Privacy Policy

Information about the Processing of Personal Data
This privacy policy describes how we collect, use and share your personal data when you use our website. In doing so, we inform you about our processing operations and fulfill our legal obligations, in particular those arising from the EU General Data Protection Regulation (GDPR).
Personal data is all data that can be related to you personally, e.g. name, e-mail address, your health information and user behavior.
The data controller pursuant to Art. 4 (7) GDPR is Soofia UG(haftungsbeschränkt), Glogauer Strasse 11a, 10999 Berlin, Germany, info@soofia.co (see our imprint) (also referred to as “we”, “us” or “our”).
We may use carefully selected and monitored service providers for certain functions of our offer or we may use your data for advertising purposes. If this is the case, we will inform you in detail below about the processes involved, including the specified storage period.
Your Rights
You have the following rights towards us regarding personal data concerning you:
  • right to information (Art. 15 GDPR),
  • right to rectification (Art. 16 GDPR),
  • right to erasure (Art. 17 GDPR),
  • right to restriction of processing (Art. 18 GDPR),
  • right to data portability (Art 20 GDPR),
  • right to object against automated processing (Art. 21 GDPR),
  • right to withdraw the data protection consent declaration, and
  • right to complain to a data protection supervisory authority about our processing of your personal data.
Processing of Personal Data when Visiting our Website
If you visit our website for informational purposes only, i.e. if you visit our website without registering or otherwise providing us with information, we automatically collect the following personal data that your browser transmits to our server:
  • Your IP address,
  • date and time of the access,
  • time zone difference from Greenwich Mean Time (GMT),
  • web pages accessed by your system through our website,
  • access status/HTTP status code,
  • data volume transferred in each case,
  • web pages from which your system accessed our website,
  • browser type as well as the version and language used, and
  • your operating system.
These data are technically necessary to display our website to you and to ensure the stability and security of the system.
The legal basis for the processing of the aforementioned data is Art. 6 (1) sentence 1 lit. f GDPR. Our legitimate interest lies in providing a functional and secure website.
The data will be deleted as soon as they are no longer required to fulfill the purpose of their collection, but no later than after seven days.
Data Security
We use appropriate technical and organizational measures to protect your data from manipulation, loss, destruction or unauthorized access. In doing so, we take into account the state of the art, the implementation costs and the nature, scope, context and purpose of the processing. In addition, we regularly assess the risks of a possible data breach, including its probability and impact. Our security measures are continuously adapted to technological progress.
Objection or Withdrawal of Consent to Processing your Personal Data
If you have consented to the processing of your data, you may withdraw this consent at any time. The withdrawal applies from the time at which you notify us of it and concerns the future processing of your data. The permissibility of the processing of your data up to the time of your withdrawal remains unaffected.
If we base the processing of your personal data on a balancing of interests, you may object to the processing. We will in particular undertake a balancing of interests if we process your data in the public interest or based on our legitimate interests. When objecting against the processing, please provide us with the reasons for your objection as to why you reject the processing of your data in the previous form. We will review your objection and will either discontinue or adjust the processing, or explain to you our compelling legitimate reasons that justify the continuation of the processing.
You may object to the processing of your personal data for purposes of advertising and data analysis at any time.
Please contact us at info@soofia.co for any withdrawals or objections.
Storage Periods of Your Personal Data
We only store your personal data for as long as is necessary to fulfill the purposes we collected it for. This includes the fulfillment of legal, tax and accounting obligations. When determining the storage period, we take into account the scope, type and sensitivity of the data, the potential risk of unauthorized use or disclosure, the purposes of the processing, whether we can achieve these purposes by other means and applicable legal requirements.
In some circumstances we may anonymize your personal data so that it can no longer be associated with you, in which case we may use such information without further notice to you.
If you have any questions on the way we retain your personal data you can contact us via the contact details provided above.
Other Functions and Offers on our Website
In addition to the use of our website for informational purposes, we offer various services and features that you can use if you are interested and that we describe in detail below. In doing so, we also use analysis and marketing functions, which we will also explain in more detail below. Usually, you will need to provide additional personal data for this, which we process in order to provide these services. All principles described above apply to these data processings.
In some cases, we use external service providers to process your data. These are carefully selected by us, are bound by our instructions and are regularly monitored.
Furthermore, we may pass on your personal data to third parties if we provide services together with partners. Depending on the service, the partners may also collect your data on their own responsibility. You will receive more information when you provide your data or below in the description of the respective offers.
If our service providers or partners are based in a country outside the European Economic Area (EEA), we will inform you about the consequences of this circumstance in the relevant offer description below.
Use of Cookies
General: In addition to the data already mentioned, we use technical aids such as cookies, which are stored on your end device. When you visit our website and also thereafter, you have the choice of whether you want to allow cookies in general or select individual functions. You can adjust these settings via your browser or our cookie consent manager.
What are cookies? Cookies are small text files or database entries that are stored on your computer system. They contain a characteristic string of characters that enables your browser to be clearly identified when you return to the website. Cookies cannot execute programs or transmit viruses. Their main purpose is to make our website faster and more user-friendly. In the following, we explain the different types of cookies we use, how they work, how long they are stored for and the corresponding legal basis.
Necessary cookies: We use necessary cookies for the technical operation of our website. Without these, the website cannot be displayed completely or correctly, and certain support functions would not be available. These cookies are usually temporary cookies (see below for an explanation of this term). These cookies cannot be deselected if you wish to use our website. You can find an overview of these cookies in the cookie consent manager. The legal basis for this processing is Art. 6 (1) sentence 1 lit. f GDPR.
Optional cookies: We only set these cookies after you have given your consent, which you can do on your first visit to our website using the cookie consent manager. They enable us to analyze and improve the use of the website, to facilitate operation across different browsers and devices, to recognize you when you visit again, or to place advertisements that are tailored to your interests and to measure their effectiveness. The legal basis for this processing is Art. 6 (1) sentence 1 lit. a GDPR. You can revoke your consent at any time.
Storage period: The storage period depends on whether the cookies are temporary or persistent (permanent).
Temporary cookies: These cookies, in particular so-called session cookies, are automatically deleted when you close your browser or log out. They contain a so-called session ID. This allows various requests from your browser to be assigned to the same session, and your computer to be recognized when you return to our website.
Persistent cookies: These are automatically deleted after a specified period, which is set differently for each cookie. You can view the cookies that have been set and their durations at any time in your browser settings and delete the cookies manually.
Some of the third-party services we integrate may use their own cookies. Information on how they work and process data can be found on the websites of the respective service providers. The third-party services we use are listed in this privacy policy.
If you are using Safari version 12.1 or later, cookies will be automatically deleted after seven days. This also applies to opt-out cookies that are set to prevent tracking.
Online Marketing / Analytics Tools
We use online marketing and analysis tools to tailor our website to your needs and to continuously optimize its use. These measures are based on your consent in accordance with Art. 6 (1) sentence 1 lit. a GDPR. If data is transferred to a country outside the European Union (so-called third country), this will only take place if you have expressly consented to it, or if it is necessary for us to provide our services to you, or if it is required by law (Art. 49 GDPR). Your data will only be processed in third countries if certain measures ensure an adequate level of data protection, e.g. through an adequacy decision by the EU Commission or through appropriate safeguards in accordance with Art. 44 et seqq. DSGVO.
Google Analytics
If you have given your consent, we use Google Analytics 4 on this website, a web analysis service provided by Google LLC. For users in the EU, the EEA and Switzerland, the responsible body is Google Ireland Limited, Dublin, Ireland (“Google”). Google Analytics uses cookies to analyze the use of our website and our marketing campaigns. The data processing is carried out on the basis of your consent in accordance with Art. 6 (1) sentence 1 lit. a GDPR.
The information collected by Google Analytics is usually transferred to a Google server in the USA and stored there. Recipients of the data may be Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), Google LLC (1600 Amphitheatre Parkway Mountain View, CA 94043, USA), or Alphabet Inc. (1600 Amphitheatre Parkway Mountain View, CA 94043, USA). On July 10, 2023, the European Commission issued an adequacy decision for data transfers to the United States. Google LLC is certified under the EU-US Privacy Framework. In addition, we have concluded the EU Standard Contractual Clauses (SCC) with Google.
Google Analytics 4 has IP anonymization enabled by default. This means that your IP address within the EU or the EEA is shortened before it is transmitted to Google. Only in exceptional cases will the full IP address be transmitted to the US and shortened there. According to Google, the IP address transmitted by your browser will not be merged with other Google data.
During your visit to our website, your user behavior is recorded in the form of “events”. These include, for example, page views, first-time visits to the website, start of the session, websites visited, your “click path”, interactions with the website, scrolling actions (when a user scrolls to the bottom of the page), clicks on external links, internal search queries, interactions with videos, file downloads, advertisements seen or clicked on, and your language setting.
In addition, your approximate location (region), date and time of your visit, your IP address (in abbreviated form), technical information about your browser and the end devices used (e.g. language setting, screen resolution), your internet provider and the referrer URL (via which website or which advertising medium you came to this website) are recorded.
You can withdraw your consent at any time. The withdrawal applies from the time you notify us of it and affects future processing. The lawfulness of the processing up to your withdrawal remains unaffected.
You can prevent the installation and storage of cookies by selecting the appropriate settings on your browser; however, we would like to point out that in this case you may not be able to use all the features of this website to its full extent.
You can also prevent the data generated by cookies about your use of the website (incl. your IP address) from being passed to Google, and the processing of these data by Google, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.
With the following link you can deactivate the use of your personal data by Google: https://myadcenter.google.de/personalizationoff.
Google Tag Manager
The Google Tag Manager, provided by Google Ireland Limited, Dublin, Ireland (“Google”), is a tool that allows us to integrate tracking and statistical tools as well as other technologies on our website. The tool itself does not create user profiles, store cookies or carry out its own analyses. It is used solely for the administration and display of the integrated tools. In doing so, the Google Tag Manager records your IP address, which may also be transmitted to Google in the United States.
The information collected by Google Analytics is usually transferred to a Google server in the USA and stored there. Recipients of the data may be Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), Google LLC (1600 Amphitheatre Parkway Mountain View, CA 94043, USA), or Alphabet Inc. (1600 Amphitheatre Parkway Mountain View, CA 94043, USA). On July 10, 2023, the European Commission issued an adequacy decision for data transfers to the United States. Google LLC is certified under the EU-US Privacy Framework. In addition, we have concluded the EU Standard Contractual Clauses (SCC) with Google.
The use of Google Tag Manager is based on Art. 6 (1) sentence 1 lit. f GDPR. Our legitimate interest lies in the efficient administration of various tools on the website. If consent has been obtained, the processing is carried out on the basis of Art. 6 (1) sentence 1 lit. a GDPR and Sec. 25 (1) German Telecommunications and Telemedia Data Protection Act. You can withdraw your consent at any time. The withdrawal applies from the time you notify us of it and affects future processing. The lawfulness of the processing up to your withdrawal remains unaffected.
For more information about Google Tag Manager and Google’s privacy policy, please visit https://policies.google.com/privacy?hl=de and https://marketingplatform.google.com/about/analytics/tag-manager/use-policy/.
Google Ads / Google Conversion Tracking
We also use the online advertising program “Google Ads” and, within the framework of Google Ads, conversion tracking, provided by Google Ireland Limited, Dublin, Ireland (“Google”).
Google Ads allows us to display ads based on certain search terms or user data such as location and interests. We can also analyze this data, e.g. which search terms triggered ads and how many clicks they received.
Google Conversion Tracking enables us to recognize whether users have performed certain actions on our website, such as clicking on buttons or purchasing products. This data helps us to generate conversion statistics. We learn the number of users who clicked on our ads and what actions they performed, but without personal identification. Google uses cookies or similar technologies for this purpose.
The data collected by Google Analytics is usually transferred to a Google server in the USA and stored there. Recipients of the data may be Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), Google LLC (1600 Amphitheatre Parkway Mountain View, CA 94043, USA), or Alphabet Inc. (1600 Amphitheatre Parkway Mountain View, CA 94043, USA). On July 10, 2023, the European Commission issued an adequacy decision for data transfers to the United States. Google LLC is certified under the EU-US Privacy Framework. In addition, we have concluded the EU Standard Contractual Clauses (SCC) with Google.
The use of Google Ads and Google Conversion Tracking is based on your consent in accordance with Art. 6 (1) sentence 1 lit. f GDPR. You can withdraw your consent at any time. The withdrawal applies from the time you notify us of it and affects future processing. The lawfulness of the processing up to your withdrawal remains unaffected.
For more information about Google Tag Manager and Google’s privacy policy, please visit https://policies.google.com/privacy?hl=de.
Conclusion of a Contractual Relationship
When concluding a contractual relationship on our website, by subscribing to one of our paid plans, we ask you to provide the following personal data:
Data that allows your personal identification, such as name and email address; date of birth; contact data, such as address billing and delivery address as well as telephone number; data that identifies your company, such as company name, address, communication data (email address, telephone, fax number), VAT ID or tax number (if applicable); information about your means of payment.
Other personal data that we are required or authorized by law to collect and process and that we need for your authentication, identification or to verify the data we collect.
The aforementioned data is processed for the purpose of carrying out the contractual relationship. The processing of the data is based on Art. 6 (1) sentence 1 lit. b GDPR. The storage period is limited to the purpose of the contract and, if applicable, legal and contractual retention obligations.
Use of Payment Providers
For processing the payment of contracts concluded with us, we collaborate with the payment service provider ‘Stripe Payments Europe, Limited (SPEL), 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (“Stripe”)’. When processing the payment, we pass on your payment data to the payment service provider – only for the purpose of facilitating the payment – insofar as this is necessary for the payment processing. The legal basis for the transfer of data is, in each case, Art. 6 (1) sentence 1 lit. b GDPR.
Signing Up for our Newsletter
If you have expressly consented in accordance with Art. 6 (1) sentence 1 lit. a GDPR, we will use your email address to send you our newsletter on a regular basis.
The email address will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. Your email address will therefore be stored as long as the newsletter subscription is active.
Unsubscribing is possible at any time, for example via a link at the end of a newsletter.
Contact via Email
When you contact us via email or via a contact form, the data you provide (your email address, name and telephone number, if applicable) will be stored by us in order to answer your questions or handle your complaint. The data processing for the purpose of contacting us is carried out in accordance with Art. 6 (1) sentence 1 lit. a GDPR on the basis of your voluntarily given consent. We delete the data accruing in this context, (i) if the inquiry is assigned to a contract, after the term of the contract has elapsed, and (ii) otherwise after the storage is no longer necessary, or (iii) restrict the processing if there are legal obligations to retain data.
Use of the Login Area
If you wish to use our soofia.co platform, you must register by entering your email address, a password of your choice and your user name. There is no obligation to use a clear name; pseudonymous use is possible. The provision of the aforementioned data is mandatory, whereas all other information can be provided voluntarily when using the platform. For this service we use the so-called double-opt-in procedure, i.e. you will receive an email in which you must confirm that you are the owner of the respective email address and wish to receive notifications. You can unsubscribe from the notifications at any time, e.g. by clicking on the link in the email or by contacting us using the contact details provided. Your provided data as well as the dates of your registration for the service and your IP address will be stored by us until you unsubscribe from the notice service.
If you use our platform, we store your data required for the fulfillment of the contract, as well as information on the method of payment, until you ultimately delete your account. Furthermore, we store the voluntary data provided by you for the time of your use of the platform, unless you delete them beforehand. You can manage and change all details in the protected customer area. Legal basis is Art. 6 (1) sentence 1 lit. b GDPR.
User Accounts
If you interact with our services and products you are given the opportunity to create an account with us. The creation of an account is based on your consent. You can withdraw your consent and/or delete your account by contacting us via the contact details provided above. The withdrawal or deletion of your account may have negative consequences on your user experience. The following personal data is processed in connection with your account: Name, address data, contact data. Legal basis for the processing of this data is Art. 6 (1) sentence 1 lit. a GDPR.
Automated Decision-Making and Profiling
In the performance of the contract with you and to the extent necessary to fulfill our obligations to you or where necessary for purposes of the legitimate interest such as to improve our products or our services, we use automated decision-making and profiling. When such automated decision-making and/or profiling leads to a negative decision about you, and you do not agree with it, or if you would like to object to this type of processing of your personal data you can contact us via the contact details provided above. We will then proceed to reassess the situation and/or to provide you with more information about why such an automated decision was made.
Up-To-Dateness and Amendments of this Privacy Policy
Due to the further development of our website and offers on it or due to changed legal or regulatory requirements, we may be required to amend this privacy policy.
This policy was last modified on 26.09.2024