Privacy Policy
1. Controller
G.M.L. Global Mind Ltd
6 Dimokratias, 4528 Pentakomo, Limassol, Cyprus
Email: [email protected]
Represented by: Marcus Meurer & Felicia Meurer (Directors)
For any privacy question, reach us at [email protected].
2. Data we collect
- First name
- Date, time and place of birth
- Email address (only if you save your reading by email or make a purchase)
- IP address (automatically on page load)
- Payment data (processed directly by Stripe — never stored by us)
3. Purposes
- Creating your personal Birth Codex reading (birth data, name)
- Delivering the reading by email (email address)
- Processing payments (email, payment data via Stripe)
- Abuse prevention and rate limiting (IP address)
- Analysing and improving the service (anonymised usage data)
4. Legal bases
- Art. 6(1)(b) GDPR — performance of a contract (creating the reading, payment)
- Art. 6(1)(a) GDPR — consent (email communication)
- Art. 6(1)(f) GDPR — legitimate interest (abuse prevention, analytics)
5. Hosting — Vercel
Our website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA; function execution and data processing take place in the EU (Frankfurt, region fra1). Vercel automatically processes technical data (IP address, browser type, access time). As Vercel Inc. is a US company, the processing additionally relies on the EU Standard Contractual Clauses. Vercel Privacy Policy
6. Text processing by a data processor
To prepare the wording of your reading we transmit your first name, your birth data (date, time and place of birth) and the values computed from them to our data processor Anthropic PBC, 548 Market St, San Francisco, CA 94104, USA. This data is not used for their own training purposes. Transfers are based on the EU Standard Contractual Clauses. Anthropic Privacy Policy
7. Payments — Stripe
Payments are handled by Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland. Your payment data is processed directly by Stripe; we never receive card or bank details — only a confirmation of payment. Stripe Privacy Policy
Purchase record (proof of your order): For every completed purchase we also create an evidence record. It contains the Stripe identifiers for your transaction (session, payment-intent and customer ID), your email address, the name given at payment, the birth data you entered for the reading you ordered (first name, date of birth, time of birth and place of birth together with the coordinates derived from it, plus gender and email address where you provided them), the amount paid and its currency, any coupon code redeemed, the tier purchased, the country from your billing address, your IP address (to defend against unjustified chargebacks), pseudonymous analytics identifiers, the ID of the reading delivered, your confirmation of the withdrawal waiver, and timestamps and status for the purchase, the reading generation and the confirmation email (dispatch, delivery, open, click). If a chargeback is raised we add its case number, the stated reason and the deadlines; if reading generation fails we keep the technical error message. Card numbers and bank details are not part of this record.
Why we keep it — and for how long: If someone disputes a payment with their bank (a chargeback), the card network gives us only a few days to prove that the service was ordered and actually delivered. Without this record we could not show that — not even when we did deliver correctly. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in defending against unjustified chargebacks). The record is stored at Upstash (EU, Frankfurt) and deleted automatically after 5 years; that period reflects how long card networks can reopen a transaction after the original purchase. The period is sliding: every update to the record (e.g. a confirmed delivery or a later chargeback event) resets it back to the full 5 years. You can object to this processing or request deletion at any time — an email to [email protected] is enough.
8. Email — Brevo
For transactional email (the confirmation email with the link to your reading) we use Brevo (Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany). Your email address is stored at Brevo and used for delivery and as a buyer record. Legal basis: Art. 6(1)(b) GDPR (contract). Brevo Privacy Policy
Daily horoscope & retrograde alert (newsletter): In addition to the transactional email, we run two separate, optional email subscriptions whose sending can be active or temporarily paused — any existing sign-up stays unaffected either way: a daily horoscope (a short interpretation based on the current planetary transits to your birth chart) and a retrograde alert (a notice whenever Mercury, Venus or Mars turns retrograde). Both are functionally a newsletter: you receive recurring emails until you unsubscribe. The sole legal basis is Art. 6(1)(a) GDPR (consent) via double opt-in — after signing up you receive a confirmation email with a link; only clicking it completes the sign-up. If you don't confirm, the sign-up automatically lapses after 7 days (daily horoscope) or 24 hours (retrograde alert), and no subscription is created.
What we store for this: For the daily horoscope we store your email address, first name and your complete birth data (date, time and place of birth), because we use it to recalculate your current transits every day — plus the time of sign-up and confirmation, the time of the last email sent, and an individual unsubscribe token. For the retrograde alert we deliberately store no birth data, only your email address, first name, the time of sign-up and confirmation, and an individual unsubscribe token. In both cases we additionally record which page you signed up from.
How long: We store a confirmed subscription without an automatic deletion period — it remains in place until you unsubscribe; we then delete the entry immediately and permanently. Storage is at Upstash (EU, Frankfurt), delivery via Brevo (see above).
Unsubscribing: Every daily-horoscope and retrograde email contains an unsubscribe link that revokes your consent instantly; alternatively, an email to [email protected] is enough. In the member area you can also pause the daily horoscope temporarily without fully unsubscribing.
9. Reach & performance — Vercel Analytics
Via our host Vercel we use Vercel Analytics and Speed Insights to measure page views, devices, countries of origin and performance metrics (load times, Web Vitals) anonymously. No cookies are set and no user IDs are created; the data cannot be traced back to individuals. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving the service). Vercel Analytics Privacy
10. Web analytics — Google Analytics
We use Google Analytics, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. It uses cookies to analyse how the website is used; the generated information is usually transferred to a Google server in the USA (based on the EU Standard Contractual Clauses). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in reach analysis). You can prevent collection via the Google Analytics opt-out add-on or by blocking cookies in your browser.
11. Internal reading statistics — Upstash Redis & internal operational notifications
When you create a reading we store a compact record for evaluation and product improvement: your first name, date and place of birth (as entered), the approximate region (country from the IP address), your IP address (kept internally for security and fraud prevention), the traffic source (referrer host of your first visit), the entry page, the submit page, time on site before submitting, and a timestamp. When you open the finished reading we additionally measure pseudonymously how far you scrolled, which sections were in view and how long you stayed (no name, no date of birth). On a purchase we additionally record the amount paid and the Stripe session ID; your IP address is kept internally for security and fraud prevention, and no email address is part of this statistics record. No automatic deletion period is set for this statistics record — it is kept until you expressly ask us to delete it.
Reading content storage: the finished reading (birth data, computed results and interpretation texts) is stored in Upstash Redis — free teaser readings for 1 year, paid full readings for up to 5 years. Both periods slide: every time you reopen your reading, the period resets to its full length, so a reading you keep revisiting via its permanent link effectively stays available indefinitely. Without a further visit, the entry is automatically deleted once the applicable period runs out. Upstash (Upstash Inc., USA) stores this on servers in the EU (AWS, eu-central-1 region, Frankfurt); as Upstash Inc. is a US company, the processing additionally relies on the EU Standard Contractual Clauses (Art. 46 GDPR) and data is transmitted over TLS. You can request earlier deletion at any time (see below). Legal basis: Art. 6(1)(f) GDPR (legitimate interest); a copy of the balancing test is available on request.
Purchase entitlement (pseudonymous birth hash): So we can recognise that you are re-opening a reading you already bought — and avoid offering you the same product a second time (protection against an accidental double payment) — we derive a pseudonymous key from your birth data (first name, date, time and place of birth). It is produced by a non-reversible one-way cryptographic process (SHA-256), contains no readable birth data itself and cannot be traced back to your inputs. Under this key we store only which tier or which individual interpretations you have already purchased, plus the time of purchase — not the content of your reading. Like the rest of the purchase record, it is kept at Upstash (EU, Frankfurt) for up to 5 years and then deleted; a further purchase or upgrade resets this period back to the full 5 years. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in correct order handling and preventing duplicate purchases); you can object to this processing or request deletion at any time.
Access log for chargebacks: Every time you open your reading — e.g. via the link in the confirmation email — we additionally log a hashed fingerprint of your IP address (SHA-256, non-reversible), your country and your browser's User-Agent together with a timestamp, for up to the last 50 accesses per reading. If someone disputes a payment with their bank, this lets us show that and when the reading was actually opened. Neither your name nor your full IP address is stored. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in defending against unjustified chargebacks); kept for up to 5 years at Upstash (EU, Frankfurt), like the rest of the purchase record, then automatically deleted — this period also slides and is reset to the full 5 years on every further open (including internal clicks).
In addition, the responsible party receives a technical operational notification with the same data via a service provider outside the EU. That country has no EU adequacy decision; this transfer is based on Art. 49(1)(f) GDPR (important business interest). Pseudonymisation is applied (no full name, no email in the channel). The channel is strictly internal and never visible to other visitors. Upstash Privacy
12. Cookies
We use technically necessary cookies for the website to function and analytics cookies (Google Analytics), set on the basis of Art. 6(1)(f) GDPR. You can block or delete cookies in your browser settings.
13. Your rights
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Withdrawal of consent — at any time with future effect
To exercise your rights, an email to [email protected] is enough; deletion then covers both the Redis record and the history of that notification.
14. Right to lodge a complaint
You have the right to complain to a data protection supervisory authority. The competent authority in Cyprus is:
Office of the Commissioner for Personal Data Protection
1 Iasonos Street, 1082 Nicosia, Cyprus
www.dataprotection.gov.cy
15. Minors
Birth Codex is intended exclusively for adults. By using it you confirm you are at least 18. We do not knowingly process data of children under 16. Where processing exceptionally relies on consent (Art. 6(1)(a) GDPR), it requires parental consent for minors under 16 (Art. 8 GDPR). If we learn that such data reached us without that consent, we delete it without delay.
16. Updates
As of September 2026. We may adapt this policy to reflect changes in the law or the service.
17. Use of Artificial Intelligence
For the language processing of your reading's interpretive texts, we use an AI language model operated by our processor, Anthropic PBC. The AI creates the interpretive texts based on your birth data, the values computed from them and templates we curated; the underlying astronomical and numerological calculations themselves are computed deterministically, without AI.
This processing does not constitute an automated individual decision within the meaning of Art. 22 GDPR: your reading has no legal effect on you and does not similarly significantly affect you.
The content serves personal inspiration and entertainment and does not replace professional advice.
18. Cloudflare — DNS/CDN & bot protection
Our website runs technically behind Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA — as a DNS and CDN layer in front of our hosting provider Vercel (section 5). Cloudflare automatically processes technical data (IP address, requested URL, browser type) on every page load to deliver and protect the website.
We additionally use Cloudflare Turnstile as bot protection on several forms (the birth data form for your reading, the contact form) — your IP address and a verification token are transmitted to Cloudflare to detect automated abuse attempts.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the technical operation of the website and in abuse prevention). As Cloudflare, Inc. is a US company, the processing additionally relies on the EU Standard Contractual Clauses. Cloudflare Privacy Policy