1. Who is responsible?
Dr. Adam S. Dampc, Rechtsanwalt
Kolpingstraße 18
68165 Mannheim, Germany
Email: rechtsanwalt@dampc.legal
Telephone: +49 621 328890
This notice concerns this website, enquiries and consultation bookings. Information about processing for a particular legal matter may be provided separately when needed.
2. Website hosting and technical information
The website and its booking system run on Odoo's cloud platform. Odoo S.A., Chaussée de Namur 40, 1367 Grand-Rosière, Belgium, provides that platform and processes customer-database information on behalf of its customers under the data-protection provisions of its subscription agreement.
Using the website involves technical information such as your IP address, requested pages, access time, browser and operating-system information, and referrer information where your browser sends it. This information is needed to deliver the website, maintain reliability and security, and investigate misuse. The legal basis for necessary website operation and security is Article 6(1)(f) GDPR, reflecting the legitimate interest in a functioning, secure website.
Odoo's published policy describes retention of browser and server/security logs for up to 12 months, with exceptions where needed for security, performance or legal reasons. It also describes the possible continued presence of deleted data in protected backups for up to 12 months. These provider periods do not mean that all booking or legal-service records are deleted after 12 months.
Odoo uses infrastructure subprocessors, including OVH and Google Cloud, and describes possible access by its international subsidiaries. Its policies describe regional hosting, backups that can include Canada, and EU Standard Contractual Clauses for subsidiary access abroad. This notice does not promise exclusively EU processing. Further information and the published safeguards are available in Odoo's privacy policy and section 6.5 of its subscription agreement.
3. Cookies and browser storage
The website uses Odoo session, language and timezone functions. In the current anonymous website configuration:
session_idmaintains the Odoo session, including security-related context. Its observed browser expiry is approximately seven days, not simply the end of the browser session.frontend_langstores the frontend language preference, with an observed expiry of approximately one year.tzprovides timezone information and is set as a session cookie.- Odoo's frontend also creates a livechat-history local-storage entry with an approximately 24-hour expiry marker, even though this website currently has no configured livechat channel.
These are observed lifetimes, not a promise that every item is physically erased at that time or that subsequent use cannot refresh it. Browser settings may affect storage and session restoration.
For access to or storage on your device that is strictly necessary to provide a service you explicitly request, section 25(2) TDDDG applies. Where optional device access requires consent, section 25(1) TDDDG applies. The applicable GDPR basis for subsequent personal-data processing must be considered separately. The mere presence of a cookie or storage entry does not make it strictly necessary.
4. Website statistics
The website is configured to use Odoo's hosted implementation of Plausible Analytics. Its frontend script is supplied by Odoo and is configured to send pageview information to Odoo's analytics service. The script includes the page URL, referring page where available, website identifier, viewport width and event name. As with other network requests, the receiving server can receive connection information such as the IP address and browser information.
This configuration is not evidence that the website uses Plausible's separately hosted commercial service. No Google Analytics measurement key is configured for this website. We do not describe the Odoo analytics implementation as collecting no personal data or as having a verified, universal exemption from consent requirements.
5. External fonts and frontend libraries
The current website loads font stylesheets and font files from Google domains, including fonts.googleapis.com and fonts.gstatic.com. These requests occur when the page loads. Google's Fonts FAQ explains that such requests include an IP address, the requested resource and browser headers, including browser/operating-system and referrer information where supplied. Google states that the Fonts API does not set or log cookies and that it does not use Fonts information to profile users or for targeted advertising.
The frontend also loads Firebase App and Messaging JavaScript libraries from www.gstatic.com. Website push notifications are currently disabled; loading these libraries is not the same as subscribing to push notifications. The resource requests nevertheless communicate with Google infrastructure.
See Google's Fonts FAQ, Google's privacy policy and its international-transfer information. Google describes international processing and safeguards including the Data Privacy Framework and Standard Contractual Clauses where applicable. This notice does not guarantee a particular Google server location.
6. Enquiries and consultation bookings
If you contact the practice, we process the information you provide to respond to your enquiry. Where this concerns a prospective or existing contract with you, the basis is Article 6(1)(b) GDPR. Other business correspondence, including communications with representatives of organisations, is generally handled under Article 6(1)(f) GDPR, reflecting the legitimate interest in responding to and administering those communications.
The online booking forms request your name, email address, telephone number, chosen appointment type and time. The business form additionally requires an address and includes optional questions about business status, advance information and an online-meeting preference. Some current forms repeat name or email fields. The business form also permits adding guests. Provide another person's details only where you are entitled to do so and inform them about the booking.
Required fields must be completed to use online booking. Optional information is not required. Please provide only what is necessary to arrange the consultation, rather than detailed sensitive case information at this stage. You may contact the practice directly if you need to discuss how to communicate confidential material.
Booking information is processed in the practice's Odoo system to arrange and administer your requested consultation. Dr. Adam S. Dampc is the assigned practitioner. Necessary booking processing is based on Article 6(1)(b) GDPR where it concerns your contract or steps you request before a contract, or Article 6(1)(f) GDPR where needed to coordinate an organisation's engagement through its representative. Legal obligations may additionally require processing under Article 6(1)(c) GDPR.
Appointment invitations and cancellations are configured through Odoo. Email reminders are configured three hours before an appointment and SMS reminders one hour before it. These are appointment-service communications, not a described subscription to marketing messages.
The outgoing email system is configured to use STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. Odoo's SMS service processes the destination telephone number and reminder text. Odoo's current IAP policy identifies MessageBird and SMS Factor as SMS service providers; the provider used for a particular message may depend on delivery routing. The reminder template includes the event name and appointment time. Odoo's IAP privacy policy describes processing in Belgium/France, moderation processing and security/abuse-prevention logs kept for up to 12 months. STRATO's privacy information explains its service-provider role.
7. Payment
The consultation types are configured with a payment step. Information needed to arrange and account for payment may include your name, contact or billing details, the selected service, amount and payment status. The basis is Article 6(1)(b) GDPR for the contractual payment process and Article 6(1)(c) GDPR where accounting or other legal duties apply.
Stripe is an enabled payment provider. If you pay using a method handled by Stripe, Stripe processes the information needed for that payment. Depending on the method, this can include payment-instrument, billing, transaction and device information. Stripe's published terms distinguish its processing on behalf of a business from its own responsibilities, including fraud prevention and legal compliance. Where payment is made by bank transfer, the participating banks process the transfer information.
Stripe describes international processing, including transfers to Stripe LLC in the United States, and the applicable safeguards in its privacy policy, data-processing agreement and Data Transfers Addendum. The addendum describes the Data Privacy Framework and Standard Contractual Clauses as applicable. Stripe's own retention depends on its service, legal, fraud-prevention and related obligations. This notice does not promise a fixed universal Stripe deletion period or that the practice never receives payment-related data.
8. Legal services and how long information is kept
For legal services, information is processed as needed to perform the engagement and meet applicable legal obligations, including professional recordkeeping requirements. Client information is subject to professional confidentiality, including section 43a(2) BRAO and section 203 StGB. Particular legal matters may require additional information about recipients or other categories of data.
For the practice's enquiry and booking records, the retention criteria are the time needed to answer the enquiry, administer the appointment and engagement, comply with professional or tax recordkeeping requirements, and establish, exercise or defend legal claims. Once no such purpose or obligation remains, information should be deleted or irreversibly anonymised under the practice's retention procedures. Provider backups, mail copies and payment records may follow their own applicable retention arrangements. An email-template cleanup setting is not a promise that the underlying booking or case record is deleted.
9. Your rights
Subject to the applicable legal conditions, you can request access, rectification, erasure, restriction of processing and data portability under Articles 15–20 GDPR.
You may object to processing based on Article 6(1)(e) or (f) GDPR on grounds relating to your particular situation, under Article 21 GDPR. Where processing relies on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing. Statutory exceptions and professional confidentiality can affect the scope of particular rights.
Contact rechtsanwalt@dampc.legal to exercise your rights or ask for further information about the recipients and transfer safeguards relevant to your data, including how to obtain a copy of applicable safeguards.
You may complain to a supervisory authority, particularly in the Member State of your habitual residence, place of work or the alleged infringement. The authority in Baden-Württemberg is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Heilbronner Straße 35
70191 Stuttgart, Germany
Postal address: Postfach 10 29 32, 70025 Stuttgart, Germany
https://www.baden-wuerttemberg.datenschutz.de/