Data Security Statement

Data Protection Declaration

1) Information on the Collection of Personal Data and Contact Details of the Controller

1.1 We are pleased that you are visiting our website and thank you for your interest. In the following pages, we inform you about the handling of your personal data when using our website. Personal data is all data with which you can be personally identified.

1.2 The controller in charge of data processing on this website, within the meaning of the General Data Protection Regulation (GDPR), is Soulfulfactory OHG, Mühlleite 8, 91560 Heilsbronn, Deutschland, Tel.: +49 9872 9566511, E-Mail: info@soulfulfactory.com. The controller in charge of the processing of personal data is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

1.3 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or inquiries to the controller). You can recognize an encrypted connection by the character string https:// and the lock symbol in your browser line.

2) Data Collection When You Visit Our Website

When using our website for information only, i.e. if you do not register or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called "server log files"). When you visit our website, we collect the following data that is technically necessary for us to display the website to you:

  • Our visited website
  • Date and time at the moment of access
  • Amount of data sent in bytes
  • Source/reference from which you came to the page
  • Browser used
  • Operating system used
  • IP address used (if applicable: in anonymized form)

Data processing is carried out in accordance with Art. 6 (1) point f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to check the server log files subsequently, if there are any concrete indications of illegal use.

3) Contacting Us

When you contact us (e.g. via contact form or e-mail), personal data is collected. Which data is collected in the case of a contact form can be seen from the respective contact form. These data are stored and used exclusively for the purpose of responding to your request or for establishing contact and for the associated technical administration. The legal basis for processing data is our legitimate interest in responding to your request in accordance with Art. 6 (1) point f GDPR. If your contact is aimed at concluding a contract, the additional legal basis for the processing is Art. 6 (1) point b GDPR. Your data will be deleted after final processing of your enquiry; this is the case if it can be inferred from the circumstances that the facts in question have been finally clarified, provided that there are no legal storage obligations to the contrary.

4) Data Processing When Opening a Customer Account and for Contract Processing

Pursuant to Art. 6 (1) point b GDPR, personal data will continue to be collected and processed if you provide them to us for the execution of a contract or when opening a customer account. Which data is collected can be seen from the respective input forms. It is possible to delete your customer account at any time. This can be done by sending a message to the above-mentioned address of the controller. We store and use the data provided by you for contract processing. After complete processing of the contract or deletion of your customer account, your data will be blocked in consideration of tax and commercial retention periods and deleted after expiry of these periods, unless you have expressly consented to further use of your data or a legally permitted further use of data has been reserved by our site, about which we will inform you accordingly below.

5) Processing of Data for the Purpose of Order Handling

The personal data collected by us will be passed on to the transport company commissioned with the delivery within the scope of contract processing, insofar as this is necessary for the delivery of the goods. We will pass on your payment data to the commissioned credit institution within the framework of payment processing, if this is necessary for payment handling. If payment service providers are used, we explicitly inform you of this below. The legal basis for the transfer of data is Art. 6 (1) point b GDPR.

6) Use of Social Media

6.1 Facebook with Shariff Solution

Our website uses so-called social plugins ("plugins") of the social network Facebook operated by Facebook Inc, 1 Hacker Way, Menlo Park, CA 94025, USA ("Facebook").

In order to increase the protection of your data when you visit our website, these buttons are not fully integrated into the page as plug-ins and only fully operational when using an HTML link. This type of integration ensures that no connection to servers of Facebook is established when a page of our website containing such buttons is called up. When you click on the button, a new browser window opens and calls up the Facebook page, where you can interact (if necessary after entering your login data) with the plugins contained there.

Facebook Inc., based in the United States, is certified for the US-European data protection agreement "Privacy Shield", which guarantees compliance with the data protection level applicable in the EU.

The purpose and scope of the data collection and the further processing and use of the data by Facebook, as well as your rights and setting options for the protection of your privacy, can be found in the Facebook data protection information: https://www.facebook.com/policy.php

6.2 Instagram with Shariff Solution

Our website uses so-called social plugins ("plugins") of the Instagram online service operated by Instagram LLC, 1601 Willow Rd, Menlo Park, CA 94025, USA ("Instagram").

In order to increase the protection of your data when you visit our website, these buttons are not fully integrated into the page as plug-ins and only fully operational when using an HTML link. This type of integration ensures that no connection to Instagram’s servers is established when you access a page on our website that contains such buttons. When you click the button, a new browser window opens and opens the Instagram page, where you can interact with the plugins (if necessary, after entering your login data).
Instagram LLC., based in the United States, is certified for the US-European data protection agreement "Privacy Shield", which guarantees compliance with the data protection level applicable in the EU.

Please refer to Instagram’s privacy policy for the purpose and scope of data collection and the further processing and use of data by Instagram and your rights and setting options for protecting your privacy at: https://help.instagram.com/155833707900388/

6.3 Pinterest with Shariff Solution

We use so-called social plugins ("plugins") of the social network Pinterest operated by Pinterest Inc., 808 Brannan Street, San Francisco, CA, 94103, USA ("Pinterest").

In order to increase the protection of your data when you visit our website, these buttons are not fully integrated into the page as plug-ins and only fully operational when using an HTML link. This type of integration ensures that no connection to Pinterest’s servers is established when a page of our website containing such buttons is accessed. When you click on the button, a new browser window opens and calls up the Pinterest page, where you can interact with the plug-ins there (if necessary after entering your login data).
Please refer to Pinterest’s privacy policy for the purpose and scope of data collection and the further processing and use of the data by Pinterest and your rights and setting options for protecting your privacy at: https://policy.pinterest.com/en-gb/privacy-policy

6.4 Twitter with Shariff Solution

Our website uses so-called social plugins ("plugins") of the microblogging service Twitter operated by Twitter Inc. 1355 Market St, Suite 900, San Francisco, CA 94103, USA ("Twitter").

In order to increase the protection of your data when you visit our website, these buttons are not fully integrated into the page as plug-ins and only operational when using an HTML link. This type of integration ensures that no connection to Twitter’s servers is established when a page of our website containing such buttons is accessed. When you click on the button, a new browser window opens and opens the Twitter page, where you can interact with the plugins (if necessary after entering your login data).
Twitter Inc., based in the United States, is certified for the US-European data protection agreement "Privacy Shield", which guarantees compliance with the data protection level applicable in the EU.

The purpose and scope of the data collection and the further processing and use of the data by Twitter as well as your relevant rights and setting options for the protection of your privacy can be found in the Twitter data protection information at: https://twitter.com/privacy

7) Use of Videos

7.1 Use of YouTube Videos

This website uses the YouTube embedding function for display and playback of videos offered by the provider YouTube, which belongs to Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 ESW5, Ireland ("Google").

To this end, the extended data protection mode is used to ensure, according to provider information, that user information will only be stored once the playback function of the video is started. When the playback of embedded YouTube videos is started, the provider sets "YouTube" cookies in order to collect information about user behavior. According to indications from YouTube, the use of those cookies is intended, among other things, to record video statistics, to improve user-friendliness and to avoid improper actions. If you are logged in to Google, your information will be directly associated with your account when you click on a video. If you do not wish to be associated with your profile on YouTube, you must log out before activating the button. Google saves your data (even for users who are not logged in) as usage profiles and evaluates them. Such an evaluation takes place in particular according to Art. 6 (1) point f GDPR, on the basis of the legitimate interests of Google in the insertion of personalized advertising, market research and/or demand-oriented design of its website. You have the right to object to the creation of these user profiles, whereby you must contact YouTube to exercise this right. When using YouTube, personal data may also be transmitted to the servers of Google LLC. in the USA.

Regardless of whether the embedded video is played back, a connection to the Google network "double click" is established when visiting this website. This may trigger further data processing beyond our control.

In the event that personal data is transferred to Google LLC. based in the United States, Google LLC. is certified for the US-European data protection agreement "Privacy Shield", which guarantees compliance with the data protection level applicable in the EU. An up-to-date certificate can be viewed here: https://www.privacyshield.gov/list.

Further information on YouTube data protection can be found in the provider’s data protection statement at: www.google.com/policies/privacy/

7.2 Use of Vimeo Videos

On our website, plugins of the video portal Vimeo of Vimeo, LLC, 555 West 18th Street, New York, New York 10011, USA are embedded. When you access a page of our website that contains such a plugin, your browser establishes a direct connection to Vimeo’s servers. The content of the plugin is transmitted by Vimeo directly to your browser and integrated into the page. Through this integration, Vimeo receives the information that your browser has called up the corresponding page of our website, even if you do not have a Vimeo account or are not currently logged in to Vimeo. This information (including your IP address) is transmitted directly from your browser to a Vimeo server in the USA and stored there.

If you are logged in to Vimeo, Vimeo can immediately assign your visit of our website to your Vimeo account. If you interact with the plugins (e.g. pressing the start button of a video), this information is also transmitted directly to a Vimeo server and stored there.

The data processing operations described are carried out in accordance with Art. 6 (1) point f GDPR, on the basis of Vimeo’s legitimate interest in market research and the need-based design of the service.

If you do not want Vimeo to assign the data collected via our website directly to your Vimeo account, you must log out of Vimeo before visiting our website.

The purpose and scope of the data collection and the further processing and use of the data by Vimeo as well as your related rights and privacy settings can be found in Vimeo’s privacy policy: https://vimeo.com/privacy

Vimeo, Inc. based in the USA is certified for the US-European data protection agreement "Privacy Shield", which guarantees compliance with the data protection level applicable in the EU. An up-to-date certificate can be viewed here: https://www.privacyshield.gov/list.

For videos from Vimeo that are embedded on our site, the tracking tool Google Analytics of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland, is automatically integrated. This relates to Vimeo’s own tracking which we do not have access to and which cannot be influenced by our site. Google Analytics uses "cookies", which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of the website will generally be transmitted to and stored by Google on servers in the United States, where it may also be transmitted to servers of Google LLC.

In the event that personal data is transferred to Google LLC. based in the United States, Google LLC. is certified for the US-European data protection agreement "Privacy Shield", which guarantees compliance with the data protection level applicable in the EU. An up-to-date certificate can be viewed here: https://www.privacyshield.gov/list.

This processing is carried out in accordance with Art. 6 (1) point f GDPR on the basis of Vimeo’s legitimate interest in the statistical analysis of user behavior for optimization and marketing purposes.

8) Online-Marketing

8.1 Google Marketing Platform (formerly Doubleclick)

This website uses the online marketing tool Google Marketing Platform of the operator Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 ESW5, Ireland ("GMP").

GMP uses cookies to serve ads relevant to users, improve campaign performance reports, or to prevent a user from seeing the same ads more than once. Google uses a cookie ID to track which ads are displayed in which browser and to prevent them from being displayed more than once. Processing is based on our legitimate interest in the optimal marketing of our website in accordance with Art. (1) point f GDPR.

In addition, GMP may use cookie IDs to collect conversions related to ad requests. This is the case, for example, when a user sees a GMP ad and later visits the advertiser’s website with the same browser and buys something there. According to Google, GMP cookies do not contain any personal information.

Due to the marketing tools used, your browser automatically establishes a direct connection to the Google server. We have no influence on the extent and the further use of the data collected by Google when using this tool and we therefore inform you according to our level of knowledge. By integrating GMP, Google receives the information that you have accessed the corresponding part of our internet presence or clicked on an advertisement from us. If you are registered with a Google service, Google may associate your visit with your account. Even if you are not registered with Google or have not logged in, it is possible that the provider may obtain and store your IP address. When using GMP, personal data may also be transmitted to the servers of Google LLC. in the USA.

If you do not wish to participate in this tracking process, you can disable cookies for conversion tracking by setting your browser to block cookies from the www.googleadservices.com domain, https://support.google.com/ads/answer/2662856?hl=en-GB, which will be deleted if you delete your cookies. Alternatively, you can contact the Digital Advertising Alliance at www.aboutads.info to find out how to set cookies and to make the relevant settings. Finally, you can set your browser so that you are informed about the setting of cookies and decide individually whether to accept them or to exclude the acceptance of cookies for certain cases or in general. If cookies are not accepted, the functionality of our website may be limited.

In the event that personal data is transferred to Google LLC. based in the United States, Google LLC. is certified for the US-European data protection agreement "Privacy Shield", which guarantees compliance with the data protection level applicable in the EU. An up-to-date certificate can be viewed here: https://www.privacyshield.gov/list..

For more information about Google’s privacy policy relevant to GMP, please visit https://policies.google.com/privacy?hl=en

8.2 Google AdSense

This website uses Google AdSense, a web ad service of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 ESW5, Ireland ("Google"). Google AdSense uses so-called "DoubleClick DART Cookies". These are text files are stored on your computer and enable an analysis of your use of the website. In addition, Google AdSense also uses "web beacons" (small invisible graphics) to collect information, which can be used to record, collect and evaluate simple actions such as visitor traffic on the website. The information generated by those cookies and/or web beacons (including your IP address) about your use of this website will normally be transmitted to a server of Google and will be stored there. When using Google AdSense, personal data may also be transmitted to the servers of Google LLC. in the USA.

Google will use the information obtained in this way to analyze your usage of this website with regard to AdSense ads. The IP address transmitted by your browser as part of Google AdSense is not merged with other Google data. The information collected by Google may be transferred to third parties, if this is prescribed by law and/or if third parties process this data by request of Google.

The described processing of data takes place according to Art. 6 (1) point f GDPR, for the purpose of target-oriented advertising to the user by third parties whose advertisements are displayed on this website based on the evaluated user behavior. At the same time, such processing serves our financial interest in exploiting the economic potential of our Internet presence by displaying personalized third-party advertising content for a fee.

In the event that personal data is transferred to Google LLC. based in the United States, Google LLC. is certified for the US-European data protection agreement "Privacy Shield", which guarantees compliance with the data protection level applicable in the EU. An up-to-date certificate can be viewed here: https://www.privacyshield.gov/list..

For more information about Google’s privacy policy, please visit: https://privacy.google.com/intl/en-GB/take-control.html?categories_activeEl=sign-in

You can permanently deactivate cookies for advertising preferences by blocking them via a respective setting of your browser software or by downloading and installing the browser plug-in, available under the following link:
https://support.google.com/ads/answer/7395996

Please note that certain functions of this website may not be used or may be used only to a limited extent, if you have deactivated the use of cookies.

9) Web Analysis Services

Matomo

Data is collected and stored on this website using the web analysis service software Matomo (www.matomo.org), a service of InnoCraft Ltd., 150 Willis St, 6011 Wellington, New Zealand, ("Matomo"). This is done on the basis of our legitimate interest in statistical analysis of user behavior for optimization and marketing purposes pursuant to Art. 6 (1) point f GDPR. Pseudonymized user profiles can be created and evaluated from this data for the same purpose. To this end, cookies may be used. Cookies are small text files that are stored locally in the cache of the visitor’s Internet browser. The cookies allow, among other things, the internet browser to be recognized. The data collected with Matomo technology (including your pseudonymised IP address) is processed on our servers.

The information generated by the cookie in the pseudonymous user profile is not used to personally identify the visitor to this website and is not merged with personal data about the holder of the pseudonym.

If you do not agree to the storage and evaluation of this data arising from your visit, you can object to the subsequent storage and use at any time, via mouse click. In this case, a so-called opt-out cookie is stored in your browser, which means that Matomo does not collect any session data. Please note: If your cookies are completely deleted, the opt-out cookie will also be deleted, and you may have to activate it again.

10) Tools and Miscellaneous

10.1 Google reCAPTCHA

On this website we also use the reCAPTCHA function of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). This function is mainly used to distinguish whether an entry is made by a natural person or misused by automatic and automated processing. The service includes the sending of the IP address and possibly other data required by Google for the reCAPTCHA service to Google and is carried out in accordance with Art. 6 (1) point f GDPR, on the basis of our legitimate interest in determining the individual willingness of actions on the Internet and avoiding misuse and spam.

In the event that personal data is transferred to Google LLC. based in the United States, Google LLC. is certified for the US-European data protection agreement "Privacy Shield", which guarantees compliance with the data protection level applicable in the EU. An up-to-date certificate can be viewed here: https://www.privacyshield.gov/list.

Further information about Google reCAPTCHA and Google’s privacy policy can be found at: https://policies.google.com/privacy?hl=en-GB

10.2 Google Web Fonts

This site uses web fonts provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google") to uniformly display fonts. When you call up a page, your browser loads the required web fonts into its browser cache to display texts and fonts correctly.

To do this, the browser you are using must have a connection to Google’s servers. When using Google Maps, personal data may also be transmitted to the servers of Google LLC. in the USA. In this way, Google will be informed that our website has been accessed via your IP address. Google Web Fonts are used for the purpose of a uniform and attractive presentation of our online offers and its use is in our legitimate interest within the meaning of Art. 6 (1) point f GDPR. If your browser does not support web fonts, a default font is used by your computer.

In the event that personal data is transferred to Google LLC. based in the United States, Google LLC. isIs certified for the US-European data protection agreement "Privacy Shield", which guarantees compliance with the data protection level applicable in the EU. An up-to-date certificate can be viewed here: https://www.privacyshield.gov/list.

Further information about Google Web Fonts can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy: https://policies.google.com/privacy?hl=en.

11) Rights of the Data Subject

11.1 The applicable data protection law grants you the following comprehensive rights of data subjects (rights of information and intervention) vis-à-vis the data controller with regard to the processing of your personal data:

  • Right of access by the data subject pursuant to Art. 15 GDPR
  • Right to rectification pursuant to Art. 16 GDPR
  • Right to erase (“right to be forgotten”) pursuant to Art. 17 GDPR
  • Right to restriction of processing pursuant to Art. 18 GDPR
  • Right to be informed pursuant to Art. 19 GDPR
  • Right to data portability pursuant to Art. 20 GDPR
  • Right to withdraw a given consent pursuant to Art. 7 (3) GDPR
  • Right to lodge a complaint pursuant to Art. 77 GDPR

11.2 RIGHT TO OBJECT

IF, WITHIN THE FRAMEWORK OF A CONSIDERATION OF INTERESTS, WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR PREDOMINANT LEGITIMATE INTEREST, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THIS PROCESSING WITH EFFECT FOR THE FUTURE ON THE GROUNDS THAT ARISE FROM YOUR PARTICULAR SITUATION.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE DATA CONCERNED. HOWEVER, WE RESERVE THE RIGHT TO FURTHER PROCESSING IF WE CAN PROVE COMPELLING REASONS WORTHY OF PROTECTION FOR PROCESSING WHICH OUTWEIGH YOUR INTERESTS, FUNDAMENTAL RIGHTS AND FREEDOMS, OR IF THE PROCESSING SERVES TO ASSERT, EXERCISE OR DEFEND LEGAL CLAIMS.

IF WE PROCESS YOUR PERSONAL DATA FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA WHICH ARE USED FOR DIRECT MARKETING PURPOSES. YOU MAY EXERCISE THE OBJECTION AS DESCRIBED ABOVE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE DATA CONCERNED FOR DIRECT ADVERTISING PURPOSES.

12) Duration of Storage of Personal Data

The duration of the storage of personal data is determined by the respective legal retention period (e.g. commercial and tax retention periods). After expiry of this period, the corresponding data will be routinely deleted, provided they are no longer necessary for the performance or initiation of the contract and/or there is no longer any legitimate interest on our part in further storage.