Privacy Policy
​
General Information on Data Protection
Thank you for your interest in working with Lohmann Executives – whether as a client, candidate, or in any other contractual relationship. Providing tailored executive search services requires the collection and processing of a wide range of personal data. The proper and lawful handling of the data you entrust to us is of the utmost importance. In the following, we aim to transparently explain how your data is processed and to fulfill our obligations under the EU General Data Protection Regulation (GDPR).
​
Controller
In accordance with Art. 4 No. 7 and Art. 26 GDPR, the data controller is:
Lohmann Executives
Owner: Markus Lohmann
Klopstockplatz 15
22765 Hamburg
Tel: +49 178 5793 125
Email: info@lohmannexecutives.de
Web: www.lohmannexecutives.de
​
For questions, complaints, data deletion requests or other data protection concerns, please contact:
​
Markus Lohmann
Klopstockplatz 15
22765 Hamburg
Tel: +49 178 5793 125
Email: datenschutz@lohmannexecutives.de
​
Data at Lohmann Executives
​
What Data We Process
According to Art. 4 No. 1 GDPR, personal data refers to any information relating to an identified or identifiable natural person. At Lohmann Executives, we process personal data from clients (organizations that commission us), candidates (individuals we approach or who apply for roles), and service providers or other business partners.
​
Client Data
If you are a client, we store specific business information necessary to fulfill the assignment, including:
-
Contact details of designated representatives (name, email, phone number)
-
Company address and billing information
-
Tax-relevant and contractual data
-
Public or confidential information about the company and the role
-
Project-related contextual details
Candidate Data
When you are approached about a vacancy and agree to participate in the process, we will collect personal data from you only after your explicit consent. This includes:
-
Full contact details (address, email, phone)
-
CV, education and work history, certificates, language skills
-
Profile photo, date of birth, marital status, nationality
-
Professional achievements and qualifications
-
Personal interests and motivations, salary expectations
-
References, notice period, willingness to relocate
-
Any further relevant data you voluntarily share with us
Service Providers and Partners
To maintain business relationships and fulfill contractual obligations, we process the following data:
-
Contact information of designated representatives
-
Company address, billing information, tax and contract details
-
Other necessary data within the scope of the collaboration
How We Handle Your Data
We treat all personal data with care and in accordance with applicable laws. Internally, we apply confidentiality policies, maintain a processing record, implement technical and organizational security measures, and enter into processing agreements with external providers when applicable.
​
Clients
To fulfill client assignments, we collect and process personal data on the basis of your consent (Art. 6(1)(a) GDPR). Some data (e.g., billing details) serve the contractual relationship. Others (e.g., job descriptions and candidate criteria) may be shared with candidates after consultation with you. We may also process client data to assert legal claims or defend against them. Data will be deleted once legal retention periods expire.
​
Candidates
With your consent (Art. 6(1)(a) GDPR), we collect candidate data during direct search and only proceed further if you opt in. Data is stored in secure recruitment software. Only after agreement will data be shared with clients, and only with authorized contacts. Candidate reports may include evaluations of qualifications and suitability. Interviews, reference checks, and further processing are always agreed upon in advance. Data will be deleted 6 months after the position is filled unless longer retention is legally required or separately consented to (e.g., candidate pool).
​
Service Providers
We collect and process service provider data for communication and contract purposes (Art. 6(1)(b) and (c) GDPR). This includes contact and billing details, stored in our system with your consent (Art. 6(1)(a) GDPR).
​
International Data Transfers
No data is transferred outside the EU or to third countries.
Data Collection on This Website
Some data is collected automatically by our IT systems when you visit this website. This includes technical information (e.g., browser, operating system, time of visit). Other data is provided voluntarily, such as through contact forms.
Purposes of Processing
We process data to ensure error-free delivery of the website, analyze user behavior, or respond to inquiries. Once the purpose no longer applies, we delete or anonymize the data unless longer retention is required by law.
Your Rights
You have the right to request information about your stored data, to correct, delete, or restrict processing, and to object to processing. You may also revoke consent at any time. Furthermore, you may file a complaint with the competent supervisory authority:
Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Str. 22
20459 Hamburg
Tel: +49 40 42854-4040
Email: mailbox@datenschutz.hamburg.de
Web: www.datenschutz-hamburg.de
Data Retention
We retain personal data only as long as necessary to fulfill the original purpose or comply with legal obligations. Once expired, data is deleted unless otherwise consented.
Security – SSL Encryption
This site uses SSL/TLS encryption to protect transmitted content. A secure connection is visible by "https://" in the browser address and a lock symbol.
Server Log Files
Our hosting provider (Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin) stores server log files (browser type, IP address, timestamp, etc.) based on Art. 6(1)(f) GDPR for stability and security purposes. More at: www.strato.de/datenschutz
Contact by Email or Phone
When contacting us by email, phone, or form, we store your request and related data for processing. This is done under Art. 6(1)(b) GDPR if contract-related, or based on your consent (Art. 6(1)(a)) or our legitimate interest (Art. 6(1)(f)).
Cookies
We use essential cookies to ensure functionality:
-
PHPSESSID: Session cookie for session ID (expires when browser closes)
-
_csrf: CSRF protection (expires when browser closes)
Deleting cookies may impact website functionality.
Hosting
Website hosted by Strato AG, see their privacy policy for more details: www.strato.de/datenschutz
Hosting and Website Platform
This website is built using Wix.com Ltd, Nemal St. 40, 6350671 Tel Aviv, Israel. Wix stores website content and processes certain technical data (e.g. IP address, browser type, access logs) as part of its infrastructure services. All data processing by Wix is governed by their privacy policy and aligned with GDPR requirements.
For more details, see: https://www.wix.com/about/privacy
Social Media
We operate LinkedIn profiles for communication and branding. LinkedIn may place cookies even for non-logged-in users. We process data from interactions (comments, messages) to respond to you based on Art. 6(1)(a) and (b) GDPR. More info: www.linkedin.com/legal/privacy-policy
Marketing Emails
We object to the use of our published contact details for unsolicited marketing. Legal action may be taken in case of violation.
Contact
If you have questions about our privacy practices, contact:
Markus Lohmann
Email: m.lohmann@lohmannexecutives.de