Data privacy

Privacy Policy

1. Privacy at a Glance

General Information

The following information provides a brief overview of what happens to your personal data when you visit this website. Personal data is any information that can be used to identify you personally. For detailed information on data protection, please refer to the privacy policy provided below.

Data Collection on This Website

Who Is Responsible for Data Collection on This Website?

The data processing on this website is carried out by the website operator. You can find the operator’s contact details in the “Information on the Responsible Party” section of this privacy policy.

How Do We Collect Your Data?

Your data is collected in two ways:

  • Directly: You provide us with your data, for example by entering information into a contact form.
  • Automatically: Other data is collected automatically or upon your consent when you visit the website by our IT systems. This mainly includes technical data (e.g., internet browser, operating system, or time of the page request). The collection of this data occurs automatically as soon as you enter this website.

For What Purposes Do We Use Your Data?

Some of the data is collected to ensure the error‑free provision of the website. Other data may be used to analyze your user behavior.

What Rights Do You Have Regarding Your Data?

You have the right to obtain information free of charge about the origin, recipients, and purpose of your stored personal data at any time. You also have the right to request the correction or deletion of this data. If you have given your consent to data processing, you may revoke this consent at any time for the future. Furthermore, under certain circumstances you have the right to request the restriction of processing of your personal data. In addition, you are entitled to lodge a complaint with the competent supervisory authority.

For any further questions regarding data protection, you may contact us at any time.

Analysis Tools and Third-Party Tools

When visiting this website, your surfing behavior may be statistically evaluated. This is done primarily with the help of so‑called analysis programs.

Detailed information about these analysis programs can be found in the following sections of this privacy policy.


2. Hosting

We host the content of our website with the following provider:

Strato

The provider is Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin (hereinafter “Strato”). When you visit our website, Strato collects various logfiles including your IP addresses.

For further information, please refer to Strato’s privacy policy at:
https://www.strato.de/datenschutz/

The use of Strato is based on Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in a reliable presentation of our website. If a corresponding consent has been obtained, the processing is carried out solely on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, insofar as the consent includes the storage of cookies or the access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TTDSG. This consent can be revoked at any time.


3. General Information and Mandatory Information

Data Protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations as well as this privacy policy.

When you use this website, various personal data are collected. Personal data are any data that can personally identify you. This privacy policy explains which data we collect and for what purposes we use them. It also explains how and for what purpose this occurs.

Please note that data transmission over the Internet (e.g., communication via e‑mail) may have security vulnerabilities. A complete protection of the data against access by third parties is not possible.

Information on the Responsible Party

The party responsible for data processing on this website is:

TABAK Steuerberatung
Fatma Özkul
Owner / Tax Advisor

Augustaanlage 27
D‑68165 Mannheim

Telephone: +49 (0) 621 702 89 450
E‑mail: info@steuerberater-tabak.com

The responsible party is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data (e.g., names, e‑mail addresses, etc.).

Data Retention Period

Unless a specific retention period is stated elsewhere in this privacy policy, your personal data will remain with us until the purpose for which the data was processed no longer applies. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted provided that we do not have any other legally permissible reasons for storing your personal data (e.g., tax or commercial retention periods); in the latter case, the deletion will occur once those reasons no longer apply.

General Information on the Legal Bases for Data Processing on This Website

If you have consented to the data processing, we process your personal data on the basis of Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, in the case that special categories of data according to Art. 9 para. 1 GDPR are processed. In the case of explicit consent for the transfer of personal data to third countries, the data processing is also carried out on the basis of Art. 49 para. 1 lit. a GDPR. If you have consented to the storage of cookies or access to information on your device (e.g., via device fingerprinting), the data processing is additionally based on § 25 para. 1 TTDSG. This consent can be revoked at any time. If your data are necessary for the fulfillment of a contract or the execution of pre-contractual measures, we process your data on the basis of Art. 6 para. 1 lit. b GDPR. Furthermore, we process your data if this is required for compliance with a legal obligation on the basis of Art. 6 para. 1 lit. c GDPR. Data processing may also be based on our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR. The respective legal bases applicable in each individual case are explained in the following paragraphs of this privacy policy.

Note on Data Transfer to the USA and Other Third Countries

We use, among other things, tools from companies located in the USA or other countries that are not considered safe from a data protection perspective. When these tools are active, your personal data may be transferred to these third countries and processed there. Please note that in these countries a level of data protection comparable to that in the EU cannot be guaranteed. For example, US companies are obliged to hand over personal data to security authorities without you being able to take legal action. It cannot therefore be ruled out that US authorities (e.g., intelligence agencies) may process, analyze, and permanently store your data located on US servers for surveillance purposes. We have no influence over these processing activities.

Withdrawal of Your Consent to Data Processing

Many data processing operations are only possible with your explicit consent. You can revoke any consent you have given at any time. The lawfulness of the data processing up to the time of the revocation remains unaffected by the revocation.

Right to Object Against Data Collection in Special Cases as well as Against Direct Advertising (Art. 21 GDPR)

IF THE DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6 PARA. 1 LIT. e OR f GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT, FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. YOU CAN FIND THE RESPECTIVE LEGAL BASIS FOR THE PROCESSING IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING PROTECTIVE REASONS THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING IS NECESSARY FOR THE ESTABLISHMENT, EXERCISE OR DEFENSE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21 PARA. 1 GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT ADVERTISING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH ADVERTISING PURPOSES; THIS ALSO APPLIES TO PROFILING, SO FAR AS IT IS RELATED TO SUCH DIRECT ADVERTISING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT ADVERTISING PURPOSES (OBJECTION PURSUANT TO ART. 21 PARA. 2 GDPR).

Right to Lodge a Complaint with the Competent Supervisory Authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, place of work, or the place of the alleged violation. This right to complain is without prejudice to any other administrative or judicial remedies.

Right to Data Portability

You have the right to receive the data that we have processed automatically on the basis of your consent or in fulfillment of a contract in a commonly used, machine‑readable format. Should you request the direct transfer of your data to another controller, this will only be carried out insofar as it is technically feasible.

Right to Access, Deletion, and Rectification

Within the framework of the applicable statutory provisions, you have the right to free-of-charge information about your stored personal data, its origin, the recipients, and the purpose of the data processing, and if applicable, the right to rectification or deletion of this data. For further questions regarding personal data, you may contact us at any time.

Right to Restrict Processing

You have the right to request the restriction of the processing of your personal data. You can contact us at any time to exercise this right. The right to restrict processing exists in the following cases:

  • If you contest the accuracy of your personal data stored by us, we usually require time to verify this. During the verification period, you have the right to request that the processing of your personal data be restricted.
  • If the processing of your personal data is unlawful, you can request restriction of data processing instead of deletion.
  • If we no longer require your personal data but you need it to exercise, defend, or assert legal claims, you have the right to request restriction of processing instead of deletion.
  • If you have objected pursuant to Art. 21 para. 1 GDPR, a balancing of your interests and ours must be carried out. As long as it is not clear which interests prevail, you have the right to request restriction of the processing of your personal data.

If you have restricted the processing of your personal data, these data – apart from their storage – may only be processed with your consent or for the establishment, exercise, or defense of legal claims, for the protection of the rights of another natural or legal person, or for reasons of an important public interest of the European Union or a member state.

SSL or TLS Encryption

For security reasons and to protect the transmission of confidential content such as orders or inquiries that you send to us as the website operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the change in the browser’s address field from “http://” to “https://” and by the padlock symbol in your browser.

When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Right to Object to Unsolicited Advertising Emails

Any use of the contact data published in accordance with the imprint obligation for sending unsolicited advertising and information material is hereby objected to. The website operators expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information (e.g., through spam e‑mails).


4. Data Collection on This Website

Cookies

[Information about cookies is typically provided here, but the original text does not include further details.]

Server Log Files

The provider of the pages automatically collects and stores information in so‑called server log files, which your browser automatically transmits to us. This includes:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • IP address

These data are not merged with other data sources.

The collection of these data is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error‑free display and optimization of its website – for which the server log files must be collected.

Contact Form

If you contact us via the contact form, the information you provide in the form—including the contact details you enter—is stored by us for the purpose of processing your inquiry and for any follow‑up questions. We will not share this data without your consent.

The processing of these data is based on Art. 6 para. 1 lit. b GDPR, insofar as your inquiry is related to the fulfillment of a contract or necessary for the implementation of pre‑contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if it was obtained; the consent can be revoked at any time.

The data you enter in the contact form will remain with us until you request deletion, revoke your consent to storage, or the purpose for storing the data no longer applies (e.g., after your inquiry has been processed). Mandatory legal provisions – in particular retention periods – remain unaffected.

Inquiry by E‑mail, Telephone, or Fax

If you contact us by e‑mail, telephone, or fax, your inquiry – including all personal data (name, inquiry) that results therefrom – will be stored and processed by us for the purpose of addressing your request. We will not pass on this data without your consent.

The processing of these data is based on Art. 6 para. 1 lit. b GDPR, insofar as your inquiry is related to the fulfillment of a contract or necessary for the implementation of pre‑contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if it was obtained; the consent can be revoked at any time.

The data you send to us via inquiries will remain with us until you instruct us to delete it, revoke your consent to storage, or the purpose for storing the data no longer applies (e.g., after your inquiry has been processed). Mandatory legal provisions – in particular statutory retention periods – remain unaffected.


5. Social Media

Facebook

This website integrates elements of the social network Facebook. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, the collected data may also be transferred to the USA and other third countries.

An overview of the Facebook social media elements can be found here:
https://developers.facebook.com/docs/plugins/?locale=en_GB

If the social media element is active, a direct connection is established between your device and the Facebook server. As a result, Facebook receives the information that you have visited this website along with your IP address. If you click the Facebook “Like-Button” while logged into your Facebook account, the content of this website can be linked to your Facebook profile. This means that Facebook may associate your visit to this website with your user account. Please note that as the provider of the pages, we do not have any knowledge of the content of the transmitted data or its use by Facebook. For further information, please refer to Facebook’s privacy policy at:
https://www.facebook.com/privacy/explanation

If consent has been obtained, the use of the above service is based on Art. 6 para. 1 lit. a GDPR and § 25 TTDSG. This consent can be revoked at any time. If no consent has been obtained, the service is used based on our legitimate interest in achieving as comprehensive a visibility as possible in social media.

If personal data is collected on our website with the help of the tool described here and passed on to Facebook, both we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). This joint responsibility is limited solely to the collection of the data and its transmission to Facebook. The subsequent processing by Facebook is not part of the joint responsibility. Our joint obligations have been set forth in an agreement on joint processing. The text of the agreement can be found at:
https://www.facebook.com/legal/controller_addendum
According to this agreement, we are responsible for providing the privacy information when using the Facebook tool and for the GDPR‑compliant secure implementation of the tool on our website. Facebook is responsible for the data security of its products. Data subject rights (e.g., requests for information) regarding the data processed by Facebook can be exercised directly with Facebook. If you exercise your rights with us, we are obliged to forward your requests to Facebook.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum,
https://de-de.facebook.com/help/566994660333381, and
https://www.facebook.com/policy.php.

Twitter

This website integrates functions of the Twitter service. These functions are provided by Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland.

If the social media element is active, a direct connection is established between your device and the Twitter server. Twitter thereby receives information about your visit to this website. By using Twitter and the “Retweet” function, the websites you have visited are linked to your Twitter account and made known to other users. Please note that as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by Twitter. For further information, please refer to Twitter’s privacy policy at:
https://twitter.com/de/privacy

If consent has been obtained, the use of the above service is based on Art. 6 para. 1 lit. a GDPR and § 25 TTDSG. This consent can be revoked at any time. If no consent has been obtained, the service is used based on our legitimate interest in achieving as comprehensive a visibility as possible in social media.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:
https://gdpr.twitter.com/en/controller-to-controller-transfers.html.

You can change your privacy settings on Twitter in your account settings at:
https://twitter.com/account/settings.

Instagram

This website integrates functions of the Instagram service. These functions are provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

If the social media element is active, a direct connection is established between your device and the Instagram server. As a result, Instagram receives information about your visit to this website.

If you are logged into your Instagram account, by clicking the Instagram button you can link the content of this website to your Instagram profile. This allows Instagram to associate your visit to this website with your user account. Please note that as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by Instagram.

If consent has been obtained, the use of the above service is based on Art. 6 para. 1 lit. a GDPR and § 25 TTDSG. This consent can be revoked at any time. If no consent has been obtained, the service is used based on our legitimate interest in achieving as comprehensive a visibility as possible in social media.

If personal data is collected on our website with the help of the tool described here and passed on to Facebook or Instagram, both we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). This joint responsibility is limited solely to the collection of the data and its transmission to Facebook or Instagram. The subsequent processing by Facebook or Instagram is not part of the joint responsibility. Our joint obligations have been set forth in an agreement on joint processing. The text of the agreement can be found at:
https://www.facebook.com/legal/controller_addendum.
According to this agreement, we are responsible for providing the privacy information when using the Facebook/Instagram tools and for the GDPR‑compliant secure implementation of the tools on our website. Facebook is responsible for the data security of its products. Data subject rights (e.g., requests for information) regarding the data processed by Facebook or Instagram can be exercised directly with Facebook.

The data transfer to the USA is based on the standard contractual clauses of the European Commission. For details, please see:
https://www.facebook.com/legal/EU_data_transfer_addendum, https://help.instagram.com/519522125107875, and https://de-de.facebook.com/help/566994660333381.

Further information on this matter can be found in Instagram’s privacy policy:
https://instagram.com/about/legal/privacy/.

6. Plugins and Tools

    YouTube with Enhanced Data Protection
    This website embeds videos from the YouTube website. The operator of these pages is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

    We use YouTube in the enhanced data protection mode. According to YouTube, this mode ensures that YouTube does not store any information about the visitors of this website before they watch the video. However, the transfer of data to YouTube partners is not necessarily excluded by the enhanced data protection mode. Thus, YouTube—regardless of whether you watch a video—establishes a connection to the Google DoubleClick network.

    As soon as you start a YouTube video on this website, a connection to YouTube’s servers is established. In doing so, the YouTube server is informed which of our pages you have visited. If you are logged into your YouTube account, you enable YouTube to directly associate your browsing behavior with your personal profile. You can prevent this by logging out of your YouTube account.

    Furthermore, after starting a video, YouTube may store various cookies on your device or use comparable recognition technologies (e.g., device fingerprinting). In this way, YouTube can obtain information about the visitors of this website. This information is used, among other things, to collect video statistics, improve user-friendliness, and prevent fraudulent activities.

    In some cases, additional data processing operations may be triggered after a YouTube video is started, over which we have no control.

    The use of YouTube is in the interest of an attractive presentation of our online offerings. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. If appropriate consent has been obtained, the processing is carried out solely on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, insofar as the consent covers the storage of cookies or the access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time.

    Further information on data protection at YouTube can be found in their privacy policy at:
    https://policies.google.com/privacy?hl=de.

    Google Fonts (Local Hosting)
    This site uses so‑called Google Fonts for the uniform display of typefaces, which are provided by Google. The Google Fonts are installed locally. No connection is made to Google’s servers.

    Further information on Google Fonts can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy:
    https://policies.google.com/privacy?hl=de.

    Font Awesome (Local Hosting)
    This site uses Font Awesome for the uniform display of typefaces. Font Awesome is installed locally. No connection is made to servers of Fonticons, Inc.

    Further information on Font Awesome can be found in the privacy policy for Font Awesome at:
    https://fontawesome.com/privacy.

    Source: https://www.e-recht24.de