Privacy notice
This notice explains how we process the personal data of visitors and customers under Regulation (EU) 2016/679 (GDPR) and applicable national law.
Version 1.0 · Last updated: 24 September 2026
Data controller: Cortx EOOD, registered office Bul. Tsar Boris III n. 165A, piano 4, uff. 11, 1618 Sofia (rione Krasno selo), Bulgaria, VAT BG208805445, EIK/UIC 208805445. Contact: email hello@astarforyou.com.
Personalised advertising
Marketing consent covers measurement. The separate ‘Personalised advertising’ choice allows eligible visits, basket activity and purchases to be used to create audiences and show you relevant AStarForYou ads on Google, Meta and TikTok when the service is enabled. It also requires Marketing; earlier consent to measurement alone is not extended. You can withdraw this choice in cookie preferences while keeping measurement enabled. Turning off Marketing also turns off personalised advertising. Dedications, names, personal dates, photographs, private links and memorial journeys are excluded. Withdrawal stops subsequent use but does not recall events already received by the platforms.
Controller
Cortx EOOD, registered office Bul. Tsar Boris III n. 165A, piano 4, uff. 11, 1618 Sofia (rione Krasno selo), Bulgaria, VAT BG208805445, EIK/UIC 208805445. Contact: email hello@astarforyou.com.
Data we collect
- Order data: name, email address and dedication details such as names, dates, messages and observation location; for orders with printed products confirmed before 24 September 2026 we also keep the shipping address given then.
- Contact data supplied through support forms or email.
- Technical navigation data, security logs and cookie choices, as described in the Cookie Policy.
- For Google Ads enhanced conversions, and only after Marketing consent, the order email address is normalised and converted on our server into a SHA-256 hash before transmission; Google uses it to associate the purchase with attributable advertising interactions.
- Payment references processed by the payment provider; we do not receive or store complete card details.
Purposes and legal bases
We process personal data for the following purposes and legal bases:
- handling orders and producing personalised content — steps requested before entering into a contract and performance of the contract;
- tax, accounting and other statutory duties — compliance with legal obligations;
- customer support and complaint handling — performance of the contract and legitimate interests;
- site security, fraud prevention and the establishment, exercise or defence of legal claims — legitimate interests;
- non-necessary cookies and any promotional communications — consent only.
- campaign measurement using Google Ads enhanced conversions — Marketing consent; advertising personalisation remains disabled.
Retention
We retain data only for the periods required by the stated purposes. Tax and accounting records are retained for ten years; consent evidence and legal-version records are retained for the period needed to demonstrate compliance; support correspondence is retained for the time needed to handle the request and any related legal claims.
At the end of the applicable period, data is deleted or anonymised unless a further legal obligation requires retention.
Recipients and processors
Authorised staff and providers needed to deliver the service—including hosting, payments, email, document storage, Google Analytics for consented statistics, Google Ads for consented campaign measurement and professional advisers—receive only the data needed for their role and act as processors where required. For enhanced conversions, Google Ads receives only the normalised SHA-256 hash of the email address together with conversion data; the tag does not transmit the plain-text email, name, postal address or dedication content.
To generate the astronomical sky cutout, the CDS/Aladin service receives only the selected star’s sky coordinates and technical image parameters, not customer identifiers or customer-entered dedication text.
With current Marketing consent, Meta Platforms receives eligible visit, product view, basket, checkout and qualified purchase events. The server sends pseudonymous identifiers, an advertising click identifier when present, browser technical information, event time, catalogue identifiers and, when available, net value and currency. Without the separate Personalised advertising choice, server requests instruct Meta to use the events for attribution only. When the service is enabled, consent to both purposes also permits the Pixel and audience use; the Pixel receives a limited copy with the same identifier to avoid duplicates. We do not send Meta email addresses, even hashed, names, dedications, personal dates, photographs, private paths or access tokens. Memorial journeys are excluded. The linking cookie lasts up to 7 days. Withdrawal stops subsequent sending and starts removal of linking identifiers; it cannot recall events already received by Meta.
To respect the choice made before purchase, we retain revocable links between consent, visit and order: up to 24 hours from the start of the Google Analytics session, 7 days for Google Ads and Meta, and 30 days for TikTok when enabled. Expired links are rejected immediately; server identifiers are removed in periodic cleanup cycles. Consent evidence and accounting records follow their respective retention requirements. An expired link is not reconstructed retrospectively to attribute a purchase. These periods do not apply to the gift link. When enabled, server delivery to Google Ads may take place within 24 hours of payment even if you do not return to the website, using net value, currency, a pseudonymous transaction identifier and the hash of the order email address. It requires Marketing consent obtained before payment and still valid; withdrawal stops subsequent sending but cannot recall data already received. Dedication content and private or memorial journeys remain excluded.
We do not sell personal data. Where a provider processes data outside the European Economic Area, the transfer takes place using the safeguards required by the GDPR.
Your rights
Under Articles 15–22 GDPR, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent at any time without affecting processing carried out before withdrawal.
To exercise these rights, contact hello@astarforyou.com. You may also lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or with the supervisory authority competent for your habitual residence or place of work.
Security
Technical and organisational measures include access controls, scoped links, encryption in transit, logging, backups and minimisation. No system can promise absolute security.
Data protection officer
Where a data protection officer is appointed, current contact details are published here. Otherwise contact the controller at hello@astarforyou.com.
Changes to this notice
Material changes are versioned and published with an updated date. The notice and consent evidence applicable to an order remain frozen by locale.

