Skip to content
07 / Legal

Data Protection

With our long experience in Procurement and Purchasing, we develop clear and easy-to-implement strategies. Tailor-made consulting. SYBX Group – Redefining Procurement. It strives to build trust by providing consulting, outsourcing, and software development services in a manner that protects the privacy of its clients, employees, and others with whom it does business, through the design of its products and robust information security safeguards. The SYBX Group aspires to promote transparency through education initiatives, privacy principles and guidelines, and opportunities for choice, access, and correction regarding the personal data of data subjects.

This notice defines how SYBX Group, Société à responsabilité limitée, (indifferently referred to as “SYBX Group”) may process, in accordance with the applicable laws and for the purposes defined below, personal data collected occasionally (directly or indirectly, compulsorily or voluntarily, manually or otherwise) from data subjects themselves as well as from its clients, third parties (such as potential clients, subcontractors, providers or any stakeholders involved in an engagement with SYBX Group) and/or from publicly available sources where applicable.

I.

Definitions

  • Applicable Laws means any laws, regulations, and standards relating to the protection, privacy, confidentiality, or security of personal data and applicable to SYBX Group. The Applicable Laws include the “General Data Protection Regulation” (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons concerning the processing of personal data and on the free movement of such data).
  • Data subjects, personal data, processing, controller and processor have the meanings given to them in the General Data Protection Regulation.
II.

Purposes of processing

SYBX Group may process the personal data in accordance with the Applicable Laws and solely for the following purposes (together the “Purpose(s)”):

  • To provide professional services including: Consulting; Training, Workshops, Lecturer, Writing and publishing; and Software Development, Cloud Technologies, Software and Server Hosting, Implementation and new technologies’ development like AI, RPA, Blockchain, Big Data, Machine Learning, etc.
  • To maintain its administrative and client/supplier relationship management systems, including: bid issuance and contract drafting; clients/suppliers/alumni follow up and management; invoicing and invoices payments; advertising, communication and public relations; event organisation; quality reviews; and client or user-experience improvement and personalisation of service delivery (such as via authentication, monitoring the performance and use of SYBX applications where applicable).
  • To apply acceptance and continuance procedures (including anti-money laundering, anti-bribery and counter-terrorist financing);
  • To facilitate compliance with its legal, regulatory, professional and/or contractual obligations (including independence and archiving requirements);
  • To maintain and protect its buildings, equipment, IT infrastructure and data (including access management and authentication, security and performance monitoring, etc.);
  • To ensure its business continuity;
  • To manage risks and litigations;
  • To process data subjects’ requests; and/or
  • To manage its websites.

The Purposes above are based on at least one of the following legal bases:

  • The processing is necessary for the performance of a contract to which the data subject is party or to take steps at the request of the data subject before entering into a contract;
  • The processing is necessary for compliance with a legal obligation to which SYBX Group is subject;
  • The processing is necessary for the legitimate interests pursued by SYBX Group or by a third party (such as protecting SYBX Group assets, understanding its clients’ needs and expectations or fulfilling its purpose or social interest); and/or
  • The data subject has given consent to the processing for one or more specific purposes.
III.

Categories of personal data processed

SYBX Group may process the following categories of personal data:

  • Identification data (e.g. name, surname, alias…);
  • Professional data (e.g. position, company…);
  • Administrative data (e.g. identity documents, birthdate, gender, language …);
  • Relational data (e.g. relation history, attendance sheets…);
  • Environmental data (e.g. characteristics, habits, social media information…);
  • Financial data (e.g. tax data, transactional data…);
  • Numeric data (e.g. logs, IP address…); and
  • Biometric data (e.g. picture, sound, video…).
IV.

Categories of data subjects

The personal data processed by SYBX Group may concern the following data subjects, when applicable:

  • Clients and potential clients;
  • Clients and potential clients’ future, former or current employees and trainees, beneficial owners and board members; and
  • Clients and potential clients’ suppliers, customers, agents, advisors, and/or personnel who are employed by, deal with, or are otherwise associated with a client or potential client or who are or may become involved in a transaction/contract with a client or potential client.
V.

Categories of recipients and personal data transfers

To the extent permitted or required by the Applicable Laws, SYBX Group may disclose the personal data to any recipients if they are concerned by the Purpose(s) and, when such recipients process the personal data on behalf of SYBX Group, if they are bound by commitments substantially equivalent to those of SYBX Group as expressed in this notice. Besides the data subjects themselves, the categories of recipients are the following:

  • Subcontractors, business partners and experts;
  • Processors and Sub-processors such as IT suppliers (including systems administrators, cloud services providers, hosting providers, etc.);
  • Other SYBX entities;
  • SYBX Group’s external counsels, agents, or auditors;
  • Entities or individuals that have a relationship with the data subjects (employers, relatives, counsels, business or potential business partners, etc.); and/or
  • Supervisory bodies or public authorities.

SYBX Group shall not transfer any personal data outside the EEA except i) to countries that provide an adequate level of protection for personal data as determined by the European Commission or ii) to recipients under a suitable agreement that contains the requirements of the Applicable Laws for such transfer. A copy of the applicable safeguards and potential additional measures may be requested to the SYBX Group’s Data Protection Officer.

VI.

Security

Considering the state of the art, the costs of implementation and the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, SYBX Group shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access including among other things as appropriate:

  • The pseudonymisation and encryption of personal data;
  • The ability to ensure the ongoing confidentiality, integrity, and availability of its processing systems;
  • The ability to restore the availability and access to personal data in the event of an incident; or
  • A process for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.

In assessing the appropriate level of security, account shall be taken, in particular, of the risks presented by processing, including accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed. More details on SYBX Group’s information security controls are outlined in Appendix 1.

VII.

SYBX Group acting as a processor

When acting as a processor, SYBX Group agrees to process the personal data only on the lawful documented instructions from the controller set in the contractual documents applicable to the services and this notice. It shall ensure that its employees authorised to access the personal data are under an appropriate obligation of confidentiality. For clarity, this notice is intended to comply with the requirements of Article 28 of the General Data Protection Regulation. The SYBX Group shall make available to the controller any lawful information necessary to demonstrate compliance with the obligations outlined in this notice. It allows for and contributes to audits and inspections, to the extent permitted by law, subject to reasonable prior notice and confidentiality obligations. Audits/inspections shall be conducted during regular Luxembourg business hours and no more than once a year. SYBX Group hereby informs the controller that audits/inspections could not breach the legal, regulatory and contractual obligations incumbent on SYBX Group, such as professional secrecy. Hence, the controller and its potential auditors shall not be entitled to access (i) data or information related to other clients of SYBX Group, (ii) any SYBX Group proprietary data or (iii) any other confidential information held by SYBX Group that is not relevant or strictly necessary for the audit/inspection.

SYBX Group shall assist the controller by undertaking appropriate technical and organisational measures, depending on the nature of the processing, insofar as this is possible, that are necessary for the fulfilment of the controller’s obligation to:

  • Respond to requests for exercising the data subject’s rights, as defined in this notice;
  • Carry out data protection impact assessments and conduct prior consultations with a supervisory authority or other government authority where required by the Applicable Laws;
  • Notify a personal data breach to the competent supervisory authority and/or data subjects. For that purpose, SYBX Group shall notify the controller without undue delay of any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to the personal data; and
  • Provide information that the controller reasonably requests to enable the controller to comply with its obligations under applicable privacy laws where the requested information is in SYBX Group’s possession or under its control and the controller has no other reasonable means of obtaining the information.

Where SYBX Group engages other processors to carry out specific processing activities on behalf of the controller (“Sub-processor”), it shall impose on them substantially similar data protection obligations as set out herein by way of a contract or other legal act under European Union or Member State law. The controller hereby provides a general authorisation to SYBX Group for the engagement of Sub-processors as defined in section V above. Any intended changes concerning the addition or replacement of the Sub-processors shall be communicated to the controller.

VIII.

Clients’ obligations

Depending on the Purposes, the provision of personal data is a statutory and/or contractual requirement; failure to provide this personal data might make it impossible for SYBX Group to perform the services. As an essential condition for performing the services, SYBX Group assumes that the clients (and any stakeholders involved in an engagement with SYBX Group, for which the clients concerned stand surety), ensure that:

  • The personal data they provide (or give access) to SYBX Group are accurate, adequate, relevant, and limited to what is necessary for the specific Purpose for which they are disclosed and are adequately backed-up in their systems;
  • They comply with the Applicable Laws in connection with SYBX Group’s processing of the personal data (including the lawfulness of the data provision and, where applicable, collecting and managing the data subject’s consent accordingly);
  • The data subjects are informed of the conditions and modalities of SYBX Group’s processing of their personal data as described in this notice in the form required by the Applicable Laws; and
  • They will immediately inform SYBX Group if any of the conditions above ceases to be met.
IX.

Retention period

The personal data shall be kept in a form which permits identification of the data subjects for no longer than is necessary for each Purpose for which they have been collected, without prejudice to automatic IT back-ups and SYBX Group’s legal and regulatory archiving obligations.

X.

Data subjects’ rights

To the extent permitted by the Applicable Laws, data subjects may have the right to:

  • Request access to, rectification or erasure of their personal data;
  • Restriction of processing of their personal data;
  • Object to the processing of their personal data; and
  • Data portability.

Should the processing of the data subject’s personal data be exclusively based on his/her consent, the data subject shall have the right to withdraw such consent at any time, without affecting the lawfulness of the processing based on consent before such withdrawal. To exercise the rights listed above, the data subject shall email SYBX Group’s Data Protection Officer demonstrating his/her identity and specifying the right that he/she wishes to exercise. Data subjects shall, in addition, have the right to complain to the competent supervisory authority, the lead supervisory authority competent for personal data processed by SYBX Group being the Commission nationale pour la protection des données (CNPD).

XI.

Governing law – Validity

This notice sets out the exhaustiveness of SYBX Group’s commitments regarding personal data processing and supplements any other commitments otherwise agreed. To comply with the Applicable Laws and to reflect adequately the way in which SYBX Group processes the data, this notice shall be updated from time to time. This notice sets out that all matters arising from or connected with it are governed exclusively by the laws of Luxembourg, with the exclusive place of jurisdiction being Luxembourg-City.

Appendix 1 — Security areas covered and controls

SYBX Group, Société à responsabilité limitée, has been assessed. An annual review of the ISP is conducted in accordance with the defined IT governance process.

a.

Information Security Policies

An ongoing process to develop and maintain further or more comprehensive information security policies, standards, and guidelines established and implemented at SYBX Group, including development, review, approval, and publication. These security policies, standards, and procedures are reviewed periodically to ensure that the SYBX Group’s information technology resources are adequately maintained and protected.

b.

Organisation of Information Security

The security management at SYBX Group encompasses the firm-wide security model framework, as well as third-party access to its resources and security requirements for outsourced service providers. Controls include, but are not limited to: a dedicated team of information security professionals; a dedicated information security committee with key members from management; a formalised commitment from top management to information security and delivering the resources and budget needed to comply with the information security strategy; and whenever confidential data is to be outsourced to a specific third-party vendor, a specific security evaluation being part of the assessment process.

c.

Asset Management

Classification and security of information assets and systems, including data classification and management. Controls include, but are not limited to: definition of a data classification scheme, communicated to all staff members. An inventory of all information systems assets is kept up-to-date, and software restricts the transferring of files on removable media from the firm’s PCs.

d.

Human Resources Security

Areas affecting personnel security include employee vetting, terms and conditions of employment, confidentiality agreements, and user awareness training. Controls include, but are not limited to: a Security Awareness Programme which keeps the employees aware of their role and responsibilities in relation to information security. This Security Awareness Programme includes training of all new employees, multiple awareness communications during the year and specific awareness programmes tailored to certain roles at SYBX Group; definition of information security responsibilities in job descriptions; and background checks of employees, which include education, professional licences and prior employment. Changes in employment status (new hires, position changes, departures, etc.) are directly notified to the relevant IT personnel to update or revoke access rights and return any SYBX Group assets.

e.

Physical and Environmental Security

Building access control, clean desk policy and laptop security with the overall aim of ensuring that our business premises and the information and technology assets residing within them are adequately protected. Controls include, but are not limited to: data centres are equipped with specific access control, fire detection and fire suppression mechanisms, cooling systems and backup power capabilities; each SYBX Group employee having their storage space, lockable with a personal security code; each SYBX Group employee having a security cable being required to attach his/her laptop at any time to prevent theft; and documents printing made secure by the employees’ individual badge being required.

f.

Communications and Operations Management

Safe operation and management of information processing centres. Controls include, but are not limited to: clear separation of test and production environments; a secondary data centre distant from the primary data centre offering real-time replication of data, a backup Internet line, and server redundancy (available in online or standby mode, depending on the availability requirements); backup of all servers performed daily on disks and tapes, with a set of backup tapes encrypted and stored at a distant site; an Internet architecture based on a “3-tiers” model protected by network firewalls, application firewalls, and Intrusion Detection/Prevention systems (both network-based and host-based) with redundancy in place at each layer; each PC (including laptops) and Server equipped with an antivirus program managed centrally and updated at least daily (emergency updates possible in real-time); each PC fitted with Desktop Firewall and HIPS (Host Intrusion Prevention Systems); PC hard disks (including laptops) fully encrypted; a secure file transfer platform for confidential file exchange, enabling authentication for file access and encryption during file transfer over the Internet.

g.

Access Control

To ensure that correct and appropriate access is assigned to our information and technology assets based upon a data classification scheme and assigned roles and responsibilities. Controls include, but are not limited to: role-based access control applied throughout SYBX Group, with roles defined according to the employees’ functions and changes to access rights subject to specific approval workflows tailored to the nature of the information being accessed; employees do not have privileged access on their computer (no administrator rights); remote access only possible from corporate devices (device authentication by certificate) through an encrypted channel (VPN); access to internal applications from mobile devices managed through a secure Mobile Device Management system; wireless connections to the internal network only authorised from corporate computers (device authentication by certificate).

h.

Information Systems Acquisition, Development, and Maintenance

Development and ongoing maintenance of information systems to ensure adequate security controls are included during the conceptual design phase. Controls include, but are not limited to: any change on production goes through a validation process supervised by our Change Advisory Board; for every IT project, a mandatory information security risk assessment has to be performed, leading to security action recommendations reviewed and validated by the project manager, the CIO, the information owner, the chief security officer, the project sponsor, as well as a risk management responsible when appropriate; each new application undergoes a security penetration test before going into production, unless specified otherwise in the information security risk assessment, with penetration tests for web applications accessible from the Internet and hosting confidential information done by an independent third-party and performed again every year; vulnerability scans performed on our servers every month; installation of software only possible after proper authorisation, with the use of new software subject to a security evaluation before being allowed.

i.

Information Security Incident Management

Controls to communicate information security events and weaknesses associated with information systems in a manner that allows for timely corrective actions to be taken. Controls include, but are not limited to: tools to detect potential incidents in log files and automatic notifications in place; periodical reviews of the log files of Security Devices performed to detect potential incidents; periodical reporting of information Security Incidents in place, including escalation to Risk Management representatives of each Business line; specific procedures in place for internal/external communication of incidents.

j.

Business Continuity Management

Business continuity and disaster recovery planning, based on service-level agreements and recovery time objectives, with the overall aim of ensuring minimal impact on our business in the event of a disaster. Controls include, but are not limited to: redundancy measures in place for all our systems and applications according to the business requirements; periodical tests conducted to ensure the efficiency of our redundancy measures; a secondary – distant – data centre where our data and systems are replicated; our business continuity and disaster recovery plans reviewed and updated periodically and after each critical change.

k.

Compliance

Outlines controls that measure and monitor compliance of SYBX Group and its systems with SYBX Group’s policies and other relevant security standards. Controls include, but are not limited to, periodic compliance reviews and reporting.

Appendix 2 — Contact details

I.

SYBX Group

A Luxembourg Société à responsabilité limitée
39 Route de Stadtbredimus, L-5570 Remich
www.sybxgroup.com
Consulting, Training, Software – ACTIVITÉS ET SERVICES COMMERCIAUX (autorisation gouvernementale n°10103574)
R.C.S. Luxembourg B 236453 – TVA LU31407785
II.

Data Protection Officer

SYBX Group has appointed a Data Protection Officer, who can be contacted at the following address: dataprotection@sybxgroup.lu. The following address is available to facilitate the exercise of data subject rights under Articles 15 to 22 of the General Data Protection Regulation: sybxgroup.com/imprint.

Zahlungsabwicklung über Stripe

Für die Abwicklung von Zahlungsvorgängen in unserem Online-Shop (Silenara) nutzen wir den Zahlungsdienstleister Stripe. Anbieter für Nutzer innerhalb der Europäischen Union ist die Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Irland. Muttergesellschaft ist die Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA.

Verarbeitete Daten

Im Rahmen der Zahlungsabwicklung werden folgende personenbezogene Daten an Stripe übermittelt: Vor- und Nachname sowie Rechnungsadresse; E-Mail-Adresse; Zahlungsdaten (z. B. Kreditkartennummer, Ablaufdatum, Prüfziffer bzw. IBAN je nach gewählter Zahlungsart); Transaktionsdaten (Bestellbetrag, Währung, Datum und Uhrzeit der Transaktion); IP-Adresse sowie technische Browser- und Gerätedaten.

Zweck der Verarbeitung

Die Datenübermittlung erfolgt zum Zweck der Zahlungsabwicklung, der Betrugsprävention sowie zur Erfüllung gesetzlicher Pflichten (z. B. Geldwäscheprävention, Zahlungsdienstleisterrecht).

Rechtsgrundlage

Die Verarbeitung erfolgt auf Grundlage von Art. 6 Abs. 1 lit. b DSGVO (Vertragserfüllung), soweit die Datenverarbeitung zur Durchführung des Kaufvertrags erforderlich ist. Für Maßnahmen zur Betrugsprävention stützt sich die Verarbeitung ergänzend auf Art. 6 Abs. 1 lit. f DSGVO (berechtigte Interessen).

Eigenverantwortlichkeit von Stripe

Wir weisen darauf hin, dass Stripe in Teilen als eigenständig datenschutzrechtlich Verantwortlicher handelt — insbesondere im Rahmen der Betrugsprävention, der Erfüllung eigener regulatorischer Pflichten sowie der Weiterentwicklung seiner Dienste. Insoweit unterliegen die betreffenden Verarbeitungen nicht unserer Kontrolle. Für Auskünfte zu diesen Verarbeitungen wenden Sie sich bitte direkt an Stripe.

Drittlandübermittlung

Stripe übermittelt Daten an die Stripe, Inc. in die USA. Die Übermittlung erfolgt auf Grundlage der von der Europäischen Kommission genehmigten Standardvertragsklauseln (SCCs) gemäß Art. 46 Abs. 2 lit. c DSGVO. Es kann nicht ausgeschlossen werden, dass US-Behörden auf die übermittelten Daten Zugriff nehmen.

Speicherdauer

Stripe speichert Transaktionsdaten für den gesetzlich vorgeschriebenen Zeitraum, der je nach anwendbarem Recht bis zu 10 Jahre betragen kann (steuer- und handelsrechtliche Aufbewahrungspflichten).

Kein Widerspruchsrecht

Da die Übermittlung der Daten an Stripe zur Durchführung des Kaufvertrags zwingend erforderlich ist, besteht kein Widerspruchsrecht, solange ein Kauf über unseren Shop getätigt wird. Alternativ können Zahlungsmethoden gewählt werden, die eine geringere Datenübermittlung erfordern, sofern diese angeboten werden.

Weitere Informationen

Die Datenschutzerklärung von Stripe finden Sie unter: stripe.com/de/privacy

Verarbeitung von Daten durch Base44 (Wix, Inc.)

Für die Bereitstellung, das Design und die dynamischen Funktionen unserer Web-Apps (Supplier Sentinel, Comparix, Tenderwatch, Procurement Intelligence, Reklahub sowie die Websites Silenara, Defence Readiness 2030, Zwischen Westwall und Ardennen, sybxgroup.com und Procurement First Aid) nutzen wir die No-Code-Entwicklungsplattform Base44. Dies ist ein Dienst der Wix, Inc. (mit Sitz in 500 Terry A. Francois Blvd, San Francisco, CA 94158, USA; im Folgenden „Base44“).

1.

Art und Umfang der Verarbeitung

Wenn Sie unsere Web-App nutzen, werden technische Verbindungsdaten (z. B. IP-Adresse, Browsertyp, Datum und Uhrzeit des Aufrufs) über das Content Delivery Network (CDN) von Base44 geleitet, um Ihnen die Inhalte schnell und sicher auszugeben. Sofern Sie Eingaben in unserer App tätigen (z. B. Formulare ausfüllen oder Berechnungsfunktionen nutzen), werden diese Daten an die Server von Base44 übertragen, um die gewünschten Backend-Funktionen und Berechnungen auszuführen.

2.

Datenminimierung und Speicherbegrenzung (Kurzzeitige Zwischenspeicherung)

Wir verfolgen den Grundsatz der Datenminimierung (Art. 5 Abs. 1 lit. c DSGVO). Personenbezogene oder vertrauliche Eingaben, die Sie im Rahmen der App-Nutzung machen, werden von uns standardmäßig nur für die Dauer des Verarbeitungsprozesses im Arbeitsspeicher gehalten und unwiderruflich aus den Datenbanken gelöscht, sofern keine gesetzlichen Aufbewahrungspflichten entgegenstehen.

3.

Rechtsgrundlage und Drittlandtransfer (USA)

Die Nutzung dieses Dienstes erfolgt auf Grundlage Ihrer ausdrücklichen Einwilligung gemäß Art. 6 Abs. 1 lit. a DSGVO (erteilt über unser Cookie- und Consent-Banner) sowie zur Erfüllung unserer vertraglichen Pflichten bzw. zur Durchführung vorvertraglicher Maßnahmen gemäß Art. 6 Abs. 1 lit. b DSGVO (Bereitstellung der App-Funktionen). Da Base44 ein US-amerikanisches Unternehmen ist, kann nicht ausgeschlossen werden, dass Daten auf Servern in den USA verarbeitet werden. Um ein angemessenes Datenschutzniveau zu garantieren, haben wir mit Base44 ein Data Processing Addendum (DPA / Auftragsverarbeitungsvertrag) abgeschlossen, welches die von der EU-Kommission genehmigten Standardvertragsklauseln (Standard Contractual Clauses – SCCs) als rechtliche Garantie beinhaltet.