Privacy Statement
The protection of information relating to you, such as your name, telephone number, and email or IP address (so-called "personal data") is very important to us. That is why we operate this website and the services we offer on it in accordance with the applicable data protection laws, in particular the EU General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG).
Below you will find an explanation of how we handle your personal data in this context.
A. General
B. Data protection information on the processing of data when using our website
C. Data protection information on the processing of client data
D. Data protection information on the processing of applicant data
A. General
I. Name and address of the data controller
The data controller is the body that alone—or jointly with others—decides on the purposes and means of processing personal data. The data controller within the meaning of the General Data Protection Regulation and other national data protection laws of the member states as well as other data protection regulations is:
Gütt Olk Feldhaus
Partnerschaft von Rechtsanwälten mbB
Hackenstraße 5
80331 Munich
Phone: 089 24 22 411 - 0
Email: info@gof-partner.com
Authorized representatives: Dr. Heiner Feldhaus, Dr. Tilmann Gütt, LL.M. (London), Dr. Kilian Helmreich, Dr. Sebastian Olk, Adrian von Prittwitz und Gaffron, LL.M. (LSE)
II. Contact details of the data protection officer
We have appointed an external data protection officer:
BerIsDa GmbH | Website: www.berisda.de
You can contact the data protection officer by mail via the data controller, to the attention of the data protection officer, or by email at datenschutz@berisda.de.
III. Your rights as a data subject
When we process your personal data, you as the data subject have the following rights vis-à-vis us as the data controller:
1. Right of access, Art. 15 GDPR
Within the framework of the applicable legal provisions, you have the right to obtain information (free of charge) about your collected and stored personal data at any time. This includes, among other things, information about the purposes of processing, the origin and recipients of the data, the storage period, and the existence of various rights.
2. Right to rectification, Art. 16 GDPR
You have the right to request the data controller to rectify (including to complete) your data if the personal data processed concerning you is inaccurate or incomplete for the purpose of processing. The data controller must rectify the data without delay.
3. Right to erasure, Art. 17 GDPR
Under the conditions of Art. 17 GDPR, you may request the erasure of your personal data at any time, unless there are circumstances that entitle or oblige the data controller to continue processing your personal data (such as legal retention obligations).
4. Right to restriction of processing, Art. 18 GDPR
If the legal requirements are met, you may request restriction of the processing of your personal data within the scope of Art. 18 GDPR.
5. Right to notification, Art. 19 GDPR
If your personal data has been processed by recipients to whom the data data controller has disclosed the data, the data controller is obliged to inform them of your requests for rectification, erasure, or restriction of processing, unless this proves impossible or involves disproportionate effort. You may request that the data controller inform you of these recipients.
6. Right to data portability, Art. 20 GDPR
If you have provided us with personal data and automated processing is carried out on the basis of your consent or on the basis of a contract, you have the right to transfer the data you have provided within the scope of Art. 20 GDPR, provided that this does not affect the rights and freedoms of other persons. The data will be provided in a commonly used, machine-readable format. If you request the direct transfer of the data to another data controller, this will only be done to the extent that it is technically feasible.
7. Right to object, Article 21 GDPR
You have the right to object to the processing of your data at any time, provided that the processing is based on a balancing of interests. This is the case if the data controller invokes the public interest or its legitimate interest as the basis for processing (see Art. 6 (1) (e) and (f)). The prerequisite is that you assert reasons arising from your particular situation which outweigh the interests of the data controller. The data controller will no longer process the personal data concerning you unless it can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves to assert, exercise, or defend legal claims.
If the personal data concerning you is used for direct marketing, you have the right to object to the processing of the personal data concerning you at any time without further requirements.
In connection with the use of information society services, you have the option of exercising your right to object by means of automated procedures using technical specifications.
8. Automated decision-making in individual cases, Art. 22 GDPR
In accordance with Art. 22 GDPR, you have the right that decisions that have legal effects on you or similarly affect you are not based solely on automated processing, including profiling. Exceptions may exist if appropriate measures for the protection of your person are guaranteed and there are necessary contractual provisions or a legal provision, or you have expressly consented.
9. Right to withdraw your consent, Art. 7(3) GDPR
You have the right to withdraw your consent at any time. The legality of the data processing carried out until the withdrawal remains unaffected by the withdrawal. You can send the withdrawal by email or post to the data controller.
10. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority for data protection, in particular in the Member State of your residence, your place of work, or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR. The supervisory authority responsible for us is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht), PO Box 1349, 91504 Ansbach, Germany. If you are located in another federal state or outside Germany, you can also contact the data protection authority there.
Please also use the above contact details of the data controller to exercise your rights.
B. Data protection information on the processing of data when using our website
I. Scope of processing of personal data
The data controller collects and uses personal data of its users (hereinafter also referred to as "data subject," or "visitor") only to the extent necessary to provide a functional website and to present its content and services. The collection and processing of users' personal data for other purposes is generally only carried out with the user's consent. An exception applies in cases where prior consent cannot be obtained for practical reasons, where processing is based on pre-contractual or contractual measures, where processing of the data is permitted by law, and/or where the data controller has a legitimate interest in processing the data.
Your personal data is generally collected directly from you, for example when you contact us, consent to services on this site, or use forms on this website. In addition, technical data that is essential for the operation of the site is automatically collected when you enter the site.
1. Legal basis for the processing of personal data
Insofar as the data controller for processing operations involving personal data obtains the consent of the data subject, Art. 6 (1) (a) of the EU General Data Protection Regulation (GDPR) serves as the legal basis for the processing of personal data. If special categories of data are processed in accordance with Article 9(1) GDPR, Article 9(2)(a) GDPR serves as the legal basis. For any transfer to a non-secure third country by means of consent, processing is carried out on the basis of Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or access to information on your terminal device, data processing is also carried out on the basis of Section 25(1) TDDDG.
When processing personal data that is necessary for the performance of a contract to which the data subject is a party, Art. 6 (1) (b) GDPR serves as the legal basis. This also applies to processing operations that are necessary for the implementation of pre-contractual measures. If the person is the contact person of a (potential) business partner (client, supplier, partner), the legal basis for (pre-)contractual measures is Art. 6 (1) (f) GDPR.
Insofar as the processing of personal data is necessary to fulfil a legal obligation to which the data controller is subject, Art. 6 (1) (c) GDPR serves as the legal basis.
In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6 (1) (d) GDPR serves as the legal basis.
If processing is necessary to safeguard a legitimate interest of the data controller or a third party and the interests, fundamental rights, and freedoms of the data subject do not override the former interest, Art. 6 (1) (f) GDPR serves as the legal basis for processing.
2. Data deletion and duration of processing
If no specific storage period is specified in this privacy policy, the personal data of our website visitors will remain with us until the purpose for data processing no longer applies. The personal data of the data subject will be deleted or blocked as soon as the purpose of storage ceases to apply or consent given by the data subject is revoked or processing is objected to. Storage may also take place if this has been provided for by the European or national legislator in EU regulations, laws, or other provisions to which the data controller is subject. The data will also be blocked or deleted when a storage period prescribed by the aforementioned standards expires, unless there is a need for further storage of the data for the conclusion or fulfilment of a contract.
3. Data transfer to a third country or an international organization
The European General Data Protection Regulation (GDPR) requires that the transfer of personal data that is already being processed or is to be processed after its transfer to a third country or an international organization is only permissible if a level of data protection comparable to that provided by the GDPR is ensured. If it is therefore ensured that the provisions of the GDPR are complied with – this may include, for example, the existence of an adequacy decision by the EU Commission within the meaning of Art. 45 (1), (3) GDPR or the introduction of internal company data protection regulations approved by a supervisory authority (so-called "appropriate safeguards", Art. 46 (2), (3) GDPR). If there is no level of data protection comparable to the requirements of the GDPR, there may be risks associated with processing in a third country .
Risks of transfer to an unsafe third country: Personal data could potentially be passed on by the provider to other third parties beyond the actual purpose of fulfilling the order, who could use the data for advertising purposes, for example. In addition, it is unlikely that any rights of data subjects can be effectively enforced against the provider. There is a higher probability that data may be processed incorrectly, as the technical and organizational measures taken by the provider to protect personal data do not fully meet the requirements of the GDPR in terms of quantity and quality. It is also possible that government agencies may access the personal data provided without the data subject's knowledge. In principle, this also complies with European legal regulations, e.g. for the purpose of averting danger. However, the threshold of admissibility for such data processing is higher in the European Union than in the country of the data recipient. In summary, non-secure third countries do not have a level of data protection comparable to that required by the GDPR.
On our website, we use tools from providers whose headquarters or the headquarters of their parent company (or their affiliated companies) are located in a third country from a data protection perspective. We also transfer data to the USA. Transferring data to the USA is permissible if the recipient is certified under the EU-US Data Privacy Framework (DPF) or has appropriate additional safeguards in place. The DPF is an (individual) agreement between the European Union and the USA, which is intended to ensure compliance with European data protection standards when processing data in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. The list of certified companies can be found at: https://www.dataprivacyframework.gov/list. There you can search for the provider name and view the certification directly.
4. Recipients of personal data
Within our organization, access to your personal data is generally granted to those departments and areas that need it in the course of our activities and for the purposes described, and that are authorized to process this data.
As part of our service provision, we commission processors who contribute to the fulfilment of contractual obligations. We work with service providers, such as IT maintenance service providers, video conferencing tools, or newsletter dispatchers (so-called processors). These service providers only act on our instructions and are contractually obliged to comply with the applicable data protection requirements. To this end, we conclude corresponding processing agreements with these service providers in writing.
We may transfer personal data to courts, supervisory authorities, or law firms if there is a legal obligation to do so under Art. 6 (1) (c) GDPR or if it is necessary under Art. 6 (1) (f) GDPR for the assertion, exercise, or defense of legal claims and there is no reason to assume that our data subjects have an overriding interest worthy of protection in not disclosing the data. exercise or defense of legal claims and there is no reason to assume that our data subjects have an overriding interest worthy of protection in the non-disclosure of the data.
5. Necessity of providing personal data
The provision of your personal data is generally neither required by law nor by contract. There is no obligation to provide data. However, failure to provide data may mean that you cannot use certain functions, services, forms, and other processing on our website. We recommend that you only provide such personal data that is necessary, for example, to process your request, to carry out your desired offer, and to use the functions we offer.
The collection of technical data (and, under certain circumstances, the collection of your IP address as personal data) for the provision of the website and the storage of data in log files is essential for the operation of the website and occurs automatically when you access this website. If you do not wish this to happen, you must leave this site.
II. SSL/TLS encryption
This website uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content, such as requests that you, as a data subject, send to us as the website operator. An encrypted connection can be recognized by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in the browser line. If SSL/TLS encryption is activated, the data you transmit to us cannot be read by third parties.
III. External hosting
1. Description and scope of data processing
This website is hosted by an external service provider (known as a host). The personal data collected on this website is stored on the host's servers. This may include IP addresses, contact requests, meta and communication data, contract data, contact details, names, page views, and other data generated via a website.
2. Legal basis for data processing
The legal basis for data processing is Art. 6 (1) (f) GDPR for the provision of the website.
3. Purpose of data processing
The host is used for the purpose of providing our online offering in a secure, fast, and efficient manner, as well as for the reliable display and provision of our website by a professional provider. These purposes constitute our legitimate interest.
4. Duration of storage, possibility of objection and removal
The data will be deleted as soon as it is no longer necessary for the purpose for which it was collected. In the case of data collection for the provision of the website, this is the case when the respective session has ended.
The collection of data for the provision of the website and the storage of data in log files is essential for the operation of the website. Consequently, there is no possibility for the user to object.
5. Conclusion of a contract for order processing
In connection with the data processing described above, the data is transferred and processed by our external host: jweiland.net, Echterdinger Straße 57, 70794 Filderstadt bei Stuttgart. We have concluded a contract for order processing with our host. This is a contract required by data protection law, which ensures that our host only processes the personal data of our website visitors in accordance with our instructions and in compliance with data protection regulations (GDPR, BDSG, etc.).
IV. Provision of the website and creation of log files
1. Description and scope of data processing
Every time our website is accessed, our system automatically collects data and information from the system of the accessing device.
The following data is collected:
(1) Information about the browser type and version used
(2) The user's operating system
(3) The user's Internet service provider
(4) The user's IP address
(5) Date and time of access
(6) Internet pages from which the user's system accesses our website
(7) Internet pages accessed by the user's system via our website
The data is also stored in our system's log files. This data is not stored together with other personal data relating to the user.
2. Legal basis for data processing
The legal basis for the temporary storage of data and log files is Art. 6 (1) (f) GDPR.
3. Purpose of data processing
The temporary storage of the IP address by the system is necessary to enable the website to be delivered to the user's computer. For this purpose, the user's IP address must remain stored for the duration of the session.
Storage in log files is done to ensure the functionality of the website. In addition, the data helps us to optimize the website and to ensure the security of our information technology systems. The data is not evaluated for marketing purposes in this context.
These purposes also constitute our legitimate interest in data processing in accordance with Art. 6 (1) (f) GDPR.
4. Duration of storage, possibility of objection and removal
The data is deleted as soon as it is no longer necessary for the purpose for which it was collected. In the case of data collection for the provision of the website, this is the case when the respective session has ended.
In the case of storage of the data in log files, this is the case after seven days at the latest. Storage beyond this is possible. In this case, the IP addresses of the users are deleted or modified such that an individualisation of the accessing terminal device is no longer possible.
The collection of data for the provision of the website and the storage of data in log files is essential for the operation of the website. Consequently, there is no possibility for the user to object.
V. Use of cookies
Our website does not use any technically necessary cookies. If you have consented to the collection of data in the "Statistics & Analysis" or "Functional Add-on" sections, cookies will be set. You can find a description of this in the Consent Management Tool, which you can access from any page (via the fingerprint icon) in the lower left corner of the website.
VI. Consent with Usercentrics
1. Description and scope of data processing
This website uses consent technology to obtain consent for the use of certain technologies and to document this in accordance with data protection regulations. This technology is provided by Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany.
When you visit our website, the following personal data [service] is transmitted:
- Consent(s) or revocation of your consent(s)
- IP address
- Information about the browser used
- Information about the device used
- Time of visit to the website
2. Legal basis for data processing
Usercentrics is used to obtain the legally required consent for the use of certain technologies. The legal basis for this is Art. 6 (1) (c) GDPR; the cookie is stored on your device on the basis of Section 25 (2) No. 2 TDDDG.
3. Purpose of data processing
The processing of personal data serves to comply with the legal requirements of the GDPR and the TDDDG for obtaining and documenting consent.
4. Duration of storage, possibility of objection, withdrawal, and deletion
As a user, you have the right to withdraw your consent at any time. Withdrawing your consent does not affect the legality of the processing carried out on the basis of your consent until withdrawal. You can withdraw the consent you have given at any time by clicking on the fingerprint icon on the left-hand side of the website.
5. Conclusion of a contract for order processing
In connection with the data processing described above, the data is transferred to and processed by our service provider. We have concluded a contract for order processing. This is a contract required by data protection law, which ensures that the personal data of our website visitors is only processed in accordance with our instructions and in compliance with data protection regulations (GDPR, BDSG, etc.).
VII. Contact by email and/or telephone
1. Description and scope of data processing
Our website and our signatures provide email addresses and telephone numbers that can be used to contact us electronically and/or by telephone. In this case, the personal data of the data subject transmitted with the email will be stored. If you contact us by telephone, personal data may also be stored in order to process your enquiry.
In this context, the data will not be passed on to third parties. The data will be used exclusively for establishing contact and conducting the conversation.
2. Legal basis for data processing
The legal basis for the processing of data transmitted in the course of sending an email or during a telephone call is Art. 6 (1) (f) GDPR. If the purpose of the contact is to conclude a contract, the additional legal basis for processing is Art. 6 (1) (b) GDPR; if the contact person is the contact person of a (potential) business partner (client, supplier, partner), the legal basis for (pre-)contractual measures is Art. 6 (1) (f) GDPR.
3. Purpose of data processing
The processing of personal data serves solely to process the contact request. This also justifies the necessary legitimate interest in the processing of the data.
4. Duration of storage, right to object and right to erasure
The data will be deleted as soon as it is no longer necessary for the purpose for which it was collected. For personal data sent by email or transmitted by telephone, this is the case when the respective conversation with the data subject has ended. The conversation is ended when it can be inferred from the circumstances that the matter in question has been conclusively clarified. If a contract is concluded as a result of the contact, the corresponding (statutory) retention obligations and regulations apply.
If a data subject contacts us by email or telephone, they can object to the storage of their personal data at any time. In such a case, the conversation cannot be continued. All personal data stored in the course of the contact will be deleted in this case.
VIII. Google Analytics
1. Description and scope of data processing
This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. Google Ireland Limited is a subsidiary of Google LLC. based in the USA.
Google Analytics enables the website operator to analyze the behavior of website visitors. The website operator receives various usage data, such as website visits, length of stay, operating systems used, and user origin. This allows the following personal data, among other things, to be collected and evaluated: user activities, device and browser information (in particular IP address), data about the advertisements displayed (click rates), and data from advertising partners. This data may be summarized by Google in a profile that is assigned to the respective user or their end device.
Google Analytics uses cookies and other browser technologies that enable the user to be recognized for the purpose of analyzing user behavior. This information is used, among other things, to compile reports on website activity. Google also transmits your data to Google affiliates and other partners.
Use of a provider based in a third country
The information collected by Google about the use of this website is usually transferred to a Google server in the USA and stored there. The parent company Google LLC. is certified under the EU-US Data Privacy Framework (DPF) ( ). Further information on the DPF can be found in this privacy policy under "I. General information on data processing – 4. Data transfer to a third country or an international organization."
IP address anonymization
Your IP address is automatically anonymized. Only in exceptional cases is the full IP address transferred to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on activities, and to provide other services related to website and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
Use of Google Consent Mode
To control and manage consent in Google services, we are required to use Google's "consent mode" and send "pings" to Google. The pings sent depend on the consents you have given in consent management. The pings are only sent after you have consented to the use of the respective Google service.
By using consent mode and transmitting pings, the following information may be transmitted to Google: Consent and consent status; function-related information (browser header, timestamp, user agent, referrer URL); indication of whether the current or a previous page in the user's navigation history on the website contains information about the ad click in the URL (e.g., GCLID/DCLID); random number generated each time a page is loaded; information about the consent management platform used by the website owner (e.g., developer ID); Google IDs; IP address.
2. Legal basis for data processing
The use of this analysis tool is based on your consent in accordance with Art. 6 (1) (a) GDPR - and Section 25 (1) (1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's end device (e.g., device fingerprinting) within the meaning of the TDDDG.
3. Purpose of data processing
The use of Google Analytics on our site serves to analyze the user behavior of our site visitors in order to optimize and display both our website and our advertising.
4. Duration of storage, possibility of objection, withdrawal, and removal
The collected data is stored until you delete the cookies set by Google Analytics yourself or the purpose for data storage no longer applies. As a user, you have the right to withdraw your consent at any time. The withdrawal of consent does not affect the legality of the processing carried out on the basis of the consent until withdrawal. You can withdraw the consent you have given via consent management.
We have no influence on the specific storage period of the processed data; this is determined by Google Ireland Limited. Data stored by Google at the user and event level that is linked to cookies, user IDs (e.g., user ID) or advertising IDs (e.g., DoubleClick cookies, Android advertising ID) is anonymized or deleted after 14 months. Details can be found at the following link: https://support.google.com/analytics/answer/7667196?hl=de
For site visitors who do not want their data to be used in Google Analytics, Google has developed a browser add-on to deactivate Google Analytics. You can download and install the available browser plugin at the following link: https://tools.google.com/dlpage/gaoptout?hl=de
For more information on how Google Analytics handles user data, please refer to Google's privacy policy: https://policies.google.com/privacy.
Further information on data protection can also be found in the privacy policy for Google Analytics: https://support.google.com/analytics/answer/6004245?hl=de.
IX. Adobe Fonts - local
1. Description and scope of data processing
This website uses certain fonts (so-called web fonts) from Adobe for uniform display. The provider is Adobe Systems Software Ireland Limited, 4-6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland, a subsidiary of Adobe Systems Incorporated, 345 Park Avenue, San Jose, CA 95110-2704, USA.
We integrate the corresponding web fonts as locally hosted fonts within the European Union. Therefore, no data is transferred to Adobe when using these web fonts.
2. Legal basis for data processing
The legal basis for the use of the aforementioned tool is our overriding legitimate interest (Art. 6 (1) (f) GDPR). As part of the necessary balancing of interests, we have weighed your interest in confidentiality against our interest in providing this website (including its functions). Your interest in confidentiality is overriden in this case. Otherwise, we would not be able to provide you with the functions of our website. The use of Adobe Typekit is technically necessary.
C. Data protection information on the processing of client data
I. Description and scope of data processing
We process your personal data that we have received in the course of our business and contractual relationship (client relationship) or in the course of pre-contractual contact or other inquiries on your part. The processing of your personal data serves the purpose of general communication and contract execution with you. Your personal data is processed for the initiation, establishment, execution, or termination of a client relationship with you. Your data is processed in particular in order to be able to provide you with appropriate legal advice and representation.
We process all information necessary for the assertion and defense of your rights within the scope of the client relationship. This may include the following categories of personal data:
- Master data and contact details relating to you or parties involved in a legal transaction, such as title, first and last names, private and/or business address, birth name, date of birth, place of birth, gender, nationality(ies), private and/or business telephone number, private and/or business mobile phone number, private and/or business fax number, and private and/or business email address
- Tax data, such as your tax ID
- Payment data, such as information required to process payment transactions (account holder, IBAN, BIC, credit institution)
- Information collected from publicly available sources and registers (e.g., land register, commercial register) or information databases
- Contract and communication data in connection with correspondence
- Other data, such as identification or family circumstances, income or financial circumstances, professional activity.
- Other data whose processing is necessary for the execution of our contractual relationships or which is provided voluntarily.
In individual cases, the data processed may also include special categories of personal data within the meaning of Art. 9 GDPR (e.g., health data) and data relating to criminal convictions and offenses within the meaning of Art. 10 GDPR.
Source of your data: Your personal data is generally collected directly from you. We may also receive data about third parties (e.g., opposing parties, law enforcement authorities, employers). In addition, we also process data that we obtain from publicly accessible directories and sources. This includes, for example, the land register, commercial register, or register of associations. We also process data that we obtain from courts and authorities (e.g., through access to files).
Provision of your data: The provision of your personal data is neither required by law nor contractually stipulated, but is necessary for communication and the execution of contracts with us. There is no obligation to provide this data. However, failure to provide it may mean that you cannot be our client, as it would not be possible to execute a contract. No fully automated decision-making (including profiling) pursuant to Art. 22 GDPR is used to process the data you provide.
II. Legal basis and purpose of processing
The processing of data within the framework of the client relationship is carried out for the fulfilment of a contract or for the implementation of pre-contractual measures (initiation, execution, and termination) on the basis of Art. 6 (1) (b) GDPR. If the client is the contact person of a legal entity, the legal basis for (pre-)contractual measures is Art. 6 (1) (f) GDPR.
The following purposes, for example, are included in the fulfilment of the client agreement: General contract processing (planning, implementation, and administration of the (contractual) business relationship (client agreement)) and exercise of the rights and obligations arising from this agreement; maintaining and protecting the security of our consulting activities; settling legal disputes; enforcement of existing contracts and for the assertion, exercise, and defense of legal claims; financial accounting, e.g., billing, debt collection, dunning; holding client events and providing information; compliance with legal requirements (e.g., tax and commercial law retention obligations; professional regulations); Preparation of documents and evidence; client data management and evaluation.
The legal basis for the processing of special categories of personal data is Art. 9 (2) (f) GDPR (in conjunction with Recital 52).
Furthermore, we process your personal data on the basis of legal requirements pursuant to Art. 6 (1) (c) GDPR in conjunction with the respective standard in order to fulfil our legal obligations. Within the contractual relationship, we process your data in particular to comply with commercial and tax law obligations under the German Fiscal Code (AO) and the German Commercial Code (HGB) or to fulfil our obligations under the relevant professional regulations. In addition, we process your data to comply with legal requirements (e.g., under the Money Laundering Act – GWG) for identifying the client and the beneficial owners associated with the client.
The processing of your data may also be in our legitimate interest (based on Art. 6 (1) (f) GDPR). Processing is carried out for statistical purposes in order to take operational requirements into account; for technical evaluation and analysis purposes in order to ensure the security of our information technology systems; to optimize our business processes, such as maintaining a customer relationship management database; to maintain and protect the security of our consulting services; to prevent and detect security risks, fraudulent activities, or other criminal or malicious acts; to settle legal disputes, enforce existing contracts, and assert, exercise, or defend legal claims. These purposes constitute our legitimate interest in processing personal data in accordance with Art. 6 (1) (f) GDPR.
III. Duration of processing, right to object and right to erasure
The data you provide will be processed for as long as it is necessary to achieve the contractually agreed purpose, but in principle for as long as the contractual relationship with you exists. The data will therefore be deleted as soon as it is no longer necessary for the purpose for which it was collected. This is the case for the fulfilment of a contract or for the implementation of pre-contractual measures if the data is no longer necessary for the implementation of the contract. Even after conclusion of the contract, it may still be necessary to store the personal data of the contractual partner in order to comply with contractual or legal obligations. After the end of the contractual relationship, the data you have provided will therefore be processed in order to comply with statutory retention obligations or on the basis of our legitimate interests. Your data will be deleted once our legitimate interests or legal requirements no longer apply.
IV. Recipients of the data
Within our law firm, those employees who need your personal data to fulfil our contractual and legal obligations or the above-mentioned purposes and who are authorized to process this data will have access to it. All employees are bound to confidentiality and professional secrecy.
In order to fulfil our contractual and legal obligations, we commission processors who contribute to the fulfilment of these obligations as service providers. These service providers only act in accordance with our instructions and are contractually obliged to comply with the applicable data protection requirements and professional confidentiality. To this end, we conclude corresponding data processing agreements with these service providers in writing. This is a contract required by data protection law, which ensures that our service providers process the personal data of our clients only in accordance with our instructions and in compliance with data protection regulations (GDPR, BDSG, etc.).
Your personal data will be passed on to third parties if this is necessary for the processing of the client relationship with you. This includes, in particular, disclosure to opposing parties and their representatives (in particular their lawyers) as well as courts and other public authorities for the purpose of correspondence and for asserting, defending, and exercising your rights. In addition, data will be passed on to business and contractual partners and advisors of the client, if applicable. Attorney-client privilege remains unaffected by the transfer. Insofar as data is subject to attorney-client privilege, it will only be passed on to third parties in consultation with you.
We may transfer personal data to courts or supervisory authorities if there is a legal obligation to do so under Art. 6 (1) (c) GDPR or if this is necessary under Art. 6 (1) (f) GDPR for the assertion, exercise or defense of our legal claims and there is no reason to assume that our clients have an overriding interest worthy of protection in the non-disclosure of the data.
V. Data transfer to a third country or an international organization
As a rule, the data you provide will not be specifically transferred to a third country or an international organization. The European General Data Protection Regulation (GDPR) stipulates that the transfer of personal data that is already being processed or is to be processed after its transfer to a third country or an international organization is only permissible if a level of data protection comparable to that of the GDPR is guaranteed—in other words, if it is ensured that the provisions of the GDPR are complied with. This may include, for example, the existence of an adequacy decision by the EU Commission within the meaning of Art. 45 (1), (3) GDPR or the introduction of internal company data protection regulations approved by a supervisory authority (so-called "appropriate safeguards," Art. 46 (2), (3) GDPR). If, in individual cases, you wish to have the data you have provided transferred to a third country or an international organization, we will only do so with your written consent.
D. Data protection information on the processing of applicant data
We only collect and use personal data from our applicants to the extent necessary to carry out the application process. The protection of our applicants' personal data is very important to us. We therefore process personal data in accordance with the applicable legal provisions on the protection of personal data and data security.
I. Description and scope of data processing
We collect and process your personal data in order to carry out the selection process. The data you provide will be processed for the purpose of processing your application and, in the event of an employment relationship being established, also for the purpose of implementing the employment relationship.
We may process the following categories and types of personal data:
- General information about you and personal data
- First name, last name, birth name, name affixes, gender, home address, postal address (if applicable), telephone numbers (landline and mobile), personal email address
- If you provide this information: date of birth (and age), marital status, religion
- If apparent from your application photo: information on health characteristics, e.g., glasses or ethnic origin
- Information about your knowledge and skills
- CV data, such as information about school, training, and studies, information about previous professional positions (including job title, previous employers, position, department, location), professional experience
- Information about previous successes and skills acquired
- Proof of further training and exams passed, as well as certificates (e.g., school certificates or references from previous employers)
- Information about your desired employment
- such as start date, place of work, salary expectations
In addition, the following data will be collected from you if you provide us with this information in your application and if:
- You are not an EU citizen:
- Information about your citizenship
- Information about your residence permit (residence and work permit)
- It is relevant to the advertised position and legally permissible:
- Information on the existence of a severe disability (Schwerbehinderung)
- Information about previous convictions; data from your police clearance certificate
- Data from your driver's license (e.g., information on the driver's license class)
- If you have other jobs: Information on other jobs (e.g., main or secondary job, type)
In addition to the above data, we may process further personal data if you provide it to us in your application.
Your personal data is generally collected directly from you during the recruitment process, in particular from your application documents, the interview, and the personnel questionnaire.
The provision of your personal data is neither required by law nor contractually stipulated, but is necessary for the application process at our company. There is no obligation to provide this data. However, failure to provide it may mean that we are unable to consider your application in the application process. Neither fully automated decision-making nor profiling (Art. 22 GDPR) is used to process the data you provide.
Publicly accessible sources
We may also process personal data from publicly accessible sources, e.g., websites, professional networks, which we use permissibly and only for the respective purpose. We also receive data from third parties (e.g., employment agencies, recruiters).
Establishment of an employment relationship
If an employment relationship is established between you and us, we may, in accordance with Section 26 (1) BDSG or Art. 6 (1) (b) GDPR, further process the personal data already received from you for the purposes of the employment relationship. This is done if it is necessary for the performance or termination of the employment relationship.
II. Purpose and legal basis of processing
The processing of your data in the application process is based on Section 26 (1) BDSG (Art. 88 (1) GDPR) or Art. 6 (1) (b) GDPR for the purpose of establishing an employment relationship with us.
Insofar as special personal data within the meaning of Art. 9 (1) GDPR is processed in this context, the legal basis for the processing is Section 26 (3) BDSG or Art. 9 (2) lit. b GDPR.
In addition, the processing of your personal data on is based on Art. 6 (1) (f) GDPR. Processing is carried out, for example, for technical evaluation and analysis purposes, to ensure the security of our information technology systems, or to assert, exercise, or defend legal claims (e.g., to fulfil our obligation to provide evidence in proceedings under the General Equal Treatment Act (AGG)). These purposes constitute our legitimate interest.
III. Duration of storage, right to object and right to erasure
In the event of rejection, your application documents will be deleted no later than six months after completion of the application process. We will only store your personal data beyond this period if this is required by law or in specific cases to assert, exercise, or defend legal claims for the duration of a legal dispute.
If you are hired, we will transfer your application documents to your personnel file. After termination of the employment relationship, we will continue to store those personal data that we are legally obliged to retain. This regularly results from legal documentation and retention obligations, which are regulated in the German Commercial Code and the German Fiscal Code, among others. We will send you the data protection information for employees, which contains more detailed information, upon acceptance of the position.
IV. Recipients of the data
Within our organization, those departments and areas involved in the application process and in the decision on your employment will have access to your personal data.
As part of our service provision, we commission processors who contribute to the fulfilment of the above-mentioned purposes. These are service providers such as IT maintenance service providers, video conferencing tools, or newsletter dispatchers (so-called processors). These service providers only act on our instructions and are contractually obliged to comply with the applicable data protection requirements. To this end, we conclude corresponding processing agreements with these service providers in writing.
Data processing is carried out using Microsoft Office, a system provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. The agreed server location is within the EU. As Microsoft is an international company headquartered in the US, data may be accessed for maintenance or support services.
The European Commission has certified the EU-U.S. Data Privacy Framework as providing an adequate level of protection. This applies provided that the organization to which data is transferred is also certified under the EU-U.S. Data Privacy Framework. MICROSOFT CORPORATION has obtained the relevant certification.
We may transfer personal data to courts, supervisory authorities, or law firms if there is a legal obligation to do so under Art. 6 (1) (c) GDPR or if it is necessary under Art. 6 (1) (f) GDPR for the assertion, exercise or defense of legal claims and there is no reason to assume that our employees have an overriding interest worthy of protection in not disclosing the data.
V. Data transfer to "unsafe" third countries
The data you provide will not be transferred to a third country without an adequate level of data protection and there are no plans to do so.
Please use the above contact details of the data controller to exercise your rights.
Stand: März 2026