Privacy Policy

Effective date: 24 August 2026

Data controller: Mark Julien Hahn / Softdrive Foundry Görlitzer Straße 52, 10997 Berlin, Germany Email: privacy@softdrivefoundry.com


We are not required to appoint a Data Protection Officer under Art. 37 GDPR. For all privacy-related inquiries, please contact us at privacy@softdrivefoundry.com.

This Privacy Policy explains how Softdrive Foundry ("we", "us", or "our") collects, uses, shares, and protects your personal data when you use our website and services. It applies to all users, including visitors, customers, and newsletter subscribers.

We are committed to privacy by design and comply with the General Data Protection Regulation (GDPR, EU 2016/679) and the German Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG).

1. What data we collect

Personal data you provide directly

We collect the following data when you actively provide it to us:

Name, email, billing/shipping address

Payment information (via Stripe)

Account registration details

Newsletter signup (email)

Note: We never receive or retain full card numbers. Payment data is processed entirely by Stripe Payments Europe, Ltd. under a signed Data Processing Agreement (DPA) with EU Standard Contractual Clauses (SCCs).

Data collected automatically

Server logs (IP address, browser/device info, request timestamp)

session cookie

admin_session cookie

Local storage (shopping cart)

Why we collect this:

Analytics data (Umami)

We use Umami, a privacy-focused analytics tool that does not use cookies and does not store IP addresses. Umami is hosted in the EU and covered by a signed DPA with SCCs.

Umami collects the following aggregate, non-personal data:

How Umami works:

Your control: You can opt out of analytics at any time via /analytics-opt-out. This stores one value in your browser's local storage to remember your choice (no cookies are used).

Legal basis: Legitimate interest (Art. 6(1)(f) GDPR). Our interest is in understanding site usage to improve our services, without compromising your privacy. You may object at any time via the opt-out link above.

Data from third parties

We receive data from the following trusted processors under signed DPAs with SCCs where applicable:

Stripe Payments Europe, Ltd.

Resend, Inc.

Vercel Inc.

Sanity AS

Umami Software, Inc.

Note: All transfers to non-EU/EEA providers are covered by signed Data Processing Agreements (DPAs) incorporating the EU Standard Contractual Clauses (Art. 46 GDPR).

2. How we use your data

Order fulfillment (licenses, deliveries)

Customer account management

Newsletter delivery

Website analytics (Umami)

Security and abuse prevention

Tax and accounting compliance

3. Legal basis for processing

We process your data only when we have a lawful basis under GDPR:

We pursue these interests without:

You may object to this processing at any time — via /analytics-opt-out for analytics, or by contacting us at privacy@softdrivefoundry.com for server logs.

4. Sharing data with third parties

We never sell your personal data to third parties. Data is shared only with the processors below, who act under our instructions and signed DPAs with SCCs where applicable:

Additional safeguards:

5. Cookies and tracking technologies

What we do not use

Result: This website does not display a cookie banner, because nothing we use requires your consent under § 25 TDDDG or the GDPR. All cookies we use are strictly necessary for functionality you have requested (§ 25(2) TDDDG).

Cookies we use

session

admin_session

Other local storage

6. Data retention

We retain your data only for as long as necessary for the purposes described in this policy:

Automatic deletion: Server logs and session cookies are automatically deleted after their retention periods. You can delete your account or unsubscribe from newsletters at any time.

7. Your rights under GDPR

You have the following rights regarding your personal data. To exercise any of them, contact us at privacy@softdrivefoundry.com. We will respond within one month, extendable to three months for complex requests.


Right to access (Art. 15 GDPR)

Request a copy of the personal data we hold about you, including:

Right to rectification (Art. 16 GDPR)

Request correction of inaccurate or incomplete data about you.


Right to erasure — "right to be forgotten" (Art. 17 GDPR)

Request deletion of your data if:

Exceptions: we may retain data to comply with legal obligations, such as tax records, or to establish, exercise, or defend legal claims.

Right to restriction of processing (Art. 18 GDPR)

Request that we temporarily restrict processing of your data while we verify the accuracy of contested data, or determine whether we have overriding legitimate grounds for processing after you object.


Right to data portability (Art. 20 GDPR)

Request your data in a structured, commonly used, machine-readable format such as JSON or CSV. This covers data you provided to us — for example account details and purchase history — that we process under consent or contract.


Right to object (Art. 21 GDPR)

Object to processing based on legitimate interest, such as analytics and server logs. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.


Right to withdraw consent (Art. 7(3) GDPR)

Withdraw your consent for newsletter subscriptions at any time via the unsubscribe link in any email, or by contacting us.


Rights related to automated decision-making (Art. 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or significantly affects you. We do not use automated decision-making in this way.

8. Data security

We implement technical and organizational measures to protect your data from unauthorized access, disclosure, alteration, or destruction.


Technical measures

Organizational measures

9. International data transfers

Some of our processors — Stripe, Resend, Vercel, Sanity — may process data outside the EU/EEA. All such transfers are protected by signed Data Processing Agreements incorporating the EU Standard Contractual Clauses (Art. 46 GDPR). Where required, we assess the risk of transfers to countries without an EU adequacy decision, such as the USA, and implement supplementary measures.

10. Children's privacy

Our services are not directed at children under 16. We do not knowingly collect personal data from children. If you are a parent or guardian and believe we have collected data from your child, contact us at privacy@softdrivefoundry.com and we will promptly delete it.

11. Changes to this policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. If we make material changes, we will post the updated policy on this page with a new effective date, and notify you by email if you have an account, or via a prominent notice on our website.

Your continued use of our services after the effective date constitutes acceptance of the changes.

12. Contact

For questions, requests, or complaints regarding this policy or your data:

Mark Julien Hahn / Softdrive Foundry
Görlitzer Straße 52, 10997 Berlin, Germany
privacy@softdrivefoundry.com

Supervisory authority

You have the right to lodge a complaint with a data protection authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement. The authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin.