This information describes how personal data is processed when you visit our website or contact Sofastil Berlin.
1. Controller and contact
Yusef Nasser, Sofastil Berlin
Wilmersdorfer Straße 142, 10585 Berlin, Germany
Email: sofastilberlin@gmail.com
Telephone: +49 175 7009080
Use these contact details for privacy questions and to exercise your rights.
2. Website and hosting
The website is provided through ChatGPT Sites by OpenAI. Visits involve processing technically necessary connection data, particularly IP address, requested page, access time and browser and device information. This enables delivery of the website, stability and protection against misuse. Where we are responsible, the legal basis is Article 6(1)(f) GDPR; our legitimate interest is a secure, functioning website.
For users in the European Economic Area, OpenAI identifies OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland, as controller for the services described in its European privacy policy. Information on platform data, international processing and safeguards is available in OpenAI's European privacy policy. Any required ChatGPT sign-in is also subject to the platform's privacy information.
3. Direct fabric and furniture enquiries
‘Send enquiry’ submits your selection directly to our website. We process your name, telephone number, preferred contact method (phone or WhatsApp), fabrics, colours and quantities or furniture type, dimensions and other requirements, and destination country and postcode where provided. We also store an enquiry number, receipt time and processing status in the database provided by ChatGPT Sites. The website confirms submission only after successful storage. No customer account is created without sign-in. If signed in, we also associate the enquiry with your verified customer identifier and email address.
Stored enquiries are available to the website owner in a protected administration view, signed into through ChatGPT. Customers do not need to sign in or use an email app to submit a direct enquiry. If you choose WhatsApp for the reply, we contact you through that service; section 4 explains its data processing.
We use your details for advice and preparing quotations under Article 6(1)(b) GDPR. To prevent bulk enquiries, we also create a hash of the telephone number and use it with the receipt time to limit repeated submissions. The basis is our legitimate interest in secure operation under Article 6(1)(f) GDPR. Retention follows section 8. Further information on these legal bases is in Article 6 GDPR.
3a. Optional sign-in with Google or Apple
You may sign in with your Google account. The first successful sign-in creates a customer account through Supabase Auth. We load Google sign-in only when you choose ‘Sign in with Google’. Google then receives technically necessary connection data such as your IP address and browser information. After your confirmation we receive a unique identifier, email address and profile details supplied by Google, particularly your name; any supplied profile pictures are not displayed on our website. We do not receive your Google password or request access to your inbox, contacts or Google Drive files.
When Apple sign-in is available, you can sign in with your Apple Account. Apple loads only after you choose it. After your confirmation, Supabase Auth verifies the sign-in issued by Apple. We receive a unique identifier and your email address; if you choose “Hide My Email”, this may be a relay address provided by Apple. We save any name Apple supplies at your first sign-in for display and to fill in your enquiry. We do not receive your Apple password. Further information is available from Apple about “Sign in with Apple” and privacy.
We use the name to fill in the enquiry. After an enquiry sent while signed in, its name, telephone number and chosen reply method may be reused for later enquiries with the same account. You can edit these before sending. Enquiries remain possible without sign-in.
We use Supabase Auth from Supabase, Inc. to verify sign-in and manage sessions. Our project's selected server region is Frankfurt. This does not rule out processing by the providers outside the European Economic Area; section 7 also applies. Provider information can be found in Supabase's privacy policy and Google's privacy policy.
Processing your requested customer account and related enquiries is based on Article 6(1)(b) GDPR. Security checks serve our legitimate interest in secure sign-in under Article 6(1)(f) GDPR. We do not use sign-in for advertising. ‘Sign out’ ends the session on the device; it does not delete your account or submitted enquiries. You can request account deletion through our contact details. Statutory retention duties for business transactions remain unaffected.
4. Email, telephone and WhatsApp
When you contact us, we process the information you provide, such as name, telephone, email, delivery address, preferences and any photos sent. This is to handle your enquiry or contract under Article 6(1)(b) GDPR; for other enquiries, the legitimate interest explained in section 3 applies.
Our email inbox is provided through Google's Gmail. Google also technically processes message and connection data. Further information is available in Google's privacy policy.
WhatsApp is an optional contact method. If you use it, the service processes in particular your telephone number, communication and usage data under its own terms. Details are in WhatsApp's privacy policy for the European Region. Alternatively, contact us by phone or email.
Please send only details and images needed for your enquiry. Only send other people's data where you are authorised to do so.
5. Order handling and recipients
If a contract is formed, we process in particular basic customer, contact, order, delivery and payment data to perform it (Article 6(1)(b) GDPR). We comply with statutory accounting and retention duties under Article 6(1)(c) GDPR.
Where necessary for the particular order, businesses commissioned for production, delivery or assembly receive the necessary details, such as the furniture design or delivery address and contact details. Payment data is processed by the institutions involved in the agreed payment method. Tax advisers and competent authorities receive data as needed to fulfil legal duties. We do not disclose data for third-party advertising.
6. Cookies, analytics and external content
We save your chosen language in your browser's local storage as ‘sofastil.language’, so the homepage opens in that language on later visits. Only the language code is stored, with no advertising identifier. You can change it at any time using the language icon; clearing this website's data in your browser removes the saved choice.
The site features we set up use no advertising pixels or third-party analytics software. The enquiry feature does not permanently store inputs in the browser. For explicitly requested Google sign-in, we use technically necessary cookies: a verification value valid for up to ten minutes and protected session cookies lasting up to 30 days, updated when sign-in is renewed. Signing out removes our session cookies. They support sign-in and protection against misuse, not advertising. This does not describe technically necessary storage used by the hosting or sign-in platform itself.
Maps and social-media references are external links; maps, feeds and videos are not automatically embedded from third parties. You visit that provider only when opening a link, and its privacy information applies there. If future storage or external content requires consent, consent must be obtained beforehand; merely using this site is not consent.
Daily statistics
To understand use of our website, we count page views and estimated visits on the server. Only daily totals and the start of collection are stored. A request without a recognisable internal source counts as a new visit; the same person may count more than once. For these counts, we store no IP addresses, visitor identifiers, full referring addresses or personal browsing histories, and set no analytics cookies. Source and browser information is used only to classify the current request. Recognised bots, signed-in administrators and requests with the browser signals “Do Not Track” or “Global Privacy Control” are excluded. Daily totals are displayed in the protected admin area and included in website backups.
Saved items without an account
When you save an image, we store your selection with a random identifier and set a protected cookie for up to 180 days. We collect names and phone numbers only when you submit an enquiry. You can remove images from your list at any time. The identifier is not used for advertising.
7. Processing outside the European Economic Area
The named platform and communication services may process data outside the European Economic Area, particularly in the USA. Providers explain their transfers and safeguards in the linked privacy information. Transfers to third countries require the conditions of Articles 44 et seq. GDPR, such as an applicable adequacy decision or appropriate safeguards. The links do not promise the same legal basis for every processing operation. You may request information on the safeguards relevant to our processing through our privacy contact.
8. Retention period
We retain enquiries and related personal data only for as long as needed to handle them or where a legal basis allows further retention. If no contract results and no other reason to retain remains, the data is deleted. Data needed to assert or defend claims may be kept for the applicable limitation periods, based on our legitimate interest under Article 6(1)(f) GDPR.
Documents subject to retention follow statutory periods, generally eight years for accounting vouchers, six years for commercial and business correspondence, and ten years for the legally specified books and accounts. Start dates and any extensions follow the relevant law. We then delete data unless another legal reason prevents this. Platform data under a provider's own responsibility follows that provider's retention rules.
9. Your rights
Subject to legal conditions, you have rights of access, rectification, erasure, restriction of processing and data portability. Where processing relies on consent, you may withdraw it at any time for the future. This does not affect the lawfulness of processing already carried out.
Objection: You may object to processing under Article 6(1)(f) GDPR on grounds relating to your particular situation. You may object to processing for direct marketing at any time without giving specific reasons.
You may complain to a data protection authority, particularly where you normally live or work or where the suspected breach occurred. In Berlin, contact the Berliner Beauftragte für Datenschutz und Informationsfreiheit at Alt-Moabit 59–61, 10555 Berlin; Contact and complaints information.
10. Providing data and automated decisions
You are not required to make an enquiry. To reply and prepare a specific quotation, however, we need sufficient contact and order information; without it we may be unable to help. We tell you if legally required invoice details are needed. Our own enquiry and order handling does not involve decisions based solely on automated processing with legal or similarly significant effects, or related profiling.