Privacy Policy

1. data protection at a glance

General information

When you visit this website, personal data is processed. Personal data is any data with which you can be personally identified. The following notes explain which data we collect and the purpose for which this is done. For detailed information on the subject of data protection, please refer to our privacy policy listed below this text.

Data collection on our website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. You can find his contact details in the imprint of this website.

How do we collect your data?

On the one hand, your data is collected when you voluntarily provide it to us. This can be, for example, data that you transmit to us in the context of an application.

On the other hand, data is automatically collected by our IT systems when you visit this website. This is mainly technical data, e.g. Internet browser, operating system type and version, time of access and IP address.

What do we use your data for?

Part of the data is collected to ensure error-free provision of the website, as well as the security of our website.

Another part of the data may be used to analyze your usage behavior, as well as for statistical evaluation of your interests.

What rights do you have in connection with your data?

You have the right to obtain information free of charge at any time about the purpose, the categories of personal data processed, the recipient, the duration of storage, as well as the origin of the data stored about you. You also have the right to request the correction of incorrect data and/or the deletion or restriction of processing. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

2 General notes and mandatory information

Data protection

The operator of this website takes the protection of your personal data very seriously. We treat your personal data with the utmost confidentiality and in accordance with the statutory data protection regulations and this data protection declaration.

We would like to point out that data transmission on the Internet (e.g. when communicating by e-mail) can have security gaps. Complete protection of data against access by third parties is not possible.

Note on the responsible entity

The responsible body is the natural or legal person who alone or jointly with others decides on the purposes and means of the processing of personal data. The responsible body for data processing on this website is:

c/o H&Z Unternehmensberatung AG
Max-Joseph-Straße 6
80333 Munich

Revocation of consent to data processing

Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. For this purpose, an informal communication by e-mail to us is sufficient. Your revocation will not affect the lawfulness of the processing carried out on the basis of the consent until the revocation.

Right of appeal to the competent supervisory authority

If you are of the opinion that the processing of personal data concerning you violates data protection regulations, you have the right to lodge a complaint with the competent supervisory authority.

As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our office location (Bavarian State Commissioner for Data Protection and Freedom of Information) for this purpose. A list of the state data protection commissioners, as well as their contact information, can be found at the following link:

Right to data portability

You also have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a structured, common and machine-readable format. If you request the direct transfer of the data to another responsible party, it will only be carried out insofar as this is technically feasible.

SSL or TLS encryption

This site uses SSL or TLS encryption in compliance with the data protection regulations according to Art. 32 DS-GVO for security reasons and to protect the transmission of confidential content, such as requests that you send to us as site operator. You can recognize an encrypted connection on the one hand by the fact that the address line of the browser changes from "http://" to "https://" and on the other hand by the lock symbol in your browser line. If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Analysis tools and tools from third parties

By visiting our website, your surfing behavior can be statistically analyzed. This is done in particular through the use of cookies and with so-called analysis programs. The analysis is anonymous, so that the surfing behavior can not be traced back to you. You can object to this analysis or prevent it by not using certain tools. Detailed information can be found in the following privacy policy.

Transfer of personal data to third countries

If we transfer data to third countries, i.e. countries outside the European Union, the transfer takes place exclusively in compliance with the legal requirements. If the transfer of data to a third country is not for the performance of our contract with you, we do not have your consent, the transfer is not necessary for the assertion, exercise or defense of legal claims, and no other exemption under Article 49 of the GDPR applies, we will only transfer your data to a third country if an adequacy decision under Article 45 of the GDPR or appropriate safeguards under Article 46 of the GDPR are in place. One of these adequacy decisions is the Commission's Implementing Decision (EU) 2016/1250 of 12.07.2016 on the so-called "EU-US Privacy Shield" ("Privacy Shield") for the USA. For transfers to companies certified under the EU-US Privacy Shield, the level of data protection is generally considered adequate within the meaning of Article 45 of the GDPR.

Right to information, correction, deletion, restriction, objection

You have the right to obtain information free of charge at any time about your personal data processed and stored by us, the purposes of the data processing, the categories of personal data processed, the categories of recipients to whom your data have been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right of complaint, the origin of your data if it has not been collected by us, as well as about the existence of automated decision-making including profiling and, if applicable, meaningful information about its use. Request meaningful information about its details. To exercise your rights, you can contact us at any time by e-mail at

Objection to advertising e-mails

We hereby object to the use of the contact data published in the imprint to send advertising and information material that has not been expressly requested. In the case of unsolicited sending of advertising information, such as spam e-mails, the operator of the site reserves the right to take legal action.

3. data collection on our website in detail

Server log files

The provider of the website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us when you visit the website. These are:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Amount of data transferred
  • Used end device of the user, including MAC address
  • Host name of the accessing computer
  • Date and time of server request
  • IP address

These files are not merged with other data sources.

The basis for data processing is Art. 6 (1) lit. b, f DSGVO, which permits the processing of data for the fulfillment of a contract or a pre-contractual measure, as well as for the protection of legitimate interest. The legitimate interest here is the technically error-free and optimized provision of our services to you.

Inquiries by e-mail, telephone, fax

If you contact us by e-mail, telephone or directly, your inquiry including all resulting personal data (name, contact details, inquiry itself) will be stored and processed by us for the purpose of processing your request. We do not pass on this data without your consent.

The processing is based on Art. 6 (1) lit. b DS-GVO if your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on your consent pursuant to Art. 6 para. 1 lit a DS-GVO and /or on our legitimate interest pursuant to Art. 6 para. 1 lit. f. DS-GVO, as we have a legitimate interest in the effective processing of requests addressed to us. You can revoke this consent at any time. For this purpose, an informal communication by e-mail to us is sufficient. Your revocation will not affect the lawfulness of the processing carried out on the basis of the consent until the revocation.

The data you send to us by contact request will remain with us until you request us to delete it, revoke your consent to store it or the purpose for storing the data no longer applies, e.g. due to the completed processing of your request. Mandatory legal provisions - in particular retention periods - remain unaffected. delivers exactly the guidance that needs who wishes to procure sustainably