Crisam Logo
  • Solutions
    Solutions
    • Risk & Resilience
    • Compliance, Controls & Security
    • Audit, Assurance & Reporting
    • Integrated Risk Management
    • Enterprise Risk Management
    • Operational Risk Management
    • Business Continuity Managament
    • Project Risk Management
    • Third Party Risk
    • Compliance Management
    • Policy Management
    • Internal Control System
    • Information Security Management
    • Data Protection Management
    • Standards & Frameworks
    • Cyber & ICT Risk
    • Audit Managament
    • Internal Audit
    • Control Testing
    • Evidence Management
    • Board & Executive Reporting
    • Whistleblowing & Case Management
    • ESG Governance
  • Industries
    Industries
    • Financial Services
    • Energy & Utilities
    • Healthcare & Pharmaceuticals
    • Industrial & Manufacturing
    • Public Sector & Infrastructure
    • Technology & Telecommunications
  • Platform
    Platform
    • Platform Capabilities
    • Oversight & Governance
    • Configurable workflows
    • Centralised GRC data model
    • Risk & control libraries
    • Evidence management
    • Action tracking
    • Automated reports
    • Board reporting
    • Roles & permissions
    • Audit trails
    • Multi-entity structures
  • Process
  • Customers
  • About CRISAM®
  • en-gb
    • de
    • en
Request demo
  • Sprache
    • de
    • en
  • Solutions
    • Risk & Resilience
      • Integrated Risk Management
      • Enterprise Risk Management
      • Operational Risk Management
      • Business Continuity Managament
      • Project Risk Management
      • Third Party Risk
    • Compliance, Controls & Security
      • Compliance Management
      • Policy Management
      • Internal Control System
      • Information Security Management
      • Data Protection Management
      • Standards & Frameworks
      • Cyber & ICT Risk
    • Audit, Assurance & Reporting
      • Audit Managament
      • Internal Audit
      • Control Testing
      • Evidence Management
      • Board & Executive Reporting
      • Whistleblowing & Case Management
      • ESG Governance
  • Industries
    • Financial Services
    • Energy & Utilities
    • Healthcare & Pharmaceuticals
    • Industrial & Manufacturing
    • Public Sector & Infrastructure
    • Technology & Telecommunications
  • Platform
    • Platform Capabilities
      • Configurable workflows
      • Centralised GRC data model
      • Risk & control libraries
      • Evidence management
      • Action tracking
    • Oversight & Governance
      • Automated reports
      • Board reporting
      • Roles & permissions
      • Audit trails
      • Multi-entity structures
  • Process
  • Customers
  • About CRISAM®
  • Request demo
Gemeinsame Nutzung CRISAM

Data Policy

How we process personal data under the UK GDPR and the Data Protection Act 2018, and the rights you have as a data subject.

Dear visitor of our website, customer, prospect, supplier, external service provider, training participant, event participant and applicant of CRISAM GRC Limited and the CALPANA group

The protection of your personal data is of particular concern to us.

You can use our website without providing any personal data.

We process personal data in accordance with the United Kingdom General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and — where applicable — the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the national data protection laws of Austria (Datenschutzgesetz – DSG) and Germany (Bundesdatenschutzgesetz – BDSG). Data are personal where they can be clearly attributed to a specific natural person.

The general rules about the website as well as the rules in the various data subject categories inform you about the type, scope and purpose of the collection, use and processing of personal data by:

CRISAM GRC Limited

20 Red Lion Street, London, WC1R 4PQ, United Kingdom

T: +44 20 4634 5000

E: andreas.schmitz@crisam.net

W: crisam.net/en-gb

Companies House Number: 16444161 · VAT: 507 5416 01

CALPANA business consulting GmbH

Blumauerstrasse 45-47, 4020 Linz, Austria

T: +43 (0) 732 601 216-0

E: office@crisam.net

W: www.calpana.com

CALPANA business consulting Deutschland GmbH

Paul-Dessau-Straße 1, 22761 Hamburg, Germany

T: +49 (40) 359 829-21

E: office@crisam.net

Your data protection enquiry

For all data protection enquiries please contact the Data Protection Coordinator of the CALPANA / CRISAM group at privacy@calpana.com. Enquiries concerning UK-specific processing can additionally be addressed to andreas.schmitz@crisam.net.

Our website

Hereby we inform you about the most important aspects of data processing within the scope of our website.

Google Analytics

Our website uses Google Analytics, a web analytics service of Google Inc. Google provides a browser plug-in for the deactivation of Google Analytics. Google Analytics uses cookies. These are small text files which make it possible to store user-specific information on the user’s device. They enable Google to analyse the use of our website offering. The information generated by the cookie about your use of our pages (including your IP address) is generally anonymised, transmitted to and stored on a Google server in the USA. Due to the anonymisation carried out, no conclusions can be drawn about your identity. Google uses the collected information to evaluate the use of our websites, to compile reports about it for us and to provide other services related to this. For more information, please see Google’s privacy policy.

Click here to manage your cookie settings.

Cookies

Our website uses Google Analytics, a web analytics service of Google Inc. Google Analytics uses cookies. These are small text files which make it possible to store user-specific information on the user’s device. They enable Google to analyse the use of our website offering. The information generated by the cookie about your use of our pages (including your IP address) is generally anonymised, transmitted to and stored on a Google server in the USA. Due to the anonymisation carried out, no conclusions can be drawn about your identity. Google uses the collected information to evaluate the use of our websites, to compile reports about it for us and to provide other services related to this.

Click here to manage your cookie settings.

Server data

For technical reasons, the following data, which your internet browser transmits to us or to our webspace provider, is recorded (so-called server log files):

  • Browser type and version
  • Operating system used
  • Website from which you are visiting us (referrer URL)
  • Website you are visiting
  • Date and time of your access
  • Your Internet Protocol (IP) address

This anonymous data is stored separately from any personal data you may have provided and does not allow any conclusions to be drawn about a specific person.

Contact options

We offer you the possibility to contact us by e-mail and/or via a contact form. In this case, the information provided by the user is stored for the purpose of processing the contact request. No disclosure to third parties takes place. A comparison of the data collected in this way with data that may be collected by other components of our website is also not carried out. For more detailed information on the contact possibility via the website, see the Website visitors section below.

You as a data subject

We process personal data of the following categories of data subjects:

Categories of data subjects

  • Prospects
  • Customers
  • Suppliers
  • Training participants
  • Event participants
  • Applicants
  • Website visitors
  • External service providers
  • Third parties
  • Newsletter recipients

The processing activities in which you are involved are carried out separately by CRISAM GRC Limited (United Kingdom), CALPANA business consulting GmbH (Austria) and CALPANA business consulting Deutschland GmbH (Germany). Where processing activities are performed as joint controllers, this is noted accordingly. For UK data subjects, CRISAM GRC Limited is the primary controller; data may be shared with the CALPANA group companies where required for cross-border service delivery.

Prospects

Prospects are all those persons who are interested in our product and our other services and / or wish to be regularly informed about news.

Personal data of prospects are processed within the scope of the following processing activities for the purposes stated below:

Processing activityPurpose of processing
Provision of informationProviding information about news, products and services
Personal contactProviding information about news, products and services in the course of a personal conversation
Processing activityLegal basis / legitimate interest
Provision of informationConsent (UK GDPR Art. 6(1)(a))
Personal contactConsent (UK GDPR Art. 6(1)(a))

Within the processing activities “Provision of information” and “Personal contact”, joint processing by CRISAM GRC Limited, CALPANA Austria and CALPANA Germany may occur. The subject of this processing is the management of contact data in order to provide cross-border services.

Processing activityData categoryData types included
Provision of information, Personal contactContact maintenance dataAmong others: name, telephone number, e-mail, address, role in the company and additional notes (prospect’s interest in product, service or events).

Within the processing activities carried out by us, we do not transmit personal data of the data subject categories concerning you to any recipients or categories of recipients.

We store your personal data for as long as required by law, necessary for the purpose, or required by the legitimate interest of the company.

Data categoryStorage periodDeletion period
Contact maintenance dataUntil revocation.Immediately after revocation.
Data categoryOrigin
Contact maintenance dataFrom the data subject themselves.

No automated decision-making, including profiling, takes place in any of the above-mentioned processing activities.

Customers

Customers are all those persons who request and acquire our products and services. Personal data of customers are processed within the scope of the following processing activities for the purposes stated below:

Processing activityPurpose of processing
Order processingProcessing of orders and service billing.
Provision of informationProvision of information about products and services.
Processing activityLegal basis / legitimate interest
Order processingContract with the customer (UK GDPR Art. 6(1)(b)).
Provision of informationLegitimate interest — contact maintenance (UK GDPR Art. 6(1)(f)).

Within the processing activity “Order processing”, joint processing by CRISAM GRC Limited, CALPANA Austria and CALPANA Germany may occur. The subject of this processing is the management of contact data for the provision of services arising from joint contracts or agreements. Only contact data (name, e-mail, address and telephone number) are processed in this context.

Processing activityData categoryData types included
Order processing, Provision of informationCustomer master dataAmong others: name, address, company registration number, VAT ID, e-mail and telephone number.
Order processingCustomer attributesAmong others: revenue, payment behaviour, contact persons and offers.
Order processingProject dataAmong others: backups of project files.

Within the processing activities carried out by us, we do not transmit personal data of the data subject categories concerning you to any recipients or categories of recipients.

We store your personal data for as long as required by law, necessary for the purpose, or required by the legitimate interest of the company.

Data categoryStorage periodDeletion period
Customer master dataUnited Kingdom: As long as the business relationship exists and all claims have been settled. Thereafter, processing is restricted and the data are stored for 6 years in accordance with HMRC requirements and the Companies Act 2006 / Limitation Act 1980.
Austria: 7 years after approved annual financial statement (under BAO).
Germany: 10 years after approved annual financial statement (under § 147 AO, § 14b UStG).
Within a deletion cycle of one year after the storage period.
Customer attributesSame retention periods as customer master data.Within a deletion cycle of one year after the storage period.
Project dataSame retention periods as customer master data.Immediately after the storage period.
Data categoryOrigin
Customer master dataFrom customer contact or prospect contact.
Customer attributesFrom customer contact or prospect contact.
Project dataFrom the customer themselves.

No automated decision-making, including profiling, takes place in any of the above-mentioned processing activities.

Suppliers

Suppliers are all those persons who provide our company with goods or services through delivery. Personal data of suppliers are processed within the scope of the following processing activities for the purposes stated below:

Processing activityPurpose of processing
Service provisionIn the course of the provision of services by suppliers, data of the contact persons are processed.
Processing activityLegal basis / legitimate interest
Service provisionContract with the supplier (UK GDPR Art. 6(1)(b)).

Within the processing activity “Service provision”, joint processing by CRISAM GRC Limited, CALPANA Austria and CALPANA Germany may occur. The subject of this processing is the management of contacts for the acquisition and use of standardised services. Only contact data (name, e-mail, address and telephone number) are processed in this context.

Processing activityData categoryData types included
Service provisionSupplier contact dataAmong others: name, telephone number, e-mail and address.

Within the processing activities carried out by us, we transmit personal data of the data subject categories concerning you to the following recipients or categories of recipients:

Data typeRecipientThird country [Y/N]Purpose of transfer
Bank details, nameBankNExecution of billing.

We store your personal data for as long as required by law, necessary for the purpose, or required by the legitimate interest of the company.

Data categoryStorage periodDeletion period
Supplier contact dataUnited Kingdom: As long as the business relationship exists and all liabilities have been settled. Thereafter, processing is restricted and the data are stored for 6 years (HMRC, Companies Act 2006) for the retention of invoice data.
Austria: 7 years after approved annual financial statement (under BAO).
Germany: 10 years after approved annual financial statement (under § 147 AO, § 14b UStG).
Within a deletion cycle of one year after the storage period.
Data categoryOrigin
Supplier contact dataFrom the supplier themselves.

No automated decision-making, including profiling, takes place in any of the above-mentioned processing activities.

Training participants

Training participants are all those persons who participate in trainings of our company and receive further training in the use of the software or other subject areas. Customers may also be considered as training participants.

Personal data of training participants are processed within the scope of the following processing activities for the purposes stated below:

Processing activityPurpose of processing
Conducting trainingsConducting training sessions for further education.
Processing activityLegal basis / legitimate interest
Conducting external trainingsContract — service (UK GDPR Art. 6(1)(b)).

Within the processing activities carried out by us, we do not transmit personal data of the data subject categories concerning you to any recipients or categories of recipients.

Data categoryStorage periodDeletion period
Training participant dataUntil deletion of the account.
Accounting-relevant data:
United Kingdom: Once all claims have been settled, processing is restricted and the data are stored for 6 years (HMRC requirements).
Austria: 7 years after approved annual financial statement (BAO).
Germany: 10 years after approved annual financial statement (§ 147 AO, § 14b UStG).
At the end of the month, provided that an application for deletion of the account has been submitted and no further retention obligations apply. Accounting-relevant data are deleted in a one-year deletion cycle after the storage period has expired.
Data categoryOrigin
Training participant dataFrom the data subject themselves.

No automated decision-making, including profiling, takes place in any of the above-mentioned processing activities.

Event participants

Event participants are all those persons who participate in our events. This includes event visitors (customers, prospects) and speakers.

Personal data of event participants are processed within the scope of the following processing activities for the purposes stated below:

Processing activityPurpose of processing
Event managementPlanning, organisation and execution of events.
Event documentationDocumentation of events within the scope of our online presence.
Processing activityLegal basis / legitimate interest
Event managementConsent (UK GDPR Art. 6(1)(a)).
Event documentationConsent (UK GDPR Art. 6(1)(a)), legitimate interest — image cultivation (UK GDPR Art. 6(1)(f)).

Within the processing activity “Event management”, joint processing by CRISAM GRC Limited, CALPANA Austria and CALPANA Germany may occur. The subject of this processing is the management of contacts in order to provide cross-border services accordingly.

Processing activityData categoryData types included
Event managementData for eventsPersonal master data (e.g. first name, last name, gender/salutation), communication data (e.g. billing address, company, e-mail), booking history, planning and control data (e.g. processing status), contract billing and payment data.
Event documentationImage dataPhotos and videos of event participants.

Within the processing activities carried out by us, we transmit personal data of the data subject categories concerning you to the following recipients or categories of recipients:

Data typeRecipientThird country [Y/N]Purpose of transfer
Photos, videosVimeoYVideos of events etc. available on the CALPANA and CRISAM website.
Data categoryStorage periodDeletion period
Data for eventsUntil deletion of the account.
Accounting-relevant data:
United Kingdom: Once all claims have been settled, processing is restricted and the data are stored for 6 years (HMRC requirements).
Austria: 7 years after approved annual financial statement (BAO).
Germany: 10 years after approved annual financial statement (§ 147 AO, § 14b UStG).
At the end of the month, provided that an application for deletion of the account has been submitted and no further retention obligations apply. Accounting-relevant data are deleted in a one-year deletion cycle after the storage period has expired.
Image dataUntil revocation.Immediately after revocation.
Data categoryOrigin
Data for eventsFrom the data subject themselves.
Image dataFrom the data subject themselves or via photographer and camera.

No automated decision-making, including profiling, takes place in any of the above-mentioned processing activities.

Applicants

Applicants are all those persons who apply for an open position or through an unsolicited application to the company.

Personal data of applicants are processed within the scope of the following processing activities for the purposes stated below:

Processing activityPurpose of processing
Applicant managementSelection of a person suitable for the vacant position.
Processing activityLegal basis / legitimate interest
Applicant managementContract (pre-contractual relationship, UK GDPR Art. 6(1)(b)).
Processing activityData categoryData types included
Applicant managementApplicant dataAmong others: master data (name, address, telephone number, date of birth, gender, religious affiliation if applicable, marital status), professional certificates, application photo, references, application letter (containing personal data and content disclosed by the applicant). Among other things, Article 9 data (health data, religious affiliation) or Article 10 data (criminal convictions) may be included.

Within the processing activities carried out by us, we do not transmit personal data of the data subject categories concerning you to any recipients or categories of recipients.

Data categoryStorage periodDeletion period
Applicant dataUnited Kingdom: 6 months after the position has been filled or rejected, plus a buffer period of one month (in line with Equality Act 2010 limitation periods).
Austria: 6 months after the position has been filled or rejected (under GlBG), plus a buffer of one month.
Germany: 2 months after rejection.
Immediately after the storage period.
Data categoryOrigin
Applicant dataFrom the applicant or recruitment service provider.

No automated decision-making, including profiling, takes place in any of the above-mentioned processing activities.

Website visitors

Website visitors are all those persons who access our website within a certain measured time and thus “visit” it.

Personal data of website visitors are processed within the scope of the following processing activities for the purposes stated below:

Processing activityPurpose of processing
Processing of contact enquiriesProcessing of enquiries via the website form to provide the enquirer with appropriate support.
Processing activityLegal basis / legitimate interest
Processing of contact enquiriesLegitimate interest — business handling (UK GDPR Art. 6(1)(f)).
Processing activityData categoryData types included
Processing of contact enquiriesContact formSubject and detailed description of the request, name, telephone number and e-mail.

Within the processing activities carried out by us, we do not transmit personal data of the data subject categories concerning you to any recipients or categories of recipients.

Data categoryStorage periodDeletion period
Contact formThe data are stored until the conclusion of the support case or up to one year beyond that, to ensure appropriate traceability.Immediately after the storage period.
Data categoryOrigin
Contact formFrom the data subject themselves.

No automated decision-making, including profiling, takes place in any of the above-mentioned processing activities.

External service providers

External service providers are all those persons who provide services to the company and bill them accordingly.

Personal data of external service providers are processed within the scope of the following processing activities for the purposes stated below:

Processing activityPurpose of processing
Service provisionVerification of the fulfilment of the service of the external service provider.
Service billingBilling of the service of external service providers.
Processing activityLegal basis / legitimate interest
Service provisionContract with the external service provider (UK GDPR Art. 6(1)(b)).
Service billingContract with the external service provider (UK GDPR Art. 6(1)(b)).
United Kingdom: Legal basis (HMRC requirements, Companies Act 2006).
Austria: Legal basis (§132 BAO).
Germany: Legal basis (§ 147 AO, § 257 HGB).
Processing activityData categoryData types included
Service provision, Service billingExternal service provider dataAmong others: company name, name, telephone number, bank details, service and fee.

Within the processing activities carried out by us, we transmit personal data of the data subject categories concerning you to the following recipients or categories of recipients:

Data typeRecipientThird country [Y/N]Purpose of transfer
Bank details, name, feeBankNExecution of billing.
Data categoryStorage periodDeletion period
External service provider dataUnited Kingdom: As long as the business relationship exists and all liabilities have been settled. Thereafter, processing is restricted and the data are stored for 6 years (HMRC, Companies Act 2006) for the retention of invoice data.
Austria: 7 years after approved annual financial statement (BAO).
Germany: 10 years after approved annual financial statement (§ 147 AO, § 14b UStG).
Immediately after the storage period.
Data categoryOrigin
External service provider dataFrom the external service provider themselves.

No automated decision-making, including profiling, takes place in any of the above-mentioned processing activities.

Third parties

Third parties are all those persons who do not belong to any of the other categories of data subjects.

Personal data of third parties are processed within the scope of the following processing activities for the purposes stated below:

Processing activityPurpose of processing
Accidental contactHandling of accidental contacts via e-mail.
Processing activityLegal basis / legitimate interest
Accidental contactLegitimate interest — handling of enquiries (UK GDPR Art. 6(1)(f)).
Processing activityData categoryData types included
Accidental contactThird party contact dataAmong others: name, telephone number and e-mail.

Within the processing activities carried out by us, we do not transmit personal data of the data subject categories concerning you to any recipients or categories of recipients.

Data categoryStorage periodDeletion period
Third party contact dataAccidental e-mails are received and stored only as long as they have been processed.Immediately after the storage period.
Data categoryOrigin
Third party contact dataFrom the data subject themselves.

No automated decision-making, including profiling, takes place in any of the above-mentioned processing activities.

Newsletter recipients

Newsletter recipients are all those persons who register to receive the newsletter.

Personal data of newsletter recipients are processed within the scope of the following processing activities for the purposes stated below:

Processing activityPurpose of processing
NewsletterSending information about the product, events, general information about CRISAM, CALPANA and risk management.
Processing activityLegal basis / legitimate interest
NewsletterConsent (UK GDPR Art. 6(1)(a) and Privacy and Electronic Communications Regulations (PECR)).
Processing activityData categoryData types included
NewsletterNewsletter formSalutation, name and e-mail address.

Within the processing activities carried out by us, we do not transmit personal data of the data subject categories concerning you to any recipients or categories of recipients.

Data categoryStorage periodDeletion period
Newsletter formUntil revocation.1 year after revocation for traceability.
Data categoryOrigin
Newsletter formFrom the data subject themselves.

No automated decision-making, including profiling, takes place in any of the above-mentioned processing activities.

Your rights as a data subject

Under the UK GDPR and the Data Protection Act 2018, you have the following rights regarding your personal data, which you can exercise free of charge by contacting us at privacy@calpana.com (Data Protection Coordinator) or andreas.schmitz@crisam.net (UK contact):

  • Right of access (Art. 15 UK GDPR): You have the right to obtain confirmation of whether we process personal data concerning you, and if so, to receive information about this processing.
  • Right to rectification (Art. 16 UK GDPR): You have the right to have inaccurate personal data corrected and to have incomplete personal data completed.
  • Right to erasure (Art. 17 UK GDPR): You have the right to have personal data erased, unless a statutory retention obligation prevents this.
  • Right to restriction of processing (Art. 18 UK GDPR): You have the right to obtain the restriction of processing under certain conditions.
  • Right to data portability (Art. 20 UK GDPR): You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format.
  • Right to object (Art. 21 UK GDPR): You have the right to object to the processing of personal data concerning you that is based on a legitimate interest.
  • Right to withdraw consent: Where processing is based on consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
  • Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with the Information Commissioner’s Office (ICO) in the United Kingdom, or — for processing activities conducted by CALPANA Austria or CALPANA Germany — with the Austrian Data Protection Authority (Datenschutzbehörde) or the relevant German supervisory authority.

Last updated: 27 May 2026

Gemeinsame Nutzung CRISAM

CRISAM GRC Limited

20 Red Lion Street

London

+44 20 4634 5000 andreas.schmitz@crisam.net

CALPANA business consulting GmbH

Blumauerstrasse 45-47

4020 Linz

+43 732 601 216-0 office@crisam.net

CRISAM GRC Limited

20 Red Lion Street

London

+44 20 4634 5000 andreas.schmitz@crisam.net

CALPANA business consulting GmbH

Blumauerstrasse 45-47

4020 Linz

+43 732 601 216-0 office@crisam.net
Solutions
  • Risk & Resilience
  • Compliance & Controls
  • Audit, Assurance & Reporting
Industries
  • Financial Services
  • Energy & Utilities
  • Healthcare & Pharmaceuticals
  • Industrial & Manufacturing
  • Industrial & Manufacturing
  • Technology & Telecommunications
Company
  • About CRISAM®
Legal
  • Data Policy
  • Imprint

© 2026 CRISAM GRC Limited