Pandelo DE — pandelo.de

Legal

Privacy notice

Version of 10 September 2026

Pandelo is built so that as little as possible about you comes into existence. What does come into existence is written here — in full, with no small print.

Who is responsible

Zamir Celik
Landstrasse 97
9490 Vaduz, Liechtenstein
support@zane.group

Liechtenstein is part of the European Economic Area. The General Data Protection Regulation applies directly here.

The short version

  • This site sets no cookies and does not measure what you do here.
  • Fonts and code libraries are served from this domain — opening the page makes no connection to Google or any third-party content network.
  • Your email address is processed only if you actively sign up as a tester — and only after you click the link in the confirmation email.
  • The app itself sends nothing. Your entries stay on your device.

This website

This site is hosted by Cloudflare. When you open it, your browser transmits technically necessary data that Cloudflare records in server logs: IP address, time, the address requested, amount of data transferred, referring page, and browser and operating-system identifiers. These logs serve the secure and stable operation of the site and the defence against attacks.

The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in being able to deliver the site at all and to protect it from abuse. Cloudflare acts as a processor. A transfer to the United States may occur. The basis is Cloudflare's certification under the EU-U.S. Data Privacy Framework; should that lapse, the European Commission's standard contractual clauses together with supplementary measures apply instead.

What does not happen here

No cookies, no audience measurement, no behavioural analysis, no profiling, no ad networks, no embedded third-party content. Everything this page loads — fonts, the 3D code, the images — comes from this domain.

Signing up for the closed test

How the signup works

Signing up happens in two steps. When you submit the form, your address is only held provisionally and you receive an email with a confirmation link. Only when you click that link does an entry on the tester list come into being. If you do not click, the provisional record is deleted automatically after three days and you hear nothing further. This rules out anyone signing you up without your involvement.

What data this creates

  • the email address you entered,
  • the time of the signup and the time of the confirmation,
  • the country code my host derives from your IP address (e.g. “DE”) — at the time of signup and at the time of confirmation,
  • the language version of the site you signed up through,
  • whether you also want a message when the app is released,
  • the version of this text you agreed to, plus a note that the confirmation went through the double opt-in procedure.

The timestamps, the country codes and the last two items exist solely so that your consent can be evidenced, as Art. 7(1) GDPR requires.

Your IP address is not stored

So that the form cannot be flooded automatically, a check value is derived from your IP address together with a random, secret addition and kept for one hour; after that it expires by itself. The addition is generated randomly once on first operation, is not known to me, and exists only for this installation. Your IP address therefore cannot be recovered from the check value. The IP address itself is stored nowhere.

What it is for

The address serves solely to invite you to the closed test on the Google Play Store and to give you feedback during the test. If you tick the box, I will additionally notify you once when the app is publicly released.

Legal basis

Your consent under Art. 6(1)(a) GDPR. You give it by clicking the confirmation link; the release notification is a separate consent given through the checkbox. Providing the address is voluntary — without it you simply cannot take part in the test. You may withdraw your consent at any time with effect for the future; an informal message is enough.

For how long

I delete the signup data no later than four weeks after the closed test ends. If you consented to the release notification, I keep the address until the app is published and delete it immediately afterwards. Sooner, as soon as you ask.

Who else is involved

The data is not sold, not used for advertising, not combined with other sources and not evaluated for profiling. Two processors are involved:

  • Cloudflare runs the site and the storage the signups live in. A transfer to the United States is possible. The basis is Cloudflare's certification under the EU-U.S. Data Privacy Framework; should that lapse, the European Commission's standard contractual clauses together with supplementary measures apply instead.
  • Sendinblue SAS (“Brevo”), 9–17 rue Salneuve, 75017 Paris, France, sends the confirmation and invitation emails and processes your address for that purpose. Delivery runs on servers inside the EU; no transfer to a third country takes place for it.

Contact form and email

If you write to me through the contact form, I process your email address, your name — if you give one — and the text of your message, solely in order to reply to you.

None of it is stored on this site. The message is forwarded straight to my mailbox and sits there afterwards like any other email. Delivery runs through Sendinblue SAS (“Brevo”) and therefore on servers inside the EU.

The legal basis is Art. 6(1)(f) GDPR — the legitimate interest in being able to answer enquiries at all. If your message concerns a contract or its initiation, Art. 6(1)(b) GDPR applies in addition.

For how long. I delete the correspondence once it is settled and no statutory retention duty stands in the way — at the latest after two years.

So that the form cannot be abused automatically, the same brake applies as above: at most three messages per hour and connection, checked through the same non-reversible check value. Your IP address is not stored here either.

The Pandelo app

The app processes no personal data on a server. There is no account, no login and no synchronisation. Your entries, settings and progress stay exclusively on your device, held in a local database. The app sends this data nowhere and contains neither analytics tools nor advertising nor third-party components that could recognise you.

If you delete the app, the data goes with it. No separate deletion request is needed — I never had a copy.

In-app purchases are handled by Google Play. What data Google processes in doing so is determined by Google; I have no influence over it.

Your rights

You may at any time request access to the data stored about you, as well as its rectification, erasure or the restriction of processing; you also have the right to data portability and a right to object to processing based on legitimate interests. Consent once given may be withdrawn at any time with effect for the future — processing carried out until then remains unaffected.

An informal message to support@zane.group is enough for all of this. No automated decision-making, including profiling, takes place.

Independently of that, you have the right to lodge a complaint with a data protection supervisory authority — in Liechtenstein with the Datenschutzstelle, otherwise with the authority where you are located.

Changes

If anything about the processing changes, I change this text and put a new version date on it. If the change affects data you have already entrusted to me, I will tell you beforehand.