Privacy policy.
Information under the GDPR on the type, scope and purpose of processing your personal data.
1. Controller and data categories
The controller within the meaning of the GDPR is BRANDAUER Rechtsanwälte GmbH, Giselakai 51, 5020 Salzburg (hereinafter „we" or „the firm"). We process your personal data only on the basis of the GDPR, in particular for the performance of the engagement (Art. 6(1)(b)), your consent (Art. 6(1)(a)) or a legitimate interest (Art. 6(1)(f)).
We collect only data required for our legal services or which you provide voluntarily: name, address, email, phone, date of birth, where applicable social security number, photo or voice recordings and biometric data. Sensitive data (health, criminal proceedings) may be included case-by-case.
2. Your rights
Subject to attorney-client privilege, you have the right to access, rectification, erasure, restriction of processing, data portability, objection and withdrawal of consent.
Requests can be sent to the address listed under section 8. If you believe your data protection rights have been infringed, you may lodge a complaint with the competent supervisory authority, in Austria the Data Protection Authority (Barichgasse 40-42, 1030 Vienna).
3. Data security and retention
We protect your data through organisational and technical measures against unauthorised access, loss and manipulation. We accept no liability for transmission errors or unauthorised third-party access outside our sphere of responsibility.
Data are retained only as long as necessary to fulfil contractual and statutory obligations and to defend against liability claims.
4. Recipients and third-country transfer
To fulfil the engagement, transfers to third parties may be necessary (opposing parties, substitute lawyers, insurers, service providers, courts, authorities). For transfers to third countries we rely on an EU adequacy decision or on standard contractual clauses (Decision 2021/914/EU).
5. Notification of data breaches
Data breaches are, where required, reported without undue delay to you and to the competent supervisory authority, including the categories of data affected.
6. Cookies
This website uses cookies. A cookie is a small text file stored by your browser on your device and recognised on your next visit. You can restrict or refuse cookies in your browser settings, the functionality of the website may then be limited.
Specifically, the following cookies and locally stored values are used on this website:
| Name | Provider | Purpose | Storage period |
|---|---|---|---|
| _ga | Google Analytics 4 | User identification (only with consent) | 2 years |
| _ga_<id> | Google Analytics 4 | Session tracking (only with consent) | 2 years |
| brandauer-klaro | This website | Storage of your cookie consent | 1 year |
| brandauer-consent-v1 | This website | Versioned consent state (Local Storage) | 1 year |
You can withdraw your consent at any time via the „Cookie settings" link in the footer. Processing already carried out remains unaffected.
6a. Cloudflare Web Analytics
This website uses Cloudflare Web Analytics (Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA), without cookies and without IP storage. Only aggregated access data is collected (page views, referrer, device category, browser type); identification of individual users is not possible. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technically adequate reach measurement). Consent is not required.
6b. Google Analytics 4 (consent only)
With your express consent we use Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street,
Dublin 4, Ireland). Processed are anonymised IP address, browser type, operating system, referrer URL, page
views and click events (in particular cta_click, language_switch,
decision_tree_step, decision_tree_completed). Content from input fields is not
transmitted.
Legal basis: Art. 6(1)(a) GDPR (consent via the cookie banner).
Storage period: cookie lifespan 2 years (_ga) or 24 hours
(_gid); GA4 data retention set to 14 months.
Recipients: Google Ireland Limited (Ireland), Google LLC (USA).
Third-country transfer (Schrems II): A transfer to Google LLC in the USA cannot be excluded. Standard contractual clauses (Module 4) under Decision 2021/914/EU are in place; following the Schrems II ruling (CJEU C-311/18) a residual risk remains that US authorities may access the data. Withdrawal at any time via „Cookie settings" in the footer. Further information: policies.google.com/privacy
7. Server log files (Cloudflare)
On each access the provider records technically necessary data in server log files (IP address, browser and language settings, operating system, referrer URL, date/time). Delivery is provided via the network of Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA) for the purposes of security and performance. Legal basis: Art. 6(1)(f) GDPR.
Third-country transfer (Schrems II): In the course of delivery, processing in the USA by Cloudflare, Inc. may occur. Standard contractual clauses under Decision 2021/914/EU are in place; following the Schrems II ruling (CJEU C-311/18) a residual risk remains that US authorities may access the data. The data are not merged with other personal data sources.
8. Contact
BRANDAUER Rechtsanwälte GmbH
Giselakai 51
5020 Salzburg
Email: [email protected]
Phone: +43 662 / 62 80000
A direct line to the firm.
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg
Phone
+43 660 2407152