Privacy policy
Effective date: 10 October 2026
1. Controller
SIRAT SOLUTIONS GmbH
Martin-Luther-King-Straße 40
63452 Hanau, Germany
Email: info@sirat-solutions.de
2. Purpose and scope We process personal data when you visit our website (www.nafscheck.com) or use the NafsCheck mobile app. Processing is limited to providing the service, operating the app, answering contact requests, and handling paid peer ratings or in-app purchases. We do not process data for advertising or profiling.
3. Hosting and server logs (website) Our website is hosted by ALL-INKL (Neue Medien Münnich). When you access the site, the provider automatically collects server log data (e.g. IP address, date/time, requested URL, referrer, browser). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and stable operation). Log data is deleted automatically by the host.
4. App data processing (NafsCheck)
When using the app, the following data may be processed:
– Account data (name, email, optionally gender, age, app language)
– Self and peer ratings
– Device information (device ID, OS version)
– Usage information (sections viewed, rating trends)
– Payment/transaction data for paid peer ratings
Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Data is stored only as long as necessary.
5. Cookies / tracking We do not use tracking cookies and we do not integrate third-party analytics. Currently no technical cookies are set.
6. Links to social media Our website contains links to our profiles on Instagram, Facebook, TikTok and YouTube. The logos are loaded locally from our web server. We do not use social media plugins or embedded content from these platforms; visiting our website alone therefore does not establish a connection to them. A connection is made only when you click a link and visit the respective platform. Its operators may process personal data such as your IP address, browser and device information, and use cookies or similar technologies. Information about processing on each platform is available in the respective operator’s privacy notice.
7. Contact by email If you contact us by email, we process your email address, the content of your message and any other information you voluntarily provide to handle and respond to your enquiry. Our website currently has no contact form. For enquiries relating to a contract or steps prior to entering into a contract, the legal basis is Article 6(1)(b) GDPR. Other enquiries are processed on the basis of Article 6(1)(f) GDPR; our legitimate interest is handling and responding to your enquiry. The data is deleted once the enquiry has been fully resolved and further retention is no longer necessary. Where statutory retention obligations apply or data is necessary to establish, exercise or defend legal claims, the relevant data is retained for the period required.
8. Data recipients We do not sell your data. Data is shared only where necessary (e.g. payment processors) or where required by law.
9. Security All transmissions are TLS-encrypted. We apply appropriate technical and organisational measures (Art. 32 GDPR) to protect personal data from unauthorised access or loss.
10. Fonts Our website uses system fonts available on your device, such as Arial or Helvetica. No external font files are loaded to display text. No requests are made to Google Fonts or other external font providers.
11. Children NafsCheck is intended for users aged 12 and older. Users under 18 should use the app only with parental consent.
12. Your rights You have the rights of access, rectification, erasure, restriction, portability and objection (Art. 15–21 GDPR). Please contact: info@sirat-solutions.de.
13. Supervisory authority Hessian Commissioner for Data Protection and Freedom of Information (HBDI), Wiesbaden, Germany.
14. Changes We may update this Privacy Policy to reflect legal or technical changes. The current version will always be published on this page.
15. Website member areaWe use Google Firebase Authentication and your existing app account for sign-in. We process your email address, technical connection data and authentication; your app user profile is retrieved to check eligibility for access. The website does not create new accounts. Session state is stored in your browser and removed when you sign out. Password reset sends an email through Firebase; the new password also applies to the app. The legal basis is Article 6(1)(b) GDPR. See the preceding sections for further information on Firebase and data transfers. The member area also retrieves and displays your own assessments, results, connections, rating requests and current token balance from Firebase. The website does not modify these records.
