Privacy policy
1. Data controller
Controller: full identification (legal name, registered office, company ID where applicable) appears or will appear in the site’s legal notice. General contact: use the details published on that page or in the site footer. Personal-data requests may be sent to the general contact (without prejudice to a future DPO appointment if required by law).
2. Data collected
Depending on the case: identity and birth data (date, place, time if known), contact details (email, phone), relationship data (synastry type, forecast period), form contents (DHN questionnaires, notes), account identifiers (Google sign-in or hashed email/password), email verification status and short-lived tokens (sign-up confirmation, password reset), order data (report type, status, Stripe references), “client” records entered in the signed-in workspace, SpikkChat data (messages exchanged, conversation metadata, discussion-credit balances and movements, any consent to conversational memory), technical anti-abuse acquisition register (one-way cryptographic fingerprint of the normalised email — without storing the address in plain text after account erasure —, indicators of one-time SpikkChat welcome grant and freemium usage), technical logs (including request IDs for diagnostics), payment data processed by Stripe (full card numbers are not stored by the publisher). Where place suggestions (Google Places) are enabled, search fragments may be sent to Google.
3. Purposes and legal bases
Contract performance (orders, production, delivery, support, account and credit management) — legal basis: performance of a contract (GDPR Art. 6(1)(b)). Email address verification on password sign-up — legal basis: contract performance and account security (6(1)(b) and 6(1)(f)). Invoicing and legal obligations — legal basis: legal obligation (6(1)(c)). Service security, request rate limiting (anti-abuse), anti-bot checks on sensitive authentication and public forms when strict configuration is enabled, fraud prevention and prevention of repeated misuse of trial offers — legal bases: legitimate interests (6(1)(f)) and/or legal obligation as applicable. Service improvement (aggregated statistics where not legally sensitive) — legitimate interest or consent as applicable. B2B outreach (if any) — legitimate interest or consent depending on practice (to be specified if you enable campaigns).
4. Retention and your rights
Astrology-related data (birth date, time, place, related questionnaires) are kept for as long as needed to perform the contract and, for connected accounts, while the account is active; they may be erased or anonymised in the application database when you exercise your right to erasure or on account closure initiated from the signed-in workspace, subject to legal exceptions. Closure removes the sign-in account; unused wallet credits are forfeited with no cash conversion (see the terms of sale). Email verification and password-reset tokens are kept only as long as needed for their purpose (limited validity shown or implied in the flow). The anti-abuse acquisition register (email fingerprint, without the address in plain text) may be retained after account closure to prevent repeated trial grants to the same email address, to the extent necessary and proportionate to the legitimate interest of fraud prevention. Payment and billing evidence (payer identity, amounts, Stripe references, order references) may be kept for up to ten (10) years for accounting and tax duties: that evidence does not necessarily include third parties’ birth times or places once separated from astrology case files. PDF files and metadata for deliverables filed in the signed-in workspace follow the same retention framework, subject to your rights and legal obligations. You have rights of access, rectification, erasure, restriction, objection and data portability where they apply, and the right to lodge a complaint with a supervisory authority (in France, the CNIL, www.cnil.fr). Rights requests: use the same channel as the controller’s general contact (see legal notice). You may also set directives regarding the retention, erasure and communication of your personal data after your death (Article 85 of the French Data Protection Act) and appoint a person to carry them out; such directives can be sent to the controller’s general contact.
5. Cookies and similar technologies
Strictly necessary cookies or equivalent storage for site operation and sessions (authentication, language preference, checkout) may be used under applicable exemption rules. Any non-essential cookies (analytics, ads) will require a consent banner when you enable those tools.
6. Processors and international transfers
Processors host or process data on the publisher’s behalf by category: web hosting and delivery; database; payment processing; AI or compute providers when the production pipeline calls them; transactional email tools; geocoding or place suggestions when enabled. Typical vendors include Vercel Inc. (application hosting, Europe region — Frankfurt), Neon Inc. (database, AWS Europe region — Frankfurt), Stripe (payments — https://stripe.com/privacy ), Google (OAuth and, where applicable, Places API), and AI operators used in production workflows (e.g. Google/Alphabet, Anthropic or others depending on configuration). Application hosting and the database are operated in Europe (Frankfurt). Because some providers are established outside the European Economic Area, transfers or access from those countries may occur; they are then governed by GDPR safeguards (notably the EU–US Data Privacy Framework and/or Standard Contractual Clauses / SCCs). A more detailed processor list may be provided on request or on this page.
7. Security
The publisher applies reasonable technical and organisational measures: HTTPS encryption, access control for admin accounts, time-based one-time password (TOTP) two-factor authentication for admin accounts covered by the site configuration, anti-bot verification (Cloudflare Turnstile) on sensitive authentication and public form flows when strict configuration is enabled; request rate limiting, including via a distributed cache (hosted Redis, e.g. Upstash) when configured; server-side event logging. No system is perfectly secure; where required by the GDPR, personal data breaches may be notified.
8. SpikkChat
When you use SpikkChat (the conversational service included with the Integral subscription), we also process messages exchanged, conversation metadata, discussion-credit balances and movements, and any consent you give to conversational memory (keeping context across sessions). Those messages may be sent to artificial-intelligence providers to generate replies. Memory is enabled only after explicit consent in the interface.
