SUCRE Website Privacy Notice
This notice is also available in German: Datenschutzhinweise auf Deutsch
Last updated: 8 August 2026 Applies to: visiting this website, sucreapp.com
1. What this notice covers
This notice explains what happens when you visit this website. Nothing more — the website is a handful of static pages about the SUCRE app, and visiting it is all you can do here.
The SUCRE iOS app has its own Privacy Policy, which covers everything the app does: Privacy Policy (Datenschutzerklärung). The two documents are separate on purpose, so each can be precise about its own subject.
2. Who is responsible
The controller for the purposes of the EU General Data Protection Regulation (GDPR) is:
Hakim Bahdo, trading as Vitality Sphere Auf der Au 6 54296 Trier Germany
Privacy contact: privacy@sucreapp.com General support: support@sucreapp.com
We have not appointed a Data Protection Officer, and we are not required to (Art. 37(1) GDPR, § 38 BDSG).
3. What this website does not do
- It sets no cookies — none at all, so there is nothing to consent to.
- It runs no analytics and contains no tracking of any kind.
- It has no accounts, no login and no forms. You cannot enter data anywhere on it.
- It loads nothing from third-party servers — no external fonts, images, scripts or embeds.
- It contains no advertising.
The pages work fully with JavaScript disabled, because they contain no JavaScript.
4. What happens technically when you visit
Like every website, this one is delivered over the network. When your browser requests a page, that request necessarily includes your IP address, the address of the page you asked for, and technical details your browser sends with every request (such as browser type and preferred language).
We do not run a web server of our own. The site is delivered by our hosting provider:
Cloudflare, Inc. (USA) — the site is served by Cloudflare Pages from a data centre near you. Cloudflare processes the connection data above in order to deliver the pages and to protect the site against attacks and abuse. Cloudflare acts as our processor: its Data Processing Addendum is incorporated into the service terms under which we use it, and that addendum incorporates the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). For transfers to the United States, Cloudflare is additionally certified under the EU-U.S. Data Privacy Framework, including its Swiss and UK extensions.
Cloudflare keeps this connection data only for the limited period it needs for delivery, security and abuse protection, under its own operational rules. We ourselves receive no visitor logs at all: we have not enabled any analytics product, and the hosting plan we use does not give us per-visitor data. We could not tell you who visited this site if we wanted to.
Legal basis: our legitimate interest in serving a fast, reliable and secure website (Art. 6(1)(f) GDPR). The processing is limited to what delivering a web page inherently requires.
5. Browser error reports
The responses our host sends include a standard instruction (Report-To / NEL headers) that asks your browser to report failed page loads to Cloudflare, at a.nel.cloudflare.com. This is configured so that successful visits are never reported — only network errors. Such a report contains the address that failed, the type of error, and technical connection details; it contains no cookie and no identifier of you. The instruction expires from your browser after seven days unless renewed. Cloudflare uses these reports to detect network problems.
This behaviour is set by Cloudflare as part of its service, not by code of ours. The same legal basis and the same retention position as in section 4 apply: Cloudflare keeps the reports only as long as analysing network problems requires, under its own operational rules.
6. Encryption
The connection between your browser and this website is encrypted (HTTPS). Plain HTTP requests are redirected to the encrypted version.
7. If you email us
The website invites you to contact support@sucreapp.com or privacy@sucreapp.com. Emailing us is your choice; the mail is handled as described in section 12 of the app Privacy Policy: it stays in our mailbox while we deal with your matter and is deleted 12 months after the matter is resolved, unless the law requires longer or we still need it to establish, exercise or defend a legal claim. Where you are exercising a data-protection right, we process your message because we are legally obliged to deal with it (Art. 6(1)(c) with Art. 12 GDPR); for any other message, our legitimate interest in answering you (Art. 6(1)(f) GDPR).
8. Your rights
Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to processing, and to data portability. You may also complain to a supervisory authority — in our case the data-protection authority of Rhineland-Palatinate, Germany, or the authority where you live.
In practice, we hold nothing about your visit: we keep no visitor logs and cannot identify you from anything this website produces (Art. 11 GDPR). If you have emailed us, the mail itself is what we hold, and you can ask us about it at privacy@sucreapp.com — we answer within one month.
9. Changes
If this website starts doing more than described here — for example, if a newsletter or any analytics were ever added — this notice will be updated before that change goes live, and the date at the top will change.