Privacy
Information on the processing of personal data in connection with this website.
1. General Information
The protection of your personal data and the confidential treatment of your information are important to us.
This Privacy Policy informs you about which personal data are processed when you use our website, the purposes for which such processing takes place, the legal bases on which it is carried out, and the rights to which you are entitled under the General Data Protection Regulation (“GDPR”) and supplementary statutory provisions.
Personal data means any information relating to an identified or identifiable natural person. This may include, in particular, names, contact details, IP addresses, communication content, and information that you provide to us in connection with an inquiry or the initiation of a legal mandate.
This Privacy Policy applies to our website, including the contact options provided through it and, where applicable, to protected administration areas.
Last updated: 21 August 2026
2. Controllers
The controllers responsible for the processing of personal data in connection with this website are:
Dr. iur. Levent Bilgi & Fatih Selçuk Hazan
Hammer Str. 19
40219 Düsseldorf
Germany
Email: info@bilgihazan.com
To the extent that both professionals jointly determine the purposes and means of processing personal data, they act as joint controllers within the meaning of Art. 26 GDPR.
The final designation and address of the controller must correspond to the information provided in the Legal Notice and to the actual corporate and professional structure of the law firm.
3. Data Protection Officer
A data protection officer will only be identified in this Privacy Policy if a data protection officer has been appointed for the law firm.
If no data protection officer has been appointed and there is no statutory obligation to appoint one, all data protection inquiries may be addressed directly to the controllers named above at info@bilgihazan.com.
4. Technical Provision of the Website
Each time our website is accessed, technically necessary information is processed in order to deliver the requested content to your browser or device.
In particular, the following data may be processed:
- IP address of the requesting device,
- date and time of access,
- requested URL or file,
- amount of data transferred,
- referrer URL,
- browser type and browser version,
- operating system,
- device and connection information,
- HTTP status codes,
- technical error and security information.
The processing takes place in particular for the following purposes:
- provision of the website,
- ensuring a stable connection,
- ensuring the functionality of the website,
- detection and prevention of misuse and attacks,
- error diagnosis,
- ensuring the security of our information technology systems.
The legal basis for the processing is Art. 6(1)(f) GDPR.
Our legitimate interest lies in the secure, stable and functional provision of our online services.
Log data are generally stored only for as long as necessary for the purposes stated above. Where data are required to investigate a specific security incident or to establish, exercise or defend legal claims, they may be retained until the relevant matter has been finally resolved.
5. Domain Management
The domain of our website is managed through IONOS SE.
Service provider:
IONOS SE
Elgendorfer Str. 57
56410 Montabaur
Germany
We use IONOS in particular for the registration and management of our internet domain.
Where IONOS also provides DNS services for our domain, connection data and technical communication data may be processed in connection with technically necessary DNS queries.
The processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable accessibility of our online services.
The website itself and our application data are not hosted by IONOS.
6. Hosting of the Frontend and CMS via Vercel
The frontend of our website and the technical interface of our content management system are provided using services supplied by Vercel.
Service provider:
Vercel Inc.
440 N Barranca Avenue #4133
Covina, CA 91723
USA
When accessing pages provided through Vercel, the following data may in particular be processed:
- IP address,
- time of access,
- requested URL,
- browser and device information,
- operating system,
- referrer information,
- HTTP headers,
- technical log and diagnostic data,
- security and connection information.
The processing is carried out for the provision, delivery, security and technical optimisation of our online services.
Legal basis: Art. 6(1)(f) GDPR.
Our legitimate interest lies in the secure, high-performance and highly available provision of our website and the content management system required for it.
To the extent that Vercel processes personal data on our behalf, this processing is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR.
Vercel operates an internationally distributed infrastructure. It therefore cannot be ruled out that technical data may also be processed outside the European Union or the European Economic Area.
For transfers of personal data to the United States, the adequacy decision of the European Commission concerning the EU-U.S. Data Privacy Framework may be relied upon where the applicable requirements are met. According to its own statements, Vercel is certified under the EU-U.S. Data Privacy Framework.
In addition, Vercel's data processing agreement provides for the use of Standard Contractual Clauses adopted by the European Commission pursuant to Art. 46 GDPR for relevant international data transfers.
Through our technical configuration, we endeavour to process personal application and mandate-related data, wherever possible, within the infrastructure designated by us in Germany.
7. Protected Administration Area and CMS
We operate a protected administration area and content management system for the management of our website.
This area is intended exclusively for authorised persons.
In connection with its use, the following data may in particular be processed:
- user identifier or user account,
- name and, where applicable, email address of the administrator,
- login time,
- IP address,
- session and authentication data,
- technical log data,
- changes made and administrative actions.
The processing serves in particular:
- user authentication,
- access control,
- website administration,
- ensuring IT security,
- traceability of administrative changes,
- prevention of unauthorised access.
Depending on the data subject and the specific use, the legal basis results in particular from Art. 6(1)(b), (c) or (f) GDPR.
Where authentication or session cookies are used for the protected administration area, these are technically necessary for the provision of the expressly requested and protected service.
8. Backend, API and Server Infrastructure at Hetzner
For the server-side processing of our website and application data, we use server infrastructure provided by Hetzner Online GmbH.
Service provider:
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany
On Hetzner servers, we operate in particular our server-side application and API based on a containerised NestJS application.
According to our technical configuration, the servers used by us for these applications are located in Germany.
In connection with their use, the following data may in particular be processed:
- IP addresses,
- connection and log data,
- data from contact inquiries,
- communication data,
- where applicable, data from the CMS,
- technical security and error logs.
The processing serves in particular the technical handling of requests, communication between frontend and backend, the secure provision of our services and the processing of functions offered through the website.
Depending on the specific processing operation, the processing is carried out in particular on the following legal bases:
- Art. 6(1)(b) GDPR, where the processing is necessary to take steps prior to entering into a contract or to process an inquiry relating to a possible legal mandate;
- Art. 6(1)(c) GDPR, where processing is necessary for compliance with a legal obligation;
- Art. 6(1)(f) GDPR, where processing is necessary for the secure and reliable operation of our information technology infrastructure.
Where required, a data processing agreement pursuant to Art. 28 GDPR is concluded with Hetzner.
9. Databases and File Storage
For the technical storage of data, we use database and object storage solutions based in particular on MongoDB and MinIO within our own server infrastructure.
These applications are operated by us on server infrastructure under our control at Hetzner in Germany.
In this configuration, MongoDB and MinIO are not used as external cloud services. The mere use of this software therefore does not result in personal data being transferred to the manufacturers of the software.
The categories of data stored depend on the respective purpose of the application.
They may include in particular:
- administrative data,
- CMS content data,
- technical metadata,
- uploaded files and media,
- where technically intended, data from contact and communication processes.
Personal data are stored only for as long as necessary for the relevant processing purpose or for as long as statutory retention obligations apply.
10. Contact and Contact Form
You may contact us using the contact form provided on our website.
The following information may in particular be processed:
- first name,
- last name,
- company,
- email address,
- telephone number,
- preferred location,
- practice or advisory area,
- the message entered by you,
- time of transmission,
- technically necessary connection data.
Mandatory fields are marked accordingly. Any additional information is provided voluntarily.
The processing is carried out exclusively for the receipt, review and handling of your inquiry and for subsequent communication with you.
Legal Basis for Mandate and Legal Advice Inquiries
Where your inquiry concerns the initiation of a legal mandate or another contractual relationship, the processing is carried out on the basis of Art. 6(1)(b) GDPR.
In this case, the processing is necessary in order to take steps at your request prior to entering into a contract.
A separate consent pursuant to Art. 6(1)(a) GDPR is generally not required for this purpose.
Legal Basis for General Inquiries
Where your inquiry does not concern the initiation of a legal mandate or other contractual relationship, the processing is carried out on the basis of Art. 6(1)(f) GDPR.
Our legitimate interest lies in the proper handling of communications addressed to us.
Special Categories of Personal Data
Please do not submit information through the general contact form that is not necessary for an initial contact, in particular login credentials or extensive confidential documents.
However, due to the nature of legal services, it cannot be ruled out that users may provide us with special categories of personal data in connection with an inquiry.
Where such data are necessary for the establishment, exercise or defence of legal claims, the processing may in particular be based on Art. 9(2)(f) GDPR.
The processing is carried out only to the extent necessary and in compliance with the professional duties of confidentiality applicable to lawyers.
11. Transmission of Contact Inquiries by Email / SMTP
After submitting the contact form, your inquiry may be transmitted to the responsible recipients within our law firm through a technically integrated email or SMTP infrastructure.
The following data may in particular be processed:
- name,
- email address,
- where applicable, telephone number,
- subject or classification of the inquiry,
- content of your message,
- technical sending and delivery information.
The legal basis corresponds to the legal basis applicable to the respective contact inquiry and is in particular Art. 6(1)(b) GDPR for mandate-related inquiries and Art. 6(1)(f) GDPR for other inquiries.
Before publication, the actual email/SMTP service provider must be inserted here if the email infrastructure is provided by an external service provider.
Where the email provider processes personal data on our behalf, a data processing agreement pursuant to Art. 28 GDPR will be concluded where legally required.
12. Confidential Communication and Professional Secrecy
Lawyers are subject to statutory and professional duties of confidentiality.
Information entrusted to us in connection with the initiation of a legal mandate or an existing legal mandate is treated confidentially in accordance with the applicable statutory and professional rules.
The general contact form is intended primarily for initial contact and does not replace a separately agreed communication channel for highly sensitive or particularly extensive documents.
Suitable secure transmission methods may be agreed in advance for particularly confidential information and documents.
13. Retention Period for Contact and Mandate Data
Contact inquiries that do not result in a legal mandate are generally deleted once the inquiry has been fully processed, provided that no statutory retention obligations or legitimate interests require further retention.
Further retention may in particular be permissible where necessary to document communications, prevent conflicts of interest, establish, exercise or defend legal claims, or comply with legal obligations.
If a legal mandate is established, the information provided may become part of the lawyer's client file.
In accordance with Section 50 of the German Federal Lawyers' Act (BRAO), lawyers' files must generally be retained for six years. The retention period begins at the end of the calendar year in which the mandate was terminated.
Any longer statutory retention obligations remain unaffected.
14. Cookies and Local Storage Technologies
Our website may use cookies or comparable technologies.
Cookies are small data files that may be stored on or read from a user's device.
We distinguish between technologies that are strictly necessary and technologies that are not strictly necessary.
Strictly Necessary Technologies
Strictly necessary cookies or comparable technologies may be used, for example:
- to ensure security,
- to manage a session,
- for authentication within the administration area,
- to store technically necessary settings.
Where storing or accessing information on the terminal device is strictly necessary in order to provide a digital service expressly requested by you, consent is not required pursuant to Section 25(2) TDDDG.
Where personal data are processed in this context, the processing is carried out, depending on the specific purpose, in particular on the basis of Art. 6(1)(b) or (f) GDPR.
Non-Essential Technologies
Technologies for analytics, statistics, marketing, retargeting or comparable purposes will, where such services are used, generally only be activated after you have given your prior consent.
The storage of or access to information on your device is then carried out on the basis of Section 25(1) TDDDG.
The subsequent processing of personal data is carried out on the basis of Art. 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future.
15. No External Analytics or Marketing Services Currently Assumed
Based on the technical infrastructure currently described, this Privacy Policy does not assume the use of external analytics, advertising, remarketing or profiling services such as Google Analytics, Meta Pixel or comparable services.
If such services are used in the future, they will only be activated following a data protection review and, where required, after obtaining prior consent.
In such a case, this Privacy Policy will be supplemented before or, at the latest, at the time the relevant service is activated, with the required information concerning the provider, purpose, legal basis, retention period and any possible transfers to third countries.
16. Social Media Profiles and External Links
Our website may contain links to external websites and social networks.
A simple link to an external website generally results in data being transferred to the respective provider only when you actively click the link.
After you access an external website, the further processing of personal data is governed by the privacy policy of the respective provider.
Where we maintain our own profiles on social networks, in particular LinkedIn or Instagram, we process information made available there in particular for the purpose of presenting our law firm publicly and communicating with prospective clients, clients and other users.
The legal basis for our own processing is in particular Art. 6(1)(f) GDPR.
For specific mandate-related inquiries, Art. 6(1)(b) GDPR may additionally apply.
17. Data Transfers Between Germany and Türkiye
Our law firm operates on a cross-border basis and maintains or uses structures in Germany and Türkiye.
Where an inquiry relates to a location in Türkiye, or cross-border handling is necessary for the processing of an inquiry or legal mandate, personal data may be processed to the extent necessary with the involvement of lawyers or other authorised persons in Türkiye.
Türkiye is not a member of the European Union or the European Economic Area and is not currently covered by a general adequacy decision of the European Commission.
Where personal data are regularly transferred to a legally independent recipient in Türkiye, such transfer will only take place in compliance with the requirements of Art. 44 et seq. GDPR.
Depending on the specific circumstances, appropriate safeguards pursuant to Art. 46 GDPR, in particular the Standard Contractual Clauses adopted by the European Commission, may be used.
In individual cases provided for by law, a transfer may additionally be based on one of the conditions set out in Art. 49 GDPR.
Irrespective of the above, the lawyers involved and persons subject to confidentiality obligations are bound by the applicable professional and statutory duties of confidentiality.
18. Recipients of Personal Data
We disclose personal data only where there is a legal basis under data protection law for doing so.
Recipients or categories of recipients may in particular include:
- lawyers and employees of our law firm,
- professionals responsible for handling an inquiry,
- IT and hosting service providers,
- Vercel Inc.,
- Hetzner Online GmbH,
- where applicable, IONOS SE in connection with domain or DNS services,
- the email/SMTP service provider actually used,
- external IT service providers, where used,
- tax advisers, auditors or other professional advisers, where necessary,
- courts, authorities or other public bodies where there is a legal obligation or other legal basis,
- lawyers, professionals or cooperation partners engaged in cross-border matters where the transfer is necessary and legally permissible.
Where service providers process personal data exclusively on our behalf, they are engaged as processors in accordance with the applicable statutory requirements.
Personal data are not transferred to third parties for their own advertising purposes.
19. Processing on Behalf of the Controller
Where we engage service providers to process personal data on our behalf, we only use processors that provide sufficient guarantees that appropriate technical and organisational measures are implemented to protect personal data.
Where legally required, data processing agreements pursuant to Art. 28 GDPR are concluded with the respective service providers.
Based on the technical infrastructure currently described, this applies in particular to the hosting and infrastructure providers used by us.
20. International Data Transfers
Where personal data are transferred to recipients outside the European Union or the European Economic Area, we comply with the requirements of Art. 44 et seq. GDPR.
Such a transfer may in particular take place:
- on the basis of an adequacy decision of the European Commission pursuant to Art. 45 GDPR,
- on the basis of appropriate safeguards pursuant to Art. 46 GDPR, in particular Standard Contractual Clauses,
- or, in cases provided for by law, on the basis of Art. 49 GDPR.
For U.S.-based service providers, the adequacy decision concerning the EU-U.S. Data Privacy Framework may be relied upon where the respective recipient is validly certified under that framework.
21. Data Security
Taking into account the state of the art, implementation costs and the nature, scope, context and purposes of processing, we implement appropriate technical and organisational measures to protect personal data.
These include in particular measures designed to ensure:
- confidentiality,
- integrity,
- availability,
- resilience of the systems used,
- access protection,
- access control,
- authorisation management,
- data backup,
- recoverability,
- logging of security-relevant events,
- secure data transmission.
Communication between your browser and our website is generally encrypted using current TLS technology (“HTTPS”).
For security reasons, we deliberately refrain from providing information on specific bit lengths or older SSL versions, as the cryptographic methods actually used are updated in accordance with the state of the art.
22. Rights of Data Subjects
Subject to the applicable statutory requirements, you are entitled in particular to the following rights:
Right of Access – Art. 15 GDPR
You may request information as to whether we process personal data relating to you and, where this is the case, obtain further information about such processing.
Right to Rectification – Art. 16 GDPR
You may request the correction of inaccurate personal data and the completion of incomplete personal data.
Right to Erasure – Art. 17 GDPR
You may request the deletion of your personal data where the statutory requirements are met.
In particular, there is no right to erasure where further processing is necessary to comply with a legal obligation or for the establishment, exercise or defence of legal claims.
Right to Restriction of Processing – Art. 18 GDPR
You may request restriction of processing where the statutory requirements are met.
Right to Data Portability – Art. 20 GDPR
Where the statutory requirements are met, you may receive the personal data you have provided to us in a structured, commonly used and machine-readable format or request that such data be transmitted to another controller.
Right to Object – Art. 21 GDPR
Where personal data are processed on the basis of Art. 6(1)(f) GDPR, you may object to the processing on grounds relating to your particular situation.
We will then no longer process the relevant data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or unless the processing is necessary for the establishment, exercise or defence of legal claims.
Withdrawal of Consent – Art. 7(3) GDPR
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future.
The lawfulness of processing carried out on the basis of consent before its withdrawal remains unaffected.
23. Right to Lodge a Complaint
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority.
You may in particular contact the supervisory authority at your habitual residence, your place of work or the place of the alleged data protection infringement.
For a controller established in North Rhine-Westphalia, the following authority is in particular competent:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
Postal address:
Postfach 20 04 44
40102 Düsseldorf
Germany
Email: poststelle@ldi.nrw.de
24. No Automated Decision-Making
In connection with this website, we generally do not carry out solely automated decision-making, including profiling, within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.
25. Amendments and Updates to this Privacy Policy
We reserve the right to amend this Privacy Policy if statutory requirements, our technical infrastructure, or the nature and scope of the processing activities carried out by us change.
The version currently published on our website shall apply.
Last updated: 21 August 2026
