Skip to main content
Version 0.2Draft

Legal agreements and templates

Overview

Every LuxID Partner relationship is governed by a single tripartite contract: the LuxID Agreement (referred to as the CIAM Agreement in the contract text itself). This page describes its structure, the key clauses Partners should be aware of, and the template text Partners can adapt for their own privacy notices and user-facing documentation.

caution

All template clauses in this page are marked Template - adapt under legal review. They are starting points, not final legal text. Each Partner's legal counsel must review and adapt the templates for the Partner's own jurisdiction, user base and specific use case before publication.


The LuxID Agreement

Three parties, one contract

The LuxID Agreement is tripartite: it is signed by three parties.

PartyRole
POST LuxembourgOperator of the platform; GDPR controller for user data; counterparty for service, security and SLA matters
LuxID E.I.G.Brand licensor and invoicing party; does not process user personal data
Partner (Client)The organisation integrating LuxID into its applications; independent GDPR controller for any claims received

There is one contract, not three. All three parties sign the same document. Operational matters route to POST; commercial and invoicing matters route to the LuxID E.I.G.; technical integration is the Partner's responsibility.

Structure

A standard LuxID Agreement is structured as a main body plus a set of annexes that form an integral part of the contract:

Main body

ClauseContent
DefinitionsKey terms used throughout the agreement and annexes
PurposeWhat POST and the LuxID E.I.G. undertake to provide
Provision of the CIAM SolutionScope of the service and access to attributes
Service Level AgreementReference to the SLA annex
FeesReference to the fees annex
PaymentInvoicing by LuxID E.I.G.; thirty-day payment terms
Roles and tasks (RACI)Reference to the RACI annex
Obligations of the partiesMutual obligations; specific obligations of POST, LuxID E.I.G. and the Partner
LiabilityLimitation of liability; no joint liability
InsuranceCivil and professional liability insurance requirement
Intellectual propertyOwnership of the platform, brand assets and licence grant
SubcontractingPOST and LuxID E.I.G. may subcontract; remain fully liable
ConfidentialityMutual confidentiality obligations
Data protectionEach party is an independent controller; no sub-processing relationship
Change procedureProcess for Partner-initiated change requests
Representations and warrantiesStandard reps from each party
SecurityReference to the security annexes
Services suspensionGrounds on which POST may suspend the service
Term and terminationIndefinite term from signature; standard and extraordinary termination rights
Force majeureSuspension and termination for force majeure events
Final provisionsAssignment, notices, amendments, severability
Governing law and jurisdictionLuxembourg law; Luxembourg courts

Annexes

AnnexContent
C1Definitions
C2Service Level Agreement (SLA)
C3Fees
C4RACI matrix
C5Client Security Standards (plain-language baseline expected from the Partner)
C6Attributes Catalogue (claims available to Partners)
G1CIAM Solution Specifications (technical architecture, protocols, environments)
G2POST Security Standards (controls and ISO alignment)
P1Ethical Code of Conduct

Key commercial clauses

Permitted use. The agreement constrains what the Partner may do with the integration. Claims received from LuxID may not be sold, the LuxID Solution may not be used as a standalone resold service, and the Partner must comply with the Ethical Code of Conduct.

Claim scope. The Attributes Catalogue (Annex C6) enumerates the claims available. Partners declare at registration which claims they need; requesting claims outside that declared set will be rejected.

Term. The agreement starts on signature and runs for an indefinite period. There is no fixed initial term and no auto-renewal mechanism - it simply continues until a party terminates.

Termination. Either party may terminate without cause on three months' written notice. Extraordinary termination rights apply for material breach (one-month cure period), non-payment, insolvency or regulator-required termination.

Exit. On termination, the Partner must remove the LuxID integration from its applications (including the login button) and certify deletion in writing to POST. LuxID-received claim data must be handled in accordance with the Partner's own GDPR retention obligations.

Liability cap. Each party's liability is capped at the total amount actually paid under the agreement in the twelve months preceding the event. The cap does not apply to liability for violation of data protection legislation. Indirect damages (loss of profits, savings, customer base, contracts, staff costs, data loss) are excluded.

Insurance. Each party must maintain civil and professional liability insurance covering its activities under the agreement and provide a certificate on request.

Fees. The current pricing model (Annex C3) is volume-based on the trailing-12-month peak of unique sign-ups:

Sign-ups (rolling 12 months)Annual service fee
Up to 1,000 usersFree
1,000 to 50,000 usersEUR 25,000
Above 50,000 usersEUR 0.50 per user

Prices are exclusive of VAT and may be indexed annually to the Luxembourg cost-of-living index (STATEC) or adjusted by up to 5% per year.

Suspension. POST may suspend the service for cause, including: scheduled or emergency maintenance, legal or regulatory requirements, suspected fraud, contractual breach, force majeure, unpaid invoices (after 30 days' notice limited to the unpaid service), individual user accounts whose passwords have been compromised, and threats to platform stability.


Why there is no separate data processing agreement

A common question from Partner legal teams is whether a separate Data Processing Agreement (DPA) under GDPR Article 28 (opens in a new tab) is required. The answer is no, and this is by design.

The relationship is controller-to-controller

The LuxID Agreement is explicit that POST and the Partner each act as independent data controllers for their own processing activities. POST is the controller for authentication event data and account profile data; the Partner becomes the controller for any claim it receives from LuxID once that claim is delivered to its application.

The release of claims from LuxID to the Partner is a disclosure between two independent controllers, not a processor acting on instructions. Neither party determines the purposes and means of the other party's processing, so the conditions for either joint controllership (Article 26 (opens in a new tab)) or processor status (Article 28 (opens in a new tab)) are not met.

The LuxID E.I.G. does not process user personal data

The LuxID E.I.G.'s processing activities under the agreement are limited to invoicing-related data about the Partner. It does not process user data. There is therefore no GDPR sub-processing relationship between POST and the LuxID E.I.G., and none between either of them and the Partner.

The LuxID Agreement is the data protection framework

Because there is no processor relationship, the data protection framework is built into the LuxID Agreement rather than alongside it:

  • Article 28-type guarantees are not contractually required, but POST commits to equivalent security obligations through Annex G2 (POST Security Standards, ISO 27001-aligned)
  • Breach notification obligations are set out directly in the main body and the SLA annex - see GDPR and data protection for the contractual 24h Urgent Security Matter clock and the statutory 72h GDPR Article 33 clock
  • The Ethical Code of Conduct (Annex P1) imposes data-minimisation and consent obligations on both POST and the Partner that go beyond GDPR's statutory floor

Partners conducting GDPR due diligence on LuxID should refer to the LuxID Agreement clauses on data protection, the security annexes, and the controller-to-controller disclosure structure. There is no separate DPA to request.

Controller-to-controller disclosure clause

Template - adapt under legal review

If your legal team needs an explicit textual handle on the controller-to-controller relationship for internal documentation, the operative concept is:

LuxID releases the following categories of personal data to the Partner upon successful authentication of a user who has consented to that release: [list of claims]. The disclosure is made between two independent data controllers. Each party is independently responsible for compliance with applicable data protection law in respect of the data it controls following the disclosure. POST Luxembourg acts as controller for the authentication event record; [Partner Name] acts as controller for the disclosed claims from the point of receipt.


Privacy notice template for Partners

Purpose

Every Partner must publish a privacy notice that describes its use of LuxID authentication. The following template provides the sections a Partner privacy notice should include in relation to the LuxID integration. Partners should integrate this into their existing privacy notice rather than publishing it as a standalone document.

Template sections

Template - adapt under legal review


Section heading suggestion: Authentication via LuxID

What is LuxID?

We use LuxID, a Luxembourgish digital identity service operated by POST Luxembourg, to provide secure sign-in to [Partner Service Name]. When you choose to sign in with LuxID, you will be redirected to LuxID's hosted login page at https://login.luxid.lu (opens in a new tab). LuxID authenticates your identity and, with your consent, shares certain information about you with us.

LuxID's own privacy policy is available at https://www.luxid.lu/en/info/terms-and-conditions (opens in a new tab).

What information do we receive from LuxID?

When you sign in with LuxID, we receive the following information from LuxID, subject to your consent:

InformationWhy we use itLegal basis
Email addressTo create and manage your account in [Partner Service Name]Contract (Art. 6(1)(b) GDPR)
Full nameTo personalise your experienceConsent (Art. 6(1)(a) GDPR)
[Add further claims as applicable][State purpose][State lawful basis]

Your rights

You may withdraw your consent to share information with us at any time by visiting your LuxID Account at https://account.luxid.lu/ (opens in a new tab) and removing [Partner Service Name] from the list of applications with access to your LuxID Account. Withdrawing consent does not affect the lawfulness of processing before withdrawal.

For information LuxID holds about you (your authentication history, account profile), exercise your rights via https://account.luxid.lu/ (opens in a new tab) or by contacting LuxID at LuxID.

For information we hold about you on our side following receipt from LuxID, [describe Partner's rights mechanism].

Retention

We retain information received from LuxID for [state retention period]. [Describe deletion procedure on account closure.]

Transfers

LuxID processes your data within the European Union (Luxembourg). We [process / do not process] information received from LuxID outside the EEA. [If processing occurs outside the EEA, describe the transfer mechanism.]


Lawful basis guidance

The two most common lawful bases for claims received from LuxID are:

Contract (Article 6(1)(b)) applies where processing the claim is objectively necessary for the Partner to provide the service the user has requested. The email address is almost always in this category - without it, the Partner cannot create or maintain an account. The necessity test is strict: if the service could function without the claim, contract is not the correct basis.

Consent (Article 6(1)(a)) applies for claims that are useful but not strictly necessary - for example, phone number for optional 2FA in the Partner's own system, or profile picture for personalisation. Consent must be freely given, specific, informed and unambiguous. Because LuxID presents its own consent screen before releasing claims, the LuxID consent covers the release from LuxID. The Partner's own legal basis covers what the Partner does with the claim once received.

Partners should not use legitimate interests (Article 6(1)(f)) as the lawful basis for processing authentication data received from LuxID unless they have completed a documented legitimate interests assessment (LIA) and are satisfied that the user's interests do not override the Partner's interests.


Brand usage agreement

What requires a brand licence

The following elements are protected intellectual property of the LuxID E.I.G. / POST Luxembourg and require the LuxID Agreement to be in place before use:

  • The "LuxID" wordmark
  • The LuxID logo and logo variants
  • The "Sign in with LuxID" button assets
  • Any phrase stating or implying that the Partner is endorsed, certified or approved by LuxID (beyond the factual statement that the Partner uses LuxID authentication)

Permitted uses

Once the LuxID Agreement is signed at the Organization level, the Organization and the Partners created under it may:

  • Display the "Sign in with LuxID" button on their login page using the approved assets provided by LuxID
  • State factually in their privacy notice and marketing materials that their service uses LuxID authentication
  • Use the LuxID wordmark in the context of describing the integration (for example, "We support sign-in with LuxID")

Prohibited uses

Without explicit written permission beyond the LuxID Agreement:

  • The LuxID logo may not be used in a manner that implies partnership at the corporate level (for example, in a "Backed by" or "Partner logos" section)
  • The LuxID wordmark may not be modified, recoloured or distorted
  • The "Sign in with LuxID" button may not be resized below the minimum dimensions or modified in appearance
  • LuxID branding may not appear in advertising in a manner that could be misleading about the nature of the relationship

Template - adapt under legal review

A sample brand attribution clause for a Partner's "About" or "Security" page:

[Partner Service Name] uses LuxID for secure sign-in. LuxID is a Luxembourgish digital identity service operated by POST Luxembourg. The "Sign in with LuxID" button and LuxID logo are trademarks of their respective owners and are used under licence.


Acceptable use clauses

The LuxID Agreement contains standard acceptable use clauses. The following summarises the most material restrictions.

Template - adapt under legal review - the following reflects the standard clauses; review the executed agreement for the binding text.

RestrictionDescription
Authentication onlyLuxID authentication may only be used for the purpose of authenticating users to the Partner's own service. It may not be used as a signal for any other purpose (for example, presence detection, fraud scoring systems not related to the Partner's service, or third-party data enrichment).
No claim resaleClaims received from LuxID may not be sold, licensed, or otherwise transferred to third parties.
No impersonationThe Partner must not use LuxID authentication in a manner that could mislead users into believing they are interacting with LuxID directly.
No reverse engineeringThe Partner must not attempt to reverse-engineer LuxID's authentication mechanisms, token structures or internal APIs.
No automated account creationThe Partner must not use LuxID authentication to programmatically create or enumerate user accounts.
Security reportingThe Partner must report security vulnerabilities discovered in the LuxID platform to LuxID and must not disclose such vulnerabilities publicly before LuxID has had a reasonable opportunity to remediate.

Updated 2026-05-27