Privacy notice
This notice explains how we process personal data under the EU General Data Protection Regulation (GDPR). It has three parts, depending on how you came into contact with us:
Your rights, which apply to all three, are listed in section D.
Who is responsible (controller)
Soerensen Digital, Carl Soerensen
Steinberg 185, 24107 Kiel, Germany
Email: [email protected]
For any privacy question or request, write to the email address above.
A. Website visitors
Server log files
When you open this website, the server automatically records: your IP address, date and time of the request, the page requested, the referring page, the HTTP status code, the amount of data transferred, and your browser and operating system (user agent).
- Purpose: delivering the website, keeping it secure and stable, and investigating errors or attacks.
- Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the website.
- Retention: log files are deleted after 7 days, unless a specific entry is needed to investigate a security incident, in which case it is kept until the investigation ends.
- Recipient: our hosting provider, Cloudflare, Inc. (Cloudflare Pages; EU Standard Contractual Clauses and EU-US Data Privacy Framework), as our processor under Art. 28 GDPR.
No cookies, tracking or third-party content
This website sets no cookies, stores nothing on your device, uses no analytics or tracking tools, and loads no fonts, scripts or other content from third parties.
When you email us
If you email us, we process your email address, name and whatever you write to us, in order to answer you. Legal basis: Art. 6(1)(b) GDPR if your message relates to a possible order, otherwise Art. 6(1)(f) GDPR (our legitimate interest in answering enquiries). We delete the correspondence once the matter is dealt with, unless we must keep it under commercial or tax law (see section C).
Links to checkout and the intake form
The order buttons take you to a checkout page run by Stripe. Stripe processes the payment data you enter there; see Stripe's privacy policy. After payment you are taken to our intake form, which is hosted by Tally BV (Belgium) on our behalf (see section C).
Free-scan form on our website
If you request a free scan, we process the store address, your email address and, if you provide it, a deadline you mention. Purpose: to scan your store's public pages and email you the result, and to reply to you about our service (Art. 6(1)(b) GDPR, steps at your request, and Art. 6(1)(f) GDPR). The request is stored with our hosting provider (Cloudflare) and deleted automatically after 180 days. To limit abuse, we keep a shortened, hashed form of your IP address for 24 hours; it cannot identify you on its own.
B. Business contacts we email about our services
This section is the information we are required to give under Art. 14 GDPR when we collect personal data from sources other than you. If we emailed you about our Shopify accessibility service, it applies to you.
Your right to object: you can object at any time, free of charge and without giving reasons, to our use of your data for direct marketing (Art. 21(2) GDPR). Your objection takes effect immediately. Reply “no” or “stop” to any of our emails, or write to [email protected]. We will not contact you again.
What data we process
- your name, role and business email address, and the name of your business;
- the web address of your online store, and the results of an automated accessibility scan of its public pages;
- where applicable, information from public court records showing that your business was named as a defendant in a lawsuit under Title III of the Americans with Disabilities Act: the court, case number, filing date and names of the parties;
- a record of our emails to you and whether you replied or objected.
Where the data comes from
From publicly accessible sources only: business contact details published by your business or in public business listings (where applicable found or verified through a B2B contact-data provider such as Hunter.io), public court records (US federal court dockets), and the public pages of your online store.
Why we process it, and on what legal basis
Purpose: to contact you, as a business, about a service that is relevant to your store; to prepare a free automated scan snapshot if you ask for one; to handle your replies; and to respect your objection if you make one.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is direct marketing of our services to businesses (see Recital 47 GDPR). We consider that your interests do not override ours because: we use business contact details only; the message relates to your business's public storefront and a matter of public record; we send a short sequence of no more than three emails; each email explains how to opt out; and objections take effect immediately.
Who receives the data
We do not sell or rent your data. It is processed on our behalf by our email provider, Google (Google Workspace, Google Cloud EMEA Ltd., Ireland), and Instantly (outreach email sending, Instantly Inc., USA, Standard Contractual Clauses) and Anthropic (AI-assisted drafting and code work, Anthropic PBC, USA, Standard Contractual Clauses), as processors under Art. 28 GDPR.
Transfers outside the EU
Some of our providers may process data in the United States. Where they do, the transfer relies on the EU-US Data Privacy Framework (for certified providers) or on the EU Standard Contractual Clauses. You can request a copy of the relevant safeguards from us.
How long we keep it
- If you don't reply, we delete your data no later than 6 months after our last email.
- If you object, we delete your data but keep your email address and store domain on a suppression list, so we can make sure you are not contacted again. Legal basis: Art. 6(1)(c) and (f) GDPR.
- If you become a client, section C applies.
Other information
You are not obliged to provide us with any data. We do not make automated decisions about you that have legal or similarly significant effects (Art. 22 GDPR).
C. Clients
What data we process
- names, roles and business contact details of your contact persons;
- billing details (business name, address, tax ID) and payment status;
- your intake form answers: store address, Shopify plan, theme and apps, who publishes the theme, priorities and brand constraints;
- if you choose to share it: whether you received a lawsuit or demand letter, related deadline dates, and your counsel's contact details;
- our correspondence with you, and the account details of our Shopify collaborator access to your store.
Purposes and legal bases
- Performing our contract with you, including the fix window and any monitoring plan: Art. 6(1)(b) GDPR.
- Invoicing, bookkeeping and keeping records required by law: Art. 6(1)(c) GDPR.
- Establishing, exercising or defending legal claims: Art. 6(1)(f) GDPR.
If you give us your counsel's contact details, we use them only to answer technical questions you ask us to answer.
Payments
Payments are processed by Stripe. You enter card details directly on Stripe's checkout page; we never see your full card number. Stripe acts as an independent controller for payment processing and fraud prevention; see Stripe's privacy policy.
Access to your store
We request only the Shopify collaborator permissions needed for the agreed scope and do not request access to orders or customer data. If we nevertheless process personal data on your behalf, we do so only on your instructions and will enter into a data processing agreement under Art. 28 GDPR on request.
Recipients
Stripe (payments), Tally BV (Belgium) (intake form), Google (Google Workspace, Google Cloud EMEA Ltd., Ireland) (email), Instantly (outreach email sending, Instantly Inc., USA, Standard Contractual Clauses) and Anthropic (AI-assisted drafting and code work, Anthropic PBC, USA, Standard Contractual Clauses), and our tax adviser where needed for bookkeeping. Transfers outside the EU are safeguarded as described in section B.
How long we keep it
- Invoices, accounting records and business correspondence: for the periods required by German commercial and tax law (currently up to 10 years for certain accounting records).
- Intake answers about lawsuits, deadlines and counsel: deleted 12 months after the order, fix window or monitoring plan ends, whichever is last, unless we need them to establish or defend legal claims.
- Everything else: deleted when no longer needed for the contract, unless a legal retention period applies.
Providing the data needed to perform the contract is necessary for the contract; without it we cannot deliver the service.
D. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased (Art. 17);
- have processing restricted (Art. 18);
- receive your data in a portable format (Art. 20);
- object to processing based on Art. 6(1)(f), on grounds relating to your particular situation, and to direct marketing at any time without giving reasons (Art. 21);
- lodge a complaint with a data protection supervisory authority (Art. 77). The authority responsible for us is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, Germany. You can also contact the authority where you live or work, if that is in the EU.
To exercise your rights, email [email protected]. We will answer within one month.
Security
We protect personal data with appropriate technical and organisational measures, including encrypted connections and restricted access to our accounts.
Changes to this notice
We will update this notice when our processing changes. The date at the top shows the current version.