Legal

Privacy Policy

Your confidences matter — in a reading and in your data. This policy explains what personal information we collect through psychicrosasheri.com, why we collect it, how long we keep it, and the rights you hold under European and Californian privacy law.

Last updated · 16 August 2026

1. Who we are (Data Controller)

Psychic Rosasheri ("we", "us") operates psychicrosasheri.com and is the data controller for personal data processed through this website. For any privacy question or rights request, write to privacy@psychicrosasheri.com.

2. Personal data we collect

  • Booking & enquiry data: name, email address, telephone number, date of birth if you choose to provide it, preferred session type and the questions or context you share with us.
  • Reading content: notes and interpretations connected with a session you book. This may reveal sensitive matters (health, relationships, beliefs), so we treat it as confidential and process it only with your explicit consent.
  • Correspondence: messages you send by email, contact form or social channels.
  • Technical data: IP address, device and browser type, pages viewed and referring page — collected through strictly necessary and (with consent) analytics cookies.

We do not knowingly collect data from children under 16. Sessions are offered to adults only.

3. Why we process it, and our legal bases (GDPR Art. 6)

  • To arrange and deliver readings — performance of a contract (Art. 6(1)(b)).
  • To answer enquiries and keep the site secure — legitimate interests (Art. 6(1)(f)).
  • Analytics, marketing cookies and newsletters — your consent (Art. 6(1)(a)), withdrawable at any time.
  • Sensitive details you disclose in a reading — explicit consent (Art. 9(2)(a)).
  • Accounting and legal obligations — legal obligation (Art. 6(1)(c)).

4. Sharing and recipients

We never sell or share your personal information for cross-context behavioural advertising, and we do not trade your data. We disclose data only to service providers who process it on our instructions — website hosting, email delivery, scheduling and payment processing — each bound by a data processing agreement, and to authorities where the law requires it.

5. International transfers

Some providers may process data outside the European Economic Area. Where that happens we rely on an adequacy decision or on the European Commission's Standard Contractual Clauses together with supplementary safeguards.

6. Retention

  • Enquiries that do not lead to a booking: up to 12 months.
  • Session records and reading notes: up to 24 months, unless you ask us to erase them sooner.
  • Invoices and accounting records: as required by tax law (typically 6–10 years).
  • Cookie consent records: 12 months.

7. Your rights in the EU/EEA and UK (GDPR)

You have the right to:

  • access a copy of your personal data;
  • rectify inaccurate or incomplete data;
  • erasure ("right to be forgotten");
  • restrict or object to processing, including profiling;
  • data portability in a machine-readable format;
  • withdraw consent at any time without affecting prior processing;
  • lodge a complaint with your national supervisory authority.

Email privacy@psychicrosasheri.com and we will respond within one month, free of charge.

8. Your rights in California (CCPA/CPRA)

California residents have the right to know what personal information is collected, used and disclosed; to delete it; to correct it; to opt out of sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights.

We do not sell or share personal information as those terms are defined under the CPRA, and we do not use sensitive personal information for purposes beyond providing the services you request. You may still submit a request — including through an authorised agent — at privacy@psychicrosasheri.com. We verify requests by matching the details you provide against our records, and we respond within 45 days.

9. Security

We apply appropriate technical and organisational measures — encryption in transit, access controls and minimal data collection. No method of transmission is perfectly secure; in the event of a breach affecting your rights we will notify you and the relevant authority as required by law.

10. Changes to this policy

We may update this policy to reflect changes in our practices or the law. The revision date at the top of the page will always show the current version.