Privacy Policy
Last updated: 28 September 2026
This policy explains how A&A Digital Factory S.à r.l. ("we", "us") processes personal data in connection with the RC Insight platform (www.rcinsight.lu) in accordance with Regulation (EU) 2016/679 (GDPR).
1. Who is responsible for your data
Our role depends on the data concerned:
- Compliance data entered by our clients (information on investors, beneficial owners, service providers and related due-diligence material): the client — the supervised entity using RC Insight — is the controller; we act as processor on its documented instructions, under a data processing agreement.
- Platform account data, contact requests and security logs: we are the controller.
Data protection contact: contact@rcinsight.lu. Registered office: 5, route d'Arlon, L-8310 Capellen, Luxembourg.
2. What we process, why, and on what legal basis
As processor, on behalf of our clients
- KYC / due-diligence data — identity, date of birth and nationality of beneficial owners, questionnaire answers, identity documents, source-of-funds information — processed so that our clients can meet their AML/CFT obligations under Luxembourg law.
- Risk assessment and monitoring data — risk scores, PEP/sanctions screening statuses, monitoring findings — for the client's regulatory risk assessment and annual compliance monitoring.
- Entity registry data — identity, contact details and governance roles of directors, beneficial owners and service providers.
For these processing activities, the legal basis and the handling of data-subject requests are determined by the client as controller; we assist the client in responding. This data is provided to us by the client, or collected from the persons concerned through secure questionnaires sent at the client's request; informing those persons about the processing (Article 14 GDPR) is the client's responsibility, which the platform supports.
As controller
- User accounts — email, name, role — to provide and secure the service (performance of contract, legitimate interest).
- Demo and contact requests made on this website — see section 3a. They are not stored in the platform database.
- Security and audit logs — user identifier, IP address, user agent — for security, abuse prevention and audit trail (legitimate interest and legal obligations).
Providing account data is necessary to access the platform; without it we cannot provide the service. We make no automated decisions producing legal or similarly significant effects: risk scores computed by the platform are decision-support indicators, configured and reviewed by the client's compliance professionals.
3. Recipients and subprocessors
Personal data is processed by the following providers:
- Supabase — database, storage, authentication — hosted in the EU (region
eu-central-1, Frankfurt, Germany). - Vercel — web application hosting and content delivery (access logs, IP addresses).
- Resend — transactional email (recipient name and email address, secure links).
- Brevo (Sendinblue SAS, France) — contact database and email for demo and contact requests made on this website (see section 3a).
- Browserless — PDF document rendering (content of the document being generated, for the duration of the rendering).
Where a provider processes data outside the European Economic Area, transfers are governed by the European Commission's Standard Contractual Clauses and supplementary measures; you may obtain a copy of these safeguards by writing to contact@rcinsight.lu. We do not sell personal data, and no data is used for advertising.
3a. Demo and contact requests
When you request a demo (/demo) or write to us through the contact form on this website, A&A Digital Factory S.à r.l. (RC Insight), 5, route d'Arlon, L-8310 Capellen, Luxembourg, is the controller of the data you send.
- Data: for a demo request, first and last name, work email, phone number, company, job title, number of fund mandates, supervisors (CSSF, AED), the service you are interested in, your optional message, the page and campaign that brought you (UTM parameters, referring page) and your consent choice with its date and text version; for the contact form, first and last name, email, message, whether you asked to be kept informed, and the same page and campaign details.
- Purposes and legal bases: handling your request and replying to you, which are steps taken at your request before any contract (Art. 6(1)(b) GDPR) or, for general enquiries, our legitimate interest in answering them (Art. 6(1)(f)); sending you information about RC Insight only if you ticked the corresponding box, on the basis of your consent (Art. 6(1)(a)), which you can withdraw at any time through the unsubscribe link in each email or by writing to us. The box is never pre-ticked.
- Recipients and processors: Brevo (Sendinblue SAS, France, European Union) stores the request as a contact in our customer database and sends the notification to our team and the confirmation to you; Vercel hosts this website and runs the form handlers in its European region (Frankfurt, Germany). The data is not sold or used for advertising.
- Email open and click tracking: our emails, including demo request confirmations and contact form acknowledgements, contain a tracking pixel and tracked links provided by Brevo (Sendinblue SAS, European Union). They tell us whether an email was opened, when, and which links were clicked. We use this to check that our replies reach you and to follow up your request. For demo requests, this is based on the consent you give on the demo form (Art. 6(1)(a) GDPR); for the contact form, on our legitimate interest (Art. 6(1)(f)), and you can object to it at any time by writing tocontact@rcinsight.lu. You can also block this tracking by turning off the display of images in your email client.
- Retention: requests that do not lead to a contract are deleted or anonymised 24 months after our last contact with you. Consent records are kept for as long as needed to prove your consent.
- Your rights: access, rectification, erasure, restriction, objection, portability and withdrawal of consent, by writing tocontact@rcinsight.lu; we answer within one month. You may also lodge a complaint with the CNPD (see section 7).
4. Retention
- Compliance data processed on behalf of clients is retained for the statutory AML/CFT retention periods applicable to the client, then deleted.
- Account data is retained for the duration of the account.
- Security logs are retained for a limited period proportionate to their purpose.
5. Security
Data is encrypted in transit (TLS) and at rest, hosted in the EU, and isolated per client through database-level row security. Access is restricted and logged, strong password rules are enforced, and two-factor authentication is available (and enforced for administrator accounts). Production access is limited to a small number of authorised staff.
6. Cookies and local storage
This website and the RC Insight application use no advertising or analytics trackers and set no third-party cookies (the emails we send contain Brevo open and click tracking, described in section 3a). The application only uses your browser's local storage for what is strictly necessary to provide the service you request:
- your authentication session (keeping you signed in);
- interface preferences (for example, sidebar state and selected views).
Because this storage is strictly necessary, no consent banner is required. If we ever introduce analytics or other non-essential trackers, we will request consent first and update this policy.
7. Your rights
You have the right to access, rectify and erase your personal data, to restrict or object to its processing, and to data portability. Where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal. To exercise these rights, contact contact@rcinsight.lu. If your data is processed on behalf of one of our clients (for example, as an investor or beneficial owner of a fund they supervise), please address your request to that client; we will assist them in responding.
You may lodge a complaint with the Luxembourg supervisory authority, the Commission nationale pour la protection des données (CNPD).
8. Changes
We may update this policy from time to time. The date at the top indicates the latest revision; material changes will be announced in the application.