Who we are
Our website address is: https://souldisco-records.de.
Provider pursuant to Section 5 DDG
SoulDisco โ Nadine Steffens
Blankenberger Str. 25a
53773 Hennef, Germany
Email:ย store@souldisco.de
Responsible pursuant to Section 18(2) MStV (editorial content)
Nadine Steffens, address as above
VAT ID No. DE365338918
โ โ โ
Content liability
We take the utmost care when creating the content of this website. Nevertheless, we cannot guarantee that the information is accurate, complete and up to date. Statutory obligations to remove or block information remain unaffected.
Link liability
This website contains links to external thirdโparty websites. We have no influence over their content and therefore assume no liability for such content. Unlawful content was not recognizable at the time the link was placed. If we become aware of infringements, we will remove such links immediately.
Copyright
Content published on this website is subject to German copyright law. Any use beyond statutory exceptions requires prior consent of the rights holders. Thirdโparty content is identified as such.
Trademark notice
โSoulDisco Recordsโ and the โSoulDiscoโ logo are trademarks. Any unauthorised use is prohibited.
ยฉ SoulDisco 2025
Privacy Policy
Last updated: 13 October 2025
This Privacy Policy explains how we process personal data when you visit and use our website and when you purchase from our online shop.
1. Controller
SoulDisco
Blankenberger Str. 25a
53773 Hennef, Germany
Email: nadine@souldisco.de
Authorised representative: Nadine Steffens
Data protection contact / Data Protection Officer (if appointed): not appointed / [insert contact]
2. Terms and legal bases
We process personal data in accordance with the General Data Protection Regulation (GDPR) and the German TelecommunicationsโTelemedia Data Protection Act (TTDSG).
Legal bases at a glance:
- Art. 6(1)(a) GDPR โ Consentย (e.g., statistics/marketing, newsletter tracking, embedded content).
- Art. 6(1)(b) GDPR โ Contract / preโcontractual measuresย (e.g., customer account, order processing, communication).
- Art. 6(1)(c) GDPR โ Legal obligationย (e.g., commercial and tax retention).
- Art. 6(1)(f) GDPR โ Legitimate interestsย (e.g., server logs, IT security, abuse prevention, functional cookies).
- Sec. 25(1) TTDSGย โ Consent for storing/accessing information on endโuser devices (e.g., cookies, local storage), unlessย Sec. 25(2) TTDSGย (strictly necessary) applies.
Requirement to provide data: Certain information is required for shop functions (ordering/shipping/payment). Without this data we cannot process orders.
3. Hosting, processing on our behalf, security
Our website is operated on the servers of our hosting provider:
ALLโINKL.COM (Neue Medien Mรผnnich), Germany
Server location: Germany
We have concluded a data processing agreement (Art. 28 GDPR).
Server log files: With each request, we process the IP address, date/time, URL, referrer, user agent, HTTP status and bytes transferred. Legal basis: Art. 6(1)(f) GDPR (technical operation/IT security).
Retention: [e.g., 14 days], longer in the event of security incidents.
TLS/SSL encryption: Our website uses HTTPS encryption.
4. Consent management (cookies & similar technologies)
We obtain your consent for optional cookies/trackers directly on our website (no external consent tool). Before setting/reading any nonโessential technologies (e.g., statistics, marketing, embedded media), we display a consent prompt. Your choices are stored in your browser; you can change them at any time via the cookie settings link in the footer.
Categories:
- Necessaryย (strictly required for the website/shop; no consent required)
- Preferencesย (optional)
- Statisticsย (optional)
- Marketing/External mediaย (optional)
Lifetimes & providers: Specific cookies/storage entries, lifetimes and providers are listed in the cookie settings.
5. Online shop (WooCommerce)
We operate our shop using WooCommerce (Automattic Inc.).
Data processed: Master data (name, address, email, phone), order data (products, prices, payment method), delivery data, invoicing data, customer account data, communication data.
Purposes: Setโup/administration of the customer account, cart/checkout, conclusion of contract, delivery, invoicing, customer service, fraud prevention.
Legal bases: Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (fraud prevention/IT security), Art. 6(1)(c) GDPR (statutory retention).
Retention: Contract/invoice data under German commercial/tax law 6โ10 years; customer account until deletion; otherwise until the purpose ceases or statutory obligations end.
Recipients: IT/hosting service providers, payment and shipping providers, tax advisors.
Customer account: Optional; keep your login credentials confidential.
Required fields: Certain fields are mandatory in checkout.
6. Payment service providers
Depending on the payment method chosen, we transmit order and payment data to payment services. These providers act as independent controllers.
PayPal
Provider: PayPal (Europe) S.ร r.l. et Cie, S.C.A., 22โ24 Boulevard Royal, Lโ2449 Luxembourg.
Data: Customer/payment data, IP address, device/usage data.
Purposes/legal bases: Payment processing (Art. 6(1)(b) GDPR), identity/fraud prevention (Art. 6(1)(f) GDPR).
Notes: PayPal may carry out credit checks. See PayPalโs privacy information.
Stripe
Provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland (affiliated companies in the USA).
Data & purposes: as above; possible transfers to third countries (see โInternational transfersโ).
Legal bases: Art. 6(1)(b) GDPR, Art. 6(1)(f) GDPR.
Bank transfer (SEPA prepayment)
Provider: Our bank as an independent controller.
Data: Account holder, IBAN, BIC, bank, reference, amount, date.
Purposes/legal bases: Payment processing (Art. 6(1)(b) GDPR); statutory retention (Art. 6(1)(c) GDPR).
7. Shipping service providers
For delivery we transmit address and contact details, andโwhere requiredโpackage contents to shipping providers.
DHL (within Germany)
Provider: DHL Paket GmbH, CharlesโdeโGaulleโStr. 20, 53113 Bonn, Germany.
Purpose: Shipping/tracking and delivery notifications for domestic shipments.
Data: Name, address, email/phone (optional for notifications), package content (where legally required).
Legal basis: Art. 6(1)(b) GDPR.
UPS (international shipments)
Provider: United Parcel Service Deutschland S.ร r.l. & Co. OHG, Gรถrlitzer Straรe 1, 41460 Neuss, Germany; affiliated companies (e.g., UPS Europe Sร rl, Luxembourg; UPS, Inc., USA).
Purpose: Shipping/tracking and delivery notifications for international shipments.
Data: Name, address, email/phone (optional), package content, customs data.
Legal basis: Art. 6(1)(b) GDPR.
Note on third countries: International shipments may involve transfers to authorities/service providers in third countries (e.g., customs); see Section 13.
8. Communication (contact form, email, phone)
When you contact us, we process your details to handle your enquiry.
Legal bases: Art. 6(1)(b) GDPR (preโ/contractual) or Art. 6(1)(f) GDPR (general enquiries).
Retention: Correspondence is deleted after completion and in line with statutory obligations.
9. Newsletter (Mailchimp)
We send our newsletter via Mailchimp (Intuit Inc., 2700 Coast Ave., Mountain View, CA 94043, USA).
Signโup & double optโin: After signing up you receive an email to confirm (double optโin). Only then does dispatch begin.
Required data: Email address; name optional.
Dispatch & performance measurement: For dispatch Mailchimp processes your email address and usage data. Performance measurement (e.g., opens, clicks) is carried out only with your consent (marketing/statistics).
Legal basis: Art. 6(1)(a) GDPR; for marketing emails also Sec. 7 UWG (Germany).
Unsubscribe/withdrawal: You can unsubscribe at any time via the link in each email; you can withdraw your consent at any time with future effect.
Processor & international transfers: We have a processing agreement with Intuit. Transfers to the USA are based on appropriate safeguards (e.g., EUโUS Data Privacy Framework or EU Standard Contractual Clauses); see Section 13.
10. Embedded content / external media
YouTube
We may embed videos (โprivacyโenhancedโ/youtubeโnocookie.com) and load them only after your consent via our consent prompt.
Provider: Google Ireland Limited / Google LLC (USA).
Data: IP address, device/usage data, cookies/local storage where applicable.
Legal bases: Sec. 25(1) TTDSG and Art. 6(1)(a) GDPR (consent); upon playback additionally Art. 6(1)(f) GDPR (providing requested content).
International transfers: see Section 13.
External fonts/maps
We use locally hosted web fonts. If we exceptionally use external sources (e.g., Google Fonts CDN, map providers), this will occur only with consent.
11. Web analytics (Google Analytics 4)
We use Google Analytics 4 (GA4) for reach and usage analysis. GA4 is enabled only after your consent via our consent prompt.
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Data: Truncated IP address, device/browser information, approximate location, events/interactions (e.g., page views, scrolls, purchases), user ID where applicable.
Endโdevice access/consent: Storing/accessing information on your device (e.g., via cookies/storage) only with consent (Sec. 25(1) TTDSG).
Legal basis for processing: Art. 6(1)(a) GDPR.
Settings: IP anonymisation enabled; data retention: 14 months; Google Signals/ads features only with separate consent.
Withdrawal: You may withdraw your consent at any time in the cookie settings.
International transfers: A transfer to the USA is possible; see Section 13.
12. Recipients / categories of recipients
- IT/hosting/maintenance providers (processors)
- Payment and shipping service providers (independent controllers)
- Communication and newsletter services
- Authorities/tax advisors where legally required
13. International data transfers
Where providers in third countries (in particular the USA) process data, this takes place on the basis of recognised safeguards (e.g., EUโUS Data Privacy Framework certification) or EU Standard Contractual Clauses including supplementary measures. See the respective provider information in the cookie details or their privacy notices.
14. Retention periods
We retain data only as long as necessary for the respective purposes or as required by law. Specific deletion periods follow from the relevant sections (e.g., shop/newsletter/analytics) and the cookie details.
15. Your rights
You have the following rights (subject to the statutory requirements):
Access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection to processing based on Art. 6(1)(e) or (f) GDPR (Art. 21), in particular to direct marketing/profiling, and the withdrawal of consent with future effect (Art. 7(3)).
Right to lodge a complaint: You may lodge a complaint with a data protection supervisory authority, for example at your place of residence or at our registered office.
Contact for exercising rights: Use the contact details in Section 1.
16. Automated decisionโmaking / profiling
No solely automated decisionโmaking takes place. Marketing/statistics profiling is carried out only on the basis of your consent.
17. Changes to this notice
We will update this Privacy Policy when functions, legal requirements or providers change. The version shown here is authoritative; see the date at the top.
