TQC Accreditation
HomePrivacy

Privacy notice

What we collect, why we collect it, and what we do not do with it.

Last updated 2026. This notice describes how TQC Accreditation processes personal data through this website.

Who is responsible

TQC Accreditation, Am Bahnhof Westend 9, 14059 Berlin, Germany, is the controller for the personal data described here. Questions about this notice, or requests to exercise any of the rights below, should be sent to info@tqcaccreditation.org.

What we collect

When you submit a form

Your name, email address, and where you provide them your telephone number, organisation, country, certificate number and message. We also record which form you used, the page you were on, the page you first arrived on, any campaign parameters in the link that brought you, and how long you had been on the site. This context tells us what your enquiry is about before we reply.

When you verify a certificate

The certificate number searched, the result, the time, and the IP address of the request. We record this to identify patterns of misuse — for example repeated searches against numbers that do not exist. You are not required to identify yourself in order to verify a certificate, and we do not publish who searched for what.

Automatically

Standard web server logs, retained for a limited period for security and diagnostics. If analytics or advertising tags have been configured for this site, they are listed in the cookies section below; if none are configured, none load.

Why we process it, and on what basis

PurposeLawful basis
Answering your enquiry and any correspondence that followsSteps prior to entering a contract, and legitimate interests
Assessing and administering an accreditationPerformance of a contract, and legal obligation
Operating the certificate register and verification serviceLegitimate interests — enabling third parties to rely on certificates
Detecting misuse of certificates and of the accreditation markLegitimate interests
Site security and diagnosticsLegitimate interests

What we do not do

  • We do not sell personal data, and we do not share it with data brokers.
  • We do not add enquirers to a marketing list. If you write to us, you get a reply, not a sequence.
  • We do not publish the identity of anyone who verifies a certificate.
  • We do not publish confidential information obtained during assessment. The register carries only what a third party needs in order to rely on a certificate.

Who else sees it

Our hosting provider, which stores the site and its data on our instructions; our email provider, which carries our correspondence; and, where they have been configured for this site, the analytics or advertising providers named below. Assessment material is seen by the assessment team and decision panel assigned to your file, and no wider.

We disclose personal data to a public authority only where we are legally required to do so.

How long we keep it

Enquiries that do not lead to an application are kept for up to 24 months and then deleted. Records relating to an accreditation are kept for the period required by our own accreditation rules and by law. Verification logs are kept for up to 24 months. Server logs are kept for a short period only.

Cookies and similar technologies

This site sets no advertising cookies of its own. It uses your browser’s local storage for two small operational things: to remember that you have already submitted a form, so that the enquiry prompt is not shown to you again, and to remember the page you first arrived on so that we have context when you write to us. Neither leaves your browser except as part of a form you choose to submit.

If analytics or advertising tags are configured by the site owner, those providers may set their own cookies. The tags in use, if any, are listed in assets/tracking.js, and where none are configured none are loaded.

Your rights

Where the GDPR applies you may request access to your personal data, correction of inaccurate data, erasure, restriction of processing, portability, and you may object to processing carried out on the basis of legitimate interests. Write to info@tqcaccreditation.org and we will respond within one month.

You also have the right to lodge a complaint with a supervisory authority. In Germany this is the data protection authority for the federal state in which the controller is established.

Transfers outside the EEA

Where a provider we use processes data outside the European Economic Area, that transfer is made under an approved transfer mechanism such as the European Commission’s standard contractual clauses.

Changes

If this notice changes materially, the date at the top of this page changes with it. Substantive changes affecting accredited bodies are also posted on the notices page.