Privacy policy

Astro Secrets - operated by BES Consulting SASU (trade name "Astro Secrets")
Address 65 Rue de la Croix, 92000 Nanterre, France
Contact privacy : contact@astro-secrets.com 
Last update: 23/11/2025

1) Who processes your data?

  • Data controller BES Consulting SASU, trading as "Astro Secrets", 65 Rue de la Croix, 92000 Nanterre, France (918 019 035 R.C.S. Nanterre).

  • Compliance with RGPD (EU), UK GDPR and nLPD (Switzerland)with useful information for CCPA/CPRA (California), PIPEDA (Canada) and LGPD (Brazil).

2) What this policy covers

This policy applies to your use of astro-secrets.com and all our services: online store, payment, automated generation of personalized content (astrological themes, synastries, horoscopes), Astrobook production/shipping, customer service, emailing, audience measurement and security.

3) Data we collect

3.1 Information you provide

  • Identity & contact Last name, first name, email, billing and delivery addresses, telephone (optional).

  • Account login (hashed password), preferences.

  • Order & Service order details, messages and attachments.

  • Astro data date, time and place of birth; surnames/first names of persons concerned (especially in synastry); free fields (optional).

  • Marketing consents and preferences.

3.2 Automatically collected data

  • Technology & safety IP address, user-agent, session identifiers, event logs.

  • Navigation : pages consulted, contents of basket, route taken (via cookies/trackers - see §10).

  • Payment Transaction status and identifiers (card data is processed by the payment service provider, not by us).

3.3 Data received from third parties

  • Payment confirmations and metadata (Stripe).

  • Printing/shipping Astrobooks manufacturing and shipping status (Prodigi).

  • Emailing & hosting Technical information required for shipment and availability.

Sensitive note (RGPD art. 9) the astro data may, by inference, reveal sensitive information. We do not use them exclusively to provide the requested service, on the basis of your explicit consent.

4) Purpose & legal basis

  • Contract performance account creation/management, order processing and delivery (digital and physical), billing, after-sales service.

  • Content generation automated creation of themes/synastries/horoscopes from astro data (consent non-decisional profiling).

  • Payment & compliance transmission to the payment processor, accounting and tax obligations (legal obligation).

  • Security & anti-fraud abuse prevention, incident management (legitimate interest).

  • Audience measurement aggregate statistics (legitimate interest or consent depending on tool and settings).

  • Marketing : offers/newsletters only if consent.

  • Service improvement testing, debugging, UX optimization (legitimate interest).

  • Litigation & requests to authorities compliance with legal obligations, defending our rights (legal obligation / legitimate interest).

5) Profiling & automated decisions

We make a non-decisional profiling (automatic generation of personalized content).
No decision producing legal effects or significantly affecting you is not taken. only by algorithm. You can request a human interventiongive your point of view or contest : privacy@astro-secrets.com.

6) Recipients & subcontractors

We share data with service providers acting on our instructions and on our behalf (subcontracting agreements):

  • Hosting/SMTP Hostinger (EU).

  • Payment Stripe (EU/US, depending on configuration).

  • Printing & fulfilment our dedicated presetter.

  • Emailing SMTP/transactional service.

  • Analytics Matomo (self-hosted) or equivalent configured in compliance.

  • Legal assistance & authorities If required by law.

7) International transfers

Where data is transferred outside the EU/EEA/UK/Switzerland (e.g. to the UK or USA via our service providers):

  • to countries benefiting from suitability decision or

  • on the basis of Standard Contractual Clauses (EU) / UK IDTAwith additional measures (encryption, minimization, access control).
    Information on available warranties on request : privacy@astro-secrets.com.

8) Shelf life

  • Account & orders duration of relationship + legal obligations (French accounting : 10 years).

  • Astro data : 24 months after delivery (for re-emission/regeneration), then deletion or anonymization.

  • SERVICE 24 months after file closure.

  • Security logs 6 to 12 months.

  • Prospecting until consent is withdrawn or 3 years of inactivity.

  • Cookies/trackers See §10.

9) Your rights

Depending on your country, you have the right toaccess, correction, deletion, limitation, opposition, portabilityand withdrawal of consent (without retroactive effect).

  • EU/EEA/UK/Switzerland same rights; you can define post-mortem directives (according to local laws).

  • California (CCPA/CPRA) access, deletion, opt-out sale/sharelimitation of sensitive data, non-discrimination.

  • Canada (PIPEDA) access, rectification.

  • Brazil (LGPD) : confirmation, access, correction, anonymization, portability, deletion, information on sharing, withdrawal of consent.

Exercising your rights : privacy@astro-secrets.com (identity verification may be required).
Claim :

  • FR : CNIL3 Place de Fontenoy, 75007 Paris - cnil.fr

  • UK : ICO - ico.org.uk

  • CH: Federal Commissioner (FDPIC) - edoeb.admin.ch

  • Other countries: competent local authority.

10) Cookies & tracers

  • Essentials (mandatory): session, shopping cart, security, consent management.

  • Audience measurement : configured to minimize collection ; consent required if not exempt.

  • Marketing : deposited only in case of consent.
    Your choice is collected via a banner offering Accept all / Reject all / Customize and can be modified at any time via the link Manage my cookies.

11) Minors

The site is not intended for people of under 16. If the data of a minor has been provided without parental consent, please contact us for deletion: privacy@astro-secrets.com.

12) Safety

Reasonable technical and organizational measures: TLS encryption, access control, minimization, backups and logging. In the event of a data breach, we will notify the relevant authorities and/or individuals if required by law.

13) Communications & marketing

  • Transactional e-mails Sending necessary for execution (confirmation, follow-up, incidents).

  • Marketing emails only in case of consent unsubscribe via the link in each message.

14) Third-party links and services

Third-party sites or services accessible from ours have their own policies. We are not responsible for their practices or content.

15) Modifications

All updates will be published with a new effective date. Use of the site after publication constitutes acceptance. In the event of significant changes, we may inform active accounts by email.

16) Contact