Privacy Policy
Privacy Policy
This privacy policy gives a concise overview of how personal data is processed on this website and in the core platform functions.
Controller and contact
- Controller
- Local Lawyer UG (haftungsbeschränkt)
- Address
- Alramstraße 27 b, 81371 München, Deutschland
- Hosting
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen (EU-Rechenzentrum, AV-Vertrag)
- Processors
- Hetzner Online GmbH (Hosting), Cloudflare Inc. (CDN/Sicherheit, EU-Standardvertragsklauseln), Stripe Payments Europe Ltd. (Zahlungen, AV-Vertrag), Zitadel Cloud (Auth, EU-Hosting)
- Data protection officer
- Local Lawyer – Datenschutz, Alramstraße 27 b, 81371 München, datenschutz@europeanlawyer.solutions
- Retention
- Anfrage- und Konto-Metadaten 36 Monate, Vertrags- und Rechnungsdaten 10 Jahre (AO/HGB), Server-Logs 90 Tage, Support-Tickets 24 Monate
1. Accounts, inquiries, and communication
If you create an account, sign in, submit an inquiry, or communicate with us or through the platform, we process the data you provide in order to operate the platform and handle your request. Depending on the context, the legal bases are Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.
2. Hosting and server logs
When you access the website, the hosting provider (Hetzner Online GmbH, EU data center, DPA in place) processes technical connection data such as IP address, time, requested page, browser and device information to deliver the site securely. Legal basis: Art. 6(1)(f) GDPR.
3. Technically necessary session cookie
For sign-in and account security, we only use the technically necessary session cookie ll.app_session. The legal basis for storing and reading the cookie is Section 25(2) TDDDG; the subsequent processing is generally based on Art. 6(1)(b) GDPR. The cookie is configured as HttpOnly with SameSite=Lax and expires after no more than 72 hours or is deleted when you sign out. We do not currently use non-essential analytics or marketing cookies.
4. Service providers
External processors (Hetzner Hosting, Cloudflare CDN/Security, Stripe Payments, Zitadel Auth) process data only on our instructions or own legal basis with EU SCCs where applicable (see MARKET_DEFINITIONS).
5. Retention periods
We retain personal data per MARKET_DEFINITIONS retention schedule: inquiry/account metadata 36 months, contract/invoice data 10 years (AO/HGB), server logs 90 days, support 24 months, or as required by law.
6. Your rights
Under the GDPR, you have in particular the following rights:
- Access to the personal data processed about them
- Rectification of inaccurate data or completion of incomplete data
- Erasure under the conditions of Art. 17 GDPR
- Restriction of processing
- Data portability
- Objection to processing based on legitimate interests
- The right to lodge a complaint with a supervisory authority