privacy
policy.
§1 Who we are
NYXA is a no-account product. You do not create a username or password. We generate your report from the birth details you enter, and we use your email only to deliver the report and support it.
NYXA ("we", "us", "our") is a personal-data-controlling sole proprietorship operated by Hong Chae-eun in the Republic of Korea.
NYXA offers an English-language self-discovery report based on Korean four-pillar (BaZi) day-pillar analysis. We do not collect data on behalf of any other organization.
- Controller: Hong Chae-eun (NYXA)
- Operating jurisdiction: Republic of Korea
- EU representative(if the EU traffic >5% threshold is reached): TBD — designate an EU-based representative per GDPR Art. 27 before that threshold.
Privacy contact and rights-request channels are listed in §14.
§2 What personal data we collect
We only ask for what we need to compute and deliver your report. That’s it.
| Field | Required? | Source |
|---|---|---|
| Email address | Required to receive the report | You enter it at checkout |
| Date of birth | Required to compute the day-pillar | You enter it on /input |
| Time of birth | Optional (improves accuracy if known) | You enter it on /input |
| Place of birth (city + country) | Required to compute true solar time | You select from a list on /input |
| Gender (binary, for archetype mapping only) | Required (Female / Male) | You select on /input |
| Payment metadata (last 4 of card, country, currency) | Required to record the transaction | Our payment processor provides this back to us; we do not see your full card number |
| Marketing consent (yes / no) | Optional | You check or leave unchecked at checkout |
| Consent record fields (ip_hash, ua_hash, policy_version, timestamps) | Required to prove consent under GDPR | Computed at the consent event |
| Coarse location (country / region / city) | Used for currency display + fraud screening | Derived from your IP at request |
Coarse location — country, region, and city — derived from your IP at the moment of request, used for currency display and fraud screening. We do not store the raw IP address long-term and we do not collect GPS.
We do not collect government IDs, photographs, social-media handles, address beyond country+city, phone numbers, payment-card numbers, or any sensitive-category data (health, religion, political affiliation, sexual orientation, biometrics, location tracking).
§3 Why we collect it
| Field | Purpose |
|---|---|
| Deliver the report link, send the magic-link to restore access, send the receipt, send marketing emails only if you opted in | |
| Date / time / place of birth | Compute the day-pillar (one of 60) via the Late-Zi method with true solar time correction |
| Gender | Select the matching archetype (Female / Male variant of the same day-pillar) |
| Payment metadata | Record the transaction, support refunds, satisfy U.S. IRS 7-year retention via our payment processor |
| Marketing consent | Lawful basis for sending the optional “new cycle launch” emails — never sent without your active opt-in |
| Consent record | Proof, under GDPR Art. 7(1), that you gave active consent at a specific time |
Your email address is used only to (a) send the link to your NYXA report, (b) send your purchase receipt, and (c) respond to support requests you send us. Optional marketing email is a separate, opt-in consent.
After checkout, if you opt in, we email a secure link to your full NYXA report so you can return to it from any device. This is a one-time transactional email and does not subscribe you to marketing.
We don’t profile you for ads.
We don’t build a shadow profile of your behavior.
We don’t cross-reference your report with anyone else’s data.
§4 Lawful basis
| Activity | Lawful basis (GDPR Art. 6) | CCPA / PIPA equivalent |
|---|---|---|
| Computing and delivering the paid report | Contract — Art. 6(1)(b) | CCPA “business purpose”; PIPA Art. 15(1)(2) (contract performance) |
| Sending the receipt and restore-link emails | Contract — Art. 6(1)(b) | Same as above |
| Sending marketing emails | Consent — Art. 6(1)(a) | CCPA opt-in; CAN-SPAM unsubscribe; PIPA Art. 22 separate consent |
| Storing transactional records for 7 years | Legal obligation — Art. 6(1)(c) (tax / accounting) | CCPA “compliance with law”; PIPA Art. 15(1)(3) |
| Operating fraud and abuse prevention (rate limits, signature verification) | Legitimate interest — Art. 6(1)(f) | CCPA “security”; PIPA Art. 15(1)(6) |
You can refuse marketing emails and still get the report. They travel separately. Refusing the transactional consent (the “receive your report” checkbox) means we cannot deliver the product and the checkout is blocked — a lawful precondition, since the report cannot be delivered without it.
Full processing matrix (cross-jurisdiction):
| Processing | Lawful basis | Legal cite | Withdraw |
|---|---|---|---|
| Generate report from birth data | Contract | GDPR Art. 6(1)(b) · PIPA §15(1)(4) | Stop using service |
| Cross-border transfer (US processors) | Contract + KR disclosure | GDPR §46 SCC · PIPA §28-8 ② | Stop using service |
| Anonymous analytics | Legitimate interest (cookie-less) | GDPR Art. 6(1)(f); ePrivacy Art. 5(3) exempt | Email privacy@trynyxa.com |
| Marketing email | Consent | GDPR Art. 6(1)(a) · CAN-SPAM · PIPA §22-2 | One-click unsubscribe |
| EU/UK 14-day waiver | Express consent | EU Directive 2011/83/EU Art. 16(m) | Per-purchase, no retroactive |
| Privacy request audit | Legitimate interest (legal claims defense) | GDPR Art. 17(3)(e); §5(2) | None (5y retention required) |
| Tax records | Legal obligation | IRS §6001 · 한국 전자상거래법 §11 | None (7y retention required) |
§5 How long we keep it
| Data category | Retention | Reason |
|---|---|---|
| Entitlement record (email + variant_id + paid_at + ls_order_id) | 3 years after the last access, then minimized to a tax-only record | Customer-support and re-delivery; GDPR data minimization |
| Tax-relevant transaction record (transactions.csv: order id, hashed email, country, amounts, status) | 7 years (U.S. IRS retention) | Legal obligation; the raw email is replaced with sha256(email + IDENTITY_SALT) once the entitlement record is minimized |
| Marketing-consent record (timestamp, policy_version, ip_hash, ua_hash) | 3 years while consent is active; 30 days after opt-out, then deleted | GDPR Art. 7(1) proof window; CAN-SPAM evidence |
| Magic-link restore tokens | 1 hour (key TTL); single-use enforced | Security |
| Webhook event-id dedupe records | 7 days (covers the payment processor's webhook retry window) | Idempotency only |
| Analytics events in PostHog (no email until checkout) | 1 year | Funnel analysis; aggregated retention only |
| Privacy request log (request_id, hashed email, request_type, received_at / responded_at / resolved_at, resolution) | 5 years from receipt | GDPR Art. 17(3)(b)(e) accountability + Art. 5(2); CCPA §1798.130(a)(5) record-keeping; PIPA Art. 15-2 ② 처리 활동 기록. Stored as sha256(email + IDENTITY_SALT) only — raw email never retained. Survives deletion of your account-level data so we can prove the request was honored |
Free report: birth details and email retained for 12 months from last activity, then purged. Paid report: retained for 24 months from purchase so you can restore access by email link, then purged unless you have requested earlier deletion.
Logs that may incidentally contain personal data (IP, user-agent) are kept by Vercel for 30 daysper Vercel’s retention default and are never copied into NYXA-owned storage.
§6 Who we share it with
We share data only with the processors listed below. Each is a “data processor” under GDPR / a “service provider” under CCPA. There is no data-sale code path in NYXA.
| Processor | Role | Data they receive | Location | Transfer mechanism |
|---|---|---|---|---|
| Third-party payment processor (Merchant of Record) | Merchant of Record — acts as Merchant of Record for all NYXA purchases. Payment processing, tax calculation and remittance, receipt issuance, refunds and chargebacks. | Email, name (if provided), billing country, card details, order amount | U.S. | EU SCC / DPF — via our payment processor’s DPA |
| Resend (Plus Five Five, Inc.) | Transactional + opt-in marketing email delivery | Email, message metadata, message content | U.S. | EU SCC (Commission Decision 2021/914) + UK Addendum |
| Vercel (Vercel, Inc.) | Hosting, edge runtime, request logs | Request data (IP, user-agent, route), no in-app personal data unless logged by an application bug | U.S. (edge nodes worldwide) | EU SCC + EU-U.S. DPF certification |
| Upstash (Upstash, Inc.) | Entitlement + consent + rate-limit storage (Redis) | Email-keyed entitlement, hashed-email-keyed consent, dedupe markers | EU region selectable (Frankfurt) | EU SCC; see Upstash DPA |
| PostHog (PostHog, Inc.) | Product analytics, EU-hosted Cloud | Anonymous funnel events; identified-by-email only after checkout if you allowed marketing | EU (EU Cloud) | Data stays in EU; controller-to-processor agreement |
NYXA does not see or store your full card number; only the last four digits and card brand are returned to us for receipt display. our payment processor’s own privacy terms also apply to the payment step.
Payment processor boundary (Merchant of Record scope, summary):
- Our payment processor handles: sales-tax / VAT / GST calculation, collection, and filing in 135+ jurisdictions; card processing; PCI compliance; refund mechanics; chargeback defense.
- NYXA handles: consent collection and disclosure, content delivery, the refund decision under NYXA’s posted policy, delete/export/withdraw endpoints, this Privacy Policy.
Upstash advisory (2026-05 research): Upstash is a Delaware C-Corp. Even with EU region selected, personal data stored there is subject to the U.S. CLOUD Act. We mitigate by storing operational records keyed on sha256(email + IDENTITY_SALT) (not raw email) and by minimizing entitlement records 3 years after last access. EU traffic crossing a 5% threshold will trigger a separate review with a qualified GDPR adviser, which may include migrating EU entitlement storage to an EU-headquartered provider.
§7 International transfers
NYXA is operated from the Republic of Korea. Your data may be transferred to and processed in:
- The United States — our payment processor, Resend, Vercel, Upstash (corporate seat). Transfer relies on (a) the EU-U.S. Data Privacy Framework where the processor is DPF-certified (Vercel), and (b) Standard Contractual Clauses (Commission Decision 2021/914) plus the UK International Data Transfer Addendum for the remainder.
- The European Union — Upstash (Frankfurt region), PostHog (EU Cloud). No further transfer required for EU/EEA data subjects.
For users covered by the Republic of Korea’s PIPA, the cross-border transfer is disclosed and consented to at the moment you accept this Privacy Policy (PIPA Art. 17(3) and Art. 28-8).
§8 Your rights
You have these rights regardless of jurisdiction (we apply the strongest of CCPA / GDPR / PIPA):
| Right | How to exercise | Response window |
|---|---|---|
| Access / portability | Submit a request via the self-service form at /privacy/request, or call /api/privacy/export. We return a JSON of your records | 30 days (45 days for CCPA, we use the shorter) |
| Deletion / erasure | Submit a request via the self-service form at /privacy/request, or call /api/privacy/delete. We purge Upstash + PostHog. Two exceptions, both noted in the deletion confirmation: (a) tax records keyed by sha256(email) are kept 7 years per IRS legal obligation; (b) a hashed audit record of the request itself (request_id, sha256(email), request_type, dates, resolution — no raw PII) is retained for 5 years to demonstrate compliance under GDPR Art. 17(3)(b)(e) + Art. 5(2) and to defend against claims | 30 days |
| Correction / rectification | Submit a request via the self-service form at /privacy/request — most fields you can also re-enter at /input and pay for a new report; the old one is then minimized | 30 days |
| Withdraw marketing consent | Click unsubscribe in any marketing email, or call /api/privacy/withdraw. Effective immediately; we delete the marketing-consent record within 30 days | Immediate |
| Object to processing for legitimate-interest basis | Submit a request via the self-service form at /privacy/request with the reason | 30 days |
| Right to opt-out of “sale” or “sharing” (CCPA / CPRA) | NYXA does not sell or share personal data. The right is honored automatically — you cannot opt out of something that doesn't happen, but we will confirm this in writing on request | N/A |
| Right not to be subject to automated decision-making with legal effects | The report is computed by deterministic public-method algorithm (Late-Zi day-pillar). It is not a decision with legal effects under GDPR Art. 22 | Not triggered |
| Lodge a complaint with a supervisory authority | EU/EEA: your national DPA; UK: ICO; Korea: Personal Information Protection Commission (PIPC); California: California Attorney General | — |
We do not charge a fee for handling rights requests except where they are manifestly unfounded or excessive, per GDPR Art. 12(5).
California residents have the right under the California Consumer Privacy Act (as amended by the CPRA) to know, delete, correct, and limit use of their personal information, and to not be discriminated against for exercising these rights. NYXA does not sell or share personal information for cross-context behavioral advertising. To exercise these rights, submit a request via the self-service form.
§9 Security
- Webhook signature verification (HMAC-SHA256 with timing-safe compare on the payment processor's webhooks).
- Hashed-email keying for non-essential operational stores (
sha256(email + IDENTITY_SALT)). - Vercel: SOC2 Type 2 (third-party audited annually).
- Upstash: SOC2 (Pro+); EU region.
- Rate limiting on abuseable endpoints.
- Encryption at rest by every processor; encryption in transit end-to-end (HTTPS / TLS 1.2+).
- No raw payment-card data is processed or stored by NYXA — that surface is wholly within the payment processor’s PCI-DSS environment.
§10 Children's data
NYXA is intended for users 16 years of age or older in the EU/EEA (per GDPR Art. 8 default age of digital consent) and 13 years of age or older in the United States (per COPPA). If we learn we have collected personal data from a child below the applicable threshold without verified parental consent, we delete it. Report via the self-service form.
§11 Cookies and similar technologies
NYXA uses only the following first-party browser storage:
localStorage— birth-data form input persistence, last-visited variant, “have you seen the splash” flag. No identifiers.sessionStorage— UTM source for the active session (cleared on tab close).
We do not use cross-site tracking cookies. PostHog uses a first-party cookie scoped to trynyxa.com only.
§12 Changes to this policy
When this policy changes materially we bump the policy_version (e.g. 2026-06-15-v1 → 2026-08-15-v2) and require re-consent at the next interaction.
We post the prior version for 12 months at /privacy/v1, /privacy/v2, etc.
§13 Contact
For any privacy question, request, or complaint, submit a request via the self-service form. We acknowledge within 5 business days and resolve within the timelines in §8.
Korean residents may also contact the Personal Information Protection Commission (privacy.go.kr / hotline 182). EU/EEA residents may contact their national supervisory authority. California residents may contact the California Attorney General (oag.ca.gov/privacy).
§14 Your privacy rights — self-service & 24h SLA
You have the right to:
- Access your personal data (GDPR Art. 15)
- Request deletion (GDPR Art. 17 / CCPA §1798.105)
- Request data export (GDPR Art. 20)
- Correct inaccurate data, e.g. birth details or email (GDPR Art. 16 / LGPD Art. 18)
- Withdraw consent at any time (GDPR Art. 7(3))
- Lodge a complaint with your local data protection authority
Response SLA: We acknowledge requests within 24 hours and resolve within 30 days (max 60 days for complex cases per GDPR Art. 12(3)).
How to submit: Use the self-service form for access, deletion, export, or marketing-consent withdrawal. Rectification (correcting inaccurate birth details or email) is handled manually — contact privacy@trynyxa.com. Other manual requests may also be sent to the same address.