This notice explains what personal data Birth Date Report collects, why, what we rely on to process it, who it is shared with, how long it is kept, and the rights you have over it. It is written to the standard of the EU and UK General Data Protection Regulation, which we apply to everyone regardless of where you are.
Birth Date Report is the controller of the personal data described here. The service generates a personal insight report from your birth details.
A contact address for privacy requests has not been published yet. Until it is, use the same channel you contacted us through to buy or ask about a report, and we will act on the request.
We do not ask for, and do not knowingly collect, special category data such as health information, religious or philosophical beliefs, political opinions, or anything about your sex life or sexual orientation. The report is for personal insight. It is not medical, financial, legal or psychological advice, and nothing in it should be relied on as such.
All of it is provided directly by you through the forms on this site — except for batch reports, where a CSV file is uploaded by someone who is responsible for having obtained the consent of every person listed in it. If you were included in such a batch and did not agree to it, contact us and we will delete your data.
Under GDPR Art. 6 each purpose needs its own lawful basis, and they are not interchangeable. Ours are:
The report is written by an automated system, but it produces a document for you to read. It makes no decision about you that has legal effect or similarly significant consequences, so it is not automated decision-making of the kind GDPR Art. 22 restricts.
We do not sell your data, and we do not share it for anyone else's advertising. It is disclosed only to the providers who operate parts of this service for us, each under a contract that limits them to our instructions:
International transfers. Several of the providers above are outside the EU and UK, principally in the United States. Where a transfer is not covered by an adequacy decision, it is made under the European Commission's Standard Contractual Clauses (GDPR Art. 46(2)(c)) or the UK equivalent. You may ask us for details of the safeguards that apply.
Required: your name, gender and birth details, because the report cannot be produced without them; and your email address and phone number, because they are how we reach you if the report or the payment fails.
Required to use the service: accepting this notice. That is not a consent to marketing — it is you confirming you have been told what happens to your data before you hand it over.
Genuinely optional: marketing. It is a separate tick box, unticked by default, and leaving it unticked costs you nothing: the free preview runs, the report generates, and the purchase completes exactly the same either way. We separate the two deliberately, because consent bundled into a condition of service is not freely given and is therefore not valid consent (GDPR Art. 7(4)).
Opening an account is also optional. You can buy and download a report without one; an account exists so you can reopen a report later.
Wherever you are, you may ask us to:
To exercise any of these: A contact address for privacy requests has not been published yet. Until it is, use the same channel you contacted us through to buy or ask about a report, and we will act on the request. We will verify who you are before acting — otherwise the access right becomes a way to read a stranger's data — and reply within one month, as Art. 12(3) requires.
If you are in the EU or the UK and you think we have got this wrong, you may complain to your national data protection authority. In the UK that is the Information Commissioner's Office. Complaining to them does not require you to raise it with us first, though we would rather you did.
All connections are encrypted in transit (HTTPS). Reports are held in private storage that carries no public URL; a link to your own report is signed and expires. The database is reachable only by our server — your browser is never given direct access to it. Card details never enter our systems. Passwords are stored as hashes, so we cannot read yours and will never ask for it. If a breach occurs that is likely to risk your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and tell you directly where the risk to you is high (Art. 33 and 34).
This service is not intended for anyone under 16, and we do not knowingly collect their data. A report can legitimately be generated about a child by a parent or guardian; the contact details we hold in that case are the adult's. If you believe a child has given us their own data, tell us and we will delete it.
We may update this notice. The version number at the top changes whenever the content changes materially, and your consent is stored alongside the version you were shown — so what you agreed to remains answerable later, rather than being quietly replaced by whatever the page says today. A report costs $19.99; nothing in this notice changes with the price.