Nexxtlab Privacy Policy

General

The Nexxtlab Privacy Policy (Nexxtlab SA, 12 avenue du Swing 4367 Belval Luxembourg) is designed to inform you about what personal data we collect about you, why and how you have control over it. NEXXTLAB is responsible for the processing of your personal data and treats it in accordance with the regulations on the protection of personal data and electronic communications. We treat your personal data as confidential information.

NEXXTLAB may also process your personal data as a subcontractor for one of its partners, who in this case is responsible for the processing. In this case we refer to the privacy policy of the partner in question.

This Privacy Policy applies to our customers (current, former and future), all visitors to Nexxtlab’s website(s) and mobile application(s) (“apps”), and all other persons who contact us.

If you have any questions about the processing of your personal data, you can contact us at data.protection@nexxtlab. lu or by mail at the company’s headquarters.

What personal data?

The personal data collected by NEXXTLAB consists, on the one hand, of the personal data you provide yourself on the various pages of our website(s) and apps, as well as the personal data we obtain through your use of our website(s) and apps, and through your use of our products and services. On the other hand, Nexxtlab’s Privacy Policy also covers personal data that you provide to us through other channels such as our contact centres, response forms, contractual documents, or through our partners.

We collect the following categories of personal data:

  • Identification data: such as your surname, first name, date of birth, identity card number, e-mail address and the IP address of your PC, tablet or smartphone, your voice recordings.
  • Contractual data: such as which contracts you have concluded with NEXXTLAB, the start and end date of these, the price and any indexation parameters.
  • Consumption and billing data: such as your electricity and/or natural gas consumption and data about your payment history.
  • Transactional data: e.g. change of supplier, move, meter replacement.
  • Technical data: e.g. what type of heating system you have, whether your house is insulated or not, the year of construction of your house, whether you have solar panels or not.
  • Data about your use of our products and services: such as how you use our online services to track your electricity and/or natural gas consumption.

Why do we process your personal data?

We process your personal data for the following reasons:

The management and execution of your request for a Nexxtlab offer or your contract(s) with NEXXTLAB;

The management of our website and apps (including the management of the customer area of our website and the management of access to it);

In some cases, to inform you about Nexxtlab’s, our affiliates’ and partners’ products and services, promotions and special offers, which we believe may be of interest to you;

This always concerns products and services related to energy and energy efficiency (e.g. related to heating, energy storage and green mobility), and may also concern energy products and services of our partners (e.g. related to insulation, solar panels).

If you are a business customer, this may also include products and services related to technical installations and/or infrastructure.

Combining data with each other, for example, to determine your credit risks or to tailor our products and services, promotions and special actions to your personal needs;

Monitoring, evaluation and continuous improvement of our products and services, promotions and special actions. For example, you may receive an invitation to take part in general or specific market research, if you wish, on an anonymous basis;

Monitoring and improving your interactions with us, our internal processes and the quality of service provided by our contact centres. To this end, we may record and access records of your electronic communications (such as telephone conversations, chat, emails) and data relating to those communications;

The protection of the rights, property or safety of Nexxtlab, its customers or third parties (including the fight against fraud, the management of disputes or legal proceedings);

Managing Nexxtlab’s legal or regulatory obligations;

Nexxtlab’s accounting; and

The management of our receivables (including the collection and/or assignment of receivables to collection agencies). To manage our receivables, we may combine the personal data you have provided with information (including personal data) we have obtained from third parties and/or public sources in order to optimise collection and to determine the most appropriate collection method (e.g. amicable collection or judicial collection).

To whom may we disclose your personal data?

Your personal data will only be communicated to the following third parties for the above purposes:

  • Our contact centres;
  • The network managers ;
  • Our partners (e.g. installers of energy and energy efficiency products, including heaters, solar panels, insulation; our door-to-door salesmen; our market research offices);
  • Collection agencies and intermediaries with whom we have dealings for the management of our receivables (e.g. collection, assignment of receivables);
  • Our related companies; and
  • The competent authorities.
  • The persons working for these third parties only have access to the data strictly necessary for the performance of their task.

Transfer of your personal data to countries outside the European Economic Area (“EEA”)

As we may in some cases work with third parties located in countries outside the EEA that do not offer an adequate level of protection for your personal data, we impose contractual obligations on them, approved by a competent authority, to ensure adequate protection of your personal data. If you would like a copy of these contractual obligations, please send an email to data.protection@nexxtlab.lu. We reserve the right to withhold any confidential information not relevant to you in such a copy.

Legal basis for processing your personal data

We process your personal data only when :

  • The processing is necessary for the performance of a contract or for the performance of pre-contractual measures taken at your request (for example when you have asked us to provide you with an offer on our products or services);
  • The processing is necessary for our legitimate interests (e.g. when we send marketing messages to existing customers);
  • You have given your consent (e.g. for sending emails to potential customers containing marketing about our products and/or services). Please note that in this case you can always revoke your consent; and
  • The processing is necessary in order to comply with our legal or regulatory obligations (e.g. in the context of judicial investigations or requests for information from public authorities).

How long do we keep your personal data?

Your personal data is not kept longer than necessary for the purposes for which it was collected. The retention period may therefore vary depending on the purpose. For example, we are obliged to keep your billing data for 7 years due to accounting and tax obligations. Furthermore, we keep your contractual data for 10 years after the end of your contract for legal purposes in order to keep certain data as evidence in case of litigation. Some personal data of former customers may be used for a period of 4 years after the end of the contract to identify the former customer and to keep him/her informed about Nexxtlab promotions and new products and services, unless the customer has objected. Personal data of potential customers is kept for 12 months from the last contact with the potential customer. However, it may be kept longer if the potential customer becomes a Nexxtlab customer.

What are your rights?

Subject to certain conditions, you have the following rights with respect to your personal data collected by NEXXTLAB:

The right to access, obtain correction or obtain deletion of your personal data;

The right to object to or obtain the restriction of the processing of your personal data;

  • The right to obtain the personal data you have provided to us in a structured, commonly used and machine-readable format and to have it communicated by Nexxtlab to another data controller;
  • The right to revoke your consent at any time, for example if you no longer wish to receive direct marketing by email.
  • You can exercise these rights by going to our website click here or by sending a letter with a photocopy of your identity card to NEXXTLAB.
  • If you, as a residential or self-employed customer, want to adjust your communication preferences, you can do so in some of our digital solutions or via email at data.protection@nexxtlab.lu.
  • If you are a contact person for a company that has a contract with NEXXTLAB, you can adjust your communication preferences by sending an e-mail to data.protection@nexxtlab.lu.

The above-mentioned rights may not give rise to additional rights than those provided for in this Privacy Policy or in the applicable legislation concerning the protection of personal data. Please be aware that the exercise of these rights may result in NEXXTLAB no longer being able to fulfil its contractual obligations or, in general, no longer being able to provide its products and/or services (or those of its commercial partners) to you.

If you have a complaint about the processing of your personal data, you can contact us at the above address or you can contact the competent Data Protection Authority in Luxembourg.

Use of cookies

For more information on NEXXTLAB’s use of cookies, see link to cookie policy.

Network security

NEXXTLAB makes every effort to optimally protect its network against unauthorized access and to guarantee the confidentiality of its clients’ personal and professional information:

We use Secure Sockets Layer (SSL) technology to prevent the interception or decoding of passwords and customer information.

Nexxtlab’s internal network is protected by a secure firewall and is not directly accessible via the Internet.

Safety also depends on you:

Use your password with care. Never give it to anyone else, even your colleagues. And change it regularly.

Don’t leave your PC, tablet or smartphone unattended when you are connected to an application.