This policy explains how personal data is processed when you visit this website and when you contact us. It applies to the domains revisd.com and revisd.de.
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Revisd GmbH
Matthias Fichtl
Nördliche Münchner Straße 47
82031 Grünwald bei München
Germany
Telephone: +49 (0)89 60 80 78 08
E-mail: datenschutz@revisd.com
No data protection officer has been appointed. The requirements of Art. 37 GDPR in conjunction with Section 38 of the German Federal Data Protection Act (BDSG) are not met: Revisd GmbH does not permanently employ at least twenty persons in the automated processing of personal data, carries out no processing that would require a data protection impact assessment, and does not process data commercially for the purpose of transfer or for market or opinion research.
Please address data protection enquiries to the contact given in section 1.
As a non-public body established in Bavaria, Revisd GmbH falls under the competence of:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
Postal address: Postfach 1349, 91504 Ansbach, Germany
Telephone: +49 (0)981 180093-0
Website: www.lda.bayern.de
Scope of processing. Each time this website is accessed, the following data transmitted by your browser is collected automatically:
Purpose and legal basis. This processing serves to establish the connection, to ensure the stability and security of the system and to analyse faults. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in the technically sound and secure operation of the website. This data is not combined with other data sources and is not evaluated in order to identify individuals.
Retention period. Log files are deleted after seven days.
Objection. The collection of this data is technically indispensable for the operation of the website; accordingly, no right to object applies in this respect.
This website is hosted by STRATO GmbH, Pascalstraße 10, 10587 Berlin, Germany. The provider operates its own data centres in Berlin and Karlsruhe; all processing takes place exclusively in Germany. The data centres are certified to ISO/IEC 27001. STRATO GmbH processes the data referred to in section 5 solely on our behalf and on our instructions. A data processing agreement pursuant to Art. 28 GDPR is in place.
Scope of processing. This website uses strictly necessary cookies only. Cookies are small text files stored on your device that allow your browser to be recognised during your visit. The following are used:
Purpose and legal basis. Both cookies are necessary for the operation of the website. The legal basis is Section 25 (2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG) in conjunction with Art. 6 (1) (f) GDPR. No consent is required for these.
Retention period. The session cookie is deleted when the session ends; the cookie-notice cookie expires at the end of its validity period.
Not used. No cookies are used for analytics, tracking or advertising purposes. No profiles are created.
Control. You can restrict or prevent the setting of cookies in your browser and delete cookies already stored. In that case, not all functions of the website may be fully available.
Scope of processing. Contact forms are available on this website. Depending on the form, the following data is processed:
You may alternatively contact us by e-mail or by telephone. In that case we process the information you provide.
Purpose and legal basis. This processing serves solely to handle your enquiry. The legal basis is Art. 6 (1) (b) GDPR where the enquiry relates to the conclusion or performance of a contract, and otherwise Art. 6 (1) (f) GDPR. Our legitimate interest lies in responding to enquiries.
Recipients. Data is not disclosed to third parties for their own purposes. For the operation of the website and of our e-mail communication we engage the processors listed in section 9.
Retention period. Data is deleted once your enquiry has been dealt with conclusively and no statutory retention obligations apply. Correspondence relevant under commercial or tax law is retained for the statutory retention periods.
Personal data is transferred only to the entities listed below. Data processing agreements pursuant to Art. 28 GDPR are in place with all processors.
Any change to the group of processors will be reflected in this policy.
In the course of our freight invoice audit services, Revisd GmbH processes data on behalf of its clients. In this respect the respective client is the controller within the meaning of the GDPR; Revisd GmbH acts as processor pursuant to Art. 28 GDPR and processes data solely on documented instructions.
Where a data subject contacts us directly, we forward the request to the responsible client without undue delay. We are not permitted to respond to such requests ourselves.
This policy does not extend to that processing. Information about it is provided by the respective controller.
We implement technical and organisational measures pursuant to Art. 32 GDPR in order to ensure a level of security appropriate to the risk. These include encrypted transmission in line with the state of the art, full-disk encryption of all end devices, two-factor authentication, an authorisation concept with strict access restriction, regular backups with restore testing, and the logging of security-relevant events. The effectiveness of these measures is reviewed annually.
Subject to the statutory requirements, you have the following rights:
An informal message to datenschutz@revisd.com is sufficient. We will deal with your request without undue delay and at the latest within one month of receipt. In the case of complex requests this period may be extended by a further two months; we will inform you accordingly.
Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, place of work or of the alleged infringement. The authority competent for us is named in section 3.
We update this policy where the processing or the legal framework changes. The version published on this page applies.
Last updated: September 2026
This is a translation of the German original. In the event of any discrepancy, the German version prevails.