Privacy Policy
Last updated: September 9, 2026
This privacy policy describes how we collect, use, and protect your personal data when you use our personalized Birth Chart generation service ("Service").
Personal data processing complies with EU Regulation 2016/679 (GDPR) and applicable Italian law (Legislative Decree 196/2003, as amended by Legislative Decree 101/2018).
1. Data Controller
The Data Controller for personal data processing is:Ivan Santonastase
Address: Via Arese 39/2, 20020 Robecchetto con Induno (MI), Italy
VAT Number: 01673550081
Email: [email protected]
2. Personal Data Collected
We collect the following personal data:Identifying data: first name, last name, email address.
Birth data: date of birth, time of birth (optional), place of birth.
Payment data: handled directly by Stripe, Inc. We do not have access to your full credit card details. From Stripe we receive the transaction references and the country given in your billing details or, failing that, the country where your payment card was issued.
Browsing data: IP address, browser type, pages visited (session technical cookies only).
Birth data (date, time, place) may indirectly reveal sensitive information. We process it with the utmost care.
3. Legal Basis and Purposes of Processing
We process your data for the following purposes:Contract performance (Art. 6.1.b GDPR): to generate and deliver the purchased personalized Birth Chart.
Legal obligations (Art. 6.1.c GDPR): tax and accounting obligations related to the transaction.
Legitimate interest (Art. 6.1.f GDPR): fraud prevention, system security.
The legal basis for processing birth data (special category under Art. 9 GDPR) is your explicit consent, given by filling out the form and submitting the order.
4. Data Retention Period
We retain your personal data for the time strictly necessary for the described purposes:Your birth data (date, time, place and coordinates), the generated Birth Chart text and your contact data (first name, last name, email address) are erased automatically 90 days after the order: the order record itself remains, but those fields are blanked and cannot be recovered. The exception is an order still awaiting a refund or manual intervention, which is left untouched until the case is closed: blanking the email address of a customer who is waiting for a refund would leave us no way to reach them.
The Birth Chart PDF is deleted from our systems at that same moment, at the 90-day erasure and not on delivery: until then it remains available from the download link you received after your purchase. We recommend that you keep a copy of it.
Couple affinity results are deleted in full, record included, after 90 days: counted from the date they were created if they were never paid for, and from the date of payment if they were.
For tax obligations we keep, for the 10 years required by Italian law, a pseudonymous purchase ledger. It holds the product purchased, the payment date, the amount, the currency, the customer country reported by Stripe, the Stripe transaction references, the language of the purchase and the versions of the legal documents that were accepted. In place of your email address it holds only a code derived from it with a one-way cryptographic function (a salted hash): your email address, your name and your birth data do not appear in the ledger. It is the only record we keep for the ten-year tax obligation.
You can request early deletion of your data at any time (see Section 5).
5. Your Rights
To exercise your rights, write to: [email protected]We will respond within 30 days.
If you ask us to erase your data, we bring forward the erasure described in Section 4: birth data, generated text, PDF and contact data are removed without waiting for the 90 days. We do keep the row in the pseudonymous purchase ledger, which the ten-year tax obligation requires us to retain (Art. 17(3)(b) GDPR); since it holds neither your email address, nor your name, nor your birth data, that row does not identify you.
6. Data Recipients
Your personal data is processed by our authorized personnel and may be disclosed to the following data processors appointed under Art. 28 GDPR:Stripe, Inc. — payment processing.
Sendinblue (Brevo) — transactional email delivery.
Google LLC (Gemini API) — AI-based Birth Chart content generation.
OpenStreetMap / Nominatim — birth location geocoding.
Meta Platforms Ireland Ltd. — conversion measurement and advertising (Meta Pixel and Conversions API), subject to your marketing-cookie consent.
We do not sell your data. We share data with Meta for measurement and advertising purposes only with your consent to marketing cookies, which you can withdraw at any time from the cookie preferences.
7. International Data Transfers
Some of our providers (Stripe, Google, Brevo, Meta) are based in the United States. Data transfers to non-EU countries are based on:Standard Contractual Clauses (SCC) approved by the European Commission.
Certification under the EU-US Data Privacy Framework (DPF), where applicable.
You can request a copy of the adopted safeguards by writing to the Data Controller's address.
8. Cookies
This site uses strictly necessary, analytics and marketing cookies. Strictly necessary cookies are required for site operation and do not need consent. Analytics and marketing cookies are activated only after your explicit consent.Strictly necessary cookies: ASP.NET session, antiforgery (CSRF), language preference, cookie preferences storage.
Analytics cookies: Google Analytics via Google Tag Manager, to measure traffic and improve the site (operating in Consent Mode v2).
Marketing cookies: used to display personalised advertising.
You can change your choices at any time by clicking .
Below is the detailed list of cookies in use.
9. Complaints
If you believe that the processing of your data violates the GDPR, you have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or the supervisory authority of your country of residence.We encourage you to contact us first so we can try to resolve any issues.
10. Changes to This Privacy Policy
This privacy policy may be updated periodically to reflect regulatory changes or Service developments. The date of the last update is indicated at the top of this document.In the event of substantial changes, we will notify you by email (if available) or via a notice on the site before the changes become effective.
Cookie Declaration
Up-to-date list of cookies set by this site. Optional categories are activated only after consent.
Strictly necessary cookies
| Name | Domain | Expiry | Purpose |
|---|---|---|---|
| .AspNetCore.Session | This site | Session | User session management. |
| .AspNetCore.Antiforgery.* | This site | Session | Protects forms against CSRF attacks. |
| .AspNetCore.Culture | This site | 1 year | Stores selected language. |
| cc_cookie | This site | 6 months | Stores user cookie preferences. |
Analytics cookies (consent required)
| Name | Domain | Expiry | Purpose |
|---|---|---|---|
| _ga | .google-analytics.com | 2 years | Distinguishes unique users (Google Analytics). |
| _ga_* | .google-analytics.com | 2 years | Persists session state (Google Analytics 4). |
| _gid | .google-analytics.com | 24 hours | Identifies users for the duration of a session. |
Marketing cookies (consent required)
| Name | Domain | Expiry | Purpose |
|---|---|---|---|
| _gcl_au | This site | 3 months | Google Ads conversion tracking. |
| IDE | .doubleclick.net | 13 months | Remarketing and ad campaign measurement. |
| _fbp | This site | 90 days | Browser identifier for Meta conversion measurement. |
| _fbc | This site | 90 days | Meta ad-click attribution (fbclid parameter). |