Data processing agreement
Most of what you store is other people. You decided to record them, and we store and sync what you entered. This sets out what that means in the form the law asks for.
1. Who this is between
You — the practitioner using Shri Jyoti Star to keep records about other people — and Andrew Foss, trading as Vedic Software, at PO Box 91, Earlysville, VA 22936, United States, Virginia, United States.
It applies from the moment you store a record about someone else, alongside the terms of use. If your practice needs a signed copy, write to privacy@shrijyotistar.com and we will send one.
2. Which of us decides what
| Data | Controller | Our role |
|---|---|---|
| Charts you store about other people | You | Processor |
| Your account, your billing, crash reports and analytics | Vedic Software | Controller |
| Your own chart | Vedic Software | Controller |
This agreement covers the first row only. The other two are ours to answer for, and the privacy policy covers them.
3. What the processing is
- Subject matter — the birth records you enter about other people, and the pages, widgets, tags, notes and life events attached to them.
- Nature — storage and synchronisation. Charts are computed on your device, so drawing one is not processing we carry out; see the privacy policy, section 1.
- Purpose — so your library is on every device you sign in to, and survives losing one.
- Duration — as long as your account is open. It ends when the account does.
4. Whose data it is
The people — your clients, and anyone else whose chart you keep: family, students, people you are studying. None of them has an account with us, has read anything we publish, or has agreed to anything with us. They know you.
The data — a name, a date of birth, an exact time of birth, a birthplace and its coordinates, plus whatever you add. A date, an exact time and a place identify a person even with the name removed, so we treat them as identifying data rather than as chart inputs.
Whether any of it is a special category under Article 9 is unsettled. Section 6 of the privacy policy says where that stands.
5. We act on your instructions
We process those records to store them, sync them and give them back to you, and for nothing else. The app is how you instruct us: what you save, edit or delete is the instruction.
We do not read them, analyse them, profile anyone in them, sell them, or use them to train anything. If a law we are subject to ever required us to do something else with them, we would tell you before we did it, unless that law forbids the telling.
6. Who can reach it
Access on our side is limited to the people who operate the service, for the work of running and supporting it, under a duty of confidentiality that outlasts their involvement.
7. How it is kept
- On the device — the local database is encrypted at rest with AES-256. The key is random, held in the iOS Keychain or the Android Keystore, and never leaves the device.
- In transit — TLS between the app and the server.
- On the server — every synced table carries row-level security keyed to the account, on reading, inserting, updating and deleting alike. One account cannot reach another’s rows even if it asks.
What we do not do: hold your clients’ records encrypted in a way we ourselves cannot read. Sync, account recovery and support could not work as they do if we did. There is no end-to-end encryption here, and we would rather say so than let it be assumed.
8. The companies we use
You authorise us to use these, and we are answerable for what they do with the data.
| Company | What they do for us | Where |
|---|---|---|
| Supabase | Account, authentication and synced chart data | European Union (AWS eu-north-1, Stockholm) |
| PowerSync (JourneyApps) | Sync between the app and Supabase | European Union (AWS eu-west-1, Ireland) |
| Sentry | Crash reports | European Union |
| PostHog | Product analytics | European Union (eu.i.posthog.com) |
| Vercel | Hosting and visitor analytics for this website | Global edge network |
| Resend | Account emails and release-note list | European Union |
| Apple | TestFlight beta distribution, and subscription billing after launch | Global |
| Tester sign-up form and Google Play testing, and subscription billing after launch | Global |
Two of them ever hold a client record: Supabase stores it, and PowerSync moves it between the app and Supabase. The rest handle your account, your payment or this website. A crash report carries a stack trace, a device model and your account id, not the contents of an entry; an analytics event carries which screen was opened, not who it was about.
If we add or replace one that handles data you control, we list it on the sub-processors page at least 30 days before it starts, and email you if you have asked us to, so you can object. If we cannot settle an objection, you may close the account and take the data with you, and section 14 applies.
9. Answering your clients
Most of it you do yourself. Correcting an entry and deleting one are both done in the app, and both reach the server. Where a request needs something the app cannot do — a copy of everything held about one person, or a pause on processing while a dispute is settled — write to privacy@shrijyotistar.com and we will do it.
If one of your clients contacts us directly about a record you hold, we will not act on it. We will tell them to ask you, and tell you that they asked.
10. Deleting reaches the server
Deleting an entry issues a real delete against the database, not a flag that hides a row, and the tags and events attached to it go with it. Backups hold a copy until they rotate.
This is the mechanism behind an erasure request one of your clients makes to you: you delete the entry, and it is gone from our side as well as from your screen.
11. If there is a breach
If we become aware of a breach affecting records you control, we tell you without undue delay, with what we know at the time — what happened, which data, roughly how many people, and what we are doing about it. We keep telling you as we learn more, and we help you meet your own notification duties.
Telling your clients is yours to do. They have a relationship with you, not with us, and a notification from a company they have never heard of would be its own harm.
12. Checking that we do this
We give you what you need to show that this agreement is being kept: this page, the sub-processor list, and written answers to specific questions. If those do not settle a question, you or an auditor you appoint may inspect once in any twelve months, on 30 days’ notice, at your cost and under confidentiality. A breach, or a supervisory authority requiring it, lifts the once-a-year limit.
13. Where it goes
We are in Virginia, United States, so data about people in the European Economic Area and the United Kingdom is transferred out of those places to reach us. Those transfers rely on the European Commission’s standard contractual clauses and, for the United Kingdom, the addendum to them. The same clauses cover any company in section 8 holding data outside the EEA.
Crash reports and analytics are processed in the European Union. The regions of the account database and the sync service are in the table above.
14. When this ends
This agreement lasts as long as your account. When you close it, we delete your clients’ records from the live database and from backups on their normal rotation. If you want a copy first, ask before you close the account and we will send one in a portable form.
Nothing about your clients survives that. What survives is about you — the records of a purchase that tax law requires us to keep, described in the privacy policy, section 8.
15. Liability, law and changes
Liability under this agreement is limited as set out in section 11 of the terms of use. Governed by the law of Virginia, United States. Where the standard contractual clauses apply to a transfer, they govern that transfer and prevail over anything here that disagrees with them.
If we change this materially we will say so by email before the change applies. Where this agreement and the terms of use disagree about the records you keep on other people’s behalf, this one governs.
16. Contact
privacy@shrijyotistar.com · Andrew Foss, PO Box 91, Earlysville, VA 22936, United States.