Privacy Policy
This privacy policy explains how LegalRift (“we”, “us”) processes personal data when you visit legalrift.com, contact us or use our services. We process your data exclusively in accordance with the General Data Protection Regulation (GDPR) and German data protection law.
1. Controller
The controller within the meaning of Art. 4 No. 7 GDPR is LegalRift. For all data protection matters you can reach us at legal@legalrift.com. All communication with us takes place by email and live chat.
2. What we process, in short
Usage data when you visit the website (server logs), contact data when you write to us (name, email address, message) and case data when we handle a matter for you (links, screenshots, correspondence, business details). We do not use analytics, advertising or tracking cookies.
3. Hosting and server logs
The website is hosted by a specialised hosting provider that acts as our processor under a data processing agreement (Art. 28 GDPR). When you access the website, the following data is processed automatically: IP address, date and time of the request, requested page, referrer, browser type and operating system.
This processing is necessary to deliver the website securely and to detect and prevent attacks. Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Log data is deleted as soon as it is no longer needed for these purposes, normally within 14 days.
4. Contact form, email and live chat
When you use the contact form, the live chat or write to us by email, we process the data you provide – in particular your name, email address, the message and any links – in order to answer your inquiry and, where applicable, to assess and prepare a mandate.
Live chat messages are forwarded to our team by email; we do not use an external chat provider. Legal basis: Art. 6(1)(b) GDPR (steps prior to entering into a contract) and Art. 6(1)(f) GDPR (our legitimate interest in answering inquiries). Inquiry data is deleted once your request has been fully dealt with, unless a mandate follows or statutory retention periods apply.
5. Handling your case and disclosure to platforms
If you mandate us, we process the data required for the mandate: your business and contact details, the content concerned, evidence and correspondence. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
To enforce your rights we transmit the data that is strictly necessary to the platform concerned – for example Google Ireland Limited or Meta Platforms Ireland Limited – or to the operator or hosting provider of the infringing content, and, where required, to courts and authorities. Some recipients are located outside the European Economic Area. Such transfers are based on adequacy decisions of the European Commission, standard contractual clauses or Art. 49(1)(e) GDPR (transfer necessary for the establishment, exercise or defence of legal claims).
6. Cookies and local storage
We use a single, technically necessary cookie (“lang”) that stores your language preference for 12 months. It contains no personal data and is not used for tracking. Legal basis: § 25(2) No. 2 TDDDG and Art. 6(1)(f) GDPR. You can delete the cookie at any time in your browser settings.
We do not use analytics tools, advertising networks, social media plug-ins or externally loaded fonts.
7. Retention
We keep personal data only for as long as it is necessary for the purposes described above or as required by law. Mandate files are retained in accordance with professional obligations for attorneys and commercial and tax law retention periods (generally six to ten years). Afterwards the data is deleted.
8. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). If processing is based on consent, you may withdraw it at any time with effect for the future (Art. 7(3)).
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence or place of work (Art. 77 GDPR). To exercise your rights, email legal@legalrift.com.
9. Security
The website and all communication channels are encrypted using TLS. Case data is protected by technical and organisational measures and is additionally subject to attorney-client confidentiality.
10. Changes
We update this privacy policy whenever our services or the legal framework change. The version published on this page applies.