Privacy Policy — NSA Luxembourg
PRIVACY
Home Privacy Policy

Privacy Policy

How NSA Luxembourg collects, uses, protects and manages your personal data — in full compliance with the General Data Protection Regulation (GDPR).

Scroll

Manage Your Data

Update your payment details, view invoices, or cancel your subscription at any time through our secure Stripe portal.

Edit My Information
01

Data Controller

NSA Luxembourg ASBL (Nursing Student Association Luxembourg), registered in the Grand Duchy of Luxembourg, is the controller of the personal data collected through this website and its services.

Registered address: 2, Rue Thomas Edison, L-1445 Strassen, Luxembourg

Contact: contact@nsaluxembourg.lu

02

Information We Collect

We collect personal information that you provide directly to us when using our services:

  • Full name, email address and phone number (membership registration)
  • Postal address (when required for official correspondence)
  • Payment information (processed securely by Stripe — we do not store card details)
  • Professional information such as your nursing programme, specialisation and institution
  • Event registration details and preferences
  • Any additional information you voluntarily share through contact forms or email

We do not collect any data automatically through cookies or tracking technologies on this website.

03

How We Use Your Information

Your personal data is used exclusively for the following purposes:

  • Processing and managing your membership with NSA Luxembourg
  • Registering you for events and General Assemblies
  • Communicating association updates, news and event invitations
  • Processing payments and donations through Stripe
  • Fulfilling our legal obligations as an ASBL under Luxembourg law
  • Responding to your enquiries and providing support

We will never sell, rent, or share your personal data with third parties for marketing purposes.

04

Legal Basis

We process your personal data on the following legal grounds under the GDPR:

  • Contractual necessity — to fulfil our obligations related to your membership
  • Legitimate interest — to communicate with members and manage association activities
  • Legal obligation — to comply with Luxembourg's law of 7 August 2023 on non-profit associations
  • Consent — where you have explicitly opted in to receive specific communications
05

Third-Party Services

We use the following third-party services to operate our association:

  • Stripe — secure payment processing (membership, donations, events). PCI-DSS compliant. We never store card details.
  • Microsoft Power Pages — website hosting and content management
  • Moovijob — job listing feeds on our Internship Offers page. Clicking a listing redirects you to their platform.

We do not use Google Analytics, Facebook Pixel, or any advertising or behavioural tracking tools.

06

Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. These include encrypted connections (HTTPS), access controls limited to board members, and secure third-party payment processing.

While we take all reasonable precautions, no method of electronic transmission or storage is completely secure. Contact us immediately if you suspect any unauthorised use of your data.

07

Data Retention

We retain your personal data only for as long as necessary:

  • Membership data — duration of membership plus 12 months after expiry
  • Financial records — 10 years as required by Luxembourg accounting law
  • Event registrations — 12 months after the event
  • Contact form submissions — 6 months after the enquiry is resolved

After these periods, your data is securely deleted or anonymised.

08

Your Rights

Under the GDPR, you have the following rights:

  • Right of access — request a copy of the personal data we hold about you
  • Right to rectification — request correction of inaccurate or incomplete data
  • Right to erasure — request deletion of your data ("right to be forgotten")
  • Right to restriction — request that we limit the processing of your data
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interest
  • Right to withdraw consent — at any time, without affecting prior processing

To exercise any of these rights, contact us at contact@nsaluxembourg.lu. We will respond within 30 days.

You also have the right to lodge a complaint with the Commission Nationale pour la Protection des Données (CNPD) — Luxembourg's data protection authority.

09

Changes to This Policy

We may update this Privacy Policy from time to time. Any updates will be published on this page with a revised date below. We encourage you to review this page periodically.

Last updated: March 2026
Questions?

Need more information?

If you have any questions about this privacy policy or how we handle your personal data, we are happy to help.

contact@nsaluxembourg.lu