Privacy Policy.
1. Who we are
Hale-X Luxembourg SA (“Hale-X”, “we”, “us”, “our”) is a société anonyme incorporated under Luxembourg law, with registered office at [Insert registered office address], registered with the Luxembourg Trade and Companies Register (RCS) under number [Insert RCS number]. We are the data controller for personal data processed through the website at https://hale-x.com (the “Website”).
This Privacy Policy explains how we collect and use personal data through the Website. Personal data processed within our clinical and software products (Anali-X, Hemalyse, Replica) is governed by separate agreements with hospitals, clinics, research partners, and customers, and is not covered by this Policy.
2. Contact for privacy matters
For any question about this Policy or to exercise your rights, please contact:
- Email: privacy@hale-x.com
- Postal: Hale-X Luxembourg SA, [Insert registered office address]
3. What personal data we collect
3.1 Information you provide
- Contact, inquiry, and partnership forms: name, email, organisation, role, country, and the content of your message.
- Career applications, where applicable: name, contact details, CV, cover letter, and any further information you choose to share.
- Newsletter or event sign-ups: name, email, professional details.
3.2 Information collected automatically
- Technical data: IP address, browser type and version, operating system, device type, referring URL, language, time-zone, and approximate location derived from IP.
- Usage data: pages viewed, time on page, links clicked, and aggregate navigation patterns.
- Cookies and similar technologies : see Section 9.
We do not knowingly collect health data, patient data, or other special-category personal data through the Website. Please do not submit such data via the Website.
4. Why we process your data and on what legal basis
We process your personal data for the following purposes, under the following legal bases:
| Purpose | Legal basis (Article 6 GDPR) |
|---|---|
| Responding to inquiries, partnership requests, and contact forms | Pre-contractual measures / legitimate interests : Art. 6(1)(b) and (f) |
| Managing career applications | Pre-contractual measures : Art. 6(1)(b); and consent : Art. 6(1)(a) where relevant |
| Sending newsletters, updates, or event invitations | Consent : Art. 6(1)(a); you may unsubscribe at any time |
| Operating, securing, and improving the Website | Legitimate interests : Art. 6(1)(f) |
| Analytics and audience measurement | Consent : Art. 6(1)(a) for non-essential cookies |
| Complying with legal, regulatory, and tax obligations | Legal obligation : Art. 6(1)(c) |
| Establishing, exercising, or defending legal claims | Legitimate interests : Art. 6(1)(f) |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You can request our balancing test by contacting us.
5. Who we share your data with
We may share your personal data with:
- Service providers acting as processors on our behalf : for example cloud and hosting providers, email and CRM tools, analytics providers, IT and security vendors. Each processor is bound by a written data-processing agreement.
- Professional advisors (lawyers, auditors, accountants) under a duty of confidentiality.
- Public authorities, regulators, and courts where required by law.
- Counterparties in connection with a corporate transaction (financing, reorganisation, merger), under appropriate confidentiality protections.
We do not sell your personal data.
6. International data transfers
Some of our service providers : including our cloud infrastructure providers : may process data outside the European Economic Area, including in the United States. When that happens, we rely on appropriate safeguards under the GDPR, in particular:
- the European Commission’s Standard Contractual Clauses,
- supplementary technical and organisational measures where required, and
- adequacy decisions where applicable.
You can request a copy of the safeguards by writing to privacy@hale-x.com.
7. How long we keep your data
We retain personal data only for as long as necessary for the purposes set out above, including any retention period required by Luxembourg or EU law. Indicative retention periods:
- Contact and inquiry data: up to 3 years from the last interaction, unless a business relationship is established.
- Career applications: up to 12 months from the end of the recruitment process, unless you consent to a longer retention.
- Newsletter subscriber data: until you unsubscribe, then up to 12 months for proof of consent.
- Server logs and security data: up to 12 months.
- Cookie data: as set out in our cookie banner.
- Accounting and tax records: as required by Luxembourg law (typically 10 years).
8. Your rights under the GDPR
Subject to the conditions of the GDPR, you have the right to:
- access your personal data and obtain a copy;
- rectify inaccurate or incomplete data;
- erase your data (“right to be forgotten”);
- restrict processing;
- portability of data you provided to us;
- object to processing based on legitimate interests, and at any time to direct marketing;
- withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
To exercise your rights, contact privacy@hale-x.com. We will respond within one month (extendable by two further months for complex requests). We may need to verify your identity before responding.
If you consider that our processing breaches the GDPR, you have the right to lodge a complaint with the Luxembourg National Commission for Data Protection (Commission nationale pour la protection des données : CNPD), 15 Boulevard du Jazz, L-4370 Belvaux, Luxembourg (www.cnpd.lu), or with the supervisory authority of your habitual residence.
9. Cookies
The Website uses cookies and similar technologies to operate, secure, and improve the Website and to measure audience. Where required by law, we ask for your consent through a cookie banner before placing non-essential cookies. You can change or withdraw your consent at any time through the cookie settings on the Website.
10. Security
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These include access controls, encryption in transit, logging, and regular review. No method of transmission over the internet is fully secure; we cannot guarantee absolute security.
11. Children
The Website is not directed at children under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact privacy@hale-x.com and we will delete it.
12. Automated decision-making
We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing through the Website.
13. Changes to this Policy
We may update this Policy from time to time. The “Last updated” date shows when it was last revised. Material changes will be notified through the Website or by direct communication where appropriate.