← when & where
Privacy policy
Your data is treated with care and used only to create and deliver your reading. This policy explains what is processed, why, and by whom, in accordance with the EU General Data Protection Regulation (GDPR).
1. Controller
Sonia Kowalewski · Miguel E. Schultz 8 · 06470 Mexico City, Mexico · hello@when-and-where.com
2. What we process, and why
- Website visit: Our site is hosted by Netlify, Inc. (USA). When you visit, technically necessary data (IP address, browser type, time of access) is processed in server logs to deliver the site securely. Legal basis: Art. 6 (1) f GDPR (legitimate interest in a secure, functional website). Netlify participates in the EU–US Data Privacy Framework.
- Fonts: This site loads fonts from Google Fonts (Google Ireland Ltd.), which transmits your IP address to Google when the page loads. Legal basis: Art. 6 (1) f GDPR.
- Purchase: Payment is processed by Digistore24 GmbH (Germany) as reseller. Digistore24 processes your name, email, and payment data under its own privacy policy. We receive your order data (name, email, order ID) to fulfil your purchase. Legal basis: Art. 6 (1) b GDPR (contract).
- Reading form: After purchase you provide your first name, email, birth date, birth time, birth place, and travel preferences via a form operated by Tally (Tally BVBA, Belgium). We use these details exclusively to create your personal reading. Legal basis: Art. 6 (1) b GDPR. Birth data is not shared with third parties and not used for marketing.
- Email contact: If you write to us, we process your message to answer it. Legal basis: Art. 6 (1) b or f GDPR.
3. Affiliate links
Reading dossiers and this website may contain affiliate links (marked as advertising). If you click such a link, the respective partner (e.g. Travelpayouts, GetYourGuide, BookRetreats) may set cookies on its own site to attribute a booking. This happens on the partner's website under the partner's responsibility; we only receive anonymous commission statistics, never your booking details.
4. Cookies
This website itself does not set tracking cookies and does not use analytics.
5. Storage period
Order and invoice data is stored as long as statutory retention periods require. Reading form data (including birth data) is deleted 12 months after delivery of your dossier, unless you ask us to keep it for follow-up readings.
6. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection (Art. 15–21 GDPR), and the right to lodge a complaint with a supervisory authority. Just write to hello@when-and-where.com.
Version 1.0 · July 5, 2026