PeakPact Elite · Legal

GDPR Compliance

Official policy page for Google Play and store review.

Full English policy

# PeakPact Elite — GDPR Compliance Statement

**Effective date:** 15 September 2026  
**Roles:** PeakPact acts as **controller** for Elite product data; processors include Clerk, Cloudflare (Workers / R2), Neon, OpenAI, RevenueCat, Firebase (Crashlytics / Analytics), and Google Play / Apple as applicable.

## 1. Principles applied

We apply GDPR principles: lawfulness, fairness, transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; accountability.

## 2. Lawful bases

Documented in the Privacy Policy (contract, consent, legitimate interests, legal obligation). Legitimate interest assessments are maintained for security/abuse prevention and reliability telemetry.

## 3. Data subject rights (Arts. 12–22)

We support:
- Access (Art. 15)
- Rectification (Art. 16)
- Erasure (Art. 17) subject to legal exceptions
- Restriction (Art. 18)
- Portability (Art. 20) for data you provided where processing is automated and based on consent/contract
- Objection (Art. 21) including to profiling-like automation intensity recommendations where applicable
- Withdrawal of consent without affecting prior lawful processing

**Request channel:** privacy@peakpactelite.app  
**Target response:** within one month (extendable per Art. 12(3) with notice)

## 4. Processors & DPAs

We maintain processor agreements / DPAs with core infrastructure vendors covering instructions, confidentiality, security, sub-processors, deletion/return, and audit cooperation.

## 5. International transfers

Transfers outside the EEA use SCCs or other approved mechanisms where required, plus transfer risk assessments for critical flows (Clerk auth, Neon DB, R2 objects, OpenAI compose).

## 6. Security of processing (Art. 32)

TLS in transit, access-controlled secrets (Worker secrets), least-privilege service roles, JWT audience binding (`peakpactelite`), audit-friendly API logging of operational events (not full media payloads), and R2 private object access patterns.

## 7. Breach notification

Personal data breaches will be assessed and, where required, notified to the competent supervisory authority within 72 hours and to data subjects without undue delay when high risk.

## 8. DPIA triggers

We conduct DPIAs when introducing high-risk processing (e.g., large-scale sensitive inference, systematic monitoring). Current Elite AI compose uses minimized context (locale, streak, intensity) without free-form personal dossiers.

## 9. EU representative / DPO

If PeakPact’s scale or risk profile requires a DPO or EU representative under Arts. 27/37, contact details will be published here. Interim contact: privacy@peakpactelite.app.