Privacy Policy breutac — Tax Advisory and Controversy.
We take data protection very seriously.
1. Controller
breutac Breuninger Rechtsanwaltsgesellschaft mbH & Co. KG Register Court:
Munich Local Court, Registration Number: HRA 122915
Widenmayerstr. 6
80538 Munich
Tel. +49 89 21 23 161–0
Fax +49 89 43 78 08 26.
Authorized General Partner (Komplementärin): Breuninger Rechtsanwalts GmbH Register Court: Munich Local Court, Registration Number: HRB 312803 Managing Director: Dr. Gottfried E. Breuninger
If you have any questions about data protection or wish to exercise your rights, you can reach us at contact@breutac.com.
2. Legal Basis
We process the data generated by visiting our website or using the contact options offered in accordance with the provisions of the European General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and—insofar as it concerns storing information on your device or accessing information already stored—the Telecommunications-Digital Services-Data Protection Act (TDDDG). Depending on the matter for which you contact us via the website, different legal bases may apply. The specific legal basis depends on the context and purpose for which we receive your data. It generally arises from the following possibilities:
Article 6(1)(a) GDPR serves as our legal basis for processing operations for which we obtain consent for a specific processing purpose. Consent given may be withdrawn at any time.
If the processing of personal data is necessary for the performance of a contract to which the data subject is a party, the processing is based on Article 6(1)(b) GDPR. The same applies to processing operations necessary for the implementation of pre-contractual measures, such as inquiries about our services.
If we are subject to a legal obligation that requires the processing of personal data, such as for the fulfillment of tax obligations, the processing is based on Article 6(1)© GDPR.
Finally, processing operations may be based on Article 6(1)(f) GDPR. Processing operations not covered by any of the aforementioned legal bases are based on this legal basis if the processing is necessary to protect a legitimate interest of our company or a third party, provided that the interests, fundamental rights, and freedoms of the data subject do not override those interests.
3. Data Processing on Our Website
3.1 Collection of General Information When Visiting Our Website
When you access our website—that is, if you do not transmit any other information to us—we collect only the personal data that your browser automatically transmits to our server. This includes the IP address, date and time of the request, the content of the request, access status or HTTP status code, the amount of data transmitted in each case, the website from which the request originates, the browser used, the operating system and its interface, and the language and version of the browser software.
This data is not merged with other data sources. The collection is technically necessary to display our website to you without errors and in an optimized manner, and to ensure its stability and security. The processing is based on Article 6(1)(f) GDPR.
3.2 Google Maps
On the contact page, we use the Google Maps mapping service. This allows us to display interactive maps directly on the website and enable convenient use of the map function. For persons from the European Economic Area and Switzerland, the mapping service is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and for all other persons by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). In order for the map material to be embedded and displayed in your web browser, your web browser must establish a connection to a Google server, which may also be located in the USA, when you access the contact page. Google thereby receives the information that the contact page of our website was accessed from the IP address of your device. For data transfers to third countries, particularly to the USA, please refer to the information in Section 13.
The legal basis for storing information on your device or accessing it is your consent pursuant to Section 25(1) TDDDG; the legal basis for the subsequent processing of your personal data is your consent pursuant to Article 6(1)(a) GDPR. Without your consent, no connection to Google’s servers is established. You can withdraw your consent at any time with effect for the future or adjust your selection via the cookie settings (see Section 5).
If you access the Google mapping service while logged into your Google profile, Google may link this event to your Google profile. If you do not wish this association to occur, you must log out of Google before accessing our contact page. Google stores your data and uses it for advertising, market research, and personalized display of Google Maps. For more information, please refer to Google’s Privacy Policy and the Additional Terms of Use for Google Maps.
3.3 Use of Social Media Plugins
We use a social media plugin from LinkedIn and employ the so-called two-click solution: When you visit our site, no personal data is initially transmitted to the plugin provider. Only when you click on and thereby activate the marked field does the plugin provider receive the information that you have accessed the corresponding page; in addition, the data mentioned in Section 4.1 is transmitted and stored by the provider (in the case of US providers, in the USA).
The legal basis for the processing triggered by your active activation is your consent pursuant to Article 6(1)(a) GDPR and—insofar as information is stored on or accessed from your device—Section 25(1) TDDDG. We understand the active operation of the button as the granting of consent. With regard to the collection and transmission of your data to LinkedIn triggered via the button, there is joint controllership with LinkedIn; for further processing by LinkedIn, LinkedIn is solely responsible. For data transfers to third countries, please refer to the information in Section 13.
We have no influence over or knowledge of the data collected, the scope of data collection, the processing purposes, the retention periods, and the deletion beyond the aforementioned process. The plugin provider stores the data as user profiles and uses them for advertising, market research, and the needs-based design of its website. You have a right to object in this regard, which you can assert against the plugin provider.
The data transfer takes place regardless of whether you have an account with the plugin provider and are logged in there. If you are logged in, the data collected from us is directly associated with your existing account there. For more information, please refer to LinkedIn’s Privacy Policy.
4. Cookies
In addition to the data mentioned above, cookies are stored on your device when you use our website. Cookies are small text files that are stored in association with the browser you are using and through which certain information flows to the entity that sets the cookie.
Technically necessary cookies serve to make our website more user-friendly and are required for operation. The legal basis for storage or access is Section 25(2) No. 2 TDDDG; the legal basis for the associated processing of personal data is Article 6(1)(f) GDPR. Non-necessary cookies (e.g., for analysis or marketing purposes) are only set with your consent pursuant to Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR. When you first visit our website, you will be asked for consent via a cookie banner. You can withdraw your consent at any time with effect for the future or adjust your selection by accessing the cookie settings again.
This website uses transient and persistent cookies. Transient cookies, particularly session cookies, are automatically deleted when you log out or close the browser. Persistent cookies are automatically deleted after a period that varies depending on the cookie; you can delete them at any time via your browser’s security settings.
You can configure your browser to reject the acceptance of cookies; in that case, you may not be able to use all the features of this website. In addition, we use HTML5 storage objects, whose storage or reading is also only carried out in accordance with Section 25 TDDDG and whose use you can prevent by using your browser’s private mode. We also recommend regularly deleting cookies and browser history manually.
5. Contact
You have various options to contact us, in particular via the contact form, by telephone, or by email to the contact addresses mentioned above. If you contact us via one of these channels, we store the data you provide (e.g., name, contact details, inquiry) in order to process your request.
The legal basis is Article 6(1)(b) GDPR if the inquiry is directed toward entering into a mandate relationship (pre-contractual measure), and Article 6(1)(f) GDPR (legitimate interest in processing and responding to inquiries) in all other cases. The provision of your data is neither legally nor contractually required; however, without the information necessary for processing, we cannot answer your inquiry or cannot answer it completely. The data collected during contact will be deleted as soon as it is no longer necessary for achieving the purpose for which it was collected, unless statutory retention obligations prevent deletion.
6. Applications
You can apply to us by email or via LinkedIn for open positions. The purpose of data collection is the selection of applicants for the possible establishment of an employment relationship. To process your application, we collect the data you provide (typically: first and last name; email address; application documents such as certificates and CV; earliest possible start date; channel through which you became aware of the job posting; if applicable, telephone number, salary expectations, and Xing or LinkedIn profile). We point out that confidentiality cannot be guaranteed when applications are sent unencrypted by email. As a rule, you can also apply to our positions by post.
The legal basis for processing your application documents is Article 6(1)(b) and Article 88(1) GDPR in conjunction with Section 26(1) sentence 1 BDSG. Insofar as special categories of personal data (Article 9 GDPR) are processed in individual cases, this is done on the basis of Section 26(3) BDSG.
We store your personal data upon receipt of your application. If we accept your application and an employment relationship is established, we store your application data for as long as it is necessary for the employment relationship and to the extent that statutory provisions establish a retention obligation. If we reject your application, we store your application data for a maximum of six months after the rejection in order to be able to defend against any claims under the General Equal Treatment Act (AGG), unless you give us your consent to longer storage (e.g., for inclusion in our applicant pool). You can withdraw this consent at any time for the future by sending us an email to contact@breutac.com.
7. Social Networks
We maintain various online presences on social networks in order to communicate with interested parties and provide information about our services, in particular our LinkedIn company page of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (“LinkedIn”).
In the context of operating our online presences, we may access aggregated usage statistics provided by the operator of the social network. These may include, in particular, demographic information (e.g., age, gender, region), employment-related information (e.g., function, industry, professional experience), and interaction data (e.g., likes, shares, subscriptions) and provide us with insights into the interests of users, which we use to optimize our content. The collection and use of these statistics is subject to joint controllership with the operator; for LinkedIn, please refer to the Page Insights Joint Controller Addendum for details.
The legal basis for this data processing is Article 6(1)(b) GDPR, in order to stay in contact with our clients and inform them, as well as to carry out pre-contractual measures with interested parties, and Article 6(1)(f) GDPR based on our legitimate interest in effective information and communication with users.
We have no influence over the data processing carried out by the social network under its own responsibility. We point out that when you visit the online presence, data about your usage behavior may be transmitted to the operator, who may process it via cookies and other identifiers into usage profiles for its own market research and advertising purposes. For more information, please refer to LinkedIn’s Privacy Policy.
Insofar as we receive your personal data when operating the online presence, you have the rights set out in this Privacy Policy. You can most easily assert rights against the operator directly with them; we are happy to support you in this and forward your requests.
8. Online Meetings via “Teams”
We use “Teams” to conduct online meetings, telephone conferences, and/or webinars (hereinafter collectively “Meetings”). Teams is software from Microsoft Ireland Operations Limited, South County Business Park, Leopardstown, Dublin 18, Ireland (“Microsoft”), available as a desktop, web, and mobile app.
The legal basis for data processing to conduct meetings via Teams is our legitimate interest in the effective and simple conduct of online meetings, discussion rounds, and presentations pursuant to Article 6(1)(f) GDPR. Insofar as meetings are conducted within the framework of existing contractual relationships with you, the legal basis is Article 6(1)(b) GDPR. Insofar as we record meetings or log text data, this is done exclusively on the basis of your consent pursuant to Article 6(1)(a) GDPR; for employees, the permissibility is governed by Section 26 BDSG or any applicable works or service agreement. We are not responsible for further data processing on the Teams product website, from which the desktop software can be downloaded and the web app can be used.
During a meeting, the following data may be processed under certain circumstances: information about the participant (if applicable, display name, first name, last name, telephone, email address, encrypted password for authentication, profile picture); metadata (meeting topic and description, IP address, participant’s telephone number, type of device or software, time of last activity, number of chat and channel messages, number of meetings attended, duration of audio, video, and screen sharing); in the case of chat or channel message use, text data for display and, if applicable, logging; in the case of audio use, recordings from the microphone; in the case of video use, recordings from the video camera; in the case of recordings, audio, video, and screen shares for storage in the cloud or in Microsoft Stream; and in the case of telephone use, incoming and outgoing call numbers, country name, start and end time, and, if applicable, other connection data such as the IP address of the device.
Before a meeting, you register via our website or by email; we process your registration data and send you a confirmation with an invitation link or calendar appointment. To participate, at least your name and—in the case of telephone use—your telephone number are required, unless we enable anonymous participation (with a corresponding note in the invitation). You can deactivate the microphone and camera at any time. Only with your consent and after prior notification do we record meetings or log text data. Microsoft uses the metadata to enable us to analyze and report on the use of Teams.
Microsoft may become aware of the aforementioned data in the context of order processing. For more information on data protection, please refer to Microsoft’s Privacy Policy.
9. Processing of Client Data in Connection with Mandate Processing
breutac processes personal data to the extent necessary for the establishment of mandate relationships and the performance, processing, and termination of mandate relationships.
This may affect personal data of our clients, including their employees and executive body members (board members, managing directors), as well as third parties whose data is required for the establishment of the mandate relationship or the processing of the mandate. This includes, among others, direct and indirect shareholders of the client, business and contractual partners as well as advisors of the client, counterparties in a legal dispute and their legal advisors—in each case including the employees and executive body members of the aforementioned persons and entities—as well as employees of authorities and courts, witnesses, experts, and other parties to proceedings.
We process the following categories of personal data to the extent necessary for our work: contact information, in particular first and last name, title if applicable, address, telephone number, and email address; information on professional activity; information on income and assets; and other personal data that is necessary in the context of mandate processing for the determination and legal assessment of the facts and the appropriate legal advice and representation of the client. In individual cases, the data processed may also include special categories of personal data, such as data on criminal convictions and offenses within the meaning of Article 10 GDPR.
Insofar as we do not receive personal data directly from the data subjects (e.g., in the context of correspondence with contact persons at clients and/or opposing parties), the data may originate from clients, courts and authorities (e.g., in the context of file inspection and/or information), other third parties (e.g., parties to proceedings, witnesses), and publicly accessible sources (public registers, internet research).
We process data in connection with mandate processing for the purposes of fulfilling statutory requirements, identifying the client and the beneficial owners associated with them, reviewing possible conflicts of interest before accepting a mandate, determining and legally assessing the facts, advising and representing clients, corresponding with clients, authorities, courts, and other parties, invoicing, and settling and asserting other claims arising from the mandate relationship.
The legal bases are Article 6(1)(b) GDPR (performance of the mandate contract), Article 6(1)© GDPR (fulfillment of legal obligations, e.g., under the Federal Lawyers’ Act or the Money Laundering Act), and Article 6(1)(f) GDPR (legitimate interest in proper legal prosecution and defense). The legal basis for processing special categories of personal data is Article 9(2)(f) GDPR, insofar as this is necessary for the establishment, exercise, or defense of legal claims; where applicable, we additionally rely on Article 9(2)(a) GDPR (explicit consent) or—in the case of employee data—on Section 26(3) BDSG.
The provision of certain data may be legally or contractually required. In particular, for mandates subject to the Money Laundering Act (GwG), we are legally obligated to identify you or your beneficial owners; without the required information and evidence, we cannot establish or continue the mandate in this respect. Insofar as we are subject to the GwG, we collect the information and evidence required for this purpose (in particular, identity document data) and retain the collected data and documents in accordance with the GwG—generally for a period of five years; the legal basis in this respect is Article 6(1)© GDPR in conjunction with the provisions of the GwG.
All persons working in the firm are obligated to maintain confidentiality pursuant to Section 43a BRAO and Section 203 of the German Criminal Code (StGB).
Insofar as it is necessary for the processing of a mandate, we transmit personal data to clients, authorities and courts, as well as to the other third parties mentioned above. In individual cases, transmission also takes place to recipients in third countries without an adequacy decision; for the guarantees provided in this respect, please refer to Section 13.
Case files are retained for a period of six years after the termination of the mandate in accordance with Section 50 BRAO, unless statutory or mandate-specific reasons require longer retention. Otherwise, personal data is stored as long as its processing is necessary for the aforementioned purposes, unless statutory provisions require a longer storage period.
10. Processing of Business Partner Data
We process personal data in the context of cooperation with service providers, suppliers, and other business partners (hereinafter “Business Partners”) as well as their employees.
In doing so, we process personal data to the extent necessary for the establishment or performance of the contractual relationship with the Business Partner. This includes contact information, in particular first and last name, title if applicable, address, telephone number, and email address; information on professional activity; and bank details. Insofar as we do not receive personal data directly from the data subjects (e.g., in the context of correspondence with contact persons at the Business Partner), the data regularly originates from the Business Partner as the employer of the data subjects.
We process this data for the establishment, performance, and settlement of the contractual relationship with the Business Partner. The legal basis, insofar as personal data of the Business Partner is processed, is Article 6(1)(b) GDPR; otherwise, Article 6(1)(f) GDPR. Personal data is stored as long as its processing is necessary for the aforementioned purposes, unless statutory provisions prescribe a longer storage period.
11. Disclosure of Data
Disclosure of the data we collect generally only takes place if you have given your express consent pursuant to Article 6(1)(a) GDPR, the disclosure is necessary pursuant to Article 6(1)(f) GDPR to protect our interests or to establish, exercise, or defend legal claims and there is no reason to assume that you have an overriding legitimate interest in non-disclosure, we are legally obligated to disclose pursuant to Article 6(1)© GDPR, or this is legally permissible and necessary pursuant to Article 6(1)(b) GDPR for the performance of contractual relationships with you or for the implementation of pre-contractual measures carried out at your request.
Part of the data processing may be carried out by our service providers. In addition to the service providers mentioned in this Privacy Policy, these may include, in particular, data centers that host our website and databases, IT service providers that maintain our systems, and consulting firms. If we disclose data to our service providers, they may only use the data to fulfill their tasks. The service providers have been carefully selected and commissioned by us; they are contractually bound by our instructions, have appropriate technical and organizational measures in place to protect the rights of data subjects, and are regularly monitored by us. In addition, disclosure may occur in connection with official inquiries, court orders, and legal proceedings if this is necessary for legal prosecution or enforcement.
12. Data Transfer to Third Countries
We may use services whose providers are partly located in so-called third countries (such as the USA) or transmit personal data there, i.e., in countries whose level of data protection does not correspond to that of the European Union.
If an adequacy decision by the European Commission (Article 45 GDPR) exists for the respective country, we base the data transfer on it. In the case of the USA, this only applies insofar as the US recipient has certified for the EU-US Data Privacy Framework.
Insofar as no adequacy decision has been issued for the corresponding country, we have taken appropriate precautions to ensure an adequate level of data protection for any data transfers. These include, among others, the European Union’s Standard Contractual Clauses or binding corporate rules (Article 46 GDPR). Where this is not possible, we base the data transfer on the derogations of Article 49 GDPR, in particular your express consent or the necessity of the transfer for the performance of a contract or for the implementation of pre-contractual measures. If a third-country transfer is planned and no adequacy decision or appropriate safeguards exist, there is a risk that authorities in the respective third country (e.g., intelligence services) may gain access to the transmitted data in order to collect and analyze it, and that the enforceability of your data subject rights cannot be guaranteed. In the event that your consent is obtained via the consent banner, you will also be informed of this.
13. Retention Period
As a general rule, we store personal data only for as long as is necessary to fulfill the purposes for which we collected the data. After that, we delete the data without delay, unless we still need it until the expiration of the statutory limitation period for evidentiary purposes for civil law claims or due to statutory retention obligations.
For evidentiary purposes, we must retain contract data for three years from the end of the year in which the business relationship with you ends; any claims become time-barred at the earliest at this time according to the statutory regular limitation period. Even after that, we must still store some of your data for accounting reasons. We are obligated to do so due to statutory documentation obligations, which may arise, for example, from the German Commercial Code, the German Fiscal Code, the German Banking Act, and the German Money Laundering Act; the retention periods specified there range from two to ten years. For the retention of case files, the period specified in Section 9 of Section 50 BRAO additionally applies.
14. Your Rights as a Data Subject
You have the following rights vis-à-vis us with regard to the personal data concerning you.
You have the right to access (Article 15 GDPR) your personal data processed by us, in particular regarding processing purposes, data categories, recipients, planned retention period, your other data subject rights, the right to lodge a complaint, the origin of the data, and the existence of automated decision-making including profiling.
You have the right to rectification (Article 16 GDPR): You can request the immediate rectification of inaccurate or the completion of your personal data stored by us.
You have the right to erasure (Article 17 GDPR): You can request the erasure of your personal data stored by us, unless the processing is necessary for exercising the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise, or defense of legal claims.
You have the right to restriction of processing (Article 18 GDPR) under the conditions specified therein, for example, if you contest the accuracy of the data, the processing is unlawful, or you have lodged an objection pursuant to Article 21 GDPR.
You have the right to data portability (Article 20 GDPR): You can receive your personal data that you have provided in a structured, commonly used, and machine-readable format or request transmission to another controller.
You have the right to withdraw consent given (Article 7(3) GDPR): You can withdraw consent once given to us at any time. The lawfulness of the processing carried out until the withdrawal remains unaffected.
You have the right to lodge a complaint with a supervisory authority (Article 77 GDPR): Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data by us if you believe that the processing violates the GDPR. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or the place of the alleged infringement. The competent authority is generally the supervisory authority of the federal state in which the firm’s registered office is located, for breutac therefore the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach.
Right to Object (Article 21 GDPR): You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you that is based on Article 6(1)(e) or (f) GDPR. If you lodge an objection, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims. If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing for this purpose; following such an objection, your data will no longer be used for direct marketing purposes. To exercise your right to object, an informal notification to the contact details specified in Section 1 is sufficient.
15. No Automated Decision-Making
Automated decision-making in individual cases, including profiling within the meaning of Article 22 GDPR, does not take place. We do not use your personal data to make decisions that have legal effects on you or similarly significantly affect you solely on an automated basis.
16. SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can recognize an encrypted connection by the fact that the browser’s address line changes from http:// to https://.
17. Technical and Organizational Measures
To secure your data, we employ appropriate measures in accordance with the state of the art, in particular to restrict access to the data, to protect against alteration and loss, and to maintain confidentiality.
18. Status and Updates to the Privacy Policy
We reserve the right to adapt this Privacy Policy so that it always complies with current legal requirements or to implement changes to our services. The new Privacy Policy will then apply to your next visit. This Privacy Policy is dated July 2026.
