finreg — Capital Markets Consulting ← Back to finreg.de
Legal

Privacy Policy

Last updated: 15 September 2026

1. Data Controller

The controller responsible for data processing under the General Data Protection Regulation (GDPR) and other data protection provisions is:

finreg GmbH
Bismarckstraße 63
52066 Aachen, Germany
info@finreg.de

You can also contact us at the email address above with questions about data protection or to exercise your rights.

2. General Information on Data Processing

We process personal data only to the extent necessary to provide this website securely, communicate with you, or handle your enquiry. The respective purposes, legal bases, recipients, and retention periods are described below.

No automated decision-making, including profiling, takes place.

3. Hosting and Server Log Files

This website is hosted by checkdomain GmbH, Große Burgstraße 27/29, 23552 Lübeck, Germany, support@checkdomain.de. Checkdomain processes data generated when the website is operated as our processor. Where Checkdomain uses subprocessors, this takes place within the contractual arrangements governing commissioned processing.

Whenever the website is accessed, the following data in particular may be processed in access and error logs: IP address, date and time of access, requested page or file, amount of data transferred, referrer URL, browser type and version, operating system, and technical status or error messages.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interests are the delivery of the website, secure and stable operation, fault analysis, and protection against misuse. We do not combine this information with other datasets or use it for advertising.

According to the hosting provider, log files are deleted after no more than 14 days. Where technically possible and appropriate, IP addresses are anonymised after 24 hours.

4. Cookies and Access to End Devices

This website does not use cookies and does not access Local Storage, Session Storage, or comparable information on your device. No analytics, marketing, or tracking technologies are used. Under the website’s current technical configuration, consent pursuant to section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG) and a consent banner are therefore not required.

5. No Analytics or Tracking Services; External Links

We do not use web analytics, tracking, or profiling services. Maps, videos, social media plugins, and other third-party content are not embedded in the website.

The website contains ordinary links to profiles on LinkedIn. Merely visiting our website does not establish a connection to LinkedIn. Only when you click such a link do you leave our website; any subsequent data processing is carried out under the responsibility of the relevant provider.

6. Fonts

All fonts used on this website are delivered locally from our hosting server. Visiting the website does not establish a connection to external font providers such as Google Fonts.

7. Contact Form

The contact form on this website is currently disabled. Submitting it sends an encrypted HTTPS request to the web server; however, the server-side endpoint immediately returns an error before the form fields are evaluated by the application or forwarded by email. The form contents are not persistently stored in a database or mailbox. Technical connection data may be processed in server log files as described in section 3.

Until the form is activated, please contact us directly by email. Before form delivery is enabled, this privacy policy will be updated to reflect the processing that will actually take place.

8. Contact by Email

If you contact us by email, we process the contact details you provide, the content of your message, and the associated communication data in order to handle your enquiry and answer any follow-up questions.

The legal basis is Art. 6(1)(b) GDPR where your message relates to entering into or performing a contract. In all other cases, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is the proper handling of business and other enquiries.

We use Microsoft 365 for email. In particular, Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, receives data as a service provider for the technical delivery and security of email communications. Microsoft may use additional subprocessors in accordance with its contractual data protection terms. Where data is processed outside the European Economic Area, this takes place subject to the requirements of Arts. 44 et seq. GDPR, in particular on the basis of an adequacy decision or appropriate safeguards such as the EU Standard Contractual Clauses.

We delete your enquiry once it has been fully dealt with and no legitimate or statutory grounds require further retention. Where communications are relevant to a contractual relationship or to tax or commercial records, they are retained for the applicable statutory retention period and then deleted, or processing is restricted until that time.

Providing your data is not required by law or contract. Without a reachable email address and the information needed to handle your enquiry, however, we cannot respond.

9. SSL/TLS Encryption

This website uses SSL/TLS encryption. This protects data during transmission between your browser and our server against unauthorised interception.

10. Your Rights

Subject to the applicable statutory requirements, you have the following rights in particular:

  • Right of access (Art. 15 GDPR)
  • Right to rectification of inaccurate data (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR)
  • Right to withdraw any consent given, with effect for the future (Art. 7 para. 3 GDPR)

To exercise your rights, an informal message to info@finreg.de is sufficient. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

11. Special Notice Concerning the Right to Object

Where we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right under Art. 21 GDPR to object to that processing at any time on grounds relating to your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defence of legal claims. You can send your objection to info@finreg.de.

12. Right to Lodge a Complaint with a Supervisory Authority

Under Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority, in particular at your habitual residence, place of work, or the place of the alleged infringement. The authority with particular jurisdiction over finreg GmbH is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
(State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia)
Postfach 20 04 44
40102 Düsseldorf, Germany
Telephone: +49 (0)211 38424-0
Email: poststelle@ldi.nrw.de
www.ldi.nrw.de/kontakt

13. Updates and Amendments

We update this privacy policy when the website, the services used, or legal requirements change. The version published on this page at the relevant time applies.

finreg — Capital Markets Consulting Banking & Capital Markets Consulting
Imprint Privacy Policy © 2026 finreg. All rights reserved.