Data privacy

This privacy notice tells you what to expect me to do with your personal data when you contact me or use my services. This privacy notice complies with the respective requirements of the EU General Data Protection Regulation (GDPR), applicable national data protection laws and regulations. This privacy notice also informs you about rights you have regarding your personal data and how you can contact me in this respect.


1. Name and contact details of the data controller

This data protection information applies to data processing by:

Law Firm GERSTBERGER l Products & Law
Dr. Ina Gerstberger
Maximilianstrasse 2
80538 Munich, Germany

Phone: +49.89 356477130
Fax: +49.89 356477139

I can be reached at the above address or also at

2. Collection and storage of personal data as well as the type and purpose of their use when visiting the website

When you visit my website, the browser used on your device automatically sends information to the server of our website. This information is temporarily stored in a so-called log file. The following information will be collected without your intervention and stored until automated deletion:

  • IP address of the requesting computer,

  • Date and time of access,

  • Name and URL of the retrieved file,

  • Website from which access is made (referrer URL),

  • the browser used and, if applicable, the operating system of your computer as well as the name of your access provider.

The mentioned data will be processed by me for the following purposes:

  • Ensure a smooth connection of the website,

  • To ensure a comfortable use of my website,

  • Evaluation of system safety and stability as well as

  • for other administrative purposes.

The legal basis for data processing is Art. 6 Para. 1 S. 1 lit. f GDPR. My justified interest follows from the purposes listed above for the collection of data. In no case do I use the collected data for the purpose of drawing conclusions about your person.

I also use cookies and analysis services when visiting my website. You will find more detailed information on this under points 4 and 5 of this data protection declaration.

3. Disclosure of data

Your personal data will not be transferred to third parties for purposes other than those listed below.

I only give your personal data to third parties if:

  • you have given your express consent to this in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR,

  • the disclosure pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR is necessary for the assertion, exercise or defence of legal claims and there is no reason to assume that you have an overriding legitimate interest in not disclosing your data,

  • if there is a legal obligation to pass on data pursuant to Art. 6 para. 1 sentence 1 lit. c GDPR, and

  • this is legally permissible and required for the execution of contractual relationships with you pursuant to Art. 6 Para. 1 S. 1 lit. B GDPR.

4. Cookies

I use cookies on my site. These are small files that your browser automatically creates and stores on your device (laptop, tablet, smartphone, etc.) when you visit my site. Cookies do not cause any damage to your device, do not contain viruses, Trojans or other malware. Information is stored in the cookie, which results in each case in connection with the specifically used device. However, this does not mean that I will immediately become aware of your identity.

The use of cookies serves on the one hand to make the use of my offer more pleasant for you. I use so-called session cookies to recognize that you have already visited individual pages on my website. These will be deleted automatically after leaving my site.

In addition, I also use temporary cookies to optimize user-friendliness, which are stored on your device for a specified period. If you visit my page again, in order to use my services, it is automatically recognized that you were already with me and which inputs and settings you have made, in order not to have to enter these again.

On the other hand, I use cookies in order to statistically record the use of my website and to evaluate it for the purpose of optimising my offer for you (see Clause 6). These cookies enable me to automatically recognize that you have already visited my site when you visit it again. These cookies are automatically deleted after a defined period.

The data processed by cookies are necessary for the purposes mentioned to protect my legitimate interests and those of third parties in accordance with Art. 6 Para. 1 S. 1 lit. f GDPR.

Most browsers automatically accept cookies. However, you can configure your browser so that no cookies are stored on your computer or a message always appears before a new cookie is created. However, if you disable cookies completely, you may not be able to use all the features of my website.

5. Google Maps

This web site uses Google Maps to display interactive maps and to provide driving instructions.

Google Maps is a map service from Google Inc., 1600 Amphitheatre Parkway, Mountain View, California 94043, USA. By using Google Maps, information about the use of this website, including your IP address and the (start) address entered as part of the route planner function, may be transmitted to Google in the USA. If you call up a website of my internet appearance which contains Google Maps, your browser establishes a direct connection with the servers of Google. The map content is transmitted by Google directly to your browser and integrated into the website by it. Therefore, I have no influence on the extent of the data collected in this way by Google. To the best of my knowledge, these are at least the following data:

  • the date and time of the visit to the website in question,

  • Internet address or URL of the website accessed,

  • IP address, the (start) address entered during route planning.

I have no influence on the further processing and use of the data by Google and can therefore assume no responsibility for this. If you do not want Google to collect, process or use data about you via my website, you can deactivate JavaScript in your browser settings. In this case, however, you cannot use the map display function. The purpose and scope of the data collection and the further processing and use of the data by Google as well as your related rights and settings to protect your privacy, please refer to Google’s privacy policy. (

By using my website, you consent to the processing of data about you by Google Maps in the manner and for the purposes set out above.

6. Google Analytics

For the purpose of the needs-based design and continuous optimization of my pages, I use Google Analytics, a web analysis service of Google Inc. ( intl/en/about/) (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; hereinafter “Google”). In this context, pseudonymised user profiles are created and cookies (see section 4) are used. The information generated by the cookie about your use of this site such as

  • Browser type/version,

  • operating system used,

  • Referrer URL (the previously visited page),

  • Host name of the accessing computer (IP address),

  • Time of the server request,

are transferred to a Google server in the USA and stored there. The information is used to evaluate the use of the website, to compile reports on website activities and to provide other services related to website and Internet use for market research purposes and to design these Internet pages in line with requirements.

This information may also be transferred to third parties if this is required by law or if third parties process this data on behalf of third parties. Under no circumstances will your IP address be merged with other Google data. The IP addresses are anonymized so that an assignment is not possible (IP masking). You may refuse the use of cookies by selecting the appropriate settings on your browser, however, please note that if you do this you may not be able to use the full functionality of this website. You may also prevent the collection of data generated by the cookie and relating to your use of the website (including your IP address) and the processing of such data by Google by downloading and installing a browser add-on (https:// As an alternative to the browser add-on, especially for browsers on mobile devices, you can also prevent Google Analytics from capturing data by clicking An opt-out cookie is set to prevent your data from being collected in the future when you visit this website. The Opt-out-cookie is only valid in this browser and only for my website and is stored on your device. If you delete the cookies in this browser, you must set the opt-out cookie again. Further information on data protection in connection with Google Analytics can be found in the Google Analytics help ( 6004245?hl=en).

7. Google Adwords Conversion Tracking

In order to statistically record the use of my website and to evaluate it for the purpose of optimizing my website for you, I also use Google Conversion Tracking. Google Adwords will set a cookie (see Clause 4) on your computer if you have reached my website via a Google advertisement. These cookies lose their validity after 30 days and are not used for personal identification. If the user visits certain pages on the AdWords customer’s website and the cookie has not expired, Google and the customer will be able to tell that the user clicked on the ad and was directed to that page. Each Adwords customer receives a different cookie. Cookies cannot therefore be traced via the websites of Adwords customers. The information collected using the conversion cookie is used to generate conversion statistics for Adwords customers who have opted for conversion tracking. Adwords customers see the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, you will not receive any information that personally identifies users. If you do not wish to participate in the tracking procedure, you can also refuse to set a cookie as required for this purpose – for example by setting your browser to deactivate the automatic setting of cookies in general. You can also disable cookies for conversion tracking by setting your browser to block cookies from the domain “”. Google’s Privacy Policy for Conversion Tracking can be found here (

8. Social Media Plug-ins

I maintain profiles on the social media platforms LinkedIn ( and XING ( under my name to network, gain information and to showcase my advisory services. On my website, these profiles are hyperlinked by using the plattforms’ respective icons. This means you will be linked to my respective social media plattform profile when you click on the respective link. If you choose to interact with me on these social media platforms (e.g. by commenting), which is at your full discretion, you will likely publish and disclose your personal data (such as your name or your picture). Insofar I process your personal data in the context of using these social media platforms, I do this for the abovementioned purposes and the legal basis for such processing is Art. 6 para. 1 lit. f GDPR. With respect to any processing of your personal data by the social media platforms themselves, which I have no control over, please refer to their respective privacy statements:

  • LinkedIn:

9. Google Web Fonts

In order to properly display the contents of this websites for all browsers, this website, like most websites, uses the font library Google webfonts ( Google webfonts will be transferred into the cache of your browser to avoid multiple loading. If your browser does not support Google webfonts or prohibits the transfer, my website contents will be displayed in a standard font. Activating the font library Google webfonts automatically starts a connection to the provider of such library. Theoretically – and it is currently unclear if this is the case at all and if so, for what purposes – the provider of Google webfonts may collect data. The privacy policy of the font library provider Google can be found here:

10. Processing of data when using the website – your requests by e-mail

If you send me an inquiry by e-mail, I collect your data for reviewing and responding to your request. I store this information for verification purposes for a period of up to two years. Legal basis for data processing is Article 6(1) sentence 1(f) GDPR. I will not pass on your data to third parties unless this is necessary to answer your enquiry or is permitted or required by law.

11. Rights of the data subject

You have the right:

  • to request information about your personal data processed by me in accordance with Art. 15 GDPR. In particular, you may request information on the purposes of processing, the category of personal data, the categories of recipients to whom your data have been or will be disclosed, the planned duration of storage, the existence of a right to rectification, erasure, limitation of processing or opposition, the existence of a right of appeal, the origin of your data if not collected from me, as well as the existence of automated decision-making including profiling and, where applicable, meaningful information on its details;

  • in accordance with Art. 16 GDPR to immediately request the correction of incorrect or incomplete personal data stored by me;

  • to demand the deletion of your personal data stored with me in accordance with Art. 17 GDPR, insofar as the processing is not necessary for the exercise of the right to freedom of expression and information, for the fulfilment of a legal obligation, for reasons of public interest or for the assertion, exercise or defence of legal claims;

  • to demand the restriction of the processing of your personal data in accordance with Art. 18 GDPR if the accuracy of the data is disputed by you, the processing is unlawful, but you refuse to delete it and I no longer need the data, but you need it to assert, exercise or defend legal claims or you have objected to the processing in accordance with Art. 21 GDPR;

  • in accordance with Art. 20 GDPR, to receive your personal data which you have provided to me in a structured, common and machine-readable format or to request transmission to another responsible person;

  • in accordance with Art. 7 para. 3 GDPR to revoke your consent once given to me at any time. As a consequence, I may not continue the data processing based on this consent for the future; and

  • to complain to a supervisory authority pursuant to Art. 77 GDPR. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or of my office for this purpose.

12. Right of objection

If your personal data are processed based on legitimate interests pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR, you have the right, pursuant to Art. 21 GDPR, to object to the processing of your personal data if there are reasons for doing so which arise from your particular situation or if the objection is directed against direct advertising. In the latter case, you have a general right of objection, which is implemented by me without stating a particular situation.

If you wish to make use of your right of withdrawal or objection, simply send an e-mail to

13. Data security

I have taken security measures on my website to protect any personal data collected from unauthorized access, loss or unauthorized use und to ensure a secure data transfer. I use the common SSL-Procedure (Secure Socket Layer) in connection with the highest encryption level supported by your browser, typically 256 bits. If your browser does not support 256-bit encryption, I use 128-bit v3 technology instead. You can check for an encrypted transfer of any site of my web presence by looking at the key or lock symbol in your browser.

I also make use of suitable technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or against unauthorized access by third parties. My security measures are continuously improved in line with technological developments.

Please note that, given the general internet infrastructure and set-up, an unintended data access by third parties remains possible and it is also your responsibility to protect your data against misuse through encryption or otherwise. Without sufficient security measures on your part, unencrypted data transfers – including by email – can potentially be reviewed/accessed by third parties.

14. Version and update of this privacy notice

This privacy notice is currently valid and has the status 07/2019.

Due to changes to my website or changes required by law, changes to this privacy notice may be required. The respective valid privacy notice can be accessed at