01
Controller and scope
The controller responsible for processing personal data on sofoste.de within the meaning of the General Data Protection Regulation (GDPR) is:
Stephane Sob FouodjiSofoste Music
Gießen, Germany
info@sofoste.de
The controller decides alone or jointly with others why and how personal data is processed. This policy applies to sofoste.de and not to independent websites reached through an external link.
02
Data when you visit the site
When the site is requested, the web server may record technical data needed to deliver the page and protect the service. Server log data can include:
- the requested page or file and transferred data volume
- date and time of the request
- IP address of the requesting device
- browser, operating system and device information
- referring page, if supplied by the browser
This processing supports secure, stable and efficient delivery of the site and the investigation of technical faults or abuse. The legal basis is the legitimate interest in operating and protecting this website under Art. 6(1)(f) GDPR.
The site uses TLS encryption. You can normally recognise an encrypted connection by the HTTPS address in your browser.
03
Hosting and technical recipients
The website, MariaDB database and outbound website mail are hosted or transmitted using services from STRATO. Data processed through the site can therefore be handled on STRATO systems to provide the contracted infrastructure.
STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin
Germany
STRATO acts as a processor where applicable and processes data only as needed to provide and secure the hosting and mail services. The hosting is used to fulfil requested services and in the legitimate interest of a reliable online presence under Art. 6(1)(b) and (f) GDPR.
05
Contact, lessons and human follow-up
The contact form stores your name, email address, selected subject, message, interface language, a one-way hash derived from the IP address and limited browser information. These details are used to receive the request, prevent abuse and answer you. Copies of replies and their delivery status can be stored with the request.
A lesson request can additionally contain a telephone number, instrument or service, format, experience, goals, preferred date and time, time zone and appointment status. A random private token enables the management link sent to you; keep this link confidential.
When a real conversation, collaboration or lesson develops, the protected administration area can contain a contact profile, communication status, follow-up date, private organisational notes and a do-not-contact marker. A student record and private pedagogical notes are created manually only when needed for actual lessons.
Messages and automatic acknowledgements are delivered through the configured STRATO mailbox. Your address is used as recipient or Reply-To as appropriate and is not added to a newsletter.
Processing is based on steps requested before or during a contract under Art. 6(1)(b) GDPR. For general communication, abuse prevention and orderly follow-up, it is based on the legitimate interests under Art. 6(1)(f) GDPR. If consent is requested for a separate purpose, Art. 6(1)(a) GDPR applies.
07
External media and links
Pages can offer players from YouTube (privacy-enhanced domain), Spotify, SoundCloud or Vimeo. No iframe and no connection to those providers is created merely by opening a Sofoste page.
Only when you press the relevant load button does your browser connect directly to the chosen provider. The provider can then receive technical data such as your IP address and page context and may use cookies or similar technologies. If you are signed in there, the visit may be associated with your account. Activation is voluntary and applies to that page load; reload or leave the page and do not reactivate the player to prevent a new connection.
Depending on the provider and your account settings, data may be processed outside the European Economic Area, including in the United States. The provider is responsible for its own processing. Your deliberate activation forms the basis for loading the player under Art. 6(1)(a) GDPR.
- YouTube / Google privacy policy
- SoundCloud privacy policy
- Spotify privacy policy
- Vimeo privacy policy
Apple Music, social channels, project pages, PayPal support and other external destinations are ordinary links. No connection is made until you follow one; the privacy rules of the destination then apply.
08
Your rights
Subject to the legal conditions, the GDPR gives you the following rights regarding your personal data:
- access to the personal data processed about you (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure of data where the requirements are met (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- notification of recipients about rectification, erasure or restriction (Art. 19 GDPR)
- data portability where applicable (Art. 20 GDPR)
- withdrawal of consent at any time for future processing (Art. 7(3) GDPR)
- a complaint to a competent supervisory authority (Art. 77 GDPR)
To exercise a right or ask a privacy question, write to info@sofoste.de.
When processing is based on legitimate interests, you may object for reasons arising from your particular situation under Art. 21 GDPR. Processing will then stop unless compelling legitimate grounds or legal claims require it to continue. You may object to direct marketing at any time; Sofoste does not currently operate an email marketing list.
09
Retention and updates
Personal data is kept only for as long as required for the relevant purpose, the handling of a request or lesson, security, legal claims and statutory retention duties. When no fixed period applies, necessity is reviewed according to the status and context of the relationship.
Data is erased or anonymised when its purpose no longer applies and no legal basis requires continued storage. A valid request for erasure, objection or withdrawal is considered together with any mandatory retention obligations.
This policy is updated when the site adds, removes or materially changes a service. The current date at the top identifies the published service inventory.
06
Journal comments
When you comment on a journal article, the chosen display name, comment text, article reference and submission time are stored. A session timestamp and honeypot field help reduce spam; the honeypot content is not retained as a public comment.
Comments are reviewed before publication. Once approved, the display name, text and publication date are visible publicly. Do not include confidential or third-party personal information in a comment.
The processing supports a moderated, constructive conversation and is based on the legitimate interest under Art. 6(1)(f) GDPR. You may request removal of your comment using the contact address above.