Privacy Policy
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation; “GDPR”), the controller must inform data subjects about the processing of personal data. With this privacy policy we inform you about the personal data processed by us.
Definitions
For a better understanding of this privacy policy, you will find below a short explanation of the terms used.
Personal data („data“) means any data containing information on the personal or material circumstances of natural persons, for example name, address, e-mail address, telephone number, date of birth, age, gender, social security number, video recordings, photographs, etc. Data of legal persons are not subject to the provisions of the GDPR.
Processing means any operation or set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Recipient means a natural or legal person, public authority, agency or other body to which personal data are disclosed, whether a third party or not.
1. Controller
The controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter the “GDPR”) is – subject to the clarifications set out in section 1.1 – in each case that attorney at law who has been retained under the relevant engagement. You can reach us at our shared office address:
GHP | Kooperation selbständiger Rechtsanwälte (cooperation of independent attorneys at law)
Herrengasse 1-3/2
1010 Vienna
Austria
Telephone: +43 664 426 06 10
E-mail: office@ghp-law.at
Web: www.ghp-law.at
Professional information:
Professional title: Rechtsanwalt (attorney at law), conferred in the Republic of Austria
Competent bar association and supervisory authority: Rechtsanwaltskammer Wien (Vienna Bar Association), Ertlgasse 2, 1010 Vienna
Professional rules: Rechtsanwaltsordnung (RAO – Austrian Attorneys’ Act), Disziplinarstatut für Rechtsanwälte und Rechtsanwaltsanwärter (DSt – Disciplinary Statute for Attorneys and Trainee Attorneys), Rechtsanwaltstarifgesetz (RATG – Attorneys’ Fees Act) and the Guidelines for the Practice of the Legal Profession (RL-BA 2015); available at www.rechtsanwaelte.at
Membership: Österreichischer Rechtsanwaltskammertag (ÖRAK – Austrian Bar Association)
For all matters relating to data protection you can reach us using the contact details set out above and at office@ghp-law.at.
1.1 Cooperation of independent attorneys at law – responsibility under data protection law
GHP is not a law firm entity within the meaning of Sections 21a et seq. RAO, but a cooperation of legally and economically independent attorneys at law, each of whom practises the profession on their own account, in their own name and on their own responsibility. Under data protection law, it follows that: For the personal data processed in the context of a specific engagement, the controller is exclusively that attorney at law to whom the power of attorney has been granted. The remaining cooperation partners access engagement data only within the scope of their respective instruction by way of substitution.
Where an engagement is conducted jointly by several cooperation partners, they are joint controllers within the meaning of Article 26 GDPR to that extent. The allocation of duties is set out in an arrangement, the essence of which will be made available to you on request. You may exercise your rights vis-à-vis each of the attorneys involved (Article 26(3) GDPR).
For the jointly used infrastructure (office premises, IT systems, telephone system, reception, general e-mail account) and for the joint website, including the processing operations described in section 14, the cooperation partners are joint controllers within the meaning of Article 26 GDPR. The contact point for data subjects is the Managing Partner of GHP Rechtsanwälte, Dr. Martin R. Geiger, LL.M., CSE, at office@ghp-law.at.
1.2 Data protection officer
We have not appointed a data protection officer, as the conditions of Article 37(1) GDPR and Section 5 DSG are not met. Our core activity consists neither in regular and systematic monitoring of data subjects on a large scale nor in the large-scale processing of special categories of personal data or of data relating to criminal convictions and offences. Pursuant to Recital 91 GDPR, the processing of personal data by an individual lawyer expressly does not constitute large-scale processing in this sense. Please address your data protection concerns to the contact details set out in section 1.
2. Principles of our data processing
We process personal data exclusively on the basis of the GDPR, the Austrian Data Protection Act (Datenschutzgesetz, DSG) – including the constitutionally guaranteed fundamental right to secrecy under Section 1 DSG – and the professional rules applicable to attorneys at law.
2.1 Attorneys’ duty of professional secrecy
All information that comes to our knowledge in the context of an engagement or in the course of a prospective engagement is subject to the attorneys’ duty of professional secrecy under Section 9(2) RAO. In terms of the level of protection it affords, this duty goes beyond the requirements of the GDPR: it is unlimited in time, continues to apply after the engagement has ended and applies vis-à-vis everyone, including public authorities and courts. It is safeguarded in particular by the right to refuse to give evidence under Section 157(1)(2) StPO (Austrian Code of Criminal Procedure) and Section 321(1)(4) ZPO (Austrian Code of Civil Procedure), and by the restrictions on the securing and seizure of evidence under Section 144 StPO. All employees and contractors of the firm, as well as the processors engaged by us, are bound to secrecy in writing.
2.2 Strict separation of engagement data and website data
Data that we process in the context of engagements are kept strictly separate from the data generated when you visit our website. Engagement data are not fed into analytics, tracking or marketing systems, are not used for profiling and are not transmitted to advertising networks. Nor are they sold, rented out or otherwise made available to third parties for advertising purposes. On our website, by contrast, we also use analytics and marketing cookies – subject to your consent; for details see section 14.
2.3 Data minimisation
We follow the principle of data minimisation (Article 5(1)(c) GDPR) and collect and store only such data as are necessary for the provision of the legal services you have instructed us to perform; are prescribed for us by mandatory statutory provisions – in particular by the professional and anti-money-laundering provisions of the RAO (client identification, “KYC”); or the processing of which you have expressly consented to.
3. Categories of data processed
Depending on the type of engagement or business relationship, we process the following categories of data:
a) Master and identification data
First name and surname, academic title, date and place of birth, nationality, residential address, marital status; in the case of companies, the company name, legal form, registered seat, company register number, VAT identification number, and details of the officers authorised to represent the company and of the beneficial owners.
b) Identity document and verification data
Type, number, issuing authority and period of validity of the official photo identification document and – to the extent provided for by the anti-money-laundering provisions of the RAO – a copy or electronic image of the identification document.
c) Contact data
Telephone and mobile number, e-mail address, address for service and, in individual cases, details of authorised representatives and agents for service.
d) Engagement and proceedings data
Subject matter and factual background of the engagement, pleadings, deeds, contracts, opinions, evidence, correspondence, file and case numbers of courts and authorities, appointments, time limits and diary entries, status and outcome of proceedings.
e) Data of third parties
Personal data of opposing parties and their representatives, of witnesses, experts, family members, employees, shareholders, corporate bodies and business partners of our clients, and of other persons involved in the matter, to the extent that the processing of such data is necessary for the performance of the engagement (see section 5.1 in this regard).
f) Data for compliance with anti-money-laundering due diligence obligations („KYC“)
Information on the purpose and intended nature of the business relationship, the source of the funds used and of the assets, occupation or business activity, information on status as a politically exposed person (PEP), as a family member of a PEP or as a person known to be a close associate of a PEP, results of screening against sanctions, embargo and PEP lists, information on capacity as trustor or trustee and on the beneficial ownership structure.
g) Escrow and payment data
Bank details, client account and escrow account data, escrow instructions and settlements, information on registration in the attorneys' escrow register (Treuhandbuch), payment flows.
h) Billing data
Time and service recording (time records, descriptions of services), fee notes and statements of costs, cash disbursements and court fees, payment and reminder data.
i) Communication data
E-mail traffic, correspondence, messenger services such as WhatsApp, LinkedIn and comparable platforms, fax, filings and service of documents via the Austrian Electronic Legal Communication system (Elektronischer Rechtsverkehr, ERV), notes of conversations and file notes.
j) Website and usage data
IP address, device and browser information, times of access, pages accessed, referrer URL and – subject to your consent – cookie identifiers, interaction and reach data (for details see section 14).
Special categories of personal data and data relating to criminal offences. As attorneys at law we regularly also process, in connection with engagements, special categories of personal data within the meaning of Article 9 GDPR – for example health data in damages, insurance, employment, social security or family law matters, data on trade union membership or on religious and philosophical beliefs – as well as data relating to criminal convictions and offences within the meaning of Article 10 GDPR. The legal basis is Article 9(2)(f) GDPR (establishment, exercise or defence of legal claims) and, where necessary, your explicit consent pursuant to Article 9(2)(a) GDPR; for data falling under Article 10 GDPR we rely on Section 4(3) DSG. Such data are processed exclusively in the context of conducting the engagement and never for advertising or analytics purposes.
4. Purposes and legal bases of the processing
Data may be processed only for a specific purpose and only where the processing can be based on a corresponding legal basis. Processing may be justified on the following grounds:
| Ground for processing | Legal basis |
|---|---|
| on the basis of your voluntary consent for a specific purpose | Article 6(1)(a) GDPR |
| for the performance of a contract to which you are a party, or in order to take steps prior to entering into a contract at your request | Article 6(1)(b) GDPR |
| for compliance with a legal obligation to which we are subject | Article 6(1)(c) GDPR |
| in order to protect your vital interests or those of another natural person | Article 6(1)(d) GDPR |
| for the performance of a task carried out in the public interest or in the exercise of official authority vested in us | Article 6(1)(e) GDPR |
| on the basis of a balancing of interests between our interest or the interest of a third party in the processing on the one hand and your interests or your fundamental rights and freedoms on the other hand | Article 6(1)(f) GDPR |
We process your data for the following purposes on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Initiation, conclusion and performance of the mandate agreement (Bevollmächtigungsvertrag), legal advice, representation before courts, public authorities and vis-à-vis third parties, including correspondence and management of time limits | Article 6(1)(b) GDPR (contract or pre-contractual measures) in conjunction with Sections 1002 et seq. ABGB (Austrian Civil Code) and Section 8 RAO |
| Processing of special categories of personal data and of data relating to criminal convictions and offences in the context of conducting the engagement | Article 9(2)(f) GDPR (legal claims) and, where necessary, Article 9(2)(a) GDPR (explicit consent); Article 10 GDPR in conjunction with Section 4(3) DSG |
| Processing of data of opposing parties, witnesses, informants and other third parties involved in the matter | Article 6(1)(f) GDPR (legitimate interest of our clients in the effective enforcement and defence of rights, and our interest in performing the engagement as a body serving the administration of justice) |
| Checking for conflicts of interest before accepting and during an engagement | Article 6(1)(c) GDPR in conjunction with Section 10(1) RAO and the relevant provisions of the RL-BA 2015 |
| Identification and verification of the client and the beneficial owner, determination of PEP status, clarification of the purpose and nature of the business relationship and of the source of funds, ongoing monitoring, sanctions list screening, suspicious activity reports to the Financial Intelligence Unit | Article 6(1)(c) GDPR in conjunction with the anti-money-laundering provisions of Sections 8a et seq. RAO, the directly applicable EU sanctions regulations and the Sanctions Act 2010 (SanktionenG 2010) |
| Handling of escrow arrangements, including notification and processing via the bar association's escrow facility | Article 6(1)(b) and (c) GDPR in conjunction with the statutes and guidelines of the escrow facility of the Vienna Bar Association |
| Filings, service of documents and searches via the Electronic Legal Communication system and in the electronically maintained registers (Companies Register, Land Register, Official Court Notices Database) | Article 6(1)(b) and (c) GDPR in conjunction with Sections 89a et seq. GOG (Courts Organisation Act) and the applicable register legislation |
| Time and service recording, fee billing, bookkeeping, financial reporting and tax obligations | Article 6(1)(b) and (c) GDPR in conjunction with Sections 190 and 212 UGB (Austrian Commercial Code), Section 132 BAO (Federal Fiscal Code), UStG 1994 (VAT Act) |
| Establishment, exercise and defence of legal claims, evidence of the proper conduct of the engagement, handling of claims under professional indemnity insurance, complaints management | Article 6(1)(f) GDPR (legitimate interest in securing evidence and defending against claims) in conjunction with Section 21a RAO |
| IT security, access and authorisation control, ensuring the proper operation of the firm | Article 6(1)(f) GDPR |
| Provision of our website, ensuring system security and use of technically necessary cookies | Article 6(1)(f) GDPR; Section 165(3) TKG 2021 (Telecommunications Act; exemption from the consent requirement) |
| Use of preference, statistics and marketing cookies, reach measurement, conversion tracking, retargeting and interest-based advertising | Article 6(1)(a) GDPR in conjunction with Section 165(3) TKG 2021 (consent, revocable at any time) |
| Sending of client information, newsletters and invitations to events | Article 6(1)(a) GDPR in conjunction with Section 174 TKG 2021 (consent, revocable at any time); within existing client relationships also Article 6(1)(f) GDPR, subject to Section 174(3) TKG 2021 |
Where we base processing on Article 6(1)(f) GDPR, we have carried out a balancing of interests; we will be happy to inform you in detail on request about the legitimate interests pursued, unless the attorneys’ duty of professional secrecy prevents us from doing so.
5. Source of the data
We collect personal data primarily directly from you or from our clients. In addition, we process data in particular (but not exclusively) from the following sources, to the extent necessary for the performance of the engagement or of our statutory obligations: publicly accessible registers and databases, in particular the Companies Register (Firmenbuch), the Land Register (Grundbuch), the Official Court Notices Database (Ediktsdatei) including the insolvency database, the Austrian Trade Information System (GISA), the Central Register of Associations and the Central Register of Wills, as well as generally from the internet; information from the Central Register of Residents to the extent permitted by law (Section 16 MeldeG – Registration Act); the Register of Beneficial Owners (WiEReG), which we are obliged to inspect in the context of our anti-money-laundering due diligence obligations; sanctions, embargo and PEP lists as well as specialised database providers; court and administrative files, in particular by way of file inspection, as well as service of documents via the Electronic Legal Communication system; opposing parties and their representatives, other parties to the proceedings, experts, insurers and credit institutions; third parties named by you (such as tax advisors, notaries, previous counsel, authorised representatives).
5.1 Data subjects who are not our clients
Where we process personal data of third parties – in particular of opposing parties, their family members, employees or witnesses – which we have not obtained from those persons themselves, there is in principle an obligation to provide information pursuant to Article 14 GDPR. That obligation does not apply, however, where the personal data must remain confidential subject to an obligation of professional secrecy regulated by Union or Member State law (Article 14(5)(d) GDPR). As all engagement information is subject to the attorneys’ duty of professional secrecy under Section 9(2) RAO, we are regularly prevented from informing such third parties; moreover, providing such information would typically frustrate the purpose of the enforcement of rights. The obligation to provide information also does not apply where doing so proves impossible or would involve a disproportionate effort (Article 14(5)(b) GDPR). The principles of purpose limitation and data minimisation naturally apply to these data as well; they are used exclusively for the respective engagement and not for advertising or analytics purposes.
6. Necessity of providing the data
The provision of the data referred to in section 3 items a) to d) and item f) is in part required by law and in part necessary for the establishment and performance of the engagement relationship. Without these data we cannot accept or continue an engagement: the anti-money-laundering provisions of the RAO oblige us to refrain from establishing or continuing the business relationship if the due diligence obligations cannot be complied with. Likewise, without the information required for checking conflicts of interest (Section 10(1) RAO) we cannot accept an engagement, and without complete information on the facts of the matter, careful legal advice and representation is not possible.
The provision of data for optional purposes – in particular for receiving newsletters and client information and for the use of cookies that are not technically necessary – is, by contrast, voluntary. Failure to provide such data has no adverse consequences; our website remains fully available to you even if you reject all non-necessary cookies.
7. Recipients and categories of recipients
Your data are transmitted only to the following recipients, and only to the extent that this is necessary for the purposes stated, covered by the engagement or required by law:
a) Courts, public authorities and public bodies
In particular civil, criminal and administrative courts, public prosecutors' offices, administrative and tax authorities, companies register and land registry courts, as well as the Financial Intelligence Unit at the Federal Criminal Police Office – in each case in the context of conducting the engagement or of mandatory statutory reporting, disclosure and production obligations. Suspicious activity reports under the anti-money-laundering provisions are subject to a statutory prohibition on disclosure; we are not permitted to inform you of any such report.
b) Parties involved in proceedings
Opposing parties and their representatives, further parties and intervening parties, experts, interpreters, witnesses and notaries, to the extent that the transfer is necessary for the performance of the engagement and covered by your instructions.
c) Other professionals engaged
Substitute counsel and corresponding counsel in Austria and abroad, notaries, tax advisors and auditors, in each case within the statutory framework, subject to a duty of secrecy and – other than in cases of mere substitution at hearings – after prior consultation with you.
d) The Vienna, Salzburg and Lower Austria Bar Associations and the ÖRAK
In the context of professional supervision, in disciplinary and complaints proceedings, and in the context of handling escrow arrangements via the bar association's escrow facility.
e) Credit institutions
In connection with the handling of escrow and client accounts and of payment transactions.
f) Professional indemnity insurers
In the context of the statutorily required professional indemnity insurance (Section 21a RAO), to the extent that claims are asserted against us or a coverage enquiry is necessary.
g) Processors
IT, hosting and maintenance service providers, the providers of the practice management software used by us and of the transmission agency for the Electronic Legal Communication system, providers of identity verification and sanctions screening systems, telephony and e-mail providers, typing and translation services, archiving and file destruction companies, as well as the providers of the services used on our website (section 14). We have concluded agreements pursuant to Article 28 GDPR with all processors; they process your data exclusively on our instructions and are additionally bound to secrecy.
h) Service providers in connection with the collection of fees
Legal expenses insurers, attorneys or other service providers engaged by us, exclusively in the event of qualified default in payment and limited to the data necessary for collection.
i) Providers of the cookies and third-party services used on our website
Exclusively on the basis of your consent and only with regard to the website usage data described in section 14. Some of these providers are, in respect of the processing carried out by them, independent controllers or joint controllers together with us (Article 26 GDPR). Engagement data are not made accessible to these providers.
8. Transfers to third countries
Engagement data.As a matter of principle, engagement data are not transferred to countries outside the European Economic Area (EEA); our firm’s IT systems are operated within the EEA. Should a transfer to a third country nevertheless become necessary in an individual case – for example in cross-border engagements, when instructing foreign corresponding counsel or when conducting proceedings abroad – such transfer will take place exclusively on the basis of an adequacy decision of the European Commission (Article 45 GDPR), appropriate safeguards such as the standard data protection clauses (Article 46 GDPR), or on the basis of Article 49(1) GDPR, in particular points (b) and (c) (performance of a contract) and point (e) (establishment, exercise or defence of legal claims). We will inform you separately in such cases.
Website.Some of the analytics and marketing services used on our website are operated by providers that process personal data in the United States or in other third countries, or transfer such data there (see the overview in section 14.2). The basis for these transfers is – where the respective provider is certified – the European Commission’s adequacy decision of 10 July 2023 on the EU-U.S. Data Privacy Framework (Article 45 GDPR), and otherwise the conclusion of standard data protection clauses (Article 46(2)(c) GDPR) together with supplementary protective measures, and, on a subsidiary basis, your explicit consent pursuant to Article 49(1)(a) GDPR. We point out that a level of data protection equivalent to that under Union law cannot be guaranteed in every case in third countries, and that in particular access by state authorities and limited legal remedies cannot be ruled out. You may withdraw your consent at any time with effect for the future (section 14.1).
There is no intention to transfer personal data to an international organisation.
9. Retention periods
We store personal data only for as long as this is necessary for the respective purposes or for as long as statutory retention obligations exist. In detail:
| Category of data | Retention period |
|---|---|
| Case file (Handakt) and documents entrusted to us | At least five years from termination of the power of attorney (Section 12(1) RAO); beyond that, until expiry of the limitation periods relevant to liability claims. We will release original documents to you at any time on request. |
| Identification and KYC documentation, records of transactions and of the business relationship | Five years from the end of the business relationship or from the execution of the occasional transaction (anti-money-laundering retention obligation under the RAO); up to ten years upon a reasoned order of the competent authority. |
| Escrow documentation | In accordance with the guidelines of the bar association's escrow facility, in any event five years from full completion of the escrow arrangement. |
| Accounting, fee and voucher data | Seven years from the end of the calendar year to which the record relates (Section 212 UGB, Section 132 BAO); longer for as long as they are relevant to pending proceedings. |
| Data for defending against professional liability claims | Until expiry of the relevant limitation periods (Section 1489 ABGB: three years from knowledge of the damage and the party causing it, absolute limit 30 years); where enforceable titles exist, up to 30 years (Section 1478 ABGB). |
| Basic data for conflict-of-interest checks | Permanently, limited to the names and contact details of the parties, the file reference and the subject matter of the engagement; no further substantive evaluation takes place. |
| Enquiries that do not lead to an engagement | Permanently, limited to the names and contact details of the potential parties; the basic data required for the conflict check are retained in accordance with the preceding row. |
| Job application documents | Seven months from completion of the application procedure (time limits under the GlBG – Equal Treatment Act); with your express consent, longer retention in our applicant pool. |
| Server log files | No longer than 30 days, unless a security-relevant incident requires longer retention in an individual case. |
| Cookies and website services | In accordance with the storage periods set out in section 14.2, but in any event no longer than until your consent is withdrawn. |
| Evidence of consent given (consent logs) | Three years from withdrawal or from the last confirmation, for the purpose of demonstrating consent pursuant to Article 7(1) GDPR. |
| Data processed on the basis of consent (e.g. newsletter) | Until consent is withdrawn. |
Upon expiry of the respective period, the data are deleted or destroyed in compliance with data protection law; physical documents are destroyed by a certified company under observance of the duty of professional secrecy.
10. Automated decision-making and profiling
No decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you (Article 22 GDPR) takes place. All legal assessments and decisions on the conduct of an engagement are taken by attorneys at law.
Where we use technical aids, including AI-supported systems, for research, word processing or document analysis, this is done exclusively in a supporting capacity and in compliance with the attorneys’ duty of professional secrecy; the final assessment and responsibility always remain with the respective attorney at law. Engagement data are not used to train such systems.
On our website, profiling within the meaning of Article 4(4) GDPR takes place for reach measurement and advertising purposes – provided that you have consented to marketing and statistics cookies (section 14). This profiling has no legal effect on you, is based exclusively on your consent and ends when that consent is withdrawn. These data are not combined with engagement data.
11. Your rights as a data subject
Subject to the statutory requirements, you have the following rights: access to the data processed by us (Article 15 GDPR); rectification of inaccurate data or completion of incomplete data (Article 16 GDPR); erasure (Article 17 GDPR); restriction of processing (Article 18 GDPR); data portability in respect of those data which you have provided to us and which we process by automated means on the basis of consent or a contract (Article 20 GDPR); objection to processing based on Article 6(1)(f) GDPR, on grounds relating to your particular situation (Article 21 GDPR) – you may object to direct marketing at any time without giving reasons; withdrawal of consent given with effect for the future (Article 7(3) GDPR), whereby the lawfulness of processing carried out until withdrawal remains unaffected. You can adjust or withdraw your cookie consent at any time via the “Cookie settings” link on our website.
Restrictions arising from the attorneys’ duty of professional secrecy. We may provide access only to the extent that this does not adversely affect the duty of secrecy owed to other clients or the rights and freedoms of others (Article 15(4) GDPR, Section 9(2) RAO). We are therefore regularly able to respond only to a limited extent to requests from opposing parties and other third parties. We review each access request on a case-by-case basis and disclose the reasons for any restriction to the extent that this is possible without breaching the duty of professional secrecy.
Restrictions arising from statutory retention obligations. To the extent that we are required by law to retain data – in particular under professional, anti-money-laundering, commercial and tax legislation – we cannot comply with a request for erasure or restriction for the duration of those obligations. The data concerned will in such cases be blocked from further processing and retained exclusively for the purpose of complying with the statutory obligations.
An informal notification to the contact details set out in section 1 is sufficient to exercise your rights. Where there are reasonable doubts as to your identity, we may request additional information for the purpose of verifying your identity (Article 12(6) GDPR).
12. Right to lodge a complaint
Without prejudice to any other legal remedies, you have the right to lodge a complaint with the supervisory authority if you consider that the processing of your data infringes the GDPR (Article 77 GDPR):
Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40–42
1030 Vienna
Telephone: +43 1 52 152-0
E-mail: dsb@dsb.gv.at
Web: www.dsb.gv.at
We point out that the investigative and corrective powers of the Data Protection Authority in relation to attorneys at law are restricted to the extent of the attorneys’ duty of professional secrecy (Article 90 GDPR in conjunction with Section 9 RAO). Complaints concerning the practice of the profession as such may in addition be addressed to the Rechtsanwaltskammer Wien, Ertlgasse 2, 1010 Vienna.
13. Data security
We take technical and organisational measures pursuant to Article 32 GDPR in order to protect your data against loss, destruction, manipulation and unauthorised access. These include, in particular, graduated access and authorisation concepts with engagement-related separation between the cooperation partners, encryption of data transmissions and of data carriers in accordance with the state of the art, access controls and locked storage of physical files, regular data backups, and the written commitment of all employees to confidentiality (Article 28(3)(b) and Article 32(4) GDPR in conjunction with Section 6 DSG and Section 9 RAO).
Communication with courts and administrative authorities takes place, where permissible, via the Electronic Legal Communication system (Sections 89a et seq. GOG) and thus via a secure transmission channel.
We point out that unencrypted communication by e-mail may be subject to security vulnerabilities. For the exchange of particularly sensitive information we will, at your express prior written request and at your cost, make available an encrypted transmission channel or a secure data room.
14. Data processing in connection with our website
14.1 Cookies and comparable technologies
Cookies are small text files stored on your terminal device. The following explanations also apply to comparable technologies such as counting pixels, web beacons, local and session storage, software development kits and device fingerprinting techniques.
Legal bases. The storage of information on your terminal device and access to information already stored there are permitted under Section 165(3) TKG 2021 only with your consent. An exception applies to cookies that serve exclusively to carry out the transmission of a communication or to provide the service expressly requested by you (technically necessary cookies); we use these on the basis of Article 6(1)(f) GDPR. For all other cookies and for the subsequent processing of the data collected by means of them, your consent pursuant to Article 6(1)(a) GDPR is the legal basis.
Categories. We distinguish between four categories: Technically necessary cookies – enable the operation of the website, session control, load balancing and the prevention of abusive access, as well as the storage of your cookie selection; no consent required. Functional or preference cookies – store settings selected by you (such as language or display) and enable extended functions such as embedded maps and videos; only with consent. Statistics and analytics cookies – serve to measure reach and to evaluate usage behaviour in order to improve our offering; pseudonymous usage profiles are created in the process; only with consent. Marketing and advertising cookies – serve to display interest-based advertising, cross-device recognition, retargeting and success and conversion measurement, including across third-party websites; only with consent.
Consent management. When you first access our website, a consent banner is displayed by means of which you can separately accept or reject the use of cookies by category – and, via the detailed settings, by individual service. Rejection is possible at the same level and with the same effort as acceptance; merely continuing to browse or closing the banner does not constitute consent. As long as you have not given consent, only technically necessary cookies are set. Your selection is logged for evidentiary purposes (Article 7(1) GDPR).
Withdrawal.You may withdraw your consent or change your selection at any time with effect for the future by clicking the “Cookie settings” link in the footer of our website. Withdrawal does not affect the lawfulness of the processing carried out up to that point. Irrespective of this, you can delete or block cookies via your browser settings or restrict their storage to individual websites; this may impair the functionality of our website.
14.2 Cookies and third-party services
For details of the data processing carried out by any third-party providers, please refer to their respective privacy policies, to which we provide links in the detailed settings of our consent banner. In respect of those services for which joint controllership pursuant to Article 26 GDPR exists, we have concluded an arrangement with the respective provider on the allocation of the obligations under data protection law; the essence of that arrangement is available on the providers’ websites. You may also exercise your rights directly vis-à-vis those providers.
14.3 Server log files
When you access our website, data are automatically stored by the hosting provider in server log files (page accessed, date and time, volume of data transferred, referrer URL, browser type and version, operating system, IP address). This processing is necessary for the technically error-free provision and the security of our system and is based on Article 6(1)(f) GDPR. These data are not combined with other data sources and are not evaluated for marketing purposes. The log files are deleted after no more than 30 days, unless a security-relevant incident requires longer retention in an individual case.
Hosting provider (processor):
IONOS SE
Elgendorfer Strasse 57
56410 Montabaur
Germany
Server location within the EEA
14.4 Contacting us; no contact forms
If you contact us by e-mail or telephone (we do not use contact forms), we process the information you provide in order to deal with your enquiry. The legal basis is Article 6(1)(b) GDPR where the enquiry is directed at instructing us, and otherwise Article 6(1)(f) GDPR (legitimate interest in responding to enquiries). Before dealing with the substance of an enquiry we carry out a conflict-of-interest check (Section 10(1) RAO). If the enquiry does not lead to an engagement, we delete the data in accordance with section 9.
Important note:An engagement relationship comes into existence only upon express acceptance of each instruction by one of our attorneys at law. It goes without saying, however, that enquiries are also subject to the attorneys’ duty of professional secrecy from the moment they are received.
14.5 Newsletters and client information
Where we offer a newsletter or client information, registration takes place by means of a double opt-in procedure: after you have registered, you will receive an e-mail containing a confirmation link. We store your e-mail address, the time of registration and of confirmation, and the IP address used in the process, in order to demonstrate consent (Article 7(1) GDPR). The legal basis is Article 6(1)(a) GDPR in conjunction with Section 174 TKG 2021. You may unsubscribe at any time via the unsubscribe link contained in every mailing or by informal notification to us. Opening and click rates are evaluated only to the extent that you have separately consented to this.
14.6 Our social media presences
We maintain profiles on social networks, in particular (but not exclusively) on LinkedIn. When you visit these profiles, the respective provider processes personal data on its own responsibility in accordance with its own privacy policy; we have no influence over that processing. With regard to the aggregated page and reach statistics made available to us, joint controllership within the meaning of Article 26 GDPR exists. We ourselves process only such data as you transmit to us by way of messages, comments or interactions; the legal basis is Article 6(1)(f) GDPR (legitimate interest in external presentation and communication) or Article 6(1)(b) GDPR in the case of engagement-related enquiries. For confidential matters, please use exclusively the contact channels set out in section 1.
15. Amendments to this privacy policy
We reserve the right to amend this privacy policy if the legal position, our services or the nature of the data processing changes. The version available on our website at the time of the processing applies in each case. We will inform existing clients separately of material changes.
This privacy policy is as of 26 August 2026.