As of: 25.05.2022
and information on the processing of personal data pursuant to Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (GDPR)
We are pleased to welcome you to our website. Protecting your personal data when it is collected, processed and used in connection with your visit to our website is important to us. We would therefore like to inform you here which of your personal data we collect when you visit our website and for what purposes it is used.
As changes in the law or in our internal processes may require this privacy policy to be amended, we ask you to read it regularly. This privacy policy can be accessed, saved and printed at any time at https://www.mofidian.com/datenschutz.
This website is operated by the law firm cooperation Mofidian + Humer Rechtsanwälte – a collaboration of self-employed attorneys who practise independently of one another. Each cooperating attorney is independently (separately) responsible as controller within the meaning of Art. 4(7) GDPR for the processing of personal data relating to him; there is no joint controllership under Art. 26 GDPR. The controller for a specific engagement is the attorney named as the instructed firm in the power of attorney.
The controllers are:
Mag. Manuel A. Mofidian, Rechtsanwalt (Attorney-at-Law), Freyung 6/10/2, 1010 Vienna, Austria, email: office@mofidian.com, phone: +43 (0) 1 3534 400.
Mag. Stefan Humer, LL.M., Rechtsanwalt (Attorney-at-Law), Freyung 6/10/2, 1010 Vienna, Austria, email: office@mofidian.com, phone: +43 (0) 1 3534 400.
If you have any questions about data protection or wish to exercise your rights, you can reach us at: Freyung 6/10/2, 1010 Vienna, Austria, phone: +43 (1) 3534 400, email: office@mofidian.com.
We process your personal data for the purpose of fulfilling our (pre-)contractual obligations towards our clients. In this context, we process, for example, information such as your name, your email address, your IP address or your usage behaviour on our website. Information that cannot be linked to you personally (or only with disproportionate effort), e.g. as a result of anonymisation, does not constitute personal data in this sense.
The processing of personal data (e.g. its collection, retrieval, use, storage or transmission) always requires a legal basis or your consent. Personal data processed will be deleted as soon as the purpose of the processing has been achieved and no statutory retention obligations remain to be observed.
Where personal data is processed for the provision of particular offerings or services in a manner not already explained in this privacy policy, you will be informed below of the specific operations, the scope and purpose of that further processing, the legal basis and the respective storage period.
When you access and use our website, the personal data that your browser automatically transmits to our server is logged and temporarily stored in a so-called log file. When you use our website, the following data is collected, which is technically necessary for us to display our website to you and to ensure its stability and security:
• name of the website accessed
• name of the file accessed
• date and time of access
• amount of data transferred
• notification of successful retrieval
• browser type and version
• the user's operating system
• the website from which you reached our site
• IP address and the requesting provider
We use the log data only for statistical analyses for the purposes of operating, securing and optimising our website and for other administrative purposes. We reserve the right to review the log data retrospectively if, on the basis of specific indications, there is a legitimate suspicion of unlawful use.
The legal basis for this processing is Art. 6(1)(f) GDPR. The processing is necessary to provide a website and thus serves the legitimate interest of our firm. Under no circumstances do we use the data collected to draw conclusions about you personally.
As soon as the data is no longer required to display the website, it is deleted. The collection and storage of data in log files is essential for the operation of the website. Further storage may take place in individual cases where required by law. If log files are reviewed on suspicion of unlawful use, the data is deleted as soon as the review has been completed.
We offer various ways of contacting us. All information collected when you contact us is necessary at that point in order to prepare our advice and to be able to provide our services to you.
You can contact us via the contact form, by email or by phone. The information you provide is stored for the purpose of handling your enquiry and of arranging and preparing a free telephone appointment for advice and information, or advice by email.
If you contact us by email, the personal data transmitted will be stored. Email has become standard practice for lawyers too. However, like telephone calls or letters, emails can be read by unauthorised third parties acting unlawfully. Encryption can reduce this risk; experience shows, however, that most clients either cannot receive encrypted emails or choose not to use encryption for practical reasons.
If you contact us via the unencrypted contact form and provide an email address, or send us an unencrypted email with a view to instructing us, you agree that we may reply to you by unencrypted email and send you all case-related documents in this way. You may decide otherwise at any time with effect for the future (except in emergencies requiring urgent action to protect your rights).
If you contact us by phone, your phone number, the date of the call and the information provided will be stored to the extent necessary to handle your enquiry. If you instruct us, this data will be transferred to your file. The contact form contains the mandatory fields name, email address and subject; information in the free-text message field is voluntary. This data is transmitted to our email inbox in unencrypted form.
The legal basis for this processing is Art. 6(1)(b) GDPR. The processing is necessary in order to take steps at the request of the data subject prior to entering into a contract. Where consent has been obtained, the processing is based on Art. 6(1)(a) GDPR.
The storage period depends on the reason for your enquiry. Data is deleted once the purpose of the communication no longer applies and storage is no longer necessary.
We process your personal data to the extent necessary to conduct the application process. This includes in particular applicant master data (first name, surname, address, position applied for), qualification data (cover letter, CV, previous positions, professional qualifications) as well as (employment) references and certificates. Where applicable, specific information may be required, such as a criminal record certificate (only upon conclusion of the employment contract). We also process voluntary information whose processing you have consented to.
The legal basis is the taking of pre-contractual steps or the performance of a contract (Art. 6(1)(b) GDPR) and, for voluntary information, your consent (Art. 6(1)(a) GDPR).
We store your data for as long as necessary to decide on your application. If no employment relationship is established, we may continue to store data to the extent necessary to defend against possible legal claims; as a rule, your data will be deleted within seven months of the end of the application process. Where you have given consent, we store your data until you withdraw it, but for no longer than one year.
We process personal data relating to a legal matter (“engagement data”) in particular to advise on and handle the engagement, to establish, exercise or defend legal claims, to comply with legal obligations and for operational purposes (e.g. internal records, accounting, invoicing, compliance with tax regulations).
The legal basis for processing your data is Art. 6(1)(b) GDPR for the performance of the engagement agreement and the provision of legal advice to our clients. For compliance with statutory and professional obligations, the legal basis is Art. 6(1)(c) GDPR. For operational purposes and the ongoing business relationship with our clients, processing is based on our legitimate interest under Art. 6(1)(f) GDPR. This legitimate interest lies in the proper and efficient organisation of our practice and in maintaining our client relationships. Where you have given us your consent, the legal basis is Art. 6(1)(a) GDPR.
Under § 12(1) RAO (Austrian Lawyers Act), client files and data must be retained for five years after the end of the engagement. In addition, in order to defend against possible damages claims arising from the engagement, we reserve the right to retain client files until the expiry of the maximum limitation period under the Austrian Civil Code (ABGB). Tax retention periods also apply, in particular the seven-year retention obligation under § 132 BAO (Austrian Federal Fiscal Code).
We only pass on your personal data to third parties if you have given your express consent under Art. 6(1)(a) GDPR, if there is a legal obligation under Art. 6(1)(c) GDPR, if this is necessary under Art. 6(1)(b) GDPR for the performance of a contract or to take pre-contractual steps, or if disclosure is necessary under Art. 6(1)(f) GDPR to protect legitimate interests or to establish, exercise or defend legal claims and there is no overriding interest of yours worthy of protection.
As attorneys, we are subject to a statutory duty of confidentiality (§ 9 RAO). Data will not be disclosed where this would conflict with attorney confidentiality; for the same reason, data subject rights – in particular the right of access – may be restricted where confidentiality interests of other clients or third parties are affected.
To fulfil our contractual and statutory obligations, your personal data may be disclosed to various public or internal bodies and to external service providers, in particular: IT service providers, web hosting providers, file management service providers, and auditors, tax advisers and attorneys.
We disclose some of your personal data to the service providers mentioned above in the following cases: where appropriate, for the purposes described in the section “Purposes of processing and legal bases”, including disclosure within the law firm cooperation Mofidian + Humer Rechtsanwälte; where appropriate to enforce agreements or to protect the rights, property or safety of the cooperating attorneys; to comply with court proceedings, a court order or an official investigation; or with your consent.
As a rule, data is not transferred to countries outside the European Economic Area (third countries). Where, in individual cases – for example when using service providers with a US connection – data is nevertheless transferred to a third country, we base the transfer on an adequacy decision of the European Commission (e.g. the EU-U.S. Data Privacy Framework), on standard contractual clauses or on a derogation under Art. 49 GDPR.
Not all the data we process comes directly from you. In the course of an engagement, we may also receive personal data relating to you from third parties or from publicly accessible sources and registers (e.g. the Austrian companies register (Firmenbuch), the land register (Grundbuch) or the official court publications database (Ediktsdatei)). We process the categories of data required for the matter concerned, in particular identification and contact data as well as information relating to the proceedings and the subject matter.
In representing our clients, we also process personal data of persons who are not themselves our clients – for example our clients' opponents, other parties involved or persons providing information. We usually receive this data from our clients or their business partners, from publicly accessible sources or from other third parties. The legal basis is our legitimate interest, or that of our clients, in asserting and enforcing their rights (Art. 6(1)(f) GDPR). These persons are not informed separately about the processing where we are exempt from the duty to provide information under Art. 14(5) GDPR – in particular because of attorney confidentiality or because providing the information would be impossible or would involve disproportionate effort.
Our website may contain hyperlinks to websites of other providers. When you click on them, you are redirected directly to the other provider's website (recognisable, among other things, by the change of URL). We cannot accept responsibility for the confidential handling of your data on these third-party websites. Please refer to those websites directly for information on how your data is handled.
When you click the link on our website, LinkedIn receives the information that you have visited our website with your IP address; LinkedIn may be able to associate this visit with your user account. We have no knowledge of the content of the data transmitted or of its use by LinkedIn. The legal basis for including the link is our legitimate interest in an appealing external presentation under Art. 6(1)(f) GDPR. Further information can be found in LinkedIn's privacy policy at https://www.linkedin.com/legal/privacy-policy.
Our website may use cookies – small text files stored on your device that allow us, for example, to recognise your browser. We process technically necessary cookies, which ensure the operation, security and basic functions of the website, on the basis of our legitimate interest (Art. 6(1)(f) GDPR). We only set cookies that are not necessary – for example for analytics or marketing purposes – with your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future. You can restrict the storage of cookies or delete cookies already stored via your browser settings; this may limit the functionality of the website.
Under the GDPR, you as a data subject have the following rights:
Right to object. In certain cases, you are entitled to object to the processing of your personal data.
Right of access. You have the right to obtain confirmation as to whether we process data concerning you, and to obtain information about and access to that data – subject to statutory exceptions and attorney confidentiality.
Right to rectification. If the personal data we process is incomplete or inaccurate, you have the right at any time to have it completed or rectified.
Right to erasure (“right to be forgotten”). Subject to certain exceptions, you have the right to request the erasure of your personal data. However, there may be reasons why immediate erasure is not possible (e.g. statutory or professional retention obligations).
Right to restriction of processing. In certain cases, you are entitled to request that the processing of your data be restricted, for example if you contest its accuracy, the processing is unlawful, you need the data to pursue legal claims, or you have lodged an objection.
Right to data portability. You have the right to receive the data you have provided in a structured, commonly used and machine-readable format, or to have it transmitted to another controller.
Right to withdraw consent. Where your data is processed on the basis of your consent, you may withdraw that consent at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.
No automated decision-making. No decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR) is taken.
If you suspect that a data protection breach may have occurred on the part of the law firm cooperation Mofidian + Humer Rechtsanwälte, you can contact us at: Freyung 6/10/2, 1010 Vienna, Austria, phone: +43 (1) 3534 400, email: office@mofidian.com. You also have the right to lodge a complaint with the competent supervisory authority:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, Austria, phone: +43 (1) 521 52-25 69, email: dsb@dsb.gv.at.
Without prejudice to a complaint to the Data Protection Authority, you may also bring proceedings before the ordinary courts; any action must be filed with the competent regional court (Landesgericht) pursuant to § 29(2) DSG (Austrian Data Protection Act).
We are committed to protecting your privacy and treating your personal data confidentially. To prevent manipulation, loss or misuse of your data stored with the cooperating attorneys (Mofidian + Humer), we take extensive technical and organisational security measures, which are regularly reviewed and adapted to technological progress. These include, among other things, the use of recognised encryption methods (SSL/TLS).
Please note, however, that due to the structure of the internet, other persons or institutions outside our area of responsibility may not comply with data protection rules and the safeguards mentioned above. In particular, data disclosed without encryption may be read by third parties. It is the user's responsibility to protect the data provided against misuse by means of encryption or otherwise.
We reserve the right to amend this privacy policy at any time in compliance with applicable data protection law or in the event of any other change in the factual or legal situation. Please check the privacy notice applicable at that time each time you start using our website. Last updated: June 2026.