to protect the rights, safety, or property of Kramer Consulting, our clients, or others.
8. International data transfers
Our primary data storage is within the European Economic Area. Some of our service providers are based in the United States. Where personal data is transferred outside the EEA, we ensure adequate safeguards are in place, primarily through Standard Contractual Clauses (SCCs) approved under Article 46 GDPR. Details of the safeguards used for each vendor are set out in Section 7. Copies of relevant safeguards are available upon request at [email protected].
9. Retention periods
| Data category | Retention period | Basis |
|---|---|---|
| Contract and billing records | 10 years from end of fiscal year | Luxembourg Commercial Code and tax law |
| Client project files and deliverables | 7 years from project closure | Legitimate interests — audit and dispute resolution |
| Raw client working data (non-deliverable) | Deleted within 30 days of project closure | Data minimisation principle — Art. 5(1)(e) GDPR |
| Prospective client data (no engagement) | 3 years after last meaningful contact | Legitimate interests — proportionate CRM |
| Mailing list subscription data | Until unsubscribe or 2 years of inactivity | Consent — withdrawn on request |
| Training attendance records | 5 years | Ministry of Education accreditation requirements |
| Website analytics | Aggregated and cookieless; no per-visitor profile retained | Legitimate interests — service improvement |
10. Your rights under the GDPR
You have the following rights in relation to your personal data under GDPR Articles 15–22:
| Right | What it means |
|---|---|
| Access (Art. 15) | Request a copy of the personal data we hold about you |
| Rectification (Art. 16) | Ask us to correct inaccurate or incomplete data |
| Erasure (Art. 17) | Ask us to delete your data where there is no lawful basis for continued processing |
| Restriction (Art. 18) | Ask us to pause processing while a dispute is resolved |
| Portability (Art. 20) | Receive your data in a structured, commonly used, machine-readable format |
| Object (Art. 21) | Object to processing based on legitimate interests, including direct marketing |
| Withdraw consent (Art. 7(3)) | Withdraw consent at any time for consent-based processing (e.g. mailing list); withdrawal does not affect prior lawful processing |
To exercise any of these rights, please contact us at [email protected]. We will respond within one calendar month. We may request verification of your identity before acting on a request. No fee applies unless a request is manifestly unfounded or excessive.
Right to complain
You have the right to lodge a complaint with the Luxembourg supervisory authority, the Commission nationale pour la protection des données (CNPD): 15, boulevard du Jazz, L-4370 Belvaux, Luxembourg — www.cnpd.lu · [email protected] · +352 26 10 60 1.
11. Security measures
We implement appropriate technical and organisational security measures proportionate to the risk, including:
- TLS encryption for all web traffic and email transmission
- Multi-factor authentication (MFA) for all cloud services
- Least-privilege access controls — access granted only to those who need it
- Annual security review of tools, access rights, and vendor DPA status
- AI data hygiene rules — pseudonymisation applied before any business data is processed by AI tools
No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to following industry best practice and reviewing our measures regularly.
12. Cookies
Our websites set no cookies and embed no third-party trackers, advertising pixels or social-media widgets. Traffic measurement uses Cloudflare Web Analytics, which is cookieless and stores no identifier on your device — so no consent banner is required.
13. Testimonials and endorsements
If you attend one of our seminars, you may choose to share a testimonial through our feedback form at kramerconsulting.lu/share. Completing that form is entirely voluntary.
- The data you provide: your first name, surname, role or organisation, your quote, and — if you choose — a photograph and an email address.
- A separate feedback field, clearly marked for internal use only: comments left there are used solely to improve our seminars and are never published.
- Your submission is stored within Google Workspace (see Section 7); we add no other processor.
We rely on your consent (Article 6(1)(a) GDPR) to process and to publish your testimonial. Publication of your name, your words and any photograph on our website and in marketing materials takes place only where you have given the specific consent requested on the form. You may withdraw your consent and ask us to remove a published testimonial at any time by writing to [email protected]; withdrawal does not affect processing carried out before your request.
We keep published testimonials for as long as they are displayed, and remove them on request. Submissions we do not publish are reviewed and deleted within 12 months. Any photograph is stored with the submission and deleted on the same basis.
14. Changes to this policy
We may update this policy to reflect changes in law, technology, or our business practices. The current version is always available at kramerconsulting.lu/privacy. The effective date below indicates when the current version was last updated. Previous versions are archived internally for accountability purposes.
15. Contact
For any questions about this policy, to exercise your rights, or to raise a concern about how we handle your data: [email protected] — Kramer Consulting SARL-S, 18, rue du Nord, L-7242 Helmsange, Luxembourg.
Legal references
- Regulation (EU) 2016/679 (GDPR), OJ L 119, 4 May 2016
- GDPR Article 9(1) — special categories of personal data
- Code de commerce (Luxembourg) — 10-year accounting retention obligation
- Luxembourg law of 1 August 2018 on the organisation of the CNPD and the general data protection framework