✦   Data Protection   ✦

Privacy & GDPR

Your Data Rights Under GDPR 2026
Data Controller: Mystic Orient (mysticorientmei@gmail.com) · Last Updated: April 23, 2026

What Data We Collect

Mystic Orient collects only the personal data necessary to generate your cultural reading. We do not sell, share, or rent your data to any third party.

Data TypePurposeLegal Basis
Name, EmailDelivering your report; responding to enquiriesConsent / Contract
Date of Birth, GenderGenerating your cultural archetype readingConsent (explicit)
Birth Time, Birth Place, MBTIOptional enrichment of cultural readingConsent (explicit)
PayPal Transaction DataPayment verification and order recordsContract / Legal Obligation
Support Ticket DataResolving customer enquiriesLegitimate Interest

Data Retention

We retain your personal data for 12 months from the date of your last interaction, after which it is automatically and permanently deleted from our systems.

Payment records processed through PayPal are subject to PayPal's own retention policies and applicable financial regulations. Support tickets are retained for 24 months for audit purposes.

You may request early deletion at any time using the GDPR Request Form below (Right to Erasure, Article 17).

How We Use Your Data

All content generated is for cultural entertainment and self-reflection purposes only. We do not claim supernatural accuracy. No data is used for profiling, advertising, or AI training.

Your Rights Under GDPR 2026

As a data subject under the EU/UK General Data Protection Regulation, you have the following rights. Submit a request using the form below:

ARTICLE 15
Right of Access
Request a copy of all personal data we hold about you. Processed within 30 days.
ARTICLE 17
Right to Erasure
Request permanent deletion of all your personal data from our systems.
ARTICLE 20
Right to Portability
Request your data in a machine-readable format (JSON / CSV).
ARTICLE 16
Right to Rectification
Request correction of any inaccurate personal data we hold.
ARTICLE 18
Right to Restriction
Request restriction of processing while a dispute is resolved.
ARTICLE 7
Right to Withdraw Consent
Withdraw consent at any time. This does not affect prior lawful processing.

You also have the right to lodge a complaint with your national data protection authority (e.g. the UK ICO at ico.org.uk, or the Irish DPC). We will always respond to GDPR requests within 30 days as required by law.

Third Party Processors

All processors are contractually bound to GDPR-compliant data handling practices.

Submit a GDPR Data Request

We will respond within 30 days as required by law (GDPR Article 12 §3).
A confirmation will be sent to your email address.

✦   Your GDPR request has been received and logged.
We will respond within 30 days as required by law. Your request reference has been sent to your email.