The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you. Detailed information on data protection can be found in our privacy policy listed below this text.
Data processing on this website is carried out by the website operator. You can find their contact details in the “Information about the responsible body” section of this privacy policy.
On the one hand, your data is collected when you provide it to us. This could be data that you enter in a contact form, for example.
Other data is collected automatically or with your consent when you visit the website by our IT systems. This is primarily technical data (e.g. Internet browser, operating system or time of page access). This data is collected automatically as soon as you enter this website.
Some of the data is collected to ensure error-free provision of the website. Other data can be used to analyze your user behavior.
You have the right to receive information about the origin, recipient and purpose of your stored personal data free of charge at any time. You also have the right to request that this data be corrected or deleted. If you have given your consent to data processing, you can withdraw this consent at any time for the future. You also have the right to request that the processing of your personal data be restricted under certain circumstances. You also have the right to lodge a complaint with the competent supervisory authority.
You can contact us at any time about this and if you have any further questions about data protection.
When you visit this website, your surfing behavior can be statistically evaluated. This is done primarily with so-called analysis programs.
Detailed information about these analysis programs can be found in the following privacy policy.
We host the content of our website with the following provider:
This website is hosted externally. The personal data collected on this website is stored on the hoster/host's servers. This may include IP addresses, contact requests, meta and communication data, contract data, contact details, names, website accesses and other data generated via a website.
External hosting is provided for the purpose of fulfilling the contract with our potential and existing customers (Art. 6 para. 1 lit. b DSGVO) and in the interest of a secure, fast and efficient provision of our online offering by a professional provider (Art. 6 para. 1 lit. f GDPR). If a corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a DSGVO and § 25 para. 1 TTDSG, insofar as the consent includes the storage of cookies or access to information on the user's device (e.g. device fingerprinting) within the meaning of the TTDSG. The consent can be withdrawn at any time.
Our host (e) will or will only process your data to the extent necessary to fulfill its performance obligations and follow our instructions with regard to this data.
We use the following host (s):
Webflow, Inc.
398 11th Street, 2nd Floor
San Francisco, CA 94103
USA
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with legal data protection regulations and this privacy policy.
When you use this website, various personal data is collected. Personal data is data that can be used to personally identify you. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
We would like to point out that data transmission over the Internet (e.g. when communicating by e-mail) may have security gaps. It is not possible to completely protect data from access by third parties.
The responsible body for data processing on this website is:
Tattoo Studio Souls and Sinners (a division of 
Square Mile GmbH) Square Mile GmbH
Gutleutstrasse 40
60329 Frankfurt/Main
Represented by: Julia Alexeeva
Commercial register: HRB 138866
Registry court: Frankfurt am Main District Court
Sales tax ID of Square Mile GmbH: is in application
telephone: +49 176 60019360
email: info@soulsandsinners.com
The responsible body is the natural or legal person who, alone or together with others, decides on the purposes and means of processing personal data (e.g. names, e-mail addresses, etc.).
Unless a specific storage period has been specified in this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you make a legitimate request for deletion or withdraw your consent to data processing, your data will be deleted unless we have any other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, the deletion will take place after these reasons cease to apply.
If you have consented to data processing, we process your personal data on the basis of Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, provided that special categories of data are processed in accordance with Article 9 (1) GDPR. In the event of express consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Article 49 (1) (a) GDPR. If you have consented to the storage of cookies or access to information on your device (e.g. via device fingerprinting), data processing is also carried out on the basis of Section 25 (1) TTDSG. The consent can be withdrawn at any time. If your data is necessary to fulfill a contract or to carry out pre-contractual measures, we process your data on the basis of Article 6 (1) (b) GDPR. We also process your data insofar as it is necessary to fulfill a legal obligation on the basis of Art. 6 para. 1 lit. c DSGVO. Data processing may also be carried out on the basis of our legitimate interest in accordance with Art. 6 para. 1 lit. f DSGVO. The following paragraphs of this privacy policy provide information on the relevant legal bases in each individual case.
Among other things, we use tools from companies based in third countries that are not secure under data protection law and US tools whose providers are not certified according to the EU-US Data Privacy Framework (DPF). If these tools are active, your personal data may be transferred to and processed in these countries. We would like to point out that in third countries that are uncertain about data protection law, no level of data protection comparable with the EU can be guaranteed.
We would like to point out that, as a safe third country, the USA generally has a level of data protection comparable to the EU. Data transfer to the USA is permitted if the recipient is certified under the “EU-US Data Privacy Framework” (DPF) or has appropriate additional guarantees. Information on transfers to third countries, including data recipients, can be found in this privacy policy.
As part of our business activities, we work together with various external agencies. In some cases, this also requires the transfer of personal data to these external bodies. We only transfer personal data to external parties if this is necessary as part of contract performance, if we are legally obliged to do so (e.g. transfer of data to tax authorities), if we have a legitimate interest in the transfer of data in accordance with Article 6 (1) (f) GDPR, or if another legal basis allows the transfer of data. When using contract processors, we only share our customers' personal data on the basis of a valid contract for order processing. In the case of joint processing, a joint processing contract is concluded.
Many data processing processes are only possible with your express consent. You can withdraw consent that you have already given at any time. The legality of the data processing carried out up to the time of revocation remains unaffected by the revocation.
IF DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6 PARA. 1 LIT. E OR F DSGVO, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU FILE AN OBJECTION, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED, UNLESS WE CAN PROVE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING THAT OUTWEIGH YOUR INTERESTS, RIGHTS AND FREEDOMS OR THE PROCESSING SERVES TO ASSERT, EXERCISE OR DEFEND LEGAL CLAIMS (OBJECTION UNDER ARTICLE 21 (1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH ADVERTISING; THIS ALSO APPLIES TO PROFILING, INSOFAR AS IT IS ASSOCIATED WITH SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL THEN NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION IN ACCORDANCE WITH ARTICLE 21 (2) GDPR).
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement. The right to lodge a complaint is without prejudice to other administrative or judicial remedies.
You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to yourself or to a third party in a common, machine-readable format. If you request the direct transfer of data to another person responsible, this will only be done insofar as it is technically feasible.
Within the framework of the applicable legal provisions, you have the right to receive information free of charge about your stored personal data, its origin and recipients and the purpose of data processing and, if applicable, a right to correct or delete this data. You can contact us at any time about this and if you have any further questions on the subject of personal data.
You have the right to request that the processing of your personal data be restricted. You can contact us for this at any time. The right to restrict processing exists in the following cases:
If you have restricted the processing of your personal data, this data — apart from storage — may only be processed with your consent or to assert, exercise or defend legal claims or to protect the rights of another natural or legal person or for reasons of an important public interest of the European Union or a Member State.
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection when the browser's address line changes from “http://” to “https://” and by the lock icon in your browser line.
If SSL or TLS encryption is activated, the data that you submit to us cannot be read by third parties.
If, after the conclusion of a paid contract, there is an obligation to provide us with your payment details (e.g. account number in case of direct debit authorization), this data is required to process payment.
Payment transactions using common means of payment (Visa/MasterCard, direct debit) are made exclusively via an encrypted SSL or TLS connection. You can recognize an encrypted connection when the browser's address line changes from “http://” to “https://” and by the lock icon in your browser line.
With encrypted communication, your payment details that you submit to us cannot be read by third parties.
Our websites use so-called “cookies.” Cookies are small data packets and do not cause any damage to your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are automatically deleted at the end of your visit. Permanent cookies remain stored on your device until you delete them yourself or until they are automatically deleted by your web browser.
Cookies can come from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies make it possible to integrate certain services from third-party companies within websites (e.g. cookies to process payment services).
Cookies have various functions. Numerous cookies are technically necessary, as certain website functions would not work without them (e.g. the shopping cart function or the display of videos). Other cookies can be used to evaluate user behavior or for advertising purposes.
Cookies that are necessary to carry out the electronic communication process, to provide certain functions requested by you (e.g. for the shopping cart function) or to optimize the website (e.g. cookies to measure the web audience) (necessary cookies) are stored on the basis of Article 6 (1) (f) GDPR, unless another legal basis is provided. The website operator has a legitimate interest in storing necessary cookies for the technically error-free and optimized provision of its services. If consent to the storage of cookies and comparable recognition technologies has been requested, processing is carried out exclusively on the basis of this consent (Art. 6 para. 1 lit. a DSGVO and § 25 para. 1 TTDSG); consent can be withdrawn at any time.
You can set your browser so that you are informed when cookies are set and only allow cookies in individual cases, exclude the acceptance of cookies for specific cases or in general, and activate the automatic deletion of cookies when you close the browser. If cookies are deactivated, the functionality of this website may be limited.
You can find out which cookies and services are used on this website in this privacy policy.
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
This data is not combined with other data sources.
This data is collected on the basis of Article 6 (1) (f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of his website — for this purpose, the server log files must be collected.
If you contact us by email, telephone or fax, your request, including all resulting personal data (name, request), will be stored and processed by us for the purpose of processing your request. We will not share this data without your consent.
This data is processed on the basis of Article 6 (1) (b) GDPR, provided that your request is related to the fulfilment of a contract or is necessary to carry out pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 para. 1 lit. f DSGVO) or on your consent (Art. 6 para. 1 lit. a GDPR) if this has been requested; consent can be withdrawn at any time.
The data you send us via contact requests will remain with us until you request us to delete it, revoke your consent to store it or the purpose for storing the data no longer applies (e.g. after your request has been processed). Mandatory legal provisions — in particular statutory retention periods — remain unaffected.
To communicate with our customers and other third parties, we use, among other things, the WhatsApp instant messaging service. The provider is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
Communication is carried out using end-to-end encryption (peer-to-peer), which prevents WhatsApp or other third parties from gaining access to the communication content. However, WhatsApp has access to metadata that is created during the communication process (e.g. sender, recipient, and time). We would also like to point out that WhatsApp, according to its own statement, shares personal data of its users with its parent company Meta based in the USA. Further details on data processing can be found in WhatsApp's privacy policy at: https://www.whatsapp.com/legal/#privacy-policy.
WhatsApp is used on the basis of our legitimate interest in communicating as quickly and effectively as possible with customers, interested parties and other business and contractual partners (Art. 6 para. 1 lit. f GDPR). If a corresponding consent has been requested, data processing is carried out exclusively on the basis of consent; this can be withdrawn at any time with effect for the future.
The communication content exchanged between you and us on WhatsApp will remain with us until you request us to delete it, revoke your consent to store it, or the purpose for storing the data no longer applies (e.g. after your request has been processed). Mandatory legal provisions — in particular retention periods — remain unaffected.
The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA, which is intended to ensure compliance with European data protection standards when processing data in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. For more information, please contact the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt00000011sfnAAA&status=Active
We use WhatsApp in the “WhatsApp Business” variant.
Data transmission to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.whatsapp.com/legal/business-data-transfer-addendum.
We have set up our WhatsApp accounts so that there is no automatic data reconciliation with the address book on the smartphones in use.
We have concluded an order processing contract (AVV) with the above-mentioned provider.
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager is a tool that we use to manage website tags via an interface. The tag manager itself (which implements the tags) does not process any personal user data. The tool triggers other tags, which in turn may collect data. However, Google Tag Manager does not access this data.
Google Tag Manager is used in the interest of easy and technical administration of the tools used on our website. The legal basis is Article 6 (1) (f) GDPR. If a corresponding consent has been requested (e.g. consent to the storage of cookies), processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a DSGVO and § 25 para. 1 TTDSG; consent can be withdrawn at any time.
You can find more information about data protection at Google here:
https://policies.google.com/privacy
This website uses Google Analytics, a web analysis service provided by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics allows us to analyze the behavior of visitors to our website. In doing so, we receive usage data such as page views, time spent, devices and browsers used, and approximate geographical origin. This data is collected pseudonymized and made available to us in the form of reports. We only use Google Analytics with activated IP anonymization. This will abbreviate your IP address by Google within the EU.
Google Analytics is only used with your express consent via our cookie banner (Art. 6 para. 1 lit. a DSGVO and § 25 para. 1 TTDSG). You can withdraw your consent at any time.
The information collected by Google is usually transferred to a Google server in the USA and stored there. Data transmission to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:
https://privacy.google.com/businesses/controllerterms/mccs/
Google is also certified under the EU-US Data Privacy Framework (DPF) and is committed to complying with European data protection standards. You can find more information here:
https://www.dataprivacyframework.gov/s/
For more information on how Google Analytics handles user data, please see Google's privacy policy:
https://support.google.com/analytics/answer/6004245