Privacy
1. Controller
Rechtsanwalt Mir Naim Heydarinami, wolves law – Business Law Firm, Hermann-Kauffmann-Straße 2, 22307 Hamburg, Germany; telephone +49 40 84600138; email nh@wolves.law. wolves law operates this website and the initial network coordination. Middle East Desk is not an additional website operator.
2. Website access and technical providers
When you visit, IP address, date and time, requested address, transmitted referrer address, browser, operating system and connection information are processed to deliver the website, diagnose errors and prevent attacks. The legal basis is Article 6(1)(f) GDPR and our legitimate interest in secure, reliable operation.
Hosting is provided by Webflow, Inc., 398 11th Street, Floor 2, San Francisco, CA 94103, USA. Necessary infrastructure includes hosting and content delivery providers such as Amazon Web Services and Cloudflare. See Webflow's subprocessor list and data processing addendum. Technical providers receive the data needed for delivery, operation and security. Retention depends on the duration needed for those tasks and any specific incident investigation; we do not combine the data into advertising profiles.
3. Local message entry
The member enquiry area asks only for your email address and a message. These entries initially remain in the browser. “Prepare email” creates a draft in your own email application; it does not itself send a message or submit the entries to a Webflow form server. We receive them only when you actually send that email. A direct email link and a copy function provide alternatives. Your browser's own autofill is controlled through your browser.
After receipt, we process the information to reply, understand the requested jurisdiction and expertise, assess conflicts and consider an appropriate introduction. Article 6(1)(b) GDPR applies to contract-related enquiries; otherwise Article 6(1)(f) GDPR and our legitimate interest in handling professional enquiries. Article 6(1)(c) GDPR applies where legal duties require processing. Providing information is voluntary; without a meaningful description and a way to reply, an enquiry cannot be handled properly.
4. Private network and confidentiality
Member identities are not displayed in a public directory. Selection is performed by people, not by an automated decision. Your enquiry is not automatically distributed to network members. Any necessary introduction or disclosure is assessed individually, requires a suitable legal basis and respects professional confidentiality and, where appropriate, your approval. A firm subsequently retained acts as its own controller for its engagement and provides its own privacy information. Requests to become a member are likewise assessed confidentially; admission and any subsequent data use are agreed separately.
Please initially send only a short description, without particularly sensitive information or confidential attachments. Email is not automatically end-to-end encrypted. A protected transfer channel can be arranged. An enquiry alone does not establish a legal engagement or deadline monitoring.
5. Email services and other recipients
The firm's communication uses Microsoft 365, provided in the EU by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Message, contact and technical delivery data are processed for the email service. See Microsoft's contractual privacy terms. Other recipients are limited to persons whose participation is necessary or bodies to which disclosure is legally required. An enquiry is not automatically added to advertising or newsletter lists.
6. Cookies, scripts and external links
Necessary scripts and hosted files support layout, navigation, language selection and local preparation of your message. The current configuration does not activate our own analytics or marketing services, Google Analytics, Google Tag Manager or review widgets. Non-essential device access requires prior consent under section 25(1) TDDDG and, for related personal-data processing, Article 6(1)(a) GDPR. Operations solely needed for transmission or an expressly requested service fall under section 25(2) TDDDG. Continuing to browse is not consent.
Links to external websites are ordinary references. Their operators process data under their own notices when you visit the destination. A link does not automatically establish joint controllership.
7. Retention and international transfers
Enquiry and communication data is retained for handling and necessary documentation. Further retention may be required by statutory duties, necessary conflict checks or legal claims. Legal case files are generally subject to the six-year period in section 50 BRAO; other statutory periods may be longer. Data no longer needed is deleted or, where necessary, its processing restricted.
Webflow and international IT services may process data outside the EEA, particularly in the USA. Webflow states that it participates in the EU-US Data Privacy Framework. Covered transfers to certified recipients rely on Article 45 GDPR; otherwise appropriate safeguards under Article 46 GDPR, including EU Standard Contractual Clauses and any necessary supplementary measures, are required. Disclosure to an independent firm outside the EEA is assessed separately, not authorised indiscriminately by this notice. Information about applicable safeguards and a copy can be requested from us.
8. Your rights
Subject to the applicable conditions, you have rights of access, rectification, erasure, restriction and data portability under Articles 15–20 GDPR. Consent can be withdrawn at any time for the future without affecting earlier lawful processing.
Where processing relies on Article 6(1)(f) GDPR, you may object under Article 21 GDPR on grounds relating to your particular situation. You may object to direct marketing at any time without giving reasons.
Contact us using the details above to exercise your rights. We do not make solely automated decisions with legal or similarly significant effects under Article 22 GDPR.
9. Complaints
You may complain under Article 77 GDPR to a supervisory authority, particularly where you live, work or suspect an infringement. The authority for the firm's location is the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany; mailbox@datenschutz.hamburg.de; datenschutz-hamburg.de.