Skip to content

Data Processing Agreement

Last updated

These terms apply where you use the Occult API to process personal data and data protection law requires an agreement between us. They form part of our Terms of Service.

1. The parties and their roles

You are the controller: you decide what personal data is sent to the API and why. OCCULTLAB CODE PRIVATE LIMITED, of B-40-a, Parbhu Marg, Tilak Nagar, Jawahar Nagar, Jaipur, Rajasthan 302004, India, is the processor: we act on your instructions and for no purpose of our own.

Sending a request to the API is your instruction to process the data in it. We do not use it to train models, we do not sell it, and we do not use it to build a profile of anyone.

2. Subject matter, duration, nature and purpose

Subject matter. Performing astrological and calendrical calculations on data you submit, and operating your account.

Duration. For calculation data, the life of the request. For account and usage records, as long as your account exists and for the period afterwards set out in our Privacy Policy.

Nature and purpose. Computation and return of a result; authentication; metering and billing; support.

3. Types of personal data and categories of data subject

From your end users, in a request: a date of birth, a time of birth, a place of birth or coordinates, and optionally a name. Depending on how you use the API this may relate to your customers, your employees, or members of the public.

From you, as our customer: name, email address, country, and the usage and payment records described in the Privacy Policy.

Special category data. The API is not designed to receive health, biometric, religious or similar data, and you should not send it. Note that a birth date and place can, depending on context and jurisdiction, be treated as sensitive — you are responsible for determining the lawful basis for sending it.

4. What we do not keep

This is the clause most reviews are actually looking for. We do not store the contents of calculation requests. A birth date, time and place is used to compute the response and is not written to a database afterwards. What we retain per call is the endpoint, the timestamp, the HTTP status and the credits consumed — which is what your usage page and ledger are built from, and what lets us answer a billing question.

Our PDF report endpoints return the document in the response and store no copy. We do not write reports to a bucket or hand back a URL, precisely so that a stranger's birth chart is not left sitting at a public address.

5. Confidentiality and security

Everyone with access to personal data is bound by confidentiality. We maintain measures appropriate to the risk, including encryption in transit (TLS), API keys stored only as hashes so that neither an administrator nor a database dump can recover a key, scoped access, per-key rate limiting, and revocation by key prefix so a leaked key can be killed without knowing its secret.

6. Subprocessors

You give general authorisation for us to engage subprocessors. The current list is published at /subprocessors. We will update that page before a new one begins handling your data, and you may object; if we cannot resolve your objection you may terminate and receive a refund of unused credits.

We remain liable to you for a subprocessor's acts as if they were our own.

7. International transfers

We are established in India. Where you are in the EEA or the UK, sending data to us is a transfer to a third country, and we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated into this agreement by reference. Where a subprocessor is outside your region, equivalent safeguards apply to that onward transfer.

8. Assisting you

We will help you, so far as we reasonably can, with: responding to requests from individuals exercising their rights; data protection impact assessments; and consultations with a supervisory authority. Because we do not store request contents, a request about an individual whose birth data you sent us is usually answered entirely from your own records — we have nothing to search.

9. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need for your own notification obligations, and will keep you updated as we learn more.

10. Deletion and return

On termination, and at your choice, we will delete or return the personal data we hold for you and delete existing copies, unless we are required to keep something by law — tax and accounting records being the usual case. You can delete your account at any time from your settings.

11. Audit

We will make available the information needed to demonstrate compliance with this agreement and will contribute to audits, on reasonable notice, no more than once a year unless a supervisory authority or a breach requires otherwise, and subject to confidentiality.

12. General

Where this agreement conflicts with our Terms of Service, this agreement prevails on data protection. It is governed by the same law and courts as the Terms — Jaipur, Rajasthan — without limiting any right you have to bring proceedings, or to complain to a supervisory authority, where you live.

If you need this signed as a standalone document, or a negotiated variant, write to mridul.kabra23@gmail.com.

This is our standard form and is provided for your review. It is not legal advice, and neither party should rely on it without taking their own.