Inner Blueprint

Privacy Policy

In accordance with the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).

1. Controller

LUXEN GmbH, Otterthal 6, 2880 Otterthal, Austria, is the controller responsible for the processing of your personal data on this website.
Contact for privacy matters: office@the-inner-blueprint.com. We have not appointed a Data Protection Officer, as none is required.

2. What we collect and why

a) When you order a report

To calculate and deliver your personalized report we process the data you enter: first name, email address, date of birth, time of birth and place of birth.

PurposeCalculating your Human Design chart and generating & delivering your personalized report.
Legal basisArt. 6(1)(b) GDPR — performance of the contract you entered into.
RetentionThe processing queue holding your birth data is purged as soon as your report is delivered. Your finished report (PDF) is stored so you can access it again in your account: if you create an account it is kept until you delete it; if you check out as a guest and never sign in, the stored report is automatically deleted after 90 days. Billing records are retained for 7 years as required by Austrian tax law (§ 132 BAO).

b) Free chart

To show your free chart, the name and birth data you enter are sent to our server, used to calculate your chart, and the result is returned to you instantly. This data is processed only for that calculation and is not stored. Legal basis: Art. 6(1)(b) GDPR — the free chart you requested.

c) Payment

Payments are processed by our payment provider Stripe. We do not receive or store your full card details. Stripe processes your payment data as an independent controller under its own privacy policy.

d) Server logs

Our hosting provider automatically records technical access data (e.g. IP address, date/time, requested page) to operate and secure the service. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning website).

e) Your account (optional)

You can create an account to save and re-download your reports. We use passwordless login: you enter your email and we send a one-time sign-in link — we never store a password. Your account holds your email, an optional display name, your report library and your marketing preference.

PurposeLetting you access and re-download the reports you purchased.
Legal basisArt. 6(1)(b) GDPR (contract).
RetentionUntil you delete your account. You can delete your account and all stored reports at any time from your account page.

f) Marketing emails

We send insight and offer emails only if you have opted in (Art. 6(1)(a) GDPR — consent). You can withdraw this consent at any time from your account page or via the unsubscribe link in each email, without affecting the lawfulness of prior processing.

3. Recipients & processors

We share your data only as necessary to provide the service, with the following processors:

Stripe (payments)Stripe Payments Europe, Ltd. / Stripe, Inc. — payment processing. Transfers to the USA are safeguarded by the EU–US Data Privacy Framework and/or Standard Contractual Clauses.
OpenAI (report text)Your first name and birth-chart details are sent to OpenAI's API to generate the written text of your report. OpenAI, L.L.C. (USA); transfers safeguarded by SCCs / DPF.
Email deliveryIONOS SE, Germany (EU) — sending confirmation and report emails.
HostingIONOS SE, Germany (EU) — operating the website and the order queue.
Google Analytics (consent only)Google Ireland Ltd. / Google LLC (USA) — website analytics. Loaded only after you consent; transfers safeguarded by SCCs / DPF.
Meta Pixel & CAPI (consent only)Meta Platforms Ireland Ltd. / Meta Platforms, Inc. (USA) — ad measurement. Loaded only after you consent; transfers safeguarded by SCCs / DPF.

4. Transfers outside the EU/EEA

Some processors (Stripe, OpenAI, and — only with your consent — Google and Meta) are based in the USA. Such transfers take place on the basis of the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses, ensuring an adequate level of protection.

5. Cookies & tracking

Strictly necessary cookies aside, this website sets analytics and advertising cookies only after you consent. On your first visit a banner asks for that consent; the tools below load only if you click “Accept”. If you decline, none of them run and no such cookies are set. You can change your mind at any time by clearing this site's storage in your browser. Legal basis: Art. 6(1)(a) GDPR (consent) and § 165(3) TKG 2021.

a) Google Analytics 4

We use Google Analytics 4 to understand how visitors use the site (e.g. pages viewed, free-chart completions, checkout starts) so we can improve it. Google sets cookies and processes usage data including your IP address. Provider: Google Ireland Ltd. (with Google LLC, USA). You can withdraw consent as described above.

b) Meta Pixel & Conversions API

With your consent we use the Meta (Facebook/Instagram) Pixel to measure the performance of our ads and to build audiences. When you complete a purchase, we additionally send the event server-side via Meta's Conversions API, including your email address in hashed (pseudonymised) form and Meta cookie identifiers, so the sale can be attributed. Provider: Meta Platforms Ireland Ltd. (with Meta Platforms, Inc., USA).

c) Fonts

Our fonts are self-hosted on our own server. No data is transmitted to Google (or any third party) when the fonts load.

6. Automated processing

Your report text is generated with the help of AI. This does not produce any decision with legal or similarly significant effect within the meaning of Art. 22 GDPR; the report is informational content for self-reflection.

7. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing, as well as to withdraw any consent at any time. To exercise these rights, contact us at office@the-inner-blueprint.com. If you have an account, you can delete it and all your stored reports yourself at any time from your account page.

You also have the right to lodge a complaint with the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at).