Full English policy
# PeakPact Elite — GDPR Compliance Statement **Effective date:** 15 September 2026 **Roles:** PeakPact acts as **controller** for Elite product data; processors include Clerk, Cloudflare (Workers / R2), Neon, OpenAI, RevenueCat, Firebase (Crashlytics / Analytics), and Google Play / Apple as applicable. ## 1. Principles applied We apply GDPR principles: lawfulness, fairness, transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; accountability. ## 2. Lawful bases Documented in the Privacy Policy (contract, consent, legitimate interests, legal obligation). Legitimate interest assessments are maintained for security/abuse prevention and reliability telemetry. ## 3. Data subject rights (Arts. 12–22) We support: - Access (Art. 15) - Rectification (Art. 16) - Erasure (Art. 17) subject to legal exceptions - Restriction (Art. 18) - Portability (Art. 20) for data you provided where processing is automated and based on consent/contract - Objection (Art. 21) including to profiling-like automation intensity recommendations where applicable - Withdrawal of consent without affecting prior lawful processing **Request channel:** privacy@peakpactelite.app **Target response:** within one month (extendable per Art. 12(3) with notice) ## 4. Processors & DPAs We maintain processor agreements / DPAs with core infrastructure vendors covering instructions, confidentiality, security, sub-processors, deletion/return, and audit cooperation. ## 5. International transfers Transfers outside the EEA use SCCs or other approved mechanisms where required, plus transfer risk assessments for critical flows (Clerk auth, Neon DB, R2 objects, OpenAI compose). ## 6. Security of processing (Art. 32) TLS in transit, access-controlled secrets (Worker secrets), least-privilege service roles, JWT audience binding (`peakpactelite`), audit-friendly API logging of operational events (not full media payloads), and R2 private object access patterns. ## 7. Breach notification Personal data breaches will be assessed and, where required, notified to the competent supervisory authority within 72 hours and to data subjects without undue delay when high risk. ## 8. DPIA triggers We conduct DPIAs when introducing high-risk processing (e.g., large-scale sensitive inference, systematic monitoring). Current Elite AI compose uses minimized context (locale, streak, intensity) without free-form personal dossiers. ## 9. EU representative / DPO If PeakPact’s scale or risk profile requires a DPO or EU representative under Arts. 27/37, contact details will be published here. Interim contact: privacy@peakpactelite.app.