This English version is provided for convenience. The German version is the authoritative version.
Legal
Privacy Notice.
This notice explains how I process personal data in connection with this website, my mandates, and application processes.
A. Overview and Controller
This privacy notice explains how personal data is processed when you visit this website, get in touch, engage me for a company mandate, or take part in an application or placement process. It also covers direct approaches to candidates and the optional contact service.
The controller within the meaning of the GDPR is Julius Oscar Lorr, LORR Personalberatung, Chodowieckistraße 19/1, 10405 Berlin, Germany. Telephone: +49 30 81 45 65 100, e-mail: kontakt@lorr-personalberatung.de. No data protection officer has been appointed; you can reach me directly for any data protection question using the contact details above.
B. Hosting, Delivery and Server Logs
The website is delivered and technically hosted as a server-rendered application on the platform of Lovable Labs Incorporated, 1111b South Governors Avenue, Dover, DE 19904, USA. The provider may use further sub-processors for operation, delivery and infrastructure, and processing may take place outside the European Union. Processing carried out on my behalf is governed by the data processing terms agreed contractually and, where a third-country transfer is involved, by the contractually agreed safeguards, in particular the EU Standard Contractual Clauses. The hosting region and the list of sub-processors are documented on an ongoing basis.
When you access the website, the infrastructure processes technically necessary log data: IP address, date and time of access, the URL requested, the referring page where applicable, browser and operating system information, and the HTTP status code. The purposes are security, stability and fault analysis. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in secure and reliable operation. Log data is only retained for as long as technically necessary for these purposes.
D. Getting in Touch
If you contact me by e-mail, telephone or the contact form, I process your contact and identifying data, the content of your message, your enquiry and any voluntary additional information.
When you submit the contact form, your subject, name, optional company and telephone details, e-mail address and message are processed server-side and sent by e-mail to the designated contact address of this consultancy. The form content is not stored in a database of this website.
To protect against misuse, I use an invisible additional field (honeypot) and a short-term, IP-based rate limit on submissions. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in preventing spam and automated enquiries.
For technical e-mail delivery, the code provides for the service Resend, Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA. The service processes the form content solely to deliver the message, as a recipient or processor. Processing may take place in a third country; the contractually agreed safeguards apply, in particular the EU Standard Contractual Clauses.
If technical delivery is unavailable, a mailto link is offered as a fallback. It only opens your local e-mail application; transmission then happens once you send it yourself through your own e-mail service.
The legal basis for handling your enquiry is Art. 6(1)(b) GDPR for pre-contractual or contractual enquiries, otherwise Art. 6(1)(f) GDPR for appropriate communication. I delete your enquiry once its purpose has been fulfilled, unless statutory retention or evidentiary obligations require otherwise.
E. Services for Companies and Mandate Handling
Within a mandate, I process contact and company data, mandate and project data, communication records, and contract and billing data. The purposes are initiating, carrying out and billing the engagement. The legal basis is Art. 6(1)(b) GDPR, supplemented by Art. 6(1)(f) GDPR for the legitimate interest in orderly mandate management, and Art. 6(1)(c) GDPR for statutory obligations.
Recipients are, only where necessary, engaged service providers, tax and legal advisers, authorities where a legal obligation exists, and the parties involved in the specific mandate. I do not sell data.
F. Applications and Applicant Management
I process identity and contact data, CV, qualifications, work experience, availability, salary expectations, interview notes, correspondence, references and any other documents you submit.
The purposes are carrying out specific application and placement processes, communicating with you, assessing professional suitability, preparing possible employment or placement, and evidencing and defending legal claims.
The legal bases are Section 26(1) BDSG and Art. 6(1)(b) GDPR; for legal defence, Art. 6(1)(f) GDPR. I only process special categories of personal data where necessary and on a suitable basis, in particular Section 26(3) BDSG or Art. 9 GDPR.
Data originates directly from candidates, from professional networks and publicly available professional sources, from referrals, and where applicable from clients. Where I approach a candidate directly, I provide the information required under Art. 14 GDPR.
Data is not passed on to potential employers or clients as a matter of course, but only within the specific, agreed process and generally only after prior information to, and approval from, the candidate.
For applicant management and documentation, I use Coveto as a processor under Art. 28 GDPR: coveto ATS GmbH, Alois-Thums-Straße 11, 63667 Nidda. The application form only opens after a deliberate external navigation on your part; beforehand, I give you a separate notice about this change of site. The public job listing on this website is displayed via a server-side feed and does not transmit any applicant data to Coveto merely by being read.
Retention period: for the duration of the process. Once a process is concluded or a candidate is not selected, the data is generally deleted, unless retention is required to assert, exercise or defend legal claims; in that case, generally for no more than six months after conclusion. If an application is withdrawn, I generally delete the data promptly unless another legal basis applies. Statutory documentation and retention obligations remain unaffected.
There is no decision based solely on automated processing within the meaning of Art. 22 GDPR. Modern research and AI-assisted tools may provide support; selection, assessment and decisions are made by people.
G. Voluntary Candidate Pool
Inclusion in the candidate pool only takes place on the basis of a separate, voluntary consent. It is not a precondition for any specific application or placement process.
The purpose is to make contact regarding future suitable positions and to match candidates against mandates. The legal basis is Art. 6(1)(a) GDPR.
Data is stored for a maximum of 24 months from the date of consent; after that, it is deleted from the pool, or renewed voluntary consent is sought in good time. If consent is withdrawn, I delete the data sooner. Withdrawal is possible at any time, informally, by writing to kontakt@lorr-personalberatung.de, without any disadvantage and with effect for the future. Evidence of consent may be retained to the extent legally required.
H. Active Sourcing and Direct Approach
The purpose is identifying and confidentially approaching people for suitable professional opportunities. I process professional contact data, publicly visible profile data, and details of experience and qualifications.
The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in a well-matched filling of open positions and in professional outreach. You may object to this processing at any time. Following an objection, no further direct approach takes place; a minimal suppression record required for this purpose may be retained.
I. Optional Contact Service
At your explicit request, I can put you in touch with a suitable external provider. Initially, no data is passed on. Before any transfer, I inform you separately about the specific recipient, the categories of data affected and the purpose, and obtain your voluntary consent under Art. 6(1)(a) GDPR, which can be withdrawn at any time. LORR itself does not provide insurance or financial advice.
J. Recipients, Processors and Third-Country Transfers
Categories of recipients are: hosting and IT service providers, e-mail and communication services, Coveto as an applicant management provider, clients and potential employers after prior coordination, tax and legal advisers, and authorities where a legal obligation exists. Data is not sold.
A transfer to third countries only takes place where necessary and on the basis of an adequacy decision or appropriate safeguards, in particular the EU Standard Contractual Clauses.
K. General Retention Period
Personal data is deleted once its respective purpose no longer applies and no statutory retention periods or requirements of legal defence stand in the way. The specific periods mentioned above take precedence over this general rule.
L. Your Rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You may withdraw any consent given at any time under Art. 7(3) GDPR with effect for the future. You also have the right to lodge a complaint under Art. 77 GDPR.
To handle a data subject request, I verify your identity to a reasonable extent; additional information may be required for this purpose.
The competent authority may in particular be: the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), Alt-Moabit 59–61, 10555 Berlin, telephone +49 30 13889-0, e-mail mailbox@datenschutz-berlin.de, datenschutz-berlin.de.
M. Security, Encryption and Changes
This website is delivered over a TLS-encrypted connection (HTTPS). I take appropriate technical and organisational measures to protect personal data. Absolute security of transmission over the internet cannot be guaranteed.
This notice is updated whenever the services used, the processing activities, or the legal situation change. The version published here at any given time applies.