Privacy Policy
How 3K Investment Office GmbH collects, processes, and protects your personal data.
1. Controller
The data controller responsible for the processing of your personal data is:
3K Investment Office GmbH
Lierstraße 25
80639 München
Deutschland
Email: support@3kinvestment.org
Phone: +49 157 92813343
2. Scope of this Policy
This Privacy Policy explains how we collect, use, store, and protect personal data when you visit our website at 3kinvestment.org or contact us directly. It applies to all data processing activities carried out by 3K Investment Office GmbH as data controller.
3. Data We Collect
We may collect the following categories of personal data:
- Identification data: name, company name
- Contact data: email address, telephone number, postal address
- Communication data: messages sent via our contact form or by email
- Technical data: IP address, browser type, operating system, referring URL, pages visited, and timestamps — collected automatically when you visit our website
- Cookie data: as described in our Cookie Policy
4. Legal Basis for Processing
We process your personal data on the following legal bases under the General Data Protection Regulation (GDPR):
- Article 6(1)(a) GDPR — Consent: where you have given explicit consent, such as by completing our contact form
- Article 6(1)(b) GDPR — Contractual necessity: where processing is necessary for the performance of a contract or pre-contractual steps at your request
- Article 6(1)(c) GDPR — Legal obligation: where processing is required to comply with applicable law
- Article 6(1)(f) GDPR — Legitimate interests: for the operation of our website and security purposes, where such interests are not overridden by your rights
5. Purposes of Processing
We use your personal data for the following purposes:
- To respond to enquiries submitted via the contact form or by email
- To provide the services described on our website
- To comply with legal and regulatory obligations applicable to investment service providers
- To operate, maintain, and improve our website
- To analyse anonymous website usage for performance monitoring
6. Retention Periods
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, and in accordance with applicable legal retention requirements. In general:
- Contact form submissions and correspondence: retained for up to 3 years following the end of the relevant enquiry or engagement, unless a longer period is required by law
- Technical log data: retained for a maximum of 30 days unless required for security investigation
- Client-related financial records: retained for a minimum of 10 years in accordance with German commercial and tax law requirements
7. Disclosure to Third Parties
We do not sell, rent, or otherwise transfer your personal data to third parties for marketing or commercial purposes. We may share personal data in the following limited circumstances:
- With service providers acting as data processors (e.g. hosting providers, IT support) under appropriate data processing agreements
- Where required by law, court order, or regulatory authority
- With regulators such as BaFin where required by applicable financial services legislation
8. International Transfers
Where personal data is transferred outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR, including the use of standard contractual clauses approved by the European Commission.
9. Your Rights
Under applicable data protection law, you have the following rights with respect to your personal data:
- Right of access (Article 15 GDPR): to obtain a copy of the personal data we hold about you
- Right to rectification (Article 16 GDPR): to request correction of inaccurate or incomplete data
- Right to erasure (Article 17 GDPR): to request deletion of your personal data in certain circumstances
- Right to restriction of processing (Article 18 GDPR): to request that we limit how we use your data
- Right to data portability (Article 20 GDPR): to receive your data in a structured, commonly used format
- Right to object (Article 21 GDPR): to object to processing based on legitimate interests
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing
To exercise any of these rights, please contact us at support@3kinvestment.org. We will respond within one month as required by applicable law.
10. Right to Lodge a Complaint
If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority. In Bavaria, Germany, this is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 27, 91522 Ansbach.
11. Website Security
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. Our website uses TLS encryption to protect data in transit.
12. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The current version will always be published on this page with the date of the last update. We encourage you to review this policy periodically.
13. Contact
For any questions regarding this Privacy Policy or our data processing practices, please contact us at:
3K Investment Office GmbH
Lierstraße 25
80639 München
Deutschland
Email: support@3kinvestment.org
Phone: +49 157 92813343