Privacy Policy

Privacy Policy (GDPR-Compliant)

1. Data Protection at a Glance

General Information

This section provides a brief overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. Detailed information on data protection can be found in the privacy policy below.

Data Collection on this Website

Who is responsible for data collection on this website?
Data processing is carried out by the website operator. Contact details can be found in the “Controller Information” section of this privacy policy.

How do we collect your data?
Some data is collected when you provide it to us (e.g. via contact forms). Other data is automatically collected by our IT systems when you visit the site (e.g. browser, operating system, time of access).

Why do we collect your data?
Part of the data is used to ensure the proper functioning of the website. Other data may be used to analyze user behavior.

What rights do you have regarding your data?
You have the right to receive information about the origin, recipient, and purpose of your stored personal data at any time. You also have the right to request rectification or deletion. If you have given consent, you may revoke it at any time. You also have the right to request restriction of processing. Furthermore, you have the right to file a complaint with the competent supervisory authority.

Analytics and Third-Party Tools
When visiting this website, your usage behavior may be statistically analyzed. This is done mainly using analytics tools. Further details are provided below.

2. Hosting

Hosting Provider: Verpex
Verpex Limited, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom

When you visit our website, Verpex collects various log files including IP addresses. For more information, please refer to Verpex’s privacy policy: https://verpex.com/legal/privacy-policy

The use of Verpex is based on Art. 6(1)(f) GDPR. We have a legitimate interest in a reliable and secure presentation of our website. Where consent is required (e.g. for cookies), processing is based on Art. 6(1)(a) GDPR and §25(1) TTDSG.

Data Processing Agreement (DPA)
We have entered into a DPA with Verpex, ensuring that personal data is processed strictly according to our instructions and in compliance with GDPR.

3. General Information and Mandatory Disclosures

Data Protection

We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with legal data protection regulations.

Controller Information

BML Advisory GmbH
Gewerbestrasse 13
82064 Strasslach-Dingharting, Germany
Email: info@bml-invest.com
Phone: +49 ‭89 20 94 01 00‬

The controller is the legal person who decides on the purposes and means of processing personal data.

Storage Period

Unless a more specific retention period is mentioned, your personal data will remain with us until the purpose for processing no longer applies. Legal obligations may require longer retention.

Legal Bases

Processing is based on Art. 6(1)(a-f) GDPR, depending on the specific purpose. We inform you of the exact legal basis for each case below.

Data Protection Officer

Marcus Lindner
BML Advisory GmbH
Lilienthalstrasse 27, 85399 Hallbergmoos
Email: info@bml-invest.com
Phone: +49 ‭89 20 94 01 00‬

Transfers to Third Countries / US Tools

Some tools we use may transfer data to third countries without an adequate level of data protection. In such cases, we ensure appropriate safeguards. For transfers to US companies, data processing is permitted if the recipient is certified under the EU-U.S. Data Privacy Framework (DPF).

Data Recipients

We only share personal data with third parties when legally permitted. This includes processors (under DPA agreements) and co-controllers (under joint agreements).

Revoking Your Consent

You may revoke your consent at any time. This does not affect the legality of processing carried out before revocation.

Right to Object (Art. 21 GDPR)

You have the right to object to data processing under Art. 6(1)(e) or (f) GDPR at any time, including profiling. You also have the right to object to direct marketing.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority, in the EU country of your habitual residence, workplace, or place of the alleged infringement.

Right to Data Portability

You may request your data in a machine-readable format or request transmission to another controller, where technically feasible.

Access, Rectification, Deletion

You have the right to access, rectify, or delete your stored data at any time.

Right to Restrict Processing

You may request restriction of processing in specific cases, such as pending verification, unlawful processing, or pending legal claims.

4. Data Collection on This Website

Cookies

This website uses cookies. Some cookies are technically necessary; others are for analytics or advertising purposes. Cookies may be set by us (first-party) or third parties (third-party). For full functionality, cookie consent may be required.

We use “Real Cookie Banner” to manage cookie consent. For more info: https://devowl.io/de/rcb/datenverarbeitung/

Legal basis: Art. 6(1)(c) and (f) GDPR; or Art. 6(1)(a) GDPR and §25(1) TTDSG when consent is required.

Contact by Email or Phone

If you contact us, your data (e.g. name, request) will be processed for the purpose of responding. Legal bases: Art. 6(1)(b), (f), or (a) GDPR.

5. Social Media

Instagram

Service provider: Meta Platforms Ireland Ltd., Dublin, Ireland.
When active, Instagram may process your data. Joint responsibility exists for initial collection and transfer (Art. 26 GDPR). More: https://www.facebook.com/legal/controller_addendum and https://privacycenter.instagram.com/policy/

LinkedIn

Service provider: LinkedIn Ireland Unlimited Company, Dublin, Ireland.
Usage may result in data transmission to LinkedIn and to the U.S. More: https://www.linkedin.com/legal/privacy-policy

6. Analytics and Advertising

Google Analytics

Service provider: Google Ireland Ltd., Dublin, Ireland.
Tracks user behavior, including interactions, scrolls, and sessions. Uses cookies and device fingerprinting.

Legal basis: Art. 6(1)(a) GDPR and §25(1) TTDSG. Consent can be withdrawn at any time.

Transfers to the U.S. based on DPF and Standard Contractual Clauses. More: https://privacy.google.com/businesses/controllerterms/mccs/

Opt-Out Plugin

You may opt out of tracking by using this plugin: https://tools.google.com/dlpage/gaoptout?hl=en

More info: https://support.google.com/analytics/answer/6004245?hl=en