Privacy
Language and language selection
Our existing hosting service Amazon CloudFront uses the country inferred from the IP address to select a language on the first visit: German in Germany and English elsewhere. If the country is unavailable, German remains the default. No additional geolocation service is called. The country is not stored in our website statistics. This processing serves our legitimate interest in presenting our services in an understandable form (Article 6(1)(f) GDPR).
If you select DE or EN yourself, we store only that selection in the sarafi_lang cookie for up to 180 days. It contains no individual identifier and serves only to retain the language you expressly selected (section 25(2), no. 2 TDDDG). You can change the selection at any time using the language switch or reset it by deleting the cookie.
Data-saving server statistics
We count server-side requests to selected public information pages in order to understand the demand for our information and the origin of links and to improve our offerings. Only incoming page requests are evaluated for this purpose. There is no statistics script, no analytics cookies, no fingerprinting, and no visit or session identifiers. Length of stay, click behavior and movements of individuals are not recorded.
As soon as the request is processed, the information is reduced to a valid public page path and a rough category of the referral source sent, such as Google, Instagram, internal references or direct/unknown. Complete referral addresses, search parameters, IP addresses, browser information, form content and documents are not written to the statistics logs. We do not identify countries of origin or device profiles. Known bots and previews are filtered out whenever possible. Inquiry, order, payment, booking, portal and internal pages as well as criminal law pages are excluded.
Insofar as personal connection data is processed during this reduction, we base it on Article 6 (1) (f) GDPR. Our legitimate interests are designing our range of information in line with needs and evaluating its general reach. Meters are sufficient for this; they are not recognized or linked to mandate, order or contact data.
The reduced technical counting protocols are created by our existing hosting provider AWS. CloudFront functional logs are processed in the Northern Virginia, USA, AWS region and include technically enhanced timestamps and execution identifiers that we don't use to link calls. Retention is set for three days; the final technical deletion can normally take up to an additional 72 hours, according to AWS. Only day counters per page and referral category are stored on our Hetzner server in Germany for 30 days. The existing AWS order processing conditions and transfer regulations also apply to this hosting feature; for more information, see the AWS Privacy Policy linked below.
You can object to processing based on legitimate interests for reasons relating to your particular situation. “Do Not Track” and “Global Privacy Control” browser signals are taken into account for incoming requests. With the following button, you can also turn off counting without any reason for this browser. Only at your click is a technically required objection cookie set for one year (Section 25 (2) No. 2 TDDDG). It only contains the switch-off value, not an identifier.
The previous voluntary browser statistics have been switched off. Data already collected with consent will not be used for the new server count and will be deleted at the latest after its previous retention period of 30 days plus one hour. Any previous selection that may have been saved locally is no longer read out.
Responsible law firm
DR. SARAFI Rechtsanwaltsgesellschaft mbH
Leerbachstraße 54, 60322 Frankfurt
email: info@sarafi.de
Accessing this website
This website is delivered using Amazon S3 and Amazon CloudFront from Amazon Web Services (AWS). When retrieved, technically required connection data is processed. This may include the IP address, date and time, the requested resource and information about the browser. The processing is used to provide and secure the website.
The legal basis is Article 6 (1) (f) GDPR. We have a legitimate interest in the reliable and secure provision of our online offering. Information about data processing by the hosting provider can be found in the AWS privacy notices.
CloudFront delivers content over a globally distributed network. Technically required connection data can also be processed outside the European Union. Information about the privacy features of AWS services is available at AWS.
Request and email draft
The entries on our contact page are compiled into a draft email in the browser. This form does not submit the entries to its own form database. Only when you send the message in your e-mail program will it be sent to the law firm via your email provider.
We process received inquiries to process your request and to review a possible order. Depending on the issue, this is based on Article 6 (1) (b) or (f) GDPR. First, please only provide the information required for the request.
Account help, warning requests, and document upload
In account help and in the warning tool, your information is first processed locally. The facts, parties, deadlines, contact details and selected files will only be transferred to our server at Hetzner in Germany upon your express submission. They are used to review and process your request and to make a possible assignment. Please only provide the information and documents required for this purpose.
Depending on the person concerned and the purpose of processing, the legal bases are Art. 6 (1) (b) or (f) GDPR. Legitimate interests include the processing of legal concerns, the examination of conflicts of interest and the security of the service. Insofar as special categories of personal data are necessary to assert, exercise or defend legal claims, Article 9 (2) (f) GDPR applies.
Transmitted information and files are stored in encrypted form. Files are checked for malware before they are released. Authorized law firm employees receive access via protected access with an additional email code. The internal email notification only contains the process ID and the administrative link, no documents or factual content. There is no automatic transfer to the other party and no automatic mandate acceptance. In account help, we also record platform, account name, usage, restriction and previous complaint history. Please do not submit passwords, login codes, or recovery links.
Uncompleted draft uploads are automatically deleted after 24 hours. Submitted inquiries will only be stored for as long as is necessary for processing and relevant storage or documentation obligations. Please send requests for deletion and information to info@sarafi.de. Technical access data can be processed to secure and limit online input.
Calculators and classification forms
The free computers process your entries exclusively in your browser. These calculation values are not transmitted to the law firm or a calculation service. A distinction must be made between the protected collection portal and the online transmission in the account help and in the warning tool, which you use to consciously submit information and documents to the law firm.
Appointment booking, online orders and payment
The appointment booking retrieves free time from the law firm's booking service at api.sarafi.de. When you proceed with payment, your selection, contact and billing details will be sent to this service to prepare for the booking and a payment session. The processing serves to initiate and fulfill contracts (Article 6 (1) (b) GDPR) as well as legal billing and storage obligations (Article 6 (1) (c) GDPR).
In the case of online orders for file inspection or trademark registration, we also store the selected service, the order details required for allocation, as well as your confirmed remuneration agreement and declarations. The data is processed in the law firm backend on the Hetzner server in Germany and is only accessible to the responsible law firm after registration. Order and payment confirmations will be sent to the email address you provided. Procedural information and documents are not transmitted to Stripe as payment metadata.
We use Stripe for payment. The payment interface is only loaded when the payment process starts. Enter payment details with Stripe; the law firm receives the payment status and the information required for allocation, not your full card details. Stripe explains responsibilities, recipients and possible third-country transfers in its Privacy notices. Please do not submit any files or detailed confidential information in the booking form.
Protected debt collection portal
If you use the collection portal, we process your confirmed email address, login details, company and representative information, and the claim, debtor and procedural data you provide. This includes documents, messages, offers, assignments and approvals. Please only submit documents that are required for the specific request.
The processing is used to verify a possible assumption of a mandate, the agreed processing and secure communication. Depending on the data subject and purpose, it is based on Article 6 (1) (b), (c) or (f) GDPR; legitimate interests include in particular the verification and enforcement of legal claims and the security of the portal. Insofar as special categories of personal data are required, Article 9 (2) (f) GDPR is particularly relevant. There is no exclusively automated decision on the acceptance of a mandate.
Amazon Cognito is used for login and two-factor authentication. Claim data and documents are stored in encrypted AWS services in the Frankfurt region. Uploaded files are checked for malware using AWS GuardDuty Malware Protection; temporary download access is only granted after successful verification. Access is given to the responsible approved law firm employees and technically required service providers. Disclosure to involved colleagues, opponents, courts or authorities depends on the specific mandate and the required scope.
Protected access uses technically necessary cookies for login and session. The login process is limited to ten minutes and the portal session is limited to a maximum of one hour. The cookies are protected against reading by JavaScript. Their use is necessary for the expressly requested protected service (Section 25 Paragraph 2 No. 2 TDDDG). No advertising or analysis cookies are used in the portal.
Technical error logs are kept for 30 days; message and document content is not recorded in these error logs. Processes and evidence of offers and assignments are stored in accordance with the processing purpose and the relevant storage obligations. You can assert your rights to deletion and information via info@sarafi.de. Removing an account does not automatically result in the deletion of legally retained mandate documents.
Writings and images
The fonts and images used are provided by this website. The reduced movement setting is taken into account. No advertising pixels or embedded social media feeds were set up on the law firm pages.
Storage period
We only store personal data for as long as is necessary for the respective processing purpose or as long as there are legal storage obligations. When mandating, there are additional information and storage obligations for mandate processing.
Your rights
Within the framework of legal requirements, you have rights to information, correction, deletion, restriction of processing and data portability. You can object to processing based on legitimate interests for reasons relating to your particular situation. You can also complain to a data protection supervisory authority, in particular the Hessian Commissioner for Data Protection and Freedom of Information.
For questions or to exercise your rights, please contact info@sarafi.de.