...
...
PRIVACY POLICY
(Numerroom)
Effective date: 24 February 2025
1. Data Controller
The controller of personal data is:
Snov, s.r.o.
Ulica Karolínum 1092/28
93041 Kvetoslavov
Slovak Republic
Company ID: 47459344
VAT ID: SK2023911780
Email: numerroom@numerroom.com
(hereinafter referred to as the "Controller", "we", "us", or "our")
We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and other applicable data protection laws.
2. What Personal Data We Collect
We may collect and process the following categories of personal data:
Account Registration
- Name or nickname
- Email address
- Encrypted password
- Registration date
- IP address
Numerological Profile
- Date of birth
- Additional information voluntarily provided by the user
Purchase Information
- Billing details (if required)
- Payment information processed via Stripe
We do not store full payment card details.
Communication & Technical Data
- Messages sent via the platform
- Device and browser information
- Log files
- IP address
- Cookies
3. Purpose and Legal Basis of Processing
We process personal data for the following purposes:
a) Providing the Numerroom Service
(personalized numerology analysis and AI-generated interpretations)
Legal basis: Performance of a contract (Art. 6(1)(b) GDPR)
b) Payment Processing
Payments are processed by Stripe Payments Europe, Ltd.
Legal basis: Performance of a contract
c) Security and System Protection
- Fraud prevention
- System integrity
- Technical monitoring
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR)
d) Marketing (if consent is given)
Sending newsletters and promotional offers.
Legal basis: Consent (Art. 6(1)(a) GDPR)
Users may withdraw consent at any time.
4. Automated Processing and Artificial Intelligence
Numerroom uses artificial intelligence tools to generate personalized numerology interpretations.
A limited scope of data (e.g., first name for addressing and parameters required for analysis) may be processed via API by OpenAI, L.L.C.
We do NOT transmit:
- Payment details
- Login credentials
- Complete user profiles
- Special categories of personal data
OpenAI acts as a data processor pursuant to Article 28 GDPR.
Data processed through the API is not used to train AI models.
Automated processing does not produce legal or similarly significant effects within the meaning of Article 22 GDPR.
5. Data Recipients
Personal data may be shared with:
- Hosting providers
- Stripe Payments Europe, Ltd. (payment processing)
- OpenAI, L.L.C. (AI processing via API)
- Accounting or legal service providers (where legally required)
We do not sell personal data. We do not sell or share personal information for cross-context behavioral advertising.
6. International Data Transfers
Some service providers (e.g., OpenAI or Stripe) may process data outside the European Union, including the United States.
Where such transfers occur, they are safeguarded through appropriate mechanisms under GDPR, including:
- Standard Contractual Clauses (SCCs)
- Or other legally recognized transfer safeguards
7. Data Retention
Personal data is retained as follows:
User account and related data (profiles, interpretations, consents): for the duration of the account. Upon confirmation of account deletion, personal data is deleted without undue delay; the account and most data are removed immediately after confirmation.
Billing and accounting data: 10 years in accordance with tax and accounting laws. After account deletion, such records are retained in anonymized form (without link to a specific user) to meet legal obligations.
Marketing data: until consent is withdrawn; at most 3 years from last activity.
Technical logs: maximum 90 days. Backups are retained in encrypted form for no longer than 30 days and are not actively processed; once an account is deleted, that data will not appear in new backups.
8. User Rights
Under applicable data protection laws, users have the right to:
- Access their personal data
- Rectify inaccurate data
- Request deletion ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing
- Lodge a complaint with a supervisory authority
Users may delete their account at any time via account settings. Upon confirmation of deletion (password and phrase "delete account"), personal data is deleted without undue delay. Anonymized retention of accounting records as required by law is the only exception.
9. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, or alteration.
Hosting and data are located in the EU. Database connections and website operation use encryption (TLS). Passwords are stored in encrypted form (hash). Backups are retained in encrypted form with limited retention.
10. Cookies
Numerroom uses cookies for:
- Essential website functionality
- Analytics
- Marketing (where consent is provided)
Further details are available in our Cookie Policy.
11. Contact
If you have questions regarding this Privacy Policy or wish to exercise your rights, contact us at: numerroom@numerroom.com
12. Changes to This Policy
This Privacy Policy is effective as of 24 February 2025. It may be updated from time to time; the latest version will always be published on our website.
13. California Privacy Notice (CCPA/CPRA)
If you are a resident of California, you may have additional rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).
Subject to applicable law, California residents may have the right to:
- Know what personal information we collect, use, disclose, or share
- Request deletion of personal information
- Request correction of inaccurate personal information
- Opt-out of the sale or sharing of personal information
- Limit the use of sensitive personal information (if applicable)
- Not be discriminated against for exercising privacy rights
Numerroom does not sell personal information.
If you wish to exercise your California privacy rights, you may contact us at: numerroom@numerroom.com
We may need to verify your identity before processing your request.