Home / Data protection
Privacy policy
In short: this website sets no cookies, uses no advertising services and loads nothing from third-party servers. Our own visitor statistics on our own server only record your visit in detail if you agree – otherwise we merely count page views anonymously.
1. Controller
Treppen Sonsala, owner Marek Sonsala
Lohmühlwiesen 14, 76356 Weingarten (Baden), Germany
Phone: +49 173 520 11 34 · E-mail: info@treppen-sonsala.de
2. Privacy settings and visitor statistics
We run our own visitor statistics. They run exclusively on our web server; no data is passed to Google, advertising networks or other third parties, and we set no cookies. On your first visit we ask whether you agree to the more detailed statistics. "Reject" and "Accept" are equal; the website works fully either way.
Without consent (and as long as you have not decided) we only count anonymously which page was opened, in which language, which website you came from (only its address) and the type of device (smartphone, tablet or computer) from the browser identification that is transmitted anyway. No identifier is assigned, nothing is stored on your device and no IP address is stored. The legal basis is our legitimate interest in a website that meets our visitors’ needs (Art. 6(1)(f) GDPR).
With your consent we store a random visitor identifier in your browser’s local storage (with no link to your person) and record your visit step by step: pages viewed and time spent, how far you scrolled, which photos and projects you opened, your choices in the stair planner and configurator, clicks on phone, e-mail, buttons and external links, videos played, screen size, browser and operating system, and the website you came from. This also shows us whether you return. If you send a request, it is linked to your visitor identifier so we can see which pages led to the request. Your IP address is not stored. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG).
We store your decision itself in your browser so the notice does not appear on every page (technically necessary, Section 25(2) TDDDG); after twelve months we ask again. Statistics data is deleted automatically after 13 months. You can withdraw your consent at any time with effect for the future – via the "Privacy settings" link at the bottom of every page; the visitor identifier in your browser is then deleted as well.
3. Providing the website (server log files)
When you open a page, our web server processes technically necessary data: IP address, date and time, the page requested, the amount of data transferred, the previously visited page (referrer) and your browser and operating system. This is necessary to deliver the website and protect it against attacks (Art. 6 (1) (f) GDPR). The log files are deleted after a short time unless they are needed to investigate a security incident. The website is hosted by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany; a data processing agreement (Art. 28 GDPR) is in place with the provider.
4. Request form
When you send us a request via the form, we process your details: name, phone number, postcode/town/country, the type of stair you are interested in, your message and – voluntarily – your e-mail address and photos of your stairwell. The photos are reduced in size in your browser before sending. The data is transmitted to our server in encrypted form and stored there, encrypted, in our own database (AES-256). Only we have access, via a login protected by password and two-factor code; by e-mail we only receive a notice without your data.
The purpose is to handle your request and prepare a quote (Art. 6 (1) (b) GDPR). To protect against automated mass requests (spam), the server stores a pseudonymised check value (hash) of your IP address for at most one hour in order to limit the number of requests (Art. 6 (1) (f) GDPR). We delete your request once it has been dealt with; if an order is placed, we keep the documents for the statutory periods (commercial and tax law, up to 10 years).
To protect against attacks, the server automatically checks all entries and photos for malicious code (security filter). Photos are re-encoded in the process; embedded additional data such as the location where they were taken is removed. If an attack attempt is blocked, we store the time, reason, browser identification and a shortened IP address (the last part removed) for at most 13 months in order to detect and repel attacks (Art. 6(1)(f) GDPR). For each request received, the statistics only count that a request came in and the chosen stair type – without name or contact details.
Appointment booking: if you request an appointment on the "Book an appointment" page, we process the kind of appointment, the day and time, your name, your phone number, for an on-site measurement the address of the project and – optionally – your e-mail address and your message. As with the request form, the details are stored encrypted in our own database. If you give an e-mail address, we send you a confirmation of receipt and later the confirmation or cancellation of the appointment. The purpose is to arrange and hold the appointment (Art. 6 (1) (b) GDPR). We delete the details once the appointment has taken place and no further enquiry results from it.
Protection against spam robots (Cloudflare Turnstile): to prevent our request and appointment forms from being misused by automated programs, we use the Turnstile service of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Turnstile is only loaded once you start filling in one of these forms – merely reading the website does not establish a connection to Cloudflare. Cloudflare checks technical characteristics of your browser and your IP address to determine whether a human is filling in the form; no advertising cookies are set and Cloudflare does not receive your form details. The legal basis is our legitimate interest in protecting our website against misuse (Art. 6 (1) (f) GDPR, Section 25 (2) No. 2 TDDDG). Cloudflare is certified under the EU-US Data Privacy Framework. More information: https://www.cloudflare.com/privacypolicy/
5. Contact by e-mail or phone
If you call or write to us, we process your details to deal with your enquiry (Art. 6 (1) (b) GDPR for enquiries about an order, otherwise (f)). Deletion works the same way as for the request form.
6. Stair planner and "In my room"
The stair planner and the "In my room" view calculate and draw entirely in your browser. A photo you choose there stays on your device; as an image or PDF you only save it on your own device. We only receive your selection if you click "Request a quote" yourself – it is then filled into the request form, which you can check and change before sending.
Sharing the room photo via the link (optional): only if you expressly tick "Also show the photo via link & QR code" when saving as PDF do we send the room picture (your photo with the drawn-in stair) to our server. It is checked, saved again without additional data such as the location and stored encrypted (AES-256) on our server in Germany. Only those who know the link or QR code can see it; the address is random and cannot be guessed. The photo is deleted automatically after 90 days; before that you can delete it at any time with "Delete the photo from the link" in the stair planner or ask us to delete it. The legal basis is your consent (Art. 6 (1) (a) GDPR), which you can withdraw at any time.
7. Google Maps and Google reviews
On the home page and the contact page we first show our location only as a drawing – no connection to Google is made. Only when you click "Load map" is the map from Google Maps (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) embedded. Your browser then transmits data such as your IP address to Google, possibly also to the USA; the legal basis is your consent given by the click (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). The "Plan route" and "Open in Google Maps" links likewise only lead to Google when clicked. Google’s privacy policy applies.
On the home page we show reviews from our Google business profile. Our server retrieves them via Google's official interface (Google Maps Platform) when you reach the reviews area and does not store them; our server does not transmit any data about you to Google. The authors' profile pictures are also loaded by our server and only passed through – your browser does not connect to Google. Only when you click on an author's name, "View on Google Maps", "All reviews on Google" or "Write a review" do you open a Google page; Google's privacy policy then applies (https://policies.google.com/privacy).
8. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw any consent at any time with effect for the future (Art. 7 (3)). Simply write to us at info@treppen-sonsala.de.
You can also lodge a complaint with a data protection supervisory authority, for example the one responsible for us: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
9. Encryption
This website uses SSL/TLS encryption. You can recognise it by the padlock symbol and "https://" in your browser's address bar.
Last updated: October 2026. This is a translation; the German version is legally binding.
