Pri­va­cy Poli­cy breutac — Tax Advi­so­ry and Con­tro­ver­sy.

We take data pro­tec­tion very serious­ly.

1. Con­trol­ler

breutac Breu­nin­ger Rechts­an­walts­ge­sell­schaft mbH & Co. KG Regis­ter Court:

Munich Local Court, Regis­tra­ti­on Num­ber: HRA 122915

Widen­may­er­str. 6
80538 Munich
Tel. +49 89 21 23 161–0
Fax +49 89 43 78 08 26.

Aut­ho­ri­zed Gene­ral Part­ner (Kom­ple­men­tä­rin): Breu­nin­ger Rechts­an­walts GmbH Regis­ter Court: Munich Local Court, Regis­tra­ti­on Num­ber: HRB 312803 Mana­ging Direc­tor: Dr. Gott­fried E. Breu­nin­ger

If you have any ques­ti­ons about data pro­tec­tion or wish to exer­cise your rights, you can reach us at contact@breutac.com.

2. Legal Basis

We pro­cess the data gene­ra­ted by visi­ting our web­site or using the cont­act opti­ons offe­red in accordance with the pro­vi­si­ons of the Euro­pean Gene­ral Data Pro­tec­tion Regu­la­ti­on (GDPR), the Ger­man Fede­ral Data Pro­tec­tion Act (BDSG), and—insofar as it con­cerns sto­ring infor­ma­ti­on on your device or acces­sing infor­ma­ti­on alre­a­dy stored—the Tele­com­mu­ni­ca­ti­ons-Digi­tal Ser­vices-Data Pro­tec­tion Act (TDDDG). Depen­ding on the mat­ter for which you cont­act us via the web­site, dif­fe­rent legal bases may app­ly. The spe­ci­fic legal basis depends on the con­text and pur­po­se for which we recei­ve your data. It gene­ral­ly ari­ses from the fol­lo­wing pos­si­bi­li­ties:

Artic­le 6(1)(a) GDPR ser­ves as our legal basis for pro­ces­sing ope­ra­ti­ons for which we obtain con­sent for a spe­ci­fic pro­ces­sing pur­po­se. Con­sent given may be with­drawn at any time.

If the pro­ces­sing of per­so­nal data is neces­sa­ry for the per­for­mance of a con­tract to which the data sub­ject is a par­ty, the pro­ces­sing is based on Artic­le 6(1)(b) GDPR. The same appli­es to pro­ces­sing ope­ra­ti­ons neces­sa­ry for the imple­men­ta­ti­on of pre-con­trac­tu­al mea­su­res, such as inqui­ries about our ser­vices.

If we are sub­ject to a legal obli­ga­ti­on that requi­res the pro­ces­sing of per­so­nal data, such as for the ful­fill­ment of tax obli­ga­ti­ons, the pro­ces­sing is based on Artic­le 6(1)© GDPR.

Final­ly, pro­ces­sing ope­ra­ti­ons may be based on Artic­le 6(1)(f) GDPR. Pro­ces­sing ope­ra­ti­ons not cover­ed by any of the afo­re­men­tio­ned legal bases are based on this legal basis if the pro­ces­sing is neces­sa­ry to pro­tect a legi­ti­ma­te inte­rest of our com­pa­ny or a third par­ty, pro­vi­ded that the inte­rests, fun­da­men­tal rights, and free­doms of the data sub­ject do not over­ri­de tho­se inte­rests.

3. Data Pro­ces­sing on Our Web­site

3.1 Coll­ec­tion of Gene­ral Infor­ma­ti­on When Visi­ting Our Web­site

When you access our website—that is, if you do not trans­mit any other infor­ma­ti­on to us—we coll­ect only the per­so­nal data that your brow­ser auto­ma­ti­cal­ly trans­mits to our ser­ver. This includes the IP address, date and time of the request, the con­tent of the request, access sta­tus or HTTP sta­tus code, the amount of data trans­mit­ted in each case, the web­site from which the request ori­gi­na­tes, the brow­ser used, the ope­ra­ting sys­tem and its inter­face, and the lan­guage and ver­si­on of the brow­ser soft­ware.

This data is not mer­ged with other data sources. The coll­ec­tion is tech­ni­cal­ly neces­sa­ry to dis­play our web­site to you wit­hout errors and in an opti­mi­zed man­ner, and to ensu­re its sta­bi­li­ty and secu­ri­ty. The pro­ces­sing is based on Artic­le 6(1)(f) GDPR.

3.2 Goog­le Maps

On the cont­act page, we use the Goog­le Maps map­ping ser­vice. This allows us to dis­play inter­ac­ti­ve maps direct­ly on the web­site and enable con­ve­ni­ent use of the map func­tion. For per­sons from the Euro­pean Eco­no­mic Area and Switz­er­land, the map­ping ser­vice is pro­vi­ded by Goog­le Ire­land Limi­t­ed, Gor­don House, Bar­row Street, Dub­lin 4, Ire­land, and for all other per­sons by Goog­le LLC, 1600 Amphi­theat­re Park­way, Moun­tain View, CA 94043, USA (“Goog­le”). In order for the map mate­ri­al to be embedded and dis­play­ed in your web brow­ser, your web brow­ser must estab­lish a con­nec­tion to a Goog­le ser­ver, which may also be loca­ted in the USA, when you access the cont­act page. Goog­le ther­eby recei­ves the infor­ma­ti­on that the cont­act page of our web­site was acces­sed from the IP address of your device. For data trans­fers to third count­ries, par­ti­cu­lar­ly to the USA, plea­se refer to the infor­ma­ti­on in Sec­tion 13.

The legal basis for sto­ring infor­ma­ti­on on your device or acces­sing it is your con­sent pur­su­ant to Sec­tion 25(1) TDDDG; the legal basis for the sub­se­quent pro­ces­sing of your per­so­nal data is your con­sent pur­su­ant to Artic­le 6(1)(a) GDPR. Wit­hout your con­sent, no con­nec­tion to Goo­g­le’s ser­vers is estab­lished. You can with­draw your con­sent at any time with effect for the future or adjust your sel­ec­tion via the coo­kie set­tings (see Sec­tion 5).

If you access the Goog­le map­ping ser­vice while log­ged into your Goog­le pro­fi­le, Goog­le may link this event to your Goog­le pro­fi­le. If you do not wish this asso­cia­ti­on to occur, you must log out of Goog­le befo­re acces­sing our cont­act page. Goog­le stores your data and uses it for adver­ti­sing, mar­ket rese­arch, and per­so­na­li­zed dis­play of Goog­le Maps. For more infor­ma­ti­on, plea­se refer to Goo­g­le’s Pri­va­cy Poli­cy and the Addi­tio­nal Terms of Use for Goog­le Maps.

3.3 Use of Social Media Plug­ins

We use a social media plug­in from Lin­ke­dIn and employ the so-cal­led two-click solu­ti­on: When you visit our site, no per­so­nal data is initi­al­ly trans­mit­ted to the plug­in pro­vi­der. Only when you click on and ther­eby acti­va­te the mark­ed field does the plug­in pro­vi­der recei­ve the infor­ma­ti­on that you have acces­sed the cor­re­spon­ding page; in addi­ti­on, the data men­tio­ned in Sec­tion 4.1 is trans­mit­ted and stored by the pro­vi­der (in the case of US pro­vi­ders, in the USA).

The legal basis for the pro­ces­sing trig­ge­red by your acti­ve acti­va­ti­on is your con­sent pur­su­ant to Artic­le 6(1)(a) GDPR and—insofar as infor­ma­ti­on is stored on or acces­sed from your device—Section 25(1) TDDDG. We under­stand the acti­ve ope­ra­ti­on of the but­ton as the gran­ting of con­sent. With regard to the coll­ec­tion and trans­mis­si­on of your data to Lin­ke­dIn trig­ge­red via the but­ton, the­re is joint con­trol­ler­ship with Lin­ke­dIn; for fur­ther pro­ces­sing by Lin­ke­dIn, Lin­ke­dIn is sole­ly respon­si­ble. For data trans­fers to third count­ries, plea­se refer to the infor­ma­ti­on in Sec­tion 13.

We have no influence over or know­ledge of the data coll­ec­ted, the scope of data coll­ec­tion, the pro­ces­sing pur­po­ses, the reten­ti­on peri­ods, and the dele­ti­on bey­ond the afo­re­men­tio­ned pro­cess. The plug­in pro­vi­der stores the data as user pro­files and uses them for adver­ti­sing, mar­ket rese­arch, and the needs-based design of its web­site. You have a right to object in this regard, which you can assert against the plug­in pro­vi­der.

The data trans­fer takes place regard­less of whe­ther you have an account with the plug­in pro­vi­der and are log­ged in the­re. If you are log­ged in, the data coll­ec­ted from us is direct­ly asso­cia­ted with your exis­ting account the­re. For more infor­ma­ti­on, plea­se refer to Lin­ke­dIn’s Pri­va­cy Poli­cy.

4. Coo­kies

In addi­ti­on to the data men­tio­ned abo­ve, coo­kies are stored on your device when you use our web­site. Coo­kies are small text files that are stored in asso­cia­ti­on with the brow­ser you are using and through which cer­tain infor­ma­ti­on flows to the enti­ty that sets the coo­kie.

Tech­ni­cal­ly neces­sa­ry coo­kies ser­ve to make our web­site more user-fri­end­ly and are requi­red for ope­ra­ti­on. The legal basis for sto­rage or access is Sec­tion 25(2) No. 2 TDDDG; the legal basis for the asso­cia­ted pro­ces­sing of per­so­nal data is Artic­le 6(1)(f) GDPR. Non-neces­sa­ry coo­kies (e.g., for ana­ly­sis or mar­ke­ting pur­po­ses) are only set with your con­sent pur­su­ant to Sec­tion 25(1) TDDDG in con­junc­tion with Artic­le 6(1)(a) GDPR. When you first visit our web­site, you will be asked for con­sent via a coo­kie ban­ner. You can with­draw your con­sent at any time with effect for the future or adjust your sel­ec­tion by acces­sing the coo­kie set­tings again.

This web­site uses tran­si­ent and per­sis­tent coo­kies. Tran­si­ent coo­kies, par­ti­cu­lar­ly ses­si­on coo­kies, are auto­ma­ti­cal­ly dele­ted when you log out or clo­se the brow­ser. Per­sis­tent coo­kies are auto­ma­ti­cal­ly dele­ted after a peri­od that varies depen­ding on the coo­kie; you can dele­te them at any time via your brow­ser­’s secu­ri­ty set­tings.

You can con­fi­gu­re your brow­ser to reject the accep­tance of coo­kies; in that case, you may not be able to use all the fea­tures of this web­site. In addi­ti­on, we use HTML5 sto­rage objects, who­se sto­rage or rea­ding is also only car­ri­ed out in accordance with Sec­tion 25 TDDDG and who­se use you can pre­vent by using your brow­ser­’s pri­va­te mode. We also recom­mend regu­lar­ly dele­ting coo­kies and brow­ser histo­ry manu­al­ly.

5. Cont­act

You have various opti­ons to cont­act us, in par­ti­cu­lar via the cont­act form, by tele­pho­ne, or by email to the cont­act addres­ses men­tio­ned abo­ve. If you cont­act us via one of the­se chan­nels, we store the data you pro­vi­de (e.g., name, cont­act details, inquiry) in order to pro­cess your request.

The legal basis is Artic­le 6(1)(b) GDPR if the inquiry is direc­ted toward ente­ring into a man­da­te rela­ti­onship (pre-con­trac­tu­al mea­su­re), and Artic­le 6(1)(f) GDPR (legi­ti­ma­te inte­rest in pro­ces­sing and respon­ding to inqui­ries) in all other cases. The pro­vi­si­on of your data is neither legal­ly nor con­trac­tual­ly requi­red; howe­ver, wit­hout the infor­ma­ti­on neces­sa­ry for pro­ces­sing, we can­not ans­wer your inquiry or can­not ans­wer it com­ple­te­ly. The data coll­ec­ted during cont­act will be dele­ted as soon as it is no lon­ger neces­sa­ry for achie­ving the pur­po­se for which it was coll­ec­ted, unless sta­tu­to­ry reten­ti­on obli­ga­ti­ons pre­vent dele­ti­on.

6. Appli­ca­ti­ons

You can app­ly to us by email or via Lin­ke­dIn for open posi­ti­ons. The pur­po­se of data coll­ec­tion is the sel­ec­tion of appli­cants for the pos­si­ble estab­lish­ment of an employ­ment rela­ti­onship. To pro­cess your appli­ca­ti­on, we coll­ect the data you pro­vi­de (typi­cal­ly: first and last name; email address; appli­ca­ti­on docu­ments such as cer­ti­fi­ca­tes and CV; ear­liest pos­si­ble start date; chan­nel through which you beca­me awa­re of the job pos­ting; if appli­ca­ble, tele­pho­ne num­ber, sala­ry expec­ta­ti­ons, and Xing or Lin­ke­dIn pro­fi­le). We point out that con­fi­den­tia­li­ty can­not be gua­ran­teed when appli­ca­ti­ons are sent unen­crypt­ed by email. As a rule, you can also app­ly to our posi­ti­ons by post.

The legal basis for pro­ces­sing your appli­ca­ti­on docu­ments is Artic­le 6(1)(b) and Artic­le 88(1) GDPR in con­junc­tion with Sec­tion 26(1) sen­tence 1 BDSG. Inso­far as spe­cial cate­go­ries of per­so­nal data (Artic­le 9 GDPR) are pro­ces­sed in indi­vi­du­al cases, this is done on the basis of Sec­tion 26(3) BDSG.

We store your per­so­nal data upon receipt of your appli­ca­ti­on. If we accept your appli­ca­ti­on and an employ­ment rela­ti­onship is estab­lished, we store your appli­ca­ti­on data for as long as it is neces­sa­ry for the employ­ment rela­ti­onship and to the ext­ent that sta­tu­to­ry pro­vi­si­ons estab­lish a reten­ti­on obli­ga­ti­on. If we reject your appli­ca­ti­on, we store your appli­ca­ti­on data for a maxi­mum of six months after the rejec­tion in order to be able to defend against any claims under the Gene­ral Equal Tre­at­ment Act (AGG), unless you give us your con­sent to lon­ger sto­rage (e.g., for inclu­si­on in our appli­cant pool). You can with­draw this con­sent at any time for the future by sen­ding us an email to contact@breutac.com.

7. Social Net­works

We main­tain various online pre­sen­ces on social net­works in order to com­mu­ni­ca­te with inte­res­ted par­ties and pro­vi­de infor­ma­ti­on about our ser­vices, in par­ti­cu­lar our Lin­ke­dIn com­pa­ny page of Lin­ke­dIn Ire­land Unli­mi­t­ed Com­pa­ny, Wil­ton Place, Dub­lin 2, Ire­land (“Lin­ke­dIn”).

In the con­text of ope­ra­ting our online pre­sen­ces, we may access aggre­ga­ted usa­ge sta­tis­tics pro­vi­ded by the ope­ra­tor of the social net­work. The­se may include, in par­ti­cu­lar, demo­gra­phic infor­ma­ti­on (e.g., age, gen­der, regi­on), employ­ment-rela­ted infor­ma­ti­on (e.g., func­tion, indus­try, pro­fes­sio­nal expe­ri­ence), and inter­ac­tion data (e.g., likes, shares, sub­scrip­ti­ons) and pro­vi­de us with insights into the inte­rests of users, which we use to opti­mi­ze our con­tent. The coll­ec­tion and use of the­se sta­tis­tics is sub­ject to joint con­trol­ler­ship with the ope­ra­tor; for Lin­ke­dIn, plea­se refer to the Page Insights Joint Con­trol­ler Adden­dum for details.

The legal basis for this data pro­ces­sing is Artic­le 6(1)(b) GDPR, in order to stay in cont­act with our cli­ents and inform them, as well as to car­ry out pre-con­trac­tu­al mea­su­res with inte­res­ted par­ties, and Artic­le 6(1)(f) GDPR based on our legi­ti­ma­te inte­rest in effec­ti­ve infor­ma­ti­on and com­mu­ni­ca­ti­on with users.

We have no influence over the data pro­ces­sing car­ri­ed out by the social net­work under its own respon­si­bi­li­ty. We point out that when you visit the online pre­sence, data about your usa­ge beha­vi­or may be trans­mit­ted to the ope­ra­tor, who may pro­cess it via coo­kies and other iden­ti­fiers into usa­ge pro­files for its own mar­ket rese­arch and adver­ti­sing pur­po­ses. For more infor­ma­ti­on, plea­se refer to Lin­ke­dIn’s Pri­va­cy Poli­cy.

Inso­far as we recei­ve your per­so­nal data when ope­ra­ting the online pre­sence, you have the rights set out in this Pri­va­cy Poli­cy. You can most easi­ly assert rights against the ope­ra­tor direct­ly with them; we are hap­py to sup­port you in this and for­ward your requests.

8. Online Mee­tings via “Teams”

We use “Teams” to con­duct online mee­tings, tele­pho­ne con­fe­ren­ces, and/or web­i­nars (her­ein­af­ter coll­ec­tively “Mee­tings”). Teams is soft­ware from Micro­soft Ire­land Ope­ra­ti­ons Limi­t­ed, South Coun­ty Busi­ness Park, Leo­pard­stown, Dub­lin 18, Ire­land (“Micro­soft”), available as a desk­top, web, and mobi­le app.

The legal basis for data pro­ces­sing to con­duct mee­tings via Teams is our legi­ti­ma­te inte­rest in the effec­ti­ve and simp­le con­duct of online mee­tings, dis­cus­sion rounds, and pre­sen­ta­ti­ons pur­su­ant to Artic­le 6(1)(f) GDPR. Inso­far as mee­tings are con­duc­ted within the frame­work of exis­ting con­trac­tu­al rela­ti­onships with you, the legal basis is Artic­le 6(1)(b) GDPR. Inso­far as we record mee­tings or log text data, this is done exclu­si­ve­ly on the basis of your con­sent pur­su­ant to Artic­le 6(1)(a) GDPR; for employees, the per­mis­si­bi­li­ty is gover­ned by Sec­tion 26 BDSG or any appli­ca­ble works or ser­vice agree­ment. We are not respon­si­ble for fur­ther data pro­ces­sing on the Teams pro­duct web­site, from which the desk­top soft­ware can be down­loa­ded and the web app can be used.

During a mee­ting, the fol­lo­wing data may be pro­ces­sed under cer­tain cir­cum­s­tances: infor­ma­ti­on about the par­ti­ci­pant (if appli­ca­ble, dis­play name, first name, last name, tele­pho­ne, email address, encrypt­ed pass­word for authen­ti­ca­ti­on, pro­fi­le pic­tu­re); meta­da­ta (mee­ting topic and descrip­ti­on, IP address, par­ti­ci­pan­t’s tele­pho­ne num­ber, type of device or soft­ware, time of last acti­vi­ty, num­ber of chat and chan­nel mes­sa­ges, num­ber of mee­tings atten­ded, dura­ti­on of audio, video, and screen sha­ring); in the case of chat or chan­nel mes­sa­ge use, text data for dis­play and, if appli­ca­ble, log­ging; in the case of audio use, recor­dings from the micro­pho­ne; in the case of video use, recor­dings from the video came­ra; in the case of recor­dings, audio, video, and screen shares for sto­rage in the cloud or in Micro­soft Stream; and in the case of tele­pho­ne use, inco­ming and out­go­ing call num­bers, coun­try name, start and end time, and, if appli­ca­ble, other con­nec­tion data such as the IP address of the device.

Befo­re a mee­ting, you regis­ter via our web­site or by email; we pro­cess your regis­tra­ti­on data and send you a con­fir­ma­ti­on with an invi­ta­ti­on link or calen­dar appoint­ment. To par­ti­ci­pa­te, at least your name and—in the case of tele­pho­ne use—your tele­pho­ne num­ber are requi­red, unless we enable anony­mous par­ti­ci­pa­ti­on (with a cor­re­spon­ding note in the invi­ta­ti­on). You can deac­ti­va­te the micro­pho­ne and came­ra at any time. Only with your con­sent and after pri­or noti­fi­ca­ti­on do we record mee­tings or log text data. Micro­soft uses the meta­da­ta to enable us to ana­ly­ze and report on the use of Teams.

Micro­soft may beco­me awa­re of the afo­re­men­tio­ned data in the con­text of order pro­ces­sing. For more infor­ma­ti­on on data pro­tec­tion, plea­se refer to Micro­sof­t’s Pri­va­cy Poli­cy.

9. Pro­ces­sing of Cli­ent Data in Con­nec­tion with Man­da­te Pro­ces­sing

breutac pro­ces­ses per­so­nal data to the ext­ent neces­sa­ry for the estab­lish­ment of man­da­te rela­ti­onships and the per­for­mance, pro­ces­sing, and ter­mi­na­ti­on of man­da­te rela­ti­onships.

This may affect per­so­nal data of our cli­ents, inclu­ding their employees and exe­cu­ti­ve body mem­bers (board mem­bers, mana­ging direc­tors), as well as third par­ties who­se data is requi­red for the estab­lish­ment of the man­da­te rela­ti­onship or the pro­ces­sing of the man­da­te. This includes, among others, direct and indi­rect share­hol­ders of the cli­ent, busi­ness and con­trac­tu­al part­ners as well as advi­sors of the cli­ent, coun­ter­par­ties in a legal dis­pu­te and their legal advisors—in each case inclu­ding the employees and exe­cu­ti­ve body mem­bers of the afo­re­men­tio­ned per­sons and entities—as well as employees of aut­ho­ri­ties and courts, wit­nesses, experts, and other par­ties to pro­cee­dings.

We pro­cess the fol­lo­wing cate­go­ries of per­so­nal data to the ext­ent neces­sa­ry for our work: cont­act infor­ma­ti­on, in par­ti­cu­lar first and last name, title if appli­ca­ble, address, tele­pho­ne num­ber, and email address; infor­ma­ti­on on pro­fes­sio­nal acti­vi­ty; infor­ma­ti­on on inco­me and assets; and other per­so­nal data that is neces­sa­ry in the con­text of man­da­te pro­ces­sing for the deter­mi­na­ti­on and legal assess­ment of the facts and the appro­pria­te legal advice and repre­sen­ta­ti­on of the cli­ent. In indi­vi­du­al cases, the data pro­ces­sed may also include spe­cial cate­go­ries of per­so­nal data, such as data on cri­mi­nal con­vic­tions and offen­ses within the mea­ning of Artic­le 10 GDPR.

Inso­far as we do not recei­ve per­so­nal data direct­ly from the data sub­jects (e.g., in the con­text of cor­re­spon­dence with cont­act per­sons at cli­ents and/or oppo­sing par­ties), the data may ori­gi­na­te from cli­ents, courts and aut­ho­ri­ties (e.g., in the con­text of file inspec­tion and/or infor­ma­ti­on), other third par­ties (e.g., par­ties to pro­cee­dings, wit­nesses), and publicly acces­si­ble sources (public regis­ters, inter­net rese­arch).

We pro­cess data in con­nec­tion with man­da­te pro­ces­sing for the pur­po­ses of ful­fil­ling sta­tu­to­ry requi­re­ments, iden­ti­fy­ing the cli­ent and the bene­fi­ci­al owners asso­cia­ted with them, revie­w­ing pos­si­ble con­flicts of inte­rest befo­re accep­ting a man­da­te, deter­mi­ning and legal­ly asses­sing the facts, advi­sing and repre­sen­ting cli­ents, cor­re­spon­ding with cli­ents, aut­ho­ri­ties, courts, and other par­ties, invoi­cing, and sett­ling and asser­ting other claims ari­sing from the man­da­te rela­ti­onship.

The legal bases are Artic­le 6(1)(b) GDPR (per­for­mance of the man­da­te con­tract), Artic­le 6(1)© GDPR (ful­fill­ment of legal obli­ga­ti­ons, e.g., under the Fede­ral Lawy­ers’ Act or the Money Laun­de­ring Act), and Artic­le 6(1)(f) GDPR (legi­ti­ma­te inte­rest in pro­per legal pro­se­cu­ti­on and defen­se). The legal basis for pro­ces­sing spe­cial cate­go­ries of per­so­nal data is Artic­le 9(2)(f) GDPR, inso­far as this is neces­sa­ry for the estab­lish­ment, exer­cise, or defen­se of legal claims; whe­re appli­ca­ble, we addi­tio­nal­ly rely on Artic­le 9(2)(a) GDPR (expli­cit con­sent) or—in the case of employee data—on Sec­tion 26(3) BDSG.

The pro­vi­si­on of cer­tain data may be legal­ly or con­trac­tual­ly requi­red. In par­ti­cu­lar, for man­da­tes sub­ject to the Money Laun­de­ring Act (GwG), we are legal­ly obli­ga­ted to iden­ti­fy you or your bene­fi­ci­al owners; wit­hout the requi­red infor­ma­ti­on and evi­dence, we can­not estab­lish or con­ti­nue the man­da­te in this respect. Inso­far as we are sub­ject to the GwG, we coll­ect the infor­ma­ti­on and evi­dence requi­red for this pur­po­se (in par­ti­cu­lar, iden­ti­ty docu­ment data) and retain the coll­ec­ted data and docu­ments in accordance with the GwG—generally for a peri­od of five years; the legal basis in this respect is Artic­le 6(1)© GDPR in con­junc­tion with the pro­vi­si­ons of the GwG.

All per­sons working in the firm are obli­ga­ted to main­tain con­fi­den­tia­li­ty pur­su­ant to Sec­tion 43a BRAO and Sec­tion 203 of the Ger­man Cri­mi­nal Code (StGB).

Inso­far as it is neces­sa­ry for the pro­ces­sing of a man­da­te, we trans­mit per­so­nal data to cli­ents, aut­ho­ri­ties and courts, as well as to the other third par­ties men­tio­ned abo­ve. In indi­vi­du­al cases, trans­mis­si­on also takes place to reci­pi­ents in third count­ries wit­hout an ade­quacy decis­i­on; for the gua­ran­tees pro­vi­ded in this respect, plea­se refer to Sec­tion 13.

Case files are retai­ned for a peri­od of six years after the ter­mi­na­ti­on of the man­da­te in accordance with Sec­tion 50 BRAO, unless sta­tu­to­ry or man­da­te-spe­ci­fic reasons requi­re lon­ger reten­ti­on. Other­wi­se, per­so­nal data is stored as long as its pro­ces­sing is neces­sa­ry for the afo­re­men­tio­ned pur­po­ses, unless sta­tu­to­ry pro­vi­si­ons requi­re a lon­ger sto­rage peri­od.

10. Pro­ces­sing of Busi­ness Part­ner Data

We pro­cess per­so­nal data in the con­text of coope­ra­ti­on with ser­vice pro­vi­ders, sup­pli­ers, and other busi­ness part­ners (her­ein­af­ter “Busi­ness Part­ners”) as well as their employees.

In doing so, we pro­cess per­so­nal data to the ext­ent neces­sa­ry for the estab­lish­ment or per­for­mance of the con­trac­tu­al rela­ti­onship with the Busi­ness Part­ner. This includes cont­act infor­ma­ti­on, in par­ti­cu­lar first and last name, title if appli­ca­ble, address, tele­pho­ne num­ber, and email address; infor­ma­ti­on on pro­fes­sio­nal acti­vi­ty; and bank details. Inso­far as we do not recei­ve per­so­nal data direct­ly from the data sub­jects (e.g., in the con­text of cor­re­spon­dence with cont­act per­sons at the Busi­ness Part­ner), the data regu­lar­ly ori­gi­na­tes from the Busi­ness Part­ner as the employ­er of the data sub­jects.

We pro­cess this data for the estab­lish­ment, per­for­mance, and sett­le­ment of the con­trac­tu­al rela­ti­onship with the Busi­ness Part­ner. The legal basis, inso­far as per­so­nal data of the Busi­ness Part­ner is pro­ces­sed, is Artic­le 6(1)(b) GDPR; other­wi­se, Artic­le 6(1)(f) GDPR. Per­so­nal data is stored as long as its pro­ces­sing is neces­sa­ry for the afo­re­men­tio­ned pur­po­ses, unless sta­tu­to­ry pro­vi­si­ons pre­scri­be a lon­ger sto­rage peri­od.

11. Dis­clo­sure of Data

Dis­clo­sure of the data we coll­ect gene­ral­ly only takes place if you have given your express con­sent pur­su­ant to Artic­le 6(1)(a) GDPR, the dis­clo­sure is neces­sa­ry pur­su­ant to Artic­le 6(1)(f) GDPR to pro­tect our inte­rests or to estab­lish, exer­cise, or defend legal claims and the­re is no reason to assu­me that you have an over­ri­ding legi­ti­ma­te inte­rest in non-dis­clo­sure, we are legal­ly obli­ga­ted to dis­c­lo­se pur­su­ant to Artic­le 6(1)© GDPR, or this is legal­ly per­mis­si­ble and neces­sa­ry pur­su­ant to Artic­le 6(1)(b) GDPR for the per­for­mance of con­trac­tu­al rela­ti­onships with you or for the imple­men­ta­ti­on of pre-con­trac­tu­al mea­su­res car­ri­ed out at your request.

Part of the data pro­ces­sing may be car­ri­ed out by our ser­vice pro­vi­ders. In addi­ti­on to the ser­vice pro­vi­ders men­tio­ned in this Pri­va­cy Poli­cy, the­se may include, in par­ti­cu­lar, data cen­ters that host our web­site and data­ba­ses, IT ser­vice pro­vi­ders that main­tain our sys­tems, and con­sul­ting firms. If we dis­c­lo­se data to our ser­vice pro­vi­ders, they may only use the data to ful­fill their tasks. The ser­vice pro­vi­ders have been careful­ly sel­ec­ted and com­mis­sio­ned by us; they are con­trac­tual­ly bound by our ins­truc­tions, have appro­pria­te tech­ni­cal and orga­niza­tio­nal mea­su­res in place to pro­tect the rights of data sub­jects, and are regu­lar­ly moni­to­red by us. In addi­ti­on, dis­clo­sure may occur in con­nec­tion with offi­ci­al inqui­ries, court orders, and legal pro­cee­dings if this is neces­sa­ry for legal pro­se­cu­ti­on or enforce­ment.

12. Data Trans­fer to Third Count­ries

We may use ser­vices who­se pro­vi­ders are part­ly loca­ted in so-cal­led third count­ries (such as the USA) or trans­mit per­so­nal data the­re, i.e., in count­ries who­se level of data pro­tec­tion does not cor­re­spond to that of the Euro­pean Uni­on.

If an ade­quacy decis­i­on by the Euro­pean Com­mis­si­on (Artic­le 45 GDPR) exists for the respec­ti­ve coun­try, we base the data trans­fer on it. In the case of the USA, this only appli­es inso­far as the US reci­pi­ent has cer­ti­fied for the EU-US Data Pri­va­cy Frame­work.

Inso­far as no ade­quacy decis­i­on has been issued for the cor­re­spon­ding coun­try, we have taken appro­pria­te pre­cau­ti­ons to ensu­re an ade­qua­te level of data pro­tec­tion for any data trans­fers. The­se include, among others, the Euro­pean Uni­on’s Stan­dard Con­trac­tu­al Clau­ses or bin­ding cor­po­ra­te rules (Artic­le 46 GDPR). Whe­re this is not pos­si­ble, we base the data trans­fer on the dero­ga­ti­ons of Artic­le 49 GDPR, in par­ti­cu­lar your express con­sent or the neces­si­ty of the trans­fer for the per­for­mance of a con­tract or for the imple­men­ta­ti­on of pre-con­trac­tu­al mea­su­res. If a third-coun­try trans­fer is plan­ned and no ade­quacy decis­i­on or appro­pria­te safe­guards exist, the­re is a risk that aut­ho­ri­ties in the respec­ti­ve third coun­try (e.g., intel­li­gence ser­vices) may gain access to the trans­mit­ted data in order to coll­ect and ana­ly­ze it, and that the enforcea­bi­li­ty of your data sub­ject rights can­not be gua­ran­teed. In the event that your con­sent is obtai­ned via the con­sent ban­ner, you will also be infor­med of this.

13. Reten­ti­on Peri­od

As a gene­ral rule, we store per­so­nal data only for as long as is neces­sa­ry to ful­fill the pur­po­ses for which we coll­ec­ted the data. After that, we dele­te the data wit­hout delay, unless we still need it until the expi­ra­ti­on of the sta­tu­to­ry limi­ta­ti­on peri­od for evi­den­tia­ry pur­po­ses for civil law claims or due to sta­tu­to­ry reten­ti­on obli­ga­ti­ons.

For evi­den­tia­ry pur­po­ses, we must retain con­tract data for three years from the end of the year in which the busi­ness rela­ti­onship with you ends; any claims beco­me time-bar­red at the ear­liest at this time accor­ding to the sta­tu­to­ry regu­lar limi­ta­ti­on peri­od. Even after that, we must still store some of your data for accoun­ting reasons. We are obli­ga­ted to do so due to sta­tu­to­ry docu­men­ta­ti­on obli­ga­ti­ons, which may ari­se, for exam­p­le, from the Ger­man Com­mer­cial Code, the Ger­man Fis­cal Code, the Ger­man Ban­king Act, and the Ger­man Money Laun­de­ring Act; the reten­ti­on peri­ods spe­ci­fied the­re ran­ge from two to ten years. For the reten­ti­on of case files, the peri­od spe­ci­fied in Sec­tion 9 of Sec­tion 50 BRAO addi­tio­nal­ly appli­es.

14. Your Rights as a Data Sub­ject

You have the fol­lo­wing rights vis-à-vis us with regard to the per­so­nal data con­cer­ning you.

You have the right to access (Artic­le 15 GDPR) your per­so­nal data pro­ces­sed by us, in par­ti­cu­lar regar­ding pro­ces­sing pur­po­ses, data cate­go­ries, reci­pi­ents, plan­ned reten­ti­on peri­od, your other data sub­ject rights, the right to lodge a com­plaint, the ori­gin of the data, and the exis­tence of auto­ma­ted decis­i­on-making inclu­ding pro­fil­ing.

You have the right to rec­ti­fi­ca­ti­on (Artic­le 16 GDPR): You can request the imme­dia­te rec­ti­fi­ca­ti­on of inac­cu­ra­te or the com­ple­ti­on of your per­so­nal data stored by us.

You have the right to era­su­re (Artic­le 17 GDPR): You can request the era­su­re of your per­so­nal data stored by us, unless the pro­ces­sing is neces­sa­ry for exer­cis­ing the right to free­dom of expres­si­on and infor­ma­ti­on, for com­pli­ance with a legal obli­ga­ti­on, for reasons of public inte­rest, or for the estab­lish­ment, exer­cise, or defen­se of legal claims.

You have the right to rest­ric­tion of pro­ces­sing (Artic­le 18 GDPR) under the con­di­ti­ons spe­ci­fied the­r­ein, for exam­p­le, if you con­test the accu­ra­cy of the data, the pro­ces­sing is unlawful, or you have lodged an objec­tion pur­su­ant to Artic­le 21 GDPR.

You have the right to data por­ta­bi­li­ty (Artic­le 20 GDPR): You can recei­ve your per­so­nal data that you have pro­vi­ded in a struc­tu­red, com­mon­ly used, and machi­ne-rea­da­ble for­mat or request trans­mis­si­on to ano­ther con­trol­ler.

You have the right to with­draw con­sent given (Artic­le 7(3) GDPR): You can with­draw con­sent once given to us at any time. The lawful­ness of the pro­ces­sing car­ri­ed out until the with­dra­wal remains unaf­fec­ted.

You have the right to lodge a com­plaint with a super­vi­so­ry aut­ho­ri­ty (Artic­le 77 GDPR): Wit­hout pre­ju­di­ce to any other admi­nis­tra­ti­ve or judi­cial reme­dy, you have the right to lodge a com­plaint with a data pro­tec­tion super­vi­so­ry aut­ho­ri­ty regar­ding the pro­ces­sing of your per­so­nal data by us if you belie­ve that the pro­ces­sing vio­la­tes the GDPR. As a rule, you can cont­act the super­vi­so­ry aut­ho­ri­ty of your usu­al place of resi­dence or work­place or the place of the alle­ged inf­rin­ge­ment. The com­pe­tent aut­ho­ri­ty is gene­ral­ly the super­vi­so­ry aut­ho­ri­ty of the fede­ral sta­te in which the fir­m’s regis­tered office is loca­ted, for breutac the­r­e­fo­re the Bava­ri­an Sta­te Office for Data Pro­tec­tion Super­vi­si­on (BayL­DA), Pro­me­na­de 18, 91522 Ans­bach.

Right to Object (Artic­le 21 GDPR): You have the right, on grounds rela­ting to your par­ti­cu­lar situa­ti­on, to object at any time to the pro­ces­sing of per­so­nal data con­cer­ning you that is based on Artic­le 6(1)(e) or (f) GDPR. If you lodge an objec­tion, we will no lon­ger pro­cess your per­so­nal data unless we can demons­tra­te com­pel­ling legi­ti­ma­te grounds for the pro­ces­sing that over­ri­de your inte­rests, rights, and free­doms, or the pro­ces­sing ser­ves the estab­lish­ment, exer­cise, or defen­se of legal claims. If your per­so­nal data is pro­ces­sed for direct mar­ke­ting pur­po­ses, you have the right to object at any time to the pro­ces­sing for this pur­po­se; fol­lo­wing such an objec­tion, your data will no lon­ger be used for direct mar­ke­ting pur­po­ses. To exer­cise your right to object, an infor­mal noti­fi­ca­ti­on to the cont­act details spe­ci­fied in Sec­tion 1 is suf­fi­ci­ent.

15. No Auto­ma­ted Decis­i­on-Making

Auto­ma­ted decis­i­on-making in indi­vi­du­al cases, inclu­ding pro­fil­ing within the mea­ning of Artic­le 22 GDPR, does not take place. We do not use your per­so­nal data to make decis­i­ons that have legal effects on you or simi­lar­ly signi­fi­cant­ly affect you sole­ly on an auto­ma­ted basis.

16. SSL/TLS Encryp­ti­on

For secu­ri­ty reasons and to pro­tect the trans­mis­si­on of con­fi­den­ti­al con­tent, this web­site uses SSL/TLS encryp­ti­on. You can reco­gni­ze an encrypt­ed con­nec­tion by the fact that the brow­ser­’s address line chan­ges from http:// to https://.

17. Tech­ni­cal and Orga­niza­tio­nal Mea­su­res

To secu­re your data, we employ appro­pria­te mea­su­res in accordance with the sta­te of the art, in par­ti­cu­lar to rest­rict access to the data, to pro­tect against altera­ti­on and loss, and to main­tain con­fi­den­tia­li­ty.

18. Sta­tus and Updates to the Pri­va­cy Poli­cy

We reser­ve the right to adapt this Pri­va­cy Poli­cy so that it always com­pli­es with cur­rent legal requi­re­ments or to imple­ment chan­ges to our ser­vices. The new Pri­va­cy Poli­cy will then app­ly to your next visit. This Pri­va­cy Poli­cy is dated July 2026.