Skip to content
SoftDarya LogoSoftDarya

Legal

Privacy Policy

Last updated: August 25, 2026

At SoftDarya, your privacy matters. This Privacy Policy explains how we collect and process personal data and which rights you have under the General Data Protection Regulation (GDPR).

1. Controller

The controller responsible for the processing of personal data on this platform pursuant to Art. 4 No. 7 GDPR is:

Hasan Koohgard

c/o flexdienst — #21953

Kurt-Schumacher-Straße 74, 67663 Kaiserslautern, Germany

Email: soft.darya.2026@gmail.com

2. General principles of data processing

The protection of your personal data is of great importance to us. We process the personal data of our users only to the extent necessary to provide a functional platform as well as our content and services.

Processing is carried out on the basis of the General Data Protection Regulation (GDPR) and the German Telecommunication and Digital Services Data Protection Act (TDDDG).

The legal bases are in particular:

  • Art. 6(1)(a) GDPR — Consent
  • Art. 6(1)(b) GDPR — Performance of a contract or pre-contractual measures
  • Art. 6(1)(f) GDPR — Our legitimate interests

3. Provision of the platform and server log files (Hetzner hosting)

Our platform is hosted on servers of Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany).

Each time you visit our website, our system automatically collects data and temporarily stores it in so-called server log files:

  • IP address of the accessing device
  • Date and time of access
  • Name and URL of the retrieved file
  • Website from which the access originates (referrer URL)
  • Browser used and, where applicable, the operating system

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the stability, functionality and IT security of our servers).

Order processing: We have concluded a data processing agreement with Hetzner pursuant to Art. 28 GDPR.

4. Data collection for user accounts, registration and profiles

On SoftDarya we distinguish between two groups of users:

General users / Searchers

When you create a user account, we process your email address, your name and your password (only in encrypted or hashed form).

Providers

When you create or claim a service or business profile, we additionally process the information you provide (e.g. company name, address, telephone number, description text, categories and contact details).

Legal basis: Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures).

5. Special deletion concept and storage period (6-week period)

To give you full control over your data and to avoid accidental deletion, we use a two-stage deletion process:

1. Deactivation (soft delete)

When you delete or deactivate your account, your profile and data are immediately made invisible to the public. Your account remains in an inactive status for up to 6 weeks. Within this period you can log in again and restore your account.

2. Immediate permanent deletion via the portal

After a soft delete, you can at any time request an immediate and permanent deletion of your data via your user portal. In this case, your personal account data is irrevocably deleted from our active database without observing the 6-week period.

Regular permanent deletion after the period expires

If you do not request immediate deletion, the relevant personal account data is automatically deleted from our active database once the 6-week period has elapsed. Backup files are also deleted after the regular backup rotation, unless statutory retention obligations apply.

Exception – statutory retention obligations

If paid services are used in the future, invoice-relevant data is retained for up to 10 years to comply with tax and commercial-law retention obligations (in particular § 147 AO and § 257 HGB). This data is stored separately and deleted after the statutory periods.

6. Reviews, profile content and publicity

Reviews submitted by users as well as publicly accessible provider profile information are stored on the platform and made visible to other visitors.

Legal basis: Art. 6(1)(a) GDPR (consent through publication) or Art. 6(1)(f) GDPR (legitimate interest in operating a transparent review and search service).

7. Contact requests and email notifications

Contact requests

When you send a request to a provider through SoftDarya, we forward the data you enter to the respective provider so they can contact you.

Legal basis: Art. 6(1)(b) GDPR.

Transactional emails

As part of using the platform, we send system-related emails (e.g. confirmation of registration, notifications about new requests or password resets).

Legal basis: Art. 6(1)(b) GDPR. You can adjust your notification settings in your user account.

8. Cookies, consents and local storage

We use technically necessary cookies that are required for the operation of the platform:

sessionid

for login and session management (storage duration: up to 30 days)

csrftoken

for protection against cross-site request forgery (storage duration: up to one year)

Legal basis: § 25(2) TDDDG in conjunction with Art. 6(1)(f) GDPR (legitimate interest in the secure operation of the platform).

Local storage

We use local storage solely to store your consent decision regarding optional technologies. The stored consent decision allows us to take your choice into account on later visits. If you delete cookies and browser storage, the previously stored consent decision can no longer be recognised.

Further information on cookies and local storage can be found in our Cookie Policy.

9. Map services

To display provider locations on interactive maps we use Leaflet. The underlying map data or map tiles are loaded from the following services:

  • Official OpenStreetMap tile server: tile.openstreetmap.org
  • CARTO: basemaps.cartocdn.com (only on the search page; in case of an error there is a fallback to OpenStreetMap)
  • For converting addresses into coordinates (geocoding) the service Nominatim at nominatim.openstreetmap.org is used.

The map function is only activated after your explicit consent via our cookie banner (§ 25(1) TDDDG, Art. 6(1)(a) GDPR).

When the map is activated, your IP address is transmitted to the aforementioned tile servers and to Nominatim. This constitutes a transfer of data to third parties.

Note: Google Maps is not embedded in SoftDarya. External navigation to Google Maps (“Take me there” / “Start route”) is only on a voluntary basis by the user and is then subject to Google’s privacy policy. SoftDarya does not transmit the user’s current live location to Google.

10. Reach measurement with Plausible Analytics

We use Plausible Analytics for a privacy-friendly, cookieless evaluation of the use of our platform.

No cookies are set and no permanent personal tracking identifiers are stored. The IP address is processed in anonymised form.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in optimising and further developing our platform).

Note: Google Analytics and Google Ads are currently not active.

11. Payment processing

SoftDarya currently does not offer any paid features. No payment data is therefore processed.

Should we offer paid features in the future, we will update this Privacy Policy accordingly.

12. Your rights under the GDPR

You have the following rights regarding the personal data concerning you:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (“right to be forgotten”) (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to the processing (Art. 21 GDPR)
  • Right to withdraw consent: consents you have given can be withdrawn at any time with effect for the future (Art. 7(3) GDPR)

To exercise your rights, please contact us by email: soft.darya.2026@gmail.com

13. Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement.

14. Changes to this Privacy Policy

We may update this Privacy Policy when our technical functions, services used or legal requirements change.

The current version will always be published on this page. The date of the last update can be found at the beginning of this policy.

15. Contact

If you have any questions about data protection or the processing of your personal data, please contact the controller named in point 1.