Parties and contractual scope
This agreement forms part of the Terms and Conditionsand applies when the user processes client or participant personal data in Esotool. The account-holding practitioner, practice, or organisation is the controller; Esotool is the processor. Acceptance of the GDPR commitment and terms concludes this agreement for the service-access period.
Subject matter and duration
Esotool hosts and processes data to provide the workspace, calculations, readings, interpretations, reports, exports, backups, security, and requested support. Processing begins when data is first recorded and ends on practitioner deletion or contract termination, subject to backup deletion cycles and legal retention duties.
Nature, purposes, and instructions
Processing may include:
- collection by entry, organisation, storage, consultation, modification, export, and deletion;
- astrology and numerology calculations, tarot reading management, and report production;
- interpretation generation when actively initiated by the practitioner;
- backup, restoration, logging, security, and technical support.
Actions performed through the service, support requests, and this agreement are documented instructions. Additional instructions must be written. Esotool will notify the controller and may pause an instruction that appears to breach the GDPR while it is verified.
Data subjects and data categories
Data subjects may include clients, prospects, session participants, compatibility-analysis partners, or others whom the practitioner may lawfully process. Data may include identity and contact details, labels and technical IDs, birth date/time/time zone/place, session intentions, questions, notes, calculations, readings, results, interpretations, corrections, reports, and security events.
The service is not a medical, legal, or social-care record. Special category or criminal-offence data must not be entered without demonstrated necessity, a valid legal basis, and suitable safeguards.
Controller obligations
- process lawfully, fairly, transparently, and only as necessary;
- inform data subjects, set retention periods, and answer their requests;
- authorise practice users and bind them to confidentiality;
- keep direct identifiers out of assisted-generation content and review outputs before disclosure;
- configure and use the service consistently with professional and security duties.
Processor obligations
- process only on documented instructions and to provide the service;
- ensure authorised persons are bound to confidentiality;
- maintain risk-appropriate technical and organisational measures;
- reasonably assist with data-subject rights, impact assessments, authority consultations, and security obligations;
- make information available to demonstrate compliance;
- delete or return data at service end as instructed, unless law requires retention.
Security measures
Measures include central authentication, time-limited sessions, permission checks, logical practice separation and server-side scope checks, encrypted communications, private storage and encryption at rest, backup and restoration capabilities, useful logging with secret masking, security headers, private-space no-index controls, and dependency monitoring. Measures evolve with risk and the state of the art without materially reducing overall protection.
Sub-processors
The controller gives general authorisation for technical infrastructure providers (hosting, database, object storage, authentication, and place search, with the main application-data region in the EU) and assisted-generation providers used only when a practitioner initiates a request.
Material additions or replacements are announced to the account address before taking effect where required. The practitioner may object on reasoned data-protection grounds. The parties seek a reasonable solution; otherwise the affected feature or contract may be ended.
Transfers outside the EEA
Any non-EEA access or transfer uses a GDPR Chapter V mechanism such as an adequacy decision, Standard Contractual Clauses, and necessary supplementary measures. Relevant mechanism information is available on request subject to provider confidentiality and security.
Data-subject requests
The application provides per-record export and deletion. Where those tools are insufficient, Esotool reasonably assists with verified requests. A request received directly about practitioner-controlled data is forwarded to the identifiable practitioner without a substantive response unless instructed or legally required.
Personal data breach
After confirming a breach affecting data processed for a practitioner, Esotool notifies them without undue delay and provides available information progressively: incident nature, affected people and data, likely consequences, measures taken or proposed, and contact point. The practitioner determines authority or data-subject notifications; Esotool provides reasonable assistance.
Audit and evidence of compliance
On reasonable written request, Esotool provides available compliance documentation. If insufficient, a targeted audit may be arranged at most annually with reasonable notice, during business hours, without compromising security, trade secrets, or other customers’ data. The practitioner bears specific-audit costs unless a material processor breach is found or an authority requires the audit.
End of processing
During access, practitioners can export or delete records and can delete the full account with reinforced confirmation. Active client records, sessions, calculations, readings, reports, prompts, results, and practice files are then deleted. Other active data is returned or deleted under available processes and instructions. Residual backups remain protected and isolated until rotation removes them, unless law requires retention. The minimal post-deletion quota receipt contains no practitioner client business data.
Contact and order of precedence
This agreement prevails over the Terms and Conditions for conflicts about personal-data processing; the remainder of the contract stays effective.
Requests about this agreement may be sent to info@esotool.com.