Last updated 2026. This notice describes how TQC Accreditation processes personal data through this website.
Who is responsible
TQC Accreditation, Am Bahnhof Westend 9, 14059 Berlin, Germany, is the controller for the personal data described here. Questions about this notice, or requests to exercise any of the rights below, should be sent to info@tqcaccreditation.org.
What we collect
When you submit a form
Your name, email address, and where you provide them your telephone number, organisation, country, certificate number and message. We also record which form you used, the page you were on, the page you first arrived on, any campaign parameters in the link that brought you, and how long you had been on the site. This context tells us what your enquiry is about before we reply.
When you verify a certificate
The certificate number searched, the result, the time, and the IP address of the request. We record this to identify patterns of misuse — for example repeated searches against numbers that do not exist. You are not required to identify yourself in order to verify a certificate, and we do not publish who searched for what.
Automatically
Standard web server logs, retained for a limited period for security and diagnostics. If analytics or advertising tags have been configured for this site, they are listed in the cookies section below; if none are configured, none load.
Why we process it, and on what basis
| Purpose | Lawful basis |
|---|---|
| Answering your enquiry and any correspondence that follows | Steps prior to entering a contract, and legitimate interests |
| Assessing and administering an accreditation | Performance of a contract, and legal obligation |
| Operating the certificate register and verification service | Legitimate interests — enabling third parties to rely on certificates |
| Detecting misuse of certificates and of the accreditation mark | Legitimate interests |
| Site security and diagnostics | Legitimate interests |
What we do not do
- We do not sell personal data, and we do not share it with data brokers.
- We do not add enquirers to a marketing list. If you write to us, you get a reply, not a sequence.
- We do not publish the identity of anyone who verifies a certificate.
- We do not publish confidential information obtained during assessment. The register carries only what a third party needs in order to rely on a certificate.
Who else sees it
Our hosting provider, which stores the site and its data on our instructions; our email provider, which carries our correspondence; and, where they have been configured for this site, the analytics or advertising providers named below. Assessment material is seen by the assessment team and decision panel assigned to your file, and no wider.
We disclose personal data to a public authority only where we are legally required to do so.
How long we keep it
Enquiries that do not lead to an application are kept for up to 24 months and then deleted. Records relating to an accreditation are kept for the period required by our own accreditation rules and by law. Verification logs are kept for up to 24 months. Server logs are kept for a short period only.
Cookies and similar technologies
This site sets no advertising cookies of its own. It uses your browser’s local storage for two small operational things: to remember that you have already submitted a form, so that the enquiry prompt is not shown to you again, and to remember the page you first arrived on so that we have context when you write to us. Neither leaves your browser except as part of a form you choose to submit.
If analytics or advertising tags are configured by the site owner, those providers may set their own cookies. The tags in use, if any, are listed in assets/tracking.js, and where none are configured none are loaded.
Your rights
Where the GDPR applies you may request access to your personal data, correction of inaccurate data, erasure, restriction of processing, portability, and you may object to processing carried out on the basis of legitimate interests. Write to info@tqcaccreditation.org and we will respond within one month.
You also have the right to lodge a complaint with a supervisory authority. In Germany this is the data protection authority for the federal state in which the controller is established.
Transfers outside the EEA
Where a provider we use processes data outside the European Economic Area, that transfer is made under an approved transfer mechanism such as the European Commission’s standard contractual clauses.
Changes
If this notice changes materially, the date at the top of this page changes with it. Substantive changes affecting accredited bodies are also posted on the notices page.

