Privacy
The public pages of this website use no cookies, no analytics or tracking, no external fonts and no third-party scripts. The portal (/portal/), which only invited users can access, uses the cookies described below, which are strictly necessary for signing in.
Display setting
If you use the switch between light and dark mode, your browser stores your choice (“light” or “dark”) in its local storage so that the site keeps it on your next visit. The value stays on your device and is never sent to us. Storing it is strictly necessary to provide the setting you asked for (§ 25(2) no. 2 TDDDG). You can delete it at any time by clearing the site data in your browser.
Controller
concilio et labore GmbH, Amselweg 4, 54306 Kordel, Germany
Email: e-mail@cetl.lu
Hosting and server logs
The website is hosted on Amazon Web Services (Amazon S3 and Amazon CloudFront) within the framework of a data processing agreement. When you visit the site, the servers process technical data that your browser sends automatically: IP address, date and time of the request, requested page, referrer, browser and operating system. This is necessary to deliver the site and to keep it secure.
Legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the secure and reliable operation of the website. We do not keep access logs of the website. Amazon Web Services may process data in countries outside the European Economic Area; such transfers rely on the EU–U.S. Data Privacy Framework and the European Commission’s standard contractual clauses.
Portal
The portal is available only to persons we have invited. To provide it we process your email address, your name if you give it, the organisation (tenant) and role assigned to you, the data needed for multi-factor authentication, and the times of your sign-ins. Legal basis is Art. 6(1)(b) GDPR where you use the portal under an agreement with us, and otherwise Art. 6(1)(f) GDPR; our legitimate interest is to give the organisations we work with secure access to the portal.
Sign-in is provided by Amazon Cognito in the AWS region Europe (Frankfurt) under our data processing agreement with Amazon Web Services. The sign-in page at auth.ifm.lu is operated by Amazon Cognito on our behalf and sets cookies needed for the sign-in session. Invitations and verification codes are sent by Amazon Simple Email Service from mail.ifm.lu. If you set up a passkey, Amazon Cognito stores only its public key and technical details of the registration; your fingerprint, face or device PIN never leave your device.
After you sign in, the portal stores these cookies in your browser. They are sent only to ifm.lu/portal, cannot be read by scripts and are strictly necessary to provide the portal you asked for (§ 25(2) no. 2 TDDDG):
| Cookie | Purpose | Duration |
|---|---|---|
__Secure-ifm_portal_state |
Protects the sign-in against forged requests | 10 minutes |
__Secure-ifm_portal_id, __Secure-ifm_portal_access |
Prove that you are signed in | 1 hour |
__Secure-ifm_portal_refresh |
Keeps you signed in without a new sign-in | 12 hours |
__Secure-ifm_portal_active |
Ends the session after 30 minutes without activity; renewed with every action in the portal | 30 minutes |
For each portal user we store the date of the last sign-in, so that accounts not used for 90 days can be disabled automatically for security; an administrator of your organisation can enable the account again. When you set up an authenticator app in the portal, its key is shown to you once and stored only by Amazon Cognito, not by us.
The portal page also keeps the time of your last action in your browser’s local storage, so that the countdown to the automatic sign-out is correct in all open tabs. This value contains no personal data and is not sent to us.
In the portal, administrators of an organisation maintain its profile (name, legal form, registered office, RCS number, LEI) and manage its users (e-mail address, role, active or disabled). Every change is recorded in an audit trail with the time, the person who made it and what was changed; the audit trail cannot be changed or deleted and is kept as long as the organisation uses the portal. These data are stored in Amazon DynamoDB in the AWS region Europe (Frankfurt). The portal’s application server records for each request only the address within the portal, the method and the result, without personal data, and keeps these records for 14 days.
Signing out, or the automatic sign-out after 30 minutes without activity, deletes these cookies and ends the session at the sign-in service. The function that checks access to the portal keeps no logs. Amazon Web Services records administrative and security events of the user directory to protect it. We delete your account when your access ends.
Contact by email
If you write to us, we process your email address and the content of your message to answer your enquiry. Legal basis is Art. 6(1)(f) GDPR, or Art. 6(1)(b) GDPR where your enquiry concerns a contract. We delete the data once it is no longer needed and no statutory retention period applies.
Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) (Art. 21). To exercise these rights, write to the email address above.
You also have the right to lodge a complaint with a supervisory authority, for example the authority responsible for us: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, Hintere Bleiche 34, 55116 Mainz, Germany.