Legal
Website privacy policy.
This policy covers the streakletics.com website only. The Streakletics mobile app is covered by its own privacy policy.
The German version of this Website Privacy Policy is authoritative. This English translation is provided for convenience. If the two versions differ or conflict, the German version prevails.
1. Controller and scope
The controller responsible for processing personal data on this website is:
Point Zero GmbH
Speditionstr. 15A
40221 Düsseldorf
Germany
Phone: +49 162 7555786
Email: info@pointzero.tech
Further company information is available in our Legal Notice.
This Website Privacy Policy applies exclusively to www.streakletics.com. It does not describe the Streakletics mobile app. The App processes data differently, including account, training, subscription, advertising and push-notification data, and is covered by a separate App Privacy Policy.
2. Data protection officer
We have not appointed a data protection officer. You can direct privacy enquiries to the contact details above.
3. Hosting and server log files
This website is hosted by:
Vercel Inc.
440 N Barranca Avenue #4133
Covina, CA 91723
United States
When you access the website, Vercel processes technical data transmitted by your browser or device. Depending on the request, this may include:
- IP address;
- date and time of the request;
- requested page, route or file;
- HTTP status code and amount of data transferred;
- referring URL, where transmitted;
- browser type and version, operating system and device type; and
- technical request, diagnostic and security information.
This processing is necessary to deliver the website, maintain its stability and security, and identify and investigate faults or attacks. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, reliable and efficient operation of the website.
Vercel generally processes this data on our behalf as a processor. The Vercel Data Processing Addendum forms part of our agreement. To the extent Vercel processes service-generated data for its own purposes as an independent controller, that processing is governed by the Vercel Privacy Notice.
4. Vercel Web Analytics
We use Vercel Web Analytics to understand in aggregated form how the website is used, which pages are visited and which technical environments visitors use. Depending on the page view, the following data points may be processed:
- time of the page view;
- page, URL or route visited;
- filtered URL parameters;
- referrer;
- approximate location derived from the network connection;
- browser and browser version;
- operating system and version;
- device type; and
- analytics-script version.
Vercel Web Analytics does not use cookies and does not place a persistent visitor identifier in your browser. Visits are distinguished through a hash generated from the incoming request. According to Vercel, the visitor session is discarded after 24 hours, cannot be used to recognise a visitor across different websites or days, and the IP address is not stored with the analytics data. We receive aggregated statistics rather than individual browsing histories.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is understanding how the website is used and improving its content, navigation and technical quality. We do not use these analytics data for advertising, individual user profiles or automated decision-making.
Further information is available in Vercel’s Web Analytics privacy documentation.
5. Cookies and browser storage
Our website code does not set or read cookies and does not use localStorage, sessionStorage or IndexedDB. The language switcher works through ordinary URL navigation and does not persist a language selection on your device. The website has no theme preference that is stored in your browser.
Vercel Web Analytics likewise does not use cookies or persistent browser identifiers. We do not use tracking pixels, advertising trackers, browser fingerprinting or comparable tracking technologies on this website.
Because the website does not store information in, or access information from, your terminal equipment for these purposes, no consent under Section 25(1) TDDDG is required for the processing described here. The website therefore does not display a cookie or consent banner.
6. Fonts
The website uses the typefaces Sora and Anton. The font files are bundled locally with the website and delivered through our hosting provider. Loading them does not establish a connection to Google Fonts or another external font provider.
7. Contact by email and Google Workspace
The website does not provide a contact form. Email addresses are displayed as mailto: links. Selecting such a link opens a new message in your own email application. The website itself does not receive the content of your message. We process it only after you send the email.
If you contact us by email, for example at info@pointzero.tech, we may process your name, email address, message, attachments and technical sending and delivery information. Where your enquiry concerns steps before entering into a contract or the performance of a contract, the legal basis is Article 6(1)(b) GDPR. We process other enquiries under Article 6(1)(f) GDPR, based on our legitimate interest in handling and responding to communications addressed to us. Legal or compliance-related correspondence may additionally be processed under Article 6(1)(c) GDPR.
We use Google Workspace as our email provider. Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland, and affiliated Google entities process email data on our behalf under Google’s applicable data processing terms. Further information is available in Google’s Cloud Data Processing Addendum and Privacy Policy.
8. Recipients of personal data
In connection with this website, personal data may be disclosed to:
- Vercel Inc. and its subprocessors for hosting, technical delivery and Web Analytics;
- Google Cloud EMEA Limited, affiliated Google entities and subprocessors for email communication through Google Workspace;
- persons within Point Zero GmbH who require access for the purposes described in this policy; and
- professional advisers, authorities, courts or other recipients where disclosure is required by law or necessary for the establishment, exercise or defence of legal claims.
Where a service provider processes personal data on our behalf, we conclude a data processing agreement as required by Article 28 GDPR.
We do not use advertising networks on this website, create individual advertising profiles or sell personal data.
9. International data transfers
Vercel Inc. and Google LLC are based in the United States, and personal data may be processed in the United States or other countries in which their subprocessors operate.
Where required, international transfers are protected by an applicable adequacy decision, including the EU-US Data Privacy Framework for participating recipients, and/or the European Commission’s Standard Contractual Clauses together with supplementary safeguards. Relevant contractual protections are contained in the providers’ data processing terms.
The use of European infrastructure or processing locations can reduce international transfers but does not necessarily exclude remote access, support processing or processing by subprocessors outside the European Economic Area.
10. Storage duration
We retain personal data only for as long as necessary for the relevant purpose, unless statutory retention duties or legitimate legal interests require longer storage.
- Server-log data accessible to us through Vercel is retained according to the configuration and retention periods applicable to our Vercel project and is then deleted or overwritten.
- The visitor session used by Vercel Web Analytics is discarded after 24 hours. Aggregated analytics statistics are retained only for as long as they are required to analyse and improve the website.
- Email correspondence is retained until the enquiry and any follow-up questions have been resolved. It may then be retained where necessary for documentation, legal claims or statutory retention duties.
Commercial and tax-related correspondence may have to be retained for six, eight or ten years depending on the document and applicable law. Information needed for legal claims may be retained until the relevant limitation period has expired.
11. Your data-protection rights
Subject to the statutory requirements, you have the right to:
- access your personal data under Article 15 GDPR;
- request correction of inaccurate data under Article 16 GDPR;
- request erasure under Article 17 GDPR;
- request restriction of processing under Article 18 GDPR;
- receive personal data you provided in a structured, commonly used and machine-readable format under Article 20 GDPR; and
- lodge a complaint with a data-protection supervisory authority under Article 77 GDPR.
Right to object under Article 21 GDPR
Where we process personal data on the basis of Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is required for the establishment, exercise or defence of legal claims.
To exercise your rights, contact info@pointzero.tech. We may request information reasonably necessary to verify your identity and locate the relevant records.
You may complain to any competent supervisory authority. The authority responsible for Point Zero GmbH is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
12. Required information
There is no statutory or contractual obligation to provide personal data merely to visit this website. Technical connection and request data are nevertheless required to deliver the website; without them, the website cannot be accessed. You are not required to contact us by email. If you do, we need the information required to process and answer your enquiry.
13. Automated decision-making
We do not use solely automated decision-making, including profiling, within the meaning of Article 22 GDPR on this website.
14. Security
We use appropriate technical and organisational measures designed to protect personal data against accidental loss, unlawful use and unauthorised access. These include encrypted transmission, access controls and restricted internal access. No method of electronic transmission or storage can guarantee absolute security.
15. Changes to this Website Privacy Policy
We may update this Website Privacy Policy when the website, our service providers, legal requirements or processing activities change. The version displayed here, together with the date stated above, applies to your visit.