Legal
Privacy policy
How LETZTOKEN S.A. collects and uses personal data on this website, and the rights you have.
Last updated · 28 September 2026
Who is responsible
The controller of your personal data is LETZTOKEN S.A., 7, rue Robert Stümper, L-2557 Luxembourg, Luxembourg, registered with the Luxembourg Trade and Companies Register (RCS) under B255868. You can reach us at contact@letztoken.com.
What we collect
- Contact and meeting requests: first and last name, work email, phone number, institution, role, the workflow you choose, your message and whether you asked to meet the team.
- Visit data: a random visitor identifier stored in your browser, the pages you view, the referring page and campaign parameters (utm_*), used to understand how visitors find and use the site.
- Usage analytics (Microsoft Clarity): clicks, scrolling and page interactions, recorded with masked form fields, plus device and browser information.
- Tags managed in Google Tag Manager (for example Google Analytics or conversion measurement): page views, events and device information, according to the tags we activate.
Why we use it, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Answering your message or arranging a meeting | Your request and the steps before a possible contract (Art. 6(1)(b)); your agreement given with the form (Art. 6(1)(a)) |
| Keeping your details in our CRM to follow up on the business relationship | Our legitimate interest in managing business contacts (Art. 6(1)(f)) and your agreement given with the form |
| Visitor statistics, usage analytics and marketing measurement | Our legitimate interest in understanding and improving the site and measuring our communication (Art. 6(1)(f)); you can switch these off at any time in Cookie settings |
| Security and the operation of the site | Our legitimate interest in a secure website (Art. 6(1)(f)) |
Who receives it
- LetzToken’s own platform and CRM, where contact requests and visit data are stored.
- Our hosting provider, which serves the website.
- Microsoft Ireland Operations Ltd (Microsoft Clarity), for usage analytics.
- Google Ireland Ltd (Google Tag Manager and the tags it runs), for analytics and marketing measurement.
Microsoft and Google may process data in the United States. Such transfers rely on the EU–US Data Privacy Framework or on the European Commission’s standard contractual clauses.
How long we keep it
- Contact and CRM data: for as long as the business relationship lasts, and up to three years after our last contact.
- Anonymous visit data that is not linked to a request: up to 7 days on our platform.
- Microsoft Clarity and Google data: for the retention period set in those tools, typically up to 13 months.
Your rights
You can ask for access to your data, its correction or deletion, the restriction of its processing, and a copy in a portable format. You can object to processing based on our legitimate interest and withdraw any agreement you gave, at any time, without affecting what happened before. Write to us at contact@letztoken.com.
You can also lodge a complaint with the Commission nationale pour la protection des données (CNPD), 15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg, www.cnpd.lu.