Legal

Privacy Policy

Last updated: April 2026 · This policy explains how RegShield collects, uses, and protects your personal data in accordance with GDPR and Luxembourg law.

Your privacy matters. RegShield is designed with data minimisation at its core. We collect only what is necessary and process it solely for compliance purposes within the European Union.

1. Who We Are

RegShield is an AI-powered regulatory compliance platform operated by Lucas Carneiro, trading as RegShield, based in Luxembourg. We act as a data processor for fund managers (data controllers) and as a data controller for our own website and contact form data.

Contact: hello@regshield.lu

2. What Data We Collect

From fund managers and compliance officers (platform users):

From investors (via the onboarding flow):

From website visitors (regshield.lu):

3. How We Use Your Data

For platform users:

For investors:

For website visitors:

4. Legal Basis for Processing

5. Data Pseudonymisation

All investor personal data is pseudonymised using a unique pseudo_id system. Investor names and contact details are stored separately from compliance records. The audit log references only the pseudo_id — never the investor's real name. This means that even if the audit log were accessed, it would not directly reveal investor identities.

6. Where Your Data is Stored

All data is stored and processed within the European Union on Hetzner Cloud infrastructure based in Germany. No personal data is transferred to third countries outside the EU/EEA. No fund or investor data is shared with third parties except as required by applicable law.

7. Data Retention

8. GDPR Erasure Rights

RegShield supports GDPR Article 17 erasure requests for investor personal data. When an erasure request is processed:

To request erasure, contact: hello@regshield.lu

9. Your Rights Under GDPR

You have the right to:

To exercise any of these rights, contact: hello@regshield.lu

10. AI and Automated Decision-Making

RegShield uses AI for suitability assessments and AML risk scoring. In accordance with GDPR Article 22 and the EU AI Act:

No personal data is used to train our AI models.

11. Cookies

The RegShield landing page (regshield.lu) does not use cookies. The platform (app.regshield.lu) uses only essential session cookies required for authentication. No tracking, advertising, or analytics cookies are used.

12. Security

RegShield implements the following security measures:

13. Third-Party Services

14. Data Protection Officer

RegShield does not currently have a formally appointed Data Protection Officer. For all data protection enquiries, contact: hello@regshield.lu

You also have the right to lodge a complaint with the Commission Nationale pour la Protection des Données (CNPD), Luxembourg's data protection authority, at cnpd.public.lu.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify active users by email of any significant changes. The date at the top of this page indicates when it was last updated.

16. Contact

RegShield · Luxembourg · hello@regshield.lu