Preamble
We, Chevalier Rechtsanwaltsgesellschaft mbH together with our subsidiaries (hereinafter collectively referred to as “the Organisation”, “we” or “us”), take the protection of your personal data seriously and wish to inform you here about data protection within our organisation.
Under the EU General Data Protection Regulation (Regulation (EU) 2016/679; hereinafter “GDPR”), there are obligations to ensure the protection of personal data of the person whose data is being processed (hereinafter also referred to as “customer”, “user”, “you” or “data subject”).
Where we, either alone or jointly with others, determine the purposes and means of processing, this particularly includes the obligation to inform you transparently about the type, scope, purpose, duration and legal basis of the processing (cf. Articles 13 and 14 GDPR). With this statement (hereinafter “Privacy Notice”), we inform you about the manner in which your personal data is processed by us.
A. General
1. Definitions
Following the model of Article 4 GDPR, the following definitions apply to this Privacy Notice:
“Personal data” (Art. 4(1) GDPR) means any information relating to an identified or identifiable natural person (“data subject”). An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, an online identifier, location data, or by reference to information concerning their physical, physiological, genetic, mental, economic, cultural or social identity. Identifiability can also be provided by linking such information or additional knowledge. The form or medium of the information is irrelevant (e.g. photographs, video or audio recordings can also contain personal data).
“Processing” (Art. 4(2) GDPR) means any operation or set of operations which is performed on personal data, whether or not by automated (i.e. technology-based) means. This includes, in particular, the collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment, combination, restriction, erasure or destruction of personal data, as well as the alteration of a target or purpose originally underlying the data processing.
“Controller” (Art. 4(7) GDPR) means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data.
“Third party” (Art. 4(10) GDPR) means any natural or legal person, public authority, agency or body other than the data subject, the controller, the processor, and persons who, under the direct authority of the controller or processor, are authorised to process personal data; this also includes other affiliated legal entities within a group.
“Processor” (Art. 4(8) GDPR) means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller, in particular in accordance with their instructions (e.g. IT service providers). In the sense of data protection law, a processor is not considered a third party.
“Consent” (Art. 4(11) GDPR) of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
2 Name and address of the controller
The entity responsible for the processing of your personal data within the meaning of Art. 4(7) GDPR is:
Chevalier Rechtsanwaltsgesellschaft mbH
Revaler Straße 28
10245 Berlin
Germany
Telephone: +49 (0) 30 – 555-786-821
E-mail: kontakt@chevalier.law
Further information about our organisation can be found in the legal notice on our website.
3 Contact details of the Data Protection Officer
For all questions and as a point of contact on data protection within our organisation, our company Data Protection Officer is available to you at any time. Their contact details are:
advokIT Datenschutz – a brand of Weißmann Datenschutz GmbH
Schirmerstraße 30
50823 Cologne
Postal address:
Kopernikusstraße 24
10245 Berlin
Website: https://www.advokit.de/
E-mail: Datenschutz[at]advokit.de
4 Legal bases of data processing
As a matter of law, the processing of personal data is generally prohibited and only permitted if the data processing falls under one of the following justifications:
Art. 6(1)(a) GDPR (“Consent”): where the data subject has freely given, in an informed and unambiguous manner, by a statement or by a clear affirmative action, their agreement to the processing of personal data concerning them for one or more specific purposes.
Art. 6(1)(b) GDPR: where processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Art. 6(1)(c) GDPR: where processing is necessary for compliance with a legal obligation to which the controller is subject (e.g. a statutory retention requirement).
Art. 6(1)(d) GDPR: where processing is necessary in order to protect the vital interests of the data subject or of another natural person.
Art. 6(1)(e) GDPR: where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
Art. 6(1)(f) GDPR (“Legitimate interests”): where processing is necessary for the purposes of the legitimate (in particular legal or economic) interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject (in particular where the data subject is a minor).
For the processing activities we carry out, we state the applicable legal basis in each case below. A processing activity may also be based on multiple legal bases.
General notes on the legal bases of data processing on this website
Where you have given your consent to the processing of your personal data, we process your personal data on the basis of Art. 6(1)(a) GDPR and, where special categories of data within the meaning of Art. 9(1) GDPR are processed, also on the basis of Art. 9(2)(a) GDPR. In the case of explicit consent to the transfer of personal data to third countries, the data processing is also based on Art. 49(1)(a) GDPR. Where you have consented to the storage of cookies or to access to information on your device (e.g. via device fingerprinting), the data processing is also based on Section 25(1) TDDDG. Consent may be withdrawn at any time.
Where your data is necessary for the performance of a contract or to take steps prior to entering into a contract, we process your data on the basis of Art. 6(1)(b) GDPR.
Furthermore, we process your data if this is necessary to comply with a legal obligation on the basis of Art. 6(1)(c) GDPR. Data processing may also be based on our legitimate interest under Art. 6(1)(f) GDPR. The relevant legal bases applicable in each case are indicated in the following paragraphs of this Privacy Policy.
5 Data erasure and retention period
For the processing activities we carry out, we state below how long the data is stored with us and when it is deleted or blocked. Unless an explicit retention period is specified below, your personal data will be deleted or blocked as soon as the purpose or legal basis for storage no longer applies. Your data will generally only be stored on our servers within the European Economic Area (EEA), subject to any transfer in accordance with the provisions set out below on “Cooperation with processors” and “Conditions for the transfer of personal data to third countries”.
However, storage may be extended beyond the stated period in the event of a (threatened) legal dispute with you or other legal proceedings, or where storage is required by statutory provisions to which we, as the controller, are subject (e.g. Section 257 HGB, Section 147 AO). Once the statutory retention period expires, the personal data will be blocked or deleted unless further storage is necessary and there is a legal basis for doing so.
6 Data security
We employ appropriate technical and organisational security measures to protect your data against accidental or deliberate manipulation, partial or complete loss, destruction or unauthorised access by third parties (e.g. TLS encryption for our website), taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing, as well as the risks of a data breach (including their probability and impact) to the data subject. Our security measures are continuously improved in line with technological developments.
7 Recipients of personal data
As part of our business activities, we work with various external entities. This sometimes requires the transfer of personal data to these external entities. We only pass on personal data to external parties where this is necessary for the performance of a contract, where we are legally obliged to do so (e.g. transfer of data to tax authorities), where we have a legitimate interest within the meaning of Art. 6(1)(f) GDPR in the transfer, or where another legal basis permits the transfer of data.
When using processors, we only transfer our customers’ personal data on the basis of a valid processing agreement. In the case of joint processing, a joint processing agreement is concluded.
8 Cooperation with processors
We use external service providers, both domestic and foreign, to conduct our business operations (e.g. in the fields of IT, logistics, telecommunications and marketing). These act only in accordance with our instructions and are contractually obliged, within the meaning of Art. 28 GDPR, to comply with data protection provisions.
Where personal data is transferred by us to our subsidiaries or received from our subsidiaries (e.g. for advertising purposes), this is done on the basis of existing processing arrangements.
9 Conditions for the transfer of personal data to third countries
In the context of our business relationships, your personal data may be transferred to or disclosed to third-party companies. These may also be located outside the EEA, i.e. in third countries. Such processing takes place exclusively for the fulfilment of contractual and business obligations and to maintain your business relationship with us. We inform you of the details of the transfer in each relevant case below.
Some third countries are recognised by the European Commission as having a level of data protection comparable to that in the EEA through so-called adequacy decisions (a list of these countries and copies of the adequacy decisions can be found on the European Commission’s website). In other third countries to which personal data may be transferred, there may be no consistently high level of data protection due to a lack of statutory provisions. Where this is the case, we ensure that data protection is adequately guaranteed, for example by binding corporate rules, standard contractual clauses of the European Commission for the protection of personal data, certificates, or recognised codes of conduct.
10 No automated decision-making (including profiling)
We do not intend to use any personal data collected from you for processes involving automated decision-making (including profiling).
11 No obligation to provide personal data
We do not make the conclusion of contracts with us dependent on you providing us with personal data in advance. As a customer, you are generally not legally or contractually obliged to provide us with your personal data; however, it may be that we can only offer certain services to a limited extent or not at all if you do not provide the necessary data. Should this be the case in relation to the products we offer, you will be informed separately.
12 Your rights
You may exercise your rights as a data subject concerning your processed personal data with us at any time using the contact details given above under A.(2). As a data subject, you have the right:
under Art. 15 GDPR to obtain information about your data processed by us. In particular, you may request information about the purposes of processing, the category of data, the categories of recipients to whom your data has been or will be disclosed, the planned retention period, the existence of the right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data if it was not collected by us, and the existence of automated decision-making, including profiling, and, where applicable, meaningful information about its details.
under Art. 16 GDPR to demand the immediate rectification of incorrect or completion of your data stored by us.
under Art. 17 GDPR to request the deletion of your data stored by us, unless processing is necessary for exercising the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of legal claims.
under Art. 18 GDPR to request the restriction of processing of your data, where the accuracy of the data is contested by you or the processing is unlawful.
under Art. 20 GDPR to receive your data, which you have provided to us, in a structured, commonly used and machine-readable format, or to request the transmission to another controller (“data portability”).
under Art. 21 GDPR to object to the collection of data in particular situations as well as to direct marketing (Art. 21 GDPR), provided the processing is based on Art. 6(1)(e) or (f) GDPR. This is particularly the case if the processing is not necessary for the performance of a contract with you. Unless the objection is to direct marketing, we ask that you provide reasons why we should not process your data as we have done. In the event of a justified objection, we will examine the matter and either cease or adjust the data processing, or demonstrate our compelling legitimate grounds for continuing the processing.
under Art. 7(3) GDPR to withdraw consent at any time – that is, your freely given, specific, informed and unambiguous statement or clear affirmative action indicating your agreement to the processing of the relevant personal data for one or more specific purposes – if you have given such consent. The withdrawal means that we may no longer continue the data processing based on this consent in the future.
under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data in our organisation.
under Art. 79 GDPR to seek judicial remedy before the ordinary courts and the labour courts, particularly if we refuse to act on the basis of a data subject’s request under Art. 12(5) GDPR.
13 Objection to marketing emails
We hereby expressly object to the use of contact details published as part of our legal notice obligation for the purpose of sending unsolicited advertising and information materials by third parties. The site operators expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for example by spam e-mails.
14 Changes to the Privacy Notice
In the course of further development of data protection law, as well as technological or organisational changes, our Privacy Notice is regularly reviewed for any need to adapt or supplement it. You will be informed of changes in particular on our website. This Privacy Notice is current as of May 2025.