Privacy Policy

1. Controller

The controller responsible for data processing on this website is:

Sebastian Wulf
Kisselnallee 1
13589 Berlin
Germany

Email: hello@simplysoftware.dev
WhatsApp: +49 177 5243745

2. Overview of processing

We process personal data only as necessary to provide this website, communicate with prospects and customers, and operate the customer portal. Legal bases include Art. 6(1)(b) GDPR (contract / pre-contractual measures), Art. 6(1)(c) GDPR (legal obligation) and Art. 6(1)(f) GDPR (legitimate interest in a secure and functional service).

3. Hosting and server log files

This website is hosted by netcup GmbH (Daimlerstraße 25, 76185 Karlsruhe, Germany). When you access pages, the web server automatically stores technically necessary access data (server log files), for example:

  • IP address
  • date and time of the request
  • requested URL / hostname
  • browser type and operating system (user agent)
  • referrer URL (if transmitted)
  • status code of the server response

Processing is carried out to provide, analyse and secure the service (Art. 6(1)(f) GDPR). Log data is retained only as long as necessary for these purposes and then deleted or anonymised. A data processing agreement pursuant to Art. 28 GDPR is in place with the host.

4. SSL/TLS encryption

This website uses SSL/TLS encryption to protect transmitted data. You can recognise an encrypted connection by “https://” in the address bar and the lock icon in your browser.

5. Cookies and browser storage

We do not use analytics, marketing or tracking cookies.

For the customer area, a technically necessary session cookie (ss_customer) is set upon login. It stores your session ID and enables authentication as well as CSRF protection. The cookie is HTTP-only, uses SameSite=Lax and expires at the end of the browser session (or earlier on logout). Legal basis: Art. 6(1)(b) and (f) GDPR.

Without this cookie, login to the customer portal is not possible.

6. Customer portal / login

For existing customers and shop purchases we operate a protected customer area at /customer/. Shop purchases require a one-time registration or sign-in (self-registration with email and password). Accounts may also still be created by us.

The customer account may store and display in particular:

  • login data: email address and password (stored as a secure hash, not in plain text)
  • master data: first name, last name, address, phone number
  • contract and invoice data including related PDF documents
  • for web hosting contracts: stored access credentials for webspace and website admin (URL, username, password, notes) so you can view them in the portal
  • for web design contracts: optional feedback reports (idea or issue) with a short summary and free text

The purpose is contract performance and the secure provision of customer documents and access details (Art. 6(1)(b) GDPR). Data is stored in a MySQL database on our hosting and – for PDF files – in the server file system. Portal login passwords are stored only as hashes.

Feedback reports from the web design area are stored in our database and forwarded by email to our project management tool Trello (Atlassian) for processing. The report content as well as the customer’s name and email address are transmitted. Legal basis: Art. 6(1)(b) GDPR. Transfers to third countries (including the USA) may occur; Atlassian provides appropriate safeguards. More information: Atlassian Privacy Policy.

Data is deleted or restricted when the customer relationship ends, unless statutory retention obligations (e.g. commercial or tax law) require longer storage.

7. Contact

If you contact us by email or WhatsApp, we process the data you provide (e.g. name, email address, phone number, message content) to handle your request. Legal basis: Art. 6(1)(b) GDPR (pre-contractual / contractual) or Art. 6(1)(f) GDPR (legitimate interest in efficient communication).

When using WhatsApp, the privacy terms of WhatsApp / Meta Platforms also apply. WhatsApp receives your phone number and communication metadata. Please avoid sending particularly sensitive data via messenger without protection.

Enquiry data is deleted once the matter is closed and no statutory retention duties apply.

8. Website briefing form

Via the optional briefing form (/website-briefing.php) you can submit project details (e.g. company name, contact person, email and further project information). The data is used to prepare a website project (Art. 6(1)(b) GDPR).

To prevent spam we use simple technical measures (e.g. captcha / honeypot). Submitted data is used only to process your briefing and then deleted or transferred into ongoing project communication as required.

9. Downloads

For selected downloads (e.g. Shopware plugins) a local browser captcha may be used. Verification is client-side; no personal data is sent to an external captcha service.

10. Shop and payments (Stripe)

In the public shop at /shop/ you can buy digital products (e.g. plugin licenses) via direct checkout. Payments are processed by Stripe Payments Europe, Limited (Stripe). When you click “Buy now”, you are redirected to a Stripe-hosted Checkout page.

Stripe processes in particular your email address and payment details. We store related order data (including email, order status, Stripe session/payment IDs, product snapshot) and – after successful payment, if a customer account with the same email exists – a matching license in the customer portal. Legal basis: Art. 6(1)(b) GDPR.

Data may be transferred to third countries (including the USA); Stripe provides appropriate safeguards. More information: Stripe Privacy Policy.

11. Google Fonts

To ensure consistent presentation we load fonts via Google Fonts (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). When pages load, your browser connects to Google servers. Your IP address may be transmitted to Google.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a consistent, modern design). More information: https://policies.google.com/privacy

12. Disclosure of data

Personal data is disclosed only where permitted by law, where you have consented, or where this is required for contract performance or website operation (e.g. the host as processor, Stripe for payment processing). Data is not shared for advertising purposes.

13. Retention period

We store personal data only as long as necessary for the respective purposes or as required by statutory retention periods (in particular under German commercial and tax law). Afterwards the data is deleted or restricted.

14. Your rights

Under the GDPR – where the legal requirements are met – you have the right to:

  • access (Art. 15 GDPR)
  • rectification (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • object to processing (Art. 21 GDPR)
  • withdraw consent (Art. 7(3) GDPR)

You also have the right to lodge a complaint with a supervisory authority. For us this is in particular the Berlin Commissioner for Data Protection and Freedom of Information (www.datenschutz-berlin.de).

For privacy requests please contact hello@simplysoftware.dev.

15. Obligation to provide data

Providing personal data is neither legally nor contractually mandatory if you only use the website for information. For customer login, shop purchases and contract performance, the respective details are required; without them we cannot provide access or the service.

16. No automated decision-making

No automated decision-making including profiling within the meaning of Art. 22 GDPR takes place.

17. Changes to this privacy policy

We may update this privacy policy if the website, customer portal or legal requirements change. The version published on this page applies.

Last updated: August 2026