Privacy Policy

This privacy policy is based on the legal provisions for the protection of your data, which are contained in the General Data Protection Regulation (GDPR - REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016). In addition, the legal provisions of the Federal Data Protection Act (BDSG) and the Telecommunications Digital Services Data Protection Act (TDDDG) are applied.
1. 1. Data Controller

The controller within the meaning of Article 4(7) of the GDPR is: 

dr.balkenhol GmbH
Friedrich-von-Spee-Str. 37
40489 Düsseldorf (Germany)
Represented by the managing director Dr. Markus Balkenhol
Phone +49 211 1583 8103
Fax: +49 211 5422 2262
E-mail: mail@dr-balkenhol.com

2. Subject matter of this Policy

This privacy policy provides information about what personal data is stored, processed and shared when you visit our website, how this is done and for what purpose.

Personal data according to Art. 4 No. 1 GDPR is any information relating to an identified or identifiable natural person (hereinafter referred to as "data subject"); A natural person is considered identifiable if they can be identified, directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person.

3. Information on transfer to third countries pursuant to Art. 13 para. 1 lit. f) GDPR

When accessing and using our website and related services, personal data may be transferred to countries outside the European Union or the European Economic Area. Such transfers will only take place if an adequacy decision by the European Commission exists, if appropriate safeguards within the meaning of Articles 46 et seq. of the GDPR—in particular EU Standard Contractual Clauses—are in place, or if an exception under Article 49 of the GDPR applies.

To the extent that a transfer to the United States takes place, it may be based, in particular, on the EU-U.S. Data Privacy Framework, provided that the respective recipient is certified accordingly.
Nevertheless, access to personal data by authorities in third countries cannot be completely ruled out despite existing safeguards.

4. Data that we process on the basis of legitimate interests pursuant to Article 6(1)(f) of the GDPR:

Server data

When you visit our website, the web server we use automatically processes access data—so-called server log files—that your browser transmits for technical reasons. This may include, in particular, the file accessed, the date and time of access, the amount of data transferred, a notification of successful access, browser type and version, operating system, referrer URL, and the IP address. This processing is carried out for the technical provision of the website, system security, prevention of misuse, and error analysis based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in the secure and uninterrupted operation of our website, as well as in the detection and prevention of attacks and misuse. The log data is deleted or anonymized after 14 days at the latest, unless longer storage is necessary to investigate security incidents. We use an encrypted connection via TLS to transmit your data. This ensures that your data is protected during transmission using state-of-the-art technology.

STRATO (hosting)

We use STRATO as our hosting provider. The service is operated by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. STRATO enables us to maintain a domain under which we can publish our website. In addition, we use STRATO’s email system, cloud services, and servers. You can find out what data is stored, as well as information on the purpose of collection and storage, in the section above (“Server Data”). Our legitimate interest lies in enabling the operation of a website on the Internet. We have entered into a Data Processing Agreement (DPA) with STRATO, through which this company assures and documents its compliance with appropriate technical and organizational measures. For more information, please see STRATO’s Privacy Policy at https://www.strato.de/datenschutz/.

Wordfence

To protect our website from unauthorized access, malware, brute-force attacks, and other security-related threats, we use the WordPress security plugin Wordfence. The provider is Defiant, Inc., 1700 Westlake Ave N Ste 200, Seattle, WA 98109, USA. Wordfence processes security-related access data. This may include, in particular, IP addresses, the date and time of access, URLs accessed, browser and device information, as well as information about security-related events, such as failed login attempts or blocked access. This processing is carried out for the purpose of technically securing our website, detecting and defending against attacks, and ensuring uninterrupted operation. The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in the secure provision of our website and protection against cyberattacks, misuse, and unauthorized access. Wordfence may set technically necessary cookies that serve the website’s security functions, in particular to recognize logged-in users and to control firewall functions. To the extent that information is stored on or read from your device in this context, this is done on the basis of Section 25(2) of the German Telecommunications Data Protection Act (TDDDG), as these processes are necessary for the security and functionality of the website.

When using Wordfence, the transfer of personal data to the United States cannot be ruled out. According to its own statements, Defiant provides standard contractual clauses as well as a Data Processing Addendum (DPA) for the processing of personal data. Further information on data processing and the contractual terms regarding data protection can be found on the information pages linked below. For more information, please see the Wordfence/Defiant Privacy Policy at: https://www.wordfence.com/privacy-policy/ The provider provides information on Wordfence and the GDPR at: https://www.wordfence.com/help/general-data-protection-regulation/.

Email enquiries

If you send us an enquiry by email, we will collect and store your email address and the data contained in the email in order to respond to your enquiry. Our legitimate interest lies in communicating with you and responding to your enquiries.

If a contractual relationship develops from the inquiry as part of pre-contractual negotiations, or if the inquiry relates to an existing contractual relationship, the legal basis is Article 6(1)(b) of the GDPR, as the storage of the data is necessary for the fulfillment of a pre-contractual or contractual obligation. The data will be deleted once the purpose for which it was stored no longer applies—that is, after your email inquiry has been answered or the matter related to the inquiry has been conclusively resolved. In the case of an existing contractual relationship or one arising from the inquiry, the data will be deleted after the statutory retention periods have expired.

Use of our own cookies for functionality purposes

Our website uses so-called cookies in certain areas. Cookies are text files that can be stored on the device you are using via your web browser. We use technically necessary cookies to ensure that our website is user-friendly, secure, and fully functional. We do not use analytics, tracking, or marketing cookies. No processing takes place for these purposes. Session cookies are automatically deleted at the end of your visit. Individual technically necessary cookies may be stored for a longer period, to the extent necessary to save your settings or to ensure the security and functionality of our website. You can disable cookies in your web browser. However, this may impair the functionality of our website. The legal basis for the use of technically necessary cookies is Section 25(2) of the TDDDG. To the extent that personal data is processed, this is done on the basis of Article 6(1)(f) of the GDPR. Our legitimate interest lies in providing our website in a secure, user-friendly, and fully functional manner.

CookieYes (Cookie-Consent-Tool)

We use the “CookieYes” consent tool to manage your privacy settings and, where necessary, to obtain and document your consent. The provider is CookieYes Limited, 3 Warren Yard Warren Park, Wolverton Mill, Milton Keynes, MK12 5NW, United Kingdom. When you make a selection via the consent tool, CookieYes automatically logs the following data in particular:

  • The end user’s IP address in anonymized form
  • Date and time of consent or selection
  • User-agent of the end user’s browser
  • URL from which the consent or selection was sent
  • An anonymous, random, and encrypted key
  • Consent status or the end user’s selected privacy settings as proof of selection

The stored data is used to save your privacy settings, to use services requiring consent only with your consent, and to document the consents granted. The legal basis for using the consent tool and documenting granted consents is Article 6(1)(c) of the GDPR, to the extent that we are legally required to provide evidence of consent. Additionally, the processing is based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in the legally compliant management and documentation of privacy settings and consents. The consent cookie is stored in accordance with Section 25(2) of the German Telemedia Act (TDDDG), as it is necessary to provide the privacy settings you have selected and to take them into account during subsequent page visits. The key and the consent status or the selected privacy settings are also stored in the end user’s browser in the “cookieyes-consent” cookie. This allows the website to automatically read and take your selection into account during subsequent page visits and future sessions for up to 12 months.

CookieYes processes personal data on our behalf. This processing is carried out in accordance with the Data Processing Agreement provided by CookieYes pursuant to Article 28 of the GDPR. The United Kingdom has an adequacy decision from the European Commission pursuant to Article 45 of the GDPR, meaning that data transfers to that country are subject to a level of data protection comparable to that of the European Union. For more information, please see the CookieYes Privacy Policy at: https://www.cookieyes.com/privacy-policy/.

LinkedIn (social network)

We maintain a profile on LinkedIn for the purpose of communicating with customers, prospective customers, and business partners, as well as to provide general information about our company. The provider is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (“LinkedIn”). A link to our LinkedIn page is embedded on our website. If you click this link, you will leave our website and be redirected to LinkedIn. From that point on, LinkedIn processes personal data under its own responsibility. If you are logged into your LinkedIn account at the same time, LinkedIn may associate your visit to our LinkedIn page with your user account. If you wish to avoid this, you should log out of LinkedIn before clicking the link. When you visit or interact with our LinkedIn page, LinkedIn processes personal data in accordance with the LinkedIn Privacy Policy. We have only limited influence over this processing. Our own processing of personal data in connection with our LinkedIn page is carried out for the purposes of corporate branding, communication, and handling interactions based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in up-to-date corporate communication, corporate branding, and maintaining contacts. In connection with the operation of our LinkedIn company page, we are jointly responsible with LinkedIn Ireland Unlimited Company, pursuant to Article 26 of the GDPR, for certain processing of personal data, particularly in connection with so-called Page Insights. The agreement specifically governs the allocation of data protection obligations with regard to the processing of Insights data as well as the exercise of data subject rights. Notwithstanding this joint responsibility, you may exercise your data subject rights with either us or LinkedIn. The transfer of personal data to LinkedIn companies or service providers outside the European Union or the European Economic Area cannot be ruled out. For more information on data processing by LinkedIn, please see LinkedIn’s Privacy Policy at: https://de.linkedin.com/legal/privacy-policy LinkedIn provides key information on joint controllership at the following link: https://www.linkedin.com/legal/l/page-joint-controller-addendum.

XING (social network)
We maintain a profile on XING for the purpose of communicating with customers, prospective customers, and business partners, as well as to provide general information about our company. The provider is New Work SE, Baumwall 7, 20459 Hamburg, Germany (“XING”).
A link to our XING page is embedded on our website. If you click this link, you will leave our website and be redirected to XING. From that point on, XING processes personal data under its own responsibility. If you are logged into your XING account at the same time, XING may associate your visit to our XING page or interactions with it with your user account. If you wish to avoid this, you should log out of XING before clicking the link.
When you visit or interact with our XING page, XING processes personal data in accordance with the XING Privacy Policy. This applies even if you do not have a XING account or are not logged in to XING. We have only limited influence over this processing.
Our own processing of personal data in connection with our XING page is carried out for the purposes of corporate branding, communication, and handling interactions based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in modern corporate communication, corporate branding, and maintaining contacts.
To the extent that statistical analyses, interaction data, or other information regarding the use of our profile is made available to us via our XING company profile, we use this information to tailor our corporate communications to meet specific needs. We generally do not receive complete usage profiles of individual visitors.
For more information on data processing by XING, please see XING’s Privacy Policy at: https://privacy.xing.com/de/datenschutzerklaerung.
https://privacy.xing.com/de/datenschutzerklaerung.

YouTube-Kanal

We operate a YouTube channel for the purposes of corporate branding, providing video content, and communicating with customers, prospective customers, and business partners. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Our website may include a link to our YouTube channel. If you click this link, you will leave our website and be redirected to YouTube. From that point on, Google processes personal data under its own responsibility. If you are logged into your Google or YouTube account at the same time, Google may associate your visit to our YouTube channel or your interactions with the content we’ve published there with your user account. If you wish to avoid this, you should log out of your Google or YouTube account before clicking the link. When you visit our YouTube channel or interact with the content we publish there, Google processes personal data in accordance with Google’s Privacy Policy. This may include, in particular, usage data, device information, IP addresses, and information about viewed content, comments, ratings, or other interactions. We have only limited influence over this processing. Our own processing of personal data in connection with our YouTube channel is carried out for the purposes of corporate branding, providing video content, communication, and handling interactions, based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in up-to-date corporate communication, corporate branding, and the provision of informational material. A transfer of personal data to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, or other Google companies outside the European Union or the European Economic Area cannot be ruled out. To the extent that personal data is transferred to the United States, such transfer may take place, in particular, on the basis of the EU-U.S. Data Privacy Framework, provided that the respective recipient is certified accordingly, or on the basis of appropriate safeguards within the meaning of Articles 46 et seq. of the GDPR. Despite existing safeguards, access to personal data by authorities in third countries, particularly the United States, cannot be ruled out with absolute certainty. For more information on data processing by Google, please see Google’s Privacy Policy at: https://policies.google.com/privacy.

Downloading the digital business card

On our website and in our email signature, we offer you the option to download a digital business card in VCF format (vCard). By downloading the vCard, you can import the contact information it contains directly into your own address books, such as those from Google or Microsoft. The downloaded vCard contains contact information provided by us, such as name, email address, phone number, and job title. When you retrieve the vCard, technically necessary server data may be processed in accordance with the “Server Data” section. Beyond that, we do not store any additional personal data in connection with the vCard download. If, after downloading the vCard, you import it into a Google or Microsoft account or into another address book, further processing of the contact information it contains is your responsibility and—depending on the service used—the responsibility of the respective provider. We have no influence over whether or how these providers process the imported contact data. Information on data processing by Google and Microsoft can be found in the privacy policies of the respective providers: https://policies.google.com/privacy https://privacy.microsoft.com/de-de/privacystatement The legal basis for providing the digital business card is Article 6(1)(f) of the GDPR. Our legitimate interest is to enable prospects, customers, and business partners to easily contact us electronically.

External Links to Third-Party Websites
Our website contains links to external third-party websites over whose content we have no control.
By clicking on an external link, you will be redirected to the website of the respective third-party provider. From that point onwards, any further processing of personal data in connection with accessing and using the linked website takes place solely within the responsibility of the respective provider.
The respective provider is exclusively responsible for the processing of personal data on these external websites. We have no influence over the nature, scope, or purpose of the processing of personal data by the operators of the linked websites. Information on data processing can be found in the respective privacy policies of the external providers.
Information on data processing can be found in the respective privacy policies of the external providers.
The linking is carried out on the basis of our legitimate interest in providing a user-friendly and informative website in accordance with Art. 6(1)(f) GDPR.

5. Contact Form

When you use our contact form, we process the data you enter—in particular your name, phone number, email address, and the content of your message—for the purpose of handling and responding to your inquiry. The legal basis is Article 6(1)(b) of the GDPR, provided that your inquiry serves to implement pre-contractual measures or relates to an existing contractual relationship. In all other cases, processing is based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in processing and responding to your inquiry, as well as in communicating with prospective customers, customers, and business partners. The data will be deleted as soon as your inquiry has been fully processed, provided that there are no legal retention requirements and no further storage is necessary within the framework of a contractual relationship or for the assertion, exercise, or defense of legal claims.

6. YouTube (Videos)

Where YouTube videos are embedded on our website, they are loaded only after you have given your consent via our consent tool. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When playing a YouTube video, personal data—in particular your IP address, device information, browser information, usage data, and information about the video you are watching—may be transmitted to Google. The transmission of personal data to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, or other Google companies outside the European Union or the European Economic Area cannot be ruled out. To the extent possible, we use YouTube’s enhanced privacy mode. However, even in enhanced privacy mode, data processing by Google may still occur, particularly when you play the video. The legal basis for setting or reading information on your device is Section 25(1) of the TDDDG. The legal basis for the subsequent processing of personal data is Article 6(1)(a) of the GDPR. You may revoke your consent at any time with future effect via the settings of our consent tool. To the extent that personal data is transferred to the United States, the transfer may take place, in particular, on the basis of the EU-U.S. Data Privacy Framework, provided that the respective recipient is certified accordingly, or on the basis of appropriate safeguards within the meaning of Art. 46 et seq. of the GDPR. Despite existing safeguards, access to personal data by authorities in third countries, particularly the United States, cannot be ruled out with absolute certainty. For more information, please see Google’s Privacy Policy and YouTube’s Terms of Service at: https://policies.google.com/privacy https://www.youtube.com/t/terms.

7. 7. Data we collect to fulfill a contract pursuant to Article 6(1)(b) of the GDPR

Contract processing

We process the personal data you provide for the purposes of contract initiation, contract execution, service provision, communication, billing, and invoicing. This may include, in particular, your name, address, email address, phone number, contract details, service details, payment details, and billing and invoicing information. The legal basis is Article 6(1)(b) of the GDPR, insofar as the processing is necessary for the implementation of pre-contractual measures or for the performance of a contract. To the extent that we process personal data to fulfill statutory retention, documentation, tax, or commercial law obligations, the processing is based on Article 6(1)(c) of the GDPR. Personal data may be disclosed, to the extent necessary, to banks, payment service providers, tax advisors, accounting service providers, and tax authorities. This is done, in particular, for the purposes of payment processing, bookkeeping, billing, fulfilling tax obligations, and complying with legal documentation requirements. The data will be deleted as soon as it is no longer necessary for the aforementioned purposes, provided that no statutory retention obligations preclude this. If statutory retention obligations exist, the relevant data will be stored for the duration of these obligations and subsequently deleted, unless further storage is necessary to assert, exercise, or defend legal claims.

8. Online Meetings, Video Conferences, Webinars, and AI-Powered Summaries with Microsoft Teams

We use Microsoft Teams to conduct online meetings, video conferences, webinars, online coaching sessions, workshops, training sessions, and other digital events. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. The involvement of other companies within the Microsoft Group, in particular Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA, cannot be ruled out. We are responsible for data processing in connection with the organization and conduct of online events, to the extent that we invite participants to the respective event and determine the purpose and means of processing. When using Microsoft Teams, the following personal data in particular may be processed: personal information, e.g., name, email address, and display name; meeting and technical metadata, e.g., date, time, duration, participant data, IP address, device, connection, and log data; communication content, e.g., audio, video, and chat messages; shared content, e.g., screen shares, presentations, or documents; as well as, where applicable, recordings, transcriptions, AI-generated notes, summaries, to-do lists, or conversation analyses, provided these features are used in specific cases. In the context of coaching sessions, consultations, or similar confidential appointments, it cannot be ruled out that participants may voluntarily disclose special categories of personal data as defined in Article 9 of the GDPR. We ask that you provide such information only to the extent necessary for the respective appointment. To the extent that special categories of personal data within the meaning of Article 9 of the GDPR are processed, this is done only on the basis of a relevant legal basis pursuant to Article 9(2) of the GDPR, in particular on the basis of explicit consent pursuant to Article 9(2)(a) of the GDPR, to the extent that such consent is required. The processing is carried out for the purpose of organizing and conducting the respective online appointments, communicating with you, and providing our services. The legal basis is Article 6(1)(b) of the GDPR, to the extent that the processing is necessary for the performance of pre-contractual or contractual obligations. To the extent that the processing is based on our legitimate interest in efficient, location-independent communication and the provision of our services, the legal basis is Article 6(1)(f) of the GDPR. To the extent that consent is required—in particular for recordings, transcriptions, or AI-generated summaries—the legal basis is Article 6(1)(a) of the GDPR. A recording, transcription, or AI-powered summary of an online meeting will only be created if this has been announced in advance and the data subjects have given their consent. Consent that has been given may be revoked at any time with future effect. The lawfulness of the processing carried out up to the time of revocation remains unaffected. To the extent that we use Microsoft Teams Copilot or comparable AI-powered features, meeting content may be used to generate, in particular, automatic summaries, meeting notes, action items, or to-do lists. Depending on the settings, these features may be based on transcriptions or on temporary speech processing during the meeting. Microsoft provides further information on this at the following link: https://learn.microsoft.com/en-us/microsoftteams/copilot-teams-transcription When providing Microsoft Teams, Microsoft generally processes personal data as a data processor based on a data processing agreement in accordance with Article 28 of the GDPR. To the extent that Microsoft processes personal data for its own purposes, Microsoft is solely responsible for such processing. Further information on Microsoft’s data protection obligations and the Microsoft Data Protection Addendum can be found at: https://learn.microsoft.com/de-de/legal/gdpr The processing of personal data outside the European Union or the European Economic Area—particularly in the United States—cannot be ruled out. Microsoft defines an EU Data Boundary for Microsoft 365 regarding the storage and processing of customer data and personal data. At the same time, certain data transfers outside the EU Data Boundary may still occur. For more information, see: https://learn.microsoft.com/en-us/privacy/eudb/eu-data-boundary-learn https://learn.microsoft.com/en-us/privacy/eudb/eu-data-boundary-transfers-for-all-services According to its own statements, Microsoft is certified under the EU-U.S. Data Privacy Framework and uses appropriate safeguards for international data transfers, in particular EU Standard Contractual Clauses. For more information, see: https://www.microsoft.com/de-de/privacy/privacystatement https://learn.microsoft.com/de-de/compliance/regulatory/offering-eu-model-clauses Despite existing safeguards and guarantees, access to personal data by authorities in third countries, particularly the U.S., cannot be ruled out with absolute certainty. The data processed in connection with online appointments will be deleted as soon as it is no longer necessary for the stated purposes, there are no legal retention requirements, and there are no legitimate interests in further storage. Recordings, transcripts, and AI-generated summaries will be stored only as long as necessary for the respective purpose or as separately specified in individual cases. For more information on data processing by Microsoft, please see the Microsoft Privacy Statement at: https://www.microsoft.com/de-de/privacy/privacystatement

9.  Your rights as a data subject

a. Right to object, Art. 21 GDPR

If we process your data to protect legitimate interests (Art. 6 para. 1 lit. f) GDPR), you may object to this processing for reasons arising from your particular situation. We will then no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or the processing serves to assert, exercise or defend legal claims. In the event of an objection to data processing for direct marketing purposes, processing for this purpose will no longer take place.

b. Right to information, Art. 15 GDPR

You have the right to obtain confirmation from us as to whether we are processing personal data concerning you and, if so, a right to information about the personal data and related information (Art. 15 para. 1 lit. a – h GDPR).

c. Right to rectification, Art. 16 GDPR

You have the right to request that we correct any inaccurate personal data concerning you without undue delay. In addition, taking into account the purposes of the processing, you have the right to request the completion of incomplete personal data, including by means of a supplementary statement.

d. Right to erasure, Art. 17 GDPR

You have the right to request that we erase personal data concerning you without undue delay, and we are obliged to erase such data without undue delay if one of the grounds specified in Art. 17 GDPR applies.

e. Right to restriction of processing, Art. 18 GDPR

You have the right to request that we restrict the processing of personal data concerning you if one of the conditions set out in Art. 18 GDPR is met.

f. Right to data portability, Art. 20 GDPR

You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, and you have the right to transmit.

g. Withdrawal of Consent, Art. 7(3) GDPR

You have the right to withdraw your consent at any time with future effect. The lawfulness of the processing carried out on the basis of your consent up until the time of withdrawal remains unaffected.

h. Right to lodge a complaint, Art. 77 GDPR

If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a data protection supervisory authority.

State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia

P.O. Box 20 04 44 40102 Düsseldorf Phone: +49 (0)211 - 38424-0 Fax: +49 (0)211 - 38424-999 Email: poststelle@ldi.nrw.de

de_DEDeutsch