GDPR Compliance

April 11, 2026

Last updated: April 11, 2026

1. Our commitment

AuraKosmos is committed to complying with the General Data Protection Regulation (GDPR — EU Regulation 2016/679) and applicable data protection laws.

2. Data controller

  • Controller: Meetricks, LLC
  • Registered office: 7302 Yellowstone Road Cheyenne, WY 82009, USA
  • Contact: Contact us

3. Record of processing activities

Processing Data Legal basis Duration
Account management First name, email, date of birth, gender Contract Account lifetime + 3 years
AI consultations Consultation history Contract Account lifetime
Payments Stripe customer ID Contract + legal obligation 10 years
Daily horoscope Zodiac sign, email Consent Until withdrawal
Marketing emails Email, preferences Explicit consent Until withdrawal
Analytics Browsing data Consent 6 months
Security IP, user-agent Legitimate interest 12 months
Backups All data Legitimate interest 14 days

4. Sub-processors

Sub-processor Role Location Safeguards
Contabo GmbH Hosting Germany (EU) GDPR native
Stripe Payments United States SCC + DPF
Mollie Payments Netherlands (EU) GDPR native
Anthropic AI (content generation) United States SCC, anonymized data
Google (Gemini) AI (translation) United States SCC + DPF
Resend Transactional emails United States SCC
Cloudflare CDN + R2 storage Global SCC + DPF

5. User rights

How to exercise your rights:

Right How
Access From account settings or via Contact us
Rectification From account settings
Erasure "Delete my account" button in settings
Portability Upon request via Contact us
Objection Communication preferences in settings
Restriction Upon request via Contact us
Withdrawal of consent Communication preferences or email unsubscribe

Response time

We respond to all rights requests within 30 days.

6. Security measures

  • HTTPS encryption (TLS 1.3) on all communications
  • Passwords hashed with bcrypt (12 rounds)
  • API keys encrypted with AES-256-CBC
  • Encrypted backups on private storage (Cloudflare R2)
  • Mandatory email verification (Double Opt-In)
  • Explicit consent for marketing emails (opt-in)

If you believe that the processing of your personal data constitutes a violation of the GDPR, you have the right to lodge a complaint with:

Commission Nationale de l'Informatique et des Libertés (CNIL) 3 Place de Fontenoy — TSA 80715 75334 Paris Cedex 07 Website: www.cnil.fr Phone: +33 1 53 73 22 22

7. Data Breach Notification

In accordance with Articles 33 and 34 of the GDPR, in the event of a personal data breach:

  • We will notify the CNIL within 72 hours of becoming aware of the breach
  • If the breach is likely to result in a high risk to your rights and freedoms, we will inform you without undue delay
  • We will document any breach and the corrective measures adopted

8. Privacy by Design

AuraKosmos integrates data protection from the design stage:

  • Minimization of collected data
  • Anonymization of data transmitted to AI providers
  • No storage of credit card data
  • Analytics cookies blocked by default (opt-in)
  • One-click account deletion

9. Contact and complaints

For any questions regarding the protection of your data, contact us via our contact page.