Legal · Privacy

Privacy policy

How daystromworks.com processes personal data, under the EU General Data Protection Regulation (GDPR) and the Estonian Personal Data Protection Act (isikuandmete kaitse seadus, IKS). Plain-English summary first, then the specifics for each part of the site.

Summary

  • We do not run analytics, tracking pixels, advertising cookies, or fingerprinting.
  • We process the minimum data needed to run the site and the free GEO tools, and to defend against abuse.
  • Some of our service providers are based in the United States. Transfers happen under Standard Contractual Clauses and (where applicable) the EU-US Data Privacy Framework.
  • You have the rights set out under the GDPR (access, rectification, erasure, restriction, portability, objection, withdrawal of consent, complaint to the Andmekaitse Inspektsioon).

1. Controller

The controller responsible for processing under Art. 4(7) GDPR is:

Daystrom OÜ (private limited company, Estonia)
Registry code 17537299 · VAT EE102999776
Tornimäe tn 5, Kesklinna linnaosa, 10145 Tallinn, Estonia
Email: hello@daystromworks.com

No data protection officer (DPO) is appointed; the controller does not meet the criteria of Art. 37 GDPR.

2. Server logs

When you visit the site, our hosting provider (Vercel) processes the following technical data: IP address, user-agent string, referrer, requested URL, response status, timestamp. This is required to deliver the page and to defend against abuse.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating and securing the site).
Retention: in line with Vercel's log retention (typically up to 30 days). We do not aggregate or persist logs beyond Vercel's defaults.

3. Free GEO tools (/tools/aio-check, Fix Pack)

When you submit a URL to the GEO check, we fetch that URL from our server, analyse the response, and return a report. Your IP address and the submitted hostname are used for rate limiting (stored in Upstash Redis). The report itself is stored under a random slug for 30 days so you can share or revisit it. No email is required for the free check.

To produce parts of the analysis (such as suggested topics, a rewritten opening paragraph, or draft FAQs), the public text content we fetched from the URL you submitted is sent to a large-language-model provider (Groq) for processing. We do not send your personal data in this step; only the content of the page at the URL you asked us to audit.

When you request a Fix Pack, you provide your email address. The generated ZIP and a manifest (containing your email, the audited site, score, and grade) are stored in Upstash Redis for 30 days. We email you the download link via Resend, and we email ourselves a notification of the new request.

When you request the GEO report by email, we store your email address and the report slug in Upstash Redis (no automatic expiry on the lead list) and email you the report via Resend.

Legal basis: Art. 6(1)(b) GDPR (delivering the service you requested) for the email and the stored result; Art. 6(1)(f) GDPR (rate limiting and abuse prevention) for the IP-based limits.
Retention: reports and Fix Pack ZIPs auto-expire after 30 days. Lead records (email plus audited URL plus score) are kept until you ask us to delete them.

4. Booking calls (Cal.com)

Calls are scheduled through Cal.com. When you follow a booking link on the site and choose a slot, your name, email, the slot you choose, and any notes you enter are processed by Cal.com to create the booking, send confirmations, and add the event to our calendar.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measure at your request).
Provider: Cal.com, Inc. Privacy policy: cal.com/privacy.
Retention: per Cal.com's policy and our own calendar; bookings tied to invoiced engagements are retained for the periods required by the Estonian Accounting Act (raamatupidamise seadus, 7 years).

5. Cookies and local storage

The site sets no advertising or analytics cookies. Theme preference (light/dark) is stored in your browser's local storage if you change it; that data never leaves your device. No consent banner is shown because no consent-requiring technologies are used.

6. Fonts and images

Typefaces are loaded from Google Fonts (fonts.googleapis.com, fonts.gstatic.com). When fonts are requested, your browser connects to Google's servers and your IP address is transmitted. Some images may be loaded from Unsplash (images.unsplash.com).
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in delivering the page consistently).

7. Processors and third-country transfers

The following processors handle data on our behalf. Some are based in the United States. Transfers rely on Standard Contractual Clauses under Art. 46(2)(c) GDPR and, where applicable, the EU-US Data Privacy Framework. You should be aware that residual access by US authorities (for example under FISA 702) cannot be excluded.

  • Vercel Inc. (USA): hosting, edge functions, logs. Privacy · DPA
  • Upstash, Inc. (USA / EU regions): Redis storage for rate limiting, GEO reports, and Fix Pack bundles. Privacy · DPA
  • Groq, Inc. (USA): LLM inference for the GEO analysis (processing the public content of the URL you submit). Privacy
  • Resend (Resend, Inc.) (USA, EU region available): transactional email delivery. Privacy · DPA
  • Cal.com, Inc.: booking and scheduling back-end. Privacy
  • Google Ireland Ltd.: Google Fonts. Privacy
  • Unsplash Inc.: image hotlinking. Privacy

8. Automated decision-making and profiling

No decisions with legal or similarly significant effect on you are made automatically. The GEO tools score the public URL you submit; booking and engagement decisions are made by humans.

9. Your rights

Under the GDPR you have the right to:

  • Access (Art. 15): confirmation of whether we process your data, and a copy of it.
  • Rectification (Art. 16): correction of inaccurate data.
  • Erasure (Art. 17): deletion, where the legal grounds apply.
  • Restriction of processing (Art. 18).
  • Data portability (Art. 20).
  • Objection (Art. 21): in particular against processing based on legitimate interest.
  • Withdrawal of consent (Art. 7(3)): without affecting the lawfulness of processing before withdrawal.

To exercise any of these, email hello@daystromworks.com.

10. Right to complain

You may lodge a complaint with the Estonian data protection authority, our lead supervisory authority:
Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
Tatari 39, 10134 Tallinn, Estonia
Email: info@aki.ee
Web: aki.ee

If you are located in another EU/EEA country, you may also lodge a complaint with your local supervisory authority.

11. Changes

We may update this policy when the site or its processors change. Material changes will be highlighted at the top of this page.

Last updated: 2026-06-23