Privacy Policy
How CLIQ processes personal data.
1. Controller
The controller responsible for the processing of personal data on this website is CLIQ. Legal Partnerschaft von Rechtsanwälten mbB, Kreuzstraße 11, 80331 Munich, Germany, represented by Attorney-at-Law Milad Ghafarian and Attorney-at-Law Burak Korkmaz. Telephone: +49 176 20110285, Email: lets@cliq.legal
2. Hosting
Our website is hosted using Lovable, a service provided by Lovable Labs Incorporated, 1 Lincoln St, Boston, MA 02111, USA. When you access our website, technically necessary connection and usage data may be processed, in particular your IP address, browser and device information, the requested page or file, and the date and time of access. This processing is necessary to provide the website and to ensure its stability, security and proper functioning.
Processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, reliable and efficient provision of our website. Lovable may use infrastructure providers and other sub-processors for the provision of its services. Information on the separate use of Lovable's visitor analytics functionality is provided in Section 4 below.
To the extent personal data is transferred to recipients outside the European Economic Area for which no adequacy decision pursuant to Art. 45 GDPR exists, appropriate safeguards are used in accordance with Art. 46 GDPR, in particular the Standard Contractual Clauses of the European Commission where applicable. Further information on the processing of personal data, international data transfers and sub-processors is available in Lovable's privacy and data protection information.
Technical data is stored only for as long as necessary to provide, secure and operate the website or for as long as statutory obligations or legitimate security interests require further storage.
3. SSL/TLS Encryption
This website uses SSL or TLS encryption for security reasons.
4. Visitor Analytics
We use the visitor analytics functionality integrated into Lovable to obtain statistical information about the use of our website and to improve its content, usability and performance.
For this purpose, information about the use of our website is processed. This may include, in particular, the number of visitors and page views, pages visited, views per visit, visit duration, bounce rate, traffic source or referrer, device type and approximate country information. According to Lovable, country information is derived from the visitor's browser time zone.
In connection with the provision and operation of the Lovable services, technical log data may also be processed, including IP address and approximate location, browser type and version, pages or features accessed, timestamps, time spent on pages or functions and technical session or device identifiers.
According to Lovable, its project analytics measures overall traffic and does not create individual visitor profiles or track visitors across separate visits.
We use this information for the statistical evaluation and optimisation of our website. To the extent consent is required for the use of analytics technologies, processing is carried out on the basis of your consent pursuant to Art. 6(1)(a) GDPR. Where processing is necessary for the technical provision, security or operation of the website, it may be based on Art. 6(1)(f) GDPR.
The analytics functionality is provided by Lovable Labs Incorporated, 1 Lincoln St, Boston, MA 02111, USA. Lovable may engage sub-processors in connection with the provision of its services. Where personal data is transferred to recipients outside the European Economic Area, such transfers are made in accordance with the requirements of Chapter V GDPR.
We do not use the analytics data for advertising purposes and do not use it to create individual marketing profiles. You can change or withdraw your analytics selection at any time via “Privacy Settings” in the footer, insofar as the relevant analytics technology is technically controlled by this consent mechanism.
5. Contacting Us and Contact Form
You may contact us by email, telephone or through the contact form provided on our website. When you use the contact form, we process the information you provide, in particular your name, email address, company, matter type and the content of your inquiry.
We process this information in order to respond to your inquiry and, where applicable, to assess and initiate a potential attorney-client relationship. Processing is carried out on the basis of Art. 6(1)(b) GDPR insofar as your inquiry relates to the conclusion of a mandate or other contractual relationship or to pre-contractual measures. In other cases, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the efficient handling of incoming inquiries and communications.
Recipients of the data may include hosting, IT and communications service providers used by us to operate the website and process communications. The provision of your data is voluntary. However, without the information required to contact you, we may not be able to process your inquiry.
Your data will be deleted as soon as it is no longer required for the purpose for which it was collected, unless statutory retention obligations, professional obligations or legitimate interests, in particular the establishment, exercise or defence of legal claims, require further retention.
6. Appointment Booking via cal.com
For appointment booking, we link to the service cal.com, operated by Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA. When you follow this link, you leave our website and Cal.com is responsible for the processing of personal data carried out on its website. No appointment booking data is processed via cal.com on our website itself. Please note that when using cal.com, personal data may also be transferred to the USA. Further information can be found at https://cal.com/privacy.
7. Recipients of Personal Data
Your personal data will only be transferred insofar as this is necessary for providing the website, processing your inquiry, fulfilling legal obligations, or asserting, exercising, or defending legal claims. Recipients may in particular include technical service providers for hosting and IT operations, telecommunications and email service providers, as well as authorities and courts where there is a legal obligation to do so.
8. Retention Period
We store personal data only for as long as necessary for the respective processing purpose or as long as statutory retention obligations exist. For data arising from mandate initiation and attorney-client relationships, the applicable professional, tax, and commercial retention obligations also apply, in particular Section 50(1) BRAO (generally six years, running from the end of the calendar year in which the mandate ended) as well as Sections 147 AO and 257 HGB (depending on the type of document, six, eight, or ten years). Analytics and technical usage data is retained only for as long as necessary for the respective purposes described above or in accordance with the applicable retention periods of our service providers; data that has been irreversibly anonymised or aggregated is no longer considered personal data.
9. Your Rights
You have the following rights with regard to your personal data: right of access (Art. 15 GDPR), right to rectification (Art. 16 GDPR), right to erasure (Art. 17 GDPR), right to restriction of processing (Art. 18 GDPR), right to data portability (Art. 20 GDPR), right to object (Art. 21 GDPR), and right to lodge a complaint with a supervisory authority (Art. 77 GDPR).
10. Right to Object
You have the right, on grounds relating to your particular situation, to object at any time to the processing of your personal data insofar as such processing is based on Art. 6(1)(f) GDPR. If you object, we will no longer process your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or unless the processing serves the establishment, exercise or defense of legal claims.
11. No Automated Decision-Making
No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.
12. Security
We implement technical and organizational security measures to protect your data against manipulation, loss, destruction, or unauthorized access. Our measures are continuously adapted in line with technological developments.
13. Right to Lodge a Complaint with a Supervisory Authority
The competent supervisory authority is in particular the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany (www.lda.bayern.de).
14. Currency of this Privacy Policy
This Privacy Policy is current as of August 2026. It may become necessary to amend this Privacy Policy due to further development of our website or changes in legal requirements.