Privacy and cookie policy
How Lux Heritage collects, uses and protects your personal data.
Data controller
Lux Heritage, SAS with share capital of €200, Paris Trade and Companies Register no. 921 510 269, 231 rue Saint-Honoré, 75001 Paris, is the controller of the personal data processing described below. For any question: michel.stofer@luxheritage.fr.
Data we collect
We only collect the data needed for our exchanges and our engagements:
- Contact and meeting request form : first name, last name, email address, phone number (optional), profile (individual, business owner, etc.) and the content of your message;
- Client relationship : identity data, contact details, family, professional, financial and tax situation, objectives, financial knowledge and experience, risk profile, as well as the supporting documents required by regulation (know-your-customer, anti-money laundering and counter-terrorist financing);
- Browsing : technical data strictly necessary for the website to function (IP address, server logs).
Purposes and legal bases
- Responding to your requests and arranging a meeting — pre-contractual measures taken at your request ;
- Providing our advisory and brokerage services and managing the client relationship — performance of a contract ;
- Complying with our regulatory obligations (duty to advise, suitability, know-your-customer, anti-money laundering, record keeping) — legal obligation ;
- Ensuring the security and proper functioning of the website, handling any disputes — legitimate interest.
Retention periods
- Prospects who did not follow up: 3 years from the last contact;
- Clients: throughout the relationship, then 5 years after it ends (extended where required by law, in particular anti-money laundering rules);
- Browsing data and technical logs: 12 months maximum.
These periods may be extended in the event of litigation or at the request of an authority.
Recipients
Your data is intended for Lux Heritage’s advisors. Where necessary, it may be shared with partner institutions (insurers, asset management companies, banks) to set up your contracts, with our technical service providers (website hosting, email, business software), and with supervisory authorities (AMF, ACPR), the CNCGP and administrative or judicial authorities where required by law. Your data is never sold or used for advertising purposes.
Transfers outside the European Union
Our hosting provider, Namecheap, Inc., is a company established in the United States. Where data may be accessible from a country outside the European Union, such transfers are governed by the safeguards provided for by the GDPR (adequacy decision or European Commission standard contractual clauses).
Your rights
You have the right to access, rectify, erase, restrict and port your data, as well as the right to object to processing based on legitimate interest. You may also set instructions regarding the handling of your data after your death. Some rights may be limited where retention of the data is required by law.
To exercise your rights, write to michel.stofer@luxheritage.fr or to Lux Heritage, 231 rue Saint-Honoré, 75001 Paris. Proof of identity may be requested in case of reasonable doubt. We will respond within one month.
If you believe your rights have not been respected, you may lodge a complaint with the CNIL (French data protection authority), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr.
Cookies
The website www.luxheritage.fr uses no audience measurement cookies, no advertising cookies and no social media cookies. Only cookies and trackers strictly necessary for the website to function may be set (for example to remember your chosen language or secure your session). In accordance with the regulations, these trackers do not require your consent.
The website’s fonts are loaded from Google Fonts servers; in doing so, your IP address is transmitted to Google in order to display the page.
You can configure your browser at any time to block or delete cookies; some features of the website may then be affected.
Security
Lux Heritage implements appropriate technical and organisational measures to protect your data against loss, unauthorised access or disclosure: encrypted connection (HTTPS), access restricted to authorised persons only, confidentiality obligations.
Changes to this policy
This policy may be updated to reflect changes in our services or in the regulations. The date of the last update is shown at the bottom of the page.
Last updated: October 2026