Privacy Policy
Last updated: June 2026
1. Introduction
Phi-NEXT ("we", "us", "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect information about you when you visit phi-next.lu (the "Site") or engage with our services.
This policy is issued in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and applicable Luxembourg data protection law. The supervisory authority for data protection in Luxembourg is the Commission Nationale pour la Protection des Données (CNPD), 15 Boulevard du Jazz, L-4370 Belvaux — cnpd.public.lu.
2. Data Controller
Phi-NEXT — Mouncef Mahlaoui
Luxembourg
Email: contact@phi-next.lu
As this is a sole proprietorship with no formal Data Protection Officer (DPO) designation threshold triggered, data protection enquiries may be directed to the data controller at the contact details above.
3. Data We Collect
We collect the following categories of personal data, depending on your interaction with the Site:
- Contact data — name, email address, phone number, company name, message content — when you use the contact form or send us an email;
- Usage data — IP address, browser type, operating system, pages visited, time of visit, referring URL — collected automatically when you browse the Site;
- Cookie preference data — your acceptance or refusal of non-essential cookies, stored locally.
We do not collect special categories of personal data (as defined in Article 9 GDPR) and we do not knowingly collect data from individuals under the age of 16.
4. Legal Basis for Processing
We process your personal data on the following legal bases:
- Legitimate interests (Article 6(1)(f) GDPR) — for analysing Site usage, improving our services, and responding to professional enquiries. Our legitimate interest is to operate and improve a professional business website.
- Consent (Article 6(1)(a) GDPR) — for non-essential cookies and analytics, where you have given explicit consent via the cookie banner.
- Contract performance (Article 6(1)(b) GDPR) — for processing data necessary to respond to enquiries and fulfil service engagements.
- Legal obligation (Article 6(1)(c) GDPR) — where we are required to retain or disclose data under Luxembourg or EU law.
5. How We Use Your Data
We use the personal data we collect to:
- Respond to your enquiries and correspond with you about potential or ongoing engagements;
- Provide, administer, and improve our professional services;
- Analyse Site traffic and usage patterns to improve performance and content;
- Comply with legal and regulatory obligations;
- Prevent fraud and protect the security of the Site.
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
6. Data Sharing
We may share your data with the following categories of recipients, strictly as necessary:
- Hosting and infrastructure providers — to operate and maintain the Site;
- Email and communication services — to deliver and manage correspondence;
- Legal and regulatory authorities — when required by law or court order.
Any third-party processors we engage are bound by data processing agreements in accordance with Article 28 GDPR and are required to process data only on our documented instructions.
7. International Transfers
Where we transfer personal data outside the European Economic Area (EEA), we ensure adequate safeguards are in place in accordance with Chapter V GDPR — including reliance on adequacy decisions or Standard Contractual Clauses (SCCs) as appropriate.
8. Retention
We retain personal data only for as long as necessary for the purposes set out in this policy:
- Contact form submissions and correspondence — up to 3 years from last contact, unless an engagement arises (in which case engagement records are retained for 10 years for accounting and legal compliance purposes);
- Usage and analytics data — up to 13 months;
- Cookie consent records — up to 13 months from date of consent or refusal.
9. Your Rights
Under the GDPR, you have the following rights with respect to your personal data:
- Right of access — to obtain a copy of the personal data we hold about you;
- Right to rectification — to have inaccurate or incomplete data corrected;
- Right to erasure — to request deletion of your data where there is no legitimate reason for us to continue processing it;
- Right to restriction of processing — to ask us to restrict processing in certain circumstances;
- Right to data portability — to receive your data in a structured, machine-readable format;
- Right to object — to object to processing based on legitimate interests;
- Right to withdraw consent — where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at contact@phi-next.lu. We will respond within one month of receipt. You also have the right to lodge a complaint with the CNPD at any time.
10. Cookie Policy
This Site uses cookies — small text files placed on your device — to ensure essential functionality and to understand how visitors use the Site.
Essential cookies (no consent required)
phi_next_consent— stores your cookie consent preference (accept/decline). Duration: 365 days (accept) or 30 days (decline). No personal data leaves your browser.
Analytics and performance cookies (consent required)
Where you have consented via the cookie banner, we may use third-party analytics tools to collect aggregated, anonymised information about Site usage (pages visited, time on page, referral source). If you have declined or not yet responded to the cookie banner, these tools are not activated.
No third-party advertising or tracking cookies are used on this Site.
Managing your cookie preferences
You may withdraw your consent at any time by clearing your browser cookies or adjusting your browser settings to block cookies. Please note that disabling essential cookies may affect Site functionality. Most browsers allow you to review, block, or delete cookies via their settings.
11. Security
We implement appropriate technical and organisational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These include TLS encryption in transit and access controls on stored data.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify you and the CNPD in accordance with GDPR Articles 33 and 34.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Material changes will be signalled by updating the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
13. Contact
For any questions, requests, or complaints relating to this Privacy Policy or your personal data, please contact:
Email: contact@phi-next.lu
If you are not satisfied with our response, you have the right to lodge a complaint with the CNPD: cnpd.public.lu.