Home › Contact › Privacy Policy
Privacy Policy
This Privacy Policy explains which personal data BaZi.cards (the “Service”, “we”) collects when you use the website en.bazi.cards and the related Telegram bot, why we process it, on what legal basis, how long we keep it and which rights you have. We write in plain language on purpose: your birth data is intimate information, and you should be able to understand exactly what happens to it.
1. Who is responsible
The controller of your personal data is the operator of BaZi.cards:
ALEKSANDR SAZONOV, MEI (Microempreendedor Individual)
Trade name: Bazi Cards
Pernambuco, Brazil
Tax / registration number: CNPJ 69.352.503/0001-22
E-mail: support@bazi.cards · Telegram bot: @Bazinterbot
For any privacy request you can write to support@bazi.cards. We do not appoint a separate data protection officer; the operator handles all requests personally.
2. What data we collect
We collect only what the Service actually needs.
- Account data — your e-mail address, a password in hashed form (we never see the password itself), the language of your interface and the date of registration.
- Birth data — date, time and place of birth, and optionally gender. You may also enter the birth data of another person (for example, for a compatibility reading); in that case you confirm that you are entitled to share it.
- Questions to the Oracle — the text of the questions you type and the automatically generated answers, stored in your account so you can return to them.
- Purchase data — which readings you ordered, the amount, currency, date and an order identifier. Card numbers and other payment credentials are handled exclusively by the payment provider and never reach our servers.
- Waitlist data — if you ask to be notified when payments open in your region, the e-mail address you enter, the language version of the site and the product and price that were shown to you at that moment.
- Referral programme data — if a referral programme is available in your region and you take part in it (by inviting someone or by following an invitation), we keep keyed hashes (HMAC) of the IP address, of its network and of the browser identifier in order to detect self-referral and abuse. A hash cannot be turned back into the address itself; the hashes are kept for about six months after the last visit. Legal basis: our legitimate interest in preventing fraud.
- Technical data — IP address, browser type, device type, referring page, time of request and error logs. These are needed to run the site securely and to defend it against abuse.
- Cookies and local storage — see section 9 and the separate Cookie Policy.
3. Birth data is treated as sensitive
A date, an exact time and a place of birth, combined with the questions you ask, can reveal a great deal about a person. Although such data is not always listed among the “special categories” in data protection law, we deliberately treat it with the protection level of sensitive data:
- we process it only to build and interpret your chart, and never for advertising or profiling for third parties;
- we request your explicit consent before the first calculation;
- you can delete it from your account at any time, and we will delete it from our systems as described in section 5;
- we never sell, rent or share it with data brokers.
4. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Creating your account and letting you sign in | e-mail, password hash | performance of a contract |
| Calculating the chart and generating interpretations, forecasts and compatibility readings | birth data | your explicit consent; performance of a contract |
| Answering questions submitted to the Oracle | question text, chart | performance of a contract; your consent |
| Writing the wording of Oracle answers and written readings with the help of an external text-generation service (sections 6 and 7) | question text, calculated chart data | performance of a contract; your consent |
| Notifying you when payments open in your region and applying the early-access discount (waitlist) | e-mail, site language, product and price shown | your consent — you can withdraw it at any time by writing to us |
| Processing orders, delivering paid readings, keeping accounting records | purchase data | performance of a contract; legal obligation |
| Sending service e-mails (confirmation, password reset, delivery of a reading) | performance of a contract | |
| Sending occasional news about the Service | your consent — you can unsubscribe with one click in every letter | |
| Security, fraud prevention, rate limiting, debugging | technical data | our legitimate interest in running a safe and stable service |
| Responding to support requests and legal claims | whatever you send us | legitimate interest; legal obligation |
Where processing rests on consent, you may withdraw it at any time; the withdrawal does not affect the lawfulness of processing carried out before it.
5. How long we keep data
- Account, birth data, readings and Oracle history — for as long as your account exists. If you delete the account, they are erased within 30 days; backups are overwritten within a further 90 days.
- Purchase records — for the period required by tax and accounting legislation applicable to the operator (typically 5–10 years), in a form that no longer contains birth data.
- Technical logs — up to 90 days, unless a specific incident requires longer retention.
- Support correspondence — up to 3 years after the last message.
- Waitlist entries — until you ask us to remove your address, and in any case no longer than 24 months from the day you joined the waitlist.
- Newsletter consent — until you unsubscribe.
6. Who else sees the data
We do not sell personal data and do not share it with advertisers. To operate the Service we rely on a small number of processors who act on our instructions under written contracts:
- Hosting — servers located in the European Union (Finland). The database, chart calculations and the storage of your account, readings and Oracle history are located there.
- Network delivery and protection — Cloudflare, Inc. (United States). Connections to the site pass through Cloudflare's network, which processes your IP address and technical request data to deliver pages and to protect the Service against attacks; on the sign-in and chart forms Cloudflare Turnstile checks that a real person is using the form. Cloudflare acts on our instructions under its data processing addendum.
- Text generation — the wording of Oracle answers (and, when paid readings are available in your region, of written readings) is produced with the help of an external provider of a text-generation service located in the United States. For each request it receives only the text of your question or of the section being written and the calculated chart data needed for it (the pillars, the elements, related indicators of the chart and the traditional rules selected for it). It does not receive your e-mail address, password or payment data. The provider acts on our instructions under a data processing agreement; under its business terms the data is not used to train its models and may be kept for a limited period (up to 30 days) to detect abuse before it is deleted.
- E-mail delivery — Brevo (Sendinblue SAS, France) sends confirmation letters, password resets and, with your consent, newsletters. Brevo receives your e-mail address and the content of the letter.
- Payment provider — the payment provider chosen by the operator receives the data required to process the payment (amount, currency, order identifier, and the details you type on its own payment page). The provider is an independent controller for the payment itself; its name is shown on the payment page before you pay.
- Telegram — if you use our bot @Bazinterbot, Telegram Messenger Inc. processes your messages under its own privacy policy; we receive your Telegram identifier and the messages you send to the bot.
- Waitlist — the addresses left in the waitlist form are stored in our own database on the same EU servers and are not passed to anyone else.
We may also disclose data when the law requires it, for example in response to a lawful request from a court or authority, or to establish, exercise or defend legal claims.
7. International transfers
Our servers are in the European Union (Finland); your account, birth data, readings and Oracle history are stored there. Some processors listed in section 6 process data outside your country:
- United States — text-generation service. When you ask the Oracle a question (or a written reading is prepared for you), the question text and the calculated chart data described in section 6 are sent over an encrypted connection to the provider in the United States, which returns the wording of the answer. Your e-mail address, password and payment data are not sent. For users in the EU/EEA, Switzerland and the United Kingdom this transfer relies on the Standard Contractual Clauses approved by the European Commission (with the UK addendum) that form part of the provider's data processing agreement; for users elsewhere it relies on the mechanism required by local law described in section 12. The transfer is necessary to answer your question; if you do not want it to take place, do not use the Oracle.
- United States — network delivery and protection. Cloudflare may process your IP address and technical request data in the United States and in other countries where its network operates. For users in the EU/EEA, Switzerland and the United Kingdom this relies on the Standard Contractual Clauses included in Cloudflare's data processing addendum; for users elsewhere it relies on the mechanism required by local law described in section 12.
- Telegram and e-mail delivery. If you use our Telegram bot, Telegram Messenger Inc. processes your messages under its own policy; Brevo delivers our e-mails from the European Union.
We limit the data transferred to what each processor genuinely needs, and we never sell personal data.
8. Your rights
Depending on where you live, you have the following rights, which we honour for every user regardless of jurisdiction:
- Access — to receive a copy of the data we hold about you;
- Rectification — to correct inaccurate data (birth data can be edited in your account);
- Erasure — to have your account and data deleted;
- Restriction and objection — to limit or object to processing based on legitimate interest;
- Portability — to receive your data in a machine-readable format;
- Withdrawal of consent — at any time, for newsletters and birth-data processing;
- Complaint — to lodge a complaint with a supervisory authority. In the EU/EEA this is the data protection authority of your country of residence; in the UK the Information Commissioner's Office (ICO).
To exercise a right, write to support@bazi.cards from the e-mail address linked to your account. We reply within 30 days; if a request is complex we may extend this by a further 60 days and will tell you why. We will not charge a fee unless a request is manifestly unfounded or excessive.
10. Age limit
The Service is intended for adults. We do not knowingly create accounts for, or accept payments from, persons under 18 years of age. If you believe a minor has provided us with personal data, write to us and we will delete it.
11. Security
All traffic is encrypted (TLS). Passwords are stored as salted hashes. Access to the database is limited to the operator and is logged. Integrity of the application is verified before every release. No system is perfectly secure, so if we ever discover a breach that is likely to affect your rights, we will notify you and the competent authority within the time limits set by law.
12. Regional notices
European Economic Area and United Kingdom
We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and, for users in the United Kingdom, the UK GDPR and the Data Protection Act 2018. The legal bases listed in section 4 refer to Article 6 (and, for birth data, Article 9 where applicable) of these regulations.
California and other US states (CCPA/CPRA)
If you are a California resident, you have the right to know which categories of personal information we collect (listed in section 2), to delete it, to correct it, to limit the use of sensitive personal information and not to be discriminated against for exercising these rights. We do not sell or share personal information in the meaning of the CCPA/CPRA, and we have not done so in the preceding 12 months; therefore no “Do Not Sell or Share My Personal Information” link is required, but you may send such a request to support@bazi.cards at any time. We do not use or disclose sensitive personal information for purposes other than providing the Service. Residents of Virginia, Colorado, Connecticut, Utah and other states with comparable laws have equivalent rights and may exercise them the same way.
Canada (PIPEDA)
We collect, use and disclose personal information with your knowledge and consent, limit it to what is necessary for the purposes identified above and keep it only as long as needed. You may withdraw consent, request access to your information and challenge its accuracy. Unresolved complaints may be directed to the Office of the Privacy Commissioner of Canada.
Other countries
Wherever you are, we apply the same standard described in this Policy; where local law gives you additional rights, we honour them.
13. Changes to this Policy
We may update this Policy when the Service or the law changes. The current version and its date are always shown at the top of this page. If a change materially affects your rights, we will notify registered users by e-mail before it takes effect.
Contact
Questions about this document or your data:
E-mail: support@bazi.cards
Telegram bot: @Bazinterbot