GDPR Statement
Our commitments under the EU General Data Protection Regulation: the roles we hold, the rights you can exercise and how we handle the data you entrust to us.
Section 1Our commitment
REGREP is built with GDPR in mind: data minimisation, defined purposes, honest scoping of our claims, and clear routes for you to exercise your rights. This statement summarises how the GDPR applies to REGREP; it works alongside our privacy policy, which sets out the detail.
Section 2Controller and processor
We act as a controller for personal data relating to our website, accounts, enquiries and marketing. We act as a processor for the data you upload to prepare and validate your regulatory filings, which we process on your instructions under a data processing agreement. That agreement, including its scope and transfer mechanism, is available through our security page.
Section 3Legal bases
We process personal data on the bases set out in our privacy policy: performance of a contract, compliance with legal obligations, our legitimate interests, and consent for analytics, advertising measurement and marketing. Where we rely on consent, you may withdraw it at any time; where we rely on legitimate interests, you may object.
Section 4Your rights
As a data subject you have the right to:
- be informed about how your data is used;
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased, where the conditions are met;
- restrict processing in certain circumstances;
- receive your data in a portable format;
- object to processing based on legitimate interests or to direct marketing; and
- withdraw consent at any time, without affecting processing already carried out.
Section 5Exercising your rights
To exercise any right, email [email protected] or use our contact page. We may need to verify your identity, and we will respond within the statutory time limit, normally one month. If your request concerns data we process on behalf of a customer, we will refer you to that customer as the controller and support them in responding.
Section 6Customer filing data
Regulatory filing data you place on the platform is held in the EU. We process it only to provide the service you have asked for — conversion, validation and delivery of outputs — and under the terms of our data processing agreement. Supporting services such as analytics, payments, consent management, email and status monitoring may process limited operational data elsewhere; each is named in our subprocessor list.
Section 7Tax identification numbers
Tax identification numbers are personal data and are treated with particular care. When a TIN is checked or validated, it is processed in memory only, never logged, never stored and never passed in an analytics parameter. We don’t store what you check.
Section 8Transfers and subprocessors
Where personal data is transferred outside the EEA, we rely on an approved transfer mechanism such as the standard contractual clauses, with additional safeguards where needed. Our providers and the purposes they serve are listed in our privacy policy and maintained subprocessor list.
Section 9Complaints
If you believe we have not handled your personal data properly, please contact us first so we can put it right. You also have the right to lodge a complaint with a data protection supervisory authority — in particular in the EU member state of your residence or workplace, or the authority competent for our establishment in Germany.
Section 10Breach contact
To report a suspected personal-data breach, contact [email protected]. We assess reported incidents promptly and notify authorities and affected individuals where the GDPR requires it.
REGREP is an independent software provider. Nothing on this page is legal, tax or regulatory advice. Questions about this notice can be sent to [email protected] or via our contact page. See also our legal information, privacy policy, terms of service and GDPR statement.