Privacy Policy
Mustafa Dinc – Dinc Consulting
Last updated: 11 August 2026
1. Controller
The controller within the meaning of Article 4(7) of the General Data Protection Regulation – GDPR – is:
Mustafa Dinc
trading under the business name
Dinc Consulting
Bloisstrasse 42A
79761 Waldshut-Tiengen
Germany
Telephone: +49 178 459 40 12
Email: mustafa.dinc@dincon.org
Website: www.dincon.org
VAT ID No.: DE298370260
Dinc Consulting is the business name of the self-employed sole proprietor Mustafa Dinc and is not a legally independent legal entity.
Data protection enquiries may be sent to the postal address stated above or by email to mustafa.dinc@dincon.org.
2. Subject Matter and Scope of this Privacy Policy
This Privacy Policy provides information about the processing of personal data:
-
when accessing and using the website www.dincon.org;
-
when using the website search function;
-
when using contact forms;
-
when contacting Dinc Consulting by email, telephone or another means of communication;
-
when booking consulting appointments online;
-
when purchasing consulting services or pricing plans;
-
when creating and using a member or user account;
-
when using the blog and any blog notifications that may be offered;
-
when initiating, performing and administering consulting, project and service agreements;
-
during business communications with clients, prospective clients, suppliers, business partners and other professional contacts.
Personal data means any information relating to an identified or identifiable natural person.
3. Principles and Legal Bases of Data Processing
Dinc Consulting processes personal data only where there is a legal basis under data protection law.
3.1 Consent
Where consent is obtained, processing is carried out on the basis of Article 6(1)(a) GDPR.
Consent may be withdrawn at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
3.2 Steps Prior to Entering into a Contract and Performance of a Contract
Where processing is necessary for the performance of a contract or in order to take steps at the request of the data subject prior to entering into a contract, the processing is based on Article 6(1)(b) GDPR.
3.3 Legal Obligations
Where processing is necessary for compliance with legal obligations, it is carried out on the basis of Article 6(1)(c) GDPR.
This includes, in particular, obligations under tax, commercial, supervisory, documentation and record-keeping law.
3.4 Legitimate Interests
Where processing is necessary for the purposes of the legitimate interests pursued by Dinc Consulting or a third party and those interests are not overridden by the interests, fundamental rights or freedoms of the data subject, the processing is based on Article 6(1)(f) GDPR.
Legitimate interests may include, in particular:
-
the secure, stable and functional provision of the website;
-
the handling of and response to business enquiries;
-
the initiation and maintenance of client and business relationships;
-
the organisation and documentation of consulting services;
-
the improvement of the website and the services offered;
-
the prevention of misuse, fraud, cyberattacks and other security risks;
-
the establishment, exercise or defence of legal claims.
3.5 Special Categories of Personal Data
Special categories of personal data within the meaning of Article 9(1) GDPR, in particular health data, are processed only where this is necessary for an expressly agreed purpose and an additional legal basis under Article 9(2) GDPR applies.
The relevant legal bases, information obligations and data subject rights arise in particular from Articles 6, 9 and 12 to 22 GDPR.
4. Hosting and Technical Provision of the Website by Wix
4.1 Provider
The website is provided through the Wix platform. The provider is:
Wix.com Ltd.
Yunitsman 5 St
Tel Aviv
Israel
Wix provides, in particular, the technical infrastructure, hosting, databases, security functions, contact forms, booking functions, member functions, pricing plans and other website functions.
Where Wix processes personal data of website visitors, clients or members on behalf of Dinc Consulting, Wix acts as a processor. Dinc Consulting remains responsible for determining the purposes and means of the processing. A publicly available and binding data processing agreement exists between Wix and its users. For certain processing purposes of its own, Wix may also act as an independent controller.
4.2 Data Processed When the Website Is Accessed
When the website is accessed, the following data may be processed in particular:
-
IP address of the device used;
-
date and time of access;
-
page or file accessed;
-
access status and error messages;
-
volume of data transferred;
-
previously visited website or referrer URL;
-
browser type and browser version;
-
operating system;
-
device type and device settings;
-
language settings;
-
screen resolution;
-
internet service provider;
-
approximate geographical location based on the IP address;
-
session, security and device identifiers;
-
information about page navigation, clicks and technical use.
4.3 Purposes of Processing
The processing is carried out in particular for the following purposes:
-
establishing a connection to the website;
-
displaying the website correctly;
-
providing the requested content and functions;
-
ensuring stability and information security;
-
detecting and preventing unauthorised access;
-
error analysis and technical administration;
-
fraud and misuse prevention;
-
performance of contractual and pre-contractual services.
4.4 Legal Basis
The processing of technically necessary data is based on Article 6(1)(f) GDPR.
The legitimate interest lies in the secure, stable and functional provision of the website.
Where access to a website function directly serves to initiate or perform a contract, the processing is additionally based on Article 6(1)(b) GDPR.
4.5 Storage Period
Technical log and security data are deleted or anonymised as soon as they are no longer required for the purposes stated.
Data may be stored for a longer period where:
-
a security incident must be investigated;
-
there are indications of unlawful use;
-
the data are required for the establishment or defence of legal claims;
-
statutory retention obligations apply.
Where Wix determines the technical storage period, it is governed by Wix's contractual and technical deletion and security policies.
5. Encryption and Data Security
The website is provided through an encrypted HTTPS connection. This is intended to protect data transmitted between the visitor's browser and the website from unauthorised access.
Taking into account the state of the art, implementation costs, the nature, scope and purposes of processing and the respective risks, Dinc Consulting and the service providers used implement appropriate technical and organisational security measures.
Where applicable, these include:
-
encrypted data transmission;
-
physical and logical access controls;
-
secure passwords;
-
multi-factor authentication;
-
authorisation and role concepts;
-
regular updating of the systems used;
-
data backups;
-
logging of security-relevant events;
-
limiting data access to persons who require it;
-
contractual obligations imposed on processors and other service providers used.
Despite appropriate safeguards, completely risk-free data transmission over the internet cannot be guaranteed.
6. Cookies and Similar Technologies
6.1 General Information
The website uses cookies and similar technologies. These may include, in particular:
-
session cookies;
-
persistent cookies;
-
local storage;
-
session storage;
-
pixels;
-
tags;
-
device and session identifiers.
Cookies are small files or units of information that may be stored on or read from a website visitor's device.
6.2 Technically Necessary Cookies and Technologies
Technically necessary cookies and similar technologies may be used to:
-
provide the website securely;
-
enable page navigation and basic functions;
-
store language settings;
-
manage sessions;
-
provide login and member functions;
-
enable booking and ordering processes;
-
provide shopping basket or pricing plan functions;
-
store the privacy settings selected by the visitor;
-
detect attempted fraud and misuse;
-
ensure the stability and security of the website.
In these cases, information is stored on or accessed from the device on the basis of Section 25(2) TDDDG.
Where personal data are subsequently processed, the processing is based, depending on the function, on Article 6(1)(b) or Article 6(1)(f) GDPR.
6.3 Non-Essential Cookies and Technologies
Analytics, statistics, convenience or marketing technologies are used only where the website visitor has first given consent through the consent management system used.
In this case, information is stored on or read from the device on the basis of Section 25(1) TDDDG. The subsequent processing of personal data is based on Article 6(1)(a) GDPR.
Section 25 TDDDG generally requires consent for storing information on or reading information from a device unless the relevant technology is strictly necessary.
6.4 Cookie Banner and Consent Management
Dinc Consulting uses the consent management system integrated into the Wix platform.
Through the cookie banner, website visitors can:
-
consent to non-essential cookies and technologies;
-
select individual categories;
-
reject non-essential processing;
-
withdraw consent previously given with effect for the future.
For this purpose, Wix provides privacy and consent management functions that can block non-essential cookies and record consent decisions.
6.5 Consent Record
For the purpose of documenting consent or refusal, the following data may be processed in particular:
-
consent status;
-
selected categories;
-
date and time of the decision;
-
pseudonymous session or consent identifier;
-
device and browser information;
-
version of the consent wording.
The processing is carried out to comply with statutory record-keeping and accountability obligations on the basis of Article 6(1)(c) GDPR in conjunction with Article 7(1) GDPR.
6.6 Changing Cookie Settings
Cookie settings may be changed at any time through the privacy or cookie settings function provided on the website.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
The specific cookies, providers, purposes, categories and storage periods are set out in the current information provided in the cookie settings.
7. Statistics and Audience Measurement
The Wix platform provides technical statistics and analytics functions.
Where Dinc Consulting processes personal data or device-related data for audience measurement beyond technically necessary security and operational statistics, this is done only after prior consent.
The following information may be processed in particular:
-
pages accessed;
-
time and duration of a visit;
-
clicks and navigation paths;
-
source of the website visit;
-
device used;
-
operating system and browser;
-
approximate geographical origin;
-
new and returning visits;
-
form submissions;
-
bookings;
-
orders or other conversions.
The processing serves statistical evaluation and the technical and content-related improvement of the website.
The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR.
Without consent, non-essential personal analytics and marketing functions are not activated.
Wix states that non-essential analytics and third-party functions must be made dependent on the website visitor's prior consent through a cookie banner.
8. Website Search
The website provides a search function.
When the search function is used, the following data may be processed in particular:
-
search term entered;
-
time of the search;
-
search results accessed;
-
session identifier;
-
IP address;
-
browser and device information.
The processing is carried out in order to display relevant website content and provide the search function technically.
The legal basis is Article 6(1)(f) GDPR. The legitimate interest lies in providing the website in a user-friendly and functional manner.
Any further evaluation of search terms for analytics purposes takes place only where consent has been given for this purpose.
9. Contact Form
Contact forms are provided on the website. The publicly visible forms request, in particular, a name, email address and subject or information concerning the enquiry.
9.1 Data Processed
When a contact form is used, the following data may be processed in particular:
-
name;
-
email address;
-
subject;
-
content of the enquiry;
-
company and professional role, where provided;
-
telephone number, where provided;
-
other information provided voluntarily;
-
date and time of submission;
-
IP address;
-
technical log and security data.
9.2 Purposes
The processing is carried out for the following purposes:
-
handling and responding to the enquiry;
-
communicating with the person making the enquiry;
-
preparing an offer;
-
taking steps prior to entering into a contract;
-
documenting the communication;
-
preventing misuse or unlawful use.
9.3 Legal Bases
Where the enquiry relates to a possible or existing contract, the processing is based on Article 6(1)(b) GDPR.
Where the person making the enquiry acts as a contact person for a company, the processing may be based on Article 6(1)(f) GDPR. The legitimate interest lies in handling business enquiries and communicating with clients and business partners.
9.4 Storage Period
Enquiries are generally deleted as soon as they have been conclusively dealt with and there are no statutory retention obligations or legitimate reasons for further storage.
Where the communication is relevant to a contractual relationship, invoicing, tax records or the defence of legal claims, it may be stored for a longer period in accordance with statutory retention and limitation periods.
9.5 No Confidential or Particularly Protected Data
The following data, in particular, should not be transmitted through publicly accessible contact forms:
-
patient data;
-
health data;
-
clinical raw data;
-
personal complaint or vigilance data;
-
passwords or access credentials;
-
trade secrets;
-
confidential technical documentation;
-
unpublished regulatory documents.
Appropriate secure transmission methods must be agreed with Dinc Consulting in advance for confidential or particularly sensitive information.
10. Contact by Email or Telephone
When Dinc Consulting is contacted by email or telephone, Dinc Consulting processes the data provided by the person making the enquiry.
This may include, in particular:
-
name;
-
company;
-
professional role;
-
email address;
-
telephone number;
-
content of the enquiry;
-
documents transmitted;
-
date and time of the communication;
-
other information provided voluntarily.
The processing is carried out to handle the enquiry, conduct business communications and, where applicable, initiate or perform a contractual relationship.
The legal basis is Article 6(1)(b) GDPR where the communication serves to initiate or perform a contract.
In all other cases, the processing is based on Article 6(1)(f) GDPR. The legitimate interest lies in the appropriate handling and documentation of business communications.
Emails may be processed through the email, hosting or IT service provider used by Dinc Consulting. These service providers may act as processors.
Without additional end-to-end encryption, ordinary email communication is not fully protected against access by third parties. Particularly confidential information should therefore be transmitted only through secure transmission methods agreed in advance.
11. Online Appointment Booking via Wix Bookings
The website provides the option to book consulting services and appointments online. The Wix booking function is used for this purpose. Several bookable consulting services are currently displayed on www.dincon.org.
11.1 Data Processed
When a booking is made, the following data in particular may be processed:
-
first name and surname;
-
email address;
-
telephone number;
-
company and professional role;
-
selected consulting service;
-
requested appointment;
-
time zone;
-
booking status;
-
messages and project-related information;
-
client or member account;
-
invoicing and payment information;
-
date and time of the booking;
-
technical usage and security data.
Wix Bookings may create contact cards for booking clients containing contact details such as email addresses and telephone numbers.
11.2 Purposes
Processing is carried out for the following purposes:
-
carrying out the appointment booking;
-
checking availability;
-
confirming the appointment;
-
organising and providing the consulting service;
-
communicating appointment changes;
-
sending service-related appointment reminders;
-
invoicing;
-
processing cancellations or rescheduling requests;
-
documenting the contractual relationship;
-
preventing misuse and fraud.
11.3 Legal Bases
Processing is based on Article 6(1)(b) GDPR.
Where statutory documentation and retention obligations apply, further retention is based on Article 6(1)(c) GDPR.
Security and misuse-related data may be processed on the basis of Article 6(1)(f) GDPR.
11.4 Service-related Booking Messages
Booking confirmations, appointment changes, reminders and other messages directly connected with the booked service constitute contractual communications and are not advertising.
Processing is based on Article 6(1)(b) GDPR.
12. Pricing Plans, Orders and Purchase of Consulting Services
A paid pricing plan or consulting service may be purchased through the website. The pricing-plan page currently includes a paid plan with a direct purchase option.
12.1 Data Processed
When a pricing plan or consulting service is purchased, the following data in particular may be processed:
-
first name and surname;
-
business contact details;
-
company;
-
billing address;
-
VAT identification number;
-
selected service or pricing plan;
-
start and duration of the contract;
-
order and contract data;
-
price and currency;
-
transaction number;
-
payment status;
-
selected payment method;
-
date and time of conclusion of the contract;
-
technical security and fraud-prevention data.
12.2 Purposes
Processing is carried out for the following purposes:
-
carrying out the ordering process;
-
entering into and performing the contract;
-
administering the purchased pricing plan;
-
processing payments;
-
issuing invoices;
-
accounting;
-
handling enquiries;
-
preventing misuse and fraud;
-
complying with statutory retention obligations.
12.3 Legal Bases
Processing is based on Article 6(1)(b) GDPR.
Processing for tax, commercial or accounting purposes is based on Article 6(1)(c) GDPR.
Measures to prevent misuse and fraud may be based on Article 6(1)(f) GDPR.
13. Payment Processing
Where online payment is offered in connection with a booking or order, payment is processed through the payment service provider displayed in the relevant checkout process.
When a payment method is selected, the following data in particular may be transmitted to the payment service provider:
-
name;
-
billing address;
-
email address;
-
order and contract data;
-
invoice amount;
-
currency;
-
transaction identifier;
-
payment status;
-
payment data required for the selected payment method;
-
security and fraud-prevention data.
The payment service provider generally processes payment data under its own responsibility under data protection law. The payment service provider's privacy information applies to its processing activities.
As a general rule, Dinc Consulting receives only the information required to allocate, confirm and process the payment, for example:
-
payment status;
-
transaction number;
-
payment date;
-
amount;
-
payment method;
-
shortened or masked payment information, where applicable.
Complete credit card details or online banking access credentials are generally not stored by Dinc Consulting.
The legal basis for payment processing is Article 6(1)(b) GDPR.
Where data are retained because of statutory retention obligations, processing is based on Article 6(1)(c) GDPR.
14. Member and User Account
The website has a login and member function. Registered users can register and log in and out using the login bar.
14.1 Data Processed
When an account is registered and used, the following data in particular may be processed:
-
name;
-
email address;
-
encrypted or hashed password information;
-
registration date;
-
login and logout times;
-
account status;
-
booked services;
-
purchased pricing plans;
-
booking and order history;
-
settings;
-
technical security and usage data.
14.2 Purposes
Processing is carried out for the following purposes:
-
creating and administering the user account;
-
authentication;
-
providing protected content and functions;
-
administering bookings and pricing plans;
-
ensuring account security;
-
communicating about account-related matters;
-
preventing unauthorised access.
14.3 Legal Bases
Where the user account is required in order to use booked or requested services, processing is based on Article 6(1)(b) GDPR.
Security and administration data are processed on the basis of Article 6(1)(f) GDPR.
14.4 Deletion of the Account
The user account can generally be deleted upon request.
Immediate and complete deletion is not possible where:
-
contractual matters remain outstanding;
-
statutory retention obligations apply;
-
data are required for the establishment or defence of legal claims;
-
security or misuse incidents are still being investigated.
In such cases, the data concerned are restricted from use for other purposes and deleted once the reason for retention ceases to apply.
15. Blog and Professional Content
The website contains a publicly accessible blog.
When blog posts are merely read, only the data that are also processed during general access to the website are generally processed.
Where a registration, subscription or notification function is offered and used, the following data in particular may be processed:
-
name;
-
email address;
-
registration or subscription status;
-
date and time of registration;
-
confirmation status;
-
IP address;
-
selected settings;
-
interactions with messages sent.
Voluntarily subscribed professional information or blog notifications are sent on the basis of consent in accordance with Article 6(1)(a) GDPR.
A double opt-in process may be used to confirm registration. In this process, a message is sent to the email address provided, through which the registration must be confirmed.
Consent may be withdrawn at any time through an unsubscribe link included in the relevant message or by notifying Dinc Consulting.
Service-related messages concerning an existing booking, order, contract or user account are not marketing messages and may be sent on the basis of Article 6(1)(b) GDPR.
16. Downloads and Documents Provided
Documents, presentations, curricula vitae, certificates or other files may be made available for download on the website.
When a file is accessed or downloaded, the same technical data are generally processed as when the website is otherwise accessed, including in particular:
-
IP address;
-
time of the download;
-
file accessed;
-
browser and device information;
-
referrer URL;
-
security and log data.
Processing is carried out in order to provide the requested document and ensure technical security.
The legal basis is Article 6(1)(f) GDPR.
17. Data Processing in Connection with Consulting and Project Engagements
In connection with the initiation and performance of consulting, project, audit, quality management, regulatory affairs, compliance and other services, Dinc Consulting processes personal data relating to:
-
clients and prospective clients;
-
employees and contact persons of clients;
-
suppliers and service providers;
-
auditors;
-
external consultants;
-
representatives of authorities and associations;
-
employees of Notified Bodies or certification bodies;
-
other project participants.
17.1 Data Processed
This may include, in particular:
-
name;
-
business contact details;
-
employer and professional role;
-
communication data;
-
offer, contract and project data;
-
project assignment;
-
appointment and activity records;
-
billing data;
-
professional assessments and statements;
-
approval and decision information;
-
audit and action information;
-
tasks, responsibilities and processing status;
-
other project-related information.
17.2 Purposes
The processing is carried out for the following purposes:
-
preparing offers;
-
initiating contracts;
-
performing and managing projects;
-
professional communication;
-
preparing work products;
-
documenting the services provided;
-
quality assurance;
-
tracking appointments and actions;
-
billing;
-
complying with legal obligations;
-
establishing and defending legal claims.
17.3 Legal Bases
Where the data subject is personally a contracting party, the processing is based on Article 6(1)(b) GDPR.
Where the data subject acts as a contact person, employee or representative of a company, the processing is generally based on Article 6(1)(f) GDPR. The legitimate interest lies in the proper initiation, performance and documentation of the business relationship.
Processing required by law is carried out on the basis of Article 6(1)(c) GDPR.
18. Processing on Behalf of a Client
Where Dinc Consulting processes personal data exclusively in accordance with a client's documented instructions, Dinc Consulting may act as a processor within the meaning of Article 28 GDPR.
In such a case, a separate data processing agreement is concluded before the processing begins.
The agreement regulates, in particular:
-
the subject matter and duration of the processing;
-
the nature and purpose of the processing;
-
categories of personal data;
-
categories of data subjects;
-
the client's rights to issue instructions;
-
confidentiality obligations;
-
technical and organisational measures;
-
the use of sub-processors;
-
assistance with data subject rights and data protection incidents;
-
return and deletion of the data after the end of the contract.
In such a case, responsibility under data protection law towards the data subjects generally lies with the respective client as controller.
19. Health Data and Other Particularly Sensitive Data
Due to Dinc Consulting's activities in the medical device and life sciences sector, access to health data or other special categories of personal data cannot be entirely ruled out in individual projects.
This may, for example, concern data contained in the following contexts:
-
complaint handling;
-
vigilance;
-
post-market surveillance;
-
field safety corrective actions;
-
clinical evaluations;
-
clinical investigations;
-
risk assessments;
-
CAPA and non-conformity procedures;
-
technical or regulatory documentation.
Such processing takes place only where:
-
it is necessary for the expressly agreed engagement;
-
there is an adequate legal basis under Article 6 GDPR;
-
an exception under Article 9(2) GDPR additionally applies;
-
the data protection roles of the parties involved have been clarified;
-
a data processing agreement has been concluded where required;
-
appropriate technical and organisational safeguards have been defined;
-
the data have been anonymised or pseudonymised where possible.
Dinc Consulting generally requires that only the data necessary for the relevant purpose be provided.
Personal patient data and health data should not be transmitted through ordinary email channels or publicly accessible website forms.
20. Sources of Personal Data
Dinc Consulting generally obtains personal data directly from the data subject.
Business contact data may also originate from the following sources:
-
the data subject's employer or company;
-
clients or business partners;
-
joint project participants;
-
business correspondence;
-
publicly accessible company websites;
-
publicly accessible professional networks;
-
trade fair, event or participant information;
-
recommendations or professional contacts;
-
communications with authorities, certification bodies or auditors.
As a general rule, only data required for business communications or the performance of the relevant project are processed, in particular:
-
name;
-
company;
-
professional role;
-
business email address;
-
business telephone number;
-
project-related responsibility.
The processing is based on Article 6(1)(f) GDPR. The legitimate interest lies in initiating, performing and maintaining business relationships and ensuring proper project communication.
Data subjects may object to this processing in accordance with Article 21 GDPR.
21. Recipients and Categories of Recipients
To the extent necessary and legally permissible, personal data may be transmitted in particular to the following recipients or categories of recipients:
-
Wix.com Ltd. and affiliated companies;
-
Wix sub-processors;
-
hosting, IT, cloud, maintenance and security service providers;
-
email and communications service providers;
-
payment service providers;
-
banks and financial institutions;
-
tax advisers and accounting service providers;
-
lawyers and other professional advisers;
-
insurers;
-
freelancers, external specialists and subcontractors;
-
clients and project partners, where required for the engagement;
-
authorities, courts and other public bodies;
-
Notified Bodies, certification bodies, testing laboratories or auditors, where required and agreed for the relevant project.
Processors are generally engaged on the basis of an agreement in accordance with Article 28 GDPR.
Personal data are disclosed only where:
-
this is necessary for performance of a contract;
-
a legal obligation applies;
-
a legitimate interest exists and is not overridden by the data subject's interests;
-
valid consent has been given;
-
another statutory legal basis applies.
22. Transfers to Third Countries
Personal data may also be processed outside the European Union or the European Economic Area.
A transfer to a third country takes place only where the requirements of Articles 44 to 49 GDPR are met.
The following may serve as the basis for such a transfer, in particular:
-
an adequacy decision of the European Commission;
-
standard contractual clauses approved by the European Commission;
-
additional technical and organisational safeguards;
-
certification under the EU-US Data Privacy Framework;
-
binding corporate rules;
-
explicit consent;
-
another legally permitted exception.
According to its own information, Wix may store or process personal data in the European Union, Israel, the United States, South Korea and Taiwan, among other locations, and potentially in other countries.
Wix.com Ltd. is established in Israel. An adequacy decision of the European Commission is in place for Israel. Wix also states that it uses, in particular, standard contractual clauses and supplementary safeguards for transfers to countries without an adequacy decision. For appropriately certified recipients in the United States, the EU-US Data Privacy Framework may serve as the basis for the transfer.
Data subjects may request information about the relevant transfer mechanisms and, where provided by law, a copy of the essential safeguards.
23. Retention Period and Deletion
Dinc Consulting stores personal data only for as long as necessary for the relevant processing purpose.
The data are then deleted or anonymised unless statutory retention obligations or legitimate grounds for further storage apply.
23.1 Contact and General Enquiry Data
Data from general enquiries are generally deleted once the enquiry has been fully dealt with.
Where communication is required for documentation, the processing of follow-up questions or the defence of potential claims, it may generally be stored until expiry of the regular limitation period.
23.2 Contract and Project Data
Contract, offer and project data are generally stored for the duration of the contractual relationship and thereafter for as long as necessary to comply with legal obligations or to establish and defend legal claims.
23.3 Booking and Payment Data
Booking, invoice, payment and accounting records are stored in accordance with the applicable tax and commercial-law retention periods.
Depending on the type of document, Section 147 of the German Fiscal Code (AO) provides, in particular, for retention periods of:
-
ten years for certain books, records and annual financial statements;
-
eight years for accounting vouchers;
-
six years for certain business correspondence and other tax-relevant documents.
23.4 User Accounts
Data associated with a user account are generally stored for the duration of the account.
Following deletion of the account, individual contract, booking, payment or documentary evidence data may continue to be stored due to statutory retention obligations or for the defence of legal claims.
23.5 Consents
Data documenting consent are stored for as long as necessary to demonstrate that valid consent was obtained.
Following withdrawal, documentary evidence may be stored until the expiry of possible limitation periods.
23.6 Limitation Periods
The regular limitation period under civil law is generally three years and normally begins at the end of the year in which the claim arose and the statutory knowledge requirements were met.
23.7 Processing on Behalf of a Client
Where Dinc Consulting acts as a processor, the deletion or return of personal data is governed by the client's documented instructions and the relevant data processing agreement.
24. Obligation to Provide Personal Data
The provision of personal data may be necessary in order to:
-
respond to an enquiry;
-
book an appointment;
-
create a user account;
-
purchase a pricing plan or consulting service;
-
enter into a contract;
-
provide a consulting or project service;
-
process a payment;
-
issue an invoice;
-
comply with legal obligations.
Without the data identified as required, the relevant enquiry, booking, order, registration or contractual service may not be capable of being processed or provided.
The provision of any additional information is voluntary unless expressly stated otherwise.
25. Automated Decision-Making and Profiling
Dinc Consulting does not generally make decisions based solely on automated processing that produce legal effects concerning a data subject or similarly significantly affect that person.
Where statistical or security functions analyse data automatically, this is done exclusively for technical, statistical or security-related purposes.
No automated decision within the meaning of Article 22 GDPR that produces legal or similarly significant effects takes place as a result.
26. Rights of Data Subjects
Subject to the applicable statutory requirements, data subjects have the following rights in particular:
26.1 Right of Access
Under Article 15 GDPR, a data subject may request information as to whether and which personal data concerning that person are processed by Dinc Consulting.
26.2 Right to Rectification
Under Article 16 GDPR, a data subject may request the correction of inaccurate personal data and the completion of incomplete personal data.
26.3 Right to Erasure
Under Article 17 GDPR, a data subject may request the erasure of personal data where the statutory requirements are met.
In particular, the right to erasure does not apply where further processing is necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.
26.4 Right to Restriction of Processing
Under Article 18 GDPR, a data subject may request restriction of processing where the statutory requirements are met.
26.5 Right to Data Portability
Under Article 20 GDPR, and subject to the statutory requirements, a data subject may receive in a structured, commonly used and machine-readable format data that the person has provided to Dinc Consulting and that are processed by automated means on the basis of consent or a contract.
26.6 Right to Withdraw Consent
Under Article 7(3) GDPR, consent that has been granted may be withdrawn at any time with effect for the future.
The lawfulness of processing carried out before the withdrawal remains unaffected.
26.7 Right to Object
Where personal data are processed on the basis of Article 6(1)(e) or (f) GDPR, the data subject has the right under Article 21 GDPR to object to the processing at any time on grounds relating to the data subject's particular situation.
Dinc Consulting will then no longer process the personal data unless Dinc Consulting demonstrates compelling legitimate grounds for the processing that override the interests, rights and freedoms of the data subject or the processing serves the establishment, exercise or defence of legal claims.
Where personal data are processed for direct marketing purposes, the data subject may object to such processing at any time without stating reasons. Following the objection, the personal data will no longer be used for direct marketing.
26.8 Right to Lodge a Complaint
Under Article 77 GDPR, data subjects have the right to lodge a complaint with a data protection supervisory authority.
Data subject rights arise in particular from Articles 15 to 22 GDPR.
27. Exercising Data Subject Rights
Data subjects may contact Dinc Consulting at the following details in order to exercise their rights:
Mustafa Dinc – Dinc Consulting
Bloisstrasse 42A
79761 Waldshut-Tiengen
Germany
Email: mustafa.dinc@dincon.org
Telephone: +49 178 459 40 12
Where Dinc Consulting has reasonable doubts concerning the identity of the person making the request, Dinc Consulting may request additional information necessary to confirm that person's identity.
Requests are generally processed within the statutory time limits.
28. Competent Data Protection Supervisory Authority
Data subjects may lodge a complaint with any competent data protection supervisory authority.
The following supervisory authority is generally competent for Dinc Consulting:
The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
Street address:
Heilbronner Straße 35
70191 Stuttgart
Germany
Postal address:
Postfach 10 29 32
70025 Stuttgart
Germany
Telephone: +49 711 615541-0
Email: poststelle@lfdi.bwl.de
The office of the State Commissioner has been located at Heilbronner Straße 35 in Stuttgart since 22 December 2025.
29. Data Relating to Minors
Dinc Consulting's services are generally directed at companies, self-employed persons, professional contacts and other business clients.
Dinc Consulting does not intend to collect personal data relating to children specifically through the website.
Should Dinc Consulting become aware that a child's personal data have been processed without a sufficient legal basis, those data will be deleted in accordance with the applicable statutory requirements.
30. External Links
The website may contain links to websites or documents provided by external parties.
Only when such an external link is accessed may data, in particular the IP address and browser and device information, be transmitted to the relevant external provider.
The respective operator is generally responsible for the processing of personal data on external websites.
Dinc Consulting has no influence over such data processing. The privacy information of the relevant external provider applies.
31. Amendments to This Privacy Policy
Dinc Consulting reserves the right to amend this Privacy Policy where:
-
the website or its functions are changed;
-
new service providers are engaged;
-
the processing of personal data changes;
-
statutory or regulatory requirements change;
-
an amendment is required due to technical or organisational developments.
The current version published on the website applies.
Last updated: 11 August 2026
