Skip to main content

The Partners – Encouraging Responsibility.

Privacy Policy

The Partners Beratungsgesellschaft mbH

Last updated: 9 October 2026

This Privacy Policy explains when and for what purposes we process personal data, what data is concerned, to whom it is disclosed and what rights you have. Personal data means any information relating to an identified or identifiable natural person.

I. Scope

This Privacy Policy applies to our website www.thepartners.io and to the processing of personal data in connection with our consultancy services, client support and relationship management. It also covers communications with us, newsletters and events, applications and the activities on social platforms described below.

We process personal data in accordance with applicable data protection legislation, in particular the European Union General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). The storage of information on terminal equipment and access to information stored there are additionally governed by the German Telecommunications Digital Services Data Protection Act (TDDDG).

If you leave our website via an external link, the privacy information of the respective provider applies to the processing carried out there. The information below applies additionally to our own processing in connection with our social media presences.

You can access, print or download this Privacy Policy at any time at www.thepartners.io/datenschutz/.

II. Controller and contact details

The controller within the meaning of Art. 4(7) GDPR is:

The Partners Beratungsgesellschaft mbH
Rüsternallee 2
14050 Berlin
Telephone: +49 172 2957116
Email: post@thepartners.io

If you have any questions about the processing of your personal data or wish to exercise your data protection rights, please contact datenschutz@thepartners.io.

III. Processing of your personal data

1. Visiting our website

When you access our website, technically necessary data is processed so that we can provide the content, ensure functionality and protect our IT systems. This includes, in particular, your IP address, date and time of access, pages accessed, browser type and version, operating system and, where applicable, the previously visited page (referrer URL).

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in providing our website securely, reliably and without technical errors. Processing is limited to the data required for these purposes.

We use IONOS to host our website. This includes, in particular, the technically necessary processing of server and connection data in connection with operating the website.

Data transmitted via our website is protected by TLS encryption. Even with appropriate security measures, complete protection of electronic communications against access by third parties cannot be guaranteed.

Cookies and similar technologies: Our website does not currently use cookies or comparable technologies to store information on or access information from your device. Should we introduce such technologies in the future, we will update this Privacy Policy accordingly and, where legally required, obtain your consent before they are used.

2. Contact and dialogue forms, email and other communications

If you contact us via a contact or dialogue form, by email, telephone or by other means, we process the data you provide in order to deal with your enquiry and communicate with you. Depending on the means of contact, this may include, in particular, your name, company or organisation, position, email address, telephone number, postal address, the content of your message and any documents attached.

When forms are used, the date and time of submission and technically necessary data used to secure the operation of the form may also be processed. Information marked as mandatory is required in order to process your enquiry. We use interests and preferences communicated via the dialogue form to process your enquiry and manage the services you have requested.

The data may be stored in a CRM system used by us. Information on categories of recipients and service providers can be found in Section VI.

Where your enquiry concerns a contract with you or pre-contractual measures taken at your request, the legal basis is Art. 6(1)(b) GDPR. In other cases, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in efficiently handling enquiries, professional communication and maintaining business relationships. Where consent is obtained, the relevant processing is based on Art. 6(1)(a) GDPR.

If you communicate with us as an employee or contact person of a business partner, we process your professional contact details for the establishment, performance or termination of the business relationship on the basis of Art. 6(1)(f) GDPR.

Access is limited to persons and service providers who require the data for the relevant task. The data is deleted once the purpose no longer applies, unless statutory retention obligations or other lawful grounds require further storage.

3. Social media presences and external platforms

We maintain company profiles on social platforms, in particular LinkedIn and, where applicable, X, in order to provide information about The Partners, our services, events and vacancies and to communicate with interested parties.

In this context, we process data that you provide to us, make publicly available in relation to our profiles or that the respective platform operator makes available to us. This may include profile names, professional information, messages, posts, comments, reactions and statistical information about interactions.

Our processing serves communication, the handling of enquiries and the presentation and further development of our services. The legal basis is Art. 6(1)(f) GDPR. Where communication serves a contract with you or pre-contractual measures, Art. 6(1)(b) GDPR applies. Any consent obtained forms the basis for processing under Art. 6(1)(a) GDPR.

Platform operators also process data for their own purposes, for example to provide their services, analyse usage and provide advertising. We have only limited influence over this processing. Data may be linked to an existing user account and processed outside the EU or the European Economic Area. Information about such processing, retention periods and settings can be found in the privacy information of the respective platform.

For certain statistical functions, joint controllership with the platform operator may apply. The respective agreements and information describe the allocation of responsibilities. You may exercise your rights against the respective controller; we will support you with enquiries insofar as they concern our processing.

LinkedIn: privacy information at https://www.linkedin.com/legal/privacy-policy; information on page statistics and joint controllership at https://www.linkedin.com/legal/l/page-joint-controller-addendum.

X: privacy information at https://x.com/en/privacy.

With simple links to social platforms, data is generally transferred to their operators only when you click the link. Where active social media elements are embedded on our website, elements requiring consent may only be activated after you have given your consent. The legal bases are Art. 6(1)(a) GDPR and, where applicable, Section 25(1) TDDDG. Please also see Section VII.

Confidential information should be sent to us via our direct communication channels.

4. Professional contacts, political contacts and relationship management for our clients

For our political and strategic communications consultancy, we process professional contact details of relevant contacts in politics, business and society. We obtain this data in particular directly from the persons concerned, through professional encounters, from publicly accessible sources such as institutional websites or from databases operated by Kürschners Politikkontakte NDV GmbH & Co. KG.

We process, in particular, names, professional roles, institutional affiliations and professional postal addresses, telephone numbers and email addresses. The data is used to identify appropriate contacts, maintain professional relationships, facilitate subject-specific dialogue and support our clients with their communications objectives.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest and, where applicable, that of our clients lies in providing informed consultancy, maintaining professional relationships and communicating appropriately with relevant contacts. In doing so, we take account of the professional context, the reasonable expectations of the individuals concerned, the source of the data and the necessity of the respective contact. Processing is limited to the data required for the specific purpose.

Where necessary for a consultancy engagement and legally permissible, we may disclose relevant professional contact details to our clients. Any further use or disclosure requires a separate legal basis. Information concerning political opinions within the meaning of Art. 9 GDPR is not covered by this legal basis for ordinary professional contact data.

Lobby Register: Where we are required to provide information under the German Lobby Register Act (LobbyRG), we process and transmit the personal data required for this purpose to the body maintaining the register at the German Bundestag. This relates exclusively to information required by law and may include, in particular, details of persons authorised to represent an organisation or engaged in lobbying activities and – where lobbying is carried out on behalf of third parties – information on clients and persons deployed. Processing is carried out to comply with our legal obligations on the basis of Art. 6(1)(c) GDPR in conjunction with the Lobby Register Act. Information is published only to the extent required by law; information exempt from publication by law is not made publicly available.

Where we do not collect data directly from you, we provide information in accordance with Art. 14 GDPR, in particular on the categories and sources of data, generally no later than one month after obtaining the data, or, where communication takes place earlier, at the time of first contact, or, where disclosure takes place earlier, at the time of first disclosure, unless a statutory exemption applies.

You may object to processing on grounds relating to your particular situation. The unrestricted right to object to direct marketing applies in accordance with Section V. The permissibility of promotional contact is assessed separately; the mere storage of professional contact details does not justify sending promotional emails.

5. Client and business relationships

If you enter into a contract with us as a natural person, we process the data required to establish and perform the contract on the basis of Art. 6(1)(b) GDPR. This includes, in particular, contact, contractual, service, communication and billing data.

If you are the contact person for a company or organisation, we process your professional data on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in establishing and conducting the business relationship and communicating with the relevant contacts.

To comply with legal obligations, in particular commercial and tax-law documentation and retention requirements, processing is based on Art. 6(1)(c) GDPR. Processing required for the establishment, exercise or defence of legal claims is based on Art. 6(1)(f) GDPR.

6. Newsletters and events

a) Newsletters, information and event invitations

If you subscribe to our newsletter and event information, we process your email address and, where applicable, your name, organisation, position and the topic preferences you provide. We use this data, within the scope of your consent, to send you information about The Partners, our topics, services and events, as well as invitations to digital or in-person events.

Processing for sending these communications is based on your consent under Art. 6(1)(a) GDPR. For promotional emails, we also comply with Section 7 of the German Unfair Competition Act (UWG). Where, exceptionally, sending without consent is permissible under the conditions of Section 7(3) UWG, the data protection basis for processing is Art. 6(1)(f) GDPR; our legitimate interest in that case is to inform existing clients about our own similar services.

Where registration takes place via the website, it is confirmed using a double opt-in procedure. You will receive an email containing a confirmation link. To document registration and consent, the time, content and confirmation of the registration and the IP address transmitted in the process may be stored. The necessary evidence is retained to comply with legal obligations under Art. 6(1)(c) GDPR or to prevent misuse and defend legal claims under Art. 6(1)(f) GDPR.

You may withdraw your consent at any time with effect for the future, for example via the unsubscribe link in the relevant message or by contacting datenschutz@thepartners.io. The lawfulness of processing carried out before withdrawal remains unaffected. You may also object to direct marketing at any time.

After unsubscribing, your data will no longer be used for the relevant mailing. Necessary evidence of consent and a suppression record limited to what is necessary may be retained insofar as this is required to comply with legal obligations, defend against claims or respect your opt-out. Data that we lawfully require for other purposes remains unaffected.

b) Registration for and organisation of events

If you register for or attend an event, we process the data required to organise and conduct it. This includes, in particular, your name, contact details, organisation and position, the selected event, registration status and, where applicable, billing-related information.

We use this data to process the registration, plan and conduct the event, issue confirmations of attendance and send necessary organisational communications, such as information about the venue, time, access or last-minute changes.

Where processing is necessary to perform an attendance agreement or pre-contractual measures taken at your request, the legal basis is Art. 6(1)(b) GDPR. In other cases, Art. 6(1)(f) GDPR applies. Our legitimate interest lies in the proper organisation and conduct of the event. We process legally required billing and documentation data on the basis of Art. 6(1)(c) GDPR.

Data is disclosed to event, technical or organisational service providers and, where applicable, co-organisers only insofar as this is necessary for the relevant event and legally permissible. Where necessary, we provide additional information at registration about event-specific recipients and their roles.

Registration for an event does not automatically result in inclusion in a newsletter or general invitation mailing list. Separate consent or another applicable statutory permission is required for this.

The data is deleted after the event and the related follow-up have been completed, once it is no longer required and no statutory retention obligations or other lawful grounds for storage apply. If photographs, video or audio recordings, publication of participant lists or special participation information are envisaged, you will receive separate information in advance about the respective processing and legal basis.

7. Digital meetings and events

We use Microsoft Teams for digital meetings, business collaboration and, where applicable, digital events. In this context, user information such as name and email address, connection and communication data such as IP address, time and meeting identifier, as well as chat, audio, video and file content provided by you may be processed.

As a rule, you can decide for yourself whether to activate your camera or microphone and whether to share content. Other participants can see or hear content and contributions you make available. Recordings require a separate assessment and prior information about purpose, legal basis, recipients and retention period; any consent required will be obtained before a recording is made.

The legal basis depends on the purpose of the communication: Art. 6(1)(b) GDPR for contractual or pre-contractual measures, Art. 6(1)(f) GDPR for our legitimate interest in efficient business communication and, where applicable, Art. 6(1)(a) GDPR where consent is given.

Information about data processing by Microsoft is available at https://privacy.microsoft.com/en-gb/privacystatement. Section VII applies to possible transfers to third countries.

8. Use of artificial intelligence

Where we use artificial intelligence (AI) to support our work, we comply with the relevant requirements of the GDPR, the BDSG and the European AI Act (Regulation (EU) 2024/1689), depending on the particular use case and their applicability. In particular, guidance issued by the German data protection supervisory authorities on the data-protection-compliant use of AI serves as professional guidance. The following standards apply to our use of AI:

Purpose limitation and data minimisation: Personal data is processed only for specified, lawful purposes and to the extent necessary. Before data is entered, we assess whether the purpose can be achieved using anonymised data or without personal data. Pseudonymised data continues to constitute personal data.

Confidentiality: Client information, trade secrets and personal data may be entered only into applications approved for the specific purpose. Entry into publicly accessible AI services without appropriate contractual and technical safeguards is excluded. Special categories of personal data additionally require a legal basis under Art. 9 GDPR.

Vetted providers and safeguards: Before use, we assess in particular privacy terms, processing purposes, allocation of roles, storage and deletion rules, access rights and possible transfers to third countries. Where processing is carried out on our behalf, a data processing agreement under Art. 28 GDPR is required. Transfers to third countries must meet the requirements of Arts. 44 et seq. GDPR. Safeguards are determined according to the risk of the processing.

No uncontrolled use for training: Personal data and confidential client content are not released for a provider’s general model training. For such content, we use only services and settings that contractually and technically exclude such training use.

Human oversight: AI supports our work. Responsibility for consultancy, decisions and approved work products remains with the responsible persons. Before use, AI outputs are appropriately reviewed for factual accuracy, potential bias, data protection and third-party rights. Decisions producing legal effects or similarly significant adverse effects are not made solely by automated means.

Transparency and data subject rights: Where personal data is processed in a specific AI use case, we provide information about purposes, categories of data, legal bases, recipients and retention periods in accordance with Art. 13 or Art. 14 GDPR. Applicable information and labelling obligations under the AI Act are observed. The exercise of data protection rights must also be ensured when AI is used.

Competence and risk assessment: Staff who use AI are informed and trained, in line with their responsibilities, about its capabilities, limitations and risks. Before use, we assess whether additional requirements under the AI Act or a data protection impact assessment under Art. 35 GDPR are required. Applications are used only where the applicable requirements are met.

The use of AI does not in itself create a legal basis for processing personal data. The legal basis depends on the specific purpose, for example Art. 6(1)(b) GDPR for necessary contractual services, Art. 6(1)(f) GDPR following a balancing of interests or Art. 6(1)(a) GDPR where valid consent has been obtained. Information on AI services actually used and their specific processing activities will be provided additionally where required.

IV. Retention periods

We store personal data only for as long as is necessary for the respective purposes. Once the purpose no longer applies, we delete the data unless statutory retention obligations or other lawful grounds require further storage.

Further grounds for retention may include, in particular, obligations under commercial or tax law and the establishment, exercise or defence of legal claims within the applicable limitation periods. Where necessary, processing is restricted to the permitted retention purposes. Specific information on newsletter, event and application data can be found in the respective sections.

V. Your rights

Subject to the applicable statutory requirements, you have the following rights:

  • Access to your personal data and information about its processing under Art. 15 GDPR.
  • Rectification of inaccurate data and completion of incomplete data under Art. 16 GDPR.
  • Erasure of your data under Art. 17 GDPR.
  • Restriction of processing under Art. 18 GDPR.
  • Data portability under Art. 20 GDPR, where processing is based on consent or a contract and is carried out by automated means.
  • Withdrawal of consent at any time with effect for the future under Art. 7(3) GDPR. The lawfulness of processing carried out before withdrawal remains unaffected.
  • The right to lodge a complaint with a data protection supervisory authority under Art. 77 GDPR, in particular in the place of your habitual residence, place of work or place of the alleged infringement.

Right to object under Art. 21 GDPR: Where we process data on the basis of Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then cease processing the data unless we demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing is required for the establishment, exercise or defence of legal claims.

Objection to direct marketing: You may object at any time, without giving reasons, to the processing of your data for direct marketing purposes. This also applies to profiling related to such direct marketing. The data will then no longer be processed for these purposes.

To exercise your rights, please contact datenschutz@thepartners.io. We process the data required to handle your request, in particular on the basis of Art. 6(1)(c) GDPR. Where necessary, we may request information to confirm your identity.

In accordance with Art. 19 GDPR, we communicate rectifications, erasures and restrictions to recipients to whom we have disclosed your data, unless this proves impossible or involves disproportionate effort. On request, we will inform you about those recipients.

The supervisory authority responsible for us is:

Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61
10555 Berlin
Telephone: +49 30 13889-0
Email: mailbox@datenschutz-berlin.de
Website: https://www.datenschutz-berlin.de

VI. Recipients and service providers

Personal data is disclosed only where legally permissible, in particular for the performance of a contract, on the basis of consent, to comply with legal obligations or to pursue legitimate interests while respecting your rights.

Recipients may include, in particular, IT and hosting service providers, providers of CRM and communication systems, event service providers, our clients where necessary, legal or tax advisers and competent authorities. Access within The Partners is restricted to persons who require the data for the relevant task.

Where external service providers process personal data on our behalf, this is carried out on the basis of data processing agreements pursuant to Art. 28 GDPR. When selecting and engaging service providers, we ensure that the required data protection agreements are in place and that appropriate technical and organisational measures are provided for. Where a provider acts as an independent or joint controller, the respective statutory requirements apply.

VII. Transfers to third countries

When external services are used, in particular social platforms or internationally operating IT service providers, personal data may be processed outside the EU or the European Economic Area. A European storage location does not automatically exclude possible access from third countries.

Where a transfer to a third country takes place, we comply with the requirements of Arts. 44 et seq. GDPR. A transfer may in particular be based on an adequacy decision by the European Commission under Art. 45 GDPR or appropriate safeguards under Art. 46 GDPR, such as EU Standard Contractual Clauses and any necessary supplementary measures. Derogations under Art. 49 GDPR apply only under the conditions set out there.

For transfers to US companies, the EU-U.S. Data Privacy Framework may be relied upon only where a relevant adequacy decision applies and the specific recipient holds a valid certification for the relevant processing. Information on certification is available at https://www.dataprivacyframework.gov/list.

Information about the safeguards used in each case and, where applicable, a copy may be requested via the data protection contact in Section II.

VIII. Applications and candidate data

1. Applications to The Partners

If you apply to us, we process the data you provide as part of the application process. This includes, in particular, your name, contact details, application documents, information about education, qualifications and professional experience, and information from interviews.

We process this data to conduct the application procedure and decide whether to establish an employment relationship. The legal basis is Section 26(1) BDSG, where applicable in conjunction with Art. 6(1)(b) GDPR. Where processing is based on voluntary consent, Art. 6(1)(a) GDPR and, where applicable, Section 26(2) BDSG apply. Special categories of personal data additionally require a condition under Art. 9(2) GDPR.

Please provide only information required for the application. Information about marital status, children or bank details is not required for an ordinary application.

Access to application data is limited to persons involved in processing and deciding on the application, as well as necessary technical service providers subject to the applicable data protection requirements.

If an employment relationship is established, the data required for that purpose will continue to be processed for the performance of the employment relationship. Otherwise, we generally delete application data no later than six months after completion of the application procedure. Longer retention takes place only where legal obligations apply, the data is required for the establishment, exercise or defence of legal claims, or you have expressly consented.

Inclusion in a candidate pool takes place only on the basis of separate, voluntary consent. You may withdraw this consent at any time with effect for the future. Data in the candidate pool is deleted no later than two years after consent is given, unless another lawful basis justifies further retention.

2. Executive search and recruitment on behalf of clients

Where The Partners approaches or places suitable individuals for positions on behalf of clients, we process the professional contact, qualification and career-history data required for this purpose. Data may come directly from you, from professional networks, publicly accessible professional sources or recommendations.

The legal basis depends on the specific process. A placement requested by you or a pre-contractual measure may be based on Art. 6(1)(b) GDPR. Identifying and making a relevant approach to professional candidates may, following an assessment of interests and expectations, be based on Art. 6(1)(f) GDPR. Where consent is required, we obtain it under Art. 6(1)(a) GDPR.

Before disclosing application documents or confidential candidate profiles to a client, we clarify with you the specific purpose and applicable legal basis. We provide additional information in the specific process about clients, recipients, responsibilities, data sources and retention periods. The information obligations under Art. 13 and Art. 14 GDPR remain unaffected.

Joint controllership with a client is not assumed as a matter of course. It must be assessed on the basis of the actual allocation of responsibilities and, where applicable, regulated in accordance with Art. 26 GDPR.

IX. Provision of data and automated decision-making

Providing personal data is generally voluntary. Certain information may be required to process your enquiry, enter into or perform a contract, participate in an event or take part in an application process. Without this information, we may not be able to provide the relevant service. Statutory obligations to provide data remain unaffected.

No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.

X. Amendments to this Privacy Policy

The further development of our website and services, as well as changes to legal or regulatory requirements, may make amendments to this Privacy Policy necessary. The current version is available at www.thepartners.io/datenschutz/.