top of page

Privacy Policy

Wang Advisory GmbH

Last updated: 15 June 2026

 

Wang Advisory GmbH ("we", "us", "our") processes personal data in accordance with the GDPR, the German Federal Data Protection Act (BDSG), and the Telecommunications Digital Services Data Protection Act (TDDDG). This policy explains how we handle your data when you visit our website or communicate with us.

1. Controller

Wang Advisory GmbH, Gabriele-Tergit-Promenade 21, 10963 Berlin, Germany (office); Friedrichsbrunner Str. 9, 12347 Berlin (registered). Managing Director: David Wang. HRB 223605 B, Amtsgericht Charlottenburg. VAT ID: DE337373969. Phone: +49 1516 3153241. Email: info@wangadvisory.com.

2. Data Protection Officer

We are not required to appoint a Data Protection Officer under § 38 BDSG. For all data protection matters, contact info@wangadvisory.com.

 

3. Data We Process, Purposes and Legal Bases

We process personal data for the following purposes and on the following legal bases:

  • Handling inquiries (email, phone, contact form): name, company, email, phone and message content — Art. 6(1)(b) GDPR (pre-contractual steps) and Art. 6(1)(f) GDPR (legitimate interest in responding to and documenting inquiries).

  • Delivering consulting engagements and managing the client relationship: contractual and project data and billing details — Art. 6(1)(b) GDPR (performance of contract).

  • Invoicing, accounting and tax compliance: billing and transaction data — Art. 6(1)(c) GDPR (legal obligation under HGB and AO).

  • Operating, securing and stabilising the website: server log data (IP address, browser, operating system, referrer URL, pages visited, timestamp) — Art. 6(1)(f) GDPR (legitimate interest in IT security and a functioning site).

  • Non-essential cookies, analytics and marketing: cookie and usage data — Art. 6(1)(a) GDPR and § 25(1) TDDDG (consent).

  • Asserting or defending legal claims: any relevant data — Art. 6(1)(f) GDPR (legitimate interest in legal defence).

Providing contact data is voluntary, but without it we cannot respond to your request.

4. Hosting and Server Log Files

Our website is hosted by Wix.com Ltd., 40 Namal Tel Aviv St., Tel Aviv 6350671, Israel ("Wix"), which processes data on our behalf as our processor under a data processing agreement pursuant to Art. 28 GDPR (available at www.wix.com/about/privacy-dpa-users). Wix may store and process data on servers located in the European Union, Israel and the United States (see Section 8).

On each access, Wix's infrastructure records log files containing the IP address, browser type and version, operating system, referrer URL, pages visited and timestamp, on the basis of Art. 6(1)(f) GDPR (legitimate interest in IT security and a functioning site). This data is deleted or anonymised after approx. 90 days unless needed to investigate a security incident.

5. Cookies (§ 25 TDDDG)

Strictly necessary cookies enabling the basic functioning of the site are used under § 25(2) TDDDG and Art. 6(1)(f) GDPR, without consent. All other cookies and similar technologies are set only after you consent via our cookie banner (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). You may withdraw consent at any time with effect for the future, without affecting prior lawfulness, via [cookie settings link] or your browser settings.

6. Analytics, Marketing and Third-Party Tools

[List only the tools actually in use. For each: provider name and address; purpose and data collected; legal basis (consent under Art. 6(1)(a) GDPR + § 25(1) TDDDG); any transfer outside the EEA and the safeguard relied on; link to the provider's privacy policy. 

We do not process personal data for analytics or marketing beyond what is stated above.

7. Recipients

We do not sell personal data. We disclose it only to IT and hosting providers (as Art. 28 processors), professional advisors (tax, audit, legal), payment and accounting providers, and public authorities or courts where legally required or necessary to defend legal claims. All processors are bound by Art. 28 GDPR agreements.

8. International Transfers

Our host, Wix.com Ltd., processes data in the European Union, Israel and the United States. Transfers to Israel are covered by the European Commission's adequacy decision (Art. 45 GDPR). Transfers to the United States or other third countries without an adequacy decision are based on the European Commission's Standard Contractual Clauses (Art. 46 GDPR) together with supplementary technical and organisational safeguards, as set out in the Wix Data Processing Addendum (www.wix.com/about/privacy-dpa-users). Where any further tool transfers data to a third country, the specific safeguard is stated in Section 6.

9. Retention

We keep personal data only as long as necessary or legally required. Inquiry data not leading to a contract is deleted once the matter is closed. Client and contract data is retained for the engagement and the applicable limitation periods (regularly three years, § 195 BGB; longer where longer periods apply). Accounting records are kept eight years (accounting vouchers and invoices), ten years (ledgers and annual financial statements) and six years (commercial correspondence), per § 257 HGB and § 147 AO. Server logs are deleted or anonymised after approx. 30 days.

10. Your Rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18) and data portability (Art. 20), and to withdraw consent at any time with effect for the future (Art. 7(3)). To exercise these rights, contact info@wangadvisory.com.

Right to object (Art. 21 GDPR): Where we process your data on the basis of legitimate interests, you may object at any time on grounds relating to your particular situation; for direct marketing, you may object at any time without giving reasons.

11. Right to Complain

You may lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority competent for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin, +49 30 13889-0, mailbox@datenschutz-berlin.de. You may also contact the authority of your residence.

12. Automated Decision-Making

We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

13. Security

We apply appropriate technical and organisational measures under Art. 32 GDPR, including TLS/SSL encryption. No internet transmission can be guaranteed fully secure.

14. Changes

We may update this policy to reflect legal, technical or operational changes. The current version, bearing the date above, is always available on our website.

bottom of page