1. Data Controller
This notice has been prepared under the Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”) to set out the principles governing the processing of the personal data of users of the Astrum platform.
Data Controller: Astrum
Address: Istanbul, Türkiye
E-mail: astrum.horary@gmail.com
Website: horaryastrum.com
2. Personal Data Processed and Method of Collection
While you use the service, the following data is processed by fully automated means:
- ◆Transaction Security Data: your e-mail address, used to match your payment and to deliver your digital receipt.
- ◆Service Data: the astrology question you enter and the geographic location at the moment of the question (used only for the instantaneous chart calculation; not stored permanently).
- ◆System Data: IP address, browser type, and date and time of visit (for legal obligations and fraud prevention).
- ◆Financial Data: the name, surname, and card details entered during payment are transmitted directly to the licensed payment institution; they are NEVER stored on Astrum's servers.
3. Purpose of Processing
- ◆delivering the AI-assisted horary astrology interpretation service instantly,
- ◆carrying out payment transactions securely and delivering the service to the correct person,
- ◆operating information-security processes and preventing potential fraud attempts,
- ◆fulfilling the record-keeping and reporting obligations arising from the applicable legislation.
4. Transfer of Personal Data
Your personal data is never sold, rented, or used for profiling for commercial purposes. It is transferred only to a limited extent, to provide the service and to meet legal requirements:
- ◆Licensed Payment Institution: transaction information, so that payment collection can be performed to PCI-DSS security standards.
- ◆AI API Provider (Google LLC — Gemini API): the question text, the chart data and — if it was given at payment — your first name, used to address you in the reading. Your e-mail address is not transferred.
- ◆Authorised Public Authorities: where legally required, to respond to lawful requests.
5. Data Retention and Cookies
Astrum uses only the session cookies that are technically required for the platform to function. No tracking, advertising, or marketing cookies are used.
Processed data is anonymised or deleted once the service has been performed. However, in accordance with e-commerce and fiscal legislation, financial transaction logs and confirmation records are kept in a secure environment for the statutory period (10 years).
6. Rights of the Data Subject (KVKK Article 11)
Under Article 11 of the KVKK, you may exercise the following rights by applying to the data controller:
- ◆to learn whether your personal data is being processed and, if so, to request information about it,
- ◆to learn the purpose of processing and whether the data is used in line with that purpose,
- ◆to request correction where the data has been processed incompletely or incorrectly,
- ◆to request erasure or destruction within the conditions set out in the law,
- ◆to object to any outcome reached by analysis via automated systems.
For your requests: astrum.horary@gmail.com
7. Data and Payment Security
All communication on our platform is protected with strong 256-bit SSL/TLS encryption certificates. Credit-card security is provided directly by licensed payment institutions holding international PCI-DSS standards. No party — including Astrum staff or servers — can access your full credit-card number or CVC code.