Last updated: June 7, 2026
Privacy Policy
This notice is provided pursuant to articles 13 and 14 of Regulation (EU) 2016/679 (the "GDPR") and describes how the personal data of users of the Impronta platform (https://www.impronta.life) is processed.
1. Data controller
Visualsense — Via Santa Maria di Porta 27 — 03037 Pontecorvo (FR), Italia
[P.IVA / C.F. — DA COMPLETARE]
Email: info@visualsense.it
The Controller has not appointed a Data Protection Officer (DPO), as the legal conditions requiring one are not met.
2. Categories of data processed
a) Registration and account data
Email address, password (stored exclusively as a cryptographic hash, never in plain text), display name (alias), preferred language. In case of Google sign-in: Google account identifier, email and name provided by Google.
b) Birth data
Date, time and place of birth, voluntarily provided by the user for the calculation of the Human Design chart. This data is the core of the Service: without it the calculation is not possible. The place of birth is converted into geographic coordinates through an external geocoding service (see §6).
c) Profile data and content
Profile photo and cover image, biography, posts, comments, reactions, private messages exchanged with other users, readings saved and linked to the account.
d) Payment data
Payments are handled entirely by PayPal: the Controller does not receive or store card data. The Controller processes only: transaction/subscription identifier, payment status, subscribed plan and related dates.
e) Technical and usage data
IP address, technical and security logs, session cookie data, essential device/browser information needed to provide the Service and prevent abuse (e.g. anti-spam limits).
f) Cookies and similar technologies
Please refer to the Cookie Policy.
3. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Provision of the Service: account creation, chart calculation, readings, transits, yoga, community, messaging | a, b, c | Performance of a contract (art. 6.1.b GDPR) |
| Generation of texts through artificial intelligence (transits, readings) | b, display name and energetic configuration (see §6) | Performance of a contract (art. 6.1.b) |
| Management of subscriptions and payments | d | Performance of a contract (art. 6.1.b); legal obligations (art. 6.1.c) for tax aspects |
| Transactional emails: address verification, password recovery, service notifications | a | Performance of a contract (art. 6.1.b) |
| Security, prevention of abuse, spam and fraud; content moderation (including retention of flagged messages) | c, e | Legitimate interest (art. 6.1.f) in the security and integrity of the Service |
| Usage statistics through Google Analytics (if active) | measurement cookies | Consent (art. 6.1.a), revocable at any time |
| Compliance with legal obligations and defence of rights | all, to the extent necessary | Legal obligation (art. 6.1.c); legitimate interest (art. 6.1.f) |
Providing the data under letters a) and b) is necessary for the provision of the Service: failure to provide it makes registration or chart calculation impossible. Any other data is provided on a voluntary basis.
4. Special nature of birth data
Date, time and place of birth do not fall within the "special categories" under art. 9 GDPR; however, the Controller recognises their personal and confidential nature and processes them with enhanced protection measures, limiting their use solely to the calculation and content-generation purposes of the Service. Public profile views in the community do not expose raw birth data, except where the user chooses to share it.
4.1 Sharing a reading via link
Every reading has a unique, unguessable web address. That address is public: anyone who has it can open the reading and see the birth data it contains — name, date, time and place — without registering or signing in.
The link does not expire and cannot be revoked: it is meant to be shared, and once given to someone there is no way to prevent its use. Whoever passes it on is responsible for that choice.
Reading pages are excluded from search engine indexing and do not appear in the sitemap, but this does not make them private: it protects them from being found, not from being shared.
The only way to make a link inaccessible is to delete the reading from your archive. Deletion is immediate and permanent: from that moment the address no longer responds.
5. Processing methods and security measures
Processing is carried out by electronic means, in accordance with the principles of data minimisation and privacy by design. Measures adopted include: encrypted connections (HTTPS), passwords stored only as cryptographic hashes, session cookies with HttpOnly and SameSite attributes, CSRF protection on forms, anti-abuse limits, upload checks, privilege separation in the administration area, security logging.
6. Recipients, processors and third parties
Data may be disclosed to the following categories of parties, within the limits of the stated purposes:
| Party | Role | Data / purpose | Location |
|---|---|---|---|
| Aruba S.p.A. | Processor (hosting) | All data: infrastructure hosting, database, sending of service emails via SMTP | Italy (EU) |
| PayPal | Independent controller | Payment data for subscriptions; PayPal processes data under its own privacy policy | EU/USA |
| Google (Sign-In) | Independent controller | Authentication via Google account, if chosen by the user | EU/USA |
| OpenAI | Processor (API) | AI text generation: the display name (if present) and the data of the energetic configuration/transits are sent; never email, passwords or payment data | USA |
| DeepSeek | Processor (API) | As above, for AI text generation | China |
| OpenStreetMap / Nominatim | External provider | Geocoding of the place of birth (only the place string is sent, without user identifiers) | EU |
| Google Analytics | Processor (if active) | Aggregate usage statistics, only with prior consent, with anonymised IP | EU/USA |
Data is not disseminated or sold to third parties. It may be disclosed to competent authorities where required by law.
7. Transfers outside the EU
Some providers listed in §6 are based outside the European Union:
- USA (OpenAI, Google, PayPal): transfers take place on the basis of the Standard Contractual Clauses adopted by the European Commission and/or, where applicable, the EU-U.S. Data Privacy Framework;
- China (DeepSeek): the transfer takes place on the basis of the Standard Contractual Clauses and with minimisation measures: only the data strictly necessary for text generation (energetic configuration, transits, display name where applicable) is sent to the AI systems, without email, credentials or payment data.
Users may request a copy of the safeguards applied by writing to info@visualsense.it.
8. Retention periods
| Data | Retention |
|---|---|
| Account, birth, profile, content and reading data | For the entire duration of the account; upon account deletion, data is erased or anonymised within 30 days, subject to the following |
| Messages flagged by anti-abuse systems | Retained for moderation purposes and as evidence of possible unlawful acts, for up to 12 months from flagging or until the conclusion of any proceedings |
| Transaction and subscription data | 10 years, for tax and accounting obligations |
| Technical and security logs | Up to 12 months |
| Backups | Data may persist in backups for their technical rotation cycle, after which it is overwritten |
9. Rights of the data subject
Pursuant to articles 15-22 GDPR, the user has the right to: access their data; obtain its rectification or erasure; obtain restriction of processing; object to processing based on legitimate interest; receive their data in a structured, commonly used format (portability); withdraw any consent given at any time, without affecting the lawfulness of processing prior to withdrawal.
Requests may be sent to info@visualsense.it. A response will be provided within one month, extendable in the cases provided by law. Account deletion is also available independently in the profile settings.
10. Complaints to the supervisory authority
The user has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, www.garanteprivacy.it) or with the supervisory authority of their EU country of residence.
11. Minors
The Service is reserved for persons aged 16 or over. The Controller does not knowingly collect data from children under 16; should it become aware of processing relating to children under that age, it will delete the relevant data. Parents or guardians may report any such cases to info@visualsense.it.
12. Automated decision-making
The Service does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect the user (art. 22 GDPR). AI-generated content is purely descriptive and informational in nature; automated anti-spam moderation systems merely hide potentially abusive content, with the possibility of human review.
13. Changes to this notice
This notice may be updated to reflect changes to the Service or to legislation. The date of the last update is shown at the top of the page; substantial changes will be communicated through the Service.