Privacy Policy
This Privacy Policy (the “Policy”) explains how the Operator, a sole proprietor operating as the Ukrainian sole proprietorship Vidlunnia (“Vidlunnia”, “we”, “us” or “our”), collects and processes your personal data when you access and use the Vidlunnia application and website (the “Service”). Vidlunnia is a self-reflection tool that helps you identify a concern and an action that is within your control. It is a reflection tool only: it is not a predictive, diagnostic, clinical or therapeutic service, it makes no medical claims, and it makes no prediction about your future, your health, your finances or your relationships.
Because the Service processes information that may reveal your philosophical beliefs, your wellness practices or your mental health, and because it includes a safety protocol that responds to signals of acute distress, some of the data we process is special-category (sensitive) personal data and receives heightened protection. This Policy sets out what we collect, why, on what legal basis, with whom we share it, how long we keep it, and how you can exercise your rights.
This Policy forms part of our Terms of Service. Where it conflicts with a mandatory provision of applicable data-protection law, that law prevails.
1. Who we are (data controller)
The controller responsible for the processing described in this Policy is the Operator, a sole proprietor acting under the laws of Ukraine, trading as Vidlunnia, with no establishment in the European Union. Privacy contact: privacy@vidlunnia.com. The Operator is the controller within the meaning of Article 4(7) GDPR and the controller (owner of the personal-data file) within the meaning of the Law of Ukraine “On Protection of Personal Data” No. 2297-VI of 1 June 2010 (the “Ukrainian Data Protection Law”). You may contact us at any time, using the details in Section 21, to exercise your rights or to raise any question about the processing of your personal data.
2. Scope and the laws that apply
This Policy applies to personal data that we process through the Service. It does not cover processing carried out by independent third parties - for example, your email provider, your device manufacturer, or any third-party service you separately choose to use - whose practices are governed by their own privacy notices.
2.1 Ukrainian law
As a Ukrainian sole proprietor, we are subject to the Ukrainian Data Protection Law, under the supervision of the Ukrainian Parliament Commissioner for Human Rights as the competent data-protection supervisory authority in Ukraine. Because the Service involves processing of data concerning a data subject’s health and beliefs - which constitutes processing that poses a particular risk to rights and freedoms under the Ukrainian Data Protection Law - we notify the Commissioner of such processing within 30 working days of its commencement and comply with the additional safeguarding obligations that the law attaches to it.
2.2 GDPR
The Service is offered to, and used by, individuals in the European Union and the European Economic Area (the “EU/EEA”). To the extent that our processing of the personal data of data subjects who are in the EU/EEA relates to the offering of the Service to them, that processing falls within the territorial scope of Article 3(2) GDPR, and the GDPR applies. References to the GDPR in this Policy are made for the benefit of EU/EEA data subjects.
2.3 Other laws
Equivalent rights and obligations may arise under other data-protection laws applicable to a particular data subject (including, without limitation, the UK GDPR and the Swiss Federal Act on Data Protection). We give effect to such laws to the extent that they are mandatorily applicable to the processing concerned.
3. Data protection officer
We have assessed whether we are required to appoint a data protection officer under Article 37 GDPR. Although the processing of special categories of personal data is central to the Service, we have concluded that, at the Service’s current scale, it does not yet amount to large-scale processing as a core activity within the meaning of Article 37(1)(c), and that the appointment of a data protection officer is therefore not mandatory at this time. We keep this assessment under review and will appoint a data protection officer should the scale of our processing make it mandatory. In the meantime, all data-protection enquiries should be sent to privacy@vidlunnia.com.
4. The personal data we process
We collect only the data we need to operate the Service. We do not collect government-issued identifiers, payment-card numbers (these are handled by our payment provider - see Section 10), postal addresses, telephone numbers, photographs or biometric data.
4.1 Account data
Your email address, which you provide so that we can deliver passwordless (“magic-link”) sign-in and essential service messages.
4.2 Birth data
Your date of birth (required to calculate your Life Path number); your first name and, optionally, your family name (used to calculate the Expression, Soul Urge, Personality and Birth Day numbers); and, optionally, your birth time and birth location (city, and the corresponding latitude and longitude), used only to add further numerological context. Birth time and birth location are optional, and the Service is fully usable without them.
4.3 Reflection and quiz data (special category)
Your answers to the multiple-choice and trait-selection questions (questions 1–16); your free-text reflection answer (question 17); the numerology numbers inferred from your inputs (Life Path, Expression, Soul Urge, Personality and Birth Day); and the personalised narrative generated from the above. This data, particularly in combination with your free-text answer, may reveal your philosophical beliefs or wellness practices, and is therefore treated as a special category of personal data under Article 9 GDPR (see Section 7).
4.4 Intention and follow-up data
Where you choose to record an intention as part of the reflection loop, we store your words verbatim, exactly as you write them, in encrypted form, and we do not reword them. Approximately seven days later, on your next visit, the Service may display your recorded words to you for your own review. We do not contact you, by push notification or email, to bring you back to the Service; any reminder rhythm is switched off by default and is yours to set and to stop. You may delete your recorded intentions at any time (see Sections 13 and 14).
4.5 Safety-signal (crisis) data (special category - health)
Where your free-text reflection answer contains a signal of acute distress or risk of harm, our safety protocol generates a safety-signal record. Such a record concerns your mental health and is therefore a special category of personal data under Article 9 GDPR. Section 7 explains in full what we do, what we store, on what basis and for how long.
4.6 Technical and security data
Minimal technical logs comprising your IP address and browser user-agent, processed to authenticate you, protect the integrity of your account and prevent fraud and abuse; session cookies (see Section 17).
4.7 Information you send us
If you contact us (for example, by email at privacy@vidlunnia.com), we process the information you include in your message, including your contact details and the content of your enquiry, in order to respond.
Providing your birth data and quiz answers is voluntary: you are under no obligation to provide them, but without them we cannot generate your reading. Providing your email address is necessary to create an account and to sign in.
4.8 Payment and billing data
Applies from the launch of paid subscriptions. We process: the transaction outcome (success or decline and its reason), card type and last digits, the **country of the payment instrument** (needed to determine the applicable VAT rate), amount, currency, date, transaction identifier, and a technical identifier used to charge the next period. **We do not receive your card number, expiry date or CVV** — those go directly to the payment service provider (section 9). This data is never combined with the content of your reflections: payment and tax records hold only the service name.
4.9 Tarot-based reflection data (special category)
A tarot spread in the Service is a structured self-reflection tool, not a prediction of the future: the symbolism of the cards only frames a question you put to yourself. When you draw a spread we process: **the question or situation you type** (it can reveal your emotional state and life circumstances, so we treat it as special-category data), **the generated reflection text**, the cards drawn, **which spread you chose**, and the time. The question and the generated text are stored **encrypted** under a key unique to your account. The name of the spread you chose is stored **unencrypted** — it is needed to show you your past sessions, and we say so plainly, because the choice of spread can say more about your state than it appears to.
5. Purposes of processing and legal bases
We process personal data for the purposes and on the legal bases set out below. Where you are in the EU/EEA, the legal bases are those of Article 6(1) GDPR and, for special categories of personal data, Article 9(2) GDPR. Equivalent grounds apply under the Ukrainian Data Protection Law and other applicable laws.
5.1 To generate your reflection content
To run the quiz, infer your numerology numbers and produce your personalised narrative, we process your birth data, your answers to questions 1–16, your free-text answer to question 17, the inferred numbers and the resulting narrative. The legal basis is your consent (Article 6(1)(a)) and, because some of this data is special category, your explicit consent (Article 9(2)(a)).
5.2 To generate your tarot spread interpretation
To produce the interpretation, your question and the cards drawn are sent to Anthropic (section 9.1) and the result is stored encrypted in our infrastructure (section 9.4). Legal bases: **Art. 6(1)(a) GDPR — consent** for the processing generally, and **Art. 9(2)(a) — explicit consent** for the special-category data. Without that consent no spread is generated; withdrawal is described in section 6 and it triggers deletion of the corresponding records.
5.3 To sign you in and send essential messages
To provide passwordless sign-in and to send you essential service messages, we process your email address. The legal basis is the performance of our contract with you (Article 6(1)(b)).
5.4 To operate the safety protocol
To detect and respond to signals of acute distress, we process your free-text answer and the resulting safety-signal record. The primary legal basis is your explicit consent (Article 9(2)(a)); in addition, where you are in a situation of acute risk, processing may be necessary to protect your or another person’s vital interests (Article 6(1)(d) and Article 9(2)(c)). Section 7 describes this processing in full.
5.5 To keep anonymised safety statistics
We retain anonymised, aggregate safety-signal records in order to review and improve the safety of the Service. Once a record is anonymised (no identifier and no verbatim text, held only in aggregated form), it is no longer personal data and falls outside the GDPR; to the extent that any residual processing remains in scope, the legal basis is our legitimate interest in the safety of the Service (Article 6(1)(f)).
5.6 To keep the Service secure
To authenticate you, protect your account and prevent fraud and abuse, we process minimal technical logs (IP address and user-agent). The legal basis is our legitimate interests (Article 6(1)(f)); we do not use this data for profiling.
5.7 To respond to your enquiries
Where you contact us, we process the information in your message in order to reply. The legal basis is the performance of a contract (Article 6(1)(b)) or our legitimate interests (Article 6(1)(f)).
5.8 To comply with the law
We process the minimum data necessary to respond to lawful requests from competent authorities and to meet tax and accounting obligations in respect of paid subscriptions. The legal basis is compliance with a legal obligation (Article 6(1)(c)).
Where we rely on consent, you give it explicitly before you begin the quiz. You may withdraw it at any time in your account settings; withdrawal does not affect the lawfulness of processing carried out before withdrawal and, in respect of reflection data, triggers a deletion request under Article 17 (see Section 12). Where we rely on legitimate interests, we have weighed those interests - operating, securing and improving the Service and protecting it and our users against fraud and abuse - against your rights and freedoms, and concluded that our processing does not override them. You may object on grounds relating to your particular situation (see Section 13).
6. Special-category data and explicit consent
The Service is built around reflection on matters that can be deeply personal. Your quiz answers, your free-text reflection and the safety-signal records described in Section 7 may reveal information about your philosophical beliefs, your wellness practices or your mental health - all of which are special categories of personal data under Article 9(1) GDPR. We process such data only on the basis of your explicit consent under Article 9(2)(a), which you give before you begin the quiz, except where, as a secondary basis in a situation of acute risk, we process safety-signal data to protect vital interests under Article 9(2)(c). We never sell this data, and we never share it with advertisers. Because this processing is, by its nature, likely to result in a high risk to the rights and freedoms of data subjects, we have carried out and maintain a data protection impact assessment under Article 35 GDPR.
7. The safety protocol and crisis-signal data
We take seriously the possibility that someone using the Service may be in distress, and we have designed a safety path rather than simply offering more reflection. This Section explains how it works.
7.1 What triggers it
When you submit your free-text reflection answer (question 17), it is assessed for signals of acute distress or risk of harm. If such a signal is detected, the Service presents a safety path - for example, directing you to appropriate support resources - instead of continuing the ordinary reflection flow.
7.2 What we record, and what we do not
When a signal is detected, we create a safety-signal record holding only signal-level information - a severity indicator, an indication of the nature of the signal and a confidence level. We do not store the verbatim text of your reflection on this record.
7.3 How long we keep it, and how it is protected
While the record is linked to your account, it is processed on the bases set out in Section 6 and is subject to your rights. If you delete your account, the link between the record and your account (your user identifier) is severed, so that the remaining information - severity, nature and confidence only, with no identifier and no verbatim text - can no longer be attributed to you. From that point it is anonymised and is no longer personal data within the meaning of Article 4(1) GDPR; we retain it only in aggregated form that does not permit any individual to be singled out, for up to seven (7) years and for the sole purpose of reviewing and improving the safety of the Service. We do not, and have no means to, re-identify these records.
7.4 What it is not
The safety protocol is a signposting and safety feature. It is not a clinical assessment, a diagnosis, an emergency service, an “AI therapist”, or a substitute for professional help. If you are in crisis, please contact your local emergency services or a recognised crisis line.
8. The AI-generated narrative
To produce your personalised narrative, your quiz answers and free-text reflection are sent to the application programming interface (API) of Anthropic PBC (United States), which operates the artificial-intelligence model that generates the text. Anthropic acts as our processor for this purpose and does not use API inputs to train its models. The transfer to the United States is made under the European Commission's standard contractual clauses (see Section 10). We do not send Anthropic your email address, your account identifier or any other identifier of your account. The narrative is a creative reflection - not a prediction, a diagnosis, a score or a decision (see Sections 11 and 16).
9. Recipients and sub-processors
We do not sell, rent or trade your personal data, and we do not share it with advertising networks for targeted advertising. We share it only with the recipients set out below, and only to the extent necessary for the stated purpose. We engage processors that provide appropriate technical and organisational safeguards and enter into data-processing agreements with them as required by Article 28 GDPR.
We may also disclose personal data where required by law or by a binding order of a competent authority, where reasonably necessary to establish, exercise or defend legal claims, or in connection with a merger, acquisition, restructuring or comparable corporate transaction - in each case subject to the protections required by applicable data-protection law.
9.1 Anthropic PBC (United States)
To generate your narrative, we send your quiz answers and free-text reflection to Anthropic, which acts as our processor and does not use API inputs to train its models. Transfer mechanism: the European Commission's standard contractual clauses (Module Two, controller to processor), incorporated into Anthropic's data processing addendum. Anthropic is not certified under the EU–US Data Privacy Framework, so we do not rely on that framework for this transfer. Anthropic does not retain the content of API requests by default, but may retain content that its automated safety systems flag, for up to two years. We have carried out a transfer impact assessment for this transfer and you may request a copy of it, and of the clauses, at privacy@vidlunnia.com.
9.2 Payment acceptance and fiscalisation
Paid subscriptions have not launched, so we do not process payment data yet. From launch, **we** — the controller named in section 1 — will be the seller, and card payments will be accepted by a **Ukrainian payment service provider (acquirer)** acting as our processor. You enter your card details directly on their side: **we never receive or store your card number or CVV**. We receive only the outcome of the transaction, the card type and last digits, the country of the payment instrument (needed to determine the applicable VAT rate), and a technical identifier used to charge the next subscription period. We will name the specific provider in this Policy **before** any payment data is processed. We deliberately do not name one in advance, so that this Policy does not carry the name of a provider we do not end up working with.
9.3 State Tax Service of Ukraine
Because the seller is a sole trader under Ukrainian law, a card payment made by an individual requires a fiscal receipt. The receipt is produced by a software cash register (ПРРО) and transmitted to the **State Tax Service of Ukraine**. It carries settlement data: date, amount, currency, service name and transaction identifier. The legal basis is compliance with a legal obligation (Art. 6(1)(c) GDPR); neither we nor you can opt out of it. **The content of your reflections, narratives or worry maps is not included in the fiscal receipt** — only the service name, for example “Vidlunnia access, monthly subscription”. Applies from the launch of paid subscriptions.
9.4 Hetzner Online GmbH (Germany / Finland, EU)
Hosting of our backend infrastructure, as our processor. No transfer of personal data outside the EEA is involved.
9.5 Resend, Inc
(United States). Delivery of magic-link and service emails, as our processor. Resend stores data in the United States and does not offer a European region, and it engages its own sub-processors, all of which are United States entities; we can provide the current list on request. Where a message we send you contains a document - for example, where you ask us to email you your worry map - that document is contained in the message and therefore passes through Resend. Transfer mechanism: the European Commission's standard contractual clauses.
9.6 PostHog, Inc
PostHog, Inc (United States; your data hosted in Frankfurt, EU). Our processor, for two things. First, product analytics on behavioural events (which screens are used, in what order, where people drop off). Second, **masked session replay**: recordings of layout, clicks and navigation, with **every input field and all on-screen text masked in the browser before anything is uploaded** — so the content you write (worries, reflections, readings) is never captured. Console logs and network bodies are off, and /auth, /verify and any URL carrying a token are excluded, so no sign-in link or reading identifier is recorded. Both are consent-gated: nothing is sent before you accept analytics cookies. If you ask us to delete your data, your recordings are deleted with it. Your data is stored on servers in Frankfurt, Germany, and our systems will refuse to send it to any non-European PostHog endpoint. PostHog, Inc is incorporated in the United States, however, so making the data available to it is treated as a transfer to the United States, made under the European Commission's standard contractual clauses (see Section 10).
9.7 Google LLC (United States)
We use Google Analytics 4 to measure app traffic, with Google Consent Mode v2 enabled. Before you consent to analytics, Google receives cookieless measurement only (no cookies, no persistent identifiers); full, cookie-based measurement begins only after you press "Accept all". We do not send Google any special-category data: safety-protocol / risk-assessment pages are not tracked, and query strings and any identifiers or tokens are stripped from page addresses. Google acts as our processor; the transfer to the United States relies on the EU–US Data Privacy Framework (Google LLC is certified), with standard contractual clauses as a supplementary safeguard.
9.8 Meta Platforms Ireland Limited (Ireland)
We use the Meta pixel to measure advertising effectiveness. It loads **only after you consent to analytics cookies**, and stops when you withdraw that consent. It receives page-view and conversion events together with technical identifiers (IP address, browser and device data, cookie identifiers). Meta processes this data for its own purposes as described in its own terms; we do not send it your reflection answers, your free-text, or any special-category data. See Section 10 for transfers and Section 17 for cookies. We also send Meta a **server-side event when you finish the quiz**, so we can measure which adverts bring people who actually complete something rather than merely open a page. It carries no content from your answers — only that a quiz was completed, plus the match keys Meta needs to connect it to an advert click: the Meta cookies its pixel set, your IP address and your browser's user-agent string, and a hashed form of your email address if you have an account. This is sent **only if you have accepted analytics cookies**; if you have not, nothing is sent.
9.9 TikTok Technology Limited (Ireland)
We use the TikTok pixel to measure advertising effectiveness. As with Meta, it loads **only after you consent to analytics cookies** and stops when you withdraw it. It receives page-view and conversion events with technical identifiers. We do not send it your reflection answers, your free-text, or any special-category data. See Section 10 for transfers and Section 17 for cookies. The same server-side quiz-completion event described in 9.7 is also sent to TikTok, on the same terms and the same consent condition.
9.10 Functional Software, Inc. (Sentry) (United States)
Error and performance monitoring for the application, as our processor, so we can detect and fix faults. It receives technical diagnostics: error messages, stack traces, the page involved, browser and device data, and an internal user identifier where you are signed in. It is configured not to capture request bodies or your reflection text, and to strip personal data and special-category patterns before anything is sent. We use Sentry's European data region, so the diagnostics are stored in Germany; because Sentry contracts through a United States company, making the data available to it is nonetheless treated as a transfer to the United States. Transfer mechanism: Sentry's certification under the EU–US Data Privacy Framework, with the European Commission's standard contractual clauses as a supplementary safeguard. This is necessary for the security and reliability of the Service and is not used for analytics or advertising.
9.11 Cloudflare, Inc. (United States)
Three functions. Cloudflare Turnstile protects sign-in and sign-up from automated abuse; it receives your IP address and interaction signals from the page carrying the challenge. Cloudflare Pages serves our public landing pages. Cloudflare also sits in front of our application as a network and security layer, which means it handles the requests your browser makes to us, including your IP address. Cloudflare acts as our processor, save that for some of the signals it uses to improve its own bot detection it acts as a controller in its own right. Transfer mechanism: Cloudflare's certification under the EU–US Data Privacy Framework, with the European Commission's standard contractual clauses as a supplementary safeguard.
9.12 Session recording — removed
Until 3 August 2026 we used a third-party session-recording tool (Microsoft Clarity) for beta diagnostics. **It has been removed.** We no longer use any session-recording or screen-replay tool, and no such recordings are created. We will not reintroduce one unless it is consent-gated, excluded from pages that can contain special-category data, and capable of deleting an individual person's recordings on request.
10. International transfers
Our own systems, and the data we store, are hosted in the European Union. Some of the recipients listed in Section 9 are located outside the European Economic Area, and sharing your data with them is an international transfer. This Section sets out, for each of them, the specific safeguard we rely on under Chapter V GDPR. Where a recipient is covered by an adequacy decision of the European Commission under Article 45 GDPR, we rely on that decision. Otherwise, we rely on appropriate safeguards under Article 46 GDPR, in particular the European Commission’s standard contractual clauses (Commission Implementing Decision (EU) 2021/914), supplemented where necessary by additional technical and organisational measures.
We do not rely on the derogations in Article 49 GDPR for any transfer, because our transfers are regular rather than occasional and Article 49 is not an appropriate basis for them.
Where we rely on an adequacy decision, we also ensure that standard contractual clauses are in place with that recipient, so that the transfer does not lose its safeguard if the adequacy decision is narrowed or set aside.
You may request a copy of the safeguards relied on for any transfer, and of our transfer impact assessments, at privacy@vidlunnia.com.
Your provision of personal data directly to us in Ukraine is collection by us as controller, not an onward transfer within the meaning of Chapter V GDPR; Chapter V applies to our onward sharing with the recipients located outside the EEA identified in Section 9. Ukraine is not the subject of an adequacy decision. We do not share your personal data with any recipient in Ukraine.
- Anthropic PBC (United States) - the European Commission’s standard contractual clauses (Module Two, controller to processor), incorporated into Anthropic’s data processing addendum. Anthropic is not certified under the EU–US Data Privacy Framework and we do not rely on that framework for this transfer.
- Resend, Inc (United States) - the European Commission’s standard contractual clauses.
- PostHog, Inc (United States, with your data hosted in Frankfurt) - the European Commission’s standard contractual clauses.
- Cloudflare, Inc (United States) - the EU–US Data Privacy Framework, under which Cloudflare is certified, with standard contractual clauses as a supplementary safeguard.
- Functional Software, Inc (Sentry) (United States, with your data hosted in Germany) - the EU–US Data Privacy Framework, under which Sentry is certified, with standard contractual clauses as a supplementary safeguard.
- Google LLC (United States) - the EU–US Data Privacy Framework, under which Google LLC is certified, with standard contractual clauses as a supplementary safeguard. This covers both sign-in with Google and, where enabled, Google Analytics.
- Ukrainian payment service provider (acquirer) — applies only from the launch of paid subscriptions. There is **no European Commission adequacy decision for Ukraine**, so this transfer will rely on the European Commission's standard contractual clauses together with a transfer impact assessment. We will not begin transferring payment data until those safeguards are in place in writing.
- State Tax Service of Ukraine — receives **settlement data only**, as part of the fiscal receipt (section 9.3), on the basis of an obligation imposed by Ukrainian law. The content of your reflections is not sent to it.
- Hetzner Online GmbH (Germany), Meta Platforms Ireland Limited (Ireland) and TikTok Technology Limited (Ireland) are located within the EEA, so sharing your data with them is not an international transfer. Meta and TikTok may themselves transfer data onward to their United States affiliates; those onward transfers are governed by their own data transfer terms and, for Meta, by its European data transfer addendum.
11. How long we keep your data
We keep personal data only for as long as necessary for the purpose for which it is processed, or as required by law.
On expiry of the relevant retention period, personal data is deleted or, where deletion is not immediately possible (for example, on immutable backup media), securely isolated until deletion is feasible.
- Account and email - retained until you request deletion. Your email address is anonymised within the same transaction; all other linked data is soft-deleted and permanently purged after a 30-day cooling-off period.
- Reflection data, intentions and AI narrative - soft-deleted immediately on your erasure request and permanently purged after 30 days. You may re-take the quiz at any time to generate a fresh reading.
- Tarot spread readings — retained while your consent is active. On withdrawal of consent they are permanently deleted **after 30 days**, and on an Art. 17 erasure request immediately. Consent audit events are kept for 1095 days separately and contain none of your text.
- Safety-signal records - as described in Section 7: the identifier link is severed on erasure; the resulting anonymised, aggregated information is retained for up to seven (7) years for safety review.
- Technical and security logs - up to twelve (12) months, unless a longer period is necessary to investigate or defend against a security incident, fraud, abuse or other unlawful conduct, or is required by law.
- Paid subscription records — invoices, fiscal receipts and related tax and accounting records are kept for the period required by applicable tax law. For sales to buyers in the European Union, VAT records are kept for **ten (10) years**; this is an EU legal requirement and it applies even after your account is deleted. Such a record deliberately holds the **minimum data**: country, amount, rate, date and transaction identifier — **no name, no email address and no content of your reflections**. That way deleting your account does not break the tax record, and the tax record does not retain your personal texts.
- Cookies - A/B-test variant: 30 days; consent state: 12 months (see Section 17).
- Idempotency keys - 24 hours, then automatically purged. Result-share tokens: 90 days from creation, hard-deleted after a 7-day grace period following expiry.
12. Your rights
Under the GDPR - in particular Articles 15 to 22 - and the equivalent provisions of the Ukrainian Data Protection Law and any other applicable law, you have the following rights, including the right to withdraw consent (Article 7(3)) and the right to lodge a complaint (Article 77):
- Access (Article 15) - to obtain confirmation of, and a copy of, the personal data we hold about you.
- Rectification (Article 16) - to have inaccurate data corrected and incomplete data completed.
- Erasure (Article 17) - to have your account and the data associated with it deleted, subject to the limits in Section 7 for information that has already been anonymised.
- Restriction (Article 18) - to ask us to pause processing while a dispute is resolved.
- Data portability (Article 20) - to receive your data in a structured, commonly used and machine-readable format, and to transmit it to another controller.
- Objection (Article 21) - to object, on grounds relating to your particular situation, to processing based on our legitimate interests.
- Withdrawal of consent (Article 7(3)) - to withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Complaint (Article 77) - to lodge a complaint with a competent supervisory authority (see Section 14).
13. How to exercise your rights
Most rights - access, erasure, export and withdrawal of consent - can be exercised directly through the self-service controls in your account cabinet. For anything you cannot complete there, email privacy@vidlunnia.com. We respond within one calendar month (Article 12(3)); complex or numerous requests may be extended by up to two further months, with notice. We may take reasonable steps to verify your identity before responding.
14. Supervisory authorities and complaints
In Ukraine: the Ukrainian Parliament Commissioner for Human Rights (Уповноважений Верховної Ради України з прав людини). In the EU/EEA: because we have no establishment in the EU, the one-stop-shop mechanism does not apply and any concerned supervisory authority is competent. You may lodge a complaint with the supervisory authority in your Member State of habitual residence, place of work or the place of the alleged infringement (Article 77).
15. Automated decision-making
We do not take any decision that produces a legal or similarly significant effect on you solely by automated means (Article 22). The numerology numbers and the AI-generated narrative are creative reflection, not a score, an assessment or a decision. The safety protocol may automatically present a safety path when a distress signal is detected; this is a protective signposting measure for your benefit, does not determine your access to the Service and does not produce legal effects.
16. Security
We apply appropriate technical and organisational measures (Article 32), including encryption of data in transit, encryption at rest of the intentions you record, httpOnly authentication cookies, restricted server access, removal of personal data from error telemetry, access controls and periodic review. No system of electronic storage or transmission can be guaranteed entirely secure; you are responsible for the security of the device and email account you use to access the Service. In the event of a personal-data breach likely to result in a high risk to your rights and freedoms, we will notify you without undue delay (Article 34) and the competent supervisory authority within 72 hours (Article 33).
17. Cookies and similar technologies
We keep cookies to a minimum. Strictly necessary cookies and local-storage entries - for session and authentication, security, recording your consent state and storing non-personal interface settings - do not require consent. Where we use any non-essential cookies or similar technologies that store or access information on your device, we do so only with your prior consent (as required by Article 5(3) of the ePrivacy Directive, as implemented in your jurisdiction), which you may withdraw at any time through the cookie-preference controls or your browser settings. We do not use cookies for cross-site advertising.
Your choice is not limited to the banner you saw once. There is a permanent analytics and cookie control at the foot of this page, under “Cookie settings”, which you can reach at any time from the link in the footer of any page. You may use it to withdraw your consent, or to give it again, as often as you wish; it requires no account, so it is available to you whether or not you are signed in. Withdrawal takes effect immediately and without a reload: we record the withdrawal, stop our own analytics collection on the server as well as in your browser, instruct the third-party tools described in Section 9 to stop, and delete the identifiers they had already placed on your device. Withdrawal does not affect the lawfulness of processing carried out before it (Article 7(3)).
18. Children
The Service is not directed to, and is not intended for use by, persons under the age of eighteen (18). We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a person under the age of 18, we will delete it without undue delay.
19. Changes to this Policy
We will notify registered users by email at least 30 days before any material change to this Policy takes effect. Minor clarifications (such as corrections of spelling or formatting, or the addition of a sub-processor under the same legal basis) may be made without advance notice; the “Last updated” date at the top of this Policy reflects any change.
20. Governing law
This Policy is governed by the laws of Ukraine, in particular the Ukrainian Data Protection Law. Nothing in this Section limits any mandatory right granted to you by the GDPR or by any other data-protection law applicable to you in your jurisdiction; such rights remain available to you and are honoured by us in accordance with this Policy.
21. Contact
Controller: the Operator, trading as Vidlunnia Privacy contact: privacy@vidlunnia.com.