Privacy Policy
Privacy Policy.
Last updated: July 21, 2026
1. Controller
The controller responsible for data processing on this website and in connection with our legal services is: Rechtsanwalt Patrick van den Hövel, van den hoevel LAW, Wiegnerstr. 24, 85716 Unterschleißheim, Germany. Phone: +49 (170) 634 80 19. E-mail: info@vandenhoevel.com. A data protection officer has not been designated, as there is no legal obligation to do so.
2. Legal Framework and Professional Secrecy
We process personal data in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), the German Telecommunications Digital Services Data Protection Act (TDDDG) and the professional rules applicable to attorneys. As an attorney admitted in Germany, Patrick van den Hövel is bound by professional secrecy (§ 43a (2) BRAO, § 2 BORA, § 203 German Criminal Code). All data relating to a mandate is additionally protected by these confidentiality obligations.
3. Hosting and Server Log Files
This website is hosted by STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany, on servers located in Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with the hosting provider. When you access this website, the web server automatically records server log files: IP address of the requesting device, date and time of the request, requested resource, HTTP status, transferred data volume, referrer URL, browser type/version and operating system. This data is processed to deliver the website, to ensure its stability and security, and to detect and defend against attacks. Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in the secure and reliable operation of the website). Log files are deleted automatically within the retention period set by the hosting provider and are not merged with other data sources.
4. Encryption
This website uses SSL/TLS encryption. Data you transmit to us via this website cannot be read by third parties in transit.
5. Cookies and Consent Management
This website uses cookies and comparable technologies. Strictly necessary cookies are used on the basis of § 25 (2) TDDDG and Art. 6 (1) lit. f GDPR. All other cookies and technologies that are not strictly necessary are used only with your prior consent pursuant to § 25 (1) TDDDG and Art. 6 (1) lit. a GDPR.
For obtaining, documenting and managing your consent we use the consent management platform CookieYes (CookieYes Limited, 3 Warren Yard, Warren Park, Milton Keynes MK12 5NW, United Kingdom). CookieYes stores your consent status in a cookie on your device and logs the consent decision (including a truncated/hashed IP address, date and time, and the consent status). Legal basis: Art. 6 (1) lit. c GDPR (proof of consent, Art. 7 (1) GDPR) and Art. 6 (1) lit. f GDPR. The United Kingdom is subject to an adequacy decision of the European Commission (Art. 45 GDPR). You can change or withdraw your consent at any time with effect for the future via the cookie settings icon on this website.
6. Contact, Intake Form and E-mail
If you contact us by telephone, e-mail or via the intake form on this website, we process the data you provide (name, e-mail address, subject matter, content of your message, and any further information you choose to share) exclusively to handle your enquiry and for possible follow-up questions. Legal bases: Art. 6 (1) lit. b GDPR (initiation of a mandate / pre-contractual measures) and Art. 6 (1) lit. f GDPR (proper handling of correspondence). E-mail dispatch is handled via our own domain infrastructure hosted in Germany.
Please note: contacting us does not by itself create an attorney-client relationship, and no retainer is established until expressly confirmed by us. Please refrain from sending highly confidential case details before a mandate has been confirmed. Enquiry data is erased once the enquiry has been dealt with conclusively, unless statutory retention obligations or the documentation duties of an attorney require longer storage.
7. Data Processing in the Course of Legal Mandates
When you retain us, we process the personal data required to provide our legal services: identification and contact data, mandate and case-related data, correspondence, billing data and, where relevant to the matter, data relating to third parties (e.g. opposing parties, witnesses, courts and authorities). Where necessary for the establishment, exercise or defence of legal claims, this may include special categories of personal data (Art. 9 (2) lit. f GDPR).
Legal bases: Art. 6 (1) lit. b GDPR (performance of the mandate), Art. 6 (1) lit. c GDPR (statutory obligations, e.g. under BRAO, tax law and anti-money-laundering law) and Art. 6 (1) lit. f GDPR. Data is disclosed to third parties only where necessary for the mandate (e.g. courts, authorities, opposing counsel, experts, translators) or where we are legally obliged to do so — always subject to attorney-client privilege.
Retention: mandate files are retained for six years after the end of the calendar year in which the mandate was concluded (§ 50 BRAO); documents relevant under commercial and tax law are retained for up to ten years (§ 147 AO, § 257 HGB). Data is erased once all retention periods have expired.
8. Third-Party Content Loaded by This Website
Google Fonts. This website loads fonts from Google servers (fonts.googleapis.com / fonts.gstatic.com; Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, USA). When fonts are loaded, your browser transmits your IP address and technical request data to Google. Legal basis: Art. 6 (1) lit. f GDPR (uniform, correct presentation of the website). Transfers to the USA are safeguarded by Google LLC’s certification under the EU-US Data Privacy Framework (Art. 45 GDPR).
Cloudflare CDN (cdnjs). Style and script libraries (Tailwind CSS, Font Awesome) are delivered via cdnjs.cloudflare.com (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). Your IP address is transmitted to Cloudflare in the process. Legal basis: Art. 6 (1) lit. f GDPR (secure and efficient delivery of technically required resources). Cloudflare, Inc. is certified under the EU-US Data Privacy Framework (Art. 45 GDPR).
Optimole image optimization. Images on this website are optimized and delivered via the CDN of Optimole (Vertigo Studio SRL, Romania, EU). When images are loaded, your IP address and technical request data are processed to deliver the appropriate image size. Legal basis: Art. 6 (1) lit. f GDPR (fast and bandwidth-efficient image delivery).
Videos shown on this website are hosted locally on our own server; no data is transmitted to external video platforms.
9. No Tracking, Analytics or Advertising
This website does not use analytics services, tracking pixels, advertising networks or social media plugins. We do not profile visitors, and we do not sell or share personal data for marketing purposes.
10. Your Rights
You have the following rights regarding your personal data: access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR) and withdrawal of any consent given, at any time with effect for the future (Art. 7 (3) GDPR). Note that the rights of access and erasure may be limited by attorney-client privilege where data of third parties processed within a mandate is concerned (§ 29 BDSG).
Right to object (Art. 21 GDPR): Where processing is based on Art. 6 (1) lit. e or f GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular with the authority competent for us: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.
11. Automated Decision-Making; Obligation to Provide Data
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. You are not obliged to provide personal data to use this website. For the performance of a mandate, the provision of certain data is necessary; without it, we cannot provide our services.
12. Data Security and Changes to This Policy
We maintain appropriate technical and organisational measures pursuant to Art. 32 GDPR, including encrypted transmission, German/EU-based hosting and access controls. We review and update this privacy policy as legal or technical circumstances change. The current version is always available on this page.