Bodenplan.de
Privacy policy
1. Data protection at a glance
Protecting your personal data is important to us. This Privacy Policy explains which personal data is processed when you use Bodenplan.de, the purposes for which it is processed, and the rights available to you.
Personal data means any information relating to an identified or identifiable natural person. This includes, for example, names, email addresses, IP addresses, account data, project data, and payment data.
2. Controller
The controller responsible for data processing on this website is:
Volodymyr Atapin
sole proprietor trading as “Bodenplan.de”
Neuhofer Str. 7
16278 Angermünde
Germany
Telephone: +49 171 3517274
Email: atapin@gmail.com
Contact form: https://bodenplan.de/kontakt
3. Hosting
This website is hosted on a server operated by the following provider:
STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin
Germany
When you access the website, the server processes technically necessary data. This may include, in particular:
- IP address;
- date and time of access;
- page or file accessed;
- amount of data transferred;
- referrer URL;
- browser type and version;
- operating system;
- hostname of the accessing device;
- HTTP status code.
This processing is carried out to provide the website securely, reliably, and without errors, and to detect and prevent attacks.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable operation of Bodenplan.de.
Server log files are stored only for as long as necessary for secure technical operation, error analysis, and the prevention of attacks. They may be stored for longer where specific security incidents need to be investigated or legal obligations must be fulfilled.
Further information is available in STRATO’s Privacy Policy.
4. SSL or TLS encryption
Bodenplan.de uses SSL or TLS encryption. You can recognise an encrypted connection by the https:// prefix and the padlock icon in your browser’s address bar.
Encryption helps prevent third parties from readily reading the data you transmit to us.
5. Technically necessary cookies
Bodenplan.de uses only cookies that are necessary for the secure operation of the website and for providing the functions you request.
XSRF-TOKEN
This cookie protects against cross-site request forgery attacks. It helps ensure that requests actually originate from the open website and the relevant user.
bodenplan-session
This cookie is required to manage the user session. Among other things, it enables login, associates requests with a session, and allows secure use of protected areas.
The cookies are set with the Secure and SameSite=Lax attributes. The session cookie is also marked as HttpOnly. Its normal lifetime is up to two hours and may be renewed through continued use of the website.
The legal bases are Section 25(2)(2) TDDDG and Article 6(1)(b) and (f) GDPR.
As only technically necessary cookies are used, prior consent is not required for these cookies.
6. Server-based web analytics using GoAccess
We use GoAccess to perform technical analyses of server access.
GoAccess processes the access logs stored on the web server and uses them to produce statistical analyses, for example regarding:
- the number of page views;
- pages and files accessed;
- access times;
- browsers and operating systems;
- referring pages;
- HTTP status codes;
- technical errors;
- IP addresses contained in the server logs.
The analysis is carried out exclusively on our own server. No analytics cookies are set, no additional tracking scripts are executed in your browser, and no data is transferred to an external analytics service.
The analysis is used for technical monitoring, error detection, security analysis, and the needs-based improvement of Bodenplan.de.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable, and technically optimised operation of the website.
The analytics data is not combined with other data sources or used to create personal advertising profiles.
7. Registration and user account
You can create a user account to use certain functions. In doing so, we may process, in particular:
- name;
- email address;
- encrypted or hashed password;
- time of registration;
- time of email confirmation;
- login and account status;
- technical security and session data.
Your password is not stored in plain text.
The data is processed to create and manage the user account, authenticate users, and provide the functions of Bodenplan.de.
The legal basis is Article 6(1)(b) GDPR.
We store your account data for as long as your user account remains active. When the account is deleted, the data is deleted unless statutory retention requirements or legitimate security and evidentiary interests require further storage.
8. Email confirmation and system messages
Bodenplan.de may send you technically necessary messages by email. These include, in particular:
- confirmation of your email address;
- password reset messages;
- security-related notices;
- user account information;
- contractual and payment-related notices;
- confirmations of changes or cancellations.
Messages are sent directly through our server. We do not use an external newsletter or email marketing service.
The legal basis is Article 6(1)(b) GDPR. Security-related messages are additionally processed on the basis of Article 6(1)(f) GDPR.
We do not currently send promotional newsletters.
9. Projects and planning data
When you use the planning software, we process the project data you enter and generate. This may include:
- project name and description;
- room shapes and dimensions;
- floor and wall areas;
- material selection;
- laying and design patterns;
- quantity and consumption calculations;
- 2D and 3D visualisations;
- editing states;
- export and print data;
- creation and modification times.
The data is processed so that projects can be saved, edited, displayed, calculated, and exported.
The legal basis is Article 6(1)(b) GDPR.
Project data is stored on our server at STRATO and is generally retained for as long as the relevant user account or project exists.
10. Uploaded images and textures
You can upload your own images, photographs, graphics, and textures. These files are processed to display floors, walls, materials, rooms, and 3D views, and are stored on our server.
Uploaded files may contain personal data, for example where a room photograph shows people, personal belongings, documents, or other identifiable information.
Please upload only files that you are authorised to use. Wherever possible, avoid images that show identifiable people or confidential information.
The legal basis for this processing is Article 6(1)(b) GDPR.
The files are stored for as long as they remain associated with a user account or project. They are deleted when you delete the file or related project, when the user account is deleted, or when storage is no longer necessary to provide the service. This does not affect statutory obligations or technically necessary backup copies.
11. Sharing projects
Bodenplan.de may provide functions for sharing projects through view or edit links.
If you create and share such a link, anyone who possesses it may access the shared project in accordance with the permission you selected.
Please share project links only with their intended recipients. Bear in mind that recipients may forward the links to other people.
The shared data is processed and made available at your request in order to provide the project-sharing function you selected. The legal basis is Article 6(1)(b) GDPR.
You can end sharing or deactivate sharing links where this function is available in your user account.
12. Contacting us
If you contact us by contact form or email, we process the information you provide. This may include:
- name;
- email address;
- subject;
- message content;
- selected project type;
- project information provided voluntarily;
- time of the enquiry;
- technical information required for secure transmission.
The data is used to process your enquiry and any follow-up questions.
If your enquiry relates to a contract or pre-contractual measures, the legal basis is Article 6(1)(b) GDPR. General enquiries are processed on the basis of Article 6(1)(f) GDPR. Our legitimate interest lies in processing and responding to enquiries.
The data is deleted once the enquiry has been conclusively dealt with, unless statutory retention requirements or legitimate evidentiary interests require further storage.
Acknowledging this Privacy Policy does not constitute consent to advertising or to any processing unrelated to the handling of your enquiry.
13. Paid subscriptions and Stripe
We use Stripe to process paid subscriptions and payments.
For users within the European Economic Area, the provider is generally:
Stripe Payments Europe, Limited
The One Building
1 Grand Canal Street Lower
Dublin 2
Ireland
When a payment is initiated or processed, the following data in particular may be transferred to Stripe or collected directly by Stripe:
- name;
- email address;
- billing address;
- payment amount;
- currency;
- selected plan;
- order and transaction number;
- payment status;
- time of payment;
- information about the payment method;
- card or bank account details;
- IP address and device information;
- fraud-prevention data;
- information about subscriptions, cancellations, and refunds.
Complete card or bank account details are not stored on Bodenplan.de servers. This data is processed directly by Stripe and the payment providers, card schemes, or credit institutions involved.
Stripe may engage other companies, banks, card organisations, and technical service providers to process payments.
The processing is carried out to perform the contract pursuant to Article 6(1)(b) GDPR, to comply with legal obligations pursuant to Article 6(1)(c) GDPR, and to prevent fraud and payment defaults pursuant to Article 6(1)(f) GDPR.
Stripe may also process data outside the European Union or European Economic Area. According to Stripe, it uses recognised transfer mechanisms for this purpose, including the EU–US Data Privacy Framework and Standard Contractual Clauses.
Further information is available in Stripe’s Privacy Policy.
14. Contract, billing, and payment data
Data required for contracts, subscriptions, invoices, payments, refunds, or cancellations is processed for the duration of the contractual relationship.
After the contract ends, the data is deleted unless it is subject to statutory retention obligations under commercial or tax law. During statutory retention periods, processing is restricted to the required purposes.
The legal bases are Article 6(1)(b) and (c) GDPR.
15. Recipients of personal data
Personal data is disclosed only where necessary to provide the website, perform a contract, process payments, comply with legal obligations, or protect legitimate interests.
Recipients or categories of recipients may include, in particular:
- STRATO as the hosting and infrastructure provider;
- Stripe and participating payment service providers;
- banks and card organisations;
- tax advisers and accounting providers, where necessary;
- public authorities and courts where required by law;
- recipients selected by you for shared project links.
Personal data is not sold.
16. No automated decision-making
Bodenplan.de does not carry out decision-making based solely on automated processing, including profiling, within the meaning of Article 22 GDPR.
Stripe may use its own automated checks in connection with payment processing and fraud prevention. Further information is available directly from Stripe.
17. Storage period
Personal data is stored only for as long as necessary for the relevant processing purpose.
The specific storage period depends, in particular, on:
- the lifetime of the user account;
- the duration of the contract or subscription;
- the continued existence of a project;
- the time required to process a contact enquiry;
- technical security requirements;
- statutory record-keeping and retention obligations;
- potential legal claims and statutory limitation periods.
When the purpose no longer applies and there is no legal or legitimate basis for continued storage, the data is deleted or anonymised.
18. Data security
We take appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access, and unauthorised disclosure.
These measures include, in particular:
- encrypted data transmission using HTTPS;
- access restrictions;
- protected user accounts;
- hashed passwords;
- secure session management;
- regular updates to the software used;
- technical logging to detect errors and attacks;
- data backups and recovery measures.
Despite all security measures, complete protection cannot be guaranteed when data is transmitted over the internet.
19. Your rights
Subject to the applicable statutory requirements, you have the following rights:
- right of access to your processed personal data under Article 15 GDPR;
- right to rectification of inaccurate or incomplete data under Article 16 GDPR;
- right to erasure of your data under Article 17 GDPR;
- right to restriction of processing under Article 18 GDPR;
- right to notification of recipients under Article 19 GDPR;
- right to data portability under Article 20 GDPR;
- right to object to processing under Article 21 GDPR;
- right to withdraw consent under Article 7(3) GDPR;
- right to lodge a complaint with a data protection supervisory authority under Article 77 GDPR.
To exercise your rights, please contact us at atapin@gmail.com.
20. Right to object
Where your personal data is processed on the basis of Article 6(1)(f) GDPR, you have the right to object to the processing at any time on grounds relating to your particular situation.
We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless the processing is required for the establishment, exercise, or defence of legal claims.
21. Withdrawal of consent
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future.
The lawfulness of processing carried out before the withdrawal remains unaffected.
Bodenplan.de does not currently use analytics or marketing services that require consent.
22. Right to lodge a complaint with a supervisory authority
If you believe that the processing of your personal data infringes the GDPR, you may lodge a complaint with a data protection supervisory authority.
The supervisory authority responsible for us is:
The Brandenburg State Commissioner for Data Protection and Access to Information
(Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg)
Stahnsdorfer Damm 77
14532 Kleinmachnow
Germany
Telephone: +49 33203 356-0
Email: Poststelle@LDA.Brandenburg.de
Website: https://www.lda.brandenburg.de
23. Changes to this Privacy Policy
We may update this Privacy Policy if legal requirements, the functions of Bodenplan.de, or the technical services used change.
The version published on this page at the relevant time applies.
Last updated: 15 July 2026