Skip to content
← Back to Home

Privacy Policy

Last updated: February 2026

1. Controller

The controller responsible for data processing on this website is:

APOS Legal Rechtsanwälte
Fatih Bektas
Am Paradeplatz 20
69126 Heidelberg, Germany
Email: info@apos.legal
Phone: +49 6221 32144-70

2. Overview of Data Processing

We take the protection of your personal data seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations, in particular the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

3. Hosting

This website is hosted on the infrastructure of Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. When you access the website, Vercel processes technically necessary data (including IP addresses) as a data processor.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and efficient website operation).

Data transfer to the US: The basis for data transfer to the USA are the Standard Contractual Clauses (SCCs) of the EU Commission.

For more information, see Vercel’s Privacy Policy.

4. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR) — You may request information about whether and which personal data we process about you.
  • Right to rectification (Art. 16 GDPR) — You may request correction of inaccurate data.
  • Right to erasure (Art. 17 GDPR) — You may request deletion of your data, subject to legal retention obligations.
  • Right to restriction of processing (Art. 18 GDPR) — You may request that we restrict the processing of your data.
  • Right to data portability (Art. 20 GDPR) — You may request your data in a structured, machine-readable format.
  • Right to object (Art. 21 GDPR) — You may object to data processing based on legitimate interests at any time.
  • Right to withdraw consent (Art. 7(3) GDPR) — You may withdraw any consent you have given at any time.
  • Right to lodge a complaint — You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence.

The competent supervisory authority is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
www.baden-wuerttemberg.datenschutz.de

5. Contact Form

When you submit our contact form, the following data is collected:

  • Name (required)
  • Email address (required)
  • Company name (optional)
  • Phone number (optional)
  • Type of dispute (optional)
  • Estimated dispute value (optional)
  • Your message (required)

Purpose: Processing your inquiry, assessing your legal matter, and contacting you.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures at your request) and Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries).

Storage duration: Your data will be stored until the purpose of the inquiry has been fulfilled. If a mandate arises, statutory retention periods of up to 10 years apply (§ 50 BRAO, § 257 HGB).

Recipient: Your contact form data is transmitted to and stored by Brevo (Sendinblue), see Section 8.

6. Google Analytics

This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).

Google Analytics uses cookies and similar technologies to analyze how you use our website. The information generated (including your truncated IP address) is transmitted to and stored on Google servers. We use Google Analytics with IP anonymization enabled, meaning your IP address is shortened within the EU/EEA before transmission.

Purpose: Analyzing website usage to improve our content and services.

Legal basis: Art. 6(1)(a) GDPR (your consent via the cookie banner).

Data transfer to the US: Google participates in the EU-US Data Privacy Framework. We have also concluded Standard Contractual Clauses (SCCs) with Google.

Opt-out: You can prevent data collection by Google Analytics by withdrawing your consent via the cookie settings on our website or by installing the Google Analytics opt-out browser add-on.

For more information, see Google’s Privacy Policy.

7. Fonts (Self-Hosted)

This website uses self-hosted fonts stored on our own server. No connection to external font services (such as Google Fonts) is established when you visit our pages. Your IP address is not transmitted to third-party font providers.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in uniform and appealing presentation). Since the fonts are served locally, no personal data is shared with third parties for this purpose.

8. Brevo (Sendinblue)

We use Brevo (formerly Sendinblue), provided by Brevo SAS, 106 boulevard Haussmann, 75008 Paris, France, for the following purposes:

  • Contact form processing: Your inquiry data is stored as a contact in our Brevo account.
  • Email notifications: When you submit the contact form, a notification email is sent to us via Brevo’s SMTP service.
  • Appointment scheduling: We use Brevo’s scheduling tool for online appointment booking.
  • Website tracking: Brevo may use cookies to track your interactions with our website for marketing analytics purposes.

Legal basis: Art. 6(1)(b) GDPR (contact form: pre-contractual measures), Art. 6(1)(a) GDPR (tracking: your consent via cookie banner).

We have concluded a Data Processing Agreement (DPA) with Brevo. Brevo stores data within the EU.

For more information, see Brevo’s Privacy Policy.

9. Cookies

Our website uses cookies. Cookies are small text files stored on your device that enable analysis of your use of the website.

9.1 Strictly Necessary Cookies

These cookies are essential for the website to function and cannot be disabled. They include cookies for storing your cookie consent preferences.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest).

9.2 Analytics Cookies (Google Analytics)

These cookies help us understand how visitors interact with our website by collecting information anonymously.

Legal basis: Art. 6(1)(a) GDPR (your consent). These cookies are only set after you give consent via our cookie banner.

9.3 Marketing Cookies (Brevo)

These cookies are used to track visitors and measure the effectiveness of our communications.

Legal basis: Art. 6(1)(a) GDPR (your consent). These cookies are only set after you give consent via our cookie banner.

CookieProviderPurposeDurationType
cookie_consentThis websiteStores your cookie preferences1 yearNecessary
_gaGoogleDistinguishes users2 yearsAnalytics
_ga_*GoogleMaintains session state2 yearsAnalytics
_gidGoogleDistinguishes users24 hoursAnalytics
sib_cuidBrevoVisitor tracking13 monthsMarketing

You can manage your cookie preferences at any time by clicking the “Cookie Settings” link in our website footer.

10. SSL/TLS Encryption

This website uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content. You can recognize an encrypted connection by the “https://” prefix in the address bar of your browser.

11. Changes to This Privacy Policy

We reserve the right to update this privacy policy to reflect changes in our data processing practices or legal requirements. The current version is always available on this page.