Privacy Policy
Last updated April 8, 2026
NEXUSVIBE SL (trading as FateArc), with registered office at C/Casas de Miravete No 22A Planta 4, Oficina 4, 28031 Madrid, Spain (NIF: B70966650), is the data controller responsible for your personal data.
This privacy notice explains how we collect, store, use, and share your information when you use our Services.
It applies when you visit our website, use our applications, or interact with us through sales, marketing, or events.
If you do not agree with this policy, please do not use our Services. For questions, contact us at gestion@nexusvibe.net.
Summary of key points
This summary covers the main parts of our notice. You can read the full policy below for more detail.
- We may process personal information depending on how you use the Services and the choices you make.
- We do not intentionally process sensitive personal information unless it is necessary and permitted by law.
- We may receive information from public databases, partners, social platforms, and other outside sources.
- We use information to provide, improve, secure, and administer the Services and to comply with law.
- We may share information in specific situations and with specific categories of third parties.
- No online system is perfectly secure, but we use organizational and technical safeguards to protect your data.
- Your rights depend on your location, and you can exercise them through our request form or by contacting us.
Data Controller
The data controller for the purposes of the General Data Protection Regulation (GDPR) and the Spanish Organic Law 3/2018 on Personal Data Protection (LOPD-GDD) is:
NEXUSVIBE SL, C/Casas de Miravete No 22A Planta 4, Oficina 4, 28031 Madrid, Spain. NIF: B70966650. Email: gestion@nexusvibe.net.
What personal data we collect
We collect information you provide directly, information generated automatically when you use our Services, and information from third parties.
- Account data: name, email address, password, profile photo, date of birth, phone number.
- Profile data (psychics): display name, bio, specialties, availability, pricing, profile images.
- Payment data: billing address, wallet transactions, Stripe customer and payment method identifiers. We do not store full card numbers.
- Session data: video session start/end times, duration, settlement amounts, chat messages exchanged during sessions.
- Technical data: IP address, browser type, operating system, device identifiers, timezone, referring URL.
- Usage data: pages visited, features used, session frequency, click patterns.
- Communication data: support emails, bug reports, feedback.
How we use your data
We process your personal data for the following purposes:
- To create and manage your account and authenticate your identity.
- To provide the Services, including connecting clients with psychic readers for video and chat sessions.
- To process payments, wallet top-ups, session billing, and psychic payouts.
- To send transactional notifications (booking confirmations, session reminders, payment receipts).
- To maintain security, detect fraud, and prevent abuse of the platform.
- To improve our Services through analytics and usage patterns.
- To comply with legal obligations, including tax and financial reporting requirements.
- To respond to your inquiries and provide customer support.
Legal basis for processing (GDPR Art. 6)
We process your data based on the following legal grounds:
- Contract performance (Art. 6(1)(b)): processing necessary to provide the Services you have requested, including account management, session delivery, and payment processing.
- Legitimate interest (Art. 6(1)(f)): analytics, fraud prevention, platform security, and service improvement, where our interests do not override your rights.
- Legal obligation (Art. 6(1)(c)): compliance with tax, financial, and regulatory requirements under Spanish and EU law.
- Consent (Art. 6(1)(a)): marketing communications and optional cookies. You can withdraw consent at any time.
Data retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required by law.
- Account data: retained while your account is active and for 3 years after account deletion, unless legal obligations require longer retention.
- Financial and transaction data: retained for 6 years as required by Spanish tax law (Ley General Tributaria).
- Session recordings and chat logs: retained for 1 year after the session date.
- Technical and usage data: retained for 12 months, then anonymized or deleted.
- Support communications: retained for 2 years after the last interaction.
Data sharing and third parties
We do not sell your personal data. We share data with third parties only as necessary to provide the Services:
- Stripe (payment processing): receives payment and billing data to process transactions. Stripe acts as an independent controller for payment data.
- Supabase (infrastructure): hosts our database and authentication services. Data is stored in EU data centers.
- LiveKit (video infrastructure): processes video and audio streams during live sessions. Streams are not recorded or stored by LiveKit.
- Vercel (hosting): serves our website and API routes. May process IP addresses and request metadata.
- Resend (email delivery): receives email addresses to deliver transactional notifications.
- Google Analytics (optional): collects anonymized usage data if you consent to analytics cookies.
- Law enforcement or regulators: when required by applicable law, court order, or regulatory request.
International data transfers
Some of our service providers are located outside the European Economic Area (EEA). When we transfer personal data outside the EEA, we ensure adequate protection through:
- EU-US Data Privacy Framework (for US-based providers certified under the framework).
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy decisions by the European Commission for countries with equivalent data protection standards.
Your rights
Under the GDPR and LOPD-GDD, you have the following rights regarding your personal data:
- Right of access: obtain confirmation of whether we process your data and request a copy.
- Right to rectification: correct inaccurate or incomplete personal data.
- Right to erasure: request deletion of your data when it is no longer necessary or when you withdraw consent.
- Right to restriction: request that we limit processing of your data in certain circumstances.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interest, including profiling.
- Right to withdraw consent: withdraw consent at any time for processing based on consent.
How to exercise your rights
To exercise any of these rights, contact us at gestion@nexusvibe.net. We will respond within 30 days as required by the GDPR.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Espanola de Proteccion de Datos, AEPD) at www.aepd.es.
Security measures
We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit (TLS), access controls, regular security reviews, and secure infrastructure hosting.
No system is 100% secure. If we become aware of a data breach that poses a risk to your rights, we will notify the AEPD within 72 hours and inform affected individuals without undue delay.
Children
Our Services are not directed to individuals under 18 years of age. We do not knowingly collect personal data from minors. If we learn that we have collected data from a minor, we will delete it promptly.
Changes to this policy
We may update this privacy policy from time to time. We will post the revised version on our website with an updated date. Continued use of the Services after changes constitutes acceptance of the updated policy.
Contact us
NEXUSVIBE SL, C/Casas de Miravete No 22A Planta 4, Oficina 4, 28031 Madrid, Spain.
Email: gestion@nexusvibe.net. For support inquiries: support@fatearc.com.