Privacy policy

With this privacy policy, the law firm schirach.law informs you about which personal data is collected in the context of your use of this website and for what purpose the data is used. If you conclude a mandate agreement with the law firm schirach.law, you will receive separate data protection notices.

This privacy information is currently valid and is dated June 2020.

Due to the further development of the website and services offered thereon, or due to changed statutory or regulatory requirements, it may become necessary to amend this privacy information.

The controller within the meaning of the data protection laws is:

Attorney at Law Marco Benedikt von Schirach

Theatinerstraße 40-42
80333 Munich
Telephone: +49 (0)89 / 433 69 56 – 0
Email contact: kanzlei@schirach.law

 

The subject matter of data protection is personal data. This comprises individual details concerning the personal or factual circumstances of a specific or identifiable natural person, i.e., all information that can be related to an individual.

Data processing is carried out by the website operator 1&1 IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, a company of United Internet AG, Montabaur. When visiting the website, information is automatically sent to the website's server. This information is temporarily stored in the system's log files (Art. 6(1)(f) GDPR).

 

The following data may be collected and stored in this context:

• Information about the browser type and version used
• The user's operating system
• The internet page from which an accessing system reaches the internet page of the law firm schirach.law (so-called referrer)
• The sub-pages accessed via an accessing system on the internet page of the law firm schirach.law
• The user's IP address
• Date and time of access
• The internet service provider of the accessing system
• And other similar data and information that serve to avert danger in the event of attacks on the information technology systems of the law firm schirach.law.

When using this general data and information, the law firm schirach.law does not draw any conclusions about the data subject. Rather, this information is required to correctly deliver the content of the internet page, optimize the content and advertising for it, ensure the long-term functionality of the information technology systems and the technology of the internet page, and provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyberattack. Therefore, this anonymously collected data and information is evaluated by the law firm schirach.law on the one hand statistically and, furthermore, with the aim of increasing data protection and data security within the firm, ultimately ensuring an optimal level of protection for the personal data processed. The anonymous data of the server log files is stored separately from all personal data provided by a data subject.

You can contact the law firm schirach.law via the email addresses provided on the websites or by using the contact form provided. In this case, your personal data transmitted with the email to schirach.law will be stored. This includes at least your name, your email address, and your request. The purpose of data storage is to establish contact at your request (Art. 6(1)(b) GDPR).

The internet pages of the law firm schirach.law use cookies in some cases; these are exclusively technically necessary cookies.

Cookies are text files that are placed and stored on a computer system via an internet browser. Numerous internet pages and servers use cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier of the cookie. It consists of a string of characters through which internet pages and servers can be assigned to the specific internet browser in which the cookie was stored. This enables the visited internet pages and servers to distinguish the individual browser of the data subject from other internet browsers that contain other cookies. A specific internet browser can be recognized and identified via the unique cookie ID. Through the use of cookies, schirach.law can provide users of this website with more user-friendly services that would not be possible without the setting of cookies. By means of a cookie, the information and offers on the website can be optimized in the user's interest. As already mentioned, cookies make it possible to recognize the users of the website. The purpose of this recognition is to make it easier for users to utilize the website. For example, the user of a website that uses cookies does not have to re-enter their access data every time they visit the website, because this is handled by the website and the cookie stored on the user's computer system.
The data subject can prevent the setting of cookies by our website at any time by means of a corresponding setting of the internet browser used and thus permanently object to the setting of cookies. Furthermore, cookies that have already been set can be deleted at any time via an internet browser or other software programs. This is possible in all common internet browsers. If the data subject deactivates the setting of cookies in the internet browser used, not all functions of our website may be fully usable.

The legal bases for the processing of personal data in this context are Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR. Our legitimate interest is the management of the cookies and similar technologies used, as well as the consents granted in this regard.

The controller shall process and store personal data of the data subject only for the period necessary to achieve the purpose of storage, or as granted by the European Directive and Regulation Authority or any other legislator in laws or regulations to which the controller is subject.
If the storage purpose ceases to apply or if a storage period prescribed by the European Directive and Regulation Authority or another competent legislator expires, the personal data is routinely blocked or erased in accordance with statutory provisions.

You have the following rights regarding data processing by the law firm schirach.law in accordance with the respective articles of the General Data Protection Regulation (GDPR):

• pursuant to Art. 15 GDPR, to request confirmation as to whether personal data concerning you is being processed by the law firm schirach.law. In particular, you can request information about the processing purposes, the categories of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing, or objection, the existence of a right to lodge a complaint, the source of your data if it was not collected by us, as well as the existence of automated decision-making including profiling and, where applicable, meaningful information about the details thereof;

• pursuant to Art. 16 GDPR, to demand without undue delay the rectification of inaccurate personal data or the completion of your stored personal data;

• pursuant to Art. 17 GDPR, to demand the erasure of your personal data stored by the law firm schirach.law, unless the processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise, or defense of legal claims;

• pursuant to Art. 18 GDPR, to demand the restriction of the processing of your personal data insofar as the accuracy of the data is contested by you, the processing is unlawful, but you oppose its erasure and the law firm schirach.law no longer needs the data, but you require it for the establishment, exercise, or defense of legal claims, or you have lodged an objection to processing pursuant to Art. 21 GDPR;

• pursuant to Art. 20 GDPR, to receive your personal data that you have provided to the law firm schirach.law in a structured, commonly used, and machine-readable format, or to request its transmission to another controller;

• pursuant to Art. 7(3) GDPR, to revoke your once-granted consent at any time vis-à-vis the law firm schirach.law. As a result, the law firm schirach.law is no longer permitted to continue the data processing based on this consent for the future;

• to lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR. As a rule, you can contact the supervisory authority of your habitual residence, your place of work, or the office of the law firm for this purpose;

• to object to the processing of your personal data pursuant to Art. 21 GDPR, provided there are grounds arising from your particular situation. You have the option of submitting your objection informally to the data protection officer of the law firm schirach.law, or by telephone, e-mail, facsimile, or to the postal address of the law firm schirach.law. Erasure can only take place if there is no statutory retention obligation; in this case, however, the data will be restricted for any other use. In the event of an objection, the conversation cannot be continued.

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR. The competent supervisory authority for data protection issues is the State Data Protection Officer of the federal state in which the law firm schirach.law has its registered office. A list of data protection officers and their contact details can be found at the following link:
https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html

Applicant Data

As part of the application process, we process personal data of applicants in accordance with Art.6(1) lit.b GDPR (decision on the establishment of an employment relationship) as well as §26 BDSG (Federal Data Protection Act).

  1. Processing of publicly available information ("Background Checks")

We reserve the right to research relevant, publicly available information regarding applicants during the application process. This particularly includes:

  • professional profiles in social networks (e.g., XING, LinkedIn)
  • publicly accessible posts or publications
  • press articles or other freely accessible online sources

The purpose of this research is to evaluate professional suitability and verify the accuracy of the information provided during the application process.

Only information that has a professional or position-related context is processed.
Private social networks (e.g., Instagram, Facebook, TikTok) are not systematically analyzed.

  1. Categories of processed data
  • Master data (name, contact details)
  • Application documents (CV, certificates, references, cover letter)
  • Communication data
  • publicly available professionally relevant information
  1. Legal basis
  • Art.6 para.1 lit.b GDPR and §26 para.1 BDSG (Initiation of an employment relationship)
  • Art.6 para.1 lit.f GDPR (legitimate interest in the qualified selection of suitable candidates)
  1. Storage period

Application documents are generally stored for six months after the conclusion of the application process and subsequently deleted, unless statutory retention obligations preclude this or consent has been given for longer storage (talent pool).

  1. Source of data (Art.14 GDPR)

To the extent that we process publicly available information about applicants, this originates from generally accessible professional online profiles, search engines, or press sources.

The controller has integrated Jetpack on this website. Jetpack is a WordPress plug-in that offers additional features to the operator of a website built on WordPress. Among other things, Jetpack allows the website operator to obtain an overview of website visitors. Furthermore, by displaying related posts and publications or the option to share content on the site, an increase in visitor numbers is made possible. Security features are also integrated into Jetpack, better protecting a website using Jetpack against brute-force attacks. Jetpack also optimizes and accelerates the loading of images integrated into the website.

The operating company of the Jetpack plug-in for WordPress is Automattic Inc., 132 Hawthorne Street, San Francisco, CA 94107, USA. The operating company utilizes the tracking technology of Quantcast Inc., 201 Third Street, San Francisco, CA 94103, USA.
Jetpack sets a cookie on the information technology system of the data subject. What cookies are has already been explained above. Each time one of the individual pages of this website, operated by the controller and on which a Jetpack component has been integrated, is called up, the internet browser on the information technology system of the data subject is automatically prompted by the respective Jetpack component to transmit data to Automattic for analysis purposes. As part of this technical procedure, Automattic acquires knowledge of data that are subsequently used to create an overview of website visits. The data collected in this manner serve to analyze the behavior of the data subject who has accessed the website of the controller and are evaluated with the aim of optimizing the website. The data collected via the Jetpack component are not used to identify the data subject without obtaining a separate, explicit consent from the data subject beforehand. The data are also transmitted to Quantcast. Quantcast uses the data for the same purposes as Automattic.

The data subject may, as outlined above, prevent the setting of cookies through the website of the law firm schirach.law at any time by means of a corresponding setting of the internet browser used and thus permanently object to the setting of cookies. Such a setting of the internet browser used would also prevent Automattic/Quantcast from setting a cookie on the information technology system of the data subject. In addition, cookies already set by Automattic can be deleted at any time via the internet browser or other software programs.

Furthermore, the data subject has the opportunity to object to and prevent the collection of data generated by the Jetpack cookie related to the use of this website, as well as the processing of this data by Automattic/Quantcast. For this purpose, the data subject must click the opt-out button under the link https://www.quantcast.com/opt-out/, which sets an opt-out cookie. The opt-out cookie set with the objection is stored on the information technology system used by the data subject. If the cookies on the data subject's system are deleted after an objection, the data subject must call up the link again and set a new opt-out cookie.

However, by setting the opt-out cookie, there is a possibility that the websites of the controller may no longer be fully usable for the data subject.

The applicable data protection provisions of Automattic can be accessed at https://automattic.com/privacy/. The applicable data protection provisions of Quantcast can be accessed at https://www.quantcast.com/privacy/.

The controller has integrated components of the LinkedIn Corporation on this website. LinkedIn is an internet-based social network that enables users to connect with existing business contacts as well as forge new business contacts. Over 400 million registered individuals use LinkedIn in more than 200 countries. Thus, LinkedIn is currently the largest platform for business contacts and one of the most visited websites in the world.

The operating company of LinkedIn is LinkedIn Corporation, 2029 Stierlin Court Mountain View, CA 94043, USA. For data protection matters outside the USA, LinkedIn Ireland, Privacy Policy Issues, Wilton Plaza, Wilton Place, Dublin 2, Ireland, is responsible.
With each individual call-up of our website equipped with a LinkedIn component (LinkedIn plug-in), this component causes the browser used by the data subject to download a corresponding representation of the LinkedIn component. Further information on the LinkedIn plug-ins can be accessed at https://developer.linkedin.com/plugins. As part of this technical procedure, LinkedIn obtains knowledge of which specific subpage of our website is visited by the data subject.

If the data subject is logged in to LinkedIn at the same time, LinkedIn recognizes, with each call-up to our website by the data subject and for the entire duration of their stay on our website, which specific subpage of our website the data subject is visiting. This information is collected by the LinkedIn component and assigned by LinkedIn to the respective LinkedIn account of the data subject. If the data subject clicks on a LinkedIn button integrated into our website, LinkedIn assigns this information to the personal LinkedIn user account of the data subject and stores this personal data.
LinkedIn receives information via the LinkedIn component that the data subject has visited our website whenever the data subject is logged in to LinkedIn at the time of calling up our website; this occurs regardless of whether the data subject clicks on the LinkedIn component or not. If the data subject wishes to prevent such transmission of information to LinkedIn, they can do so by logging out of their LinkedIn account before calling up our website.

LinkedIn offers the option to unsubscribe from e-mail messages, SMS messages, and targeted advertisements, as well as to manage ad settings at https://www.linkedin.com/psettings/guest-controls. LinkedIn also uses partners such as Quantcast, Google Analytics, BlueKai, DoubleClick, Nielsen, Comscore, Eloqua, and Lotame, which may set cookies. Such cookies can be rejected at https://www.linkedin.com/legal/cookie-policy. The applicable data protection provisions of LinkedIn can be accessed at https://www.linkedin.com/legal/privacy-policy. LinkedIn's cookie policy can be accessed at https://www.linkedin.com/legal/cookie-policy.

The controller has integrated components of Xing on this website. Xing is an internet-based social network that enables users to connect with existing business contacts and establish new business contacts. Individual users can create a personal profile on Xing. Companies can, for example, create corporate profiles or publish job openings on Xing.

The operating company of Xing is XING SE, Dammtorstraße 30, 20354 Hamburg, Germany.

Each time one of the individual pages of this website operated by the controller and on which a Xing component (Xing plug-in) has been integrated is called up, the internet browser on the information technology system of the data subject is automatically prompted by the respective Xing component to download a representation of the corresponding Xing component from Xing. Further information on the Xing plug-ins can be accessed at https://dev.xing.com/plugins. As part of this technical procedure, Xing obtains knowledge of which specific subpage of the website of the law firm schirach.law is visited by the data subject.

If the data subject is logged in to Xing at the same time, Xing recognizes, with each call-up to our website by the data subject and for the entire duration of their stay on our website, which specific subpage of our website the data subject is visiting. This information is collected by the Xing component and assigned by Xing to the respective Xing account of the data subject. If the data subject clicks on one of the Xing buttons integrated into our website, Xing assigns this information to the personal Xing user account of the data subject and stores this personal data.
Xing receives information via the Xing component that the data subject has visited our website whenever the data subject is logged in to Xing at the time of calling up our website; this occurs regardless of whether the data subject clicks on the Xing component or not. If the data subject wishes to prevent such transmission of information to Xing, they can do so by logging out of their Xing account before calling up our website.

The data protection provisions published by Xing, which are available at https://www.xing.com/privacy, provide information on the collection, processing, and use of personal data by Xing. Furthermore, Xing has published privacy notices for the XING Share button at https://www.xing.com/app/share?op=data_protection.

Insofar as legal bases are mentioned in this privacy policy, these are in accordance with the General Data Protection Regulation. These have been applicable since May 25, 2018. We collect and process personal data based on the legal bases stated below:

• Consent pursuant to Article 6(1)(a) of the General Data Protection Regulation (GDPR). Consent is any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

• Necessity for the performance of a contract or implementation of pre-contractual measures pursuant to Article 6(1)(b) GDPR, i.e., the data is necessary for us to fulfill our contractual obligations towards you or we require the data to prepare the conclusion of a contract with you.

• Processing for compliance with a legal obligation pursuant to Article 6(1)(c) GDPR, meaning that data processing is prescribed by law or other regulations.

• Processing for the protection of legitimate interests pursuant to Article 6(1)(f) GDPR, meaning that the processing is necessary to protect legitimate interests on our part or by third parties, provided that your interests, fundamental rights, and fundamental freedoms requiring the protection of personal data do not override them.

To ensure data security, the transmission of content on our website is encrypted using state-of-the-art SSL technology. To secure the data, we and the contracted service providers, with whom corresponding contractual agreements have been concluded, employ appropriate state-of-the-art technical and organizational measures, in particular to restrict access to the data, protect against alteration and loss, and ensure confidentiality in accordance with the state of the art.

Would you like further information?

Get in touch for more information regarding preventive criminal defense and legal counsel.