KAR-TESS HOLDINGHolding company · Luxembourg
Privacy

What this page processes

In short: very little. This page embeds no third-party services and measures no visitor behaviour. There is a single cookie — and only if you sign in to the protected area.

Controller

KAR-TESS HOLDING S.à r.l., 17, rue Léon Laval, L-3372 Leudelange, Luxembourg. RCS Luxembourg B18031. Contact: kontakt@kartess.lu.

When the page is opened

The server that hosts this page processes the data every request technically requires: IP address, time, file requested, volume transferred, browser and operating system identifier. Without them a page cannot be delivered at all. The legal basis is the legitimate interest in secure operation (Art. 6(1)(f) GDPR).

No measurement, no third-party services

There is no audience measurement, and no counting pixels, social buttons or advertising networks are embedded. The only cookie set is the one that keeps a session in the protected area alive — strictly necessary for the service you asked for, and therefore not subject to consent under Art. 5(3) of Directive 2002/58/EC. That is why no consent banner appears on this page: there is nothing to consent to.

Typefaces

The typefaces used sit on the same server as the page. The usual route via a font service would pass every visitor's IP address to a third party before they have clicked anything. That does not happen here.

The two forms

Until 11 September 2026 these forms only opened the e-mail program on your own device. That is no longer the case, and so it is stated here: your details are now sent to this site and stored there.

Request a call: stored are the name, telephone number, the time window given and the moment of submission. The legal basis is your consent given by ticking the box (Art. 6(1)(a) GDPR) and the initiation of contact (b). The entry is deleted once the call has been made.

Request access: stored are the name, e-mail address, firm, the moment of submission, the version of the confidentiality undertaking and the fact that you accepted it. Of your IP address the address itself is not kept — only a checksum formed from it, which shows whether two acceptances came from the same connection but cannot be turned back into an address. The legal bases are your consent (a), the initiation (b) and the demonstrability of consent (f and Art. 7(1) GDPR). The record is kept for the duration of the undertaking.

Both reach the company alone. An e-mail service provider acts as processor for sending the notification and the credentials; it receives the recipient address and the content of that message. Nothing is passed on for advertising, there is no mailing list, and nothing is sold to third parties.

The protected area

Behind Login lies an area holding the company's filings. It is not self-service: no account can be created there. Every request is reviewed by the company; only once it is approved are credentials generated and sent to the address given. Acceptance of the confidentiality undertaking is a precondition. Access can be withdrawn at any time and then ceases to work immediately.

The password is not stored in clear text but only as a hash with its own salt (scrypt). Anyone reading the file cannot sign in with it — and the company itself cannot look up an issued password either. If it is lost, a new access is granted.

On sign-in, the user name and password are transmitted and compared with the stored values. If they match, the server sets a cookie named kt_zugang. It holds only two things — the user name and the time the session expires — and is signed with a secret key so that it cannot be altered. It is HttpOnly (unreadable to scripts in the browser), SameSite=Lax and, over HTTPS, Secure. There is no session database; nothing about your visit is stored on the server. Once it expires — twelve hours by default — the cookie lapses by itself; Sign out deletes it immediately.

Beyond the cookie, the server processes your IP address at sign-in to slow down bulk password guessing (at most six attempts in ten minutes). That count lives in memory only and is gone after a restart. The operating log records each accepted sign-in with the user name, and each rejection with no details at all. The legal basis for both is the legitimate interest in secure operation (Art. 6(1)(f) GDPR); for providing the filings themselves it is the performance or initiation of the relationship with you (Art. 6(1)(b) GDPR).

The assistant

The assistant at the bottom right runs entirely in your browser. It sends no input to a server, stores nothing beyond the visit and writes no text of its own: it selects from pre-formulated answers. Your questions do not leave your device.

Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection. Please write to the address given above. You may also lodge a complaint with a supervisory authority; in Luxembourg this is the Commission nationale pour la protection des données (CNPD).

Draft — to be reviewed by a lawyer before publication This text describes accurately what the page does in its present state: delivery, a protected area with sign-in, and two forms that open your e-mail program. As soon as a server receives those forms itself, sends confirmation e-mails or keeps a contact list, the processing changes — and this text has to be extended and reviewed to match.

Back to the home page