Privacy Policy 

Last Updated: Tuesday, September 1st, 2026

1. Introduction 

Welcome to The Modern Reference (“We”, “Our”, “Us”). 

We are committed to protecting and respecting your privacy. This Privacy Policy explains how  We process, collect, use, disclose, store and protect your personal data (as defined in  Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing  of personal data and on the free movement of such data of 27 April 2016 (“GDPR”) when you: 

• Visit Our website: www.themodernreference.com

• Create an account on Our platform or in Our members’ area 

• Participate in Our online community 

• Join Our private membership private circle 

• Register for gatherings, workshops, dinners, meetings or wellbeing activities • Subscribe to Our newsletters and communications 

• Interact with Us through any other services We provide. 

We process personal data in accordance with: 

• GDPR 

• Any applicable national data protection laws within the European Economic Area  (“EEA”) 

• Any other applicable privacy legislation. 

By using Our services, you acknowledge being perfectly aware that your personal data will be  processed as described in this Privacy Policy. 

2. Data controller 

The data controller responsible for processing your personal data is: 

The Modern Reference 

21 rue Glesener, L-1631 Luxembourg 

Email: hello@themodernreference.com

Company Registration Number: A46902 

Business Licence number: 10192784/0 

VAT Number: LU34970625 

Data Protection Contact: privacy@themodernreference.com

If you have any questions regarding this Privacy Policy or the processing of your personal data,  please contact Us using the details above. 

3. The services We provide 

The Modern Reference operates a women's private circle in Luxembourg, where members  meet through gatherings and curated experiences, with an online member space extending  the circle between gatherings. 

The Modern Reference provides: 

• Membership access to a women's private circle; 

• Artistic, cultural and wellbeing activities; 

• Workshops, conferences, dinners, gatherings and events; 

• Subscription-based membership services; 

• Communications relating to the circle and its activities. 

Certain services may be available only to registered members. 

4. Personal data We collect 

Depending on your interactions with us, We may collect the following categories of personal  data. 

a) when you navigate on the website  

Standard technical data (eg logs, cookies). Please refer to the cookies policy for more  information. 

b) When you subscribe to Our newsletter (without being a member) 

Your email 

c) When you register on the waiting list 

Email and consent to the registration on the waiting list 

d) In relation to the membership 

i) as a candidate: first name, last name, email, job title, Instagram account  (optional) and LinkedIn account (optional), the answers to the questions of  the membership form, the information on how you know Us, and if any the  member of refer Us to you. Please note that if you have been referred to Us by a member, we will ask you to disclose the first name et last name of this  member. 

ii) As member: the aforementioned information and your phone number, your membership option, date of your subscription, member number and  membership status. Please note that if you refer a person to become a  member, this person will be asked to disclose your first name and last name.

e) Content  

Information you voluntarily post in Our community areas, including comments,  messages, responses to surveys or discussion topics.

Please remember that information shared in community areas may be visible to other  members according to your privacy settings. 

f) Event Information and pictures 

When registering for gatherings: accessibility requirements, event preferences,  feedback submitted after events.  

Some pictures or videos may be taken during a gathering. Please note that no picture  nor video where you can be identified will be shared, published or transferred to  anyone.  

g) When you communicate with Us 

Email correspondence, support requests, feedback, complaints, survey responses.

5. How We use your personal data 

We only use your personal data for the following purposes: 

a) Review of applications and management of the admission process, including the  assessment of applications, interviews, and admission decisions. 

b) Membership administration, including payment processing through Stripe, issuance of  a digital membership card (Apple Wallet and Google Wallet) containing the member's  first name, last name and membership number, creation and management of the  member account area, member communications, and invitation to the community  WhatsApp group. 

Please note that participation in the WhatsApp group will make the member's  telephone number visible to other members of the group by default. Nevertheless, WhatsApp recently implemented a function to hide your phone  number when using WhatsApp. It is recommended to activate this function to  keep your phone number private. 

c) Organisation and administration of events, including ticketing, guest list management. 

d) Distribution of Our newsletter, including the management of newsletter subscriptions  and the delivery of editorial content to subscribers. 

e) Regarding photography and video recording during gartherings for communication,  promotional and editorial purposes, including publication on Our website, social media  channels, newsletters and partner communication materials. By default, no pictures or  video where you can be identified will be used. Nevertheless, should it be the case,  appropriate consent mechanisms will be implemented, including notice during  gathering registration and throughout the membership application process. Separate  written and specific consent will be obtained before using identifiable portraits or named  images of members. 

f) Accounting, financial management and compliance with legal obligations, including the  transmission of required accounting records and supporting documents to Our accountants, auditors, fiduciary service providers and other professional advisers  where necessary. 

g) Advertising, analytics and campaign optimisation, including the measurement,  analysis and improvement of marketing and communication campaigns, subject to  applicable consent requirements and data protection laws. 

7. Legal basis for processing 

We process personal data under one or more of the following GDPR legal bases:

a) The performance of the contract (or pre-contractual measures) 

Where processing is necessary to: 

• Create your account 

• In relation to the admission process and to provide the membership services b) With your explicit consent 

Where you have given consent, including for: 

• Marketing communications 

• Certain cookies 

• Optional profile information 

• Transfer of personal data outside the EEA or to a country with does not benefit from an  adequacy decision from the European Commission 

• Publication of testimonials or photographs 

You may withdraw consent at any time. 

c) Legitimate Interests 

We may process personal data where necessary for Our legitimate interests, including:
• Improving services 

• Community management 

• Website security 

• Fraud prevention 

• Internal administration 

We ensure such interests do not override your rights and freedoms. 

8. Sharing personal data 

Only where it is necessary, We may share personal data with: 

a) Service Providers, such as hosting providers, membership management providers, e mail service providers, analytics providers, customer support systems

These providers process data (including personal data) only on Our instructions only and under  Our responsibility. If they are not located in a country benefiting from an adequacy decision from the European Commission, We will ensure that appropriate contractual and security  safeguards are in place and/or that you have given explicit consent. 

b) Event Partners 

Where necessary to organize specific events, workshops or activities. 

c) Professional Advisors 

Including lawyers, accountants, auditors and insurers, only where legally necessary. 9. International transfers 

If personal data is transferred outside the European Economic Area, we will ensure that you  gave your consent or been informed and that appropriate safeguards are in place, including: 

• European Commission adequacy decisions; 

• Standard Contractual Clauses (SCCs); 

• Other approved transfer mechanisms under GDPR. 

You may request additional information regarding such safeguards. 

10. Personal data retention 

We retain personal data only as long as necessary for the purposes described in this Privacy  Policy. 

Retention periods may include:

Data processed in relation to  any rejected candidate : 1 month

Data processed in relation to  Membership : All the duration of the membership and 3 years after its  termination

Data processed for accounting  purposes : 10 years

Data processed for any  attendance to an event: 2 months after the event if you are not a member. All the duration of your membership and 3 years after if you  are a member.

Newsletter : As long as you have not unsubscribed to the newsletter

Technical data (eg website  Logs): up to 7 days, where Activity Log is enabled. Other technical  logs may be retained by Squarespace in accordance with  its own privacy policy and applicable documentation.

After the retention period, personal data will be securely deleted or anonymized.

11. Your GDPR rights 

Where applicable, you have the following rights which can be exercised at any time without  being charged: 

a) Right of access 

To obtain a copy of your personal data that We process. 

b) Right to rectification 

To correct inaccurate or incomplete your personal data. 

c) Right to erasure 

To request deletion of your personal data from Our system. Please be informed that  such deletion can lead to the termination of your membership and/or any other  services We provide. 

d) Right to restrict processing 

To request limitation of processing activities. Please be informed that such limitation  can lead to the termination of your membership and/or any other services We provide. 

e) Right to personal data portability 

To receive your personal data in a structured and machine-readable format.

f) Right to object 

To certain processing activities, including direct marketing. Please be informed that  such objection can lead to the termination of your membership and/or any other  services We provide. 

g) Right to withdraw consent 

Where processing relies on consent. Please be informed that such withdrawal can  lead to the termination of your membership and/or any other services We provide. 

h) Right to lodge a complaint 
You have the right to lodge a complaint with your local data protection authority. 

For individuals located in the EU, complaints may be submitted to the competent  supervisory authority in their country of residence. 

In Luxembourg, the competent authority is: 

La Commission Nationale pour la Protection des Données 

Address: 15 boulevard du Jazz, L-4370 Belvaux 

Tel: +352 26 10 61-1 

Website: www.cnpd.public.lu

13. Security measures

We implement appropriate technical and organizational measures to protect personal data,  including: 

a) Personal data is managed primarily by one person, who is the sole individual with full  access to member and operational data or any other employee on a need-to-know  basis. 

b) Access to the premises is controlled through badge-based entry systems, and  members of the workspace are identified prior to being granted access. The workstation is systematically locked whenever left unattended, and the device's hard  drive is encrypted using FileVault. 

c) No physical documents containing personal data are left unattended on the premises. d) Access to business applications and systems is protected through the use of strong  passwords and a password management solution. Multi-factor authentication (MFA)  is enabled on critical accounts and services, including but not limited to Microsoft 365,  Squarespace, Stripe, and Instagram. 

e) The mobile device used for business purposes, including the management of the  community WhatsApp group, is protected by biometric authentication and/or a secure  passcode. 

f) A dedicated professional email environment is maintained through Microsoft 365  for all business communications involving personal data. 

g) Membership records are maintained in a password-protected Excel register stored  within a secure Microsoft OneDrive environment. Access to this register is  restricted exclusively to the founder. 

h) Communications between devices and business systems are encrypted using  industry-standard Transport Layer Security (TLS) protocols. 

Access to personal data is restricted according to operational needs. Only the manager of TMR has full access to the data necessary for operating the membership of the private circle and  community. External service providers, including the website administrator and accounting or  fiduciary advisers, are granted access only to the personal data strictly necessary for the  performance of their respective services and responsibilities. 

The organisation does not collect, store, or have access to members' payment card  information. Payment transactions are processed exclusively by third-party payment service  providers, including Stripe and Luma, in accordance with their own security and compliance  standards. 

Where personal data is temporarily exported for administrative or operational purposes, such  exports are deleted promptly once processing has been completed and are not retained longer  than necessary. 

15. Photographs and event media 

During events, photographs and videos may be taken. 

These materials may be used for community communications, promotional materials, social  media, and website content. By default, the materials used will enable any identification of any  person.  

If we want to use some material where you can be identified, we will always ask for your  consent before using identifiable images.

You may contact Us to withdraw consent at any time. 

16. Automated decision-making 

We DO NOT currently use automated decision-making or profiling that produces legal or  similarly significant effects on individuals. 

If this changes, We will update this Privacy Policy and inform affected users where required. 

We do not use personal information shared within community discussions, private groups,  events, wellbeing activities, or member interactions for behavioral profiling, targeted  advertising, or the automated assessment of an individual's personal characteristics,  preferences, health, wellbeing, or life circumstances. 

17. Changes to this Privacy Policy 

We may update this Privacy Policy from time to time. 

Any updated version will be posted on this page with the revised “Last Updated” date. 

For significant changes, We may provide additional notice through email or website  notifications. 

18. Contact Us 

For questions regarding this Privacy Policy or your privacy rights, please contact: The Modern Reference 

21 rue Glesener, L-1631 Luxembourg 

Email: hello@themodernreference.com

Data Protection Contact: privacy@themodernreference.com