Privacy Policy
How we protect and handle your personal information
1. Data Controller
Controller: Hucke & Sanker Partnerschaft
Address: Zusestraße 40, 50859 Cologne, Germany
Phone: +49 221 650 88 272
Email: [email protected]
2. Overview
At Hucke & Sanker, we are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your personal information when you visit our website or interact with our services.
As a law firm, we are bound by professional confidentiality obligations and data protection laws including the GDPR (EU General Data Protection Regulation) and other applicable privacy regulations.
3. Data Collection Principles
Data Minimization
We only collect personal data that is necessary for specific, explicit, and legitimate purposes. We avoid collecting unnecessary information.
Purpose Limitation
Your data is only processed for the purposes we have disclosed to you. We will not use your data for unrelated purposes without your consent.
Storage Limitation
We retain personal data only as long as necessary for the purposes for which it was collected, or as required by law and professional regulations.
Accuracy
We take reasonable steps to ensure your personal data is accurate and up-to-date.
Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.
4. Website Usage Data
Server Logs
Our web server automatically collects basic technical information for security and operational purposes:
- IP address (anonymized after 7 days)
- Timestamp and duration of visit
- Pages accessed and files downloaded
- Browser type and version
- Referring website
This data is processed on a legitimate interest basis for website security, availability, and optimization.
Content delivery network (Cloudflare)
This site is delivered through the network of Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA), which caches it and protects it against attacks. In doing so Cloudflare processes your IP address and the technical data of each request. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in fast and secure delivery). Cloudflare is certified under the EU-U.S. Data Privacy Framework (participant list of the U.S. Department of Commerce, checked 2026-09-10); the transfer to the United States rests on the European Commission's adequacy decision for that framework.
Cookies and measurement
Without your consent, this website sets no cookies at all — not even a technically necessary one.
Always on — audience measurement without cookies. We measure the use of this site with Plausible Analytics, which we host ourselves on our own server in Frankfurt am Main, Germany. Plausible sets no cookies and assigns no identifier that recognises you; your IP address is not stored, but combined with a daily-changing random value into a hash that cannot be reversed and becomes meaningless after 24 hours. The data never leaves our server and is not passed to any analytics provider. Legal basis: Art. 6 (1) (f) GDPR. Consent under § 25 TDDDG is not required because nothing is stored on or read from your device. You may object under Art. 21 GDPR.
Only with your consent — advertising measurement. If you accept in the consent dialog, we additionally load the Google Ads conversion tag (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) and the LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland). Both set cookies and recognise whether a click on one of our ads led to a visit here. Both providers build a profile of your behaviour and link it to data they already hold; if you are signed in with them, this visit can be attributed to your account. We have no influence over how far that linking goes.
Legal basis: § 25 (1) TDDDG and Art. 6 (1) (a) GDPR — your consent, and nothing else. Third-country transfers: both providers also process data in the United States, on the basis of the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework. Retention: cookie lifetimes are set by Google and LinkedIn, not by us; according to their own information they range from a few days to 24 months depending on the cookie. Their notices govern: Google and LinkedIn.
Without your consent none of this loads. The
scripts are present in the page source but disabled
(type="text/plain") and only run once you accept. A
tracking pixel that cannot be switched off is deliberately not
included. Your consent decision is stored in your browser's
localStorage under the key consent_v2 — that is not
a cookie, and it is never transmitted to us. Storing it is nonetheless an access to your device within the meaning of § 25 TDDDG; it needs no consent of its own because it is strictly necessary to provide a service you expressly requested — remembering your choice so we can honour it (§ 25(2) no. 2 TDDDG). It is kept for six months, after which you are asked again, and the button below deletes it at any time.
The button deletes your stored decision and reloads the page. You will then be asked again, and no advertising service loads until you make a new choice. Withdrawal takes effect for the future; the lawfulness of processing carried out beforehand is unaffected. Cookies already set by Google and LinkedIn can additionally be removed in your browser settings.
5. Contact and Inquiry Data
When you contact us via email, contact form, or phone, we collect:
- Your name and contact information
- The content of your inquiry or message
- Communication history
- Any documents you provide
This data is processed based on your consent and our legitimate interest in responding to your inquiry. If you become a client, this data becomes part of your client file and is subject to attorney-client privilege.
6. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent: When you provide explicit consent for specific processing activities
- Performance of a Contract: When we have an engagement agreement with you
- Legal Obligation: When required by law, court order, or professional regulations
- Legitimate Interest: When we have a legitimate interest that is not overridden by your privacy rights
7. Data Sharing and Third Parties
We do not sell or rent your personal data. We share it only in the following circumstances:
- Advertising measurement — only with your consent: If you accept in the consent dialog, Google Ireland Limited and LinkedIn Ireland Unlimited Company receive data about your visit for advertising measurement, as described under Cookies and measurement above. This is the only case in which your data is used for marketing purposes, and it does not happen without your consent.
- Service Providers: With trusted IT service providers who assist in operating our website and services (subject to data processing agreements)
- Legal Requirements: When required by law, court order, or regulatory authority
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- Professional Obligations: When necessary to provide legal services or protect your interests
8. International Data Transfers
As a transnational law firm, we may transfer your data outside the European Economic Area (EEA). Such transfers are protected by:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Appropriate technical and organizational security measures
9. Your Rights
Under the GDPR and applicable privacy laws, you have the right to:
- Access: Request access to your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data (subject to legal and professional obligations)
- Portability: Request transfer of your data to another controller
- Objection: Object to processing of your data
- Restriction: Request restriction of processing
- Complaint: Lodge a complaint with a supervisory authority
To exercise these rights, please contact us at [email protected].
10. Data Retention
We retain personal data according to the following periods:
- Website logs: 7 days (IP addresses anonymized after this period)
- Contact inquiries: 6 months from last contact, unless retained as potential client
- Client files: 10 years after engagement completion, as required by professional regulations
- Accounting records: 10 years as required by tax law
11. Security Measures
We implement appropriate technical and organizational security measures including:
- SSL/TLS encryption for data transmission
- Secure authentication and access controls
- Regular security audits and updates
- Employee training on data protection
- Secure data storage and backup systems
12. Children's Privacy
Our website is not directed to children under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete such information immediately.
13. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of any material changes by posting the updated policy on our website with a new effective date.
14. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer:
Email: [email protected]
Phone: +49 221 650 88 272
Address: Zusestraße 40, 50859 Cologne, Germany
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority competent for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf, Germany
www.ldi.nrw.de
For matters of professional conduct — as distinct from data protection — the competent chamber is:
Rechtsanwaltskammer Köln
Christophstraße 2
50670 Köln, Germany
www.rak-koeln.de
This Privacy Policy was last updated on 2026-09-08