Privacy
1. Controller and scope
Rechtsanwalt Mir Naim Heydarinami, wolves law – Business Law Firm, Hermann-Kauffmann-Straße 2, 22307 Hamburg, Germany; telephone +49 40 84600138; email nh@wolves.law. Lupacta is an offering brand operated by wolves law, not a separate company or controller. This notice concerns website visits and initial enquiries; a subsequent engagement may be subject to additional information.
2. Hosting and access data
Website access involves processing IP address, time, requested address, any transmitted referrer address, browser, operating system and connection details. This is necessary for delivery, troubleshooting and security. The legal basis is Article 6(1)(f) GDPR and our legitimate interest in operating a secure and functional website.
The hosting provider is Webflow, Inc., 398 11th Street, Floor 2, San Francisco, CA 94103, USA. Hosting and content delivery infrastructure includes providers such as Amazon Web Services and Cloudflare. See Webflow's subprocessor list and data processing addendum. Providers receive the technical data needed for their tasks. Retention depends on the duration necessary for operation and security, including any specific incident investigation. We do not combine these data into advertising profiles.
3. Simple message entry
You may enter your email address and a message. The entries are initially processed locally in your browser. “Prepare email” opens a draft in your email application; it does not send a message itself or submit the entries to a Webflow form server. We receive the information only after you actually send the email. A direct email link and a copy function provide alternatives. Your browser's autofill settings remain under your control.
After receipt, wolves law processes your contact details, message and any documents you provide to respond, clarify the requested assistance and consider an engagement. Contract-related enquiries rely on Article 6(1)(b) GDPR. Other professional enquiries rely on Article 6(1)(f) GDPR and our legitimate interest in appropriate business communication. Article 6(1)(c) GDPR applies where legal duties require processing. Providing information is voluntary, but a meaningful message and a reply address are needed for effective handling.
Please initially avoid particularly sensitive information and confidential attachments. Email is not automatically end-to-end encrypted. A protected channel can be arranged. Sending an enquiry alone does not establish an engagement or deadline monitoring.
4. Email services and coordination
The firm's email communication uses Microsoft 365. The EU provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Message, contact and technical delivery data are processed for the email service. See Microsoft's contractual privacy terms.
Requests are assessed by people. They are not automatically distributed to law firms or other providers. A necessary introduction or disclosure is considered separately, on a suitable legal basis and with regard to professional confidentiality and any required approval. A separately retained professional is responsible for their own processing. An enquiry is not automatically used for a newsletter or advertising list.
5. Technical functions, cookies and links
Necessary hosted files and scripts support the display, navigation, language switch and local message preparation. The current configuration does not activate our own analytics or marketing services, Google Analytics, Google Tag Manager or review widgets. Non-essential device access requires prior consent under section 25(1) TDDDG; associated personal-data processing relies on Article 6(1)(a) GDPR. Operations solely required for transmission or an expressly requested service fall under section 25(2) TDDDG. Continuing to browse is not consent.
External websites are reached through ordinary links. Their operators process data under their own notices when you open the destination. A link alone does not create joint controllership.
6. Recipients and retention
In addition to the technical providers above, data is available only to necessary participants or recipients to whom disclosure is legally required. Enquiry and communication data is retained for handling and necessary documentation. Further retention may be required by statutory duties, conflict checks or legal claims. Legal case files are generally subject to the six-year period in section 50 BRAO; other statutory duties may require longer periods. Data no longer required is deleted or, where necessary, its processing restricted.
7. International transfers
Webflow and international IT services may process data outside the EEA, particularly in the USA. Webflow states that it participates in the EU-US Data Privacy Framework. Covered transfers to certified recipients rely on Article 45 GDPR. Other transfers require safeguards under Article 46 GDPR, particularly EU Standard Contractual Clauses and any necessary supplementary measures. Disclosure to a professional outside the EEA is assessed separately. You may request details and a copy of the applicable safeguards from us.
8. Your rights
Subject to the legal conditions, Articles 15–20 GDPR provide rights of access, rectification, erasure, restriction and data portability. Consent can be withdrawn at any time for the future without affecting earlier lawful processing.
You may object under Article 21 GDPR to processing based on Article 6(1)(f) GDPR on grounds relating to your particular situation. You may object to direct marketing at any time without giving reasons.
Use the contact details above to exercise your rights. We do not make solely automated decisions with legal or similarly significant effects under Article 22 GDPR.
9. Complaints
Article 77 GDPR permits a complaint to a supervisory authority, in particular where you live, work or suspect an infringement. The authority for the firm's location is the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany; mailbox@datenschutz.hamburg.de; datenschutz-hamburg.de.