Effective: August 2026
A. Data Controller, Joint Control
1. Data Controller
This website is the joint online presence of BODENHEIMER. The data controllers within the meaning of Article 4(7) of the GDPR are therefore jointly:
BODENHEIMER GbR
Hohenzollernring 103
50672 Cologne
Germany
Phone: +49 221 291 90 6 08
Email: mail@bodenheimer.legal
Represented by:
Attorney at Law Dr. Rouven F. Bodenheimer, M.A.
Attorney and Solicitor (England and Wales) Axel Benjamin Herzberg, LL.M.
Attorney at Law Dr. Christof Siefarth, LL.M.
Attorney Dr. Sebastian Feiler
and
BODENHEIMER Ltd
3701-06 – D1 & 3701-06 – D2, 37, Sky Tower
Shams Abu Dhabi, Al Reem Island
Abu Dhabi, United Arab Emirates
Phone: +971 2 404 1902
Email: mail@bodenheimer.legal
Represented by:
Attorney Dr. Rouven F. Bodenheimer, M.A.
2. Joint Control under Article 26 of the GDPR
Since both of the aforementioned companies jointly determine the purposes and means of processing in connection with this website, they are joint controllers within the meaning of Article 26 of the GDPR. They have set forth in an agreement who fulfills which obligations under the GDPR. BODENHEIEMER GbR and BODENHEIMER Ltd are jointly responsible for the technical operation of the website, for fulfilling the information obligations under Articles 13 and 14 of the GDPR, for handling inquiries from data subjects, and for cooperating with the supervisory authority. They serve as your central point of contact for all data protection-related matters. Both companies support each other in fulfilling the rights of data subjects and promptly inform each other of any claims asserted and of any breaches of personal data protection.
Regardless of this internal division of responsibilities, you may exercise your rights under the GDPR in accordance with Article 26(3) of the GDPR with either of the two controllers. We recommend that you contact BODENHEIMER GbR using the contact information provided above.
B. General Provisions
1. Scope
This Privacy Policy applies to the website www.bodenheimer.legal, including all subpages. It does not apply to third-party websites to which we merely provide links.
2. Processing Principles
We process personal data only to the extent necessary to provide a fully functional website and our content, or where you have given your consent. Processing is always carried out in accordance with the GDPR, the Federal Data Protection Act (BDSG), and the Telecommunications and Digital Services Data Protection Act (TDDDG), as well as the Abu Dhabi Global Market (ADGM) Data Protection Regulations 2021, including any applicable supplementary provisions.
We have deliberately designed our website to minimize data collection. It operates without cookies, without tracking, and without the integration of third-party content for advertising or analytical purposes.
3. Overview of Legal Bases
| Legal Basis | Application on This Website |
|---|---|
| Art. 6(1)(b) GDPR (Contract / Pre-contractual Measures) | Initiation of a client relationship or other contractual relationship upon contact |
| Art. 6(1), sentence 1, subparagraph (c) of the GDPR (legal obligation) | Statutory and professional retention obligations |
| Art. 6(1), sentence 1, subparagraph (f) of the GDPR (legitimate interests) | Website delivery and security, server log files, delivery of video content, processing of inquiries |
Processing based on consent (Art. 6(1), sentence 1, subparagraph (a) of the GDPR) does not currently take place.
4. Encryption
This website uses TLS encryption (indicated by “https://” in your browser’s address bar). This protects the data transmitted between your device and our server from being intercepted by third parties.
Important: We cannot guarantee that unencrypted email communication will not be accessed by third parties. Upon request, we offer a secure transmission channel for the transfer of confidential or client-related information.
C. Website Provision and Server Log Files
1. Hosting
BODENHEIMER has outsourced the technical operation of this website to a service provider:
anQuorage GmbH
Hohenzollernring 103
50672 Cologne
Germany
anQuorage GmbH processes the data collected on this website exclusively in accordance with the instructions of the two data controllers. A data processing agreement pursuant to Article 28 of the GDPR is in place.
anQuorage GmbH leases the server used from:
netcup GmbH
Emmy-Noether-Straße 10
76131 Karlsruhe
Germany
The server is located in netcup’s data center in Nuremberg, Germany. No personal data is transferred to a third country as part of the hosting service.
netcup GmbH is part of the Anexia Group and, in turn, uses the following additional processors, all of which are based in the European Union:
Anexia Holding GmbH, Klagenfurt, Austria (support services)
Anexia Cloud Solutions GmbH, Klagenfurt, Austria (infrastructure services, human resources)
Anexia Cloud Solutions GmbH, Karlsruhe, Germany (infrastructure services, human resources)
netcup GmbH’s information security and data protection management system is certified according to ISO 27001 and ISO 27701.
Personal data that remains in backup copies after processing has ended is deleted by netcup within 14 days at the latest.
The website is technically operated using the headless content management system Strapi in conjunction with a Node.js application. We operate both components ourselves on the aforementioned infrastructure.
The legal basis for using the netcup server via anQuorage GmbH is Article 6(1)(f) of the GDPR. Our legitimate interest lies in the secure, stable, and efficient provision of our online services by a professional provider.
2. Server Log Files
Each time this website is accessed, our system automatically collects data and information from the system of the accessing device. The following data is collected:
Browser type, browser version, and language setting
Operating system used
User’s IP address
Date and time of access
Name and URL of the file accessed
Referrer URL (the previously visited page)
Access status/HTTP status code
Amount of data transferred in each instance
This data is not combined with other personal data and is not analyzed for marketing purposes. We do not analyze the usage behavior of individual users.
The temporary processing of the IP address is technically necessary to deliver the website to your device. Storage in log files also serves to ensure the functionality, error analysis, and security of our IT systems, in particular the detection and prevention of attacks. The legal basis for processing is Article 6(1)(f) of the GDPR.
The log files are automatically deleted after 14 days. If there are concrete indications of an attack or other legal violation, the relevant log files will be retained until the incident has been fully resolved.
The collection of this data is strictly necessary for the operation of the website. There is no option to object in this regard.
D. No Cookies, No Tracking
This website does not use cookies.
Neither we nor third parties store information on your device or retrieve it from there. In particular, we do not use:
Cookies for analytics or tracking purposes
Cookies for advertising or marketing purposes (such as Meta Pixel, Google Ads, LinkedIn Insight Tag)
Cookies for convenience features
Embedded third-party content that sets cookies
The video player (Section F) also operates without cookies.
Since no storage or access process takes place on your device within the meaning of Section 25(1) of the TDDDG, consent is not required for this. For the same reason, we do not display a cookie banner.
E. Locally Embedded Resources
All files required to display this website are served from our own server in Germany. No content is retrieved from external content delivery networks. This applies in particular to fonts, icon sets, JavaScript libraries, and CSS frameworks.
To be reviewed (open item from the voting process): The web font kit used dates from 2020 and, according to the service provider, references only locally hosted font files. In contrast, for current web font projects, Monotype/MyFonts provides a tracking CSS file (“1.css”) through which the IP address of every website visitor is transmitted to a Monotype service provider for reporting and licensing purposes. If such a tracking code is provided in the MyFonts customer account, it must not be integrated without a prior data protection review—it would establish a third-party connection with a U.S. connection and render both this section and Section J (no transfers to third countries) invalid. In this case, the necessity under licensing law must first be clarified.
F. Videos
We embed videos on certain pages. The video files are delivered via the Bunny Stream service. The provider is:
BunnyWay, informacijske storitve d.o.o.
Dunajska cesta 165
1000 Ljubljana
Slovenia
We do not use the provider’s embedded player (no iFrame), but rather the hls.js library, which we host ourselves. This library retrieves the video as an HLS stream directly from BunnyWay’s servers. The player does not set any cookies and does not store any information on your device.
The video thumbnails are also loaded from BunnyWay’s servers.
When a thumbnail is retrieved or a video is played, the following data is transmitted to BunnyWay:
Your IP address
Date and time of the request
Browser type, browser version, and operating system
Referrer URL (the page on which the video is embedded)
The video or image file accessed
Since the thumbnails are loaded from BunnyWay, your IP address is already transmitted to BunnyWay when you visit a page with video content,
Since the thumbnails are loaded from BunnyWay, your IP address is transmitted to BunnyWay as soon as you visit a page containing video content,
BunnyWay also collects technical usage and performance statistics (such as view counts and delivery quality) and provides them to us in aggregated form. Neither BunnyWay nor we associate this data with individual persons.
According to the provider’s specifications in the data processing agreement, personal data is stored on the delivery servers (edge servers) exclusively in RAM and only for approximately 20 to 30 seconds; it is then deleted and passed on solely in aggregated form to a central processing service operated within the European Union.
The purpose of processing by Bunny Stream is to ensure the high-performance and uninterrupted delivery of our video content, as well as to reduce the load on our own server infrastructure. The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in the reliable and technically high-quality provision of video content.
Consent is not required because no information is stored on or read from your device when you access the content; § 25(1) of the German Telemedia Act (TDDDG) therefore does not apply. Furthermore, BunnyWay processes the data exclusively on our behalf in accordance with our instructions and not as an independent recipient.
4. Data Processing on Behalf of a Controller – No Transfer to Third Countries
We have entered into a data processing agreement with BunnyWay pursuant to Article 28 of the GDPR. BunnyWay is headquartered in the European Union.
In the configuration of our Bunny account, we have restricted the delivery of our content to server locations within the European Union. According to the provider’s information, in this case all data flows exclusively through locations within the European Union; therefore, no transfer to a third country takes place. This setting also serves contractually as a documented instruction within the meaning of Article 28(3), sentence 2, letter a of the GDPR regarding the transfer of data to third countries.
BunnyWay uses additional processors. The current list is available at https://bunny.net/gdpr/sub-processors/
For more information, please see the privacy policy of bunny.net at https://bunny.net/privacy/
G. Analytics
We do not currently use web analytics. No statistical analysis of your usage behavior takes place.
H. Contacting Us
You can reach us using the contact information provided. If you contact us, we will process the personal data you provide—in the case of emails, specifically your email address, your name, and the content of your message—exclusively for the purpose of handling your inquiry.
If your contact is aimed at initiating or executing a contract, the legal basis is Article 6(1)(b) of the GDPR. In all other cases, the legal basis is our legitimate interest in processing inquiries directed to us, Article 6(1)(f) of the GDPR.
Depending on the subject matter of your inquiry, your request may be processed by BODENHEIMER GbR in Cologne or by BODENHEIMER Ltd in Abu Dhabi.
We delete the data as soon as it is no longer necessary to achieve the purpose for which it was collected. This is generally the case when the circumstances indicate that the matter has been conclusively resolved. Statutory retention obligations—in particular under Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO), as well as professional retention obligations under Section 50(1), sentence 2 of the German Federal Lawyers’ Act (BRAO)—remain unaffected.
You may object to the storage of your personal data at any time. In this case, the conversation cannot be continued. Please direct your objection to mail@bodenheimer.legal.
I. Recipients and Processors
We only disclose personal data if this is permitted by law. Recipients are:
| Recipients | Location | Purpose | Legal Basis |
|---|---|---|---|
| anQuorage GmbH | Cologne, Germany | Technical operation of the website as a service provider | Data processing on behalf of a client, Art. 28 GDPR |
| netcup GmbH | Karlsruhe, Germany (Nuremberg data center) | Server operation | Additional data processor |
| Anexia Holding GmbH | Klagenfurt, Austria | Support services for netcup | Additional Data Processor |
| Anexia Cloud Solutions GmbH | Klagenfurt, Austria, and Karlsruhe, Germany | Data center infrastructure services for netcup | Additional data processor |
| BunnyWay, informacijske storitve d.o.o. | Ljubljana, Slovenia | Delivery of video content and thumbnails (delivery limited to the EU) | Additional data processor |
| Other data processors used by BunnyWay | See https://bunny.net/gdpr/sub-processors/ | Content delivery | Additional data processors |
| exovia Webdesign | Hamburg, Germany | Creation, maintenance, and support of the website | Data processing, Art. 28 GDPR |
| tech-support.koeln | Cologne, Germany | IT administration | Processing on Behalf of the Controller, Art. 28 GDPR |
The exchange of personal data between the two joint controllers (Section A) does not constitute a transfer to third parties, but rather takes place within the framework of joint controllership pursuant to Article 26 of the GDPR; see Section J for more information.
We do not use any external error or application monitoring tools (such as Sentry, LogRocket, Datadog, or New Relic).
Furthermore, we disclose data to the extent that we are legally required to do so or to the extent necessary to assert, exercise, or defend legal claims.
Data is not transferred to third parties for advertising purposes. Data is not sold.
J. Transfer to Third Countries
All service providers used in connection with the technical operation of this website and their respective subprocessors are based in the European Union and process data exclusively on servers located within the EU or the EEA:
One of the two joint controllers, BODENHEIMER Ltd, is headquartered in the Abu Dhabi Global Market (ADGM) Free Zone, Abu Dhabi, United Arab Emirates. The United Arab Emirates is a third country within the meaning of Chapter V of the GDPR. To the extent that personal data is transferred to BODENHEIMER Ltd within the framework of joint controllership, we base this transfer on the European Commission’s Standard Contractual Clauses pursuant to Article 46(2)(c) of the GDPR (Implementing Decision (EU) 2021/914, Module 1 – Transfer from Controller to Controller). We have additionally verified whether the United Arab Emirates provides a level of protection equivalent to that of the Standard Contractual Clauses and have implemented appropriate additional safeguards. Please note that the United Arab Emirates does not have a level of data protection comparable to that under European law, and access by government authorities cannot be ruled out in all cases. We will provide you with a copy of the agreed safeguards upon request.
K. Retention Period
We store personal data only for as long as is necessary for the respective purposes. The specific retention periods are specified above for each individual processing activity. Statutory retention periods for business correspondence, accounting documents, invoices, and legal case files remain unaffected. Once the respective retention period has expired, the data will be deleted unless, in exceptional cases, it is still required to assert, exercise, or defend legal claims.
L. Your Rights as a Data Subject
If your personal data is being processed, you have the following rights:
| Right | Legal Basis | Content |
|---|---|---|
| Right to access | Art. 15 GDPR | Information on whether and what data we process about you |
| Rectification | Art. 16 GDPR | Rectification of inaccurate data and completion of incomplete data |
| Erasure | Art. 17 GDPR | Erasure of Your Data, Unless an Exception Applies |
| Restriction of processing | Art. 18 GDPR | Restriction Instead of Erasure, for Example During an Audit |
| Data Portability | Art. 20 GDPR | Receipt of your data in a structured, commonly used, machine-readable format |
| Objection | Art. 21 GDPR | See separate note below |
| Withdrawal of Consent | Art. 7(3) GDPR | Withdrawal at any time with future effect |
| Filing a complaint with a supervisory authority | Art. 77 GDPR | Right to lodge a complaint, in particular in the place where you reside or work |
Since this involves joint controllership, you may exercise these rights under Art. 26(3) GDPR with respect to either of the two controllers. An informal notification is sufficient to exercise these rights; the following serves as your central point of contact:
mail@bodenheimer.legal · +49 221 291 90 60 · Hohenzollernring 103, 50672 Cologne
Competent supervisory authorities:
State Commissioner for Data Protection and Freedom of Information, North Rhine-Westphalia
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
https://www.ldi.nrw.de
ADGM Office of Data Protection (ODP)
ADGM Authorities Building
ADGM Square
Al Maryah Island
P.O. Box 111999
Abu Dhabi, UAE
https://www.adgm.com
M. Notice Regarding Your Right to Object Under Article 21 of the GDPR
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is carried out pursuant to Article 6(1)(e) or (f) of the GDPR.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.
If your personal data is processed for direct marketing purposes, you have the right to object to the processing at any time and without providing a reason. Following such an objection, we will no longer process your data for direct marketing purposes.
Please submit your objection informally to: mail@bodenheimer.legal
N. No Automated Decision-Making
Automated decision-making, including profiling, as defined in Article 22(1) and (4) of the GDPR, does not take place.
O. Necessity of Providing Data
The provision of personal data is not required by law or contract. You are not obligated to provide us with personal data.
However, the data automatically collected when you visit the website (Section C) is technically necessary to display the website to you. Without your contact information (Section H), we cannot process your inquiry.
P. Changes to This Privacy Policy
We will update this Privacy Policy as soon as changes to our data processing activities or the legal framework require it. The version available on this page is the current one.
Date of this version: August 2026