EN
Privacy Policy
Last updated: 7 September 2026
SONKO Consulting GmbH, based in Leverkusen, takes the protection of personal data seriously. This Privacy Policy applies to every interaction between visitors and clients of SONKO Consulting and SONKO itself. We strictly follow the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
Controller
SONKO Consulting GmbH
Borsigstraße 1
51381 Leverkusen
Germany
Legal representative: Tity Sonko, Managing Director
Registered: Amtsgericht Köln, HRB 128138
Tax No.: 135/5770/1711 (Finanzamt Hilden)
Email: info@sonko-consulting.de
Web: sonko-consulting.com
Data protection officer
SONKO Consulting GmbH is not required by law to appoint a data protection officer (Art. 37 GDPR in conjunction with § 38 BDSG), as we do not fall within any of the mandatory categories. All privacy-related requests are handled directly by the Managing Director. Please write to info@sonko-consulting.de for any concern.
Competent supervisory authority
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Postfach 20 04 44
40102 Düsseldorf
Germany
Phone: +49 211 384 24-0
Email:
poststelle@ldi.nrw.de
Your rights
Under the GDPR you have the right to receive information about the personal data we process (Art. 15), to have inaccurate data corrected (Art. 16), to request the erasure (Art. 17) or restriction (Art. 18) of your data, to object to processing based on legitimate interests (Art. 21), to receive your data in a structured, common and machine-readable format (Art. 20) and to withdraw any consent you have given us with effect for the future (Art. 7 (3)).
You can exercise these rights informally by writing to info@sonko-consulting.de. If you believe we do not process your data lawfully, you have the right to lodge a complaint with the supervisory authority listed above.
How and why we process data
Outside of a signed advisory engagement with SONKO, we collect and process personal data only when you voluntarily provide it. Beyond legal permissions, your personal data is processed only on the basis of your explicit consent. We rely on the following legal bases:
1. Consent (Art. 6 (1) (a) GDPR)
Consent is given for a defined purpose, such as:
- Getting in touch. When you send us your contact details to receive information or a proposal.
- Newsletter. Your email address (and optionally your name and title) are used to send you our LinkedIn newsletter The DACH Prestige Signal. You can unsubscribe at any time via the link in the newsletter or by writing to info@sonko-consulting.de.
- Free tools. When you use the Fit-Check, Leadership Mindset Audit or Positioning Sanity-Check, you consent to us processing the inputs you provide in order to give you a result.
You can withdraw consent at any time with effect for the future by writing to us at the address above.
2. Performance of a (pre-)contract (Art. 6 (1) (b) GDPR)
- Contract execution. Client contact data, project data, and correspondence are processed to deliver our advisory services (Feasibility Audit, Expansion Blueprint, Fractional DACH Manager and hourly executive sessions).
- Enquiries. Data you send us in the context of an enquiry is processed to send you a proposal or arrange a pre-contractual conversation.
- NDA workflow. When you request a mutual NDA through SONKO OS, we process the company details you provide (legal name, registered address, registration court, registration number, signatory) to prepare the NDA for signing.
3. Legal obligations (Art. 6 (1) (c) GDPR)
As a German limited-liability company we are subject to commercial-law and tax-law obligations, including reporting and record-keeping duties. Examples: retention of invoice data under HGB / AO, statutory reporting obligations.
4. Legitimate interests (Art. 6 (1) (f) GDPR)
- Business operations. Maintaining and improving our services, including analysing how our website and SONKO OS are used.
- Direct communication. Using your email address to inform you about advisory services similar to those you have already engaged us for, as long as you have not objected.
- Fraud prevention and platform security. Logging access to SONKO OS, detecting misuse, protecting client data.
Categories of data
- Customer and prospect data commonly used in business (name, business email, phone, company, role).
- Contract and mandate data (project brief, client materials shared under NDA, correspondence).
- NDA-preparation data (legal company name, registered address, registration court, registration number, signatory).
- Payment and invoicing data (billing address, tax IDs, invoice numbers).
- Usage data of SONKO OS (login timestamps, tool inputs such as Fit-Check answers and Leadership Mindset Audit responses, uploaded documents).
- Data required to conduct video calls (Cal.com booking data; name, email, availability).
Recipients of data
We share personal data only where necessary for the purposes described above.
1. Public authorities (only where required by law)
Tax authorities, supervisory authorities and other public bodies where we are legally obliged to disclose data.
2. External processors and service providers
- Hosting provider: united-domains AG, Gautinger Straße 10, 82319 Starnberg, Germany. Servers and data centres are located in Germany.
- Scheduling: Cal.com, Inc., used to book advisory calls. Cal.com is operated from the United States; personal data (name, email, availability) is transferred there under the EU Standard Contractual Clauses.
- AI-assisted analysis: Anthropic PBC (Claude) for private, one-off text and document analysis used inside the SONKO OS platform; Google LLC (Gemini) for compliance-checks and market intelligence. Neither provider is used to train their models on your data. Data transfers to the United States are covered by the EU Standard Contractual Clauses.
- Electronic signature (NDA): Depending on the client, either Documenso GmbH (EU-based, open-source e-signature) or a comparable EU-based provider is used to countersign mutual NDAs.
- Newsletter: LinkedIn Ireland Unlimited Company hosts our newsletter The DACH Prestige Signal. If you subscribe there, LinkedIn processes your data under its own policy.
- Email: Business email is delivered via our hosting provider’s EU-based mail infrastructure.
3. Professional advisors
Tax advisors, auditors and lawyers acting for SONKO Consulting on the basis of professional confidentiality obligations.
4. Transfers outside the EU/EEA
Some processors (in particular Cal.com, Anthropic and Google) operate from the United States. In every such case we rely on the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) and further safeguards as required by Art. 44 ff. GDPR.
Data security
We apply technical and organisational measures (TOMs) proportionate to the sensitivity of client data:
Encryption
- In transit: All connections to www.sonko-consulting.com and SONKO OS use TLS.
- At rest: Sensitive data (passwords, session tokens, payment references) is stored hashed or encrypted.
Access controls
- Data centres of our hosting provider are secured with physical access controls and video surveillance.
- Access to client data inside SONKO OS is restricted to authorised users; every admin action is logged with a timestamp and actor.
Minimisation and separation
- We only process the data we actually need to deliver our services (data minimisation, Art. 5 (1) (c) GDPR).
- Client workspaces in SONKO OS are logically separated so that one client cannot see another client's data.
Backups and continuity
- Databases and file storage are backed up regularly; backup media is encrypted.
- Restore procedures are tested.
Monitoring
- Application access is logged; anomalies are reviewed.
- Third-party dependencies are patched on a regular cadence.
Privacy by design and by default (Art. 25 GDPR)
- New features in SONKO OS are designed with the least amount of personal data required.
- Sensible privacy defaults are pre-selected in every workspace (for example: notes and activities are internal by default, not client-visible).
Retention
Client data
- Contract data: stored for the duration of the mandate and 10 years after termination, in line with German commercial and tax retention obligations (§ 257 HGB, § 147 AO).
- Enquiries without contract: deleted after 6 months if no engagement follows.
Newsletter data
Email addresses are stored until you unsubscribe. Withdrawal is possible at any time.
SONKO OS usage data
Login events and tool inputs (Fit-Check, Leadership Mindset Audit, Positioning Sanity-Check) are stored for as long as your workspace exists. If you request deletion of your account, we erase your personal data within 30 days, subject only to statutory retention duties (invoicing, NDA record).
Log data
Web-server access logs are typically kept for 6 months and then deleted or anonymised.
Data held for legal purposes
Data related to actual or anticipated legal disputes may be stored until the matter is closed and applicable limitation periods have expired.
Data collected when you visit our website
If you use our website for information only, your browser sends the following data to our server, which we process to display our pages and maintain security:
- IP address (shortened where possible)
- Date, time and duration of the request
- Content of the request (page and click path)
- HTTP status code and transferred data volume
- Referring website
- Browser, operating system and version
- Screen resolution and language
Cookies and consent
When you first visit our website a cookie banner is shown. Through the banner you can grant or refuse consent for the following categories:
- Strictly necessary cookies: required for basic functions (session, CSRF-token, language selection). These cannot be disabled.
- Analytical cookies: only if consented, used to understand aggregate usage of the site.
- Marketing cookies: only if consented.
You can also disable cookies in your browser settings. Blocking strictly necessary cookies may cause parts of the website or SONKO OS to stop functioning.
Google Analytics and IP anonymisation
Where consent is given via the cookie banner, we use Google Analytics, a web-analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (for EU users), and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (for data ultimately processed in the US). Google Analytics uses cookies stored on your device to help us understand how our website is used, aggregated across visitors.
IP anonymisation is enabled. Your IP address is shortened by Google inside the European Union or another party to the Agreement on the European Economic Area before it is transmitted to the United States. The full IP address is never stored.
Data transfers to the United States are covered by the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) and by Google's participation in the EU-U.S. Data Privacy Framework, as far as applicable.
You can prevent collection by Google Analytics in the following ways:
- Cookie settings. Manage or withdraw your consent at any time through our cookie settings link in the footer.
- Browser add-on. Install the Google Analytics Opt-out Browser Add-on.
- Browser settings. Block or delete cookies through your browser.
Legal basis: your consent under Art. 6 (1) (a) GDPR, given through the cookie banner. You can withdraw this consent at any time with effect for the future.
Booking a call (Cal.com)
We use Cal.com to let you book advisory calls with Tity Sonko. When you use the booking widget, Cal.com processes your name, email address, chosen time slot and any notes you add. Data is transferred securely (TLS) and stored on Cal.com's servers in the United States; the transfer is covered by EU Standard Contractual Clauses.
Social plug-ins
Our site links to LinkedIn but does not embed active LinkedIn plug-ins. Only when you click a LinkedIn link is a connection to LinkedIn established, at which point LinkedIn processes your data under its own policy.
External links
Our website contains links to third-party sites. SONKO Consulting has no control over their content or privacy practices and accepts no responsibility for either.
Security note
Confidential handling of client information is our operating philosophy; NDA-first is not marketing. Nevertheless, the internet remains an open system. We recommend not sending highly sensitive documents by unencrypted email; encrypted client folders inside SONKO OS or postal delivery are the safer channels.
Your rights in detail
- Right of access (Art. 15 GDPR).
- Right to rectification (Art. 16 GDPR).
- Right to erasure (Art. 17 GDPR).
- Right to restriction of processing (Art. 18 GDPR).
- Right to data portability (Art. 20 GDPR).
- Right to object (Art. 21 GDPR).
- Right to withdraw consent (Art. 7 (3) GDPR).
- Right to lodge a complaint (Art. 77 GDPR) with the supervisory authority listed above.
To exercise any of these rights, please write to info@sonko-consulting.de or to the postal address at the top of this page.
Changes to this policy
We may adjust this Privacy Policy as our services, tooling or legal obligations evolve. The date at the top of the page indicates when the current version came into effect. Material changes will be announced on our website and, where required, communicated to registered users of SONKO OS.