Data Protection
Data Protection Information
The following information provides a simple overview of how we process your personal data when you visit this website (B.), when you contact us (C.), when you subscribe to our newsletter (D.) or when we process your applicant data (E.). Personal data is all data with which you can be personally identified.
A. Data Controller
The data controller for the listed processes is:
BM Partner Revision GmbH Wirtschaftsprüfungsgesellschaft
(hereinafter referred to as "we" or "us")
Theodorstraße 180
40472 Düsseldorf
Email: mail@bmpartner.de
Telephone: 0049 211 9605 03
B. Data collection on this website
I. Accessing the website
1. Categories of personal data
If you use our website purely for information purposes, we collect and store the following data:
-
IP address of the requesting computer,
-
Date and time of access,
-
Name and URL of the retrieved file,
-
Website from which access is made,
-
The browser used and, if applicable, the operating system of your computer and the name of your internet service provider.
2. Purposes and legal bases of processing
The aforementioned data is automatically recorded by our web server and temporarily stored in so-called server log files. This processing serves the following purposes:
-
Ensuring a trouble-free connection to the website,
-
Ensuring an easy use of our website,
-
Evaluating system security and stability,
-
Administrative purposes, in particular for the technical improvement of our offer,
-
Protection against misuse or cyber attacks as well as analysis of them and defence against them.
Your personal data is processed in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR on the basis of our legitimate interest. Our legitimate interest lies in the aforementioned purposes of data collection.
3. Right to object
Data processing is absolutely necessary for the security and operation of the website. The option to object is therefore only enforceable if you do not visit our website.
4. Storage duration
The information in the server log files will be deleted after 4 weeks.
5. Recipient of the data
The website is provided by the service provider Convoy Interactive GmbH, which acts as a processor for us and with which we have concluded a data processing agreement that uses Hetzner Online GmbH as a sub-processor for hosting. An order processing contract was also concluded in this relationship, which takes into account the requirements of Art. 28 GDPR.
II Geolocation function for job adverts
1. Purposes and legal bases of processing
On our website it is possible to filter job adverts according to geographical distance. To calculate the distance, we use the geolocation API of your browser - only with your active consent. Your location coordinates are determined by your browser and used exclusively locally to calculate the distance. The location data is not stored or transmitted to third parties.
The legal basis for this data processing is your consent in accordance with Art. 6 para. 1 lit. a GDPR.
2. Revocation of consent
You can revoke your consent at any time with effect for the future via our consent management platform. Select the checkbox for the data processing for which you wish to withdraw your consent.
3. Storage duration
The location data is only processed temporarily and discarded once the distance calculation has been completed.
III Services deployed
1. Usercentrics
a) Purposes and legal bases of processing
We use the consent management platform "Usercentrics" from Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich on our website. Usercentrics enables us to obtain, manage and document your consent to data processing. The following personal data is collected and processed when Usercentrics is used:
-
Date and time of access,
-
Device information (e.g. browser type, operating system, device type),
-
Anonymised IP address,
-
Opt-in and opt-out data (consent preferences, consent/refusal, time of consent, scope of consent),
-
URL of the retrieved file,
Your personal data is processed in accordance with Art. 6 para. 1 lit. c GDPR in conjunction with Article 25 German Act to Regulate Data Protection and Privacy in Telecommunications and Telemedia (TTDSG) on the basis of our legitimate interest. We are obliged to obtain and document consent for the use of cookies.
b) Storage duration
The consent data will be stored by Usercentrics GmbH for a maximum of 12 months. Further information is available from Usercentrics GmbH using the following link: https://usercentrics.atlassian.net/wiki/spaces/SKB/pages/53313702/Rechtliches.
2. Google Tag Manager and Google Analytics
a) Purposes and legal bases of processing
We use Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google Analytics uses cookies and similar technologies that enable an analysis of your usage behaviour on our website. In addition, our website uses Google Tag Manager, a tag management system from Google that enables us to manage tracking tags such as Google Analytics. The Google Tag Manager itself does not store any personal data, but only serves to trigger other services that can collect data. The processing of Google Analytics serves the following purposes:
-
Analysis and statistical evaluation of user behaviour to optimise our website,
-
Improving the user-friendliness of the website,
-
Monitoring the success of marketing and advertising measures.
Your personal data is processed in accordance with Art. 6 para. 1 lit. a GDPR on the basis of your voluntary consent.
b) Revocation of consent
You can revoke your consent at any time with effect for the future via our consent management platform. Select the checkbox for the data processing for which you wish to withdraw your consent.
c) Storage duration
The data processed by Google Analytics is automatically deleted after 14 months as standard. Google Analytics cookies are stored on your device until you delete them or they become invalid (usually after a maximum of 2 years).
d) Recipient of the data
Google processes the data on our behalf as a sub-processor. We have concluded an order processing agreement with our service provider who, in turn, has concluded a contract with Google in accordance with Art. 28 GDPR.
e) Third country transfer
Google may transmit data to third countries (e.g. the USA). The American company Google LLC is certified under the EU-US Data Privacy Framework, meaning that this transmission can be based on the corresponding adequacy decision of the European Commission. Furthermore, the European Commission’s Standard Data Protection Contractual Clauses (SCC) have been concluded.
3. Integration of YouTube videos
a) Purposes and legal bases of processing
Our website uses plugins of the YouTube video portal, provided by YouTube LLC, 901 Cherry Ave, San Bruno, CA 94066, USA (a subsidiary of Google). When YouTube videos are played, a connection to YouTube servers is established. In the process, your IP address and the pages you have visited are transmitted to YouTube.
YouTube is incorporated only on the basis of your voluntary consent in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR.
b) Revocation of consent
You can revoke your consent at any time with effect for the future via our consent management platform. Select the checkbox for the data processing for which you wish to withdraw your consent.
c) Storage duration
YouTube stores personal data for up to 2 years. More information about how YouTube processes your data can be found at: https://www.youtube.com/intl/ALL_en/howyoutubeworks/user-settings/privacy/.
d) Third country transfer
YouTube may transmit data to third countries (e.g. the USA). The American company Google LLC is certified under the EU-US Data Privacy Framework, meaning that this transmission can be based on the corresponding adequacy decision of the European Commission. Furthermore, the European Commission’s Standard Data Protection Contractual Clauses (SCC) have been concluded.
4. Google Maps
a) Purposes and legal bases of processing
We integrate map material from the "Google Maps" service of the provider Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, on our website. The use of Google Maps may transmit information about your use of our website, including your IP address, to Google servers and be stored there.
We use Google Maps only on the basis of your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR.
b) Revocation of consent
You can revoke your consent at any time with effect for the future via our consent management platform. Select the checkbox for the data processing for which you wish to withdraw your consent.
c) Third country transfer
Google may possibly also process data in the USA. The American company Google LLC is certified under the EU-US Data Privacy Framework, meaning that this transmission can be based on the corresponding adequacy decision of the European Commission.
c) Storage duration
The data processed by Google Maps is stored on the basis of the Google data privacy declaration. Google usually stores this data for up to 2 years. The precise duration depends on the type of saved cookies and Google’s usage terms. More information on storage periods and data processing by Google can be found under the following link: https://policies.google.com/privacy.
5. Use of Amazon Web Services (AWS)
a) Purposes and legal bases of processing
We use services from Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg (AWS), in particular AWS S3, for the purposes of storing and exchanging data for the management and maintenance of our website.
The legal basis for this according to Art. 6 para. 1 lit. f GDPR is our legitimate interest in the safe and efficient storage and management of our data.
b) Right to object
Data processing is absolutely necessary for the security and operation of the website. The option to object is therefore only enforceable if you do not visit our website.
c) Storage duration
The storage duration of the data such as the server log, can be found in the relevant sections of this Data Protection Information.
Further information on data protection at AWS can be found at https://aws.amazon.com/de/privacy/.
IV. Social Media Presence on LinkedIn
For the information service offered here we use the technical platform and services of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (hereinafter referred to as “LinkedIn”). It is important to note that you use our LinkedIn page and its functions under your own responsibility. This is especially the case for the use of the interactive functions (e.g. commenting, sharing, liking).
1. Shared responsibility with LinkedIn
We are jointly responsible with LinkedIn only for so-called insights data, where this data is used to create so-called page insights. We have concluded an agreement with LinkedIn within the framework of our joint responsibility that you can access here (so-called Page Insights Joint Controller Addendum). The agreement refers data processing recorded in connection with a visit to or interaction with our LinkedIn profile, but only to the extent that this data is also processed for page insights (afterwards). “Page insights” comprise analysis services that help the operator of a LinkedIn profile to better understand interactions with a page. The purpose of the data processing is compilation of aggregated statistics for LinkedIn profile operators. It is about processing the data as part of visiting a LinkedIn profile or interaction of people with a LinkedIn profile, but only if the purpose is use for page insights. LinkedIn provides more information on this under this link. The Information on Data for Page Insights provide information on how and when insights data is recorded and used to create page insights:
-
When a LinkedIn member visits, follows or interacts with the page, LinkedIn processes personal data to give the page operator insights into the use.
-
In particular, LinkedIn processes data that the member has made available to LinkedIn, such as data on position, country, sector, length of service, company size and employment status from a member’s profile.
-
Furthermore, LinkedIn processes information on how a member has integrated with your company page, e.g., whether a member is a follower.
When our LinkedIn page is visited, LinkedIn records your IP address and other information that is available on your PC in the form of cookies. This information is used to provide us as operator of the LinkedIn page with statistical information about the use of the LinkedIn page. In this context, we do not receive any personal data from LinkedIn.
The data about you collected in this way is processed by LinkedIn and may be transmitted to countries outside the European Union in the process. In its user agreement and privacy policy, LinkedIn describes in a general form which data it receives and how it uses it. There, you will also find information about how to contact LinkedIn and settings options for ads. LinkedIn’s data guidelines are available under this link.
If you want to make use of the data subject rights due to you under the GDPR, we must point out that we cannot fully meet all of the rights without the participation of LinkedIn. It would therefore be more effective for you to contact LinkedIn directly. However, if you still need help, don’t hesitate to get in touch with us. The respective responsibilities, in particular in connection with respecting the rights of the data subject, in the relationship between us and LinkedIn can be found in the Pages Insights Addendum. LinkedIn assumes primary responsibility for fulfilling the GDPR duties for the joint processing of insights data. This includes fulfilling the following data subject rights:
-
Right of access (Art. 15 GDPR)
-
Right of erasure (Art. 17 GDPR)
-
Right to restriction of processing (Art. 18 GDPR)
-
Right to data portability (Art. 20 GDPR)
-
Right to object (Art. 21 GDPR)
LinkedIn makes more information on exercising these rights available in Point 4 of its Privacy Policy.
2. Our Responsibility
In addition, we are solely responsible for certain data processing. To offer our information service, we process the following data for communication with LinkedIn users:
-
User interactions (posts, likes etc.)
-
Profile names and data stated by the user during the conversation, e.g. for processing service queries
-
Statistical data for advertising to target groups
-
Statistical data on user interactions in aggregated form, i.e. without us being able to attribute it to individuals (e.g. page activities, page accesses, page previews, likes, recommendations, contributions, videos, page subscriptions incl. origin, times)
-
Target group controlled advertisements on the basis of aggregated demographic data without being able to attribute it to individuals (e.g. age, home, language or gender details)
a) Purposes and legal bases of processing
Processing is for the purpose of processing your queries (if you have made a query to us) or communication with you and to publish information about our events and services. The legal basis of processing for the purpose of answering queries in the interests of a future contract conclusion and initiated by you is Art. 6 para 1 sentence 1 lit. b GDPR and, in the other cases, Art. 6 para. 1 sentence 1 lit. f GDPR.
b) Legitimate Interests in Data Processing
The legitimate interest lies in the effective provision of information for users, clients and interested parties and communication with these people and our public image.
c) Transmission to a Third Country
If personal data is transmitted to LinkedIn servers in the USA and stored or further processed there, LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland has concluded the standard data protection contract clauses adopted by the European Commisson with the LinkedIn countries based in the USA, which permit the transmission of personal data to the USA on a case-by-case basis.
d) Data Storage Duration
After your query has been dealt with, the personal data you have provided will be deleted from our systems. If you interact with us in public, for example, by leaving a comment or “liking” a contribution, this data will remain publicly accessible on the page until it is deleted by us or you. If statutory storage obligations require a longer storage period, your data will be stored for this purpose only and blocked for other purposes.
e) Right to Object to Data Processing
You may object to the processing of your personal data in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR at any time. To exercise your right to object to us please get in touch with us using the contact data above. We will then process your query without undue delay.
f) Requirement/Obligation to Provide Data
Your data is provided voluntarily. However, it is not possible to visit our profile without us processing personal data together with LinkedIn and LinkedIn processing it under its own, separate responsibility.
C. Contact
I. Purposes and legal bases of data processing
You can contact us via various channels, such as contact form, email or telephone. We store and process the personal data transmitted in this way (in particular name and the content of your query) only to process your query. The legal basis for this processing is Art. 6 para. 1 lit. b GDPR, provided that your query is associated with fulfilling a contract or precontractual measures. In all other cases, your personal data is processed in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest.
II. Right to object
You may object to the processing of your personal data in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR at any time. To exercise your right to object to us please get in touch with us using the contact data above. We will then process your query without undue delay.
III. Storage duration
Your data will remain with us until the purpose of storage no longer pertains, e.g., after final processing of your query.
D. Newsletter
I. Purposes and legal bases of data processing
To send newsletters, we use the Brevo service, provided by Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany.
If you register for our newsletter, Brevo stores your email address and other voluntary information that you have provided during registration This data will be used only for sending our newsletter. We have concluded a contract on order processing with Brevo that satisfies the requirements of Art. 28 GDPR.
Your personal data is processed in accordance with Art. 6 para. 1 lit. a GDPR on the basis of your consent.
II. Revocation of consent
You can revoke your consent at any time, e.g. by using the “unsubscribe” link in the newsletter.
III. Storage duration
After the newsletter is sent, transaction logs which may comprise personal data, such as the email addresses that receive the newsletter, are stored for statistical purposes one month after the newsletter has been sent.
More information can be found in Brevo’s privacy policy: https://www.brevo.com/legal/privacypolicy/.
E. Applicant management
Afileon Audit GmbH Wirtschaftsprüfungsgesellschaft undertakes applicant management and staff recruitment services on behalf of the companies in the Afileon Group. A current list of all of the companies in the Afileon Group can be found in the Annex to this Data Protection Information. Information about the processing of personal data within the context of applicant management and your respective rights can be found at: https://www.brevo.com/legal/privacypolicy/.
F. Change in purpose
Your personal data is processed for purposes other than those described only if a legal provision allows this or you have consented to the changed purpose of data processing.
In the event of further processing for purposes other than those for which the personal data was originally collected, we will inform you of these different purposes before the further processing and will provide you with all of the relevant information required for this.
G. Automated decision-making
We do not intend to use your personal data for a process of automated decision-making (including profiling).
H. Your rights
I. Rights of a data subject
You have the following rights:
-
The right to revoke any consent given without stating reasons. This results in the data processing based on consent may no longer be continued for the future. (Right to revoke your consent, Art. 7 para. 3 GDPR)
-
The right to request information about personal data processed by us. In particular, you can request information about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage duration, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to object, the origin or your data, if it was not collected by us, and about the existence of automated decision-making including profiling and, where applicable, meaningful information on their details (right of access, Art, 15 GDPR)
-
The right to request immediate rectification of incorrect or completion of your stored personal data (right to rectification, Art. 16, GDPR)
-
The right to delete your stored personal data, provided that the processing is not required to exercise the right of freedom of expression and information, to meet a legal obligation, for reasons of the public interest or to assert, exercise or defend legal claims (right to erasure, Art. 17 GDPR)
-
The right to request the restriction of the processing of your personal data, provided that you dispute that the data is correct, processing is illegal, but you reject its deletion and we no longer need the data, but you need it for asserting, exercising or defending legal claims or you have submitted an objection against processing in accordance with Art. 21 GDPR (right to restriction of processing, Art, 18 GDPR) and
-
The right to receive your personal data that you have provided to us in a structured, common and machine-readable format or to request transmission to another data controller (right to data portability, Art. 20 GDPR)
To exercise your rights, you can contact us for queries about data protection using the contact data above.
II. Right to object
If your personal data is processed in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR on the basis of our legitimate interest, in accordance with Art. 21 GDPR you have a right to object to the processing this data on the basis of a legitimate interest. If you make use of your right to object, your personal data will no longer be processed unless the there are compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims. To exercise your right to object, you can contact us for queries about data protection using the contact data above.
III. Right to complain
You have the right to complain to a data protection supervisory authority. To do this, you can contact the supervisory authority of your usual residence or workplace or the supervisory authority of our company headquarters.
I. Changing the data protection information
As part of the further development of data protection legislation and technological or organisational changes, our data protection information is regularly checked for any needs for adaptation or supplements.
This data protection information is dated 15.04.2025.
Annex: Companies in the Afileon Group
Where companies of the Afileon Group are referred to in this data protection information, the following companies are meant:
Bartsch & Kollegen Steuerberatungsgesellschaft mbH, Hamburg
Conrad, Bartsch & Kollegen GmbH, Hamburg
BFS, Offenbach
bks partners. GmbH Steuerberatung, Munich
BM Partner Revision GmbH Wirtschaftsprüfungsgesellschaft, Düsseldorf
Garlich, Müller und Partner mbB, Haan (near Düsseldorf)
Kai Säland + Collegen Steuerberatungsgesellschaft mbH, Harsefeld
LHP Rechtsanwälte, Fachanwälte für Steuerrecht, Steuerberater Tax GmbH und LHP Legal GmbH, Cologne, Zürich
Mertens Schabow Steuerberatungsgesellschaft Hamburg mbH, Hamburg
navigator GmbH Wirtschaftsprüfungsgesellschaft, Gütersloh
TAXFBA GmbH, Hamburg
TLC AG Steuerberatungsgesellschaft, Berlin
Weitkamp Hirsch & Kollegen Steuerberatungsgesellschaft mbH, Schleswig
Dr. SchwarzPartners GmbH, Fürth, Neustadt, Kahla
Dr. Schwarz Recht GmbH, Fürth
Friebe & Dr. Schwarz GmbH, Nuremberg
Freiß Dr. Schwarz GmbH, Nuremberg
Wartenberg, Dr. Schwarz Steuerberatungsgesellschaft mbH, Ingolstadt
Harrer, Dr. Schwarz & Partner mbB, Neumarkt