Skip to content
Call, 0511 – 47 55 58 11

Legal

Privacy information

1. Controller

The controller for the processing of your personal data within the meaning of Article 4(7) GDPR is:

lexICT legal Korte Rasche Heermann Rechtsanwält:innen PartG mbB

Address
Eichenbrink 530453 HannoverGermany
Phone
+49 511 47 55 58 11
Fax
+49 511 47 55 58 19
Email
info@lexict.legal

We have not appointed a data protection officer; the conditions of Article 37 GDPR and section 38 BDSG are not met in our case.

2. Processing when you visit this website

When you open our website, your browser automatically sends information to the server hosting it. The connection data technically required for the transfer is processed: your IP address, the date and time of the request, the address requested, the volume of data transferred, the server status message and the identification string sent by your browser with details of browser and operating system.

This connection data arises in two places, and it is treated differently in each.

On our own server it is processed solely for the duration of delivery. We keep no access logs of it and do not store the data afterwards.

At the upstream network service the position is different. It can identify malicious traffic only by analysing the connection data, and it retains that data for a limited time in order to do so. This processing is the purpose of the service, not a side effect; details are in section 2.2. Our statement that no access logs are kept therefore relates to our own server and not to that upstream layer.

In both cases the legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in the secure and uninterrupted operation of the website. The data is not evaluated for any other purpose, and in particular not to analyse your behaviour.

2.1 Hosting

The website is operated for us by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany, in a data centre in Germany. Hetzner processes the data named above solely on our behalf and on our instructions. We have concluded a data processing agreement with Hetzner under Article 28 GDPR.

2.2 Delivery through Cloudflare

We use the service of Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany, as an upstream network service. All requests to our website first pass through Cloudflare’s servers and only then reach our server. Cloudflare filters malicious traffic, defends against denial of service attacks and delivers static content more quickly.

For that purpose Cloudflare processes your IP address and the details of the request and retains them for a limited time in order to recognise recurring attack patterns. We have configured the service so that processing takes place in data centres inside the European Union.

So that Cloudflare can perform this task, the encrypted connection terminates at Cloudflare and is established anew from there. The content of your requests, including the details from the contact form, is therefore present there in clear text for the duration of processing.

The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in the security and availability of the website. A data processing agreement under Article 28 GDPR is in place with Cloudflare.

Cloudflare Germany GmbH belongs to Cloudflare, Inc., which is based in the United States. Where data is transferred there, the transfer relies on the adequacy decision of the European Commission on the EU-U.S. Data Privacy Framework, under which Cloudflare, Inc. is certified. In addition, the standard contractual clauses of the European Commission have been agreed and apply should the certification lapse. Further details are set out in Cloudflare’s privacy policy at cloudflare.com/privacypolicy.

3. Cookies and local storage

3.1 Your choice of colour scheme

The website appears in a dark colour scheme. Using the control in the service row at the top you can switch to a light scheme.

What is stored. So that the choice still applies on your next visit, we store it in your browser’s local storage, in localStorage under the key schema. The content is a single word, light. No name, no identifier, no timestamp and no address.

Where the value goes. Nowhere. It does not leave your device, it is not transmitted to us or to third parties, and it appears in no server log.

When nothing is stored at all. As long as you stay with the dark scheme, which is the normal case. The entry is created only when you switch to light.

Legal basis. For the associated processing, Article 6(1)(f) GDPR. Our legitimate interest lies in not asking you for a setting again on every visit. Storing it on your device is strictly necessary within the meaning of section 25(2) no. 2 TDDDG in order to provide a service you have expressly requested; no consent is required for it.

Duration and deletion. The entry remains until you delete it. You can do so using the same control, by switching back to the dark scheme, or through your browser’s settings for deleting website data.

3.2 Marker for a passed security challenge

Cloudflare sits in front of the website as an upstream network service, see section 2.2. The service fends off attacks and classifies every request in order to do so. Where it presents a security challenge, it sets a cookie.

What is stored. Only the fact that the challenge was passed. The marker saves you from having to repeat it on every further page.

When this happens. Not routinely, but not only during an ongoing attack either. The service presents the challenge as soon as it considers a request suspicious. That may be a wave of attacks, but equally a single request that strikes it as unusual, for instance from an anonymisation service, over a conspicuous network address or from an unusually configured browser. Which characteristics it judges this by is for the service to determine, and it does not disclose them to us. On an ordinary visit you will as a rule see no challenge. We cannot rule it out.

Legal basis. Storing it is strictly necessary for operation within the meaning of section 25(2) no. 2 TDDDG; no consent is required for it. For the associated processing, Article 6(1)(f) GDPR, with the legitimate interest in fending off attacks. Who Cloudflare is, where processing takes place and what arises in the course of it is set out in section 2.2.

3.3 Your privacy settings

On your first visit we ask you whether we may measure the reach of this website. We record how you decide so that the question does not reappear on every visit. What is measured is set out in section 4.

What is stored. Your decision, in a cookie named lexict-einwilligung. The content is the name of the service and whether you agreed or declined. No identifier, no name, no address.

Where the value goes. Nowhere. It is sent to our server with every request, because that is how cookies work, and it is not evaluated there. The decision is applied in the browser.

When nothing is stored at all. As long as you do not decide. Without a decision nothing is measured and the cookie is not created. If you dismiss the question without agreeing, you are not measured.

Legal basis. Storing it is strictly necessary within the meaning of section 25(2) no. 2 TDDDG in order not to ask you for the decision again on every visit. For the associated processing, Article 6(1)(c) GDPR, since consent has to be demonstrable under Article 7(1) GDPR.

Duration and deletion. The cookie expires after 180 days. After that we ask again. You can delete it at any time through your browser’s settings, or withdraw your decision using Privacy settings in the footer.

3.4 No analysis of your behaviour beyond the measurement of reach

Beyond the measurement of reach under section 4 we use no analytics services. There are no counting pixels, no profiling and no disclosure to advertising networks.

4. Measurement of reach

With your consent we measure the reach of this website using Umami. The instance is operated by lexICT GmbH, Eichenbrink 5, 30453 Hannover, Germany. In doing so it acts on our behalf and on our instructions under Article 28 GDPR. A data processing agreement is in place. No further provider is involved.

lexICT GmbH is a separate company connected to this firm through the people working in both.

What is recorded. The page visited, the referring page, the country, the screen size as well as the browser and the operating system. From these details and your IP address an identifier is derived that changes daily. The IP address itself is not stored, and no cookie is set for the measurement.

For what purpose. We want to improve our website further by collecting statistics on how it is used. Recognising individual people is neither intended nor possible with the details recorded.

Legal basis. Your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG.

Withdrawal. You can withdraw your consent at any time with effect for the future. The withdrawal takes effect immediately. Without consent the counting script is not executed. It is present in the document, but in a form the browser does not execute.

You will find the same control under Privacy settings in the footer of every page.

Duration and deletion. We keep the details recorded for one year. They are deleted after that. A longer period would add nothing to the question of which topics to go into more deeply.

5. Fonts and third-party content

All fonts are loaded from our own server. There is no connection to Google Fonts or any comparable service. We embed no maps, videos, social media buttons or other third-party content that would transfer data to third parties when the page is opened.

6. Mini games and best score of the week

Some pages carry a small game. It starts only when you click and runs entirely in your browser.

If a round ends with a result that would beat the best score of the current calendar week, a button appears. Only a click on it sends the result to our server. Without that click the number does not leave your device. Submitting is voluntary and has no effect whatsoever on your use of the website.

For the transmission itself your IP address and the usual connection data are processed, as with every visit to this website. They are not stored together with the result. What is stored is the number alone, the game it belongs to and the calendar week. The best score is therefore anonymous, and we cannot trace it back to you.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in an engaging presence and in making a result comparable with others.

The best score is deleted at the end of the calendar week. It is stored on our own server.

7. Processing when you contact us

7.1 Contact form

Through our contact form we collect your name, your email address and your message, and optionally your organisation and your telephone number. We also process the language of the page you were on and the time of submission.

The details are processed in order to answer your enquiry. The legal basis is Article 6(1)(b) GDPR where your enquiry is directed at entering into a mandate, and otherwise Article 6(1)(f) GDPR; our legitimate interest lies in answering your request.

Your details are not stored in any database of the website. They are transmitted solely as an email to our mailbox. We delete the data once the purpose of the processing has ceased. That is the case at the latest by the end of the following calendar year, unless a statutory retention obligation applies.

Technical protective measures. The form is secured against automated submissions. To that end we check several technical characteristics of the request when it is sent, and we process your IP address in order to limit the number of requests. In addition, your browser solves a small computational task before sending; we use ALTCHA for this.

All checks are purely local processing on our own server. Nothing is loaded from external servers, no data is transferred to third parties, and no cookies are set. ALTCHA too runs entirely with us; the task is generated and verified on our own server. Your IP address is held in memory for no more than fifteen minutes, is not written to any storage medium, and is not transmitted to our mailbox with your message. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in preventing misuse.

The task is sized so that you will not notice it; it merely makes automated bulk submission more expensive. The form therefore requires JavaScript. Without JavaScript you can reach us using the contact details on the same page.

The route your message takes. Every leg of that route is encrypted:

  1. Your browser hands the form over HTTPS to the network service named in section 2.2.
  2. From there the request travels to our server over a connection that is encrypted again.
  3. Our server hands the message to our mailbox at the email provider over an SMTP connection that is encrypted from the outset, with TLS 1.2 or above.
  4. We access that mailbox over encrypted connections only.

Two qualifications belong with this, because “encrypted throughout” would otherwise promise more than the route delivers. The encryption ends at each handover point and begins anew; the network service in section 2.2 and the email provider in section 7.3 therefore each see the content in clear text. And on our server the message sits in memory for the moment of processing before it is passed on; it is not written to any storage medium in the process.

The form does not provide end-to-end encryption, where only you and we could read the content. For documents that need that protection, please speak to us and we will agree another route.

After submitting you receive an automatic confirmation at the address you gave. It states that the enquiry arrived and when, but not the text of your message. We deliberately do not send the text back, so that a typing error in the address cannot deliver it to an uninvolved third party. What happens to that confirmation afterwards is no longer in our hands. Whether delivery to your provider is encrypted is decided by their configuration, not ours.

7.2 Email, telephone and fax

If you contact us by one of these routes, we process the details arising in order to deal with your request. The legal bases are Article 6(1)(b) and (f) GDPR. Here too we delete the data once the purpose has ceased, at the latest by the end of the following calendar year, unless a statutory retention obligation applies.

7.3 Email service provider

Our mailboxes and the delivery of form messages run through IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. IONOS processes the data on our behalf; a data processing agreement under Article 28 GDPR is in place. Transmission to our mailbox is encrypted in transit. The route through the form does not provide end-to-end encryption.

8. Video conferences and online meetings

For meetings we use Microsoft Teams on request. The provider for users in the European Economic Area is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.

What data arises. We process the details you need in order to take part and that you supply yourself: your display name, your email address where we invite you, and video, audio and text messages during the meeting. Added to that is technical data about the connection, such as IP address, device and network details, and the start and end of your participation.

Purposes and legal bases. We process this data in order to hold the meeting. The legal basis is Article 6(1)(b) GDPR where the meeting serves to initiate or carry out a mandate, and otherwise Article 6(1)(f) GDPR; our legitimate interest lies in coordinating quickly and independently of location.

No recording without agreement. We do not record meetings and produce no automatic transcripts or summaries. Where something else is wanted in an individual case, we obtain the consent of everyone involved beforehand under Article 6(1)(a) GDPR and say so at the start of the meeting. You may withdraw that consent at any time with effect for the future.

Professional secrecy. As lawyers we are bound to confidentiality under section 43a(2) BRAO. Section 43e BRAO permits us to use a service provider; we have bound Microsoft contractually to confidentiality and chosen the technical options so that content is not disclosed further than necessary. If you would prefer a different route for a meeting, please tell us; the telephone and a meeting at our offices are open at any time.

Processing on our behalf and transfers to third countries. Microsoft processes the data on our behalf on the basis of the Microsoft Data Protection Addendum under Article 28 GDPR. According to Microsoft’s commitments for the EU Data Boundary, processing takes place within the European Union. Where data is transferred to Microsoft Corporation in the United States, the transfer relies on the adequacy decision on the EU-U.S. Data Privacy Framework, under which Microsoft Corporation is certified; the standard contractual clauses apply in addition.

Erasure. We delete invitations, participation data and any text messages once the purpose has ceased, at the latest by the end of the following calendar year, unless a statutory retention obligation applies.

Further details from Microsoft are available at microsoft.com/privacystatement.

9. Disclosure of data

Beyond the service providers named above, your personal data is not disclosed to third parties. Exceptions may arise where

10. Social media presences

lexICT legal maintains presences on LinkedIn and Instagram. Our website merely links to them; simply opening our pages transfers no data to those platforms.

Controllership. Where we determine the means and purposes of processing, we process your data as controller. In all other cases the platform determines means and purposes and is itself the controller:

Details of the processing on the platforms, of retention periods and of the cookies used are set out in the providers’ privacy policies. The platforms transfer personal data to the United States and rely on the adequacy decision of the European Commission or on standard contractual clauses.

Interactions. If you follow our profiles, comment on or share posts, or write to us there, we process the details arising in order to answer your request and to present our firm. The legal basis is Article 6(1)(f) GDPR. Before contacting us through a platform, please consider whether you wish to send those details there or whether another route is more suitable.

Statistics. The platforms provide us with aggregated statistics on reach and interactions. We can draw conclusions about individuals only insofar as you interact with our profiles yourself. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in improving our content and how we communicate.

11. Your rights and right to lodge a complaint

As a data subject you have the right

An email to info@lexict.legal is sufficient to exercise your rights.

Where we process your personal data on the basis of consent under Article 6(1)(a) GDPR, you may withdraw that consent at any time without giving reasons. We may then no longer continue the processing based on it. The lawfulness of processing carried out up to the withdrawal is unaffected.

For the measurement of reach under section 4 the route is Privacy settings in the footer of every page. Withdrawing is therefore as easy as giving consent, as Article 7(3) sentence 4 GDPR requires.

13. Right to object

Where we process your personal data on the basis of legitimate interests under Article 6(1)(f) GDPR, you have the right under Article 21 GDPR to object on grounds relating to your particular situation. Where your objection is directed at direct marketing, the right to object applies without further reasons.

An email to info@lexict.legal is sufficient.

14. Data security

Encrypted transmission. This website is reachable over HTTPS only; a request over an unencrypted connection is redirected to the encrypted one. Your browser shows this with the padlock symbol in the address bar. TLS versions 1.2 and 1.3 are used; older versions are switched off.

The connection consists of two legs. Between your browser and the network service named in section 2.2, the certificate issued there applies. Between that service and our server there is a separate, automatically renewed certificate; this second leg is encrypted as well, and the authenticity of our server is verified in the process.

Sending the form. We hand the message from the contact form to our mailbox over an SMTP connection that is encrypted from the outset, likewise with TLS version 1.2 or above.

We deliberately do not state a key length. It is negotiated between browser and server and changes with both; a figure here would be wrong before long.

That encryption secures the transport, not the entire path from end to end. The network service named in section 2.2 and the email provider named in section 7.3 each process the content in clear text. Please bear that in mind before describing confidential detail to us through the form.

Beyond that we take appropriate technical and organisational measures to protect your data against loss, destruction, alteration and unauthorised access. We adapt these measures continuously to the state of the art.

15. Currency and amendment of this privacy information

This privacy information is dated August 2026. As our website develops or legal requirements change, it may become necessary to amend it. The current version is available on this page at any time.

Last updated: