Privacy notice
1. Controller
The controller for the processing of personal data on this website is:
8.2 QHSE GmbH & Co. KG
Am Strande 18
18055
Rostock
Germany
Telephone: +49 381 202 603 22
Email:
info@qhse-campus.de
Further details about our company can be found in our legal notice.
2. General information on data processing and legal bases
Protecting your personal data matters to us. We process personal data solely within the scope of the applicable data protection law, in particular the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
Personal data is any information relating to an identified or identifiable person, for example a name, contact details, an IP address or information about how our website is used.
We process personal data only where this is necessary to provide our website, to communicate with you, to fulfil contractual or legal obligations, or on the basis of your consent. The relevant legal bases are Art. 6(1)(a) GDPR (consent), (b) (contract and pre-contractual measures), (c) (legal obligation) and (f) (legitimate interests). Each is named with the individual processing activities below.
3. Visiting our website (server logs)
Each time our website is accessed, your browser may automatically transmit information to the server hosting our website.
The following data may be processed in particular:
- IP address of the accessing device
- date and time of access
- pages and content accessed
- referrer URL
- browser and browser version used
- operating system
- technical information about the device used
This data is processed in order to provide the website technically, to ensure the security and stability of our systems and to detect possible technical faults.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in providing our website securely, stably and reliably.
We keep our server logs for 30 days and then delete them automatically. In encrypted backups they may persist for up to six months before they are overwritten. Statutory retention obligations remain unaffected. For signed-in accounts we record, for each session, the IP address, device type, browser and operating system as well as the time of the first and last activity. These records protect your account against unauthorised access. The legal basis is Art. 6(1)(f) GDPR. Under “Login details & security” you can log out from all devices at any time. We delete these records 90 days after the last activity.
4. Contacting us
If you contact us by email, by telephone or through a contact form provided on our website, we process the personal data you send us.
This may include in particular:
- name
- contact details
- company
- the content of your enquiry
- any other information you provide when contacting us
We process this data in order to handle your enquiry, to answer follow-up questions and, where applicable, to prepare pre-contractual measures or contractual services.
Depending on the purpose of the contact, the legal basis is Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR.
We erase the data once your enquiry has been dealt with conclusively and no statutory retention obligations or other legitimate grounds for further storage remain.
5. Cookies and comparable technologies
Our website uses cookies. Cookies are small text files stored on your device that may contain certain information.
We use strictly necessary cookies to operate the website: a session cookie for sign-in and the shopping basket that expires one hour after the last activity, a language cookie valid for twelve months, a time zone cookie that ends when the browser is closed, and a cookie that stores your cookie choice (valid for twelve months). On the payment pages Stripe additionally sets the cookies __stripe_mid (twelve months) and __stripe_sid (30 minutes) and a cookie on the domain m.stripe.com. These are created as soon as the payment page is opened and are necessary for secure payment processing. The legal basis is Art. 6(1)(f) GDPR in conjunction with Section 25(2) TDDDG.
With your consent we additionally set attribution cookies (odoo_utm_campaign, odoo_utm_source, odoo_utm_medium; stored for 31 days), which record which campaign or source brought you to us. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), given via the cookie choice on your first visit.
You can withdraw or change your consent at any time with effect for the future via the “Cookie settings” link in the footer of every page. Upon withdrawal, optional cookies already set are deleted.
6. Web analytics and tracking
With your consent we use the self-hosted analytics software Umami to evaluate how our website is used (pages visited, referral source, device type). Umami runs exclusively on our own server in Germany, sets no cookies, stores no full IP addresses and shares no data with third parties. There is no profiling and no cross-device recognition. We transmit the page address and the referral source without URL parameters or anchors. In the customer area, during checkout and on the certificate check page, identification numbers in the address are also replaced by a placeholder.
The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). Without consent, web analytics remains completely switched off. You can withdraw your consent at any time with effect for the future via the “Cookie settings” link in the footer.
When you open our contact or feedback form, we record in pseudonymous form which of these pages were visited. We link that record to a later enquiry. We store an identifier derived from IP address, browser signature and session, together with country, time zone and language. The legal basis is Art. 6(1)(f) GDPR, our legitimate interest being the allocation and handling of enquiries. If neither an enquiry nor a customer account results, we delete this record after 60 days. We use no further third-party analytics or tracking services.
7. Embedded third-party content and services
On the payment pages we load scripts from Stripe (js.stripe.com). This transmits your IP address to Stripe. To detect abuse, Stripe embeds the hCaptcha service there. On all other pages we embed no content or functions from external providers. Fonts, images, scripts and stylesheets are delivered from our own servers. No content delivery network, video platform or map service is called.
Should we embed external content in future, we will name the provider concerned here and use non-essential services only where the requisite data protection conditions are met.
8. QHSE Campus and user accounts
If you use the QHSE Campus and a user account is created for that purpose, we process the personal data required to provide and administer the account.
This may include in particular:
- first name and surname, and on request the date of birth (optional, it appears on the certificate)
- business contact details
- company
- access credentials
- digital self-paced training courses booked or assigned
- learning and completion progress
- results of knowledge checks
- completion and certificate data
The processing serves to provide the QHSE Campus, to deliver and document digital self-paced training courses and to administer participants and companies. The legal basis is performance of the contract under Art. 6(1)(b) GDPR.
For the shop and the customer area we create an account for you with its own password. A separate account is created on the learning platform, and the platform sends you its credentials itself. As soon as a course seat is assigned to a person, we transfer first name, surname and email address to our learning platform, which a service provider runs for us as a processor under Art. 28 GDPR, in order to set up course access. Participation and completion records are returned to us and form the basis of the certificate.
The controller responsible in each case and the applicable legal basis depend on how the QHSE Campus is used and on the underlying contractual relationship.
Every certificate carries a certificate number. Anyone who knows it can call up the course, the completion date and the validity at qhse-campus.de/zertifikat-pruefen without signing in. Your name is not shown there. Without your first name, surname and email address we cannot set up an account or course access, so providing this data is necessary for the conclusion of the contract. Supplementary privacy information about the processing of personal data within the QHSE Campus may be provided separately.
9. Company administration and Campus Managers
Within the QHSE Campus, companies can organise participants and manage instruction courses through a company administration area.
This may involve processing the personal data required to assign participants to companies, to organise instruction courses, to display learning progress and to document completed training.
Campus Managers and authorised contacts are granted access to the information required for administration in line with their respective permissions.
Access to personal data takes place solely within those permissions and for the intended purposes.
10. Surveys and feedback
The QHSE Campus may offer ways to submit feedback, suggestions and requests for topics.
If you take part in such a survey, we process the information you enter in order to develop our offering and the QHSE Campus further. Your answers are linked to your user account. The legal basis is our legitimate interest in improving our offering under Art. 6(1)(f) GDPR.
Where a survey collects personal data beyond this, we inform participants at the survey itself about the scope and purpose of the processing and, where applicable, the legal basis.
11. Recipients of your data
We transfer personal data to third parties only where this is necessary to perform our tasks, where a legal obligation exists or where consent has been given.
Within our organisation, only those departments that need your data to perform the contract have access to it. Beyond that, the following recipients may receive data:
- our tax adviser and, to the extent provided for by law, the tax authorities (for invoice and accounting data)
- our bank (for settling payments made by bank transfer)
- service providers for hosting, IT infrastructure, maintenance and technical support. Servers and backups are held by Hetzner Online GmbH in Germany. An additional encrypted copy of the backups is held by Backblaze, Inc. in the United States. Backups are overwritten after six months at the latest. Odoo S.A., Chaussée de Namur 40, 1367 Ramillies, Belgium, provides our business software. It checks VAT identification numbers for us against the VIES system of the European Commission and adds publicly available company data to incoming enquiries on the basis of the email domain.
- the service provider that operates our learning platform. We transfer the learner's first name, surname and email address as well as the course assignment, so that course access can be created there
- Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland, for processing payments on the payment pages of the shop. We transfer name, email address, billing address, amount and payment details, and for fraud prevention also the IP address together with device and browser information. Stripe embeds the hCaptcha service to detect abuse. The legal basis is Art. 6(1)(b) GDPR, and for fraud prevention Art. 6(1)(f) GDPR
- Microsoft as the operator of our business mailbox, through which we send and receive email. We transfer sender, recipient, subject and content of the message
Where these service providers process personal data on our behalf, they do so under data processing agreements pursuant to Art. 28 GDPR. They process your data solely on our instructions.
12. Transfers to third countries
Website, shop, customer area and learning platform run on infrastructure within the European Union. Our email is sent through Microsoft. That provider belongs to a group headquartered in the United States, so access from a third country cannot be ruled out. The transfer rests on the conditions of Art. 44 et seq. GDPR, in particular on the European Commission's standard contractual clauses and on the adequacy decision for the EU-US Data Privacy Framework. On the payment pages Stripe also processes data through Stripe, Inc. in the United States. An encrypted copy of our backups is held by Backblaze, Inc. in the United States. These transfers rest on the standard contractual clauses of the European Commission.
Should a transfer to a third country become necessary in future, it will take place only where the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision of the European Commission or appropriate safeguards such as standard contractual clauses.
13. Storage period
We store personal data only for as long as it is required for the respective processing purpose or for as long as statutory retention obligations apply. Invoices and accounting records are kept for eight and ten years respectively under Section 147 of the German Fiscal Code and Section 257 of the German Commercial Code.
Fixed technical periods apply to: server logs 30 days, withdrawal declarations with IP address 90 days, notifications in the customer area 180 days and unread notifications 365 days, pseudonymous visit records without a customer account 60 days, session records of signed-in accounts 90 days, daily database dumps 14 days. Backups are overwritten after six months at the latest.
Data in your customer account is stored until you have the account deleted. Enquiries are deleted once they have been dealt with and no statutory retention obligation applies. Once the purpose ceases to apply, the data is erased or, where erasure is technically or legally impossible, its processing is restricted.
14. Your rights
Subject to the statutory requirements, you have in particular the following rights:
- right of access under Art. 15 GDPR
- right to rectification under Art. 16 GDPR
- right to erasure under Art. 17 GDPR
- right to restriction of processing under Art. 18 GDPR
- right to data portability under Art. 20 GDPR
- right to object to processing under Art. 21 GDPR
- right to withdraw consent under Art. 7(3) GDPR
If you have given consent to the processing of personal data, you may
withdraw it at any time with effect for the future. This does not affect
the lawfulness of processing carried out before the withdrawal.
Right to object: Where we process your data on
the basis of legitimate interests (Art. 6(1)(f) GDPR), you may object at
any time on grounds relating to your particular situation. A message to
info@qhse-campus.de is enough.
To exercise your rights, please contact info@qhse-campus.de.
15. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint about our processing of your personal data with a data protection supervisory authority (Art. 77 GDPR).
The supervisory authority responsible for our company is:
The State Commissioner for Data Protection and Freedom of Information
of Mecklenburg-Western Pomerania (Der Landesbeauftragte für Datenschutz
und Informationsfreiheit Mecklenburg-Vorpommern)
Schloss Schwerin
Lennéstraße 1
19053
Schwerin, Germany
16. Data security
We use appropriate technical and organisational measures to protect personal data against loss, destruction, manipulation, unauthorised access and other unauthorised processing.
Our security measures are reviewed and adjusted regularly in line with technical developments and organisational requirements.
17. Updates to this privacy notice
We reserve the right to amend this privacy notice if the technical circumstances, the services we offer or the legal requirements change.
The version published on this website applies in each case.
Last updated: September 2026