Germany
Maximilianstr. 280539 München
Germany+49 89 4444 373-20
Kanzlei Verbracken & Partner GmbH
Information about personal data processing under Swiss data protection law and, where applicable, GDPR.
The controller for this website is Kanzlei Verbracken & Partner GmbH, Alter Postplatz 2, 6370 Stans, Switzerland, UID CHE-478.695.246. Send privacy enquiries and rights requests by post to this address or by email to info@kanzlei-verbracken.com, using the subject “Privacy”. This contact does not imply appointment of a statutory data protection adviser or EU representative.
This notice covers website visits, media, downloads and preparation of enquiries. Swiss FADP, its Ordinance and, where relevant, Article 45c(b) of the Telecommunications Act apply. Where the GDPR applies territorially, its requirements also apply. Separate engagements may require additional notices. Reading this policy is not consent to tracking or the creation of an engagement.
We process connection data such as IP address, URL, time, browser, device and referrer. Enquiries and bookings include names, contact details, messages and appointment information. An initial assessment also involves the financial and personal information you provide, including debts, employment and taxes. Voluntary documents may contain sensitive personal data. With consent, analytics and advertising services process usage events, online identifiers and referral information. Provide only information necessary for your enquiry.
We process data to provide the website, answer enquiries, organise appointments, deliver requested services, fulfil legal duties and protect security and legal claims. Analytics and advertising require your consent. We follow Swiss principles of lawfulness, proportionality, purpose limitation, transparency and security. Where justification is required, we rely on consent, overriding interests or law. Where GDPR applies, Article 6(1)(b) covers contractual and pre-contractual steps, (c) legal duties, (f) necessary security and administration, and (a) consent-based processing. Additional requirements apply to special categories, including Article 9 GDPR.
Our website is hosted on servers in Germany. The hosting and infrastructure provider processes connection and log data on our behalf, including IP address, requested file, time, response status and browser information. Purposes are website delivery, maintenance, troubleshooting and abuse prevention. Logs are retained as required for operational and security purposes; specific incidents may require retention for investigation and legal claims. Separate third-party services process data in the countries described below, irrespective of the German hosting location.
When you contact us by form, email or telephone, we process your information to assess and answer your enquiry and organise further cooperation. Website forms pass through an internal interface to the responsible people and systems. We use Close for contact management and Calendly for appointments. Personal and financial information serves your enquiry and is not used as advertising audience criteria. Contacting us does not constitute consent to advertising or tracking. Ordinary email is not necessarily end-to-end encrypted; agree a suitable channel with us for particularly confidential documents. Additional information may apply to individual engagements.
We use cookies, Local Storage and Session Storage. Necessary storage supports website functionality, privacy preferences and language choice. Additional analytics, advertising and media identifiers are used under the respective consent. Session entries expire with the session; persistent entries remain until expiry or deletion. You can delete or block storage through your browser, which may limit functionality.
You choose whether to permit optional analytics, advertising and media services. Without the respective consent, these services are not loaded and associated measurement or advertising signals are not sent. Change or withdraw consent through Cookie settings; YouTube also has a disable option in the video section. Withdrawal takes effect for the future and cannot recall previously transmitted data. Provider cookies can also be deleted through your browser. Where applicable, access to non-essential device information requires consent under Section 25 TDDDG. Necessary storage follows the statutory exception. Consent to contact is separate from tracking consent.
We embed YouTube using youtube-nocookie.com after your consent. Google Ireland Limited, Ireland, provides the European service; processing by Google LLC in the USA is possible. Loading the player transmits IP address, device/browser data, page information and playback events. Google may associate these with a logged-in account. Privacy-enhanced mode does not eliminate all transfers. Local thumbnails, videos, fonts, publication PDFs and review excerpts are served directly by our website without contacting their original platforms.
We use Google Analytics 4 for website statistics and improvement after consent. It evaluates page views, interactions, duration, referral sources and device/browser information using pseudonymous identifiers. Google Ireland Limited, Ireland, and Google LLC, USA, participate in provision. Google states that GA4 does not log or store IP addresses, although connections require their processing. Advertising attribution also requires advertising consent. We do not transmit free-text enquiries, engagement documents or details of debt or health to Analytics.
We use Google Ads for advertising and conversion measurement after consent. Click identifiers including gclid, gbraid or wbraid connect defined website events to advertisements. Technical data, events and pseudonymous identifiers support measurement and permitted remarketing. Google Ireland Limited, Ireland, and Google LLC, USA, participate; account association is possible. Consent is voluntary and withdrawable. Confidential enquiry content and financial hardship information are excluded. Enhanced conversions or customer-list matching require an appropriate basis and separate transparent information; an ordinary enquiry does not authorise matching.
We use Meta Ads, Meta Pixel and Conversions API to advertise on Facebook and Instagram and measure results. After consent, defined events, identifiers, device/browser data and page information are sent to Meta Platforms Ireland Limited, Ireland. Server-side API transmission remains subject to consent. Meta may associate events with an account and process them for measurement and permitted audiences, including through Meta Platforms, Inc., USA. Joint collection and transmission are subject to applicable joint-controller arrangements; subsequent independent processing follows Meta’s notice. Confidential form content and financial hardship data are excluded.
We use TikTok Ads, Pixel and Events API for advertising and measurement after consent. Defined interactions, page information, IP address, device/browser data and identifiers are transmitted through the browser or server. European providers include TikTok Technology Limited, Ireland, and TikTok Information Technologies UK Limited, UK. Account association is possible. International processing and access may include the USA, Singapore and China, subject to the transfer provisions below. Confidential enquiries and financial hardship information are excluded.
Google Tag Manager manages website tags in accordance with your privacy choice. It is not itself consent. Server-side measurement and Consent Mode do not remove legal requirements for processing. External links, including review, social and booking links, open the provider’s service when clicked, subject to its privacy notice. Locally hosted media and downloads do not connect to their original source.
We use LinkedIn Ads and Insight Tag for campaign measurement and permitted audiences after consent. URL, time, IP address, device/browser data and interactions are transmitted to LinkedIn Ireland Unlimited Company, Ireland; processing by LinkedIn Corporation, USA, is possible. LinkedIn can associate visits with member accounts and provide aggregate reports. Confidential information and pages with sensitive consultation content are excluded. Consent does not override platform restrictions on sensitive data.
We use Microsoft Advertising / Bing Ads and UET for campaign measurement and permitted audiences after consent. Defined events, identifiers including msclkid and technical data are transmitted to Microsoft Ireland Operations Limited, Ireland, and Microsoft Corporation, USA. Association with a Microsoft account is possible. Confidential form, personal and financial information is excluded. Microsoft Clarity and full session recording are not part of this service.
We use Close, provided by Elastic Inc., USA, to manage contacts, enquiries and progress. Necessary names, contact details, messages and case information pass from our website through an internal interface to the CRM, without requiring a direct browser connection. Access is limited to responsible staff and necessary service providers. Close acts as our processor; US transfers follow the safeguards described below. Calendly LLC, USA, provides appointment booking. Opening a booking link allows Calendly to process connection data and the name, email and appointment details you enter. Enquiries and bookings are not automatically shared as advertising customer lists. Where applicable, GDPR Article 6(1)(b) covers requested pre-contractual services and (f) necessary supplementary administration.
When you submit an advertising-platform lead form, we receive your contact and enquiry information to respond. The platform also processes data under its own notice. Information displayed with that form applies. An enquiry does not subscribe you to a newsletter. Electronic marketing follows required consent or statutory exceptions, and you may object at any time. Separate consent applies only to its stated purpose.
Debt, assets, health, family and legal information is confidential and purpose-limited. It is not used for advertising audiences. Analytics and advertising events exclude free-text enquiries and engagement documents. Pseudonymous identifiers and hashed contact data are not automatically anonymous. We do not make exclusively automated decisions about accepting or legally assessing an engagement with legal or similarly significant effects. Automated routing only prepares personal handling.
Recipients include responsible staff and necessary hosting, IT, communications, CRM, booking and processing providers. Professional partners receive information where necessary and lawful and may act as independent controllers. Authorities, courts and other parties receive data where law requires or legal claims justify it. Advertising and media recipients are identified above. Hosting is in Germany; service processing includes Ireland, the USA and UK, with TikTok also involving Singapore and China. Transfers to countries without recognised adequate protection rely on appropriate safeguards, including applicable standard contractual clauses with Swiss adaptations and supplementary measures, or a statutory exception. The Swiss-US Data Privacy Framework only covers appropriately certified recipients and processing; certification is not assumed for every provider. GDPR Articles 44 onward apply where relevant. Foreign access may involve public-authority access and more difficult enforcement. Contact us for information on safeguards applicable to your data.
We retain personal data for its necessary purpose, enquiry handling and subsequent cooperation, then delete or anonymise it unless law or necessary evidence for claims requires retention. Relevant accounting records are retained for ten years where legally required; this does not apply indiscriminately to all website data. Technical logs follow operational, troubleshooting and security needs; analytics and advertising data follow measurement purposes and service settings. Renewed consent does not justify unlimited retention. Independently acting providers apply their own retention criteria. Appropriate technical and organisational safeguards restrict access and protect transmission and storage according to risk. No technical procedure guarantees absolute security.
Under the FADP, you may request access, correction and, subject to conditions, deletion/cessation of unlawful processing, a disputed-data note and portability of provided data. Consent may be withdrawn prospectively. Retention duties and others’ rights may limit requests. Proportionate identity verification may be required. Access is generally provided within 30 days, with notice of permissible delays. You may contact the FDPIC and seek judicial remedies. Where GDPR applies, Articles 15-22 and 77 provide additional rights; object to legitimate-interest processing for your particular situation, and to direct marketing at any time. Use the privacy contact above.
We update this notice when processing or legal requirements change. The version published here applies. Where changes require new consent, we request it separately. Updated: 14 September 2026.
Our offices