Privacy policy
This privacy policy explains how personal data are processed when you visit wittenstein.law, contact the law firm or use a service that has been enabled for you. Merely visiting the website does not constitute consent to optional processing.
1. Controller
The controller within the meaning of the EU General Data Protection Regulation (GDPR) is Rechtsanwaltskanzlei JUDr. Gunther WITTENSTEIN, Overfeldweg 63, 51371 Leverkusen-Bürrig. You may contact the law firm by telephone on +49 (214) 500950-30, by fax on +49 (0) 214 50095033 or by eMail at Contact@WITTENSTEIN.law.
2. Data protection officer
Information on whether a data protection officer has been appointed and the applicable contact details: <<< FOLGT IN KÜRZE >>>
3. Principles and legal bases
Personal data are processed only where a statutory legal basis applies or valid consent has been given. Depending on the purpose, processing is based in particular on Article 6(1)(a), (b), (c) or (f) GDPR. Where special-category data are concerned, an additional basis under Article 9 GDPR is required. Any consent that is necessary is obtained separately, voluntarily and on a revocable basis.
4. Hosting, server logs and technical provision
When you access the website, the server processes technically necessary connection data. These may include your IP address, date and time, the page or file requested, referrer information and details of your browser, operating system and device. Processing serves delivery, stability, fault analysis and abuse prevention and is generally based on Article 6(1)(f) GDPR.
The current hosting provider, server location, processing agreement and specific retention period for server logs are: <<< FOLGT IN KÜRZE >>>
5. WordPress, Polylang and language preferences
The public website is provided using WordPress. Polylang assigns content to the available language versions. Technically necessary settings may be used to retain your selected language or ensure stable operation. Where information on your terminal equipment is accessed or stored, permissibility is governed by section 25 TDDDG; any associated processing of personal data is governed by the GDPR.
6. Consent management, cookies and similar technologies
Technically necessary cookies or comparable technologies may be used subject to section 25(2) TDDDG. Optional technologies, analytics and external media are activated only after any required consent has been obtained. The specific consent-management solution, active categories, providers and retention periods are: <<< FOLGT IN KÜRZE >>>
You may withdraw consent at any time with future effect through the privacy settings provided. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
7. Contact by form, eMail, telephone or fax
If you contact the law firm, it processes your contact details, the content of your message and supporting information required to deal with it. Where an enquiry concerns steps prior to a contract or instructions, Article 6(1)(b) GDPR applies; Article 6(1)(c) applies to legal obligations and Article 6(1)(f) generally applies to other enquiries. Confirming that you have read this policy is not blanket consent to indefinite storage.
8. Initial enquiries and conflict checks
To assess whether instructions can be accepted, identity, contact, party, opponent, factual and procedural data may be processed. This serves initial case assessment, conflict checking, compliance with professional duties and documentation. Processing is based in particular on Article 6(1)(b) and (c) GDPR and, where required, Article 6(1)(f) GDPR. An enquiry does not itself establish a lawyer-client relationship.
9. Client portal and user account
Authorised users may use the client portal to maintain master data, matters, questionnaires, messages and evidence. Account data, authentication and security events, communications, entries, documents, processing status and technical logs are processed for this purpose. Processing supports secure initial case handling or performance of instructions and is generally based on Article 6(1)(b) and (c) GDPR and legitimate security and documentation interests under Article 6(1)(f). Law-firm portal identities and WordPress identities are kept technically and organisationally separate.
10. Document uploads, identity evidence and special-category data
Enabled functions may permit documents, including identity documents, to be uploaded. Depending on the matter, these may contain health data or other special-category data. Such data are processed only where necessary for the establishment, exercise or defence of legal claims or under another applicable basis in Article 9(2) GDPR. The virus-scanning, OCR, conversion and document-analysis components actually used, their processing locations and retention periods are: <<< FOLGT IN KÜRZE >>>
11. Witti, Lexa and AI-supported functions
Within the publicly accessible online-divorce module, Lexa supports structured cost guidance, preliminary routing and application intake by using lawyer-defined rules and explanatory wording. When the module starts, a short-lived technical session containing the server-derived IP address, browser identifier, device category, language and timestamps is created to provide the service securely and prevent misuse. Additional form and contact data are processed only after you have acknowledged the privacy information and expressly requested that your specific enquiry be handled. This confirmation is not blanket consent for optional or unrelated purposes. At the present stage, no eMail is sent and your form entries are not disclosed to external AI providers. Prospect records that are not converted into a matter are deleted automatically after 30 days. Lexa does not make a legally binding decision or accept instructions.
Witti is prepared for internal source-bound research and review and is used only within expressly authorised law-firm functions. Where an authorised UGP review run involves external model providers, only previously redacted or pseudonymised legal working material without direct identifiers may be transmitted; every result remains subject to human and lawyer review. The final details of the providers, models, processing locations, legal bases, contractual and transfer mechanisms, retention periods and deletion rules actually used are: <<< FOLGT IN KÜRZE >>>
eSignPad is not enabled. Neither Lexa nor Witti makes a solely automated legal decision or accepts a mandate automatically.
12. Appointments and video conferences
Contact, appointment and, where necessary, matter data are processed to arrange and conduct appointments. The legal basis is Article 6(1)(b) GDPR or, outside a contractual context, Article 6(1)(f). Any external appointment or video provider, its integration and any third-country transfer are: <<< FOLGT IN KÜRZE >>>
13. Communications and eMail delivery
The law firm uses, in particular, Contact@WITTENSTEIN.law and Kontakt@WITTENSTEIN.law for eMail communications. Technical transport and synchronisation use Microsoft Exchange Online and Microsoft Graph where that connection has been approved and activated. Sender, recipient, subject, content, attachment, delivery, receipt and log data may be processed. The final contractual, storage, tenancy and transfer details for the mail service are: <<< FOLGT IN KÜRZE >>>
14. Recipients and processors
Where necessary and lawful for the relevant purpose, recipients may include courts, public authorities, opposing representatives, insurers, experts, translators, payment and postal service providers, and carefully selected providers of IT, hosting, practice software, communications, security and cloud services. Processors are bound in accordance with Article 28 GDPR. Information protected by professional secrecy is also subject to applicable professional and criminal-law confidentiality requirements.
The complete current list of recipient categories and processors used for the website, portals and law-firm operation is: <<< FOLGT IN KÜRZE >>>
15. Transfers to third countries
Transfers outside the European Union or European Economic Area take place only where the requirements of Articles 44 et seq. GDPR are met. Depending on the provider, an adequacy decision, appropriate safeguards or a statutory derogation may apply. The transfer routes and safeguards that apply to services actually used are: <<< FOLGT IN KÜRZE >>>
16. External media, social networks, analytics and security services
External maps, videos, social-media content, statistics, analytics, anti-spam or security services may be used only in accordance with their actual technical configuration and any required consent or other legal basis. The services currently active, their providers, purposes, legal bases and retention periods are: <<< FOLGT IN KÜRZE >>>
17. Retention and deletion
Personal data are retained only for as long as necessary for the relevant purpose. Statutory retention requirements, professional documentation duties, the establishment, exercise or defence of legal claims, and security incidents may require longer retention. The binding retention and deletion schedule for website enquiries, conflict checks, accounts, communications, documents, security logs and backups is: <<< FOLGT IN KÜRZE >>>
18. Your rights
Where the statutory conditions are met, you have rights of access under Article 15 GDPR, rectification under Article 16, erasure under Article 17, restriction under Article 18, data portability under Article 20 and objection under Article 21. Consent may be withdrawn at any time with future effect under Article 7(3).
19. Right to complain
You may lodge a complaint with a data-protection supervisory authority under Article 77 GDPR. In North Rhine-Westphalia, you may contact the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, Postfach 20 04 44, 40102 Düsseldorf, Germany, eMail poststelle@ldi.nrw.de, www.ldi.nrw.de.
20. Automated decisions
No decision based solely on automated processing within the meaning of Article 22 GDPR currently takes place that produces legal effects concerning you or similarly significantly affects you. Legal classification, acceptance of instructions and material processing decisions remain subject to review by a lawyer or another expressly authorised person.
21. Data security
The website uses TLS encryption. Technical and organisational measures appropriate to the relevant risk are also applied, including access, session, logging, integrity, backup and recovery controls. Complete elimination of all risks inherent in internet data transmission cannot be guaranteed.
22. Currency and changes
This privacy policy is dated August 2026. It is updated when processing, providers, applicable law or technical functions change. The current authoritative German version is available at www.wittenstein.law/datenschutzerklaerung/.
