Legal & Privacy Notice

LEGAL & PRIVACY NOTICE

Legal Notice

Information Disclaimer

The content provided on this website (www.dsra.info) is for general informational purposes only and does not constitute binding service or pricing offers. Binding statements are made exclusively within the scope of an individual offer following a review of the respective request.

Despite careful preparation of the content, we assume no responsibility for its accuracy, completeness, or timeliness.

Distinction from Legal Services

Our advisory services do not provide legal services, including legal advice, court representation, or any other services that may only be provided by a qualified legal professional.

Independent Use and Responsibility

The use of the information provided is at your own risk. Any decisions made on the basis of the content presented here are solely the responsibility of the user.

References to External Websites

The content provided on this website may contain links to external websites that are outside our control. We assume no responsibility or liability for the content of these external sites. The respective provider of the linked website is solely responsible for its content.

Protection of Intellectual Property

The content published on this website is protected by copyright, unless otherwise stated. Any use beyond private purposes requires prior written permission.

System-Related Limitations

It cannot be excluded that, due to technical conditions, individual system configurations, or external influences, limitations in the display, use, or accessibility of this website may occur. No liability is assumed for any resulting impairments.

Online inquiries, contact forms, or appointment requests are processed upon receipt but do not constitute a binding confirmation of an appointment or assignment.

Right to Amend Content

The content of this website may be updated, supplemented, or removed at any time without prior notice.

This right to amend content applies exclusively to the information provided on this website. Binding information contained in offers, invoices, or contracts remains unaffected and shall continue to prevail.

Severability Clause

If any individual provisions of these terms are found to be legally invalid or become invalid in the future, the validity of the remaining provisions shall remain unaffected.

 

As of: July 2026

 

Privacy Notice

Thank you for visiting our website www.dsra.info. We place great importance on the protection of your personal data and would like to provide you with transparent information on how we handle it. We explain which of your data is processed when you visit our website. In addition, we inform you about how we process this data in the context of contacting us as well as for the preparation of offers and invoices.

Controller

The data controller responsible for the processing of your data within the meaning of the GDPR is:

DSRA – Digital Security & Regulatory Advisory
Address: Florentisugraben 9, 53111 Bonn | Germany
Phone: +49 (0) 157 3522 8961
Email: dsra@dsra.info

General Information on Data Processing

We process personal data in accordance with the GDPR (General Data Protection Regulation) and the applicable national and European data protection laws.

Personal data, as defined in Article 4 (1) GDPR, refers to any information relating to an identified or identifiable natural person, such as name, address, IP address, or email address.

Our IT systems and devices are secured using technical and organizational measures (TOM) in line with the current state of the art. These measures include, in particular, TLS encryption as well as access protection through PIN codes and biometric authentication methods. In this way, the data you transmit is protected as effectively as possible against unauthorized access.

However, please note that data transmission over the internet may inherently contain security vulnerabilities. Complete protection of data against access by third parties cannot be guaranteed.

The operators of external websites to which we link are solely responsible for their content. When accessing external links, separate data processing activities may occur on those websites.

Data Processing When Visiting Our Website

Our website is hosted by ‘‘STRATO‘‘ (STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin| Germany). When you visit our website, STRATO processes technical data as part of the hosting service (so-called server log files). This may include, in particular, the following data:

  • Website access data: IP address, technical server log files, date and time of access, requested pages/URLs, browser and device information.
  • Domain access data: Technical domain-related information processed when accessing the website.
  • Email data (only when using the contact form or sending an email): Name, if applicable title, email address, if applicable telephone number, and the content of the message.
  • Security data: Data generated through SSL connections and malware scans (e.g., SiteLock).

The processing of this data is necessary to ensure the secure and uninterrupted operation of our website and to maintain the security of our information technology systems.

The legal basis for this processing is Article 6 (1) GDPR. Our legitimate interest lies in the secure, stable, and efficient provision of our website.

Where STRATO processes personal data on our behalf, such processing is carried out on the basis of a Data Processing Agreement in accordance with Article 28 GDPR.

For more information about how STRATO processes personal data, please refer to STRATO's Privacy Policy: https://www.strato.de/datenschutz/.

Contact

You may contact us through various channels, such as the contact form on our website, by email, or by telephone. The personal data transmitted in this context is processed exclusively for the purpose of handling your request and for the related communication. 

If you contact us via the contact form or by email, we process in particular the following data:

  • Name, if applicable title
  • email address, if applicable telephone number
  • content of the message

Your contact details – in particular your name and telephone number – may also be stored on mobile devices so that we can contact you promptly and smoothly if necessary. These data will not be transferred to any cloud services.

The processing of your data is carried out on the basis of Art. 6 (1) (b) GDPR (pre‑contractual measures/contract performance), insofar as your request is aimed at concluding or performing a contract. In all other cases, processing is carried out on the basis of Art. 6 (1) (f) GDPR (legitimate interest).

We have a legitimate interest in receiving and responding to enquiries from interested parties and (potential) customers, and in being able to reach you promptly and without complications. Without processing the data you provide, this would not be possible.

The data collected in the course of contacting us will be deleted once your request has been fully processed, unless they must be retained to fulfill legal or contractual obligations.

Processing of data for preparing offers and issuing invoices

To prepare quotations, invoices, and to manage customer and order data, we use the software ’’Lexware’(Haufe‑Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg im Breisgau, Germany).

In this context, we process the following personal data:

  • Master data: name, address, contact details (telephone number, email)
  • Order and contract data: type and scope of the requested or commissioned services, quotation and invoice numbers, service descriptions
  • Payment data: bank details, payment status, invoice amounts
  • Communication data: correspondence related to the preparation of quotations and the handling of orders.

We process personal data because, in accordance with Article 6 (1) (b) GDPR (pre-contractual measures/contract performance), it is necessary to handle inquiries from prospective clients, prepare offers, and fulfill contracts with our customers.

In addition, we process your data because we are legally obliged under Article 6 (1) (c) GDPR (legal obligation) to retain and document certain information, in particular documents relevant under tax and commercial law. Furthermore, we are required under various statutory provisions — especially the retention obligations under the German Fiscal Code (Abgabenordnung – AO) and the German Commercial Code (Handelsgesetzbuch – HGB) — to store and document certain data.

In some cases, processing is also carried out on the basis of Article 6 (1) (f) GDPR, as we have a legitimate interest in the efficient, secure, and traceable management of our business processes.

The processing is carried out for the preparation of offers, the implementation of pre-contractual measures, the fulfilment of contractual obligations, invoicing, as well as the legally required retention of tax-relevant documents.

Master data, order and contract documents, as well as payment data that are relevant for tax or commercial law purposes, are stored in accordance with statutory requirements under Sections 147 of the German Fiscal Code (AO) and 257 of the German Commercial Code (HGB) for up to 10 years. Business correspondence, including quotation and communication data, is retained for 6 years. Data of prospective clients without a subsequent contractual relationship is generally deleted after 6 months, unless there is a legitimate interest in longer retention.

Further information on data processing by Lexware can be found here: https://datenschutz.lexware.de.

Recipients of Personal Data

Your personal data will not be disclosed to third parties without your explicit consent. Disclosure without explicit consent only takes place where a pre-contractual or contractual relationship exists in accordance with Article 6(1)(b) GDPR, or where disclosure is required by law, for example pursuant to Article 6(1)(c) GDPR to comply with a legal obligation.

Possible recipients include hosting providers (Strato), software providers (Lexware), tax advisors (for bookkeeping and annual financial statements), as well as public authorities in the context of statutory obligations.

Transfer to Third Countries

No transfer of personal data to countries outside the European Union (EU) or the European Economic Area (EEA) takes place.

Data Subjects' Rights

Under the GDPR, you have the following rights with regard to your personal data:

  • Right of access (Art. 15 GDPR) – You may request information about which personal data we process about you.
  • Right to rectification (Art. 16 GDPR) – You have the right to have inaccurate or incomplete data corrected.
  • Right to erasure (Art. 17 GDPR) – You may request the deletion of your personal data, provided that no statutory retention obligations prevent this.
  • Right to restriction of processing (Art. 18 GDPR) – You may request that the processing of your data be restricted.
  • Right to data portability (Art. 20 GDPR) – You have the right to receive the data you have provided to us in a structured, commonly used, and machine-readable format, or to have it transferred to another controller.
  • Right to object (Art. 21 GDPR) – You may object to the processing of your personal data where it is based on legitimate interests.
  • Right to withdraw consent (Art. 7 (3) GDPR) – You may withdraw any consent you have given at any time with effect for the future.
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR) – You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR. For North Rhine-Westphalia, this is the State Commissioner for Data Protection and Freedom of Information (LDI NRW), based in Bonn.

Address: Graurheindorfer Straße 153, 53117 Bonn, Deutschland
Phone: +49 (0) 228 997799-0
Email: poststelle@ldi.nrw.de

If you wish to exercise any of the rights mentioned in this privacy policy, you may contact us at any time. You can reach us using the contact details provided in the “Controller” section.

Currency of this Privacy Notice

This privacy policy is updated as necessary, in particular if we further develop our website or if legal or regulatory requirements change.
 

As of: July 2026

DSRA - Digital Security & Regulatory Advisory © 2026         All rights reserved        Legal & Privacy Notice        Imprint         

Information icon

Wir benötigen Ihre Zustimmung zum Laden der Übersetzungen

Wir nutzen einen Drittanbieter-Service, um den Inhalt der Website zu übersetzen, der möglicherweise Daten über Ihre Aktivitäten sammelt. Bitte überprüfen Sie die Details in der Datenschutzerklärung und akzeptieren Sie den Dienst, um die Übersetzungen zu sehen.