Privacy Policy
Last Updated: Tuesday, September 1st, 2026
1. Introduction
Welcome to The Modern Reference (“We”, “Our”, “Us”).
We are committed to protecting and respecting your privacy. This Privacy Policy explains how We process, collect, use, disclose, store and protect your personal data (as defined in Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data of 27 April 2016 (“GDPR”) when you:
• Visit Our website: www.themodernreference.com
• Create an account on Our platform or in Our members’ area
• Participate in Our online community
• Join Our private membership private circle
• Register for gatherings, workshops, dinners, meetings or wellbeing activities • Subscribe to Our newsletters and communications
• Interact with Us through any other services We provide.
We process personal data in accordance with:
• GDPR
• Any applicable national data protection laws within the European Economic Area (“EEA”)
• Any other applicable privacy legislation.
By using Our services, you acknowledge being perfectly aware that your personal data will be processed as described in this Privacy Policy.
2. Data controller
The data controller responsible for processing your personal data is:
The Modern Reference
21 rue Glesener, L-1631 Luxembourg
Email: hello@themodernreference.com
Company Registration Number: A46902
Business Licence number: 10192784/0
VAT Number: LU34970625
Data Protection Contact: privacy@themodernreference.com
If you have any questions regarding this Privacy Policy or the processing of your personal data, please contact Us using the details above.
3. The services We provide
The Modern Reference operates a women's private circle in Luxembourg, where members meet through gatherings and curated experiences, with an online member space extending the circle between gatherings.
The Modern Reference provides:
• Membership access to a women's private circle;
• Artistic, cultural and wellbeing activities;
• Workshops, conferences, dinners, gatherings and events;
• Subscription-based membership services;
• Communications relating to the circle and its activities.
Certain services may be available only to registered members.
4. Personal data We collect
Depending on your interactions with us, We may collect the following categories of personal data.
a) when you navigate on the website
Standard technical data (eg logs, cookies). Please refer to the cookies policy for more information.
b) When you subscribe to Our newsletter (without being a member)
Your email
c) When you register on the waiting list
Email and consent to the registration on the waiting list
d) In relation to the membership
i) as a candidate: first name, last name, email, job title, Instagram account (optional) and LinkedIn account (optional), the answers to the questions of the membership form, the information on how you know Us, and if any the member of refer Us to you. Please note that if you have been referred to Us by a member, we will ask you to disclose the first name et last name of this member.
ii) As member: the aforementioned information and your phone number, your membership option, date of your subscription, member number and membership status. Please note that if you refer a person to become a member, this person will be asked to disclose your first name and last name.
e) Content
Information you voluntarily post in Our community areas, including comments, messages, responses to surveys or discussion topics.
Please remember that information shared in community areas may be visible to other members according to your privacy settings.
f) Event Information and pictures
When registering for gatherings: accessibility requirements, event preferences, feedback submitted after events.
Some pictures or videos may be taken during a gathering. Please note that no picture nor video where you can be identified will be shared, published or transferred to anyone.
g) When you communicate with Us
Email correspondence, support requests, feedback, complaints, survey responses.
5. How We use your personal data
We only use your personal data for the following purposes:
a) Review of applications and management of the admission process, including the assessment of applications, interviews, and admission decisions.
b) Membership administration, including payment processing through Stripe, issuance of a digital membership card (Apple Wallet and Google Wallet) containing the member's first name, last name and membership number, creation and management of the member account area, member communications, and invitation to the community WhatsApp group.
Please note that participation in the WhatsApp group will make the member's telephone number visible to other members of the group by default. Nevertheless, WhatsApp recently implemented a function to hide your phone number when using WhatsApp. It is recommended to activate this function to keep your phone number private.
c) Organisation and administration of events, including ticketing, guest list management.
d) Distribution of Our newsletter, including the management of newsletter subscriptions and the delivery of editorial content to subscribers.
e) Regarding photography and video recording during gartherings for communication, promotional and editorial purposes, including publication on Our website, social media channels, newsletters and partner communication materials. By default, no pictures or video where you can be identified will be used. Nevertheless, should it be the case, appropriate consent mechanisms will be implemented, including notice during gathering registration and throughout the membership application process. Separate written and specific consent will be obtained before using identifiable portraits or named images of members.
f) Accounting, financial management and compliance with legal obligations, including the transmission of required accounting records and supporting documents to Our accountants, auditors, fiduciary service providers and other professional advisers where necessary.
g) Advertising, analytics and campaign optimisation, including the measurement, analysis and improvement of marketing and communication campaigns, subject to applicable consent requirements and data protection laws.
7. Legal basis for processing
We process personal data under one or more of the following GDPR legal bases:
a) The performance of the contract (or pre-contractual measures)
Where processing is necessary to:
• Create your account
• In relation to the admission process and to provide the membership services b) With your explicit consent
Where you have given consent, including for:
• Marketing communications
• Certain cookies
• Optional profile information
• Transfer of personal data outside the EEA or to a country with does not benefit from an adequacy decision from the European Commission
• Publication of testimonials or photographs
You may withdraw consent at any time.
c) Legitimate Interests
We may process personal data where necessary for Our legitimate interests, including:
• Improving services
• Community management
• Website security
• Fraud prevention
• Internal administration
We ensure such interests do not override your rights and freedoms.
8. Sharing personal data
Only where it is necessary, We may share personal data with:
a) Service Providers, such as hosting providers, membership management providers, e mail service providers, analytics providers, customer support systems
These providers process data (including personal data) only on Our instructions only and under Our responsibility. If they are not located in a country benefiting from an adequacy decision from the European Commission, We will ensure that appropriate contractual and security safeguards are in place and/or that you have given explicit consent.
b) Event Partners
Where necessary to organize specific events, workshops or activities.
c) Professional Advisors
Including lawyers, accountants, auditors and insurers, only where legally necessary. 9. International transfers
If personal data is transferred outside the European Economic Area, we will ensure that you gave your consent or been informed and that appropriate safeguards are in place, including:
• European Commission adequacy decisions;
• Standard Contractual Clauses (SCCs);
• Other approved transfer mechanisms under GDPR.
You may request additional information regarding such safeguards.
10. Personal data retention
We retain personal data only as long as necessary for the purposes described in this Privacy Policy.
Retention periods may include:
Data processed in relation to any rejected candidate : 1 month
Data processed in relation to Membership : All the duration of the membership and 3 years after its termination
Data processed for accounting purposes : 10 years
Data processed for any attendance to an event: 2 months after the event if you are not a member. All the duration of your membership and 3 years after if you are a member.
Newsletter : As long as you have not unsubscribed to the newsletter
Technical data (eg website Logs): up to 7 days, where Activity Log is enabled. Other technical logs may be retained by Squarespace in accordance with its own privacy policy and applicable documentation.
After the retention period, personal data will be securely deleted or anonymized.
11. Your GDPR rights
Where applicable, you have the following rights which can be exercised at any time without being charged:
a) Right of access
To obtain a copy of your personal data that We process.
b) Right to rectification
To correct inaccurate or incomplete your personal data.
c) Right to erasure
To request deletion of your personal data from Our system. Please be informed that such deletion can lead to the termination of your membership and/or any other services We provide.
d) Right to restrict processing
To request limitation of processing activities. Please be informed that such limitation can lead to the termination of your membership and/or any other services We provide.
e) Right to personal data portability
To receive your personal data in a structured and machine-readable format.
f) Right to object
To certain processing activities, including direct marketing. Please be informed that such objection can lead to the termination of your membership and/or any other services We provide.
g) Right to withdraw consent
Where processing relies on consent. Please be informed that such withdrawal can lead to the termination of your membership and/or any other services We provide.
h) Right to lodge a complaint
You have the right to lodge a complaint with your local data protection authority.
For individuals located in the EU, complaints may be submitted to the competent supervisory authority in their country of residence.
In Luxembourg, the competent authority is:
La Commission Nationale pour la Protection des Données
Address: 15 boulevard du Jazz, L-4370 Belvaux
Tel: +352 26 10 61-1
Website: www.cnpd.public.lu
13. Security measures
We implement appropriate technical and organizational measures to protect personal data, including:
a) Personal data is managed primarily by one person, who is the sole individual with full access to member and operational data or any other employee on a need-to-know basis.
b) Access to the premises is controlled through badge-based entry systems, and members of the workspace are identified prior to being granted access. The workstation is systematically locked whenever left unattended, and the device's hard drive is encrypted using FileVault.
c) No physical documents containing personal data are left unattended on the premises. d) Access to business applications and systems is protected through the use of strong passwords and a password management solution. Multi-factor authentication (MFA) is enabled on critical accounts and services, including but not limited to Microsoft 365, Squarespace, Stripe, and Instagram.
e) The mobile device used for business purposes, including the management of the community WhatsApp group, is protected by biometric authentication and/or a secure passcode.
f) A dedicated professional email environment is maintained through Microsoft 365 for all business communications involving personal data.
g) Membership records are maintained in a password-protected Excel register stored within a secure Microsoft OneDrive environment. Access to this register is restricted exclusively to the founder.
h) Communications between devices and business systems are encrypted using industry-standard Transport Layer Security (TLS) protocols.
Access to personal data is restricted according to operational needs. Only the manager of TMR has full access to the data necessary for operating the membership of the private circle and community. External service providers, including the website administrator and accounting or fiduciary advisers, are granted access only to the personal data strictly necessary for the performance of their respective services and responsibilities.
The organisation does not collect, store, or have access to members' payment card information. Payment transactions are processed exclusively by third-party payment service providers, including Stripe and Luma, in accordance with their own security and compliance standards.
Where personal data is temporarily exported for administrative or operational purposes, such exports are deleted promptly once processing has been completed and are not retained longer than necessary.
15. Photographs and event media
During events, photographs and videos may be taken.
These materials may be used for community communications, promotional materials, social media, and website content. By default, the materials used will enable any identification of any person.
If we want to use some material where you can be identified, we will always ask for your consent before using identifiable images.
You may contact Us to withdraw consent at any time.
16. Automated decision-making
We DO NOT currently use automated decision-making or profiling that produces legal or similarly significant effects on individuals.
If this changes, We will update this Privacy Policy and inform affected users where required.
We do not use personal information shared within community discussions, private groups, events, wellbeing activities, or member interactions for behavioral profiling, targeted advertising, or the automated assessment of an individual's personal characteristics, preferences, health, wellbeing, or life circumstances.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
Any updated version will be posted on this page with the revised “Last Updated” date.
For significant changes, We may provide additional notice through email or website notifications.
18. Contact Us
For questions regarding this Privacy Policy or your privacy rights, please contact: The Modern Reference
21 rue Glesener, L-1631 Luxembourg
Email: hello@themodernreference.com
Data Protection Contact: privacy@themodernreference.com

