Skip to main content

Privacy policy

Version 2026-07-23 · Applies to the TaxWallet proof-of-concept platform

This is a demonstration platform

TaxWallet is currently a proof of concept built to demonstrate a concept to the Luxembourg Ministry of Economy, investors and institutional partners. It performs no real financial transactions, holds no funds, and has no connection to any bank or tax administration. Do not upload real confidential business records.

1. Who is responsible for your data

The data controller for the purposes of Regulation (EU) 2016/679 (GDPR) is [Operator legal entity name — e.g. TaxWallet S.à r.l.], [Registered address], [Postal code + city], Luxembourg. Data protection enquiries: [privacy contact email]. Full operator details are in the legal notice.

No data protection officer has been designated; the platform does not process data on a scale that requires one (Art. 37 GDPR). Data protection enquiries are handled by the controller directly.

2. What we collect and why

Categories of personal data processed, their purpose and lawful basis
DataPurposeLawful basis
Name, email, phoneAccount creation and sign-inContract (Art. 6(1)(b))
Company name, registration and VAT numberVerifying a company registrationContract (Art. 6(1)(b))
Password (hashed with bcrypt)AuthenticationContract (Art. 6(1)(b))
Sign-in events, browser, hashed IP addressAccount security and abuse preventionLegitimate interests (Art. 6(1)(f))
Consent records with version and timestampDemonstrating accountabilityLegal obligation (Art. 6(1)(c))
Customers, invoices, documents you enterProviding the demonstrated featuresContract (Art. 6(1)(b))

Your IP address is never stored in plain text. It is hashed with a server-side secret so that repeated abuse can be detected without retaining an identifier.

3. Cookies

We use strictly necessary cookies only. Under Article 5(3) of the ePrivacy Directive these do not require consent, and we set no analytics, advertising or tracking cookies.

Cookies set by the platform and their purpose
CookiePurposeLifetime
traceo_access_tokenKeeps you signed in15 minutes
traceo_refresh_tokenRenews your session securely30 days
traceo_csrf_tokenProtects against cross-site request forgery30 days
traceo_sessionTells the app a session may exist (contains no data)30 days

Your light or dark theme preference is stored in your browser's local storage and is never sent to us.

4. How long we keep it

  • Account data: for as long as the demonstration account exists
  • Security and sign-in logs: 90 days, then deleted automatically
  • Expired or signed-out sessions: deleted automatically after 30 days
  • One-time email verification and password-reset tokens: deleted within 7 days
  • In-app notifications: deleted automatically after 180 days
  • Customers you delete: permanently erased 30 days after deletion
  • Consent records: retained as proof of consent while the account exists
  • Demonstration data: deleted when the proof of concept concludes

These periods are enforced by an automated daily clean-up job — expired data does not wait for a manual purge.

5. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict and port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time without affecting processing carried out beforehand.

You can exercise the most important rights yourself, at any time, from within the application: Settings → Security → Privacy & data lets you download a complete copy of your data (access and portability, Art. 15 and 20) and permanently delete your account together with all company data and uploaded files (erasure, Art. 17). You can change your own details and password from the same settings area.

For anything else — rectification, restriction, objection — contact [privacy contact email]. You also have the right to lodge a complaint with the Luxembourg supervisory authority, the Commission nationale pour la protection des données (CNPD).

6. Security

  • Passwords hashed with bcrypt; never stored or logged in readable form
  • Session cookies are HttpOnly and unreadable by scripts in your browser
  • Sessions rotate on renewal, and reuse of an old session revokes every device
  • Accounts lock temporarily after repeated failed sign-in attempts
  • Logs are automatically scrubbed of passwords and tokens and rotate after 90 days

7. Where your data is processed

The platform is hosted within the European Union and your personal data is not transferred outside the EU/EEA. The only recipients of personal data are the hosting infrastructure provider operating the servers on the controller's behalf and, once a transactional email provider is engaged, that provider — both under data processing agreements pursuant to Art. 28 GDPR. No personal data is sold, and no data is shared with advertising or analytics providers.

8. No automated decision-making

The platform performs no automated decision-making and no profiling within the meaning of Art. 22 GDPR. Company registrations are reviewed and approved by a human administrator.