Version: 13 August 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Collegium Auditores GmbH
Am Apfelbäumchen 4
53757 Sankt Augustin
Germany
Phone: +49 151 10310564
Email: office(at)collegium-auditores.de
Data Protection Officer
You can contact our Data Protection Officer at:
datenschutz(at)collegium-auditores.de
2. General information
We process personal data only insofar as this is necessary to provide this website, handle business enquiries, take pre-contractual or contractual measures, or comply with legal obligations. Our services are primarily directed at companies and other organisations. Business contact details may nevertheless constitute personal data.
The applicable legal basis depends on the purpose of the processing. Relevant bases may include Article 6(1)(a) GDPR for consent, Article 6(1)(b) GDPR for pre-contractual and contractual measures, Article 6(1)(c) GDPR for compliance with legal obligations, and Article 6(1)(f) GDPR for legitimate interests.
3. Hosting and server log files
Our website is hosted by Raidboxes GmbH, Hafenstraße 32, 48153 Münster, Germany. When the website is accessed, technically necessary connection data may be processed in server log files. This may include the IP address, date and time, requested page or file, referrer URL, browser type and version, operating system, amount of data transferred and HTTP status code.
The processing is carried out to provide the website, monitor stability and security, and detect or address attacks and malfunctions. The legal basis is Article 6(1)(f) GDPR. Log data is deleted or anonymised when it is no longer required for these purposes, unless legal or security-related reasons require longer retention.
4. Contacting us
If you contact us by email or another channel, we process the information you provide to handle your enquiry and related follow-up questions. Article 6(1)(b) GDPR applies where the enquiry relates to a contract or pre-contractual measures. In other cases, processing is generally based on Article 6(1)(f) GDPR. Where consent is requested, Article 6(1)(a) GDPR applies.
Communication data is retained only for as long as necessary to process and document the enquiry. Statutory retention obligations and the need to establish, exercise or defend legal claims may require longer retention.
5. Cookies and consent management
Our website may use cookies and comparable technologies. Functions that are technically necessary are used on the basis of section 25(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG) and, where personal data is processed, Article 6(1)(f) GDPR. Technologies that are not necessary are activated only with consent under section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR.
We use Cookiebot CMP, a service provided by Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark, to manage and document consent choices. Data processed may include the consent decision, time and version of consent, a technical identifier, and device and browser information. You can change your selection or withdraw consent for the future through the cookie settings provided on the website.
6. Recipients and processors
Personal data is accessible only to those internal functions and external service providers that require it for the stated purposes. Where required, service providers act on the basis of a data processing agreement under Article 28 GDPR. Other disclosure takes place only where a legal basis exists or we are required to do so by law.
7. Transfers to third countries
For individual services, processing outside the European Union or the European Economic Area cannot be excluded. In these cases, we observe the requirements of Articles 44 et seq. GDPR, for example by relying on an adequacy decision, appropriate safeguards or a statutory derogation. Further information is provided for the relevant service.
8. Retention periods
We retain personal data only for as long as necessary for the relevant purpose. Data is then deleted or anonymised unless statutory retention or accountability duties, or legitimate interests in continued retention, apply. The specific period depends on the type of data, the purpose and the applicable legal requirements.
9. Your rights
Subject to the statutory requirements, you may have rights of access under Article 15 GDPR, rectification under Article 16 GDPR, erasure under Article 17 GDPR, restriction under Article 18 GDPR, data portability under Article 20 GDPR and objection under Article 21 GDPR. Consent may be withdrawn at any time with future effect under Article 7(3) GDPR.
You also have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority generally responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Postfach 20 04 44
40102 Düsseldorf
You may also contact another authority competent under Article 77 GDPR.
10. Objection to processing based on legitimate interests
Where we process personal data on the basis of Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. We will then no longer process the data unless compelling legitimate grounds override your interests, rights and freedoms, or the processing is required for the establishment, exercise or defence of legal claims.
11. Security
We apply appropriate technical and organisational measures to protect personal data against loss, unauthorised access and unlawful processing. The measures are reviewed and adapted in light of the risk and available technology.
12. Changes to this privacy notice
We may update this privacy notice if processing activities, legal requirements or technical services change. The version stated at the beginning applies.
