PrivacyArt. 13 GDPR

Privacy Policy

As of: 9 September 2026

1. Controller

Dilara Ekici
Attorney-at-law
Witzlebenstraße 4
14057 Berlin
Phone: +49 177 1430428
Email: info@kanzlei-ekici.de

No data protection officer has been appointed because the statutory thresholds are not met.

2. Purposes and legal bases of processing

2.1 Provision of the website

When you visit this website, technically necessary data are processed so that the pages can be delivered and displayed (e.g. IP address, date and time of access, requested resource, referrer URL, user agent / browser type). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure and functional online offering).

2.2 Contact (forms / email)

Via the website contact forms (homepage, fine self-check, and every practice-area landing page — civil law, criminal law, tenancy law, traffic law, regulatory offences — including optional legal-expenses insurance fields) you may in particular submit:

Name and email address are required so that the enquiry can be handled and answered. On the homepage and practice-area pages, the practice area and description of your matter are also required; phone and legal-expenses fields remain optional. The fine self-check uses the required fields marked there. There is no legal obligation to use the contact form.

Transmission from your browser to our website is TLS-encrypted. Your enquiry is then forwarded to the firm mailbox info@kanzlei-ekici.de. It is not stored in a forms database on the website. To prevent abuse, a short-lived server session may be used on submit (see section 4).

In addition, a short automatic acknowledgement may be sent to the email address you provided.

If you contact us by email or via a form, we process the details you provide to handle your enquiry and, where applicable, to prepare a mandate. Legal bases: Art. 6(1)(b) GDPR (pre-contractual steps) or Art. 6(1)(f) GDPR (legitimate interest in responding). The form checkbox documents that you have taken note of this privacy notice; it is not consent under Art. 6(1)(a) GDPR.

2.2a Optional file upload with the fine self-check

With the fine self-check you may optionally upload a file (e.g. fine notice or hearing form). The file content may include details of regulatory offences. The file is received by the server only temporarily via the PHP upload buffer / in memory for the duration of request handling, attached to the email to info@kanzlei-ekici.de, and not stored permanently in a website forms database or published under the web root. Temporary server files are removed by PHP after the request ends.

Processing is for handling your enquiry and possible mandate preparation. Legal bases — as for contact enquiries — are Art. 6(1)(b) or (f) GDPR. The form checkbox documents notice of the privacy information and is not consent under Art. 6(1)(a) GDPR. After a mandate is accepted, attorney–client confidentiality applies.

2.3 Mandate-related processing

If a mandate is concluded, further processing of personal data follows professional rules (in particular confidentiality) and statutory retention duties. Clients are informed separately about this.

2.4 Special categories of personal data and criminal-law data

Via the contact forms (homepage, self-check and practice-area pages), the fine self-check and an optional file upload you may voluntarily submit details that can include special categories of personal data under Art. 9 GDPR (e.g. health data, religion or sexual life) and/or data relating to criminal convictions and offences or ongoing investigations under Art. 10 GDPR. This arises in particular in criminal law, traffic offences, narcotics matters and fine / regulatory offence proceedings.

We process such data only insofar as necessary to handle your enquiry, prepare a possible mandate, and establish, exercise or defend legal claims.

Additional legal bases — where applicable — are Art. 9(2)(f) GDPR (legal claims) and Art. 10 GDPR together with applicable national and professional rules; Art. 6(1)(b) or (f) GDPR also apply as described under 2.2. After mandate acceptance, attorney–client confidentiality applies.

3. Recipients / processors

3.1 Hosting

The website is hosted by the following provider (processing on behalf / technical provision):

STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin

In the course of hosting, server log data and technically necessary connection data may be processed. A data processing agreement (DPA) under Art. 28 GDPR is in place with the hosting provider.

3.1b Email

Email for info@kanzlei-ekici.de runs via STRATO GmbH (same provider as hosting). The existing Art. 28 GDPR DPA note also covers this. No Google or Microsoft mail service is used for this form path.

3.2 Fonts (local)

The fonts used on this website (Fraunces, IBM Plex Sans, IBM Plex Mono) are served locally from our server. There is no connection to fonts.googleapis.com / fonts.gstatic.com and therefore no transfer of connection data to Google LLC for this purpose.

3.3 Content Delivery Network / Cloudflare

For security, availability and performance, the domain may be connected via a content delivery network or proxy of Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA; possibly also via Cloudflare Germany GmbH, Rosental 7, 80331 Munich) (proxy/CDN/WAF — typically “orange cloud” / proxied DNS).

Purpose: protection against attacks, DDoS mitigation, caching/delivery and technical stability of the website.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, available and performant online offering).

Recipient / data: With an active proxy, Cloudflare sees connection data (in particular IP address and request metadata such as time, requested URL, referrer, user agent) before forwarding to hosting at STRATO GmbH. Hosting and email remain with STRATO (see 3.1 / 3.1b).

Third country USA: A transfer to the USA may occur. Cloudflare is certified under the EU-US Data Privacy Framework; in addition, Standard Contractual Clauses (SCCs) and/or a DPA with Cloudflare under Art. 28 GDPR apply.

DNS note: If Cloudflare is used only as DNS (without proxy, “grey cloud”), Cloudflare does not itself process website traffic. This notice documents the intended or possible proxied operation via Cloudflare.

4. Cookies, local storage and tracking

This website does not use analytics, marketing or tracking cookies. Technically necessary session data may be processed temporarily only when a contact form is used.

On submit via kontakt.php, the server may set a short-lived PHP session — solely for rate limiting and abuse protection, not for tracking.

Your language preference is stored locally in your browser (localStorage key ke_lang) and is not transmitted to us. You can delete this entry at any time in your browser settings.

5. Retention

Hosting logs: Server log data are typically retained for a few days up to a few weeks — as configured by the hosting provider (STRATO) and as needed for operations and IT security.

Enquiries from the contact form or by email are handled in the firm’s mailbox (recipient info@kanzlei-ekici.de). No forms database is operated on the website.

Any PHP session ends with the session timeout or when the browser session is closed (depending on server/browser configuration).

6. Your rights

Where the legal requirements are met, you have the following rights:

Right to object under Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you that is based on Art. 6(1)(f) GDPR (legitimate interests — e.g. server/access logs, securing the website, handling a contact enquiry on the basis of legitimate interests); this also applies to any profiling based on those provisions. We will then no longer process the data unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

You may object informally by email to info@kanzlei-ekici.de. This notice of the right to object is highlighted expressly and separately from the other information pursuant to Art. 21(4) GDPR.

To exercise your other rights, a message to the contact address above is likewise sufficient.

7. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The authority for Berlin is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Website: www.datenschutz-berlin.de

8. Security / SSL

The website is delivered over an encrypted connection (HTTPS / SSL/TLS). Look for the padlock symbol in your browser’s address bar.

9. Automated decision-making

The self-check produces a rule-based automated initial orientation. This does not involve automated decision-making within the meaning of Art. 22 GDPR that produces legal or similarly significant effects. The self-check is for orientation only and does not replace an individual attorney review; a conclusive assessment is always made personally.

10. No sale of data

Personal data are not sold and not shared with third parties for advertising. Disclosure occurs only where required for contract performance, to meet legal duties, with your consent, or where processors (e.g. hosting) are engaged.

11. Changes

This privacy policy may be updated if technology, hosting or the law changes. The version published on this page applies (as of: 9 September 2026).

See also: Imprint · Datenschutz (DE) · Gizlilik (TR)