Privacy Policy

You can generally use our website without providing any personal data. If the collection, processing or use of personal data becomes necessary and there is no legal or contractual obligation to do so, we will ask for your consent beforehand.

We process personal data in compliance with applicable data protection regulations. Despite all protective measures, however, absolute security cannot be guaranteed when data is transmitted via the Internet. You may therefore also provide us with your personal data via any of the other communication channels published on this website.

  1. Definitions
    Our Privacy Policy uses terms from the General Data Protection Regulation (GDPR), the definitions of which can primarily be found in Art. 4 GDPR. Accordingly:

“Personal data”
means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

“Processing”
means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

“Profiling”
means any form of automated processing of personal data consisting of the use of such data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

“Pseudonymisation”
means the processing of personal data in such a manner that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data cannot be attributed to an identified or identifiable natural person.

“Filing system”
means any structured collection of personal data which is accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis.

“Controller”
means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

“Processor”
means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

“Recipient”
means a natural or legal person, public authority, agency or other body to which personal data is disclosed, whether or not a third party. Public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not, however, be regarded as recipients. The processing of such data by those public authorities shall comply with the applicable data protection rules according to the purposes of the processing.

“Third party”
means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

“Consent”
of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they, through a statement or clear affirmative action, signify agreement to the processing of personal data relating to them.

“Personal data breach”
means a breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

“Genetic data”
means personal data relating to the inherited or acquired genetic characteristics of a natural person which provide unique information about that person's physiology or health and which result, in particular, from an analysis of a biological sample from the natural person in question.

“Biometric data”
means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person which allow or confirm the unique identification of that natural person, such as facial images or fingerprint data.

“Data concerning health”
means personal data relating to the physical or mental health of a natural person, including the provision of healthcare services, which reveal information about their health status.

“Main establishment”
means, in the case of a controller with establishments in more than one Member State, the place of its central administration in the Union, unless decisions on the purposes and means of processing personal data are taken in another establishment of the controller in the Union and that establishment has the power to have such decisions implemented. In that case, the establishment having taken such decisions shall be considered the main establishment.

“Enterprise”
means a natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity.

“Binding corporate rules”
means personal data protection policies which are adhered to by a controller or processor established in the territory of a Member State for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within the same group of undertakings or group of enterprises engaged in a joint economic activity.

“Supervisory authority”
means an independent public authority established by a Member State pursuant to Article 51 GDPR.

“Supervisory authority concerned”
means a supervisory authority concerned by the processing of personal data because the controller or processor is established in the territory of the Member State of that supervisory authority; data subjects residing in that Member State are substantially affected or likely to be substantially affected by the processing; or a complaint has been lodged with that supervisory authority.

“Cross-border processing”
means either the processing of personal data which takes place in the context of the activities of establishments in more than one Member State of a controller or processor in the Union where the controller or processor is established in more than one Member State, or processing which takes place in the context of the activities of a single establishment of a controller or processor in the Union but which substantially affects or is likely to substantially affect data subjects in more than one Member State.

“Relevant and reasoned objection”
means an objection as to whether there is an infringement of the GDPR or whether envisaged action in relation to the controller or processor complies with the GDPR, which clearly demonstrates the significance of the risks posed by the draft decision regarding the fundamental rights and freedoms of data subjects and, where applicable, the free flow of personal data within the Union.

“Information society service”
means a service as defined in Article 1(1)(b) of Directive (EU) 2015/1535 of the European Parliament and of the Council.

  1. Cookies
    This website uses cookies. Cookies are small text files automatically created by your browser and stored on your device, such as a laptop, tablet or smartphone, when you visit our website. Cookies do not cause any damage to your device and do not contain viruses, Trojans or other malware. Cookies store information relating to the specific device used.
    This does not mean that we immediately become aware of your identity. We use cookies, on the one hand, to make our website more convenient for you to use. We use session cookies, for example, to recognise that you have already visited individual pages of our website. These cookies are automatically deleted after you leave our website.
    We also use temporary cookies to optimise user-friendliness. These are stored on your device for a defined period. When you visit our website again to use our services, it is automatically recognised that you have previously visited us and which entries and settings you made, so that you do not have to enter them again.
    We also use cookies to statistically record the use of our website and evaluate it for the purpose of optimising our services. These cookies allow us to recognise automatically that you have previously visited our website when you return. They are automatically deleted after a defined period.
    The data processed by cookies is necessary for the purposes stated above to safeguard our legitimate interests and those of third parties pursuant to Art. 6(1)(f) GDPR.
    Most browsers automatically accept cookies. However, you can configure your browser so that no cookies are stored on your computer or so that a notification always appears before a new cookie is created. Completely disabling cookies may mean that you are unable to use all functions of our website.

  2. Collection and Storage of Data by the Provider
    The provider of this website automatically collects and stores information in server log files that your browser automatically transmits. This information is only partially available in aggregated and anonymised form. It is not personally identifiable and is generally not intended to be.

The server log files, which are kept separate from personal data, may in particular include:
browser type/version,
operating system,
the referring page from which you accessed this website,
the subpages of this website that you visited,
the date and time of your visit,
the IP address assigned to you at the time of your visit,
your Internet service provider,
similar data and information used to prevent unlawful or abusive use.

The aforementioned data is used to:
ensure the correct and unrestricted display and usability of our website,
enable optimisation for advertising purposes,
support effective law enforcement by providing required information to judicial authorities.
The data is also evaluated for statistical purposes and to ensure an appropriate level of data protection.

  1. Personal Data
    In some cases, we are required to collect personal data due to statutory provisions, for example under the German Money Laundering Act. Collection may also be based on contractual arrangements, such as the establishment of a client relationship. Without such personal data, it may not be possible to enter into a contract.
    Your personal data will only be stored for as long as necessary to achieve the relevant purpose or as expressly required by other legislation. The applicable statutory, contractual or consent-based retention periods determine when personal data is deleted.

  2. Integration of Other Online Services and Transfer of Data to Third Countries
    Data may be transferred to so-called third countries, in particular countries outside the European Union (EU) and European Economic Area (EEA), when third-party services are used. This primarily concerns services from Google's portfolio.
    According to the current German-language Privacy Policy, such data transfers take place where an EU-equivalent level of data protection is ensured through safeguards such as the Privacy Shield.
    Our legitimate interests include the analysis, optimisation and commercial operation of our online services within the meaning of Art. 6(1)(f) GDPR.

Google
The German-language Privacy Policy states that Google participates in the Privacy Shield. The various Google services we use place computer code, typically cookies, on your device. The data obtained in this way is not combined in an unauthorised manner.
You can prevent cookies from being stored by installing Google's relevant opt-out solution. Please also refer to Google's Privacy Policy for detailed information on how Google handles your data.

Google Analytics
This service generates additional information from personal data collected through cookies. Google combines this information into pseudonymised profiles and transfers it to servers in the United States.
Pseudonymisation is achieved by shortening the IP address, which usually takes place before transmission to the United States.
You can prevent Google from collecting the data generated by the cookie relating to your use of the website, including your IP address, and from processing this data by downloading and installing the browser plug-in provided by Google.

AdWords
We use AdWords to influence the search engine positioning of our website among our target audience. Google uses various technologies for AdWords that are continuously being developed, including remarketing, pixel tags and other technologies. These enable users' search and browsing behaviour to be tracked and analysed in order to display advertising that corresponds as closely as possible to their individual interests.
Google's ad personalisation settings can be used to control personalised advertising.

Other Services (YouTube) and Content
We also use videos and, where applicable, fonts from YouTube/Google. In order to display these in the user's browser, personal data such as the user's IP address is transmitted.
The integration of these additional services and content may result in user-related data being stored. This data is primarily technical in nature and may include the browser and operating system used, referring websites, the time of the visit and other information regarding the use of our online services, as well as links to information from other sources.

Xing
Our online presence also extends to the Xing platform operated by XING AG, Dammtorstraße 29–32, 20354 Hamburg, Germany.
There you will find personal profile information, images, videos, buttons and options for connecting with other services. If you have a user profile on Xing, Xing may associate your visit to our page with your individual profile. Further information can be found in Xing's Privacy Policy.

MaTelSo
Based on our legitimate interests, particularly to ensure the quality of our online services, we use call-tracking technology provided by MaTelSo GmbH, Heilbronnerstr. 150, 70191 Stuttgart, Germany (“Matelso”).
The following telephone numbers listed on our website may be call-tracking numbers. In this case, the time and date of the call, whether the call was answered, its duration and the telephone numbers of both participants may be collected, stored and transmitted to Matelso and the called party for the purpose of measuring advertising effectiveness:

0221 925700-0

0671 83900-0

030 2250272-30

Further information can be found in Matelso's Privacy Policy. To prevent the execution of Matelso JavaScript code altogether, you can disable JavaScript in your browser settings or install a JavaScript blocker.

Zoho Forms
We use Zoho Forms to collect client data via the Internet. Zoho Forms is described as a GDPR-compliant tool that meets high security standards to protect the privacy and security of your personal data.
All data collected via Zoho Forms is transmitted over an SSL-encrypted connection, helping to protect information including sensitive data such as names, addresses and bank details.
Zoho Forms also provides field-level encryption so that only authenticated users can access secured data. Changes to forms are recorded in an audit log to ensure transparency and traceability.
Your data is stored in secure data centres within the EU and processed in accordance with applicable data protection regulations.
Once the legal client file has been created, the data collected via Zoho is deleted without undue delay to ensure that no unnecessary data remains stored.

Provider:
Zoho Corporation B.V.
Hoogoorddreef 15
1101 BA Amsterdam
The Netherlands

  1. Right of Access and Right to Object
    You have the right to obtain confirmation as to whether personal data concerning you is being processed. You may contact the controller responsible for data protection or one of its employees for this purpose.
    You may obtain information about the personal data stored about you and a copy of this information at any time and free of charge. You are also entitled to information regarding:
    the purposes of processing,
    the categories of personal data being processed,
    the recipients or categories of recipients to whom personal data has been or will be disclosed, in particular recipients in third countries or international organisations,
    where possible, the envisaged period for which the personal data will be stored or, where this is not possible, the criteria used to determine that period,
    the existence of a right to request rectification or erasure of personal data or restriction of processing by the controller, or a right to object to such processing,
    the existence of a right to lodge a complaint with a supervisory authority,
    where personal data is not collected from the data subject, any available information as to its source,
    the existence of automated decision-making, including profiling pursuant to Article 22(1) and (4) GDPR, and meaningful information about the logic involved as well as the significance and envisaged consequences of such processing for the data subject.
    You also have the right to obtain information as to whether personal data has been transferred to a third country or international organisation. Where this is the case, you have the right to be informed of the appropriate safeguards relating to the transfer.
    You have the right to request the immediate rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you also have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
    You may request the immediate erasure of personal data concerning you where one of the following grounds applies and insofar as processing is not necessary:
    The personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed.
    The data subject withdraws the consent on which the processing is based pursuant to Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR and there is no other legal ground for the processing.
    The data subject objects to the processing pursuant to Art. 21(1) GDPR and there are no overriding legitimate grounds for the processing, or the data subject objects pursuant to Art. 21(2) GDPR.
    The personal data has been unlawfully processed.
    The personal data must be erased to comply with a legal obligation under Union or Member State law to which the controller is subject.
    The personal data has been collected in relation to the offer of information society services pursuant to Art. 8(1) GDPR.
    Where personal data has been made public and the controller is obliged pursuant to Art. 17(1) GDPR to erase it, reasonable measures, including technical measures, will be taken, taking account of available technology and implementation costs, to inform other controllers processing the published personal data that the data subject has requested the erasure of links to, copies of or replications of that personal data, insofar as processing is not required.
    You may request restriction of processing where one of the following conditions applies:
    The accuracy of the personal data is contested by the data subject for a period enabling the controller to verify its accuracy.
    The processing is unlawful and the data subject opposes the erasure of the personal data and requests restriction of its use instead.
    The controller no longer requires the personal data for the purposes of processing, but the data subject requires it for the establishment, exercise or defence of legal claims.
    The data subject has objected to processing pursuant to Art. 21(1) GDPR and it has not yet been determined whether the legitimate grounds of the controller override those of the data subject.
    You also have the right to receive personal data concerning you in a structured, commonly used and machine-readable format.
    Where processing is based on consent pursuant to Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR or on a contract pursuant to Art. 6(1)(b) GDPR and is carried out by automated means, you have the right to transmit such data to another controller without hindrance from the controller to which the personal data was provided.
    Where technically feasible and provided that the rights and freedoms of others are not adversely affected, you also have the right to have personal data transmitted directly from one controller to another pursuant to Art. 20(1) GDPR.
    You may object at any time to the processing of your personal data for direct marketing purposes.
    Where grounds relating to your particular situation exist, you may object to the processing of your personal data for scientific or historical research purposes or statistical purposes pursuant to Art. 89(1) GDPR, unless such processing is necessary for the performance of a task carried out for reasons of public interest.

  2. Consent and Withdrawal of Consent
    Art. 6(1)(a) GDPR serves as the legal basis for processing operations for which we obtain consent for a specific processing purpose.
    You may freely withdraw your consent to the processing of personal data at any time.
    Where processing is necessary for the performance of a contract, the legal basis is Art. 6(1)(b) GDPR.
    Processing of personal data necessary to comply with legal obligations is based on Art. 6(1)(c) GDPR.
    Where processing is necessary to protect vital interests, for example in the event of an accident requiring emergency medical treatment, processing of personal data is based on Art. 6(1)(d) GDPR.
    Personal data may also be processed pursuant to Art. 6(1)(f) GDPR where processing is necessary for the purposes of a legitimate interest.
    You may object to the processing of your personal data based on Art. 6(1)(e) or (f) GDPR.
    In the event of an objection, the controller will no longer process your personal data unless it can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or unless processing is necessary for the establishment, exercise or defence of legal claims.

  3. Amendments to These Provisions
    These provisions are updated from time to time in order to protect your personal data. We will draw your attention to significant changes by means of clearly visible notices.

Last updated: December 2020