Privacy policy
Information about the processing of personal data when you visit compliance-ombudsman.com or contact us.
1. Responsible firm and data protection contact
The controller is Rudolph Rechtsanwälte Partnerschaft mbB, Westtorgraben 1, 90429 Nürnberg, Germany, represented by Dr. Tobias Rudolph. Phone: (+49) 911 999 396-0, email: kanzlei@rudolph-recht.de.
Our data protection officer is Anna Lößlein. You can reach her at the firm’s postal address and at loesslein@rudolph-recht.de.
2. Website visits and hosting
The website is hosted by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. When you visit, your browser transmits the technical data required to deliver the site. This includes, in particular, your IP address, the requested resource, the date and time, the response status, and, where applicable, browser and device information and a referring address if your browser sends one.
This processing serves the operation, stability, and security of the website. The legal basis is Article 6(1)(f) of the General Data Protection Regulation (GDPR); our legitimate interest is in maintaining a functional and secure website. The hosting provider processes the data necessary for this service as an engaged service provider.
Server and error logs are retained only as long as needed to operate the website, resolve errors, and defend against attacks. Once their purpose no longer applies, they are deleted unless a specific security incident, legal proceedings, or statutory obligations require further retention. This website does not analyze personal data for advertising purposes.
3. Cookies, search, and external content
The website itself does not set cookies, use analytics or advertising services, or embed external fonts, maps, videos, or social media plug-ins. The search function searches the provided page content in your browser; it does not transmit search terms to a search service or store them in cookies or local device storage.
External links lead to independent websites. Those sites are accessed only when you open a link. Their own privacy notices apply to their data processing. Email and phone links open the application you have configured.
4. Contacting us
If you contact us by phone, email, or mail, we process your contact details and the content of your inquiry to address your concern. For inquiries about engaging the firm, the legal basis is Article 6(1)(b) GDPR; for other inquiries, it is generally our legitimate interest in responding under Article 6(1)(f) GDPR. Where a legal obligation applies, Article 6(1)(c) GDPR is the relevant basis.
Access is limited to those handling the matter who are bound by confidentiality, and the necessary communications and IT service providers within their respective roles. Data is deleted when the matter is resolved and further retention is no longer necessary for legal obligations or claims. Attorneys’ case files are generally subject to a retention period of six years after the end of the calendar year in which the engagement ended.
Providing information is voluntary; an inquiry may not be answerable without sufficient information or a way to contact you. Unencrypted email does not guarantee confidentiality of its content. Please discuss arrangements with us before sending particularly sensitive documents.
5. Reports within an ombuds engagement
When you make a report, we process, in particular, the information you provide about the events, people involved, and possible evidence, and, where applicable, your identifying and contact details. The purpose is to receive, legally assess, and handle the report within the relevant engagement.
Where we perform reporting office functions under the HinSchG, section 10 HinSchG and the applicable statutory duties apply in particular, together with Article 6(1)(c) GDPR. Outside that framework, Article 6(1)(f) GDPR may apply where its requirements are met; the legitimate interests are the investigation and prevention of legal violations. Special categories of personal data and information about criminal offenses may be processed only if the additional statutory requirements are satisfied.
The specific allocation of controller responsibilities, recipients, and retention rules depends on the engagement and the reporting procedure established. The supplementary privacy notice of the relevant confidential reporting service or reporting office explains these matters. Documentation under the HinSchG is generally deleted three years after the procedure ends; necessary and proportionate statutory exceptions and attorneys’ retention duties must still be observed.
Identifying information is handled in accordance with attorneys’ duties of confidentiality and sections 8 and 9 HinSchG. This does not amount to a blanket assurance that information will never be disclosed to another office or recipient under any circumstances. No decision on your report is made solely by automated means.
6. Your rights
Subject to the statutory requirements, you may request access, rectification, erasure, restriction of processing, and data portability. You may withdraw consent at any time with effect for the future. Statutory duties of confidentiality and retention, and the rights of others, may limit individual entitlements.
Right to object: You may object to processing based on Article 6(1)(f) GDPR on grounds relating to your particular situation. We will then stop processing the data unless the legal requirements for continued processing are met.
You have the right to lodge a complaint with a data protection supervisory authority, particularly in the place of your habitual residence, workplace, or the alleged infringement. The competent authority for private-sector bodies in Bavaria is the Bavarian State Office for Data Protection Supervision (German).
7. Date and further information
This policy is current as of September 13, 2026. Changes to the website or the legal framework may require revisions. You can use the contact details above at any time for data protection inquiries.