Privacy policy

Information on the processing of personal data

Privacy policy

In case of doubt, the German version of this privacy policy prevails.

cogito.legal Rechtsanwälte Rheingans Römisch Wiehl PartGmbB (hereinafter “cogito.legal") strictly complies with all relevant data protection regulations, in particular the European General Data Protection Regulation (GDPR).

This privacy policy covers the use of the digital services of cogito.legal on all internet-enabled devices. The digital services may contain links to third-party websites to which this privacy policy does not apply.

1. Controller

The controller responsible for the processing of your personal data is cogito.legal Rechtsanwälte Rheingans Römisch Wiehl PartGmbB, Poststraße 14/16, 20354 Hamburg, Germany, telephone: +49 40 232 053 000, info@cogito.legal.

If you have any questions about data protection, please write to us at the above postal address, marked “Datenschutz", or at datenschutz@cogito.legal.

2. Purposes and legal bases of data processing

2.1 Data processing for the performance of contractual services

We process your data in order to handle the contractual relationship between you and us and to be able to make you suitable contractual offers. Data is collected in particular for the conclusion of a contract. We only collect, on a mandatory basis, the personal data that is strictly necessary for handling the contractual relationship. Data that is not strictly necessary but of interest to us is collected on an optional basis only. In that case you decide voluntarily whether and which data you wish to provide. For your engagement we require your correct name, address and payment details. We ask for your email address and possibly your telephone number so that we can confirm the engagement and communicate with you in the event of problems concerning the service you have commissioned.

The legal basis for this processing is Art. 6(1)(b) GDPR, which permits the processing of data for the performance of a contract or pre-contractual measures.

Data that comes to our knowledge in the course of a mandate is additionally subject to the duty of professional secrecy under sec. 43a(2) of the German Federal Lawyers' Act (BRAO).

2.2 Data processing for communication purposes

In addition to contract data, we process communication data (name, address, telephone number, email address) in order to handle enquiries and/or contact the persons concerned. Personal data provided to us by email or via another communication channel we have opened is processed only for correspondence with the person concerned or only for the purpose for which the data was provided to us.

One such communication channel is the “Arrange an initial consultation" form on this website. Name, company and email address are mandatory there; preferred date and your enquiry are optional. To prevent the form from being abused by automated means, we check every submission on our own server; no third-party captcha service is embedded. To limit the number of enquiries per connection, your IP address is truncated, hashed with a key that changes daily and held in working memory for no longer than one hour; it is not stored for this purpose. We also check whether a mail server is registered for the domain of your email address; only the part after the @ sign is queried via the public domain name system, not your full address.

This data is processed on the basis of Art. 6(1)(b) GDPR where the enquiry relates to the performance of a contract or is necessary for pre-contractual measures. In all other cases the processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Art. 6(1)(f) GDPR) or on consent (Art. 6(1)(a) GDPR) where such consent has been obtained.

2.3 Data processing in connection with our LinkedIn company page

We operate a company page on the social network linkedin.com of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (“LinkedIn") and receive so-called Page Analytics from LinkedIn. For the operation of this LinkedIn company page we are jointly responsible with LinkedIn within the meaning of Art. 26 GDPR.

The nature and scope of the information processed and provided by LinkedIn, the associated purposes of the processing by LinkedIn, its lawfulness and information on exercising data subject rights can be found in LinkedIn's privacy policy at www.linkedin.com/legal/privacy-policy and in the joint controller agreement at legal.linkedin.com/pages-joint-controller-addendum. Page Analytics are aggregated data that give us insight into how our pages are interacted with. The generation and provision of these Page Analytics takes place within LinkedIn's area of responsibility; we have no influence over it. LinkedIn assumes all obligations under the GDPR with regard to the processing of Insights data (including Articles 12 and 13 GDPR, Articles 15 to 22 GDPR and Articles 32 to 34 GDPR).

The purpose of our processing of the data provided by LinkedIn is the statistical analysis of the use of our company page. This allows us, for example, to identify preferred visiting and posting times and to use them to optimise our posts and our company page. In addition, we process personal data made publicly available on LinkedIn (e.g. real names in user profiles) and data directly connected with activities on our company page (e.g. contributions, posts, likes, mentions), also for the purpose of communication.

The legal basis for the above processing is Art. 6(1) sentence 1 (a) GDPR. Where consent has been given to LinkedIn, it can be withdrawn at any time vis-à-vis LinkedIn with effect for the future. Where consent has been given to us, it can be withdrawn at any time vis-à-vis us with effect for the future. Otherwise the legal basis for our processing is Art. 6(1) sentence 1 (f) GDPR, which permits the processing of data to safeguard the legitimate interests of the controller unless the interests or fundamental rights and freedoms of the data subject prevail. Our interest lies in providing content and communicating with LinkedIn users and in improving the reach and effectiveness of our posts.

The rights to access, rectification, erasure, restriction of processing and data portability of stored Insights data can be asserted against LinkedIn, as LinkedIn has assumed the corresponding obligations:

LinkedIn Ireland Unlimited Company
Wilton Place
Dublin 2
Ireland
Privacy policy: www.linkedin.com/legal/privacy-policy

2.4 Cookies

No cookies are set on this website and no cookie consent is obtained. For the digital services of cogito.legal, the following otherwise applies:

We may use so-called cookies to provide website-specific services. Cookies are small text files that are stored on a visitor's computer and contain data about the respective user in order to give them access to various functions.

Websites may use both session cookies and persistent cookies. A session cookie is stored temporarily on the computer used while navigating through the website. A session cookie is deleted as soon as the internet browser is closed or as soon as the session has expired after a certain time. A persistent cookie remains on the computer until it is deleted.

For some of our services we may work with third parties, so when you visit such a website, cookies from partner companies may also be stored (third-party cookies). Where applicable, we inform you in advance about the use of such cookies and the scope of the data stored or retrieved. Additional information on the cookies used is available, where applicable, via the cookie tool we use and the explanations provided there.

We use necessary cookies that are required to enable the provision of the services we owe or to ensure the functionality of our services. The legal basis for setting these cookies is Section 25(2) no. 2 of the German TDDDG. Any processing of personal data in this context is then carried out on the basis of Art. 6(1) sentence 1 (b) GDPR, which permits the processing of data for the performance of a contract or pre-contractual measures, or under Art. 6(1) sentence 1 (f) GDPR, which permits data processing to safeguard the legitimate interests of the controller unless the interests or fundamental rights and freedoms of the data subject override the controller's interest in the processing. Our interest then lies in ensuring the provision of the functions of our services.

For the use of other, non-essential cookies we obtain consent where applicable. Such cookies are then set on the basis of consent pursuant to Section 25(1) TDDDG; any processing of personal data in this context is based on Art. 6(1) sentence 1 (a) GDPR. Data subjects can withdraw their consent at any time — including via the cookie tool we may have integrated. The lawfulness of processing already carried out on the basis of consent remains unaffected by the withdrawal.

2.5 Log files

Each time our websites are accessed, usage data is transmitted by the respective internet browser and stored in log files, the so-called server log files. The records stored contain the following data: date and time of access, name of the page accessed, truncated IP address of the website visitor, referrer URL (the URL from which you reached the web pages), the amount of data transferred, and product and version information of the browser used. The truncated IP addresses are deleted or anonymised after seven days. This data cannot be attributed to specific persons. This data is not merged with other data sources.

The legal basis for this processing is Art. 6(1)(f) GDPR, which permits the processing of data to safeguard the legitimate interests of the controller unless the interests or fundamental rights and freedoms of the data subject prevail.

2.6 Data processing to fulfil legal obligations

In addition, we may process your data to fulfil legal obligations (e.g. professional and regulatory requirements, retention and documentation obligations under commercial and tax law).

The legal basis for this processing is Art. 6(1)(c) GDPR, which permits processing for compliance with a legal obligation.

3. Data security

Your personal data is transmitted to us securely using encryption. We use the SSL (Secure Socket Layer) coding system. Furthermore, we protect our websites and other IT systems through technical and organisational measures against loss, destruction, access, modification or distribution of your data by unauthorised persons.

If you would like to send us encrypted emails, we will be happy to provide you with our public key. You will need PGP encryption software (e.g. PGP or GnuPG). If you would also like to receive encrypted emails from us, please send us your public key at the same time.

4. Recipients of personal data

Your personal data is only passed on or otherwise transmitted to third parties if this is necessary for the purpose of contract performance or billing, or if you have given prior consent, or if there is a legal basis for the transfer. Service providers supporting us in the provision of our services are providers of server hosting, email operation and IT support and, where applicable, other IT and SaaS service providers; agreements on processing under Art. 28 GDPR are in place with them.

In the course of a mandate, data is also transmitted to courts, authorities, the opposing party and their representatives in so far as this is necessary to carry out the mandate.

5. Duration of data storage

As a matter of principle, we delete your data as soon as it is no longer required for the purposes stated above, unless temporary retention continues to be necessary. We store your data on the basis of statutory documentation and retention obligations arising, among other things, from the German Commercial Code and the Fiscal Code. Under those provisions the retention periods amount to up to ten full years. For the lawyer's file, the six-year period under sec. 50(1) BRAO additionally applies, running from the end of the calendar year in which the mandate ended. We also retain your data for the period during which claims can be asserted against our firm (statutory limitation period of three or up to thirty years).

6. Data subject rights

Within the framework of the applicable statutory provisions, data subjects have the right at any time to obtain free information about their personal data stored by us, its origin and recipients and the purpose of the data processing, and, where applicable, a right to rectification or erasure of that data.

For this and for further questions on the subject of personal data you can contact us at any time using the contact details given in section 1.

Data subjects may further have a right to restriction of the processing of their data and a right to receive the data they have provided in a structured, commonly used and machine-readable format.

If you have given us consent to process personal data for specific purposes, you can withdraw your consent at any time with effect for the future. If we process your data to safeguard legitimate interests, you can object to this processing on grounds relating to your particular situation. If we cannot demonstrate compelling legitimate grounds for the further processing which override your interests, rights and freedoms, or if we process the data concerned for the purposes of direct marketing, we will no longer process your data.

In addition, you have the option of contacting a data protection supervisory authority (right to lodge a complaint). The authority competent for us is Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany, datenschutz-hamburg.de.