Legal Document - current
Privacy Notice
Read how personal data is collected, used, stored, shared, and protected when you interact with the Hermetic Arts platform.
Privacy Notice
1. Introduction Hermetic Arts respects your privacy and is committed to handling personal data in a transparent, lawful, and secure manner. This Privacy Notice explains what personal data may be collected through the platform, how it may be used, why it may be used, who it may be shared with, how long it may be retained, and what rights individuals may have in relation to their information. Hermetic Arts is a brand, web application, and platform operated by IAF Tech Development. The Hermetic Arts brand, software, visual identity, content structure, and associated intellectual property are owned by IAF Design and are used by IAF Tech Development for the operation of the Hermetic Arts platform. This notice describes how personal data is handled in relation to the current platform experience and should be read together with any more specific notices presented in a relevant product flow. 2. Scope of This Notice This Privacy Notice applies to personal data collected through: the website the web application account registration sign-in and account management flows public profile interactions contact and enquiry routes messaging features where enabled booking and payment-related features where enabled support, moderation, legal, compliance, and security processes other related interactions with the platform 3. Who Controls Personal Data Operating entity: IAF Tech Development Brand / IP owner: IAF Design IAF Tech Development operates the Hermetic Arts platform. IAF Design owns the Hermetic Arts brand and associated intellectual property described in this notice. Where a specific feature, service, or legal arrangement involves another controller or a joint arrangement, that should be made clear in the relevant flow or notice. 4. Personal Data We May Collect Depending on how you use the platform, we may collect and process categories of personal data such as: Account and identity information name display name email address login credentials and account identifiers role or account type Profile and participation information profession, specialties, portfolio-related information, biographical details, and other submitted profile content account preferences onboarding or role assignment information Communications data messages, enquiries, support requests, replies, and moderation-related communications where relevant Transactional and service-related information bookings, orders, service requests, payment status information, payout-related details, and related operational records where relevant and enabled Astrology chart and compatibility information birth data supplied for natal-chart calculation saved chart identifiers and saved comparison records calculated planetary positions houses and angles where birth time permits compatibility factors, scores, confidence information, warnings and interpretations membership unlock, allowance, purchase, refund and entitlement records only for disabled/future paid comparison and membership foundations, not as launch-active paid features Free Tarot information free Tarot questions, draws, reflections, results, and reading history are not stored by the launch-active free Tarot feature and are not connected to the planner Technical and usage information IP addresses processed transiently where needed, and IP hashes or security metadata where the repository stores hashed abuse-prevention records limited recent network observations for authenticated accounts, stored as hashed and masked security records for abuse prevention and enforcement browser/device data session and login records access timestamps audit and security logs usage events and diagnostics Cookie and preference data information collected through cookies and similar technologies as explained in the Cookie Notice 5. How Personal Data May Be Collected We may collect personal data: directly from you when you register, sign in, complete forms, contact us, apply for roles, or use platform features automatically when you use the website or app from communications or support interactions from payment, verification, hosting, analytics, messaging, or other service providers where relevant from moderation, compliance, fraud-prevention, or security monitoring activities where necessary and lawful 6. Why We Use Personal Data We may use personal data for purposes such as: creating and managing accounts providing access to platform features showing public profile content where appropriate enabling discovery, communication, services, bookings, and related features processing operational, transactional, or support activities maintaining security, audit trails, and access controls detecting fraud, abuse, misuse, or unauthorised activity responding to legal, regulatory, or rights-related matters improving platform functionality, stability, and user experience communicating important service, legal, or account notices 7. Lawful Bases Where UK GDPR or similar law applies, we may rely on lawful bases such as: performance of a contract compliance with legal obligations legitimate interests, where those interests are not overridden by the rights and freedoms of individuals consent, where consent is required establishment, exercise, or defence of legal claims where relevant The precise lawful basis may vary depending on the type of data and the processing activity involved. 8. Who Personal Data May Be Shared With We may share personal data where appropriate with: hosting and infrastructure providers authentication and security providers analytics providers where enabled payment and transaction providers where relevant messaging, notification, or communications providers professional advisers, auditors, insurers, or legal representatives courts, regulators, law enforcement, or other authorities where required or justified by law internal teams, role-holders, or authorised personnel on a need-to-know basis We do not share personal data arbitrarily. Access and disclosure should be limited to what is reasonably necessary for the relevant purpose. Launch-active infrastructure and service providers may include Vercel or equivalent hosting, Neon/PostgreSQL or equivalent database hosting, Stripe for payments and Connect onboarding, Resend for email delivery, and Cloudinary for public media uploads. Private-document upload and access routes remain disabled for launch and should not be treated as launch-active document collection. Astrology comparison purchase metadata sent to Stripe uses opaque identifiers and version references. It should not include birth date, birth time, birthplace, coordinates, chart labels, person names, relationship labels, or interpretation text. Stripe processes payment information under Stripe's own terms and privacy practices. Birth data is not stored inside commercial purchase or entitlement records merely for payment audit. Commercial audit records may survive deletion of a saved comparison where required for financial, fraud-prevention, dispute, accounting, tax, compliance, or legal obligations. Locked full-report data is not sent to unauthorised browsers; free users receive only the server-approved capped projection. Users should avoid putting unnecessary sensitive third-party information into chart labels, comparison names, notes, or messages. Users should create, compare, or share another person's chart only where they have an appropriate lawful and ethical basis to do so. 9. International Transfers If personal data is transferred outside the UK or outside another applicable jurisdiction, appropriate safeguards should be used where required by law. Where material international transfers apply to a specific platform flow or provider arrangement, the relevant notice or provider terms may describe the safeguards used. 10. Retention We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including: platform operation account administration legal and regulatory compliance audit and security needs dispute handling fraud prevention enforcement of rights and agreements Retention periods may vary depending on the type of data, the feature involved, legal obligations, and operational needs. Specific retention periods for astrology comparison reports, membership allowance records, and commercial audit records should be reviewed by legal and operations before public commercial launch where they are not already defined by an approved retention schedule. Recent authenticated-account network observations may be retained for approximately up to 30 days for security, fraud-prevention, abuse-prevention, and enforcement purposes. This moderation feature stores hashed network identifiers and masked display hints in the Hermetic Arts application database; it does not persist full IP addresses there. Infrastructure, hosting, security, and other service providers may process IP addresses under their own applicable service and privacy terms. Moderation and IP-block records may be retained longer where reasonably necessary for security, audit, fraud-prevention, dispute, legal, compliance, or platform-integrity purposes. Account closure, archive, or deactivation may restrict access and visibility without immediately deleting every underlying record. Some booking, order, payment, payout, message, application, moderation, security, tax, accounting, legal, dispute, fraud-prevention, and platform-integrity records may need to be retained where reasonably necessary or legally required. Deletion or erasure requests will be assessed through the applicable rights-request process rather than treated as an automatic immediate deletion of all historical records. 11. Security We take steps intended to protect personal data through technical and organisational measures appropriate to the nature of the platform and the risks involved. These measures may include access controls, authentication safeguards, logging, role-based permissions, monitoring, review processes, and other security measures as implemented from time to time. No method of transmission or storage is guaranteed to be completely secure, but we aim to apply reasonable and proportionate safeguards. 12. Your Rights Where applicable, you may have rights in relation to your personal data, including the right to: request access request correction request deletion in certain circumstances request restriction of processing in certain circumstances object to certain processing in certain circumstances withdraw consent where processing is based on consent complain to the relevant supervisory authority if you believe your rights have been infringed The exact scope of these rights depends on applicable law and the circumstances of the processing. Hermetic Arts currently supports privacy-rights enquiries through the Help or Contact route. The current product does not promise an instant self-service DSAR export or immediate total erasure tool. Requests for access, correction, deletion/erasure, restriction, objection, portability where applicable, or consent withdrawal will be handled through the available support and administrative workflow. Transactional and service emails, such as sign-in, booking, payment, payout, application, support, and important account notices, are sent for operational purposes. Hermetic Arts does not currently operate a launch-active marketing newsletter or promotional email system that is bundled into account creation. If optional marketing communications are introduced later, they should use an appropriate separate consent and withdrawal process. 13. Children The platform is not intended to be used in breach of applicable age or legal eligibility requirements. If we become aware that personal data has been collected in a way that should not have occurred under the applicable rules of platform use, we may take appropriate steps to review, restrict, or remove that data. 14. Changes to This Notice We may update this Privacy Notice from time to time to reflect changes to the platform, the law, the relevant entities, or the way personal data is processed. Where appropriate, updates may be brought to users' attention through the website, the app, or other suitable communication methods. 15. Contact and Complaints Privacy and data protection enquiries should be directed through the official privacy or legal contact route made available by the platform. For privacy and data protection enquiries, please use the platform's Help or Contact route unless a more specific contact method is shown in the relevant product flow or notice.