top of page

Privacy Policy

1. About this Privacy Policy

 

Advokatur GTK Ltd, Klybeckstrasse 141, CH-4057 Basel, Switzerland ("Advokatur GTK", "we", "us") operates the website www.swisslitigationcounsel.com (the "Website"). This Privacy Policy explains how we collect, use, and protect personal data when you visit the Website, contact us, or otherwise interact with our firm.

 

This Privacy Policy is governed primarily by the Swiss Federal Act on Data Protection (FADP). To the extent that the EU General Data Protection Regulation (GDPR) or the UK General Data Protection Regulation (UK GDPR) applies to specific processing activities — for instance, when you visit the Website from the European Union or the United Kingdom — we recognise and honour the rights granted under those regulations as described in Section 9.

If you provide us with personal data about third parties (e.g. family members, business contacts, counterparties), we assume that you are authorised to do so and that the data is accurate. Please ensure that those individuals are informed of this disclosure where required by law.

2. Controller

The controller for the processing of your personal data under this Privacy Policy is:

Advokatur GTK Ltd Klybeckstrasse 141 CH-4057 Basel Switzerland

Privacy contact: privacy@advokatur-gtk.ch

3. Personal data we process

We process personal data for the following purposes:

 

Communication. When you contact us by email, telephone, WhatsApp Business, or other channels, we process the content of your message together with metadata (sender, time, channel). For mandate-related correspondence, we use Protonmail (Proton AG, Switzerland), which provides Swiss-based hosting. Where both sender and recipient use Protonmail, communication is end-to-end encrypted; in other cases, encryption is limited to transport-layer security (TLS) and the content of the message resides on the servers of the parties involved.

Mandate initiation and execution. Before accepting a mandate, we collect data necessary to assess conflicts of interest, including names, contact details, the identity of involved parties, and a description of the matter. During the mandate, we process all data necessary for legal representation: correspondence, contract documents, submissions to courts and authorities, evidence, financial records, and information obtained from public sources or third parties (e.g. commercial registers, credit agencies, public authorities, courts, counterparties, the media).

Website operation. When you visit the Website, our hosting provider Wix (see Section 5) automatically collects technical data including IP address, browser type, operating system, referring page, date and time of access. This data is used to deliver the Website, ensure its security, and analyse aggregated usage patterns.

Website analytics and advertising measurement. Subject to your consent, we use Google Analytics 4 and Google Ads to measure how visitors find and use our Website (see Section 7).

Compliance. We process personal data to comply with our legal obligations as a Swiss law firm, including anti-money-laundering checks, tax requirements, and professional conduct rules.

LinkedIn presence. We operate a LinkedIn profile for the firm. Data processed by LinkedIn when you visit or interact with our profile is governed primarily by LinkedIn's own privacy policy (see Section 8).

4. Sources of personal data

We obtain personal data primarily from you (when you contact us, visit the Website, or instruct us) and, where necessary, from publicly available sources (commercial registers, debt-enforcement registers, court records, media, the internet) and from third parties (your employer or client, opposing parties, courts, public authorities, correspondent law firms, credit reference agencies, service providers).

You are not obliged to provide personal data. However, certain interactions (e.g. instructing us as your lawyer) require disclosure of specific data; where this is the case, we will indicate it.

5. Service providers and recipients of personal data

We rely on the following categories of service providers and recipients:

File storage and document exchange. Mandate documents and files exchanged with clients are stored and shared via Tresorit (Tresorit AG, Switzerland), an end-to-end encrypted, zero-knowledge cloud storage service. Files are encrypted on the user's device before upload; Tresorit does not have technical access to the unencrypted content. Tresorit is headquartered in Switzerland and, as a Swiss company, is not subject to the US CLOUD Act. Data centre location for our account: EU or Switzerland. Further information: https://tresorit.com/legal/privacy-policy

Email infrastructure. Mandate-related email is hosted by Proton AG (Switzerland). Server infrastructure is located in Switzerland. Further information: https://proton.me/legal/privacy

Hosting and website infrastructure. The Website is hosted by Wix.com Ltd (Israel), which may process data through its global infrastructure including data centres in the United States, Ireland, South Korea, Taiwan, and Israel. Wix's selection of data centre is automatic and cannot be restricted by us. Where personal data is transferred to countries without an adequacy decision under Swiss or EU law, Wix relies on Standard Contractual Clauses and equivalent safeguards. Further information: https://www.wix.com/about/privacy

Google services (subject to consent). With your consent, we use Google Tag Manager, Google Analytics 4, and Google Ads provided by Google Ireland Limited. Data may be transferred to Google LLC in the United States, which is certified under the EU-US Data Privacy Framework. Further information: https://policies.google.com/privacy

Clients, counterparties, courts, and authorities. In the course of representing our clients, we routinely share personal data with the parties involved in the matter, including opposing parties, their counsel, courts, and authorities in Switzerland and abroad.

Other service providers. This includes accountants, banks, IT providers, debt-collection agencies, and credit reference agencies, where the engagement of such third parties is necessary for our operations. All service providers processing personal data on our behalf are bound by contractual obligations to handle the data in accordance with applicable data protection law.

6. International data transfers

The nature of our practice — representing clients in matters with international dimensions — means that personal data is regularly transferred internationally, including to countries that do not provide a level of data protection equivalent to Swiss or EU standards. Where we rely on service providers (Section 5), we ensure adequate safeguards through Standard Contractual Clauses, the EU-US Data Privacy Framework (where applicable), or recognised adequacy decisions.

Where data is transferred in the context of legal proceedings, the recipients (foreign courts, authorities, opposing parties, correspondent counsel) act under their own responsibility and are not bound by our processing instructions.

7. Cookies, tracking technologies, and advertising

The Website uses cookies and similar technologies to operate, secure, and analyse the Website, and to measure the effectiveness of our online advertising. Strictly necessary cookies are used without your consent; all other cookies require your consent, which you can provide or withhold through our cookie banner.

The following providers are used subject to your consent:

 

Google Tag Manager (Google Ireland Limited). Loads and manages the measurement tags listed below. Privacy policy: https://policies.google.com/privacy

 

Google Analytics 4 (Google Ireland Limited). Measures Website usage. Data is retained for 14 months. Privacy policy: https://policies.google.com/privacy

 

Google Ads (Google Ireland Limited). Measures the effectiveness of our advertising campaigns, including conversion tracking and (where activated) remarketing. Privacy policy: https://policies.google.com/privacy

 

We use Google Consent Mode v2. If you reject cookies, no identifying data is sent to Google. Limited anonymised signals (without personal identifiers) may still be transmitted to Google for statistical modelling. These signals do not allow your identification.

 

You can change or withdraw your consent at any time through the cookie settings link in the Website footer.

8. Social media

We operate a LinkedIn profile (https://www.linkedin.com/) for the firm. When you visit our profile or interact with our content, LinkedIn processes your data under its own responsibility. We have access only to aggregated statistics provided by LinkedIn. For information on LinkedIn's processing of your data, please refer to: https://www.linkedin.com/legal/privacy-policy

9. Your rights

Subject to the conditions and limitations of applicable law, you have the right to:

  • request information about whether and how we process your personal data;

  • request correction of inaccurate personal data;

  • request deletion of your personal data;

  • object to specific processing activities;

  • request transfer of your personal data in a structured, machine-readable format;

  • withdraw consent at any time, with effect for future processing;

  • lodge a complaint with the competent data protection supervisory authority.

In Switzerland, the competent authority is the Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch). In the European Union, you may contact the supervisory authority of your country of residence; in the United Kingdom, the Information Commissioner's Office (ICO, www.ico.org.uk).

Please note that our obligations of professional confidentiality (Art. 13 of the Swiss Federal Act on the Free Movement of Lawyers, BGFA) may restrict your rights in relation to data we process in the course of legal representation. In addition, certain documents and records are subject to mandatory retention obligations and cannot be deleted on request.

To exercise your rights, please contact us at privacy@advokatur-gtk.ch. To prevent unauthorised access, we may ask you to verify your identity.

10. Retention

We retain personal data for as long as is necessary for the purposes for which it was collected, or as required by law. In particular:

  • Mandate-related files: 10 years after the conclusion of the mandate, in accordance with Article 12 of the Swiss Federal Act on the Free Movement of Lawyers (BGFA) and applicable retention obligations.

  • Accounting records: 10 years, in accordance with Article 958f of the Swiss Code of Obligations.

  • Website analytics data: 14 months.

  • Communication data outside of an active mandate: until the purpose of the communication is fulfilled or longer if required by law.

11. Legal basis for processing

Where the GDPR or UK GDPR applies, we process personal data on the following legal bases:

  • Contract (Art. 6(1)(b) GDPR): processing necessary to enter into or perform a mandate or other contract with you.

  • Legal obligation (Art. 6(1)(c) GDPR): processing necessary to comply with Swiss legal obligations, professional duties, anti-money-laundering rules, and tax obligations.

  • Legitimate interest (Art. 6(1)(f) GDPR): operating and securing the Website, defending legal claims, conducting business administration, and improving our services.

  • Consent (Art. 6(1)(a) GDPR): for cookies and tracking technologies that are not strictly necessary, as well as for any other processing for which we explicitly request your consent.

Under Swiss law, our primary legal basis is the existence of a legitimate purpose and the principle of proportionality (Art. 6 FADP), supplemented by your consent where required.

12. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, and destruction. These measures include encrypted email infrastructure (Protonmail, Switzerland), end-to-end encrypted document storage (Tresorit, Switzerland), HTTPS encryption for the Website, restricted access controls, and routine security audits of our infrastructure. Despite these measures, no system can guarantee absolute security; we therefore recommend that you do not transmit highly confidential information through unencrypted channels.

13. Changes to this Privacy Policy

This Privacy Policy is not part of any contract with you and may be updated at any time. The version published on the Website at the time of your visit is the version that applies. Material changes will be highlighted with an updated "Last updated" date at the top of this document.

Last updated: 20 May 2026

bottom of page