1. Controller
The controller responsible for data processing on this website is:
Heinrich Thiele
Attorney-at-law · Tax advisor · Specialist lawyer for tax law
Neufahrner Weg 18
82057 Icking
Phone: +49 151 7000 9374
Email: rechtsanwalt@heinrichthiele.de
2. Hosting and server log files
This website is hosted on Contabo. In the course of operating the website, the hosting provider may automatically collect and store information in so-called server log files.
This includes in particular:
- IP address of the requesting device
- Date and time of access
- Browser type and browser version
- Operating system
- Referrer URL
- Name and URL of the requested file
- Access status and amount of data transferred
The processing is carried out to ensure uninterrupted operation of the website, to ensure IT security and to technically provide the online offering.
The legal basis is Art. 6 (1) lit. f GDPR.
Where required under data protection law, a data processing agreement pursuant to Art. 28 GDPR exists with the hosting provider.
3. Contact by email or telephone
If you contact me by email or telephone, the personal data you provide will be processed exclusively for the purpose of handling your enquiry, initiating a client relationship or carrying out an existing client relationship.
The legal basis is Art. 6 (1) lit. b GDPR and Art. 6 (1) lit. f GDPR.
The data will be deleted as soon as it is no longer required for the respective purpose and no statutory retention obligations prevent deletion.
4. Video conferences via Microsoft Teams
For meetings, telephone conferences and video conferences I use Microsoft Teams, a service of Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.
When using Microsoft Teams, the following data in particular may be processed:
- Name and contact details
- Communication content
- Image and sound data
- Technical connection data
- Communication metadata
The processing is carried out for holding meetings, initiating client relationships and handling client matters.
The legal basis is Art. 6 (1) lit. b GDPR and Art. 6 (1) lit. f GDPR.
Further information on data processing by Microsoft can be found in Microsoft's privacy notices.
5. LinkedIn
This website may contain links to my profile on LinkedIn.
By clicking on such a link, you leave this website. The respective provider is solely responsible for data processing by LinkedIn.
Information on data processing by LinkedIn can be found in LinkedIn's privacy notices.
6. Storage period
Personal data is stored only for as long as this is necessary for the respective processing purposes or statutory retention periods apply.
Professional, tax and commercial law retention obligations remain unaffected.
7. Rights of data subjects
You have the right
- pursuant to Art. 15 GDPR to request information about your processed personal data,
- pursuant to Art. 16 GDPR to request correction of inaccurate data,
- pursuant to Art. 17 GDPR to request deletion of your data,
- pursuant to Art. 18 GDPR to request restriction of processing,
- pursuant to Art. 20 GDPR to receive your data in a structured, commonly used and machine-readable format,
- pursuant to Art. 21 GDPR to object to processing,
- to withdraw consent granted at any time with effect for the future.
8. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data.
The competent supervisory authority is:
The Bavarian State Commissioner for Data Protection
Wagmüllerstraße 18
80538 Munich
Phone: +49 89 212672-0
Email: poststelle@datenschutz-bayern.de
9. Data security
The protection of personal data and the confidential handling of information are of great importance to me. Appropriate technical and organisational measures are used to protect personal data against loss, unauthorised access and misuse and to ensure secure transmission of data.
10. Professional confidentiality
Communication in the context of the mandate may generally take place by unencrypted email. The client is aware that electronic communication entails security risks and that it cannot be ruled out in particular that third parties may gain knowledge of the content of an email.
Unless the client gives instructions to the contrary, I am entitled to transmit information, documents and work results by this means.
At the request of the client or where the nature, scope or confidentiality of the information requires it, additional security measures, in particular encrypted communication channels or secure data rooms, can be agreed.
11. Currentness and amendment of this privacy policy
This privacy policy is dated 01.06.2026.
Due to the further development of this website or changes in legal or regulatory requirements, it may become necessary to amend this privacy policy.