Data Protection
Controller
Rechtsanwalt Frederico Eduardo Reichel (RAFER)
Katzbachstraße 18, 10965 Berlin, Germany
E-mail: info@rafer.de
General information
This Privacy Policy explains how personal data is processed when you visit this website or contact us. We process personal data in accordance with the GDPR.
Website hosting and server log files
This website is hosted by Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA, and delivered via its content delivery network (CDN). When accessing the website, technically necessary server log data is processed (e.g., IP address, date/time, requested page/file, referrer URL, browser/OS information) to deliver the website and to ensure security and technical stability. Legal basis: Art. 6(1)(f) GDPR (legitimate interests). As Netlify is based in the USA, personal data may be transferred to a third country; such transfers are based on the EU Standard Contractual Clauses (Art. 46 GDPR) or, where applicable, the EU-US Data Privacy Framework. Log data is stored only as long as necessary for security and troubleshooting and is then deleted.
Cookies
This website does not use analytics or marketing tracking. We may use technically necessary cookies (or similar technologies) required for basic functionality and security. If optional cookies are used in the future, we will request your consent via a cookie banner before setting them. Legal basis for technically necessary cookies: Art. 6(1)(f) GDPR. Legal basis for optional cookies (if used): consent.
Contact by e-mail / phone
If you contact us, we process the data you provide (e.g., name, contact details, content of your message) to handle your request. Legal basis: Art. 6(1)(b) GDPR (pre-contractual/contractual measures) and/or Art. 6(1)(f) GDPR.
The contact form on this website is processed via Netlify Forms (Netlify, Inc., USA); the data you enter in the form is transmitted there so that we can receive and handle your request. The statements above regarding third-country transfers and safeguards apply accordingly.
For e-mail communication we use Microsoft 365 (Exchange Online) provided by Microsoft Ireland Operations Ltd., One Microsoft Place, Dublin, Ireland. Processing generally takes place on servers within the EU (EU Data Boundary); transfers to third countries, in particular to Microsoft Corporation (USA), cannot be ruled out and are based on the EU Standard Contractual Clauses (Art. 46 GDPR) or the EU-US Data Privacy Framework.
Recipients / processors
We use service providers (processors) that process personal data only on our instructions and only as necessary. These are, in particular: Netlify, Inc. (USA) for hosting, content delivery (CDN) and processing of contact-form submissions; and Sanity AS (Oslo, Norway, EEA) as the content management system in which this website’s editorial content is maintained. Website content is generated statically at build time, so visitors do not connect directly to Sanity.
In addition, Microsoft Ireland Operations Ltd. (Ireland) processes personal data on our behalf for e-mail communication (Microsoft 365 / Exchange Online).
Data retention
Personal data is stored only as long as necessary for the purposes described and thereafter in accordance with statutory retention obligations where applicable.
Your rights
You have GDPR rights, in particular: access, rectification, erasure, restriction, data portability, and objection. If processing is based on consent, you may withdraw consent at any time with effect for the future.
Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). For Berlin: Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI).
