Privacy Policy

Privacy Policy

1. Who we are

Astrā Soma by Om Osco (“we”, “us”) operates this Website as a UK sole trader.

Contact: info@astra-soma.com

Astrā Soma by Om Osco (“we”, “us”) operates this Website as a UK sole trader.

Contact: info@astra-soma.com

2. Personal data we collect

2. Personal data we collect

Depending on how you interact with us, we may collect:


A) Identity & contact data

• Name, email address, and any information you include in messages/forms.


B) Booking and purchase data

• Session/workshop booking details.

• Payment status, receipts, and transaction identifiers.


Note: Payments are processed by Stripe. We do not store full card details.


C) Astrology data

• Birth details you provide (e.g., date of birth, time of birth, place of birth) and information you

share in consultations related to your chart.


D) Health and wellbeing data (special category data)

• Health/injury information you choose to share (e.g., conditions, injuries, limitations) to support

safe yoga/somatic practice.


E) Website usage data

• IP address, device/browser information, and how you use

3. How we use your data

3. How we use your data

We use your data for the following purposes:


To provide services and fulfil bookings/purchases

• Managing bookings, delivering services, providing customer support.

Legal basis: Contract.

To respond to enquiries


• Replying to messages and questions.

Legal basis: Legitimate interests (running our business) or consent (where applicable).

To manage payments and prevent fraud


• Processing payments via Stripe and handling chargebacks/disputes.

Legal basis: Contract; legitimate interests; legal obligation (where relevant).

To send updates and communications


• Service emails (e.g., booking confirmations, changes).

Legal basis: Contract / legitimate interests.

Marketing/newsletter (Substack)


• If you subscribe to Substack, Substack will process your data under their policies.

Legal basis: Consent (you can unsubscribe anytime).


• Website improvement

Understanding Website usage to improve performance (only where analytics cookies are

enabled and consented).

Legal basis: Consent (for non-essential cookies).

Special category data (health/injury info)


• To adapt practices safely and appropriately.

Legal basis: Explicit consent (you choose to provide it), and it is used only for wellbeing/safety in

the service context.

4. Where we get your data

4. Where we get your data

• Directly from you (forms, emails, bookings, sessions).

• Automatically via cookies/analytics (where enabled).

5. Who we share your data with

We may share data with trusted providers only as needed:


• Framer / hosting providers (website hosting and forms/bookings)

• Stripe (payments and fraud prevention)

• Substack (newsletter subscriptions — Substack acts as its own controller for subscriber data)

• Professional advisers (e.g., accountant) where necessary

• Legal/regulatory authorities if required by law


We do not sell your personal data.

6. International transfers

6. International transfers

Some providers may process data outside the UK. Where this happens, safeguards are used (such as adequacy regulations or appropriate contractual protections) to protect your data.

7. Data retention

7. Data retention

We keep your data only as long as needed:

• Enquiries: typically up to 12 months

• Bookings/purchases: typically up to 6 years (for accounting/tax)

• Astrology/health notes: kept only as long as needed for ongoing work, and reviewed periodically

(you may request deletion where applicable)

• Substack subscriptions: until you unsubscribe (managed via Substack)

8. Your rights (UK GDPR)

8. Your rights (UK GDPR)

You have the right to:


• Access your data

• Correct inaccurate data

• Request deletion (in certain circumstances)

• Restrict processing (in certain circumstances)

• Object to processing (in certain circumstances)

• Data portability (in certain circumstances)

• Withdraw consent (where we rely on consent)


To exercise your rights, email info@astra-soma.com.

9. Complaints

9. Complaints

If you are unhappy with how we handle your data, you can complain to the Information Commissioner’s Office (ICO). We’d appreciate the opportunity to resolve your concern first by contacting us.

10. Security

10. Security

We take reasonable steps to protect your data (access controls, secure tools/providers). No online transmission is 100% secure, but we work to minimise risks.

11. Children

11. Children

Our Website and services are not intended for children. If you are under 18, please do not use our services or submit personal data without a parent/guardian.

12. Changes to this policy

12. Changes to this policy

We may update this policy from time to time. The latest version will be posted on this page.

Contact: info@astra-soma.com