Privacy Notice
This notice explains what personal data www.getsagas.com collects, why, on what legal basis, who receives it, how long we keep it, and what you can do about it. It applies to the English and the German (/de) version of the site alike, and to the emails we send.
Version of 15 August 2026. It replaces the interim notice of 14 August 2026 and describes the site as it is actually built today, purpose by purpose, rather than in general terms.
Who is responsible (the controller)
TRIPLE INFINITY HOLDINGS LLC, a limited liability company under the law of the State of Washington, USA, is the controller for the personal data described here (Article 4(7) GDPR).
Address: 522 W Riverside Ave, Ste N, Spokane, WA 99201-0581, USA.
Email for anything in this notice, including any request about your rights: legal@getsagas.com.
We have no establishment in the European Union or in Switzerland. No single supervisory authority acts as our lead, so you may go to the authority for your own country. See "Complaining to a supervisory authority" below.
What this notice covers
This website, the free readiness check on it, the newsletter, the emails we send in connection with either, and the business contacts we approach ourselves.
It does not cover other companies' sites we link to, and it does not cover a customer platform: we do not operate one yet, and when we do it will carry its own terms and its own notice.
Serving the site: hosting and server logs
The site is hosted by Vercel. To deliver a page, Vercel necessarily processes your IP address together with the request itself: the address requested, the time, the response status, your browser's user agent string, and the region the request was served from.
We do not copy those logs into our own systems, we do not analyse them, and we do not build profiles from them. Vercel keeps them for a short window set by our plan, at most 30 days, and then deletes them.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is delivering a working and reasonably protected website, and there is no way to send a page to you without processing the address it has to be sent to.
The visitor identifier, and why we call it pseudonymous
We do not store your IP address in our own database. Where we do need to tell one visitor apart from another, to count how many people used the check on a given day, to record a cookie decision, or to stop the newsletter form being abused, we compute a short identifier instead: your IP address, your browser's user agent string and the current date are combined, put through a keyed one-way hash function, and only the first 16 characters of the result are kept. The inputs themselves are never stored.
That hash is keyed everywhere we use it, for analytics events, for cookie consent records and for the newsletter form's abuse counters alike: HMAC-SHA-256 under a secret that exists only on our server. Without the secret, the value cannot be reproduced by guessing at inputs.
Because the identifier no longer varies by what kind of record it is computed for, the same identifier is shared across every analytics event, every cookie consent record and every abuse counter we write for one visitor on one day. That lets us tell, inside our own database, that two records from the same day belong to the same visitor; it does not let us, or anyone else, work out who that visitor is.
This identifier is pseudonymous, never anonymous. It is personal data within the meaning of Article 4(1) and (5) GDPR, and everything in this notice applies to it. Because the date is one of the inputs, the value changes every day and cannot follow you from one day to the next, and we do not use it to look anyone up by name or email address. One narrow exception is built into the sign-up form's abuse counters: a sign-up writes one counter under the identifier and one under a keyed hash of the address on the same day, so on a quiet day the two could in principle be lined up.
Forms: early access and the waitlist
Two forms on this site ask for an email address: early access for battery teams, and the waitlist for consumer brands. The report request at the end of the readiness check is a third, described in the next section.
What we store when you submit one: your email address, which form it was, the path of the page you sent it from, the referring page if your browser supplied one, the campaign parameters of the link that brought you (utm_source, utm_medium, utm_campaign) if and only if you have agreed to analytics, and the time.
We hold one entry per form and address. Submitting the same address on the same form again replaces the earlier entry, including its timestamp.
Purpose: to answer you, to send you what you asked for, and to see which channels bring people here. Legal basis: Article 6(1)(b) GDPR where you are asking us to take steps before a possible contract, which is what early access and the waitlist are, and otherwise Article 6(1)(f) GDPR, our legitimate interest in responding to people who approach us.
The readiness check and the gap report
The check runs in your browser. There are twelve questions: two of them decide whether the rules apply to you at all and when, and the other ten are scored. Your answers are not sent to us as you answer them.
If you have agreed to functional storage, your progress is held in your browser's session storage so that reloading the page does not lose it. If you declined, the check still works from beginning to end; the only thing you lose is the ability to resume.
If you fill in the form at the end to have the report sent to you, that reaches us whatever you have decided about analytics: your email address, the page you sent it from and the referring page if your browser supplied one, and a short summary of your result, your score out of ten, whether you said the rules apply to you, the timing you selected, and which areas came out as gaps or as partly covered. Separately, if you have agreed to analytics, the check also sends a pseudonymous record when you start it, abandon it or complete it, including the score, scope and timing for a completed one, described under "Analytics" below.
That summary says something about your company's compliance position, which is commercially sensitive. We use it only to send you the report and to prepare for a conversation if you ask for one, we never pass it to anyone outside the providers listed under "Who receives your data", and we delete it earlier than the contact entry itself. Legal basis: Article 6(1)(b) GDPR, since you asked us for something specific, and otherwise Article 6(1)(f) GDPR.
How the check is scored, and what that score is not
The scoring is fixed and mechanical. Each of the ten scored questions is rated ready, partly covered, or a gap by a rule that does not change: yes counts as ready and scores one point, partly counts as partly covered and scores half a point, no and not sure both count as a gap and score nothing, and a question you skip is treated as not sure. The score is the sum, out of ten, and the report lists your gaps in order of how much lead time each one usually needs.
The same answers always produce the same report. Nothing about you personally goes into it, and no data from any other source is added to it.
What comes out is a statement about products and processes at a company, not an assessment of you as a person, and nothing follows from it: your access to this site, the prices we publish, and what we offer you are the same whatever it says. If we ever began using a result to decide whether to work with someone, what to charge them, or whether to turn them away, we would say so here before we did it.
Newsletter
The consent box is never pre-ticked, you tick it yourself, and it asks about the newsletter alone rather than being bundled with anything else.
When you submit the form we store: your email address in lower case, your first name and last name if you chose to give them (both are optional), the page you signed up from, the language you were reading, the exact consent wording you were shown together with its version, and the time. We also generate two random tokens, one for confirming and one for unsubscribing.
We then send exactly one email, and it contains nothing but the request to confirm. Until you click the link in it you are not subscribed and we send you nothing else. That link works once and expires after seven days; if it goes unused, the pending entry is deleted.
Once you confirm, we record the time of confirmation and send one welcome email. Every newsletter email carries an unsubscribe link and the List-Unsubscribe header, so that your mail program's own unsubscribe button works as well. The confirmation request carries neither, on purpose: until you confirm there is no subscription to leave, and an unconfirmed address gets that one message and nothing else.
Legal basis: your consent, Article 6(1)(a) GDPR, and Section 7(2) No. 2 of the German Act against Unfair Competition (UWG) for the sending itself. The single confirmation email is not advertising: we send it to check that the address belongs to the person who entered it, and so that we can demonstrate the consent we rely on (Article 7(1) GDPR).
You can withdraw your consent at any time with effect for the future, and withdrawing is exactly as easy as giving it was: one click on the unsubscribe link, no login, no confirmation step, no reason required. Withdrawal does not make what we did beforehand unlawful.
When you unsubscribe, your subscriber entry is deleted. Your address and the date stay on a suppression list, and nothing else: that list exists only so that a later sign-up or import cannot put you back on a list you left (Article 21(3) GDPR). The sign-up form checks it, so entering an address that is on it changes nothing and sends nothing, whoever typed it in.
If you later decide you do want the newsletter after all, write to legal@getsagas.com. We take your address off the suppression list, and you can then sign up again in the ordinary way. Doing it by hand is deliberate: it means nobody but you can undo your own objection.
We use no tracking pixels, we do not measure whether you opened an email, and we do not route links through a click tracker. Every email is sent in two versions, a styled one and a plain text one, with the same content and the same links; neither includes an image.
Sign-ups from before 14 August 2026. Until that date the footer form stored an address as an ordinary form entry, marked newsletter-interim, with no consent box and no confirmation step. Those addresses were never migrated into the subscriber list, nothing has ever been sent to them and nothing will be, and we delete them at most 90 days after they were submitted. You can ask us to delete yours sooner at any time. The basis for holding them for that bounded window is Article 6(1)(f) GDPR, our legitimate interest in being able to invite someone who asked to be kept informed, and nothing further.
Keeping the sign-up form from being abused
Anyone can type someone else's address into a sign-up form. Double opt-in means that person receives one confirmation request and nothing further, and the counters described here limit how many such requests can be triggered at all: at most ten attempts a day from one visitor identifier, and at most five a day for any one address.
For that we store, per day: whether the counter belongs to a visitor or to an address, the value it counts (the keyed visitor identifier described above, or a keyed hash of the address, never the address itself), and the count itself.
Legal basis: Article 6(1)(f) GDPR. The legitimate interest is ours and, more to the point, that of the person whose address it is: the form must not become a way of sending them mail they did not ask for.
Analytics
Nothing in this section happens before you agree to analytics in the cookie banner. Until then Google Analytics is not in the page at all, no measurement request is sent to us, and no campaign parameters are stored in your browser.
Our own event log. With analytics allowed, the site sends us short events from a fixed list: the readiness check started, completed or abandoned, the tap-to-verify demo used, a click on a link to book a call. Each event carries the path of the page, the referring page and campaign parameters. In addition, depending on the event: for a completed check, the score, the number of questions, whether the rules apply to you, the timing you selected and whether the completion counted towards our own goal tracking; for a started check, whether you were resuming an earlier one; for an abandoned check, the number of the last question you reached, which is a record of how far into the twelve you got before stopping; for the demo, which element you tapped and which action it triggered; and for a booking link, which page it was clicked from. Each entry also carries the visitor identifier and the date.
We keep one entry per event type, day and visitor identifier, so a repeat of the same event on the same day overwrites the first. What we hold is therefore a count of visitor-days, not a trail of individual clicks. Requests from recognised bots, and requests sent from a deployment other than the live production site (previews, local development), are accepted and discarded.
Google Analytics 4. With analytics allowed we also load Google Analytics 4, which sets its own cookies and processes data on Google's infrastructure, with Google acting as our processor. The cookies and their lifetimes are listed in the Cookie Policy. One event goes only there: a newsletter sign-up is mirrored to Google Analytics, while our own event log rejects it, so we store nothing about it ourselves.
Legal basis: your consent, Article 6(1)(a) GDPR, for the processing, and Section 25(1) TDDDG for the storing of and access to information on your device. You can withdraw it at any time through the Cookie settings link in the footer, with effect for the future.
Your cookie decision, and the record we keep of it
When you agree to a category, your browser sends us a record: the decision (granted or withdrawn), which categories it covered, the version of the banner text you were shown, the language you were reading, the time, and the keyed visitor identifier. Narrowing an earlier agreement is sent the same way and recorded as a withdrawal, which is what happens when you switch one category off and leave another on.
Two decisions are never sent to us at all and stay in your browser: refusing everything, and switching every optional category back off. Both of those say stop, and we are not going to answer that by creating a fresh record about you.
Records are added, never overwritten: where a withdrawal does reach us, it sits beside the consent it narrows, because being able to show what was agreed and when is the entire point of keeping it.
So that this record cannot be filled up by anyone who feels like it, we count how many decisions arrive from one visitor identifier per day and stop accepting them past a limit no ordinary use comes near. That counter works exactly like the sign-up counters described above, and is kept for the same 30 days.
Your decision is remembered in your browser for twelve months, after which we ask again. If we change the banner wording we also ask again, since agreement to different words is not agreement to these.
Legal basis: Article 6(1)(c) GDPR together with Article 7(1) GDPR and Section 25 TDDDG. We keep the record in order to be able to demonstrate the consent those provisions require.
Cookies and storage on your device
The Cookie Policy lists every cookie and every piece of browser storage this site uses, what each one is for, which category it belongs to, and how long it lasts.
One is worth naming here: the language cookie is written only when you choose a language yourself in the header. It is never set on an ordinary page load and never on a redirect.
Business contacts we approach ourselves
We contact companies in the battery industry directly about the digital passport requirements that apply from 18 February 2027. If you heard from us that way, your data did not come from you, and this section is what Article 14 GDPR requires us to tell you.
Categories of data: the company and its website, a business email address, and, where a company publishes them, the name and role of a contact person, together with our own note on why that company may be affected.
Where it comes from: publicly accessible sources, specifically company websites and public business directories and registers.
Purpose and legal basis: telling companies that may be affected about the deadline and about what we sell. Legal basis: Article 6(1)(f) GDPR; the legitimate interest is direct marketing to businesses, and Recital 47 GDPR names direct marketing as a legitimate interest that can carry it. We give you this information at the latest in our first message to you (Article 14(3)(b) GDPR).
Recipients: only Google Workspace, listed below, because we send this outreach from a mailbox rather than through this platform; outside an objection (see "Objecting to direct marketing"), none of the other providers below receive it. We keep this data for 24 months after our last contact with you.
Your right to object is unconditional, and one line back to us is enough to end the contact permanently. See "Objecting to direct marketing" below.
Who receives your data
We do not sell personal data, we do not share it with anyone for their own marketing, and we use no advertising networks. Apart from the providers below, data leaves us only where we are legally required to disclose it.
- Vercel Inc. (USA): hosting and delivery of the site; sees IP addresses and request metadata.
- Neon Inc., a Databricks company (USA): the database in which everything described above is stored, except the business contacts we approach ourselves, which are not held in a database at all outside an objection (see "Objecting to direct marketing").
- Plus Five Five, Inc., trading as Resend (USA): delivery of the confirmation and welcome emails; sees the recipient address and the message.
- Google LLC (USA): Google Workspace, which carries the email addresses named in this notice, legal@getsagas.com and khoa@getsagas.com; sees anything sent to or from those addresses, including a rights request you send us.
- Google LLC (USA) and Google Ireland Limited: Google Analytics 4, and only once you have agreed to analytics.
Processors, and one company that is not one
Each provider above acts for us as a processor, on our instructions, under the data processing terms that provider publishes (Article 28 GDPR).
One company is worth naming precisely because people assume otherwise: Cloudflare operates the DNS for our domain, which means it answers the question of which server our name points to. It does not sit in front of the site, it does not proxy requests, and it does not see the traffic between you and the site.
Where your data is processed, and the safeguards we rely on
We are a US company and the providers above are US companies, so the processing described here takes place in the United States. Data you send us yourself is not an international transfer within the meaning of Chapter V GDPR, because we collect it directly as controller rather than exporting it from anyone in the EU; that is the reading in the European Data Protection Board's Guidelines 05/2021. The transfers that do need a safeguard of their own are the ones from us to these providers.
Each of the four lines below reports what that provider publishes for itself. We read Vercel's, Neon's, Resend's and Google Analytics 4's on 15 August 2026, and give them as that provider's own statement rather than as a conclusion of ours.
- Vercel Inc.: Vercel's published data processing addendum, in its version of 31 March 2026, provides for the EU standard contractual clauses under Commission Implementing Decision (EU) 2021/914 and, for the United Kingdom, the UK International Data Transfer Addendum. That document claims no Data Privacy Framework certification, and we do not claim one for it.
- Neon Inc.: Neon's published data processing agreement states that Neon relies on the EU-US Data Privacy Framework, the Swiss-US Data Privacy Framework and the UK Extension, and that the standard contractual clauses are incorporated and take over if a framework does not cover a transfer or ceases to apply, with the UK Addendum and the Swiss adaptations where those are relevant.
- Plus Five Five, Inc. (Resend): its data processing agreement, effective 31 December 2025, provides for the EU standard contractual clauses, applied in their modified form for transfers out of Switzerland. Resend states in that same document that it has certified to the EU-US Data Privacy Framework and its UK Extension.
- Google LLC (Google Analytics 4): Google states that for its advertising and analytics products it has relied on the EU-US Data Privacy Framework since 1 September 2023 and, since 16 September 2024, on the Swiss-US Data Privacy Framework and the UK Extension for transfers from Switzerland and the United Kingdom, and that it may rely on the standard contractual clauses where it does not rely on a framework.
- Google LLC (Google Workspace): for this transfer we rely on the European Commission's standard contractual clauses.
If a framework is withdrawn
Whether an adequacy decision stays in force is not in our hands. If one is annulled or suspended, we will move the affected transfer to another safeguard and say so here.
You can ask us for the current text of any of the documents named above, and we will send you the link or the document itself.
If you are in Switzerland
The Swiss Federal Act on Data Protection applies to this processing alongside the GDPR. Article 19(4) of that Act requires us to name the country your data goes to and the safeguard that covers it.
Destination country: the United States, for every recipient named above, and for us, since we are a US company.
Safeguards: Switzerland recognised the Swiss-US Data Privacy Framework as providing adequate protection with effect from 15 September 2024, and Neon and Google Analytics 4 both state that they rely on it. For recipients that do not, including Google Workspace, we rely on the European Commission's standard contractual clauses, which the Federal Data Protection and Information Commissioner recognises, read with the adaptations Switzerland requires: references to the GDPR read as references to the Swiss Act, the Commissioner as the competent authority, and the Swiss courts as the competent courts.
Your rights under the Swiss Act, in particular information, correction, deletion and data portability, work the same way as the rights below, and the same address reaches us. You can also contact the Federal Data Protection and Information Commissioner in Bern.
How long we keep each kind of data
The periods below are our retention rules. For the data that lives in our own database, a job that runs once a day deletes it once its period has run out, so nothing there depends on someone remembering to do it by hand. Business contacts we approach ourselves are the exception: outside an objection (see "Objecting to direct marketing"), they are not held in that database at all, and we delete them from where they do live, a mailbox, by hand.
- Form entries (early access, waitlist): 24 months after you last submitted that form. Submitting the same address on the same form again replaces the entry and restarts the period.
- The answer summary attached to a report request: 12 months, after which the summary is removed and only the contact entry remains, under the line above.
- Analytics events: at most 90 days after they are recorded, we fold each day's events into one count per event type and delete the recorded entries. That count carries no visitor identifier, so once the entries behind it are gone it is no longer personal data, and we keep it afterwards so we can still see our own trends.
- Newsletter, not yet confirmed: deleted when the confirmation link expires, 7 days after sign-up.
- Newsletter, confirmed: for as long as you are subscribed.
- Newsletter, after you unsubscribe: your address and the date stay on the suppression list for as long as we run a newsletter at all, because that is what keeps you off it.
- Newsletter sign-ups from before 14 August 2026 (the newsletter-interim entries): at most 90 days after they were submitted.
- Cookie consent records: three years after the decision was recorded.
- Abuse counters for the sign-up form and the consent record: 30 days after the day they count.
- Business contacts we approached: 24 months after the last contact, or at once on objection, apart from the minimum needed to make sure we do not contact you again.
- Server logs at our host: a short window set by our plan, at most 30 days, after which the host deletes them.
Whether you have to give us anything
No. You can read every page of this site without providing personal data: there is no login, no wall, and no form you have to pass. The readiness check itself asks you for none, though it does generate the pseudonymous analytics record described above if you have agreed to analytics.
Where a form asks for your email address, giving it is neither required by law nor a condition of any contract. It is simply what we would need in order to do the thing the form offers. If you do not give it, we cannot send you the gap report, cannot put you on the early access list, and cannot send you the newsletter. Nothing else follows: no page is withheld from you and no price changes.
Your rights
Under the GDPR, and subject to the conditions it sets, you have the right to:
- ask what data we hold about you and receive a copy of it (Article 15)
- have inaccurate data corrected (Article 16)
- have your data erased (Article 17)
- have processing restricted (Article 18)
- receive the data you gave us in a portable format, and have it sent on where that is technically possible (Article 20)
- object to processing based on our legitimate interest, on grounds relating to your particular situation (Article 21(1)), and to direct marketing at any time and with no grounds at all (Article 21(2), see below)
- withdraw a consent at any time, without affecting what was lawful before you did (Article 7(3))
- complain to a supervisory authority (Article 77, see below)
Exercising them
Write to legal@getsagas.com. We answer within one month; if a request is genuinely complex we may take up to two months longer, and we will tell you inside the first month if that happens (Article 12(3) GDPR). Answering costs you nothing (Article 12(5) GDPR).
We may ask for something that lets us be sure it is you, but only what is actually needed for that, and never a copy of an identity document (Article 12(6) GDPR).
One honest limit. Some of what we hold is pseudonymous by design and cannot be traced back to a person by us. We cannot connect an analytics visitor identifier to you without you handing us more data than we hold, and we are not going to ask you to do that. Where we genuinely cannot identify you in a record, Articles 11(2) and 12(2) GDPR mean the rights of access, correction and erasure cannot be exercised on that record. Everything we hold under your email address is covered by those rights in full.
Objecting to direct marketing
You may object at any time to our use of your personal data for direct marketing, including any profiling connected with it (Article 21(2) GDPR).
This right is unconditional. You do not have to give a reason, there is no balance of interests for us to weigh against it, and there is no case in which we may carry on anyway. Once you object, we stop using your data for direct marketing immediately and permanently (Article 21(3) GDPR).
In practice: click the unsubscribe link in any email, or send one line to legal@getsagas.com. The only thing we keep afterwards is the minimum that lets us honour the objection, which is your address on a suppression list.
Complaining to a supervisory authority
You may complain to a data protection supervisory authority, in particular in the EU or EEA state where you live, where you work, or where you believe something went wrong (Article 77 GDPR).
Because we have no establishment in the European Union, the one-stop-shop mechanism does not apply to us and there is no lead authority to be referred to. Each national supervisory authority is competent in its own right, so the authority for your country can take your complaint directly. In Switzerland, the Federal Data Protection and Information Commissioner is the address; in the United Kingdom, the Information Commissioner's Office.
You are welcome to raise it with us first at legal@getsagas.com, but nothing obliges you to.
How we protect your data
Traffic to the site and to our endpoints is encrypted in transit. The database is not reachable without credentials, and those credentials, along with the secret key used to compute the visitor identifier, exist only on the server side and never in your browser.
Confirmation and unsubscribe tokens are 32 bytes from a cryptographic random source. A confirmation token can be used once and expires after seven days.
One person runs this company, and no one else has access to the data. Where a provider processes data for us, that provider's own security terms apply in addition.
Changes to this notice
This version is dated 15 August 2026 and replaces the interim notice of 14 August 2026. We update it when the processing changes, and the date changes with it. Where processing rests on your consent, a material change means we ask you again rather than announce it here.
Contact
TRIPLE INFINITY HOLDINGS LLC, 522 W Riverside Ave, Ste N, Spokane, WA 99201-0581, USA.
Email: legal@getsagas.com.