Data Security

Legally Responsible

Lawyer
Christian Krüger
Dorothea-Petersmann-Weg 12
48147 Münster
Phone: 0251/2806868
Email: kanzlei[at]ra-krueger.net

29.05.2025

Basic information regarding data processing and legal foundations

1.1. This data privacy statement explains to you the nature, scope and purpose of processing personal data within our online offer and the related websites, features and content (hereinafter commonly referred to as “online offer” or “website”). The data privacy statement applies regardless of domains, systems, platforms and devices used (e.g. desktop or mobile) on which the online offer is executed.

1.2. Regarding the concepts and terms used, such as “personal data” or its “processing”, we refer to the definitions in article 4 of the General Data Protection Regulation (GDPR).

1.3. The users’ personal data processed in the framework of this online offer comprises usage data (server logfiles of the provider) and content data (establishing contact via e-mail).

1.4. The term “user” comprises all categories of persons affected by data processing. They include our customers, interested parties and other visitors of our online offer. The terms used, such as “user”, are to be understood in a gender-neutral way.

1.5. We will process the users’ personal data strictly in compliance with relevant data protection provisions. This means that data of users will only be processed if a legal permission exists. Particularly, this applies to the following cases:

  • Data processing is required or statutory in order to render our contractual services (processing of e-mail enquiries) as well as online services.
  • The users’ consent exists.
  • Owing to our legitimate interests, i.e. interest in economic operation and security of our online offer in accordance with article 6, paragraph 1 lit. f. of the GDPR. (Server logfiles are stored by the provider.)

1.6. We would like to point to following legal foundations:

  • Legal foundation of consents in terms of article 6, paragraph 1 lit. a. and article 7 of the GDPR
  • Legal foundation for processing to fulfil our services and to perform contractual measures of article 6, paragraph 1 lit. b. of the GDPR
  • Legal foundation for processing to fulfil our legal obligations in terms of article 6, paragraph 1 lit. c. of the GDPR
  • Legal foundation for processing to protect our legitimate interests in terms of article 6, paragraph 1 lit. f. of the GDPR

2. Safety measures

2.1. We will take organisational, contractual and technical safety measures according to the state of the art. This is to ensure that provisions of the data protection acts are adhered to and to protect data which we have processed against accidental or intentional manipulation, loss, destruction or against access by unauthorized persons.

3. Transfer of data to third parties and third-party providers

3.1. Data will only be passed on to third parties in the framework of legal specifications. We will only pass on data of users to third parties if this, for instance, is necessary for contractual purposes on the basis of article 6, paragraph 1 lit. b) of the GDPR or on the basis of legitimate interests regarding an economical and effective operation of our business according to article 6, paragraph 1 lit. f. of the GDPR.

3.2. Should we deploy subcontractors (presently we only use a “web hoster”) to provide our services, we will take suitable legal precautions as well as respective technical and organisational measures in order to ensure protection of personal data in accordance with relevant legal provisions.

3.3. We will not use content, tools or other means of third parties.

4. Establishing contact

4.1. When a user contacts us (via e-mail), their data will be dealt with to process the contact request and its handling according to article 6, paragraph 1 lit. b) of the GDPR.

5. Collection of access data and logfiles

5.1. We, i.e. our “web hoster”, will collect data regarding any access to the server on which our online offer is available (so-called server logfiles) based on our legitimate interests according to article 6, paragraph 1 lit. f. of the GDPR. Access data comprise the name of the web page retrieved, any file, date and time of retrieval, data volume transferred, notification about successful retrieval, browser type and version, the user’s operating system, referrer URL (previously visited page), IP address and requesting provider.

5.2. Our provider will store server logfile information for security reasons (e.g. to clear up misuse or fraud activities). This specific information is subject to purpose limitation of article 5, paragraph 1 lit. b. of the GDPR. The server is located in Germany.

6. Cookies & range measurement

6.1. During a website visit, cookies will not be used and information about range measurement will not be collected.

7. Inclusion of third party’s services and contents

7.1. We will not use services of third parties within our online offer. Particularly, no information about your website visit will be tracked or passed on to third parties.

8. User rights

8.1. Users have the right to obtain free information upon request concerning personal data which we have stored about them.

8.2. In addition, users have the right to have inaccurate data corrected, to have processing and deletion of their personal data restricted, if applicable, to claim their rights to data portability and, in case unlawful data processing is assumed, to file a complaint to the responsible supervisory authority.

 

9. Deletion of data

9.1. Data of e-mail enquiries stored with us will be deleted as soon as it is no longer required for its purpose and if the deletion does not contradict any legal obligation to retain data.

10. Right of objection

Users may object future processing of their personal data at any time in accordance with legal specifications.

11. Changes of the data privacy statement

11.1. We reserve the right to modify the data privacy statement in order to adapt it to changed legal situations or if the respective service as well as data processing have changed. However, this only applies to declarations regarding data processing. If the users’ consent is required or if elements of the data privacy statement contain provisions of the contractual relationship with the users, changes will only be made with the users’ approval.

11.2. Users are requested to read up on the content of the data privacy statement on a regular basis.