Datenschutz

Privacy Policy at s&w Tax Consulting

Datenschutzerklärung

We appreciate your interest in our company. This GDPR Privacy Policy explains how we handle data. Data protection is a top priority for the management of s&w Steuerberatungsgesellschaft mbH. Our website can generally be used without providing any personal data. If you wish to use specific services through our site, data processing may be necessary. If there is no legal basis for this, we will obtain your consent beforehand.

The processing of personal data—such as name, address, email address, or phone number—is carried out in accordance with the General Data Protection Regulation (GDPR) and the local data protection regulations applicable to s&w Steuerberatungsgesellschaft mbH. In this statement, we provide information about the nature, scope, and purpose of the data we collect, use, and process. We also explain the rights of data subjects in a manner that is understandable within the context of the GDPR.

As the data controller, s&w Steuerberatungsgesellschaft mbH has implemented numerous technical and internal security measures to safeguard the data on this website as effectively as possible. Nevertheless, data transmissions over the Internet may be subject to security vulnerabilities. Complete protection is therefore never guaranteed. For this reason, data subjects may also submit their data by other means, such as by telephone.

1. Begriffsbestimmungen

Our GDPR Privacy Policy uses the terminology of the General Data Protection Regulation. To ensure the text remains easy to read, we provide brief explanations of the most important terms:

  • a) Personal data: any information relating to an identified or identifiable natural person.
  • b) Data subject: the person whose data is being processed.
  • c) Processing: any operation or set of operations performed on data, such as collection, storage, modification, retrieval, disclosure, erasure, or destruction.
  • d) Restriction of processing: Stored data is flagged so that it is not used further for the time being.
  • e) Profiling: the automatic analysis of data to assess or predict personal characteristics.
  • f) Pseudonymization: Data is processed in such a way that it can no longer be linked to a specific individual without additional information.
  • (g) Controller: the entity that determines the purposes and means of processing.
  • (h) Data processor: an entity that processes data on behalf of the data controller.
  • (i) Recipient: an entity to which data is disclosed.
  • (j) Third party: any entity other than the data subject, the controller, the processor, and the respective authorized persons.
  • k) Consent: the data subject’s voluntary and unambiguous agreement.

2. Name and address of the data controller

The controller, as defined by the General Data Protection Regulation, other EU data protection laws, and other data protection-related regulations, is:

Thomas Wirtz

s&w Steuerberatungsgesellschaft mbH

Neuer Zollhof 2, D-40221 Düsseldorf

info@suw-steuerberatung.de

3. Name und Anschrift des Datenschutzbeauftragten

The data protection officer for the data controller is:

Thomas Wirtz

s&w Steuerberatungsgesellschaft mbH

Neuer Zollhof 2, D-40221 Düsseldorf

info@suw-steuerberatung.de

Any affected individual may contact our Data Protection Officer at any time with questions regarding data protection.

4. Cookies

Our website uses cookies. Cookies are small text files that are stored on a device via a web browser.

Many cookies contain a cookie ID. This ID is a unique identifier. It helps identify and recognize browsers and servers. This allows visited pages and servers to distinguish a user’s browser from other browsers.

Cookies make our website more user-friendly. For example, they help us recognize users so they don’t have to re-enter their information every time they visit. A typical example is the shopping cart in an online store.

You can block or delete cookies at any time through your browser settings. This is possible in all common browsers. If cookies are disabled, some features of the website may no longer be fully available.

To manage cookies and similar technologies, such as tracking pixels or web beacons, we use the Consent Tool at Real Cookie Banner. For more information, visit https://devowl.io/de/rcb/datenverarbeitung/.

The legal basis for processing in this context is Article 6(1)(c) of the GDPR and Article 6(1)(f) of the GDPR. Our legitimate interest is the management of the cookies and similar technologies we use, as well as the associated consents.

Providing this information is neither required by contract nor necessary for a contract. You are not obligated to provide this information. If you do not provide this information, we will not be able to manage your consents.

5. Collection of General Data and Information

Whenever a data subject or an automated system accesses our website, general data and information are collected. This data is stored in the server log files.

The following, among other things, can be recorded:

  • Browser Type and Browser Version
  • Operating System
  • the page from which you accessed our website
  • the subpages you visit
  • Date and time of access
  • IP address
  • Internet Service Provider
  • Similar data on defending against attacks

This data does not allow us to draw any direct conclusions about the individual concerned. We need it to deliver content correctly, improve the website, maintain system stability, and assist authorities in the event of a cyberattack. The anonymous log file data is stored separately from all other personal data.

6. Registrierung auf unserer Internetseite

Individuals concerned can register on our website. The data provided during registration depends on the specific form.

We use the data you provide solely for internal purposes and for our own use. We may share it with one or more third-party service providers, such as a package delivery company, if this is necessary for internal processing.

When you register, we also store the IP address assigned by your Internet service provider, as well as the date and time of registration. This helps us prevent misuse and investigate potential criminal offenses.

The purpose of registration is to offer registered users content or services that are available only to logged-in users. Registered users can have their data changed or deleted at any time.

Upon request, we will inform each data subject of the data we have stored. We will correct or delete data upon request, provided that no legal retention requirements prevent us from doing so.

7. Abonnement unseres Newsletters

Users can subscribe to our newsletter on our website. The data provided during registration is specified in the respective form.

You will only receive the newsletter if you have a valid email address and sign up to receive it. We will send a confirmation email to the first email address you provide using the double opt-in process. This is to verify that the owner of the email address has actually authorized receipt of the newsletter.

When you log in, we also store the IP address of the device you’re using, as well as the date and time of the login. This is necessary so that we can later prove any potential misuse of your email address.

We use the data provided during registration solely for the purpose of sending the newsletter. We may also notify subscribers via email about the operation of the service or any changes, such as updates to the newsletter content or technical changes. We do not share this data with third parties.

You can unsubscribe from the newsletter at any time. You can also revoke your consent to the storage of your data at any time. You’ll find a link for this in every newsletter. Alternatively, you can unsubscribe directly on the website or notify us in another way.

8. Newsletter-Tracking

Our newsletters contain web beacons. A web beacon is a small graphic in HTML emails that allows us to track when they are opened and clicked.

This allows us to see if and when an email was opened and which links were clicked. This data helps us improve the newsletter and better tailor future content to the data subject’s interests.

The data collected in this manner will not be shared with third parties. The separate consent granted through the double opt-in process may be revoked at any time. We consider unsubscribing from the newsletter to be a revocation of consent.

9. Kontaktmöglichkeit über die Internetseite

Our website contains the information required by law to enable you to contact us quickly and communicate directly with us, including an email address.

If a data subject contacts us by email or through a contact form, we automatically store the data provided. We use this data solely to process the inquiry or to get in touch. We do not share this data with third parties.

10. Kommentarfunktion im Blog auf der Internetseite

On a blog on our website, users can leave individual comments on specific posts.

When a user posts a comment, we store and publish not only the comment itself but also the time it was posted and the username selected. We also log the IP address assigned by the Internet service provider.

IP addresses are stored for security purposes and to prevent legal violations through comments. Data will not be shared with third parties unless required by law or necessary for our legal defense.

11. Routinemäßige Löschung und Sperrung von personenbezogenen Daten

We store personal data only for as long as necessary for the purpose for which it was collected or as required by laws and regulations.

If the purpose no longer applies or a statutory time limit expires, the data is routinely blocked or deleted.

12. Rights of Data Subjects Under the GDPR

a) Recht auf Bestätigung

Any data subject may request confirmation from us as to whether data concerning them is being processed.

b) Recht auf Auskunft

Every data subject has the right to receive, free of charge, information about the data stored and a copy of that information. This includes, in particular:

  • die Verarbeitungszwecke
  • The categories of data processed
  • the recipients or categories of recipients, including those in third countries or at international organizations
  • the planned retention period or the criteria for determining it
  • the right to rectification, erasure, restriction of processing, or objection
  • the right to file a complaint with a supervisory authority
  • the source of the data, if we did not collect it directly from the data subject
  • the existence of automated decisions, including profiling, as well as clear information about their logic, scope, and impact
  • whether data has been transferred to a third country or an international organization, and what appropriate safeguards apply

c) Recht auf Berichtigung

Incorrect information will be corrected immediately upon request. Incomplete information may be supplemented, including through a supplementary statement.

d) Right to erasure

Data subjects may request that data be deleted immediately if one of the legal grounds applies and the processing is not necessary. This applies, among other things, when:

  • the data is no longer needed for that purpose
  • consent is revoked and there is no other legal basis
  • An objection has been filed pursuant to Article 21 of the GDPR, and there are no overriding legitimate grounds
  • the data was processed unlawfully
  • There is a legal obligation to delete the data
  • the data was collected in connection with information society services

If data is stored by us and is to be deleted, the data subject may contact a member of our staff. We will then ensure that the data is deleted. If the data has been made public, we will take appropriate measures—taking into account available technology and costs—to inform other data controllers of the request for deletion.

e) Recht auf Einschränkung der Verarbeitung

Processing may be restricted if:

  • the accuracy of the data is disputed
  • the processing is unlawful, but deletion is not requested
  • we no longer need the data, but the data subject needs it to assert claims
  • An appeal has been filed, and it has not yet been determined whose interests take precedence

f) Recht auf Datenübertragbarkeit

Data subjects may receive their data in a structured, commonly used, and machine-readable format and have it transferred to another controller if the legal requirements are met. If technically feasible, the data may also be transferred directly from one controller to another.

g) Recht auf Widerspruch

Data subjects may object to the processing at any time on grounds relating to their particular situation, if the processing is based on Article 6(1)(e) or (f) of the GDPR. This also applies to profiling based on those provisions.

If we process data for direct marketing purposes, you may object to this use at any time. This also applies to profiling, insofar as it is related to direct marketing.

Objections may also be possible for scientific or historical research purposes or for statistical purposes, provided that no public interest stands in the way.

To exercise the right to object, the data subject may contact any employee. In the context of information society services, the right to object may also be exercised through technical means that meet appropriate specifications.

h) Automatisierte Entscheidungen im Einzelfall einschließlich Profiling

No one may be subject solely to an automated decision, including profiling, if that decision produces legal effects or similarly significantly affects the person, unless the statutory exceptions apply.

If such decisions are permitted, we will take appropriate measures to protect rights and freedoms, including, at a minimum, the right to have a person intervene, to present one’s own point of view, and to challenge the decision.

i) Recht auf Widerruf einer datenschutzrechtlichen Einwilligung

Consent to the processing of personal data may be withdrawn at any time. To withdraw consent, the data subject may contact a member of staff.

13. Datenschutz bei Bewerbungen und im Bewerbungsverfahren

We collect and process applicants’ data for the purpose of handling the application process. This also applies to electronic applications, such as those submitted via email or a web form.

When we enter into a contract with a job applicant, we store the data provided to administer the employment relationship. If no contract is concluded, we delete the application documents two months after the rejection, provided there are no other legitimate interests that would prevent us from doing so.

Such a legitimate interest could be, for example, the burden of proof in proceedings under the General Equal Treatment Act.

14. Datenschutzbestimmungen zu Einsatz und Verwendung von Facebook

The controller has integrated Facebook components into this website. Facebook is a social network.

A social network is an online community where users can communicate with one another and share content. Among other features, Facebook allows users to create profiles, post photos, and send friend requests.

Facebook is operated by Facebook, Inc., 1 Hacker Way, Menlo Park, CA 94025, USA. For individuals outside the United States or Canada, Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, is the data controller.

When a page with a Facebook plugin is loaded, the browser automatically downloads a version of the Facebook component from Facebook. This allows Facebook to determine which subpage was visited.

If the user is logged into Facebook, Facebook can associate the visit to our website with that user’s account. If a Facebook button is clicked or a comment is posted, this information is associated with the Facebook account and stored.

If you do not want your information to be shared, you should log out of your Facebook account before visiting our website.

You can find Facebook’s Data Policy at https://de-de.facebook.com/about/privacy/. That page also includes information about privacy settings. In addition, there are apps that can be used to prevent data from being sent to Facebook.

15. Google AdSense Privacy Policy

The website operator has integrated Google AdSense into this website. Google AdSense is an online service for advertising on third-party websites. The ads are selected algorithmically to match the content of the respective page. Google AdSense enables interest-based targeting based on user profiles.

Betreibergesellschaft der Google-AdSense-Komponente ist die Alphabet Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

The purpose of this component is to display advertisements on our website. Google AdSense places a cookie on the data subject’s device. This allows Alphabet Inc. to analyze the use of our website.

When a page containing a Google AdSense component is accessed, data for online advertising and commission billing is transmitted to Alphabet Inc. This includes personal data such as the IP address. Among other things, this data helps track visitors and clicks and enables commission billing.

As described above, cookies can be blocked or deleted in your browser. In that case, Alphabet Inc. will not set any cookies either. Cookies that have already been set can be deleted at any time.

Google AdSense also uses web beacons. These allow Alphabet Inc. to detect when a web page has been opened and which links have been clicked. Web beacons are also used to analyze visitor traffic.

Data and information, including your IP address, may be transferred to the United States, where it may be stored and processed. Alphabet Inc. may also disclose this data to third parties under certain circumstances.

For more information, visit https://www.google.de/intl/de/adsense/start/.

16. Google Analytics Privacy Policy

The data controller has integrated Google Analytics with the anonymization feature on this website. Google Analytics is a web analytics service. It collects data about visitors’ behavior on websites.

The information collected includes, among other things, the referring page, the subpages visited, the frequency of visits, and the duration of visits. We use web analytics primarily to improve the website and to evaluate the cost-effectiveness of online advertising.

Betreibergesellschaft der Google-Analytics-Komponente ist die Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

For web analytics, we use the add-on _gat._anonymizeIp. This shortens and anonymizes the IP address when access originates from the EU or the EEA.

Google Analytics sets a cookie. This allows Google to analyze how our website is used. When a page containing a Google Analytics component is accessed, data—including the IP address—is transmitted to Google. This data is stored in the United States and may be shared by Google with third parties.

We also use a browser add-on that prevents data collection by Google Analytics. The add-on can be downloaded and installed at https://tools.google.com/dlpage/gaoptout. If the system is later deleted, formatted, or reinstalled, the add-on must be set up again.

For more information and Google’s privacy policy, visit https://www.google.de/intl/de/policies/privacy/ and https://www.google.com/analytics/terms/de.html. For more information about Google Analytics, visit https://www.google.com/intl/de_de/analytics/.

Use of Script Libraries and Google Web Fonts

To ensure that content is displayed correctly and in a visually appealing way across different browsers, we use script libraries and font libraries such as Google Web Fonts. These are also stored in the browser’s cache for faster loading.

If the browser does not support or blocks Google Web Fonts, content will be displayed in a default font. When such a library is accessed, a connection is established with the provider. In the process, data may be collected. You can find Google’s privacy policy at https://www.google.com/policies/privacy/.

Verwendung von Google Maps

This website uses the Google Maps API to display geographic information. When you use Google Maps, Google also processes data regarding your use of the map features.

For more information about how Google processes data, please see the Google Privacy Policy. You can also change your personal settings in the Privacy Center.

17. Datenschutzbestimmungen zu Einsatz und Verwendung von Google Remarketing

Google Remarketing is a feature of Google AdWords. It allows you to show ads to users who have previously visited the company’s website. This makes it possible to create user-specific ads that are relevant to their interests.

Google Remarketing sets a cookie. This allows Google to recognize visitors to our website when they later visit sites in the Google Display Network. Google automatically recognizes the browser and can use data such as the IP address or browsing behavior to serve ads tailored to the user’s interests.

The cookie is used to track which pages you visit. In the process, data is also transmitted to Google in the United States and stored there. Google may share this data with third parties.

You can block or delete cookies as described above. You can also opt out of interest-based advertising through Google’s ad settings at www.google.de/settings/ads.

For more information, visit https://www.google.de/intl/de/policies/privacy/.

18. Datenschutzbestimmungen zu Einsatz und Verwendung von Google+

The data controller has embedded the Google+ button on this website. Google+ is a social network.

When a page with a Google+ button is accessed, the browser downloads an image of that button from Google. This allows Google to determine which subpage was visited.

If the user is logged in to Google+, Google can associate the visit to our website with the Google+ account. If a Google+ button is used and a Google+1 recommendation is made, Google stores this information and makes it publicly available in accordance with the accepted terms and conditions.

The recommendation may appear alongside the name of the Google+1 account, the profile photo, and other information in other Google services, such as in search results or in connection with advertisements. Google may also link the visit to other stored data.

If you do not want your data to be transmitted, you should log out of your Google+ account before visiting our website.

For more information, visit https://www.google.de/intl/de/policies/privacy/ and https://developers.google.com/+/web/buttons-policy.

19. Privacy Policy Regarding the Use of Google AdWords

The data controller has integrated Google AdWords into this website. Google AdWords is an advertising service provided by Google. It enables ads to appear in search results and on the Google Display Network.

With Google AdWords, advertisers can specify keywords in advance. An ad then appears only when a user clicks on a relevant search result. In the Display Network, ads are distributed to thematically relevant pages using an algorithm.

Google AdWords sets a conversion cookie. It remains valid for 30 days and is not used to identify the data subject. It allows us to track whether, after clicking on an ad, certain subpages—such as a shopping cart—were visited.

This allows us and Google to see whether an AdWords ad led to a purchase or was abandoned. The resulting data is used to generate visitor statistics and improve ads.

Here, too, you can block or delete cookies in your browser. You can also manage interest-based advertising at www.google.de/settings/ads.

For more information, visit https://www.google.de/intl/de/policies/privacy/.

20. Datenschutzbestimmungen zu Einsatz und Verwendung von LinkedIn

The controller has integrated LinkedIn into this website. LinkedIn is an online social network for professional connections and establishing new business contacts.

The operator is LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. LinkedIn Ireland, Privacy Policy Issues, Wilton Plaza, Wilton Place, Dublin 2, Ireland, is responsible for data protection matters outside the United States.

When a page with a LinkedIn plug-in is loaded, the browser downloads a rendering of the LinkedIn component from LinkedIn. This allows LinkedIn to determine which subpage was visited.

If the individual is logged in to LinkedIn, LinkedIn can associate the visit to our website with that account. If a LinkedIn button is used, LinkedIn stores this information in the user’s account.

LinkedIn offers settings for email messages, text messages, and ads at https://www.linkedin.com/psettings/guest-controls. Partners such as Quantcast, Google Analytics, BlueKai, DoubleClick, Nielsen, Comscore, Eloqua, and Lotame may set cookies. These cookies can be opted out at https://www.linkedin.com/legal/cookie-policy.

You can find LinkedIn’s privacy policy at https://www.linkedin.com/legal/privacy-policy. The cookie policy is available at https://www.linkedin.com/legal/cookie-policy.

21. Datenschutzbestimmungen zu Einsatz und Verwendung von Twitter

The data controller has integrated Twitter into this website. Twitter is a multilingual, public microblogging service. Users can post and share tweets—that is, short messages—on the platform.

Tweets are accessible to everyone, including users who are not logged in. Tweets are also displayed to followers. Followers are users who follow another user. Through hashtags, links, and retweets, Twitter reaches a wide audience.

Betreibergesellschaft von Twitter ist die Twitter, Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA.

When a page with a Twitter button is accessed, the browser automatically downloads a rendering of the Twitter component. This allows Twitter to determine which subpage was visited. The purpose of this integration is to share content, raise awareness of the website, and increase traffic.

If the user is logged in to Twitter, Twitter can associate the visit to our website with that account. If a Twitter button is used, the transmitted data and information are associated with the Twitter account and stored.

If you do not want this information to be transmitted, you should log out of your Twitter account before visiting our website.

You can find Twitter’s privacy policy at https://twitter.com/privacy?lang=de.

22. Datenschutzbestimmungen zu Einsatz und Verwendung von Xing

The controller has integrated Xing components into this website. Xing is an online social network for professional contacts and establishing new business connections. Users can create a personal profile there. Companies can create company profiles or post job openings.

Betreibergesellschaft von Xing ist die XING SE, Dammtorstraße 30, 20354 Hamburg, Deutschland.

When a page containing a Xing component is loaded, the browser downloads a rendering from Xing. This allows Xing to determine which subpage was visited.

If the user is logged in to Xing, Xing can associate the visit to our website with that account. If a Xing button—such as the “Share” button—is used, Xing stores this information in the user’s account.

If you do not want your data to be transmitted, you should log out of your Xing account before visiting our website.

You can find Xing’s published privacy policy at https://www.xing.com/privacy. Information about the XING Share button is available at https://www.xing.com/app/share?op=data_protection.

23. Datenschutzbestimmungen zu Einsatz und Verwendung von YouTube

The controller has embedded YouTube components on this website. YouTube is a video platform where video publishers can upload clips for free and other users can view, rate, and comment on them.

YouTube is operated by YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. YouTube, LLC is a subsidiary of Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

When you visit a page that contains a YouTube video, the browser automatically downloads a rendering of the YouTube component. This allows YouTube and Google to determine which subpage was visited.

If the user is logged in to YouTube, YouTube and Google can associate the visit to the subpage with the user’s account. If you do not want this information to be transmitted, you should log out of your YouTube account before visiting our website.

You can find YouTube’s and Google’s privacy policies at https://www.google.de/intl/de/policies/privacy/.

24. Zoom Privacy Policy

Below, we provide information about the processing of personal data in connection with the use of Zoom.

We use Zoom for conference calls, online meetings, video conferences, and webinars. Zoom is a service provided by Zoom Video Communications, Inc., which is headquartered in the United States.

Note: When you visit the Zoom website, the provider of Zoom is responsible for it. You only need to visit the site if you want to download the software for Zoom.

You can also use Zoom by entering the meeting ID and other access information directly in the Zoom app.

If you do not want to or are unable to use the app, the basic features are also available via a browser version on the website at Zoom.

When using Zoom, various types of data are processed depending on how the site is used. These include, in particular:

  • User Information: First Name, Last Name, Phone Number, Email Address, Password, Profile Picture
  • Meeting metadata: Topic, description, participants’ IP addresses, device and hardware information
  • For recordings: MP4 file containing video, audio, and presentation; M4A file containing audio; text file of the chat
  • When dialing in by phone: phone number, country name, start and end times, and, if applicable, other connection details such as the device’s IP address
  • Text, audio, and video data: chat messages and questions, as well as image and audio transmission via microphone and camera

If you are participating in the meeting, you must provide at least your name.

We use Zoom to host online meetings. If we plan to record a meeting, we will let you know in advance and, if necessary, obtain your consent. The recording will also be displayed in the app.

If it is necessary to document the results, we can record chat content. However, this is not usually the case. For webinars, we can also include participants’ questions in the recording and follow-up materials.

If you are registered with Zoom, reports on online meetings can be stored for up to 12 months at Zoom. This includes meeting metadata, phone dial-in data, questions and answers from webinars, and the survey feature.

Automated decision-making as defined in Article 22 of the GDPR is not used.

For employees of Mustermann GmbH, § 26 of the German Federal Data Protection Act (BDSG) serves as the legal basis. If data is not necessary for the employment relationship but is nonetheless required for the use of Zoom, we rely on Art. 6(1)(f) of the General Data Protection Regulation (GDPR). Our legitimate interest in this case is the effective conduct of online meetings.

If meetings take place within the context of contractual relationships, the legal basis is Article 6(1)(b) of the GDPR. If no contractual relationship exists, the legal basis is Article 6(1)(f) of the GDPR.

As a general rule, we do not disclose personal data from online meetings to third parties, unless such data is specifically intended for disclosure. Content from online meetings is often intentionally shared with customers, prospective customers, or third parties.

The provider of Zoom necessarily obtains knowledge of the aforementioned data to the extent provided for in our data processing agreement with Zoom.

Zoom is a service provided by a U.S.-based provider. As a result, data processing also takes place in a third country. We have entered into a data processing agreement with the provider in accordance with Article 28 of the GDPR.

An adequate level of data protection is achieved through the EU Standard Contractual Clauses. In addition, we have configured Zoom so that online meetings are hosted only in data centers located in the EU, the EEA, or safe third countries such as Canada or Japan.

You have the right to access the data concerning you. You may submit a request for access to us at any time.

If a request for information is not submitted in writing, we may require proof of identity to ensure that you are who you claim to be.

In addition, you have the right to rectification, erasure, restriction of processing, and objection in accordance with legal requirements.

There is also a right to data portability.

As a general rule, we delete personal data when further storage is no longer necessary. A need for storage may exist, for example, in connection with contractual services or warranty and guarantee claims. In cases where there are statutory retention requirements, we will not delete the data until the retention period has expired.

You may file a complaint with a data protection supervisory authority regarding our processing of personal data.

25. Legal Basis for Processing

Article 6(1)(a) of the GDPR serves as our legal basis when we obtain consent for a specific purpose.

Article 6(1)(b) of the GDPR applies when processing is necessary for the performance of a contract or for taking steps prior to entering into a contract, such as in connection with deliveries, services, or inquiries regarding our products and services.

Article 6(1)(c) of the GDPR applies when we are required to process data due to a legal obligation, such as tax obligations.

Article 6(1)(d) of the GDPR may apply in rare cases where vital interests must be protected, for example, following an accident at our facility.

Article 6(1)(f) of the GDPR applies to processing operations based on legitimate interests, provided that the interests, fundamental rights, and fundamental freedoms of the data subject do not override those interests. The European legislator has expressly mentioned such an interest, for example, when the data subject is a customer of the controller.

26. Legitimate Interests in Processing

If the processing is based on Article 6(1)(f) of the GDPR, our legitimate interest is the conduct of our business operations for the benefit of all employees and shareholders.

27. Retention Period for Personal Data

The retention period is determined by the applicable statutory retention period. Once this period has expired, we routinely delete the data, provided it is no longer necessary for the performance or initiation of a contract.

28. Statutory or contractual requirements regarding the provision of data

Please note that the provision of personal data is, in some cases, required by law—for example, under tax regulations—or may be required under contractual provisions, such as when providing information about a contractual partner.

In order to enter into a contract, it may be necessary for a data subject to provide us with data. Without this data, the contract may not be able to be concluded under certain circumstances.

Before providing any data, the data subject should contact one of our employees. Our employee will then explain, on a case-by-case basis, whether the provision of data is required by law or contract, whether there is an obligation to provide it, and what the consequences of failure to do so would be.

29. Existence of Automated Decision-Making

As a responsible company, we do not use automated decision-making or profiling.

This Privacy Policy was created using the Privacy Policy Generator provided by DGD Deutsche Gesellschaft für Datenschutz GmbH, which serves as an external data protection officer in Munich, in cooperation with data protection attorney Christian Solmecke.

Änderung unserer Datenschutzbestimmungen

We reserve the right to update this Privacy Policy from time to time to ensure that it remains in compliance with current legal requirements or to reflect changes to our services. The new version will then apply to your next visit.

Q&A

Question: Who is responsible for processing personal data, and how can I contact them?

Answer: The person responsible is Thomas Wirtz, s&w Steuerberatungsgesellschaft mbH, Neuer Zollhof 2, D-40221 Düsseldorf. For data protection inquiries, the data subject may also contact the data protection officer at this address or by email at info@suw-steuerberatung.de.

Question: What data is automatically collected when you visit the website?

Short answer: When you visit the website, general data and information may be stored in server log files, such as browser type and version, operating system, referrer, subpages visited, date and time of access, IP address, Internet service provider, and similar security-related information. This data is used primarily to ensure the proper delivery of content, to optimize the website, to safeguard the technology, and to prevent security threats.

Question: Can cookies be blocked or deleted?

Answer: Yes. The data subject can prevent cookies from being set at any time through the settings of the web browser being used and can delete cookies that have already been set using the browser or other software programs. However, the privacy policy notes that if cookies are disabled, not all features of the website may be fully functional. The Consent Tool Real Cookie Banner is also used to manage cookies and similar technologies.

Question: What rights do data subjects have under the privacy policy?

Answer: Data subjects have, among other things, the right to confirmation, access, rectification, erasure, restriction of processing, data portability, and objection, as well as the right to withdraw their consent under data protection law at any time. In addition, data subjects have the right not to be subject to decisions based solely on automated processing, including profiling, provided that the legal requirements are met. To exercise these rights, data subjects may contact employees of s&w Steuerberatungsgesellschaft mbH.

Question: Are third-party services used, and could data be transmitted in the process?

Answer: Yes. The privacy policy lists, among others, Facebook, Google AdSense, Google Analytics, Google Remarketing, Google+, Google AdWords, LinkedIn, Twitter, Xing, YouTube, Google Web Fonts, Google Maps, and Zoom. Depending on the service, personal data such as IP addresses, usage data, or information about visited subpages may be transmitted to the respective providers, in some cases also to the U.S. The privacy policy also describes ways to reduce data transfers, such as by logging out of social networks before visiting the site, adjusting cookie settings in the browser, or using the providers’ specific opt-out or settings pages.

GDPR Cookie Consent with Real Cookie Banner