Privacy Policy
How NSA Luxembourg collects, uses, protects and manages your personal data — in full compliance with the General Data Protection Regulation (GDPR).
Manage Your Data
Update your payment details, view invoices, or cancel your subscription at any time through our secure Stripe portal.
Data Controller
NSA Luxembourg ASBL (Nursing Student Association Luxembourg), registered in the Grand Duchy of Luxembourg, is the controller of the personal data collected through this website and its services.
Registered address: 2, Rue Thomas Edison, L-1445 Strassen, Luxembourg
Contact: contact@nsaluxembourg.lu
Information We Collect
We collect personal information that you provide directly to us when using our services:
- Full name, email address and phone number (membership registration)
- Postal address (when required for official correspondence)
- Payment information (processed securely by Stripe — we do not store card details)
- Professional information such as your nursing programme, specialisation and institution
- Event registration details and preferences
- Any additional information you voluntarily share through contact forms or email
We do not collect any data automatically through cookies or tracking technologies on this website.
How We Use Your Information
Your personal data is used exclusively for the following purposes:
- Processing and managing your membership with NSA Luxembourg
- Registering you for events and General Assemblies
- Communicating association updates, news and event invitations
- Processing payments and donations through Stripe
- Fulfilling our legal obligations as an ASBL under Luxembourg law
- Responding to your enquiries and providing support
We will never sell, rent, or share your personal data with third parties for marketing purposes.
Legal Basis
We process your personal data on the following legal grounds under the GDPR:
- Contractual necessity — to fulfil our obligations related to your membership
- Legitimate interest — to communicate with members and manage association activities
- Legal obligation — to comply with Luxembourg's law of 7 August 2023 on non-profit associations
- Consent — where you have explicitly opted in to receive specific communications
Third-Party Services
We use the following third-party services to operate our association:
- Stripe — secure payment processing (membership, donations, events). PCI-DSS compliant. We never store card details.
- Microsoft Power Pages — website hosting and content management
- Moovijob — job listing feeds on our Internship Offers page. Clicking a listing redirects you to their platform.
We do not use Google Analytics, Facebook Pixel, or any advertising or behavioural tracking tools.
Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. These include encrypted connections (HTTPS), access controls limited to board members, and secure third-party payment processing.
While we take all reasonable precautions, no method of electronic transmission or storage is completely secure. Contact us immediately if you suspect any unauthorised use of your data.
Data Retention
We retain your personal data only for as long as necessary:
- Membership data — duration of membership plus 12 months after expiry
- Financial records — 10 years as required by Luxembourg accounting law
- Event registrations — 12 months after the event
- Contact form submissions — 6 months after the enquiry is resolved
After these periods, your data is securely deleted or anonymised.
Your Rights
Under the GDPR, you have the following rights:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — request correction of inaccurate or incomplete data
- Right to erasure — request deletion of your data ("right to be forgotten")
- Right to restriction — request that we limit the processing of your data
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interest
- Right to withdraw consent — at any time, without affecting prior processing
To exercise any of these rights, contact us at contact@nsaluxembourg.lu. We will respond within 30 days.
You also have the right to lodge a complaint with the Commission Nationale pour la Protection des Données (CNPD) — Luxembourg's data protection authority.
Changes to This Policy
We may update this Privacy Policy from time to time. Any updates will be published on this page with a revised date below. We encourage you to review this page periodically.
Need more information?
If you have any questions about this privacy policy or how we handle your personal data, we are happy to help.
contact@nsaluxembourg.lu
