Note: This privacy notice is a draft still to be legally reviewed (Entwurf). It covers the typical processing operations of a consulting website with a contact form; before the site goes live it should be adapted to your specific data processing and the services actually used.

1. Controller

The controller for the processing of personal data within the meaning of the GDPR is:
IngenieurConsult QHSE GmbH
Unter Buschweg 29
50999 Cologne
Managing Director: Andreas Linder
Email: Linder@IngenieurConsult-QHSE.de

2. Collection and storage of personal data

2.1 When visiting the website

When you access our website, the browser used on your device automatically sends information to the server hosting our website. This information is temporarily stored in a so-called log file. The following information is collected without any action on your part and stored until it is automatically deleted:

  • IP address of the requesting device
  • Date and time of access
  • Name and URL of the file accessed
  • Website from which the access originated (referrer URL)
  • Browser used and, where applicable, the operating system of your device

The data is processed to ensure a smooth connection, comfortable use, and to evaluate system security and stability. The legal basis is Art. 6 (1) (f) GDPR.

2.2 When using the contact form

For questions of any kind, we offer you the possibility to contact us via a form on our website. A valid email address is required so that we know who the enquiry is from and can answer it. Further details (company, phone, topic, message) can be provided voluntarily.

The processing of personal data for the purpose of contact takes place pursuant to Art. 6 (1) (a) GDPR on the basis of your voluntarily given consent. Personal data collected by us for the use of the contact form will be deleted automatically after your enquiry has been dealt with, unless legitimate interests or statutory retention obligations preclude this.

3. Disclosure of data

A transfer of your personal data to third parties for purposes other than those listed below does not take place. We only pass on your personal data to third parties if:

  • you have given express consent in accordance with Art. 6 (1) (a) GDPR,
  • disclosure is necessary in accordance with Art. 6 (1) (f) GDPR for the establishment, exercise or defence of legal claims and there is no reason to assume that you have an overriding legitimate interest in your data not being disclosed,
  • there is a legal obligation to disclose pursuant to Art. 6 (1) (c) GDPR,
  • this is legally permissible and necessary pursuant to Art. 6 (1) (b) GDPR for the performance of contractual relationships with you.

4. Cookies

We use cookies on our website. These are small files that your browser automatically creates and that are stored on your device when you visit our site. We use technically necessary cookies to ensure the functionality of our website. These are processed on the basis of Art. 6 (1) (f) GDPR.

Optional analytics cookies are only set after your express consent (Art. 6 (1) (a) GDPR). You can change your selection at any time via the cookie banner.

5. Web hosting and server log files

Our website is hosted by a service provider with server location in Germany. A data processing agreement pursuant to Art. 28 GDPR exists with the hosting provider.

6. Your rights as a data subject

You have the right:

  • pursuant to Art. 15 GDPR to request information about the personal data processed by us,
  • pursuant to Art. 16 GDPR to request the immediate correction of inaccurate personal data or completion of personal data stored by us,
  • pursuant to Art. 17 GDPR to request the deletion of your personal data stored by us, unless processing is required to exercise the right to freedom of expression and information, to fulfil a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims,
  • pursuant to Art. 18 GDPR to request the restriction of the processing of your personal data,
  • pursuant to Art. 20 GDPR to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format, or to request the transmission to another controller,
  • pursuant to Art. 7 (3) GDPR to revoke any consent given to us at any time,
  • pursuant to Art. 77 GDPR to lodge a complaint with a supervisory authority.

7. Right to object

Insofar as your personal data is processed on the basis of legitimate interests pursuant to Art. 6 (1) (f) GDPR, you have the right pursuant to Art. 21 GDPR to object to the processing of your personal data, provided that there are grounds for doing so arising from your particular situation.

8. Data security

During visits to our website we use the widely used TLS (Transport Layer Security) procedure in combination with the highest level of encryption supported by your browser.

9. Currency and changes to this privacy notice

This privacy notice is currently valid. Due to the further development of our website and offerings or due to changed legal or regulatory requirements, it may become necessary to amend this privacy notice.