Data protection at a glance

1. Controller

The controller responsible for data processing on this website is:
Sachverständigenbüro Reinhard Brandt
Reinhard Brandt
Dorstenerstr. 46
40472 Düsseldorf, Germany
Phone: +49 (0)211 6549230
E-mail: info@sv-brandt.de

2. General information

Protecting your personal data is important to us. We process your data exclusively on the basis of the statutory provisions (GDPR, BDSG, TDDDG). In this privacy policy we inform you about the most important aspects of data processing in connection with our website.

3. Your rights as a data subject

Under the GDPR you have, in particular, the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR)
  • Right to withdraw consent once given (Art. 7 (3) GDPR)

An informal message to the contact details given above is sufficient to exercise these rights.

You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
www.ldi.nrw.de

4. No data protection officer has been appointed

We are not legally obliged to appoint a data protection officer, as fewer than 20 people in our office are permanently engaged in the automated processing of personal data (§ 38 (1) BDSG). For all questions regarding data protection, please contact the controller named above directly.

5. Data collected when visiting the website (server log files)

When you access our website, the hosting provider automatically stores information transmitted by your browser in what are known as server log files. As a rule, these are:

  • IP address of the requesting device
  • Date and time of access
  • Name and URL of the file retrieved
  • Browser used and, where applicable, the operating system
  • Referrer URL (the page visited previously)

Processing takes place on the basis of our legitimate interest in the technically faultless and secure operation of the website (Art. 6 (1) (f) GDPR). This data is not merged with other data sources and is not evaluated to analyse your usage behaviour. Our hosting provider stores website log files for a maximum of 7 days; log files of the e-mail services are stored there for a maximum of 6 months.

6. Hosting and processing on our behalf

Our website and our e-mail accounts are operated by an external service provider:

STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin, Germany

STRATO processes the data arising via the website exclusively on our behalf and in accordance with our instructions. A data processing agreement pursuant to Art. 28 GDPR is in place with STRATO. Processing takes place in data centres in Germany. The legal basis for this is our legitimate interest in the secure and efficient operation of our online offering (Art. 6 (1) (f) GDPR).

7. Contacting us & contact form

If you contact us via the contact form, we process the data you provide (salutation, first and last name, e-mail address, type of report or details of the asset, and your message) in order to handle your enquiry. Providing a telephone number is optional; we only use it if you would like to be contacted by phone. The contents of the form are transmitted exclusively by e-mail to our business address; the form data is not stored in a database on the web server.

The same applies if you contact us by e-mail, by telephone or by post: we process the information you provide in order to deal with your request.

The legal basis is your consent, which you give via the corresponding checkbox before submitting the form (Art. 6 (1) (a) GDPR), the initiation or performance of a contract (Art. 6 (1) (b) GDPR) as well as our legitimate interest in responding to your enquiry (Art. 6 (1) (f) GDPR). You may withdraw your consent at any time with effect for the future.

The data is deleted as soon as it is no longer required for processing your request. If your enquiry leads to an engagement, the correspondence is subject to statutory retention obligations: 6 years as commercial correspondence (§ 257 (4) HGB) or 10 years where it is relevant for tax purposes (§ 147 (3) AO). The periods begin at the end of the respective calendar year.

8. Spam protection and security check in the contact form

To protect our contact forms against automated misuse, we use a procedure we developed ourselves. It deliberately works without external services such as Google reCAPTCHA – no data is therefore transmitted to third parties and no cookies are set. The procedure comprises a simple arithmetic task, an additional field invisible to you, a signed time stamp and a limit on the number of submission attempts.

For this limit we store your IP address exclusively in the form of a cryptographic hash value from which the original IP address cannot be reconstructed, together with the time of the submission attempt. This information is automatically deleted after 24 hours at the latest. The legal basis is our legitimate interest in preventing spam and ensuring the availability of our systems (Art. 6 (1) (f) GDPR).

9. Cookies

No cookies are set for visitors to this website. We do not use any analytics, tracking or marketing cookies and do not embed any services that store or read information on your device. For this reason we also do not need a cookie banner or consent pursuant to § 25 (1) TDDDG.

Only when the password-protected internal area is accessed does the web server set a session cookie (PHPSESSID), which serves exclusively to manage the login session and expires when the browser is closed or you log out. This cookie is strictly necessary for operation and is therefore exempt from consent under § 25 (2) no. 2 TDDDG. It concerns only our own staff, not the publicly accessible pages.

Should we use services requiring consent in future, we will obtain that consent expressly and in advance.

10. Internal, password-protected area

This website has a non-public login area used to maintain our blog posts. When logging in, we process the user name and the password (stored as a cryptographic hash value) as well as – in order to fend off attacks on the login – the number of failed login attempts in combination with a hash value of the IP address. The legal basis is our legitimate interest in the security of our systems (Art. 6 (1) (f) GDPR). Registration by website visitors is not possible.

11. Security scanning of the website (SiteLock)

As part of our hosting contract, our website is automatically scanned daily by STRATO for malware and security vulnerabilities. For this purpose STRATO engages, as a sub-processor, the company SiteLock, LLC, 8701 East Hartford Drive, Suite 200, Scottsdale, AZ 85255, USA. This may involve a transfer of data to the USA – a third country within the meaning of the GDPR.

The transfer is safeguarded by the EU standard contractual clauses pursuant to Art. 46 (2) (c) GDPR, which STRATO has concluded with the sub-processor. The scan covers the files stored on the web server, not the behaviour of individual visitors. The legal basis is our legitimate interest in the security and integrity of our online offering (Art. 6 (1) (f) GDPR).

12. No embedded third-party services

We deliberately do without external content and services. In particular, we do not use:

  • no web analytics or tracking services (e. g. Google Analytics, Matomo)
  • no advertising networks, retargeting or conversion tracking services
  • no social media plug-ins or "like" buttons
  • no external map services (e. g. Google Maps) and no embedded iframes
  • no external fonts – all fonts are loaded from our own server
  • no content delivery networks for program libraries
  • no external video platforms – our corporate video is delivered directly from our server

When you access our pages, no connection to third-party servers is therefore established, and your IP address is not passed on to anyone – apart from the processing on our behalf described in section 6. References to profiles on social networks or to partner organisations are plain text links; data is only transmitted once you actively click such a link.

13. No automated decision-making

Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place.

14. SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the "https://" in the address bar of your browser.

15. Objection to advertising e-mails

We hereby object to the use of contact data published in fulfilment of the legal notice obligation for the purpose of sending advertising and information material that has not been expressly requested. The operators of these pages expressly reserve the right to take legal action in the event of unsolicited advertising being sent, for example by means of spam e-mails.

16. Currency and amendment of this privacy policy

This privacy policy is dated October 2026. Further development of our website or changes in legal requirements may make it necessary to amend this privacy policy. You will always find the current version on this page.