Home

Privacy Policy

DestinyMTRX respects your privacy. This policy explains which personal data the service processes, why it is used and your rights under the EU General Data Protection Regulation (GDPR).

1. Data controller

Controller: DestinyMTRX
Business ID: 3530524-2
Address: Yläkiventie 11, Helsinki
Privacy contact: Info@destinymtrx.com

The controller determines why and how personal data is processed in DestinyMTRX.

2. Data we collect

Depending on how you use the service, we may process the following information:

Account data, such as email address, first and last name, user identifier, possible date of birth, marketing consent and profile-picture information.

Interpretation data, such as date of birth, possible partner data, interpretation name, calculated content, save status and links to purchased interpretations.

Purchase and payment data, such as products, purchase history, amounts, tax data, discounts, payment status, Stripe identifiers, saved payment methods and gift-card data.

Communication data, such as service emails including welcome messages, receipts and gift card codes.

Usage data, including cookies required for sign-in and technical information needed to operate the service securely.

When you use the AI question feature, your question and the relevant selected interpretation context are processed to generate an answer.

Customer-service messages may contain your contact details, message content and the data needed to resolve your request.

3. Purposes of processing

Personal data is used to provide the service, manage accounts, create, save and display interpretations, process purchases and payments, create gift cards, send receipts and service messages, and manage the customer relationship.

With your consent, data may also be used for marketing. You may withdraw marketing consent in the service settings or by contacting Info@destinymtrx.com.

4. Legal bases for processing

Processing is mainly necessary to perform a contract when you use the service, create an interpretation, make a purchase or manage your account.

Processing may also be based on a legal obligation, such as accounting requirements; a legitimate interest in keeping the service secure and functional; or consent, for example for marketing communications.

5. Recipients and processors

We do not sell personal data. We use external processors to provide the service.

Supabase is used for the database, authentication and file storage. Stripe is used to process payments, customers and saved payment methods. Service emails are sent through an SMTP/Nodemailer solution. OpenAI is used to answer questions submitted through the AI feature.

Service providers process data under their current service and privacy terms and applicable data-processing agreements.

6. Cookies and local storage

The service uses cookies required for authentication and session management. Technical browser storage, including local and session storage, is also used to support interface functionality.

An interpretation identifier cookie allows an unfinished or previously created interpretation to be opened again at the user's request.

The service uses localStorage and sessionStorage for items such as birth-date data, interface selections and admin-view state. If analytics, advertising pixels or other tracking technologies are introduced, this policy and any cookie notice must be updated before they are used.

7. Retention

We retain data only as long as necessary for the purposes described here, for the customer relationship and to meet legal obligations.

Account, purchase and billing data may be retained while an account is active and as long as applicable law requires. Accounting and transaction records are retained for the legally required period.

8. Transfers outside the EU/EEA

Some service providers may process data outside the EU or EEA. In those situations, we seek to ensure appropriate safeguards, including contractual arrangements and other mechanisms required by applicable data-protection law.

9. Your rights

You have the right to access your data, request correction, request deletion when a legal basis exists, restrict processing, object in certain situations and request data portability where applicable.

Where processing is based on consent, you may withdraw it at any time. You may also lodge a complaint with a supervisory authority.

In Finland, the supervisory authority is the Office of the Data Protection Ombudsman. Contact information and instructions are available at tietosuoja.fi.

10. Data security

We protect personal data with appropriate technical and organisational measures. Access is restricted according to need, and payment data is processed through the payment provider.

11. Automated decision-making and AI

The AI question feature generates an answer based on the selected interpretation context. It is not medical, legal or financial advice. AI questions and the related interpretation context are sent to OpenAI to generate the answer.

12. Changes to this policy

We may update this privacy policy when the service or applicable law changes. The current version is published on this page.

Last updated: 06/08/2026