1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) for the processing operations carried out on our own behalf and described in this Privacy Policy is Robert Kraft, trading under “SOF Solutions Hub” and “SOF AI”, Schönefelder Chaussee 221, 12524 Berlin, Germany. You can contact us at contact@sofsolutionshub.com and by telephone at +49 160 6119180.
Where SOF AI processes personal data contained in Customer Content exclusively on behalf of a business customer, the respective business customer generally acts as controller and SOF AI as processor. Details are governed by a data processing agreement.
2. Scope
This Privacy Policy applies to the cloud-based SOF AI software platform, in particular the login area, dashboard, user accounts, projects, workspaces, content plans, research and generation functions, and product-related support and billing processes.
Additional privacy information may apply to purely editorial, affiliate or other website content of SOF Solutions Hub. This Privacy Policy concerns the SOF AI product area.
3. Data We Process
Depending on how SOF AI is used, we process in particular master and contact data, account and user identifiers, authentication and session data, project and workspace data, content plans, keywords, URLs, texts, files, instructions and other Inputs, research context, generated content and Outputs, support communications, and technical connection, security and log data.
Customers generally decide themselves which content they enter into SOF AI. Personal data of third parties may be transmitted only where there is a sufficient legal basis. Special categories of personal data within the meaning of Art. 9 GDPR should be processed only where this is necessary for the relevant purpose, suitable for the function used and legally permissible.
4. User Account, Login and Authentication
To create and use an SOF AI account, we process the data required for registration, login, account administration, authorization checks and securing access. This includes in particular user and account identifiers, contact data and technical authentication and session information.
Processing is carried out for performance of the user agreement or to take steps prior to entering into the agreement. Security-related processing is additionally carried out, where necessary, on the basis of our legitimate interest in preventing misuse, unauthorized access and technical attacks.
5. Strictly Necessary Cookies and Session Storage
In the SOF AI product area, we use strictly necessary cookies and comparable session mechanisms for login, session validation, CSRF/XSRF protection and security. In addition, the browser session storage (sessionStorage) may be used for session-related states.
These mechanisms are necessary to provide and secure the service expressly requested. In the SOF AI product area, we currently do not use analytics or marketing cookies, fingerprinting, personalized advertising or retargeting technologies.
6. Projects, Customer Content and Generated Outputs
SOF AI processes project information, keywords, URLs, research context, texts, files, instructions and other Inputs to the extent necessary for the functions selected by the user. This may generate analyses, content plans, texts, metadata, quality checks and other Outputs.
Processing is generally carried out to perform the user agreement. For users acting on behalf of a company, processing may additionally be based on our legitimate interest in providing and administering the business account.
SOF AI does not use Customer Content to train its own generative models. Where external AI services are used, their contractual data processing terms additionally apply.
7. External AI and Research Services
For individual functions, SOF AI may use external AI and research services. Depending on the function, research mode, model routing and availability, these may include in particular OpenAI, Anthropic/Claude, Google Gemini and Perplexity. Not every request is transmitted to every provider.
Only data required for the respective processing step is transmitted to these services. This may include Inputs, selected project information, research context, technical instructions and required metadata.
For production processing, we use business API offerings and the applicable data processing agreements. The providers currently used, their role under data protection law and the respective purpose are listed in our “Service Providers and Subprocessors” list. Where SOF AI acts as processor for a business customer, the providers designated there as subprocessors form part of the processing on behalf of that customer.
8. Hosting and Infrastructure
The SOF AI platform is operated on server infrastructure of IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. The VPS currently used for SOF AI is assigned to the Europe data center region in the IONOS Cloud Panel.
IONOS processes the data stored on the infrastructure as a processor on the basis of a data processing agreement.
9. Payment Processing via Paddle
For paid subscriptions, we use Paddle as Merchant of Record and authorized reseller. During checkout, Paddle processes in particular the buyer and payment information required for payment, invoicing, tax calculation, fraud prevention and order processing.
As part of order and contract processing, Paddle may provide us in particular with name, address, email address, purchase history and transaction-related information. In SOF AI’s own systems, we store only the information required for account activation, plan assignment, subscription status, contract administration, support and allocation of transactions. SOF AI does not store payment instrument data such as complete credit card or bank details.
Paddle processes buyer and payment data for its own purposes in its role as Merchant of Record and, in this respect, acts as an independent controller. SOF AI does not use Paddle as a subprocessor for Customer Content.
10. Support and Communication
If you contact us by email or through a support function, we process the contact data you provide, the content of your request and the account and technical information required to handle it.
Processing serves to handle your request and perform the contract and, where necessary, is based on our legitimate interest in efficient support, error analysis and improving operational security.
11. Security and Log Data
To secure accounts, sessions, interfaces and systems, we process technical security and log data. This may include in particular IP addresses, timestamps, authentication events, technical identifiers, error messages and security-relevant events.
Login, security and comparable log data are generally retained for up to 90 days. Longer retention takes place only where this is necessary to investigate a specific security incident, prevent or pursue misuse, defend legal claims or comply with statutory obligations.
12. Retention, Deletion and Backups
We store personal data only for as long as necessary for the respective purpose or for as long as statutory retention obligations apply. Account and contract data are generally processed for the duration of the contractual or account relationship and thereafter retained only to the extent necessary to comply with legal obligations or to establish, exercise or defend legal claims.
Project, article, research and other Customer Content is generally stored for as long as it is required for the respective account, project or function requested by the Customer. When content or accounts are deleted, the relevant data is removed from active systems unless conflicting statutory requirements or compelling technical reasons apply.
Automated system backups are subject to a rotating Restic retention schedule of 7 daily, 4 weekly and 12 monthly backup snapshots. Deleted data may therefore still be contained in older backup snapshots until the relevant snapshot expires under this cycle. Backup data no longer required is removed as part of regular repository cleanup. Additional technical change or recovery backups are retained only for as long as required for operational security, troubleshooting or restoration.
13. Legal Bases
Depending on the processing activity, we rely in particular on Art. 6(1)(b) GDPR for performance of a contract and pre-contractual measures, Art. 6(1)(c) GDPR for legal obligations, and Art. 6(1)(f) GDPR for legitimate interests, in particular IT security, misuse prevention, support, error analysis and administration of business user accounts.
Where consent is required for optional processing, the processing is based on Art. 6(1)(a) GDPR. Access to information in end-user devices that is strictly necessary from a technical perspective is carried out without consent in accordance with Section 25(2) TDDDG, provided that the statutory requirements are met.
14. Recipients and Transfers to Third Countries
Personal data is transmitted to recipients only to the extent necessary to provide SOF AI, process the contract, secure the service or comply with legal obligations. These recipients include in particular hosting and infrastructure partners, external AI and research services, and payment and billing service providers. An up-to-date overview of the main providers and their roles is contained in the “Service Providers and Subprocessors” list.
For individual external AI and research services, processing may take place outside the European Economic Area. Where no adequacy decision applies to such a transfer, appropriate safeguards are used, in particular the Standard Contractual Clauses approved by the European Commission, to the extent required under the respective data processing terms.
15. Your Data Protection Rights
Subject to the statutory requirements, you have in particular the right to obtain access to your personal data, rectification of inaccurate data, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. You may withdraw consent you have given at any time with effect for the future.
To exercise your rights, you may contact contact@sofsolutionshub.com. Where SOF AI processes personal data exclusively as processor for a business customer, it may be necessary to forward your request to, or coordinate it with, the respective business customer acting as controller.
16. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority concerning the processing of your personal data. For SOF AI’s place of business, the competent authority is in particular the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), Alt-Moabit 59-61, 10555 Berlin. Your right to contact another supervisory authority competent under the applicable statutory provisions remains unaffected.
17. Changes to this Privacy Policy
We update this Privacy Policy when functions, data flows, service providers used or legal requirements change. The current version is made available in the SOF AI product area and, where applicable, on the product website.