Skip to content
Norwell Partners
DEEN
CapabilitiesApproachAboutCareers
Let's Talk

Last updated: 2 October 2026

Privacy policy

Information about the processing of personal data when you visit our website or contact us.

1. Controller and contact details

Norwell Partners GmbH
Bahnhofstraße 17
82327 Tutzing
Germany
hallo@norwell-partners.com
Contact details are available in the Legal notice

You can also use those contact details for privacy questions and to exercise your rights.

2. Website provision

When you access our website, technically necessary connection data is processed. This includes in particular your IP address, the time and duration of access, the requested URL, HTTP status, volume of data transferred, and information supplied by your browser about the browser, operating system and, where applicable, the previously visited page. We use this data to deliver the website, analyse errors and defend against attacks. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the secure and reliable operation of the website.

We operate this website using Firebase App Hosting and Cloud Firestore, provided by Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland. The application and database are configured in europe-west4 (the Netherlands). Google processes data on our behalf under the Cloud Data Processing Addendum. Global CDN delivery, support and security operations may involve processing outside the European Economic Area.

Technical website and application logs are retained in the default log store for 30 days. Separate mandatory cloud administration and system audit logs maintained by Google are retained for 400 days. These support accountability and security of cloud operations, not visitor analytics. Where a specific security incident occurs, necessary information may be preserved separately for the duration of the investigation or legal proceedings.

Provider information: Privacy and Security in Firebase and Google Cloud Data Processing Addendum.

3. Contact form and email

When you contact us, we process the information you provide. The form requires your email address and message; your first name, last name and company are optional. We also record the time of the inquiry and the version identifier of the privacy notice displayed. This identifier is not evidence of consent or acknowledgement. Please do not send sensitive personal data or confidential documents that are unnecessary for an initial inquiry.

We process these details to assign, handle and respond to your inquiry. The legal basis is Article 6(1)(b) GDPR where the inquiry concerns a contract with you or pre-contractual steps taken at your request. For inquiries made as a company contact and other correspondence, we rely on Article 6(1)(f) GDPR. Our legitimate interest is appropriate business communication.

Providing your details is voluntary. Without the information marked as required, we cannot process the form. Alternatively, you can contact us by email. We do not automatically use your inquiry to add you to newsletters or advertising lists.

Contact form submissions are transmitted to our website server over an encrypted connection and stored in Cloud Firestore. Database access is server-side only; direct access by website visitors is blocked. We also store a submission identifier, a checksum to prevent duplicate submissions and delivery information. To prevent abuse, we use a value derived from the email address and a short sending cooldown. These data are not used for visitor statistics. The legal basis for abuse prevention and reliable delivery is Article 6(1)(f) GDPR. Information about the database service: Privacy and Security in Firebase.

The retention period for enquiries, delivery data and email copies depends on the purpose of the communication: until the enquiry has been fully handled, and beyond that only where ongoing business correspondence, a statutory retention obligation or the establishment, exercise or defence of legal claims requires it. The responsible staff arrange deletion once these grounds no longer apply. The deletion rule for statistics does not apply to enquiries and emails. Technical abuse-prevention data are required only for as long as they serve to protect against repeated abusive submissions.

Email notifications

Following a successful contact submission, we create an internal notification and an acknowledgement sent to your email address. The internal message contains your details; the acknowledgement contains an enquiry reference. Messages are sent through the info@norwell-partners.de mailbox at united-domains GmbH, Gautinger Straße 10, 82319 Starnberg, Germany. The internal notification is forwarded to Daniel Ottenberg’s business Microsoft mailbox. We use Microsoft 365/Exchange Online for further email correspondence. This involves processing senders, recipients, message contents and technical delivery data. The purposes, legal bases and retention criteria described in the contact form section also apply to this processing.

united-domains: Datenschutz / Privacy · Microsoft: Datenschutz / Privacy · Microsoft Data Protection Addendum

4. Job applications

You can send applications to hallo@norwell-partners.com. Application links open your own email application with an editable draft; a message is sent only when you choose to send it. We process your contact details, application documents and correspondence to conduct the recruitment process. The legal basis is in particular Section 26(1) of the German Federal Data Protection Act in conjunction with Article 88 GDPR. Access is limited to staff responsible for recruitment and service providers required for email communication.

If you are hired, the necessary data is transferred to personnel administration. Otherwise, we delete application data after the process is complete as soon as retention is no longer necessary to protect or defend legal claims. Inclusion in a talent pool requires separate, voluntary consent. Providing information is voluntary; without appropriate contact details and qualifications, we cannot assess your application.

5. Cookies, media and external services

We do not use advertising trackers, marketing cookies or embedded social media, map or video platforms. Our own website statistics are used only with your consent. Your decision is saved in local browser storage under norwell-statistics-choice; this entry contains no visitor identifier. After a successful login to the internal statistics area, the necessary nw_statistics_admin session cookie is set for one hour. Fonts are drawn from those available on your device. Images and the background video are delivered through our website hosting.

Strictly necessary storage on or access to your device is covered by section 25(2) TDDDG. Optional statistics require your prior consent under section 25(1) TDDDG and, where personal data is processed, Article 6(1)(a) GDPR.

External links initially serve only as references. When you open a link, the privacy information of the destination service applies. Opening an email link starts your email program; this alone does not send a message.

Optional website statistics

If you explicitly consent in the cookie banner, we count page views, clicks on links to the contact form and successfully stored enquiries. These statistics help us improve the website. We store only aggregated daily totals by page, language and event type in Cloud Firestore. Statistics do not contain visitor identifiers, browsing profiles, full referring URLs, URL parameters or form contents. Your IP address is technically processed during transmission but is not stored in the statistics counters. Hosting logs are covered by the website operation section.

Your choice and the version of the notice are saved in your browser’s local storage for 180 days without an individual visitor identifier. No statistics events are sent without consent. You may withdraw consent at any time with effect for the future via “Cookie settings” at the bottom of the page. The contact form and the rest of the website work regardless of your choice. When you submit an enquiry, any statistics consent is documented with the enquiry; the statistics themselves contain no reference to it.

Daily counters are retained for a 90-day reporting window and then removed by a deletion policy. Technical deletion may occur with a delay. Access to statistics is restricted to authorised people. Internal login sets a necessary session cookie lasting one hour. Statistics use the Firebase infrastructure described above; no additional analytics provider is integrated.

6. Recipients and processing in third countries

Only people and service providers who need access for the described purposes receive access to personal data. This includes website hosting, database operation and email communication. Authorities or advisers subject to professional confidentiality may also receive data where a legal obligation or another legal basis applies.

Google, Microsoft and their subprocessors may process data outside the EU and European Economic Area, particularly in the United States. Google is subject to the agreed data processing terms, including the transfer mechanisms specified in them. International transfers rely, where applicable, on adequacy decisions under Article 45 GDPR or appropriate safeguards under Article 46 GDPR, in particular EU Standard Contractual Clauses. A European server location alone does not exclude international processing. You can request information about the safeguards applicable to your data and a copy through our privacy contact.

7. Your rights

Subject to the legal requirements, you have the right to access your data and obtain a copy (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20). You may withdraw consent at any time with effect for the future; the lawfulness of processing before withdrawal remains unaffected.

Right to object: Where we process data on the basis of Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. We will then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or processing serves the establishment, exercise or defence of legal claims. You may object to direct marketing at any time without giving reasons.

To exercise your rights, please use the contact details in the Legal notice. You also have the right to complain to a data protection supervisory authority, in particular in the place of your habitual residence, workplace or the alleged infringement (Article 77 GDPR).

The supervisory authority for private companies based in Bavaria is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany; postal address: Postfach 1349, 91504 Ansbach, Germany. Contact details and complaint form: www.lda.bayern.de.

8. Automated decisions and security

We do not make decisions through this website based solely on automated processing that produce legal or similarly significant effects within the meaning of Article 22 GDPR. We do not carry out profiling for advertising purposes.

To protect data, we use encrypted transmission and restricted access to processing in particular. Despite appropriate safeguards, completely risk-free transmission over the internet is not possible. This information is updated when data processing or legal requirements change.

Start a conversation

Let's shape the future of Finance.

Contact Us
Norwell Partners

The transformation partner for the Office of the CFO.

Available for selected transformation mandates
ExploreCapabilitiesApproachPerspectives
CompanyAboutCareersContact
ConnectDaniel Ottenberg · LinkedIn Carsten Börner · LinkedIn Dr. Frank Müller · LinkedIn
NORWELL
© 2026 Norwell PartnersLegal noticePrivacy