Back

Privacy

How we handle your data, under the GDPR

This is a translation for your convenience. In case of doubt, the German version of this privacy policy applies.

1. Controller

Wooow Innovations UG (haftungsbeschränkt)
Wohnweg 1
01326 Dresden, Germany

Represented by: Managing Director Jakob Wowy
Email: info@wooow-innovations.com
Phone: +49 351 25027759

We are not legally required to appoint a data protection officer. For questions about data protection, please write to the address above.

2. Overview of processing

This application calculates and stores Human Design charts. You create an account and enter birth data: your own, and that of people whose chart you want to look at. From this we calculate the charts, the connections between two charts, and the daily transit reading.

Date, time and place of birth are personal data. They are the core of this application, and we handle them accordingly.

3. Legal bases

  • Art. 6 (1) (b) GDPR (performance of a contract): account, sign-in, storing your people and connections, calculating the charts.
  • Art. 6 (1) (a) GDPR (consent): the AI-assisted quick capture you switch on yourself, and joining the waitlist.
  • Art. 6 (1) (f) GDPR (legitimate interest): protection against large-scale automated sign-ups, and recording which invitation an account came through.

4. What we collect

a) Account

When you register we collect your email address and your password. The password is stored only as an Argon2 hash, never in plain text. Your language setting comes with it.

b) Your own person

Name, date of birth, time of birth, how precise that time is, time zone and place of birth. From this we calculate your chart. The key results (type, authority, profile, definition) are cached so the list loads quickly.

c) Other people you add

For other people you fill in the same fields. The name is a free text field: a first name or a nickname is enough, we don't ask for a real name. More on this in section 7.

d) Connections and notes

You can pair two people into a connection, give it a relationship type and add a free-form note. You can also store notes on a single person. What you write there is up to you.

e) Invitations

Every account has a personal invite code. When someone joins through your code, we record that this account came through you. That tells us how the application spreads. If you delete your account, the record of that link goes with it.

f) Waitlist

While access runs through invitations, you can put your email address on a waitlist. We store the address, your language and where you signed up. It is used solely to send you an invitation. A message to the address above is enough for us to take you off the list.

5. Cookies and local storage

We set two cookies, neither of them for tracking:

  • A session cookie for signing in. It is httpOnly, holds a random token and is technically necessary.
  • A cookie for the terminology you picked, so the centres keep the names you chose.

We set no marketing, analytics or tracking cookies, and there is no web analytics. That is why you see no cookie banner here.

6. Processors

ServiceProviderLocationPurpose
Hetzner CloudHetzner Online GmbHNuremberg, GermanyServer hosting and database of the application
Azure OpenAI ServiceMicrosoft Ireland Operations Ltd.Germany (Azure region germanywestcentral)Quick capture of person details from free text

Data processing agreements under Art. 28 GDPR are in place with these providers. We use no other services: there is no email delivery provider, no error tracking and no analytics tooling.

7. Other people's data

When you add someone else's chart, you process information about a person who has told us nothing. You share responsibility for that. Two things help:

  • The name is a free field. A first name or a nickname is entirely enough for the calculation. When in doubt, pick something nobody but you can place.
  • Ask the person before you enter their birth data. Beyond being polite, it is the cleanest basis for precise details.

Other people's charts are visible only to you, inside your account. We don't pass them on and we don't analyse them. Anyone who wants their data deleted can write to the address above.

8. AI-assisted quick capture

With AI switched on, you can type details about a person as plain text instead of filling in every field. A sentence like “Anna, born 3 April 1990 at 14:20 in Dresden” is then split into the matching fields, which you can check and correct afterwards.

To do that, the text you enter goes to an OpenAI language model, which we use through Microsoft's Azure OpenAI Service. The deployment sits in a German Azure region, so the processing happens in Germany. Your input is not used to train models there.

The legal basis is your consent under Art. 6 (1) (a) GDPR. You give it when you first start out or under “Me”, and you can withdraw it there at any time with effect for the future. Without your consent no text leaves the server towards a language model, and the quick capture button does not appear at all.

The submitted text is processed to produce the answer and is not stored by us. We only store the fields you confirm in the form afterwards.

9. Retention and deletion

  • Account, people, connections and notes: until you delete them. Under “Me” you will find “Delete account”. That removes your account and everything attached to it, immediately and for good.
  • Individual people and connections can be deleted one by one at any time.
  • Sign-in sessions expire after 30 days. Signing out ends them right away.
  • Waitlist entries: until the invitation is sent, or until you ask us to remove the entry.

Database backups are kept for 14 days. After that, deleted data is gone there too.

10. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Consent you have given, such as for AI support, can be withdrawn at any time with effect for the future (Art. 7 (3)); the switch for that is under “Me”.

To exercise these rights, write to info@wooow-innovations.com.

You also have the right to lodge a complaint with a supervisory authority. The competent one is the Saxon Data Protection Commissioner: www.saechsdsb.de

11. Data security

  • All connections are encrypted via HTTPS, and the certificate renews itself.
  • Passwords are stored as Argon2 hashes, session tokens only as SHA-256 hashes. Neither can be reversed.
  • The database is not reachable from outside; it only talks to the application on the same server.
  • Sign-in and registration are rate limited against large-scale automated attempts.

12. Changes to this policy

When the processing changes, this text changes with it. The version in force is always the one on this page.

Last updated: July 2026