Practical training for all regulatory and organizational topics of modern data protection, security, and governance structures.
Direct legal support for data protection, AI Regulation, cybersecurity, whistleblower protection, and digital governance.
We, Scheja & Partners GmbH & Co. KG, appreciate your interest in a business relationship with our firm. Your privacy is our top priority. We take the protection of your personal data and its confidential treatment very seriously. Below, we inform you about the processing of your personal data in connection with the business relationship with you or your employer and about your data protection rights.
The controller responsible for data processing is:
Scheja & Partners GmbH & Co. KG (hereinafter: “we”)
Adenauerallee 136
D-53113 Bonn
Tel.: 0228-227 226-0
Email: Encrypted contact form
You can contact our Data Protection Officer as follows:
Scheja & Partners GmbH & Co. KG
Data Protection Officer
Adenauerallee 136
D-53113 Bonn
Email: Encrypted contact form
In connection with the business relationship with you or your employer, we only process personal data from you that is related to the business relationship. This may include:
Contact Data: First and last name, email address, and where applicable, postal address and telephone numbers
Business Relationship Data: Contents of inquiries, offers and invoices, communication in connection with the business relationship, documents
Contract Data: Service and product descriptions, contract documents
Web Meeting Data: Data in connection with web meetings, such as user data, audio and video data, contributions and content shared by you during the web meeting.
a. Preparation and Performance of Our Business Relationship
We process your personal data for the preparation and performance of the business relationship. The scope of data processing and the specific purposes depend on the respective contract.
Data processing is based on Article 6(1)(b) GDPR if a business relationship exists or is to be entered into with you personally. If, however, you are acting on behalf of a third party, in particular your employer, data processing is based on Article 6(1)(f) GDPR, provided this is compatible with your fundamental rights and freedoms.
b. Fulfillment of Legal Obligations
We also process personal data to comply with legal obligations to which we are subject. These may arise, for example, from commercial, tax, anti-money laundering, financial or criminal law. The purposes of processing arise from the respective legal obligation; in these cases, processing generally serves the purpose of complying with governmental control and disclosure obligations.
Data processing is carried out on the basis of Article 6(1)(c) GDPR.
c. Conducting Web Meetings
In connection with conducting video and audio conferences, we process data only to enable the smooth conduct of the web meeting. We conduct web meetings in the context of a contractual relationship or contract initiation with you (Article 6(1)(b) GDPR), in the context of a business relationship with the company for which you work (Article 6(1)(f) GDPR – in the interest of conducting joint projects and other business relationships), or where you have given us your informed consent in individual cases (Article 6(1)(a) GDPR).
Where we use Microsoft services for participation in web meetings, Microsoft is responsible for data processing. With regard to the processing of personal data by Microsoft, we refer to its privacy notice: https://privacy.microsoft.com/de-de/privacystatement.
You are not obligated to provide us with personal data. However, depending on the individual case, the provision of certain personal data is necessary for the preparation and performance of a business relationship. If you do not provide us with this personal data, we may not be able to perform the business relationship.
In addition to direct collection, we may also collect personal data in connection with the preparation and performance of our business relationship from other business partners, other companies/entities and, where applicable, your employer.
Within our organization, only those persons have access to your personal data who require it for the purposes stated in Section 4. We only disclose your personal data to external recipients if this is necessary for the performance of our business relationship or if another legal authorization exists.
External recipients may include:
Processors: Service providers we engage to provide services, for example in the areas of technical infrastructure and maintenance of our IT systems.
Public Authorities: Authorities and governmental institutions to which we must transmit personal data for legally mandatory reasons.
Private Entities: Private entities to which we transmit your personal data on the basis of a legal provision, for example attorneys, tax advisors, as well as other companies or entities contacted for the preparation and performance of the business relationship. In the case of web meetings, providers of such services as well as meeting participants may also be recipients.
In the context of IT services and IT infrastructure, we use service providers whose registered office is not located in the European Union or the European Economic Area. In doing so, except in legally permitted exceptional cases, we ensure prior to the transfer that either an adequate level of data protection exists at the recipient or that appropriate safeguards are in place. You may request an overview of the recipients in third countries and a copy of the appropriate or adequate safeguards. Please use the details under Section 1.
The personal data we collect for the business relationship will be deleted after expiry of the statutory retention obligation, unless we are obligated to store it for a longer period due to legal documentation obligations. In this case, we will delete your personal data after the legal obligation ceases to apply.
As a data subject, you have the following rights under the GDPR, provided the respective statutory requirements are met:
Access: You have the right to obtain information about the data concerning you that we process.
Rectification: You may request the rectification of inaccurate data concerning you. Furthermore, you may request the completion of incomplete data.
Erasure: In certain cases, you may request the erasure of your personal data.
Restriction of processing: In certain cases, you may request that we restrict the processing of your data.
Data portability: If you have provided us with data on the basis of a contract or consent, you may request to receive the data you have provided in a structured, commonly used and machine-readable format, or that we transmit it to another controller.
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out on the basis of Article 6(1)(f) GDPR. We will then no longer process this personal data for these purposes unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Exercising Your Rights: To exercise all of your aforementioned rights, please contact us using the contact details provided in Section 1. Please ensure that we can clearly identify you.
Right to Lodge a Complaint with a Supervisory Authority: You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you believe that the processing of personal data concerning you is unlawful.
Automated decisions in individual cases including profiling within the meaning of Article 22 GDPR do not take place in connection with our business relationship.
The most current version of this privacy policy applies.
Status: April 2022