Privacy Policy

1.1

Your privacy is the foundation of this platform. By the very nature of our services, we receive intimate information from you — date of birth, personal questions, sometimes photographs. The document below tells you exactly what we collect, why, with whom we share this data, and how we protect it. We wrote it as clearly as possible and avoided technical jargon where it was not strictly necessary.

1. Who we are

The controller of personal data under GDPR is NEXUS CONCEPT SRL, registered office at Str. Grădiștei 36, Sat Păulești, Prahova County, postal code 107400, România, Tax ID 52611066, Trade Register no. J2025074790000.

For any request related to your personal data, please contact us at:

2. What data we collect and why

We collect only the data needed to provide you with the services you order. Below we grouped everything into categories, with the clear purpose of each.

2.1 At account creation

  • Full name — so that we can address you personally and personalize interpretations;
  • Email address — for authentication, account confirmation, and communication with you;
  • Billing address — for invoice generation;
  • Password — stored encrypted with bcrypt (a one-way algorithm). Nobody, no NexusGrounds employee, including administrators, can see your password;
  • Language preference — to display the interface in Romanian or English;
  • Date and time of registration, plus versions of accepted documents (Terms and Privacy Policy) — proof of your consent, as required by Art. 7 GDPR.

2.2 When ordering astrology, numerology, or compatibility services

  • Date, time, and place of birth — the only data strictly necessary for our artificial intelligence system to build your chart and generate the interpretation;
  • Questions and additional notes you voluntarily provide in the order wizard;
  • For compatibility, the birth data of the second person (with their consent).

This data is considered sensitive (Art. 9 GDPR — given its spiritual/philosophical dimension) and is encrypted in our database using an AES-256 algorithm. Even if someone were to gain unauthorized access to the database, the data could not be read without our key.

2.3 For services with photographs (Palm Reading, Coffee Reading)

  • The photos you upload — used exclusively for drafting your reading;
  • Technical metadata of the photos (size, format, timestamp) — for validation and processing.

Who can see your photos? Exclusively our AI system for generating the reading, plus the technical administration team for platform maintenance. All operators with access have signed confidentiality agreements. Photos are stored in a private area of our servers, inaccessible to the public via direct URL — access is exclusively through secure links with limited duration (60 minutes).

How long are they retained? Your photos are automatically deleted 30 days after your reading is finalized. After this period they no longer exist physically on our servers and cannot be recovered.

2.4 At payment

  • Payment is processed entirely through the chosen sub-processor — Banca Transilvania, 3-D Secure or PayPal Europe S.à r.l. (Luxembourg, EU) and or other accredited financial institutions — depending on the payment method selected;
  • Your card data never reaches NexusGrounds servers. The chosen payment gateway processes it directly;
  • We store only: transaction reference, amount paid, status (paid / failed / refunded), currency, and date — data strictly necessary for invoicing and tax obligations.

2.5 Data collected automatically

  • Session cookie nexusgrounds-session — needed to keep you signed in;
  • Security cookie XSRF-TOKEN — protects you from CSRF attacks;
  • IP address and user-agent — retained for security and to audit your consents. We do not use them for advertising targeting.

For full details, see the Cookie Policy.

3. Whom we share your data with

Our policy is clear: we do not sell, rent, or transfer your data to anyone for advertising or marketing. Your data only reaches the following categories of recipients, strictly to deliver your service:

  • Our artificial intelligence system (operated internally by NEXUS CONCEPT SRL) — generates the interpretations based on the data you provide. The system is hosted on the operator's own infrastructure.
  • Internal technical team — system administrators who keep the platform functional and secure, plus occasional quality reviews of interpretations. Data access is restricted and logged.
  • PayPal Europe S.à r.l. (Luxembourg, EU) — PayPal payment processor. Receives your email, amount, and transaction reference. PayPal is a separate controller for your payment data; see their privacy policy.
  • Revolut Bank UAB (Lithuania, EU) — Revolut payment processor. Receives your email, amount, and transaction reference. Your data only reaches one of these two sub-processors, depending on the payment method chosen; we do not store full card data (PAN, CVV).
  • Hosting provider (server infrastructure) — EU data center.
  • Transactional email provider (account notifications, email confirmation) — with EU servers.

If state authorities formally request, through a well-founded legal request, that we disclose certain data, we are legally obliged to comply. We always ask for the legal basis and strictly respect the scope of the request.

4. Your rights (GDPR)

The European regulation grants you a set of rights over your data. You can exercise them at any time — we strive to respond within a maximum of 30 days.

  • Right of access (Art. 15) — you can see what data we hold about you. Much of it is accessible directly from your account (overview, experience history, settings); for a complete view, write to us.
  • Right of rectification (Art. 16) — you can correct or update incomplete or incorrect data from the Settings section of your account.
  • Right to erasure — "to be forgotten" (Art. 17) — you can delete your account at any time from Settings → Security. We immediately anonymize your name and email, decouple interpretations from your identity, and close sessions. The only data retained is financial (7 years tax obligation) — legally required.
  • Right to restriction (Art. 18) — you can ask us to "freeze" the processing of certain data while we investigate a concern.
  • Right to portability (Art. 20) — you can download your data in a structured format (JSON / PDF), to transfer it to another controller or for your personal use.
  • Right to object (Art. 21) — you can unsubscribe from the newsletter at any time and withdraw optional consents (analytics/marketing cookies) from the cookies page.
  • Right not to be subject to solely automated decision-making (Art. 22) — your interpretations are generated by our artificial intelligence system, based on the data you provide. These interpretations are symbolic tools for personal reflection and DO NOT constitute decisions producing legal effects on you (e.g., credit scoring, recruitment, medical decisions) or significantly affecting you in a similar manner. To exercise this right (request human review or contest), contact us at contact@nexusgrounds.com.

To exercise any of these rights, write to contact@nexusgrounds.com.

Right to lodge a complaint — if you are dissatisfied with how we process your data, you can always contact the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)www.dataprotection.ro, tel. +40 318 059 211, email anspdcp@dataprotection.ro.

5. How long we retain your data

Data category Retention period
Active account data (name, email) For the duration of the active account
Interpretations and birth data For the duration of the account; anonymized upon deletion
Photos (palm, coffee) 30 days after the interpretation is finalized, then automatically deleted
Transactions and invoices 7 years (tax obligation — Romanian Tax Code)
Consent history (Terms, Privacy, Cookies) For the duration of the account + 3 years after deletion (legal proof)
Session cookie 120 minutes
Technical security logs Maximum 90 days

6. How we protect your data

Security is not a detail — it is a priority. Here are, briefly, the measures we take:

  • Passwords — stored with the bcrypt algorithm (12 rounds); they are one-way hashes that nobody can reverse. If you forget your password, we reset it, we do not "recover" it.
  • Encryption at rest for personal data — the most sensitive information (date of birth, time, place, names introduced in orders) is encrypted in the database with AES-256, using the platform's private key. Even if someone physically extracted the database, the data would appear as unreadable random text.
  • Encryption in transit — all connections with the platform are protected through HTTPS with an up-to-date TLS certificate. Your data never travels "in the clear" between your browser and our servers.
  • Photos in private storage — stored on a separate volume, inaccessible through public URL. Access is exclusively through temporary links, cryptographically signed, with 60-minute expiration.
  • Restricted access — only employees who need access to a specific type of data have permissions for that data. Each access is logged.
  • Encrypted backups — kept in a separate EU location.

If — despite all these measures — a security breach that could affect your rights were to occur, we will notify you directly within a maximum of 72 hours, together with the competent authority (ANSPDCP), as required by Art. 33-34 GDPR.

7. Cookies

We use a strict minimum of cookies, necessary for the platform to work. We do not use Google Analytics, we do not use Meta Pixel, we do not use any third-party tracking tool. Full details, including how to manage your preferences, in the Cookie Policy.

8. International data transfers

All your data is stored on servers within the European Union. The main sub-processors are located in the EU: PayPal Europe S.à r.l. (Luxembourg, EU) for PayPal payments — global headquarters in the USA, European operations in Luxembourg, GDPR-compliant — and Revolut Bank UAB (Lithuania, EU) for Revolut payments. For our services, we do not transfer your data outside the EU.

9. Changes to the Privacy Policy

If we substantially update this Policy, we notify you by email and via a visible banner in your account with at least 30 days before it takes effect. Old versions are preserved in our consent register, so that you can always see what you accepted and when.

Current version: 1.1, in force since May 9, 2026.

10. Contact


Ultima actualizare: May 9, 2026
Versiune: 1.1

What those who lived the experience say

Real stories from our clients, shared with their consent.

A pleasant experience and interesting information. I was impressed by the attention to detail and the professionalism.

Oana Anca

Palm Reading

The analysis was detailed and well explained. I found a lot of useful and relevant information for my relationship.

Adrian Client

Compatibility Report

One of the most interesting experiences I've had. The natal chart gave me a complete picture of my strengths and my personal challenges.

Caroline Vasilescu

Natal Chart

The interpretation was done with care and professionalism. I felt heard and received answers that helped me see certain situations more clearly.

Ramona Voicu

Coffee Reading

The report was extremely useful and well structured. It helped me better understand both the strengths and the challenges in my relationship.

Diana Stănciulescu

Compatibility Report

I received answers to many questions and appreciated the professionalism with which the interpretation was carried out.

Anca Chiorean

Palm Reading