Privacy & Data Protection Notice
This notice explains what personal data I collect through my website and in connection with enquiries about my work as an independent non-executive director, board adviser, speaker and trainer — why I collect it, what I do with it, how long I keep it, and what rights you have. It is provided in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and the Luxembourg Law of 1 August 2018.
Who is responsible for your personal data
I am the controller of the personal data described in this notice, which means I decide why and how it is processed.
- Controller
- Katia Ciesielska, acting as an independent professional (independent non-executive director and consultant)
- Professional address
- 28 rue de Hobscheid, L-8422 Steinfort, Luxembourg
- Telephone
- +352 621 704 504
- Website
- www.katiaciesielska.com
I have not appointed a data protection officer. My activity does not meet the criteria in Article 37 GDPR that make a DPO mandatory: I am not a public authority, my core activity is not large-scale regular and systematic monitoring of individuals, and it does not involve large-scale processing of special categories of data. You can raise any data protection question with me directly, using the contact details above.
What this notice does — and does not — cover
This notice covers personal data I process in my own name: through this website, through enquiries and correspondence sent to me, and in the course of advisory, speaking and training engagements I accept personally. It does not cover:
Personal data I handle as a board member. When I act as a director, board member or committee member of a company, fund, general partner, association or other entity, that entity is the controller of the personal data processed in that context, and its own privacy notice applies — not this one.
Personal data I handle in regulated compliance roles. Where I act as an AML/CFT officer (RC / RR) or in a similar function for a supervised entity, the supervised entity is the controller and its notice applies.
Personal data I handle as an employee. Data processed in the course of an employed or in-house role belongs to that employer as controller.
Third-party platforms. LinkedIn, publishers, event organisers and similar third parties process data under their own notices when you interact with them, even where you reach them through a link on this site.
The personal data I collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Contact and enquiry data | Your name, email address, telephone number, organisation, and the content of your message | The website contact form; email, telephone, LinkedIn or in person |
| Professional background data | Your role, employer, board positions, professional biography, and publicly available information relevant to an enquiry or mandate | You; public sources (see section 4) |
| Engagement data | Correspondence, engagement or appointment documentation, meeting notes, invoicing and payment details | You and your organisation |
| Speaking and training data | Event details, audience information, the biography and photograph you ask me to use, and session materials | You or the event organiser |
| Technical data | IP address, browser and device type, operating system, referring page, pages viewed and timestamps | Collected automatically by the web server and by strictly necessary cookies (see section 9) |
I do not ask for special categories of personal data under Article 9 GDPR (such as data revealing health, political opinions or trade union membership) or data relating to criminal convictions. Please do not include confidential, price-sensitive or sensitive personal information in the website contact form — use email or telephone for anything of that nature.
Where the data comes from
Most of the personal data I hold comes directly from you. In addition, where I am considering an enquiry, a mandate or an engagement, I may consult publicly available sources — the Luxembourg Trade and Companies Register (RCS) and equivalent registers in other jurisdictions, official gazettes, regulatory registers, company websites, LinkedIn and the professional press.
I use those sources only to verify professional information, to understand the structure and ownership of an entity, and to carry out the independence and conflict-of-interest checks that my role requires before I accept a mandate.
Why I use your data, and on what legal basis
| Purpose | Data used | Legal basis (Article 6 GDPR) |
|---|---|---|
| Responding to your enquiry and discussing a possible mandate, engagement, speaking slot or training | Contact and enquiry data; professional background data | 6(1)(b) — steps taken at your request before entering a contract; and 6(1)(f) — my legitimate interest in responding to professional enquiries |
| Carrying out independence, conflict-of-interest and, where applicable, know-your-client checks before accepting a mandate | Professional background data; publicly available register data | 6(1)(f) — legitimate interest in a properly documented acceptance process; and 6(1)(c) — compliance with the duties applicable to directors under Luxembourg law |
| Performing an advisory, speaking or training engagement, and managing the relationship | Engagement data; contact data | 6(1)(b) — performance of a contract |
| Invoicing, accounting, tax and record-keeping | Engagement and billing data | 6(1)(c) — legal obligation |
| Operating, maintaining and securing the website, and preventing abuse | Technical data; strictly necessary cookies | 6(1)(f) — legitimate interest in a secure and functioning website |
| Sending occasional professional updates or articles where you have asked to receive them | Contact data | 6(1)(a) — your consent, withdrawable at any time |
| Establishing, exercising or defending legal claims | Any of the above, as relevant | 6(1)(f) — legitimate interest in protecting my legal position |
Where I rely on legitimate interests, I have considered whether those interests are overridden by your interests, rights and freedoms, and concluded that they are not. You can object to processing based on legitimate interests at any time — see section 10.
Providing your data is not a statutory requirement. However, if you do not give me your name and contact details, I will not be able to respond to your enquiry or accept an engagement.
Who has access to your data
I do not sell personal data, I do not share it for advertising purposes, and I do not disclose the substance of enquiries to third parties other than as set out below.
| Recipient | Role | Purpose and location |
|---|---|---|
| Hostinger International, Ltd — 61 Lordou Vironos Street, 6023 Larnaca, Cyprus | Processor | Website hosting, server logs and backups. Servers within the EU/EEA. |
| Google Ireland Limited — Google Workspace | Processor | Email correspondence, calendar and document storage. |
| Google Ireland Limited — reCAPTCHA | Processor | Spam protection on the contact form; loaded only on pages that carry the form. See section 9. |
| My accountant, tax adviser and legal adviser | Processor or independent controller | Accounting, tax filings and legal advice. Luxembourg. |
| Event organisers, training providers and publishers | Independent controllers | Where your enquiry concerns an event or publication they run. |
| Public authorities, regulators and courts | Independent controllers | Only where I am required to disclose by law, or where disclosure is necessary to establish or defend a legal claim. |
All processors act on my documented instructions under a written contract that meets Article 28 GDPR.
Transfers outside the European Economic Area
The website is hosted within the EU/EEA and, as a rule, your data stays there. Some of the providers listed above are part of international groups and may process limited data outside the EEA, principally in the United States.
Where that happens, the transfer is covered by one of the safeguards in Chapter V GDPR: an adequacy decision of the European Commission (including the EU–US Data Privacy Framework, where the recipient is certified under it), or the European Commission’s Standard Contractual Clauses together with any additional measures required. You can ask me for a copy of the relevant safeguard at any time.
How long I keep it
| Data | Retention period |
|---|---|
| Enquiries that do not lead to an engagement | 12 months from our last contact, then deleted |
| Enquiries that do lead to an engagement | For the duration of the engagement, and then as set out below |
| Engagement, appointment and accounting records | 10 years from the end of the financial year concerned, in line with Luxembourg commercial and tax record-keeping requirements |
| Correspondence of continuing professional relevance | For as long as the professional relationship continues, and 3 years thereafter |
| Website contact form submissions (stored in the site database) | Kept with the corresponding enquiry and deleted on the same schedule; you can ask me to delete a submission at any time |
| Website server logs | As retained by my hosting provider — typically a short rolling period for security and diagnostics |
| Cookies | As set out in section 9. The site uses only strictly necessary cookies, which are session- or short-lived |
| Data relevant to an actual or threatened legal claim | Until the claim is resolved and the applicable limitation period has expired |
At the end of the applicable period, data is deleted or irreversibly anonymised.
Cookies and similar technologies
The website runs on WordPress with the Elementor page builder and a caching plugin. It sets only strictly necessary cookies. It does not use analytics, measurement, advertising or profiling cookies, and there is no consent banner because none is required for the cookies described here.
Strictly necessary cookies. Where cookies are set — for example by WordPress, Elementor or the caching plugin — they exist only to keep the site working: session handling, security and page caching. Under the amended Luxembourg Law of 30 May 2005 on privacy in the electronic communications sector, these do not require your consent because they are strictly necessary to deliver the service you requested. Browsing the site as an ordinary visitor, without submitting the contact form, sets no cookie that identifies you.
Fonts are served locally. The site’s typefaces are hosted on this website and are not loaded from Google’s servers, so opening a page does not transmit your IP address to a font provider.
Contact form and spam protection. The contact form is protected by Google reCAPTCHA, which distinguishes genuine enquiries from automated abuse. On a page that carries the form, reCAPTCHA is loaded from Google, may set a cookie in your browser and transmits technical data — including your IP address — to Google for that security purpose. This is necessary for the security of the form; Google acts as a provider, any transfer outside the EEA is covered by the safeguards in section 7, and Google’s own privacy policy governs its use of that data. If you would prefer not to use reCAPTCHA, you can reach me by email or telephone instead.
You can block or delete cookies through your browser settings, and most browsers let you refuse third-party cookies specifically. Blocking strictly necessary cookies may stop parts of the site from working.
Your rights
Under the GDPR you have the following rights in relation to your personal data.
- Access (Article 15) — to be told whether I hold data about you and to receive a copy of it.
- Rectification (Article 16) — to have inaccurate data corrected and incomplete data completed.
- Erasure (Article 17) — to have data deleted where one of the grounds in the GDPR applies.
- Restriction (Article 18) — to have processing paused while a dispute about accuracy or lawfulness is resolved.
- Portability (Article 20) — to receive data you gave me in a structured, machine-readable format, where processing is based on consent or contract and carried out by automated means.
- Objection (Article 21) — to object to processing based on legitimate interests, on grounds relating to your situation. Where processing is for direct marketing, the right to object is absolute.
- Withdrawal of consent (Article 7(3)) — to withdraw consent at any time, without affecting processing carried out before withdrawal.
- Automated decision-making (Article 22) — I do not take decisions about you by automated means and I do not carry out profiling.
To exercise any of these rights, email me at katia@katiaciesielska.com. I will respond within one month of receiving your request, and will tell you if I need to extend that by up to two further months because the request is complex (Article 12(3) GDPR). I may need to ask for information to confirm your identity. There is no charge, unless a request is manifestly unfounded or excessive.
If you are not satisfied with how I have handled your data, you have the right to lodge a complaint with the Luxembourg supervisory authority:
- Authority
- Commission nationale pour la protection des données (CNPD)
- Address
- 15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg
- Telephone
- (+352) 26 10 60 - 1
- Website
- www.cnpd.public.lu
You may also complain to the supervisory authority of the EU member state where you live or work, or where you believe an infringement took place.
Security
I take appropriate technical and organisational measures to protect personal data, proportionate to the risk. These include encrypted transmission of the website over HTTPS/TLS, the security measures maintained by my hosting and email providers, password protection and device encryption, access limited to me and — where strictly necessary — my professional advisers, and prompt deletion of data once its retention period has ended.
No method of transmission over the internet is entirely secure. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, I will notify you and the CNPD as required by Articles 33 and 34 GDPR.
Children
This website is directed at professional audiences and is not intended for children. I do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided me with personal data, please contact me and I will delete it.
External links and social media
This site links to third-party websites, including LinkedIn, publications I write for and organisations I am associated with. I have no control over their content or their handling of personal data, and this notice does not apply to them. Please read their own privacy notices before providing them with personal data.
Changes to this notice
I review this notice periodically and will update it when my processing changes or when the law requires. The version number and date at the top of this page always show the current version. If a change materially affects you and we have an ongoing relationship, I will tell you directly.
Contact
Any question about this notice, or about how I handle personal data, can be sent to katia@katiaciesielska.com or raised by telephone on +352 621 704 504.