Data protection
This English translation is provided for convenience only. The legally binding version is the German version. In case of any discrepancies or inconsistencies between the German and English versions, the German version shall prevail.
In the following, we inform you pursuant to Art. 13 GDPR about the processing of personal data when using our website and when contacting us by e-mail.
We process personal data only to the extent necessary for the use of our website, for handling your contact request by e-mail, for initiating or carrying out a legal mandate or notarial matter, or for complying with statutory obligations.
For the processing of personal data in connection with notarial matters, our separate Privacy Policy for Notarial Matters also applies.
Download Privacy Policy for Notarial Matters (German version)
1. Name and contact details of the controller and of the Data Protection Officer
The controller responsible for data processing in connection with this website is:
GERNS & PARTNER rechtsanwälte notare
An der Welle 3
60322 Frankfurt am Main
Germany
E-mail: mail@gerns.eu
Telephone: +49 69 717199-0
Fax: +49 69 717199-110
https://www.gerns.eu/
The responsible legal professionals are:
Attorney-at-law and Notary Ronald Gerns,
Attorney-at-law and Notary Ingrid Fornoff,
Attorney-at-law and Notary Frank Brüggemann,
Attorney-at-law and Notary Dr. Georg Thomas Scherl,
Attorney-at-law and Notary Dr. Thomas Tiedemann,
Attorney-at-law and Notary Dr. Alexander Täumer,
Attorney-at-law and Notary Dr. Johann Hecht,
Attorney-at-law and Notary Vedrana Ponseck, and
Attorney-at-law and Notary Dr. Maximilian Mosch.
Our Data Protection Officer can be contacted at:
Gerns & Partner rechtsanwälte notare
Datenschutzbeauftragte/r
An der Welle 3
60322 Frankfurt am Main
Germany
E-mail: datenschutzbeauftragter@gerns.eu
Telephone: +49 69 717199-0
Fax: +49 69 717199-110
The attorneys-at-law, notaries and employees of Gerns & Partner are bound by confidentiality obligations. The notaries are also subject to the special statutory duty of confidentiality under Section 18 of the German Federal Notarial Code (Bundesnotarordnung – BNotO). External service providers are contractually bound to confidentiality and to compliance with data protection requirements, insofar as they may have access to personal data.
2. Collection and storage of personal data as well as the type and purpose of its use
a) When visiting the website
When you access our website, the browser used on your device automatically transmits information to the server of our website. This information is temporarily stored in so-called server log files.
In particular, the following data may be processed:
- date and time of access,
- IP address or anonymised IP address of the requesting device,
- name and URL of the file accessed,
- website from which access is made, known as the referrer URL,
- browser used,
- where applicable, the operating system of your device,
- name of your access provider,
- amount of data transferred, and
- access status.
The processing is carried out for the following purposes:
- ensuring a smooth connection setup of the website,
- ensuring the technical usability of the website,
- evaluating system security and stability,
- error analysis, and
- administrative purposes.
The legal basis is Art. 6(1) sentence 1 lit. f GDPR. Our legitimate interest lies in the secure, stable and functional provision of our website.
According to the hosting service provider, the server log files are kept available for a maximum period of 8 weeks and are then deleted, unless longer storage is required to investigate security incidents or to establish, exercise or defend legal claims.
b) Hosting and technical provision of the website
Our website is operated by an external hosting service provider. The hosting service provider processes personal data, in particular technical access data and server log files, insofar as this is necessary for the provision, security and stability of the website.
Where the hosting service provider processes personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR.
c) Contact by e-mail
If you contact us by e-mail, we process the personal data you provide in order to handle and respond to your enquiry. This may include, in particular, your e-mail address, your name, the content of your message, and the date and time of contact.
Depending on the content of the enquiry, processing is carried out on the basis of Art. 6(1) sentence 1 lit. b GDPR, insofar as your enquiry is aimed at initiating or carrying out a mandate or contractual relationship, and otherwise on the basis of Art. 6(1) sentence 1 lit. f GDPR. Our legitimate interest lies in the appropriate handling and response to your enquiry.
Enquiries are deleted as soon as they are no longer required for processing, unless statutory retention obligations apply or longer storage is required to establish, exercise or defend legal claims.
d) Legal mandate or use of notarial services
If you instruct us in a legal matter or use notarial services, we process personal data for the purpose of handling the respective mandate or notarial matter.
In the case of legal mandates, processing is carried out in particular on the basis of Art. 6(1) sentence 1 lit. b GDPR, insofar as it is necessary for initiating or carrying out the mandate relationship.
In the case of notarial matters, processing is carried out in particular on the basis of Art. 6(1) sentence 1 lit. e GDPR, since notarial activities are performed in the public interest and in the exercise of public authority. Where statutory obligations exist, processing is also carried out on the basis of Art. 6(1) sentence 1 lit. c GDPR.
For notarial matters, the specific data protection information contained in our Privacy Policy for Notarial Matters also applies.
e) Cookies and similar technologies
At present, we do not use cookies or similar technologies on our website that store information on your device or read information from your device.
Should cookies, analytics tools, external media or similar technologies be used in the future, we will amend this Privacy Policy accordingly and, where legally required, obtain your consent in advance.
3. Disclosure and deletion of personal data
Personal data is disclosed to third parties only where this is permitted or required by law, necessary for handling your enquiry, necessary for carrying out a mandate or notarial matter, initiated by you, or required due to a statutory obligation.
Depending on the circumstances, recipients of personal data may include, in particular, courts, authorities, registers, chambers of notaries, supervisory authorities, tax authorities, attorneys-at-law, tax advisers, credit institutions, technical service providers, hosting service providers and other parties involved in the processing of the matter.
Where we use service providers, this is done only within the framework of statutory requirements. Service providers are carefully selected and, where required, contractually bound to confidentiality and to compliance with data protection requirements.
Personal data is deleted as soon as it is no longer required for the purposes for which it was collected or processed, unless statutory retention periods or other legal grounds require longer storage. Longer storage may be necessary in particular due to commercial, tax, anti-money-laundering, professional or procedural retention and documentation obligations, as well as for establishing, exercising or defending legal claims.
4. Rights of data subjects
Subject to the statutory requirements, you have the right:
- a) pursuant to Art. 15 GDPR, to request information about the personal data processed by us;
- b) pursuant to Art. 16 GDPR, to request the rectification of inaccurate personal data and the completion of incomplete personal data;
- c) pursuant to Art. 17 GDPR, to request the deletion of personal data concerning you, provided that a statutory ground for deletion exists and processing is not required for compliance with a legal obligation, for reasons of public interest, or for establishing, exercising or defending legal claims;
- d) pursuant to Art. 18 GDPR, to request the restriction of the processing of your personal data, provided that the statutory requirements are met;
- e) pursuant to Art. 20 GDPR, where the statutory requirements are met, to receive the personal data concerning you in a structured, commonly used and machine-readable format, or to request its transmission to another controller;
- f) pursuant to Art. 21 GDPR, to object to the processing of your personal data, insofar as the processing is carried out on the basis of Art. 6(1) sentence 1 lit. e or f GDPR and there are grounds relating to your particular situation;
- g) pursuant to Art. 77 GDPR, to lodge a complaint with a data protection supervisory authority.
A complaint may be lodged in particular with the supervisory authority responsible for our registered office:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Wilhelmstraße 7
65185 Wiesbaden
Germany
Telephone: +49 611 1408-0
E-mail: poststelle@datenschutz.hessen.de
Irrespective of this, you may also contact the data protection supervisory authority of your usual place of residence or workplace.
Where processing is exceptionally based on your consent, you may withdraw this consent at any time with effect for the future pursuant to Art. 7(3) GDPR. The lawfulness of processing carried out on the basis of consent before its withdrawal remains unaffected.
If you wish to exercise your rights as a data subject, you may contact us by e-mail at mail@gerns.eu or at datenschutzbeauftragter@gerns.eu.
5. Automated decision-making
Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place in connection with our website.
6. Data security
For security reasons, our website uses encrypted transmission by means of TLS/HTTPS. This protects the data transmitted between your browser and our web server in accordance with the state of the art.
In addition, we use appropriate technical and organisational measures to protect personal data against loss, manipulation, destruction and unauthorised access. Our security measures are continuously adapted in line with technological developments.
7. Validity and amendment of this Privacy Policy
This Privacy Policy is currently valid and was last updated in June 2026.
Due to the further development of our website and our services, or due to changes in legal, technical or regulatory requirements, it may become necessary to amend this Privacy Policy. The current Privacy Policy can be accessed and printed out at any time on our website.

