Effective date and last updated: 2 October 2026
This Policy explains how ZODIARA ENGINE processes personal data of website visitors, people using the test report access form, and business contacts. It also explains the different roles of ZODIARA ENGINE and a Partner in a future white-label deployment.
1 Controller and contact details
For the ZODIARA ENGINE website, test report form, and business enquiries, the controller is ZODIARA ENGINE Paulina Malkiewicz, ul. ks. Jerzego Popiełuszki 28/44, 10-693 Olsztyn, Poland, Polish tax ID NIP 7393778561, REGON 365171931.
Privacy contact: contact@zodiaraengine.com. Service and security support: support@zodiaraengine.com.
We have not appointed a data protection officer because our present activities do not require one.
2 Scope and roles
When a person uses the ZODIARA ENGINE website form to receive a test report, ZODIARA ENGINE is the controller of the data required to provide that access.
When an independent Partner offers or sells a report through its own website or sales process, the Partner normally determines the purpose and lawful basis for processing its customer's data and acts as controller. ZODIARA ENGINE processes that data on the Partner's behalf as its processor under the applicable agreement and instructions. The Partner must also provide its own customer-facing privacy information.
ZODIARA ENGINE remains a separate controller for limited data used for its own legal obligations, security, accounting, correspondence, and the establishment, exercise, or defence of legal claims.
3 Personal data we process
The test report form may collect an access code, the name used in the report, the selected language or grammatical form, report language, date of birth, exact time of birth, city and country of birth, the report period start date, and the email address used to deliver the report.
We also process records of required acknowledgements and optional consent, report and Partner or access-source identifiers, product type and language, generation, archive and delivery status, timestamps, error information, and limited technical data such as IP address, browser type, request headers, and security logs.
For a paid Partner flow, we may receive technical order information such as order ID, payment status, amount in the smallest currency unit, and currency code. We do not need or receive complete payment card numbers, CVV codes, or online banking credentials.
We may also process business contact details and correspondence where a person asks about a partnership. The report form does not request medical records, identity document numbers, bank credentials, or unrelated information.
4 Purposes and lawful bases
We process report form data to accept the request, perform calculations, generate, validate, deliver, and temporarily secure the report. The lawful basis is Article 6(1)(b) GDPR: taking steps at the user's request and performing the electronic service.
We process technical and operational records to secure the service, prevent abuse or repeated code use, diagnose errors, confirm delivery, and protect legal claims. The lawful basis is our legitimate interests under Article 6(1)(f) GDPR.
We process information required for accounting, legal compliance, or valid public authority requests under Article 6(1)(c) GDPR.
Where a person voluntarily consents to a later partnership follow-up, we process the relevant contact data under Article 6(1)(a) GDPR and applicable electronic communications law. Consent may be withdrawn at any time without affecting prior lawful processing.
We do not use report form data for behavioural advertising and we do not sell personal data.
5 AI and automated processing
The report is created through an automated workflow. An astrology calculation engine performs the structured calculations, and the OpenAI API assists with the narrative portion based on limited structured context.
The standard configuration blocks direct identifiers from the AI payload, including the person's name, email address, Partner ID, complete birth date and time, birth city, coordinates, and report ID. The model receives only information needed to draft narrative from calculations already performed.
The report is not a decision producing legal or similarly significant effects. We do not use this workflow for solely automated decision-making within Article 22 GDPR.
6 Recipients and service providers
We disclose data only as necessary to providers supporting the website and report service. These may include the website and DNS host; Render for the API, queue, and generation process; Cloudflare for the private R2 archive and D1 registry; OpenAI for limited narrative generation; Postmark for report delivery by email; and GeoNames for resolving coordinates or time zone from a place name.
A payment provider selected by a Partner operates within the Partner's checkout and does not receive card data from ZODIARA ENGINE. A Partner may receive agreed status information about report fulfilment and delivery but does not receive administrative access to ZODIARA ENGINE infrastructure.
Authorised technical, security, accounting, or legal advisers may receive limited access where required for their work. We may also disclose data to a public authority where legally required.
7 Transfers outside the EEA
The main API and report-generation infrastructure operates in Frankfurt, Germany, and the report archive uses a European Union jurisdiction restriction. This does not mean that every account administration, email, AI, or metadata function of all providers remains exclusively in the EEA.
Where a provider processes data outside the European Economic Area, we rely on a legally permitted mechanism, such as an adequacy decision, the EU-US Data Privacy Framework where applicable, or European Commission Standard Contractual Clauses with required supplementary measures. Details of the applicable mechanism may be requested at contact@zodiaraengine.com.
8 Retention
A successfully generated and delivered report and related quality files may be kept in the private archive for up to 90 days after confirmed delivery and are then subject to the configured deletion lifecycle.
Failed, incomplete, or retryable runs are ordinarily kept for no more than 30 days, unless limited longer retention is needed for a safe retry, complaint, incident, legal obligation, or legal claim.
Server working files are removed after archive confirmation, required delivery, and registry completion. The minimal operational registry is ordinarily actively available for up to 90 days. Aggregated or limited settlement records may be kept longer where required for accounting, tax, audit, or legal claims.
Postmark may retain message content and activity data for up to 45 days by default, depending on the active configuration. Enquiry data is kept until the matter is completed and then for as long as reasonably needed to evidence the correspondence and protect legal claims. Consent-based contact data is kept until consent is withdrawn or the purpose ends, subject to limited retention of evidence required for legal claims.
9 Whether data is required
Providing required form data is voluntary, but the report cannot be generated and delivered without it. Missing or inaccurate birth time or place may prevent certain calculations or reduce their precision. Partnership follow-up consent is optional and does not affect access to the test report.
10 Individual rights
Subject to the GDPR, a person may request access and a copy, rectification, erasure, restriction, data portability, object to processing based on legitimate interests, and withdraw consent.
Requests may be sent to contact@zodiaraengine.com. We may ask for information reasonably needed to verify identity and locate the relevant record safely. Where a Partner is the controller, the request should normally be directed to that Partner; we will assist it for systems under our control.
A person may also complain to the President of the Polish Personal Data Protection Office, ul. Stanislawa Moniuszki 1A, 00-014 Warsaw, Poland, uodo.gov.pl, or another competent supervisory authority.
11 Security
We use measures appropriate to the risk, including encrypted connections, access restrictions, a private archive without a public URL, separation of secrets from code, request validation, status records, and controlled deletion. No system can guarantee complete security or uninterrupted availability.
12 Minors and other people's data
The test report form is intended only for people aged 18 or over who provide their own birth data. Do not submit a child's data or another person's data. If we receive credible notice of unauthorised submission, we will take appropriate steps to restrict or erase it.
13 Changes to this Policy
This Policy describes the current website and service model. We will update it before introducing a new processing purpose, analytics or marketing tool, or materially different data flow. The current version will remain available at this address with its revision date.