IDENTITY AND CONTACT DETAILS OF THE CONTROLLER
The controller for the processing of personal data within the meaning of Art. 4 para. 7 GDPR is:
METIS Rechtsanwälte PartG mbB
Untermainkai 30
60329 Frankfurt am Main
Germany
Phone: +49 69 271 38 89 0
Fax: +49 69 271 38 89 70
E-Mail: email hidden; JavaScript is required
The controller’s legal representatives are its partners Dr. Felix Dette, Dr. Lars Friske, Dr. Andreas Rasner, Dr. Heinrich von Bünau and Dr. Florian Wettner. Each of them is authorised to represent the controller solely.
CONTACT DETAILS OF OUR DATA PROTECTION OFFICER
Our data protection officer is:
ENSECUR GmbH
Höhefeldstraße 28
76356 Weingarten
Germany
E-Mail: email hidden; JavaScript is required
1 — CATEGORIES OF PERSONAL DATA PROCESSED BY US
In connection with our legal services, we process personal data which we obtain
- directly from you,
- from third parties authorised by you (e.g. another lawyer, a notary or a tax advisor),
- from other third parties (e.g. your employer, an authority or the opponent) or
by inspecting publicly available sources (e.g. land register or commercial and association registers).
This includes in particular the following categories of personal data:
- master data (e.g. your name, your address, your contact details such as email address(es) or telephone number(s)),
- biometric data, especially in the form of copies of your identity card or passport,
- mandate-related data (e.g. the existence and the content of contracts, communication or evidence),
- consulting data (e.g. content of enquiries, records of advice, documents received and prepared, file notes, legal opinions and assessments),
- activity data (e.g. evidence of services, billing or invoice data) as well as
- further data that we obtain in connection with our legal services.
This may also include special categories of personal data within the meaning of Art. 9 para. 1 GDPR (e.g. data concerning racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union memberships, health data, or, as stated above, biometric data).
2 — PURPOSES AND LEGAL BASES FOR THE PROCESSING
Unless otherwise indicated below, we process personal data in order to fulfil our obligations arising from ongoing attorney-client relationships.
This includes, in particular, the provision of appropriate legal advice in and out of court, correspondence with contractual partners, courts and opponents, as well as invoicing. In addition, we process personal data for the management of our client relationships.
The legal basis for this processing is Art. 6 para. 1 s. 1 lit. b GDPR if you are our client yourself. In addition and, if another person (e.g. a legal entity) is our client, processing is based on our legitimate interest (Art. 6 para. 1 s. 1 lit. f GDPR) in managing of our client relationships.
Furthermore, we may also process your personal data for the following purposes:
- Contacting: If you contact us, whether by email, phone or in writing, the personal data you provide (e.g. your email address, telephone number, name, and/or further contact details) are stored and used to process your enquiry and respond to it. The legal basis for this processing is our legitimate interest (Art. 6 para. 1 s. 1 lit. f GDPR) in responding to you.
- Compliance with legal obligations: We process your personal data if this is necessary for compliance with a legal obligation to which we are subject (Art. 6 para. 1 s. 1 lit. c GDPR), such as conflict-of-interest checks pursuant to Section 43a para. 4 Federal Code for Lawyers (Bundesrechtsanwaltsordnung, BRAO).
- Money laundering check: Pursuant to Sections 10–12 of the German Anti-Money Laundering Act (Geldwäschegesetz, “GwG”), we are obliged to carry out so-called money laundering checks for certain transactions and business relationships. For this purpose, we also have to process personal data (e.g. in order to identify beneficial owners on the basis of their biometric identity cards or passports). The legal basis for this processing activity is Section 11a para. 1 GwG and Art. 9 para 2 lit. g GDPR in conjunction with Section 11a para. 1 GwG.
- Greeting cards and invitations: If we know you personally and/or if you have a client relationship with our law firm, we may send you greeting cards on special occasions (e.g. Christmas) or invitations to events based on our legitimate interest (Art. 6 para. 1 s. 1 lit. f GDPR). We assume that recipients appreciate such greetings and invitations. You may object to receiving greeting cards and invitations at any time (see further below Section 7).
- Processing based on consent: In rare cases, particularly when none of the above legal bases apply, we process your personal data based on your consent (Art. 6 para. 1 s. 1 lit. a GDPR or, for the processing of special categories of personal data, Art. 9 para. 2 lit. a GDPR).
We do not use any systems or programs for automated decision-making/profiling within the meaning of Art. 22 GDPR.
3 — CATEGORIES OF RECIPIENTS OF THE PERSONAL DATA
As attorneys, we are subject to a statutory duty of confidentiality. Such duty of confidentiality also applies to our employees and other persons engaged by us. We only disclose personal data in the following cases:
- Management of our attorney-client relationships: Where necessary, we disclose your personal data to third parties in the context of managing our attorney-client relationships (Art. 6 para. 1 s. 1 lit. b GDPR), especially to opponents and their representatives as well as courts and public authorities for correspondence and to assert or defend clients’ rights. We may also disclose information to banks for payment processing.
- Use of service providers: Like many businesses, we use external service providers. Such service providers may, depending on the nature of the service rendered, have access to personal data that we process or even explicitly process personal data on our behalf. The legal bases for these transfers are always Art. 6 para. 1 s. 1 lit. b GDPR, Art 6 para. 1 s. 1 lit. c GDPR or our legitimate interest (Art. 6 para. 1 s. 1 lit. f GDPR) in ensuring the smooth operation of our legal services. Our contracts with the service providers require that they process the transferred personal data solely for the purposes necessary for delivery of their services.
- Compliance with legal obligations: In addition, we may be subject to particular legal requirements obliging us to provide personal data to third parties (especially to public authorities). Such disclosure is based on Art. 6 para. 1 s. 1 lit. c GDPR. Examples for these transfers is the reporting of suspicious money-laundering activities under Section 43 GwG to the competent authority.
4 — TRANSFER TO THIRD COUNTRIES
A transfer of your personal data to third countries, i.e. countries outside the European Economic Area (EEA), such as the USA or the United Kingdom, occurs only if required to handle the matter (e.g. cooperation with foreign law firms), if we have to respond to a request of a foreign authority or court, if a party to proceedings is located in a third country, or when we engage an external service provider.
Any transfer to a third country will take place only if the conditions set forth in Art. 44 et seqq. GDPR are fulfilled. This may include, for example, an adequacy decision pursuant to Art. 45 GDPR, i.e. the binding recognition by the European Commission that a country has an adequate level of data protection. If no such adequacy decision exists, the transfer may be based on other suitable safeguards, such as Standard Contractual Clauses under Art. 46 para. 2 lit. c GDPR. If you wish to receive a copy of the Standard Contractual Clauses (or other suitable safeguards) we use, please contact our data protection officer or us directly via the above-mentioned contact details.
5 — DATA ERASURE AND RETENTION PERIOD
Your personal data stored by us will be deleted as soon as the purpose or legal basis for storage/processing no longer applies.
However, legal retention obligations may apply, which require personal data to be stored for a longer period. Essentially, these retention obligations are based on commercial or tax law, in particular on the German Commercial Code (Handelsgesetzbuch, “HGB”), the German Fiscal Code (Abgabenordnung, “AO”) or the German Value Added Tax Act (Umsatzsteuergesetz, “UStG”), such as Section 147 AO, Section 257 HGB, or Section 14b UStG.
So far as such obligations apply, we restrict the further processing of your personal data and will delete them at the end of such retention periods. Generally, deletion takes place five to ten years after the end of the attorney-client relationship, or, in the case of legally enforceable claims, after 30 years.
External service providers engaged by us will store your personal data in their systems only as long as necessary for performing the respective services in accordance with our instructions.
6 — NO REQUIREMENT TO PROVIDE PERSONAL DATA
We do not make communication or entering into attorney-client relationships or contracts with us dependent on you providing us with personal data. Generally, you are under no general statutory or contractual obligation to provide us with your personal data. However, in some cases, we may be able to provide our legal advice and representation only to a limited extent or not at all if you do not provide the necessary data.
7 — YOUR RIGHTS
In connection with our processing of your personal data, you have the following rights:
- Right of Access (Art. 15 GDPR): According to Art. 15 GDPR, you have the right to request information about your personal data processed by us. You may especially request information on the purposes of processing, the categories of personal data processed, the categories of recipients to whom your personal data have been or are disclosed, the planned storage period, the existence of rights to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of the personal data (if not collected from you) and the existence of automated decision-making including profiling and, where applicable, request meaningful information about the details thereof.
- Right to Rectification (Art. 16 GDPR): According to Art. 16 GDPR, you have the right to request the rectification of your inaccurate or incomplete personal data stored by us without undue delay.
- Right to Erasure (Art. 17 GDPR): According to Art. 17 GDPR, you have the right to request the erasure of your personal data stored by us, unless processing is necessary for the exercise of the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise, or defence of legal claims.
- Right to Restriction of Processing (Art. 18 GDPR): According to Art. 18 GDPR, you have the right to request the restriction of processing of your personal data if the accuracy of such personal data is contested by you or the processing is unlawful.
- Right to Data Portability (Art. 20 GDPR): According to Art. 20 GDPR, you have the right to obtain your personal data provided to us in a structured, commonly used and machine-readable format or to have it transmitted to another controller.
- Right to Object (Art. 21 GDPR): According to Art. 21 GDPR, you have the right to object to the processing of your personal data if processing is based on Art. 6 para. 1 s. 1 lit. e or f GDPR. Please state the reasons why you object to the processing, so that we may re-examine the situation and either stop or adjust the processing or give you our compelling legitimate reasons to continue the processing.
- Right to Withdraw Consent (Art. 7 para. 3 GDPR): If processing is based on your consent for the processing of personal data, you have the right to withdraw your consent at any time with effect for the future. This means the consent ceases to be a legal basis for processing of your personal data from the time of withdrawal.
- Right to Lodge a Complaint (Art. 77 GDPR): According to Art 77 GDPR, you have the right to lodge a complaint about the processing of your personal data by us with a data protection supervisory authority, for example, with the supervisory authority responsible for us:
Phone: +49 611 1408 0
E-Mail: email hidden; JavaScript is required
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Gustav-Stresemann-Ring 1
65189 Wiesbaden
Telefon: +49 611 1408 0
E-Mail:email hidden; JavaScript is required
8 — UP-TO-DATENESS OF THIS PRIVACY POLICY
This Privacy Policy is current as of January 2026.
Due to legal or regulatory changes or as a result of modifications to our internal policies, it may become necessary to amend this Privacy Policy. The latest version can always be viewed and printed from this website.
If you have any questions regarding this Privacy Policy, please contact our data protection officer or us at any time.