Privacy information:

How We Handle Your Data and Your Rights

Information pursuant to Articles 13, 14, and 21 of the EU General Data Protection Regulation (GDPR)

The following information is intended to provide you with an overview of how we process your personal data and the rights you have in this regard. The specific data that is processed and the manner in which it is used depend largely on the services you have requested or agreed to. Therefore, not all of the information contained herein may apply to you.

Data Controller

The controller within the meaning of the GDPR is:

hinsch.consulting
Holger Hinsch
Eisenlohrstraße 29
76135 Karlsruhe
Phone: +49 (0) 721 8514 8412
Email: info@hinsch-consulting.com

Contact for Data Protection Inquiries

If you have any questions regarding data protection, please contact:

info@hinsch-consulting.com

Type of Personal Data Processed

We generally receive personal data directly from you. To the extent necessary for establishing, conducting, or initiating a business relationship, personal data may also be obtained from companies, project partners, public sources, or other third parties authorized by you. We process the following personal data:

  • Company Name
  • Salutation, title, first name, and last name
  • Position or Area of Responsibility
  • Address (if provided)
  • Phone numbers
  • Email addresses
  • Communication and Correspondence Information
  • Contract, Billing, and Payment Information
  • Schedule and Project Data
  • Information on Consultations and Counseling
  • Other personal data voluntarily provided to us in the course of our business relationship.

Purposes and Legal Bases for Data Processing

We process personal data in accordance with the provisions of the European General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

To fulfill contractual obligations (Art. 6(1)(b) of the GDPR)

Data is processed for the purpose of: initiating contracts and fulfilling consulting and service agreements

Due to legal requirements (Art. 6(1)(c) of the GDPR)

We are subject to various legal obligations that require us to process data. These include, for example:

  • Tax laws and statutory accounting
  • Compliance with requests and requirements from regulatory or law enforcement agencies
  • Compliance with Tax-Related Audit and Reporting Requirements

In the context of balancing interests (Art. 6(1)(f) of the GDPR)

To the extent necessary, we process your data beyond the actual performance of the contract to protect our legitimate interests or those of third parties. Examples of such cases include:

  • Asserting Legal Claims and Defending Against Legal Disputes
  • Maintaining existing and potential business relationships and documenting business communications.

Recipients of Data

Internal Recipients

Within our company, the following departments or individuals may access your data:

  • Manager, Contact Person, or Account Manager
  • Accounting
  • IT/Technology

In the context of data processing on behalf of clients

Your data may be shared with the following types of service providers, who act as data processors on our behalf:

  • Support or maintenance of computer or IT applications
  • Accounting

All service providers are bound by contract and, in particular, are obligated to treat your data as confidential.

Other third parties

Data will only be disclosed to recipients outside our organization in compliance with applicable data protection regulations. Recipients of personal data may include, for example:

  • Public agencies and institutions (e.g., tax or law enforcement authorities) when there is a legal or regulatory obligation
  • Credit and Financial Services Providers (Payment Processing)
  • Tax advisor or auditor specializing in business, payroll, and corporate taxes (statutory audit engagement)
  • Technical service providers and project partners, to the extent necessary to carry out the respective assignment

Retention period

We process and store your personal data for as long as necessary to fulfill our contractual and legal obligations. Once the data is no longer needed to fulfill contractual or legal obligations, it is regularly deleted.

There are exceptions,

  • to the extent that statutory retention requirements must be met, e.g., under the German Commercial Code (HGB) or the German Fiscal Code (AO). The retention and documentation periods specified therein are generally six to ten years;
  • to preserve evidence within the framework of the statutory statutes of limitations. According to Sections 195 et seq. of the German Civil Code (BGB), these statutes of limitations may be as long as 30 years, although the standard statute of limitations is 3 years.

If data processing is carried out in our legitimate interest or that of a third party, the personal data will be deleted as soon as that interest no longer exists. The exceptions mentioned above apply in this regard.

Your Privacy Rights

As a data subject, you have the following data protection rights:

  • Right of access under Article 15 of the GDPR,
  • Right to rectification under Article 16 of the GDPR,
  • Right to erasure under Article 17 of the GDPR,
  • Right to restriction of processing under Article 18 of the GDPR,
  • Right to object under Article 21 of the GDPR,
  • Right to data portability under Article 20 of the GDPR.

With regard to the right of access and the right to erasure, restrictions under Sections 34 and 35 of the BDSG may apply.

In addition, you have the right to file a complaint with a competent data protection supervisory authority pursuant to Article 77 of the GDPR. The supervisory authority with jurisdiction over us is:

The State Commissioner for Data Protection and Freedom of Information in Baden-Württemberg
Prof. Dr. Tobias Keber
P.O. Box 10 29 32
70025 Stuttgart
(Street address: Heilbronner Straße 35, 70191 Stuttgart)
Phone: 0711 615541-0
Email: poststelle@lfdi.bwl.de

Provision required or mandatory

As part of the contractual relationship, you must provide the personal data necessary for the establishment, performance, and termination of the contractual relationship and for the fulfillment of the associated contractual obligations, or data that we are legally required to collect. Without this data, we will generally not be able to enter into or perform the contract with you.

Information Regarding Your Right to Object Under Article 21 of the General Data Protection Regulation (GDPR)

Right to Object on a Case-by-Case Basis

You have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you that is carried out pursuant to Article 6(1)(f) of the GDPR (data processing based on a balancing of interests); this also applies to profiling based on this provision within the meaning of Article 4(4) of the GDPR.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.

Recipient of an objection

The objection may be submitted in any form to: Holger Hinsch, info@hinsch-consulting.com

Changes to Our Privacy Policy

This privacy policy may be updated from time to time. You can find the current version at any time on our website at:

https://hinsch-consulting.com/datenschutzinformationen/

Copyright Notices

This information notice was prepared with the assistance of activeMind AG—the experts in external data protection officers (Version #2025-08-04).

Book a Meeting

We use Microsoft Bookings to schedule meetings online.
By clicking the “Book a Meeting” button, you accept Microsoft’s privacy policy.
You can find Microsoft’s privacy policy here.

Book a Meeting

We use Microsoft Bookings to schedule meetings online.
By clicking the “Book a Meeting” button, you accept Microsoft’s privacy policy.
You can find Microsoft’s privacy policy here.