datenschutz

Privacy Policy

Last updated: August 2026

1. General Information

This Privacy Policy explains how we process personal data when you visit our website, contact us or use our services.

Personal data means any information relating to an identified or identifiable natural person. Processing means any operation performed on personal data, in particular its collection, storage, use, transfer, alteration or deletion.

We process personal data in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and other applicable data protection laws.

2. Controller

The controller responsible for the processing of personal data is:

Sesch Group GmbH Wirtschaftsprüfungsgesellschaft
Rahmannstr. 11
65760 Eschborn
Germany

Email: mail@taxrep.de

Managing Directors:
Tibor Schade
Alexander Fölsche

3. Principles of Data Processing

We process personal data only to the extent necessary for the operation of this website, communication with prospective clients and clients, the provision of our services, the fulfilment of legal obligations or the protection of legitimate interests.

We take care to ensure that personal data:

  • is processed lawfully, fairly and transparently;
  • is used only for specified and identifiable purposes;
  • is limited to what is necessary for the relevant purpose;
  • is accurate and, where possible, kept up to date;
  • is not retained longer than necessary; and
  • is protected by appropriate technical and organisational measures.

4. Accessing and Using the Website

When you access our website, technical data may be collected automatically by the web server or hosting provider. This may include in particular:

  • IP address of the device used;
  • date and time of access;
  • pages and files accessed;
  • amount of data transferred;
  • referrer URL;
  • browser type and browser version;
  • operating system;
  • device type; and
  • technical status and error messages.

This data is processed in order to provide the website technically, ensure the stability and security of our systems, detect errors, prevent misuse and carry out statistical analyses of website usage.

The processing is based on Article 6(1)(f) GDPR. Our legitimate interest is the provision of a secure, stable and functional website.

5. Hosting

Our website is hosted by the following provider:

[Name of hosting provider]
[Address of hosting provider]
[Country]

According to our current knowledge, the servers used for hosting are located in the European Union or the European Economic Area.

The hosting provider processes technical access data and other data generated through the use of this website on our behalf to the extent necessary for the provision, security and maintenance of the website.

6. Contacting Us

If you contact us by email or via a contact form, we process the information you provide. This may include in particular:

  • first and last name;
  • email address;
  • telephone number;
  • company and position;
  • country of residence or registered office;
  • information concerning your enquiry;
  • messages and documents submitted; and
  • date and time of contact.

We use this data to review your enquiry, communicate with you, prepare a potential engagement and, where applicable, initiate or perform a client relationship.

Depending on the circumstances, processing is based on Article 6(1)(b) GDPR for the performance of pre-contractual measures or a contract, Article 6(1)(c) GDPR for compliance with legal obligations, or Article 6(1)(f) GDPR based on our legitimate interest in processing business enquiries.

Please do not send particularly confidential tax, financial or identity documents unencrypted through the general contact form or by ordinary email. Where necessary, we provide a separate secure transmission method for the exchange of extensive or confidential documents.

7. Client Onboarding and Provision of Services

If you engage us for tax, accounting or other professional services, or enquire about such an engagement, we may process additional personal data. This may include in particular:

  • identification and contact data;
  • tax identification numbers and registration numbers;
  • information regarding residence, nationality and tax status;
  • financial, income, asset and transaction data;
  • company and ownership information;
  • contract and billing data;
  • correspondence and advisory documents; and
  • other information required for the performance of the specific engagement.

We process this data to assess whether an engagement can be accepted, identify clients, prepare proposals and engagement letters, perform the engagement, issue invoices, document our services and fulfil statutory, professional and regulatory obligations.

Additional privacy notices or contractual provisions may apply to a specific client relationship.

8. Cookies and Similar Technologies

Our website may use cookies and similar technologies. Cookies are small files that may be stored on your device or associated with your browser.

We distinguish in particular between:

  • strictly necessary cookies: These are required for the website to function properly, to be operated securely and to store settings selected by you;
  • analytics cookies: These help us understand how the website is used and how we can improve content and user navigation.

Strictly necessary cookies and similar technologies may be used without separate consent where their storage or access to information on your device is strictly necessary within the meaning of Section 25(2) TDDDG. Non-essential analytics or marketing technologies are activated only after you have given consent through the cookie consent tool.

You may withdraw or change your consent at any time with effect for the future through the cookie settings. You may also delete or block cookies through your browser settings. This may result in some functions of the website no longer being fully available.

9. Google Analytics

Where Google Analytics is used on this website, we use this web analytics service to statistically evaluate the use of our website and improve our services.

Within the European Economic Area, the provider is generally:

Google Ireland Limited
Gordon House, Barrow Street
Dublin 4
Ireland

Google Analytics may process, in particular, the following information:

  • shortened or full IP address;
  • approximate location;
  • browser and device information;
  • operating system;
  • pages accessed;
  • length of visit;
  • navigation within the website;
  • source of the website visit;
  • technical event and usage data; and
  • cookie or similar identifiers.

We use Google Analytics only if you have previously given your consent through the cookie consent tool. Processing is based on your consent pursuant to Article 6(1)(a) GDPR and, to the extent information is stored on or read from your device, Section 25(1) TDDDG. You may withdraw your consent at any time with effect for the future.

Where technically available, we activate Google's settings designed to limit data collection and do not use the information obtained to directly identify individual website visitors.

Google may also process data on servers outside the European Union or the European Economic Area, in particular in the United States. Where required, such transfers are based on an adequacy decision, a recognised data protection framework, standard contractual clauses or other safeguards provided for by law.

Further information about Google's processing of personal data can be found in Google's privacy information.

10. Google Tag Manager

Where Google Tag Manager is used on this website, we use this service to manage and technically trigger other website tags.

Within the European Economic Area, the provider is generally:

Google Ireland Limited
Gordon House, Barrow Street
Dublin 4
Ireland

Google Tag Manager primarily serves to manage integrated services. The personal data actually processed depends in particular on the tags and services integrated and triggered through Tag Manager.

Non-essential services integrated through Google Tag Manager are activated only after you have given your consent. Google Tag Manager may not be used to circumvent the absence of consent for an integrated analytics or marketing service.

Google may also process technical data outside the European Union or the European Economic Area. The safeguards described above apply to such transfers.

11. WordPress

Our website is operated using the WordPress content management system. WordPress and the extensions used may set strictly necessary cookies or process technical data where this is necessary for the display, administration, security and functionality of the website.

We use WordPress extensions only where they are necessary for the operation of the website or have been expressly selected by us. Depending on the extensions used, additional data processing may take place. If additional services, plugins or embedded content are used in the future, this Privacy Policy will be updated accordingly.

12. Recipients of Personal Data

We may disclose personal data to third parties where this is necessary for the purposes described above, required by law or initiated by you. Potential recipients include in particular:

  • hosting, IT, security and maintenance service providers;
  • providers of analytics and cookie management services;
  • communication and document exchange service providers;
  • tax authorities and other competent authorities;
  • courts and public authorities;
  • banks and payment service providers;
  • external professional advisers and cooperation partners; and
  • other recipients to whom data is transferred with your consent.

Service providers that process personal data on our behalf are contractually required to process and protect the data appropriately where required by law.

13. International Data Transfers

We generally process personal data in Germany, the European Union and the European Economic Area.

However, when international IT and analytics services are used, personal data may also be processed in other countries, in particular in the United States.

Where a recipient is located in a country outside the European Union or the European Economic Area, data is transferred only in accordance with Articles 44 et seq. GDPR. This may be based in particular on an adequacy decision of the European Commission, appropriate safeguards such as standard contractual clauses or the statutory derogations under Article 49 GDPR.

Despite such measures, where data is processed in another country it cannot be completely excluded that foreign authorities may obtain access to personal data under the laws applicable there.

14. Retention Period

We retain personal data only for as long as necessary for the relevant purpose or for as long as statutory, contractual or professional retention obligations apply.

Technical log data is generally stored only for as long as necessary for secure operation and error analysis. Enquiries, correspondence and client documents may be retained for longer where this is necessary for the performance or documentation of a business relationship, compliance with legal obligations or the establishment, exercise or defence of legal claims.

After the applicable retention period has expired, the data is deleted, anonymised or restricted unless there is a further legal or factual necessity to retain it.

15. Data Security

We implement appropriate technical and organisational security measures to protect personal data against loss, misuse, unauthorised access, unlawful alteration and unauthorised disclosure.

These measures may include, in particular, access restrictions, authorisation concepts, encryption, backups, security updates and contractual obligations imposed on service providers used by us.

Data transmitted between your browser and our website is generally encrypted. However, completely secure data transmission over the internet cannot be guaranteed.

16. Rights of Data Subjects

Subject to the GDPR, you have in particular the following rights:

  • access to information as to whether and which personal data we process about you;
  • rectification of inaccurate or incomplete personal data;
  • erasure of personal data;
  • restriction or cessation of certain processing activities;
  • objection to certain processing activities;
  • receipt or transfer of certain personal data in a commonly used format;
  • withdrawal of consent with effect for the future; and
  • lodging a complaint with a competent data protection supervisory authority.

These rights are not absolute. Statutory obligations, overriding interests, professional secrecy obligations or the rights of third parties may mean that we are not permitted to comply with a request, or may comply only in part.

To exercise your rights, you may contact us at mail@taxrep.de. We may request appropriate proof of your identity.

You also have the right to lodge a complaint with a data protection supervisory authority. For us, the Hessian Commissioner for Data Protection and Freedom of Information (Hessischer Beauftragter für Datenschutz und Informationsfreiheit) is of particular relevance as the competent supervisory authority.

17. No Automated Individual Decision-Making

In connection with the use of this website, we generally do not make decisions based solely on automated processing within the meaning of Article 22 GDPR that produce legal effects concerning you or similarly significantly affect you.

18. Links to Third-Party Websites

Our website may contain links to third-party websites. The respective operators are responsible for data processing on those external websites. Please refer to the privacy policies published there.

19. Changes to this Privacy Policy

We may amend this Privacy Policy at any time, in particular if we change our data processing activities, use new services or if legal requirements change.

The version published on this website at the relevant time applies. The date stated at the beginning of this Privacy Policy indicates when it was last revised.