Legal
Privacy Policy
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
DW Selection UG (haftungsbeschränkt) Alt Heiligensee 26a, 13503 Berlin, Germany Managing Director: Dirk Wittke Commercial Register: Amtsgericht Charlottenburg, HRB 285812 B Email: hello@solacio.life
A data protection officer has not been appointed, as the statutory requirements for a mandatory appointment (Art. 37 GDPR, Section 38 BDSG) are not met.
2. Overview: what this policy covers
This privacy policy explains which personal data is processed when you visit and use the platform solacio.life, on which legal basis this takes place, how long data is stored, and which rights data subjects have. Solacio is a digital product: users name a personal burden, make a payment, and receive a personal document (the "Certificate of Release"). From every payment, DW Selection UG funds the work of nonprofit organizations.
3. Principles of data processing
We process personal data only to the extent necessary to provide the platform, process orders, and fulfill legal obligations (principle of data minimization, Art. 5(1)(c) GDPR). The platform uses no advertising cookies, no cross-site tracking, and no profiling. There is no automated decision-making within the meaning of Art. 22 GDPR.
4. Hosting and server log files (Vercel)
The platform is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. When the website is accessed, Vercel processes technically necessary data, in particular the IP address, date and time of access, the page accessed, browser type, and operating system (server log files).
The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in ensuring the stability and security of the website and in detecting and defending against misuse and attacks. A data processing agreement pursuant to Art. 28 GDPR is in place with Vercel. Where data is transferred to the USA, the transfer is based on Vercel's certification under the EU-US Data Privacy Framework, to the extent such certification exists at the time of the transfer, and additionally on the EU Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR).
5. Web analytics (Plausible)
For reach measurement, we use Plausible Analytics, a service of Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia (EU). Plausible works without cookies and without cross-device tracking. IP addresses are not stored; only aggregated usage statistics are collected (e.g. page views, referrers, device type) that cannot be attributed to any person.
The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in measuring reach and improving the service. Since no cookies are set and no information is stored on or read from the end device, consent under Section 25 TDDDG is not required.
6. Orders and payment processing (Stripe)
When you place an order, we process the email address of the person ordering, the selected product category, the payment amount, and transaction-related references. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR).
Mandatory and voluntary information: Required for the order are the email address (delivery of the document), the selection of a catalog category, and the payment details provided to Stripe. Without this information, the order cannot be carried out. All further information — in particular, for the gift function, the name of the gift recipient — is voluntary.
Payment processing is carried out by Stripe. For users in the European Economic Area, the contracting party is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland; in the course of this, data may be transferred to Stripe, Inc. in the USA. Payment data (e.g. card details) is collected and processed directly by Stripe; we do not receive complete payment data. With regard to fraud prevention, Stripe processes data on the basis of its legitimate interest in preventing fraudulent payments (Art. 6(1)(f) GDPR). The transfer to the USA is based on Stripe's certification under the EU-US Data Privacy Framework, to the extent such certification exists at the time of the transfer, and on Standard Contractual Clauses.
7. The selected burden: special categories of personal data
The core of the product is the selection of a personal burden from a catalog. Depending on the entry selected, this selection may allow inferences about special categories of personal data within the meaning of Art. 9(1) GDPR (for example, with a possible connection to health, philosophical beliefs, or sex life). As a precaution, we therefore treat the selection as a whole as processing of special categories.
The processing of the selected burden takes place exclusively on the basis of your explicit consent (Art. 9(2)(a) GDPR), which is obtained during the order process via a separate, non-preselected checkbox. The contract for the creation and delivery of the document in all other respects is based on Art. 6(1)(b) GDPR. Giving consent is voluntary. However, without it, the document cannot be created because the selected burden forms an essential part of the service. Consent may be withdrawn at any time with effect for the future (Art. 7(3) GDPR).
To minimize risk, a strict deletion concept applies: the selected burden is processed exclusively for the technical creation of the document, is not permanently associated with any account, is not used for profiling, and is not transferred to third parties — in particular, neither to the beneficiary organization nor to the payout service provider Pledge. Immediately after the document has been successfully created and the associated email has been sent, the data field containing the selected burden is deleted. Only accounting-relevant, non-sensitive transaction data is retained (amount, date, organization, receipt number, payment references).
8. Email delivery (Resend)
For sending transactional emails (in particular the document email as well as order and service messages), we use Resend, a service of Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA. The data processed comprises the email address, delivery metadata, and the message content.
The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). A data processing agreement is in place with Resend. Resend (Plus Five Five, Inc.) is certified under the EU-US Data Privacy Framework (DPF), including the UK Extension; the transfer to the USA is therefore based on the EU Commission's adequacy decision (Art. 45 GDPR) for as long as this certification remains valid. In addition, Resend's data processing agreement includes the EU Commission's Standard Contractual Clauses as a fallback safeguard.
9. Database and storage (Supabase)
Transaction data is stored in a database with Supabase, Inc. The project is hosted in the region Ireland (eu-west-1) within the European Union. A data processing agreement pursuant to Art. 28 GDPR is in place with Supabase. The legal basis for storage is the performance of the contract (Art. 6(1)(b) GDPR) and compliance with statutory retention obligations (Art. 6(1)(c) GDPR).
10. Funding of nonprofit organizations (Pledge)
From every payment, DW Selection UG funds the work of nonprofit organizations. The payout is processed via Pledgeling Technologies, Inc. ("Pledge"), USA. In this process, DW Selection UG acts exclusively as the donor of record. Pledge receives only the information required to carry out the payout of the contribution initiated by DW Selection UG (in particular the organization, the amount, and the UG's transaction reference). No personal data of customers is transferred to Pledge or to the beneficiary organizations — neither name nor email address nor the selected burden. Pledge does not receive any information that identifies the customer. Customers do not themselves become donors through their payment and do not receive a donation receipt.
11. Gift function
For an order placed as a gift, we additionally process the gift recipient's email address as provided by the person ordering and — depending on the option selected — the recipient's name. This data is used exclusively for the one-time delivery of the gift; no further use, in particular for advertising purposes, takes place.
The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in carrying out the delivery requested by the person ordering; at the same time, the transfer forms part of the performance of the contract with the person ordering. The gift recipient may object to further processing at any time; they are informed about the origin of their data in the gift email (Art. 14 GDPR).
12. Contact
When you contact us by email (hello@solacio.life), we process the data provided (email address, content of the message) to handle the inquiry. The legal basis is Art. 6(1)(b) GDPR insofar as the inquiry relates to an order or its initiation, and otherwise our legitimate interest in responding to inquiries (Art. 6(1)(f) GDPR). The data is deleted once the inquiry has been conclusively handled and no statutory retention obligations stand in the way. A contact form is not currently offered; should one be set up in the future, this policy will be amended accordingly.
13. Retention periods
The selected burden is deleted immediately after the document has been created (see Section 7). Invoice and accounting records are stored in accordance with statutory retention obligations and are deleted or anonymized after these expire. Server log files are automatically deleted by the hosting provider after a short time. We store contact inquiries only for as long as necessary to handle them.
14. Recipients and processors
Recipients of personal data are exclusively the service providers named in this policy (Vercel, Plausible, Stripe, Resend, Supabase), in each case on the basis of agreements pursuant to Art. 28 GDPR or — in the case of Stripe — in its own data protection responsibility for payment processing. No data is passed on for advertising purposes. No data is sold.
15. Transfers to third countries
Where service providers process data in the USA (Vercel, Stripe, Resend), the transfer is based on an adequacy decision pursuant to Art. 45 GDPR (EU-US Data Privacy Framework), to the extent the respective provider is certified under the EU-US Data Privacy Framework at the time of the transfer, and additionally on the EU Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR), including supplementary protective measures.
16. Your rights
Under the GDPR, you have the following rights:
- access to the personal data processed (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection to processing based on legitimate interests (Art. 21 GDPR)
- the right to withdraw any consent you have given, at any time, with effect for the future (Art. 7(3) GDPR)
To exercise any of these rights, a simple email to hello@solacio.life is sufficient. No login is required.
17. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for the controller is the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI). You may also contact the supervisory authority of your habitual residence.
18. Data security
All data is transmitted encrypted in line with the current state of the art. We take appropriate technical and organizational measures to protect personal data against unauthorized access, loss, and misuse, and restrict access to the necessary minimum. These measures are reviewed regularly and adapted to the state of the art.
19. Changes to this policy
We update this privacy policy when our processing or the legal situation changes. The version published on solacio.life applies.
Last updated: 19 July 2026