Skip to content
Legal letguru TENNIS INSIGHTS System · ready
← back to home

Privacy Policy

Effective date: 2026-05-24. Last reviewed: 2026-05-24.

This notice explains what personal data Letguru collects when you create and use a letguru account, why we collect it, how long we keep it, and what rights you have under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Romanian Law 190/2018.

Contents
  1. 1. Data controller
  2. 2. What we collect
  3. 3. Why we process it
  4. 4. Who else processes your data
  5. 5. International transfers
  6. 6. How long we keep it
  7. 6a. Web push notifications
  8. 7. Your rights
  9. 8. Right to lodge a complaint
  10. 9. Is providing your data required?
  11. 9a. Age requirement
  12. 10. Automated decision-making
  13. 11. Cookies and similar technologies
  14. 12. Changes to this notice

1. Data controller

The data controller is ALANDALA SOFTWARE SOLUTIONS SRL, a Romanian limited-liability company. Full registration details (tax ID, trade-register number, registered seat) are in our legal notice.

Privacy contact: privacy@letguru.app. General contact: hello@letguru.app.

2. What we collect

  • Email address (you provide it)
  • Consent timestamp (the date and time you ticked the privacy-acceptance box)
  • IP address of the device that submitted the form (logged for anti-abuse)
  • User-Agent string sent by your browser (logged for anti-abuse)

We do not collect names, billing details, or device fingerprints at this stage.

3. Why we process it (purposes & legal basis)

  • Create and manage your account — legal basis: GDPR Art. 6(1)(b) (performance of a contract to which you are party, or steps taken at your request prior to entering into one).
  • Prevent abuse of the sign-up and login forms (rate-limit, anti-bot) — legal basis: GDPR Art. 6(1)(f) (legitimate interest in preserving service availability).

4. Who else processes your data (recipients)

We use the following sub-processors:

EU/EEA-based sub-processors:

  • Brevo SAS (France) — transactional email delivery (account verification and other service email).
  • Hetzner Online GmbH (Germany) — server hosting and database storage.

Non-EEA sub-processors under EU Standard Contractual Clauses (SCCs, GDPR Art. 46):

  • Cloudflare Inc. (United States; EU-edge points of presence serve EU traffic; SCCs in place) — Turnstile anti-bot challenge served on the sign-up and login forms. Cloudflare's own privacy notice applies to that challenge.
  • Backblaze, Inc. (United States; EU bucket region eu-central-003, SCCs in place) — encrypted off-site backups of the application database. Backups are age-encrypted before upload; Backblaze stores ciphertext only and cannot read the underlying data without the encryption key, which never leaves the operator's 1Password vault.

We do not sell, rent, or share your data with advertising networks or data brokers.

5. International transfers

EU/EEA-based sub-processors (Brevo, Hetzner) keep your data inside the EU/EEA. Cloudflare Inc. and Backblaze, Inc. are United-States-incorporated companies. Cloudflare's EU-edge points of presence serve EU traffic; Backblaze backups are uploaded to an EU bucket region (eu-central-003). Any incidental processing on US infrastructure is covered by Standard Contractual Clauses (SCCs) under GDPR Art. 46 (see Cloudflare's Data Processing Addendum at cloudflare.com/cloudflare-customer-dpa). No other international transfers take place. If that changes, this notice will be updated and you will be informed before the change takes effect.

6. How long we keep it (retention)

  • Erasure requests are honoured within 30 days of receipt, in line with GDPR Art. 12(3).
  • Account row + linked auth artefacts (sessions, refresh tokens, rate-limit buckets, OAuth links, TOTP secrets): hard-purged within 30 days of self-service account closure (DELETE /v1/auth/me in the in-product erasure flow). The 30-day window lets us reverse accidental closures.
  • Anti-abuse logs containing IP/UA are retained only as long as needed to investigate abuse signals and are rotated out by the operating-system log lifecycle.

6a. Web push notifications

If you enable alerts, we can deliver them as browser ("web push") notifications. Web push is optional and only ever activated by you: it begins when you set an alert and your browser asks for — and you grant — notification permission. If you deny that prompt we store nothing and fall back to in-app alerts only.

  • What we store: the push subscription your browser hands us — a push-service endpoint URL, the two encryption keys (p256dh and auth) that let only your device decrypt a message, and a short user-agent hint (first 100 characters) so you can recognise the device. We never store the contents of a notification.
  • Legal bases: performance of our contract with you (GDPR Art. 6(1)(b)) — the alert you asked for cannot be delivered without the stored endpoint; and, for placing the subscription on your device, the "strictly necessary" exemption under the ePrivacy rules (Romanian Law 506/2004, Art. 4(5)). Your browser's permission grant is the record of that explicit request, so web push is not part of any cookie-consent banner.
  • Recipients & international transfers: delivery is routed by the push service built into your browser — Google (Firebase Cloud Messaging), Mozilla, or Apple. They act as independent providers and only ever handle an end-to-end encrypted payload they cannot read (RFC 8291). Where this involves a transfer to the United States it relies on the EU–US Data Privacy Framework, where the provider is certified, with Standard Contractual Clauses (GDPR Art. 46) as a fallback.
  • Retention: we delete a subscription when you turn alerts off, when you revoke notification permission in your browser, and when you delete your account (it is removed automatically along with the account). We will also remove subscriptions that become stale — for example once a push service reports one as expired, or after a long period with no successful delivery — so we never keep an endpoint we can no longer use.
  • How to withdraw: turn alerts off in your account settings, or revoke notification permission in your browser — either one removes the stored subscription. Deleting your account removes it too.

7. Your rights

Under GDPR Articles 15–22 you have the right to:

  • Access — ask for a copy of the data we hold about you;
  • Rectification — ask us to correct inaccurate data;
  • Erasure — ask us to delete your data ("right to be forgotten");
  • Restriction — ask us to limit how we use your data;
  • Portability — receive your data in a machine-readable format;
  • Object — object to processing based on legitimate interest;
  • Withdraw consent — for any processing based on consent, at any time, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise any of these rights, email privacy@letguru.app. We respond within 30 days of receipt, in line with GDPR Art. 12(3).

8. Right to lodge a complaint

If you believe we have not handled your data properly, you have the right to complain to the Romanian Data Protection Authority:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 București, România
Web: dataprotection.ro
Email: anspdcp@dataprotection.ro

You also have the right to a judicial remedy under GDPR Art. 79.

9. Is providing your data required?

Providing your email address is required to create an account — without it we cannot register you or send you account-related messages. Refusing simply means no account; there is no other consequence.

9a. Age requirement

letguru accounts are available to users aged 18 or older. Romanian Civil Code Art. 41–42 limits the contractual capacity of minors, so we do not process personal data of users under 18 in connection with account creation or the paid tier. If we learn that an account belongs to a person under 18, we suspend the account and delete the data within 30 days. Full account terms — including the age floor — are in our Terms of Use §4.

10. Automated decision-making

We do not use automated decision-making or profiling that produces legal effects concerning you (GDPR Art. 22).

11. Cookies and similar technologies

letguru uses a small number of strictly necessary cookies and similar technologies on letguru. Romanian Law 506/2004 (transposing EU Directive 2002/58/EC, "ePrivacy") requires that we list them:

  • CSRF token cookie (set by letguru, first-party, session-scoped) — prevents cross-site request forgery on the sign-up and login forms. Cleared when you close the browser tab. No tracking purpose.
  • Cloudflare Turnstile cookies (set by Cloudflare, third-party, short-lived) — used by the anti-bot challenge embedded on the sign-up and login forms. See Cloudflare's privacy policy for details and lifetime. No advertising tracking.

We do not use analytics, advertising, or behavioural-tracking cookies. If that changes, a cookie-consent banner will be added and this notice will be updated before the new cookies are set.

12. Changes to this notice

If we materially change how we process your data, we will update this notice and, where required, notify you by email before the change takes effect. The "Effective date" at the top reflects the current version.

How it works · Roadmap · Privacy · Imprint · Terms · Cookies · Contact ·