NYXA.
PRIVACY · POLICY VERSION v1

privacy
policy.

Effective 2026-06-21 · Version 2026-06-21-v2

§1 Who we are

NYXA is a no-account product. You do not create a username or password. We generate your report from the birth details you enter, and we use your email only to deliver the report and support it.

NYXA ("we", "us", "our") is a personal-data-controlling sole proprietorship operated by Hong Chae-eun in the Republic of Korea.

NYXA offers an English-language self-discovery report based on Korean four-pillar (BaZi) day-pillar analysis. We do not collect data on behalf of any other organization.

  • Controller: Hong Chae-eun (NYXA)
  • Operating jurisdiction: Republic of Korea
  • EU representative(if the EU traffic >5% threshold is reached): TBD — designate an EU-based representative per GDPR Art. 27 before that threshold.

Privacy contact and rights-request channels are listed in §14.

§2 What personal data we collect

We only ask for what we need to compute and deliver your report. That’s it.

FieldRequired?Source
Email addressRequired to receive the reportYou enter it at checkout
Date of birthRequired to compute the day-pillarYou enter it on /input
Time of birthOptional (improves accuracy if known)You enter it on /input
Place of birth (city + country)Required to compute true solar timeYou select from a list on /input
Gender (binary, for archetype mapping only)Required (Female / Male)You select on /input
Payment metadata (last 4 of card, country, currency)Required to record the transactionOur payment processor provides this back to us; we do not see your full card number
Marketing consent (yes / no)OptionalYou check or leave unchecked at checkout
Consent record fields (ip_hash, ua_hash, policy_version, timestamps)Required to prove consent under GDPRComputed at the consent event
Coarse location (country / region / city)Used for currency display + fraud screeningDerived from your IP at request

Coarse location — country, region, and city — derived from your IP at the moment of request, used for currency display and fraud screening. We do not store the raw IP address long-term and we do not collect GPS.

We do not collect government IDs, photographs, social-media handles, address beyond country+city, phone numbers, payment-card numbers, or any sensitive-category data (health, religion, political affiliation, sexual orientation, biometrics, location tracking).

§3 Why we collect it

FieldPurpose
EmailDeliver the report link, send the magic-link to restore access, send the receipt, send marketing emails only if you opted in
Date / time / place of birthCompute the day-pillar (one of 60) via the Late-Zi method with true solar time correction
GenderSelect the matching archetype (Female / Male variant of the same day-pillar)
Payment metadataRecord the transaction, support refunds, satisfy U.S. IRS 7-year retention via our payment processor
Marketing consentLawful basis for sending the optional “new cycle launch” emails — never sent without your active opt-in
Consent recordProof, under GDPR Art. 7(1), that you gave active consent at a specific time

Your email address is used only to (a) send the link to your NYXA report, (b) send your purchase receipt, and (c) respond to support requests you send us. Optional marketing email is a separate, opt-in consent.

After checkout, if you opt in, we email a secure link to your full NYXA report so you can return to it from any device. This is a one-time transactional email and does not subscribe you to marketing.

We don’t profile you for ads.
We don’t build a shadow profile of your behavior.
We don’t cross-reference your report with anyone else’s data.

§4 Lawful basis

ActivityLawful basis (GDPR Art. 6)CCPA / PIPA equivalent
Computing and delivering the paid reportContract — Art. 6(1)(b)CCPA “business purpose”; PIPA Art. 15(1)(2) (contract performance)
Sending the receipt and restore-link emailsContract — Art. 6(1)(b)Same as above
Sending marketing emailsConsent — Art. 6(1)(a)CCPA opt-in; CAN-SPAM unsubscribe; PIPA Art. 22 separate consent
Storing transactional records for 7 yearsLegal obligation — Art. 6(1)(c) (tax / accounting)CCPA “compliance with law”; PIPA Art. 15(1)(3)
Operating fraud and abuse prevention (rate limits, signature verification)Legitimate interest — Art. 6(1)(f)CCPA “security”; PIPA Art. 15(1)(6)

You can refuse marketing emails and still get the report. They travel separately. Refusing the transactional consent (the “receive your report” checkbox) means we cannot deliver the product and the checkout is blocked — a lawful precondition, since the report cannot be delivered without it.

Full processing matrix (cross-jurisdiction):

ProcessingLawful basisLegal citeWithdraw
Generate report from birth dataContractGDPR Art. 6(1)(b) · PIPA §15(1)(4)Stop using service
Cross-border transfer (US processors)Contract + KR disclosureGDPR §46 SCC · PIPA §28-8 ②Stop using service
Anonymous analyticsLegitimate interest (cookie-less)GDPR Art. 6(1)(f); ePrivacy Art. 5(3) exemptEmail privacy@trynyxa.com
Marketing emailConsentGDPR Art. 6(1)(a) · CAN-SPAM · PIPA §22-2One-click unsubscribe
EU/UK 14-day waiverExpress consentEU Directive 2011/83/EU Art. 16(m)Per-purchase, no retroactive
Privacy request auditLegitimate interest (legal claims defense)GDPR Art. 17(3)(e); §5(2)None (5y retention required)
Tax recordsLegal obligationIRS §6001 · 한국 전자상거래법 §11None (7y retention required)

§5 How long we keep it

Data categoryRetentionReason
Entitlement record (email + variant_id + paid_at + ls_order_id)3 years after the last access, then minimized to a tax-only recordCustomer-support and re-delivery; GDPR data minimization
Tax-relevant transaction record (transactions.csv: order id, hashed email, country, amounts, status)7 years (U.S. IRS retention)Legal obligation; the raw email is replaced with sha256(email + IDENTITY_SALT) once the entitlement record is minimized
Marketing-consent record (timestamp, policy_version, ip_hash, ua_hash)3 years while consent is active; 30 days after opt-out, then deletedGDPR Art. 7(1) proof window; CAN-SPAM evidence
Magic-link restore tokens1 hour (key TTL); single-use enforcedSecurity
Webhook event-id dedupe records7 days (covers the payment processor's webhook retry window)Idempotency only
Analytics events in PostHog (no email until checkout)1 yearFunnel analysis; aggregated retention only
Privacy request log (request_id, hashed email, request_type, received_at / responded_at / resolved_at, resolution)5 years from receiptGDPR Art. 17(3)(b)(e) accountability + Art. 5(2); CCPA §1798.130(a)(5) record-keeping; PIPA Art. 15-2 ② 처리 활동 기록. Stored as sha256(email + IDENTITY_SALT) only — raw email never retained. Survives deletion of your account-level data so we can prove the request was honored

Free report: birth details and email retained for 12 months from last activity, then purged. Paid report: retained for 24 months from purchase so you can restore access by email link, then purged unless you have requested earlier deletion.

Logs that may incidentally contain personal data (IP, user-agent) are kept by Vercel for 30 daysper Vercel’s retention default and are never copied into NYXA-owned storage.

§6 Who we share it with

We share data only with the processors listed below. Each is a “data processor” under GDPR / a “service provider” under CCPA. There is no data-sale code path in NYXA.

ProcessorRoleData they receiveLocationTransfer mechanism
Third-party payment processor (Merchant of Record)Merchant of Record — acts as Merchant of Record for all NYXA purchases. Payment processing, tax calculation and remittance, receipt issuance, refunds and chargebacks.Email, name (if provided), billing country, card details, order amountU.S.EU SCC / DPF — via our payment processor’s DPA
Resend (Plus Five Five, Inc.)Transactional + opt-in marketing email deliveryEmail, message metadata, message contentU.S.EU SCC (Commission Decision 2021/914) + UK Addendum
Vercel (Vercel, Inc.)Hosting, edge runtime, request logsRequest data (IP, user-agent, route), no in-app personal data unless logged by an application bugU.S. (edge nodes worldwide)EU SCC + EU-U.S. DPF certification
Upstash (Upstash, Inc.)Entitlement + consent + rate-limit storage (Redis)Email-keyed entitlement, hashed-email-keyed consent, dedupe markersEU region selectable (Frankfurt)EU SCC; see Upstash DPA
PostHog (PostHog, Inc.)Product analytics, EU-hosted CloudAnonymous funnel events; identified-by-email only after checkout if you allowed marketingEU (EU Cloud)Data stays in EU; controller-to-processor agreement

NYXA does not see or store your full card number; only the last four digits and card brand are returned to us for receipt display. our payment processor’s own privacy terms also apply to the payment step.

Payment processor boundary (Merchant of Record scope, summary):

  • Our payment processor handles: sales-tax / VAT / GST calculation, collection, and filing in 135+ jurisdictions; card processing; PCI compliance; refund mechanics; chargeback defense.
  • NYXA handles: consent collection and disclosure, content delivery, the refund decision under NYXA’s posted policy, delete/export/withdraw endpoints, this Privacy Policy.

Upstash advisory (2026-05 research): Upstash is a Delaware C-Corp. Even with EU region selected, personal data stored there is subject to the U.S. CLOUD Act. We mitigate by storing operational records keyed on sha256(email + IDENTITY_SALT) (not raw email) and by minimizing entitlement records 3 years after last access. EU traffic crossing a 5% threshold will trigger a separate review with a qualified GDPR adviser, which may include migrating EU entitlement storage to an EU-headquartered provider.

§7 International transfers

NYXA is operated from the Republic of Korea. Your data may be transferred to and processed in:

  • The United States — our payment processor, Resend, Vercel, Upstash (corporate seat). Transfer relies on (a) the EU-U.S. Data Privacy Framework where the processor is DPF-certified (Vercel), and (b) Standard Contractual Clauses (Commission Decision 2021/914) plus the UK International Data Transfer Addendum for the remainder.
  • The European Union — Upstash (Frankfurt region), PostHog (EU Cloud). No further transfer required for EU/EEA data subjects.

For users covered by the Republic of Korea’s PIPA, the cross-border transfer is disclosed and consented to at the moment you accept this Privacy Policy (PIPA Art. 17(3) and Art. 28-8).

§8 Your rights

You have these rights regardless of jurisdiction (we apply the strongest of CCPA / GDPR / PIPA):

RightHow to exerciseResponse window
Access / portabilitySubmit a request via the self-service form at /privacy/request, or call /api/privacy/export. We return a JSON of your records30 days (45 days for CCPA, we use the shorter)
Deletion / erasureSubmit a request via the self-service form at /privacy/request, or call /api/privacy/delete. We purge Upstash + PostHog. Two exceptions, both noted in the deletion confirmation: (a) tax records keyed by sha256(email) are kept 7 years per IRS legal obligation; (b) a hashed audit record of the request itself (request_id, sha256(email), request_type, dates, resolution — no raw PII) is retained for 5 years to demonstrate compliance under GDPR Art. 17(3)(b)(e) + Art. 5(2) and to defend against claims30 days
Correction / rectificationSubmit a request via the self-service form at /privacy/request — most fields you can also re-enter at /input and pay for a new report; the old one is then minimized30 days
Withdraw marketing consentClick unsubscribe in any marketing email, or call /api/privacy/withdraw. Effective immediately; we delete the marketing-consent record within 30 daysImmediate
Object to processing for legitimate-interest basisSubmit a request via the self-service form at /privacy/request with the reason30 days
Right to opt-out of “sale” or “sharing” (CCPA / CPRA)NYXA does not sell or share personal data. The right is honored automatically — you cannot opt out of something that doesn't happen, but we will confirm this in writing on requestN/A
Right not to be subject to automated decision-making with legal effectsThe report is computed by deterministic public-method algorithm (Late-Zi day-pillar). It is not a decision with legal effects under GDPR Art. 22Not triggered
Lodge a complaint with a supervisory authorityEU/EEA: your national DPA; UK: ICO; Korea: Personal Information Protection Commission (PIPC); California: California Attorney General

We do not charge a fee for handling rights requests except where they are manifestly unfounded or excessive, per GDPR Art. 12(5).

California residents have the right under the California Consumer Privacy Act (as amended by the CPRA) to know, delete, correct, and limit use of their personal information, and to not be discriminated against for exercising these rights. NYXA does not sell or share personal information for cross-context behavioral advertising. To exercise these rights, submit a request via the self-service form.

§9 Security

  • Webhook signature verification (HMAC-SHA256 with timing-safe compare on the payment processor's webhooks).
  • Hashed-email keying for non-essential operational stores (sha256(email + IDENTITY_SALT)).
  • Vercel: SOC2 Type 2 (third-party audited annually).
  • Upstash: SOC2 (Pro+); EU region.
  • Rate limiting on abuseable endpoints.
  • Encryption at rest by every processor; encryption in transit end-to-end (HTTPS / TLS 1.2+).
  • No raw payment-card data is processed or stored by NYXA — that surface is wholly within the payment processor’s PCI-DSS environment.

§10 Children's data

NYXA is intended for users 16 years of age or older in the EU/EEA (per GDPR Art. 8 default age of digital consent) and 13 years of age or older in the United States (per COPPA). If we learn we have collected personal data from a child below the applicable threshold without verified parental consent, we delete it. Report via the self-service form.

§11 Cookies and similar technologies

NYXA uses only the following first-party browser storage:

  • localStorage— birth-data form input persistence, last-visited variant, “have you seen the splash” flag. No identifiers.
  • sessionStorage — UTM source for the active session (cleared on tab close).

We do not use cross-site tracking cookies. PostHog uses a first-party cookie scoped to trynyxa.com only.

§12 Changes to this policy

When this policy changes materially we bump the policy_version (e.g. 2026-06-15-v12026-08-15-v2) and require re-consent at the next interaction.

We post the prior version for 12 months at /privacy/v1, /privacy/v2, etc.

§13 Contact

For any privacy question, request, or complaint, submit a request via the self-service form. We acknowledge within 5 business days and resolve within the timelines in §8.

Korean residents may also contact the Personal Information Protection Commission (privacy.go.kr / hotline 182). EU/EEA residents may contact their national supervisory authority. California residents may contact the California Attorney General (oag.ca.gov/privacy).

§14 Your privacy rights — self-service & 24h SLA

You have the right to:

  • Access your personal data (GDPR Art. 15)
  • Request deletion (GDPR Art. 17 / CCPA §1798.105)
  • Request data export (GDPR Art. 20)
  • Correct inaccurate data, e.g. birth details or email (GDPR Art. 16 / LGPD Art. 18)
  • Withdraw consent at any time (GDPR Art. 7(3))
  • Lodge a complaint with your local data protection authority

Response SLA: We acknowledge requests within 24 hours and resolve within 30 days (max 60 days for complex cases per GDPR Art. 12(3)).

How to submit: Use the self-service form for access, deletion, export, or marketing-consent withdrawal. Rectification (correcting inaccurate birth details or email) is handled manually — contact privacy@trynyxa.com. Other manual requests may also be sent to the same address.

ENCRYPTED · NEVER SOLD