Document version V1.10 | effective from 21.07.2026
This Privacy Policy applies exclusively to the Astro Berries Service. The rules for processing personal data in connection with the yoga services provided at coloursofsamadhi.pl are set out in a separate Privacy Policy available on that website.
Contact with the Controller on matters concerning the protection of personal data is possible at the e-mail address: help@coloursofsamadhi.com or in writing to the Controller's registered office.
| Data | Status | Purpose of processing | Legal basis |
|---|---|---|---|
| First name/last name of a person or name of a company/event | Required | Generating and describing the Horoscope | Performance of a contract / pre-contractual steps (Art. 6(1)(b) GDPR) |
| Date and time of birth/inception | Required | Calculating planetary positions, houses, and astrological aspects | Performance of a contract (Art. 6(1)(b) GDPR) |
| Place of birth | Required | Geocoding to coordinates, necessary for astrological calculations | Performance of a contract (Art. 6(1)(b) GDPR) |
| Place of residence (if different from place of birth) | Optional | Recalculating astrological houses relative to the current location (relocation chart) | User consent expressed by providing the data (Art. 6(1)(a) GDPR) |
| Birth data of a second person (Relationship Portrait / Synastry) | Optional | Generating a comparison of two charts | Performance of a contract / legitimate interest (Art. 6(1)(b) / (f) GDPR) — see the note on third-party data below |
| E-mail address, first name, last name | Optional | Creating a Customer Account, logging in, payment, sending confirmations | Performance of a contract / necessary pre-contractual steps (Art. 6(1)(b) GDPR) |
Data on the date, time, and place of birth of the subject of the Horoscope are not special category personal data within the meaning of Art. 9 GDPR (they do not reveal racial or ethnic origin, religious beliefs, health, sexual orientation, etc.) — they are processed on general terms.
Note on third-party data (Relationship Portrait / Synastry). If the User enters the birth data of another person in order to generate a comparison of two charts, the User declares that they are authorized to provide such data. The scope of this data is limited to the first name and the date, time, and place of birth and does not include special category data. The Controller processes it solely to generate the Relationship Portrait, including the optional relationship forecast and the Vedic compatibility analysis (Guna Milan / Ashtakoot, Mangal Dosha, comparison of Dasha periods), computed solely from the same birth data — without extending the scope of the data processed.
Note on the moon calendar. The optional moon calendar that the User may add to a Horoscope is computed solely from data already provided by the User (birth data and, if provided, place of residence for the purpose of determining the timezone). Generating it does not involve processing any new categories of personal data or transferring data to any new external entities.
Note on calendar subscription (iCal). The User may optionally enable a subscription to their moon calendar in an external calendar app (Google Calendar, Apple, Outlook). For this purpose the Controller provides an individual, tokenized URL that serves a calendar file (`.ics`) containing astrological data relating to the User's Horoscope (the day's rating and aspects to the Horoscope). This feature does not involve transferring data to any new external entities (the file is served from the Controller's infrastructure) — however, the calendar app chosen by the User (e.g. Google) will poll this address on its own. The subscription URL should be treated as personal data: anyone who knows the address can access the calendar's contents, so it should not be shared with anyone. The User may at any time generate a new address (which invalidates the previous one) or disable the subscription in the Account panel.
The Controller records the number of billing units (Tokens, presented in the interface as "berries") used in a conversation with the AI Astrologer solely for the purpose of managing the Service's cost limits and settlements. This data is not used for analytical or marketing purposes. The legal basis is performance of a contract and the Controller's legitimate interest (Art. 6(1)(b) and (f) GDPR) in managing the Service's operating costs.
In the event of a payment, data necessary for its execution is processed (first name, last name, e-mail address, amount). Payment card data is not processed by the Controller — it is transferred directly to the bank (ING Bank Śląski S.A.) via the ING Pay payment gateway (formerly imoje). The legal basis is performance of a contract (Art. 6(1)(b) GDPR) and, with respect to accounting documents, the Controller's legal obligation (Art. 6(1)(c) GDPR).
The User may voluntarily consent to receiving marketing information (newsletter). Consent is optional, does not condition the use of the Service, and may be withdrawn at any time. The Controller records the fact and time of granting consent. The legal basis is the User's consent (Art. 6(1)(a) GDPR). Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
The User's IP address and browser/operating system data are processed automatically for technical purposes, ensuring the security of the Service, and preventing abuse. System logs do not include the content of the User's conversations with the AI Astrologer. The legal basis is the Controller's legitimate interest (Art. 6(1)(f) GDPR).
The Controller applies technical and organizational measures to protect Users' personal data, in particular: encryption of AI Astrologer conversation content stored in the database, storage of passwords solely as cryptographic hashes (bcrypt), optional two-factor authentication (2FA), access control restricting access to Horoscopes and conversations to the User who owns them (including logging of unauthorized access attempts in technical logs), transmission of data over an encrypted connection (HTTPS) together with appropriate security headers, and protection against cross-site request forgery (CSRF). Passwordless login (Magic Link) serves solely to log in to an existing Account and does not create a new Account.
Providing personal data in the Service is always voluntary. However, providing data marked as "Required" in the table above is necessary to generate the Horoscope — without it, the service cannot be performed. Providing data marked as "Optional" is voluntary also in the sense that it does not affect the ability to use the basic functionality of the Service.
The Controller uses the following third parties to provide the Service. Each of them processes data only to the extent necessary to perform its function.
| Entity | Role | Data transferred | Location / transfer mechanism |
|---|---|---|---|
| Railway Corporation | Hosting of the application and the Service's database | All data entered by the User to generate a Horoscope, Customer Account data, encrypted conversation content | Company based in the USA. Railway acts as a data processor under a data processing agreement (DPA) concluded with the Controller, based on the Standard Contractual Clauses (SCC) approved by the European Commission. Railway holds a SOC 2 Type II certificate. The full list of Railway's subprocessors is available at trust.railway.com. |
| Anthropic | Generating AI Astrologer responses (Richard persona) | Chat message content and Horoscope data (planetary positions, aspects, transits) within a given conversation | Company (Anthropic PBC) based in the USA. Use of the Anthropic API under the Commercial Terms of Service automatically includes a data processing agreement (DPA) with the Standard Contractual Clauses (SCC). Anthropic is certified under the EU-US Data Privacy Framework (DPF). |
| Generating AI Astrologer responses (Elizabeth persona) | Chat message content and Horoscope data (planetary positions, aspects, transits) within a given conversation | Google (Google LLC, USA / Google Ireland Limited) using the Gemini API interface. Processing takes place under a data processing agreement (DPA) including the Standard Contractual Clauses (SCC) and, with respect to transfers to the USA, certification under the EU-US Data Privacy Framework (DPF). | |
| Nominatim / OpenStreetMap | Geocoding the place of birth/residence | The name of the locality entered by the User and the User's IP address | A service operating on open data terms. The geocoding query is made directly from the User's browser to the OpenStreetMap servers, which means that in addition to the entered locality name, the User's IP address is also disclosed to them. Only the name of the locality necessary to determine geographic coordinates is transferred. |
| ING Bank Śląski S.A. / ING Pay (formerly imoje) | Payment processing | First name, last name, e-mail address, payment amount. Payment card data is transferred directly to the bank, outside the Controller's systems. | Entity based in Poland, with its own privacy policy available on the provider's website. |
| Resend | Sending Magic Link, verification, confirmations, password reset, and — with the User's voluntary consent, with an opt-out link in every message — key-transit notifications and a weekly lunar-rhythm summary (a `.ics` calendar file containing the User's astrological data may be attached to consent-based messages) | The User's e-mail address | Company (Plus Five Five, Inc.) based in the USA. Resend acts as a data processor under a data processing agreement (DPA) concluded with the Controller, based on the Standard Contractual Clauses (SCC). Resend is certified under the EU-US Data Privacy Framework (DPF) and its UK extension. The full list of Resend's subprocessors is available on the provider's website. |
The Service uses the Swiss Ephemeris library (Astrodienst AG, Switzerland) for astronomical calculations, operating locally within the Controller's infrastructure. Use of this library does not involve the transfer of any of the User's personal data to Astrodienst AG — the data provided by the User does not leave the Controller's infrastructure for this purpose. This information is provided solely for transparency regarding the technical components used by the Service; details concerning the license of this software (AGPL v3) are described in the Terms and Conditions of the Service.
The function of downloading a conversation with the AI Astrologer as a PDF file is carried out locally within the Controller's infrastructure and does not involve the transfer of the User's data to third parties in order to generate such a file.
As a data subject, you have the right to:
Submitting requests electronically. Requests concerning the processing of personal data — including requests for information about the data processed, access to it, its rectification, erasure, restriction of processing, portability, and objection — may be submitted electronically, by e-mail to the personal data Controller's address: pomoc@coloursofsamadhi.com. The Controller responds to the request without undue delay, within the time limits arising from the GDPR.
To the extent that data is processed on the basis of consent (e.g. place of residence data for a relocation chart, newsletter consent), you may withdraw it at any time by contacting the Controller or — in the case of the newsletter — using the opt-out option. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
The Controller does not make decisions towards Users producing legal effects based solely on automated processing, including profiling. Content generated by the AI Astrologer is of an informational and entertainment character and is not used to make any decisions affecting the User's legal situation.
The Service is intended for persons who are at least 18 years old. The Controller does not knowingly collect personal data of minors. If the Controller obtains credible information that the personal data of a minor has been provided to the Service, it will take steps to delete it.
This Policy is continuously reviewed and updated as needed, in particular in connection with changes to the third parties indicated in the table above. The current version of the Policy (V1.10) is effective from the date indicated at the beginning (21.07.2026).
Note on language versions: This Privacy Policy has also been prepared in an English version. In the event of any discrepancies between the Polish and English versions, the Polish version prevails.