At the CFL Group, the customer always comes first.
As such, and quite naturally, the protection of personal data is an absolute priority of the CFL Group, respectively for each Group entity that is required to process your personal data for the needs of its business.
We have a commitment to transparency concerning the data collected about you within the framework of the use of the CFL mobile app, as well as around the use and sharing of this personal data.
This information notice provides you with the necessary information and explains how we collect, use, share, store and protect your personal data.
It also provides you with information on your rights and how to exercise them.
1. Who is the data controller?
The Luxembourg National Railway Company (CFL), 9 place de la Gare à L-1616 Luxembourg, is the data controller for the personal data concerning you and which we process.
In this respect, we are responsible for the manner in which we collect, use, share, store and protect your personal data.
If you have any questions or complaints concerning this Information Notice, you may contact us by sending a written request to the CFL Data Controller, 9 place de la Gare, L-1616 Luxembourg.
2. What categories of personal data are processed and for what purpose?
CFL collects, processes and stores personal data that you send to us, as well as data provided by any device (including a mobile device) that you use when using our parking ticket reservation services.
The processing of data is carried out by CFL for the following end purposes:
- The online sale and issue of parking tickets reservations,
- The management of the CFL services relating thereto (management of contractual relations, claims management, prevention of frauds and infractions processing),
The CFL directly collect the following personal data:
- Your identification data (first and last name(s), address) and your electronic ID data (e-mail address, IP),
- Your financial data (credit card number) in connection with your purchase of parking tickets,
- Optionally a phone number,
- Optionally, for parking tickets reservations made in connection with a business trip, the name of your employer
Mandatory data is indicated in the data collection forms with an asterisk.
In the event of a refusal to provide said personal data, the service depending on said collection cannot be performed; in such case, please purchase the parking ticket you wish for from the entrance gates or from the Park+Rail counter.
In all cases, we ensure that the data is collected for specific purposes and that it is processed in an appropriate and relevant manner and solely for that which is necessary in respect of the intended purpose.
3. How do we collect, process and use your data?
We collect, process and use the personal data you provide for us :
- whenever you purchase a parking ticket reservation,
- and you pay the parking ticket reservation online
For each of the previously described purposes, the collection and processing of your data will be carried out:
- in compliance with the applicable regulations relating to the protection of personal data including the GDPR (European Regulation EU 2016/679 of 27 April 2016), the Guidelines and related materials and the national laws implementing the GDPR where necessary;
- on legal grounds
- - either based on the fact that the processing of your personal data is required for the performance of the contract that you are a party to or in order to take steps at your request prior to entering into a contract;
- - or on the basis of your consent;
- - or based on the fact that the processing is necessary for compliance with a legal obligation to which the data controller is subject;
- - or an interest that is recognised as legitimate;
- - or when the processing of your data is necessary for the performance of a task carried out in the public interest vested in the data controller (passenger and staff safety, protection of property, prevention and identification of infringements etc.).
Any confidential information entered on our reservation site are secured and protected by SSL (Secure Socket Layer) technology. Every time you communicate confidential information such as your personal data, your data is encrypted and thus rendered illegible by third parties.
4. Who has access to your data?
The data collected is processed and used by the CFL passenger traffic department – "Service Activité Voyageurs Trains".
In addition, in order to ensure optimum service quality, the CFL has entrusted certain tasks to specialised subcontractors. With this in mind, the data is stored and used by the following subcontractors:
- ilogs information logistics GmbH, a company with registered office in Klagenfurt, Austria, in their role as developer, integrator and operator of the online reservation solution.
- The company Six Payment Services (Europe) S.A., with registered office in Munsbach, Luxembourg, in their role as payment services provider.
We ensure that your personal data is processed for the purposes mentioned above.
This data may be shared with certain internal departments in strict compliance with the tasks entrusted to these departments: Finance and Controlling Department, IT Department, Legal and Insurance Department and Internal Audit Department.
Within the strict framework of the purposes referred to above, and whenever it is necessary, we share your personal data with our auditors, our legal advisers, the Luxembourg authorities or competent foreign authorities.
5. Where your data is processed. Will your data be transferred?
Your data is intended for the authorised CFL departments (Passenger traffic department, Finance and Controlling Department, IT Department, Legal and Insurance Department and Internal Audit Department), which take all of the appropriate technical and organisational measures to protect the security of your personal data and primarily the confidentiality, integrity and availability of your personal data.
For security reasons, it is also transferred to:
- ilogs information logistics GmbH, a company with registered office in Klagenfurt, Austria, in their capacity as developer, integrator and operator of the online reservation solution.
- The company Six Payment Services (Europe) S.A., with registered office in Munsbach, Luxembourg, in their capacity as provider of payment services.
For transfers, CFL contractually imposes the obligation on service providers to provide guarantees in terms of the security and confidentiality of your personal data by taking appropriate technical and organisational measures pursuant to regulations.
6. How long do we keep your data ?
The conservation period for data is limited to the duration of use of the parking tickets reservation service and to the period along which the conservation of data is necessary for us to be able to fulfill our obligations resulting from statutes of limitation and / or any further legal provisions.
The personal data defined here above is erased 6 months at the latest after the last parking tickets reservation.
7. What are your rights regarding your personal data?
Under the conditions provided for by the regulations, you have the right to:
- Access the personal data that we hold about you;
- Request the correction of the data if it is inaccurate or incomplete;
- Request the deletion in certain cases, such as whenever your data is no longer required for the intended purpose for which it was collected and/or processed and which we haven't yet deleted by virtue of the statutory and regulatory requirement obligations applicable to the period of data retention;
- Request the limitation of the processing of your personal data such as the limitation of the processing of data for which you dispute the accuracy and throughout the period that we require to enable us to verify your request;
- Request the portability of your personal data so that your personal data can be sent to you in a structured, commonly used and readable format, or to have it transferred to another data controller;
- Withdraw your consent at any time to the processing of your personal data without this compromising the lawfulness of the processing on the basis of the consent given prior to your withdrawal and unless such data is processed on a legal basis other than your consent.
- Object to the processing of your data solely in the pursuit of our legitimate interests or prohibit us from processing it, including for direct marketing purposes.
- Lodge a complaint with the competent authority for the protection of personal data in your country and/or the Grand Duchy of Luxembourg (National Commission for Data Protection – CNPD).
8. How can you contact us and exercise your rights?
Should you have any questions relating to the processing of your personal data and/or wish to exercise your previously mentioned rights, please write to the Data Protection Officer – DPO of the CFL:
- On our website www.cfl.lu or by following the link gdpr.cfl.lu
- By letter to the following address:
Société Nationale des Chemins de Fer Luxembourgeois (CFL)
Data Protection Officer – Service Juridique et Assurances
9 place de la Gare
- L-1616 Luxembourg
To ensure the confidentiality and protection of your personal data, we will need to confirm your identity in advance so that we can respond to you. A copy of both sides of your valid identity card must be sent to us for this purpose.
Any complaints regarding the processing of your personal data can be sent to the above-mentioned postal address or to the Luxembourg national data supervisory authority:
Commission nationale pour la protection des données
1, avenue du Rock'n'Roll
9. How do we update the present information notice ?
In order to best comply with regulations in force, CFL undertakes to update the present information notice whenever necessary. The latest version is at all times available when purchasing a parking ticket reservation.
Any modification of the present statement on personal data may thus be consulted by the client at the time of purchase of a parking ticket reservation.