Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
We hereby inform you about the processing of your personal data (“Data”) when you visit our website or our social media profiles, when you have a client relationship or other business relationship with us, when you attend one of our events, or when you apply for a job with us.
We are responsible for data processing:
WIPIT Partnerschaft mbB
Attorneys and Tax Advisors
Ohmstraße 22
80802 Munich
T +49 89 38 39 95-0
F +49 89 38 39 95-99
info@wipit.legal
If you have any questions regarding data protection, please contact our internal data protection team or our external data protection officer, DataCo GmbH, Sandstr. 33, 80335 Munich, 089 452 459 900, www.dataguard.de.
Please feel free to use our data protection email address:privacy@wipit.legal.
Contents:
Is there an obligation to provide data?
To the extent that we require data in connection with the performance or handling of the client or business relationship and the fulfillment of legal obligations, you are required to provide such data.
I. Use of our website
In this section, we provide information about the processing of your data when you visit our website. To the extent that the Act on Data Protection and the Protection of Privacy in Telecommunications and Digital Services (“TDDDG”) applies to the use of our website, cookies (small text files stored on your device) are used when technically necessary for the operation of the website, in accordance with Section 25(2)(2) of the TDDDG.
1. Scope of data processing
When you access our website, the following data is transmitted to our web server and stored in a log file:
• IP address;
• Date and time of each access to a page on the website;
• Amount of data transferred to your device;
• Files accessed via the homepage;
• URL of the page/homepage from which you accessed our website;
• Browser used by you (type and version);
• The operating system you are using (type and version).
In addition, we use a so-called Content Delivery Network (CDN) to deliver and optimize website performance, which enables the content of our website to be delivered more quickly and securely via servers distributed across different regions. To this end, when you visit our website, server requests are sent to the CDN provider’s servers. In particular, the IP address, content accessed, date and time of the request, amount of data transferred, and browser and device information may be processed and stored in server log files. In this context, the session cookie _cfuvid is set to limit the access rate and protect against bots, in order, among other things, to distinguish between individual website visitors who use the same IP address.
2. Purposes of data processing
The processing of this data is necessary to display the website’s content optimally on your device and to ensure website security. In addition, we process this data to investigate and track attacks on our IT systems.
3. Legal basis for data processing
This data is processed in accordance with Section 25(2)(2) of the TDDDG and Article 6(1)(f) of the EU General Data Protection Regulation (“GDPR”) based on our legitimate interest in ensuring the secure, stable, and efficient provision of website functionality and the ability to track attacks on our IT systems.
4. Recipients of the data
We use external IT service providers to operate the website. These service providers process your data exclusively in accordance with our instructions and on the basis of a data processing agreement pursuant to Article 28 of the GDPR. To the extent that personal data is transferred to a country outside the EU (third country), this is done in compliance with the provisions of Articles 44 et seq. of the GDPR, for example on the basis of the EU Commission’s Standard Data Protection Clauses and—where necessary—supplementary safeguards.
5. Retention Period
Log data is stored for a period of seven days and then deleted, unless it must be retained for a longer period in exceptional cases to investigate an identified attack. The session cookie is automatically deleted at the end of your visit to the website.
2. Purpose of Data Processing
Your data is processed for the purpose of carrying out our clients’ mandates and safeguarding their interests.
3. Legal Basis for Data Processing
We process your data either on the basis of Article 6(1)(c) of the GDPR due to legal obligations or on the basis of Article 6(1)(f) of the GDPR based on our legitimate interest. In this case, the legitimate interest is the protection of our clients’ interests and the proper handling of the mandate.
4. Recipients of the Data
Your data or the data of your employees is received by agencies, institutions, or individuals. Recipients may include, in particular, our clients, government agencies, administrative offices, courts, as well as experts, opposing parties in our clients’ proceedings, or other involved parties. The transfer of data is based on our legitimate interest (Art. 6(1)(f) GDPR) in being able to properly handle the mandate, so that a transfer takes place only to the extent necessary to safeguard this interest.
5. Retention Period
We will delete your data along with all case-related data upon expiration of the statutory retention obligation for attorneys (pursuant to § 50(1) BRAO, 6 years after the end of the calendar year in which the case was concluded), unless we are required under Article 6(1), first sentence, letter c of the GDPR, due to tax and commercial law retention and documentation obligations (under the German Commercial Code (HGB), the German Criminal Code (StGB), or the German Fiscal Code (AO)), the retention is necessary to assert, exercise, or defend civil law claims, or you have consented to further retention pursuant to Article 6(1), first sentence, letter a of the GDPR.
IV. Business Contacts and Their Employees
Below, we provide information on how we process data belonging to our business partners or their employees.
1. Scope of Data Processing
As part of our business relationship with you as a business partner or an employee of a business partner, we process the data we receive from you or your employer.
This specifically refers to data we receive when you or your colleagues are in contact with our employees.
In this context, we process the following categories of data:
2. Purpose of Data Processing
We process your data for the purpose of establishing and fulfilling the contractual relationship with our business partner, as well as to comply with legal requirements.
3. Legal Basis for Data Processing
We process data based on the following legal grounds:
4. Recipients of the Data
Within our firm, only those persons who require your data for the described purposes have access to it.
We also transfer your data to government agencies (e.g., tax authorities, police, public prosecutors, social security agencies) or courts within the scope of their respective jurisdictions if we are required to do so by law or by order. Even in these cases, we will only transfer data to the extent necessary for the respective purposes.
5. Retention Period
We will retain your data for as long as we need it for the specific purpose of processing. We generally retain your data at least for the duration of our business relationship with you or with the business partner on whose behalf you are acting.
In addition, we store certain data for the duration of statutory limitation periods (typically three years, in individual cases up to thirty years) and for as long as required by statutory retention periods (e.g., under the German Commercial Code or the German Fiscal Code), though generally for a maximum of ten years.
Under certain circumstances, we may be required to retain your data for a longer period. This is the case, for example, if, in connection with administrative or judicial proceedings, a prohibition on data deletion is ordered for the duration of the proceedings.
V. Video Conferencing Tools
To conduct video and audio conferences, webinars, and other types of video and audio meetings, we use the video conferencing tool Microsoft Teams ("MS Teams").
Below, we outline which data we process when you conduct a video or audio conference with us via the video conferencing software MS Teams.We use the video conferencing tool Microsoft Teams (“MS Teams”) to conduct video and audio conferences, webinars, and other types of video and audio meetings.Below, we outline what data we process when you hold a video or audio conference with us using the MS Teams video conferencing software.
1. Scope of Data Processing
2. Purpose of Data Processing
The processing of the above-mentioned personal data serves to set up and provide online meetings/video conferences, as well as to conduct them within the scope of the client-attorney relationship.
3. Legal Basis for Data Processing
If a client-attorney relationship exists with us or is to be established, we process your data to fulfill our obligations arising from the client-attorney relationship. The legal basis is Article 6(1)(b) of the GDPR, provided that the client is a natural person. If our client is a legal entity, we process the data of our client’s employees and the data of other natural persons whose participation in the video/audio conference takes place within the scope of handling the client relationship, based on our legitimate interests in efficient and secure communication with our communication partners pursuant to Article 6(1), sentence 1, subparagraph (f) of the GDPR.
4. Recipients of the Data
Microsoft Teams is a cloud application provided to us by Microsoft Ireland Operations Ltd. (“Microsoft”). In this context, Microsoft processes personal data on our behalf in accordance with our instructions, based on a data processing agreement (Article 28 of the GDPR). In addition, we have entered into a separate confidentiality agreement with Microsoft for parties bound by professional secrecy, in which Microsoft acknowledges that the data processed by us is subject to special attorney-client privilege.
To the extent that personal data is stored in the cloud when using MS Teams, such storage takes place exclusively within the European Union (at-rest data). However, data processed during the use of MS Teams may also be processed in third countries—particularly if communication participants are not located in the EU. In such cases, Microsoft engages subprocessors (e.g., Microsoft Inc.) and ensures adequate data protection safeguards for any transfers to third countries in accordance with Art. 44 et seq. of the GDPR; Microsoft is certified under the EU-U.S. Data Privacy Framework.
5. Retention Period
Your personal data that we process in connection with the use of MS Teams is generally deleted as soon as it is no longer needed for the purposes for which it was collected. We delete metadata after 30 days.
VI. Job Applicants
You can apply to us in response to our published job openings or submit a speculative application. Below, we outline which data is processed in this context.
1. Scope of Data Processing
During the application process, we process the following categories of data:
A minimum amount of information is required to carry out our application process.
Your application materials will be sent to the contact person listed in the job posting and will be forwarded internally to other individuals responsible for the application process.
2. Purpose of Data Processing
We process your data to assess whether you are a suitable candidate for employment with us as part of the applicant selection process.
3. Legal Basis for Data Processing
The legal basis for data processing is Section 26(1) of the German Federal Data Protection Act (BDSG) and Article 6(1)(b) of the General Data Protection Regulation (GDPR) (pre-contractual measures). Information you voluntarily provide that goes beyond what is strictly necessary is processed on the basis of our legitimate interest (Article 6(1)(f) of the GDPR), namely to respond to your application in the best possible way. If, in individual cases, you provide information for which we have no legal basis for processing, we will not process it.
4. Recipients of the Data
Internally, only those individuals who need your data for the stated purposes have access to it. These are primarily the relevant hiring managers, HR staff responsible for the process, and all individuals who are necessarily involved in the applicant selection process.
5. Retention Period
If an employment relationship is established with you, we will process your data for the purposes of that employment relationship. For further information, our Privacy Notice for Employees will be made available to you.
If an employment relationship is not established with you, we generally store your data for a period of six months from the date you receive notification of the rejection. After that, your application documents will be deleted.
VII. Social Media Profiles: LinkedIn
No cookies from social media platform operators are integrated into our website (e.g., via plug-ins). However, we maintain various social media profiles of our own to continuously improve our public image and provide information on the respective social media platforms.
Below you will find information about our data processing activities on LinkedIn.
1. Scope of Data Processing
You can interact with our profile on LinkedIn by, for example, following us, leaving comments on posts, “liking” our posts, or sharing our updates. In this case, we receive a notification from LinkedIn that you have visited or interacted with our account. We can then see your profile name, your interaction, and—if available—your profile picture. If you contact us via direct message on LinkedIn, we can see your user profile and your message.
We also receive information from LinkedIn about visitors, followers, and updates to our LinkedIn page (“Page Insights”). This information is displayed to us at on our admin page. Both we and LinkedIn Ireland Unlimited Company (Wilton Place, Dublin 2, Ireland, “LinkedIn”) are jointly responsible for processing your data in connection with this feature on our LinkedIn page. LinkedIn is specifically responsible for fulfilling your data protection rights in connection with Page Insights. However, you may still contact us to exercise your rights.
2. Purpose of Data Processing
We process the data to be able to interact with you at your initiative, as well as to read and respond to your inquiry or notification.
We do not use the analytics feature, but we are unable to disable it because LinkedIn does not provide this option.
3. Legal Basis
We process your data based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR. Our legitimate interest consists of the interaction with you described above.
4. Recipients of the Data
Your data is accessed by our employees who manage our LinkedIn account.
In addition, LinkedIn processes your data in accordance with LinkedIn’s privacy policy.
Provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
Privacy Policy: https://www.linkedin.com/legal/privacy-policy
Opt-out of advertising: www.linkedin.com/psettings/guest-controls/retargeting-opt-out
5. Retention Period
We cannot delete your messages or other data because we lack the authorization to do so. We do not actively use LinkedIn direct messages to communicate with you—we prefer encrypted communication via email for this purpose. If you send us direct messages, we will delete them no later than one year after receiving your message.
VIII. Law Firm Events
1. Scope of Data Processing
We will send event invitations to the email address we have on file. If you would like to attend the law firm event, you can register online. You will be asked to provide the following information: email address, first name, last name (optional: title), as well as the number of guests and their first and last names. After you’ve filled out the online form, you’ll receive a registration confirmation at the email address you provided, including a calendar entry and a QR code. Please bring the QR code with you on the day of the event. It will be scanned at the entrance, and name tags will be printed for you and your guests. Three days before the event, you will receive an event reminder via email. If any key details change, you will also be notified via email. Additionally, you can cancel your registration at any time by clicking the “I’m afraid I can’t attend” button included in the registration confirmation.
Some photos will be taken during the event. Selected group photos will be published on our website and our LinkedIn page for promotional purposes. If you do not consent to this, please let us know on the day of the event.
2. Purpose of Data Processing
The data processing described above is carried out for the purpose of organizing and conducting our firm’s event, as well as for brief external promotion of the event. In addition, photos will be stored internally as a memento of the event and to document our firm’s highlights, and will be published on our internal WIPIT intranet.
3. Legal Basis for Data Processing
The organization, public presentation, and storage of the photos are generally based on our legitimate interest (Art. 6(1)(f) GDPR) or, to the extent that we process your data in connection with the execution of the event, on Art. 6(1)(b) GDPR. Our legitimate interests lie in the purposes mentioned above.
4. Recipients of the Data
We use the Guestoo SaaS solution to manage registrations and check-in on the day of the event. In this context, Guestoo processes personal data on our behalf in accordance with our instructions, based on a data processing agreement (Art. 28 GDPR). The data is processed on servers in Germany.
In addition, a few selected group photos are published on our website and our LinkedIn page (see the Social Media section above regarding processing on LinkedIn).
5. Retention Period
Registration data will be processed for as long as necessary to carry out the event. In addition, selected photos will be stored internally for the purpose of documenting WIPIT highlights as part of our firm’s history.
IX. Your Rights as a Data Subject
The following rights may be restricted, in particular, by attorney-client privilege pursuant to Art. 23 GDPR in conjunction with § 29 BDSG. Provided there is no conflict with the attorney-client relationship, you have the following rights if the legal requirements are met:
1. Right of Access
You have the right, upon request and free of charge, to obtain information as to whether data concerning you is being processed and, if so, what personal data we process about you (Art. 15 GDPR). You may submit this request again within a reasonable timeframe. In addition, you have the right to receive a copy of your data that is subject to our processing.
2. Right to Rectification
You may also, pursuant to Art. 16 of the GDPR, request the rectification of inaccurate data concerning you. Furthermore, you have the right to request the completion of incomplete data concerning you, taking into account the purposes of the processing.
3. Right to Erasure
Under the conditions set forth in Article 17 of the GDPR, you may request the erasure of your data.
4. Right to Restriction of Processing
You have the right to request that we restrict the processing of your data if the conditions set forth in Article 18 of the GDPR are met. This is the case, for example, if the processing of your data is no longer necessary for our purposes, but you need it to assert, exercise, or defend legal claims. If the processing of your data is restricted, we may process this data—apart from storing it—only with your consent or in the specific cases listed in Article 18(2) of the GDPR.
5. Right to Data Portability
To the extent that data you have provided is processed by us using automated means on the basis of Article 6(1)(b) or (a) of the GDPR (for the purpose of entering into or performing a contract, or based on your consent), you may, under the conditions set forth in Article 20 of the GDPR, request that this data be provided to you in a structured, commonly used, and machine-readable format. In this case, you may also request that we transfer this data to another controller.
6. Right to Withdraw Consent
If we process your data based on your consent, you have the right to withdraw your consent at any time with future effect (Article 7(3) of the GDPR).
7. Right to Object
If we process your data based on our legitimate interests (Article 6(1)(f) of the GDPR), you also have the right to object if your interests in opposing the data processing, for reasons arising from your particular situation, outweigh our interests in processing. In the event of an objection, we therefore ask that you inform us of the reasons why you are objecting to the data processing.
8. Exercising Your Data Subject Rights
To exercise your rights as a data subject, please contact our data protection officer listed above.
9. Right to Lodge a Complaint with a Supervisory Authority
If you believe that your personal data is being processed unlawfully, you may file a complaint with a data protection supervisory authority, in particular in the Member State of your residence, your workplace, or the location of the alleged infringement (Art. 77 GDPR).
As of: July 2026