Immutable legal bundle · effective July 16, 2026 · service provider: Martin Neumann, trading as NOX Publishing
Save or print this document for your records. Every section is expanded in print.
Service and brand
ChronOS Ephemeris by Neumann (a Nox Publishing Product)
Information according to § 5 DDG
Martin Neumann, trading as NOX Publishing
Chemnitzer Str. 1
90491 Nürnberg
Germany
Contact
General, legal, and privacy: hello@chronos-ephemeris.com
Billing, cancellation, and payment: payment@chronos-ephemeris.com
The address noreply@chronos-ephemeris.com is used only to send automated service messages and is not monitored for support.
Legal form and tax information
Sole proprietor. Prices are stated in euro and the binding Checkout shows taxes collected for the specific transaction where legally required and supported. Stripe’s calculation does not replace the provider’s or customer’s own registration, reporting, withholding, reverse-charge, or similar obligations. Any German VAT ID, business identification number, or register entry that becomes applicable will be published here as required by law.
Responsible for editorial content according to § 18(2) MStV
Martin Neumann, address as above.
Consumer dispute resolution
Paid self-service plans are offered only to business customers. Without acknowledging that consumer law applies, the provider is neither willing nor obliged to participate in dispute-resolution proceedings before a German consumer arbitration board.
Version, scope, and controller
chronos-privacy-global-2026-07-16.2, effective July 16, 2026. This notice covers the website, account dashboard, ephemeris API, support, and billing for ChronOS Ephemeris by Neumann (a Nox Publishing Product). The controller is Martin Neumann, trading as NOX Publishing, Chemnitzer Str. 1, 90491 Nürnberg, Germany. Privacy requests: hello@chronos-ephemeris.com.
Data we receive
We receive account and contact data; organization, project, and API-key metadata; subscription, invoice, billing-country, and tax-status data; support communications; API requests and returned calculations; usage, quota, security, and audit events; and technical log data such as IP address, timestamp, requested resource, referrer, device, and browser information. Data comes from you, authorized organization users, your use of the service, and our payment and infrastructure providers.
Purposes and legal bases
We process data to create and secure accounts; provide, meter, maintain, and improve the contracted service; administer subscriptions and taxes; answer requests; prevent fraud and abuse; keep audit records; establish or defend legal claims; and comply with accounting, tax, sanctions, and other legal duties. Under GDPR/UK GDPR, the bases are contract performance or pre-contract steps (Art. 6(1)(b)), legal obligations (Art. 6(1)(c)), and legitimate interests in secure, reliable, supportable B2B operations and claim protection (Art. 6(1)(f)). Consent is used only where expressly requested and may be withdrawn prospectively.
Website and storage
The public site loads no analytics, advertising networks, social embeds, or externally hosted visual runtime assets and writes no public-page preference to persistent browser storage. Fonts, logo, and planetary texture maps are delivered from the same origin. If you sign in, Supabase uses browser storage strictly to persist and refresh the requested authenticated session. We do not use this site data for cross-context behavioral advertising.
Service providers and locations
Supabase supports authentication and account security in Frankfurt, Germany. Hetzner Online GmbH hosts the website, management API, calculations, operational databases, local backups, and logs in Helsinki, Finland. ALL-INKL.COM – Neue Medien Münnich in Germany relays transactional authentication mail from noreply@chronos-ephemeris.com and stores encrypted offsite disaster-recovery snapshots. Stripe provides hosted Checkout, subscription management, fraud prevention, payment, and tax technology. Stripe receives billing identity, address, tax, and payment information; ChronOS does not receive complete card details. Depending on the processing, Stripe may act as our processor or as an independent controller for its own legal, fraud, and compliance purposes.
International transfers
Core ChronOS hosting is in the European Economic Area. Providers and their approved subprocessors may process limited data in other countries for support, security, resilience, or payment operations. Where required, transfers rely on an adequacy decision, the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum or another lawful transfer mechanism, together with supplementary safeguards where appropriate. Information about the relevant safeguard can be requested at the privacy address above.
Retention
The authenticated Privacy & deletion center provides application-data exports and delayed account or organization deletion with a cancellation period. Request-level usage events are retained for 90 days, monthly usage aggregates for 730 days, webhook delivery diagnostics for 90 days, and ordinary non-legal audit events for 180 days. Completed export archives expire after 7 days. Compliance reviews are pseudonymized after 730 days. Contract acceptance, sanctions/compliance evidence, invoices, subscription and payment records are retained for applicable commercial, tax, claims and regulatory periods, commonly up to ten years under German law; deletion therefore removes operational tenant data while isolating and pseudonymizing records that must lawfully remain. Technical container and proxy logs rotate under bounded storage limits. Local database dumps are retained for 14 days. Encrypted offsite snapshots rotate through 14 daily, 8 weekly and 12 monthly recovery points, so a deleted item may remain in an inaccessible disaster-recovery snapshot for up to approximately 12 months. Backups are used only for disaster recovery and a restored system must be reconciled with intervening deletion obligations. Newly generated API secrets are shown once; only a one-way SHA-256 digest is persisted.
Sharing, sale, and automated decisions
We disclose data only to service providers, professional advisers, authorities where legally required, and a successor in a lawful business transaction. We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising. ChronOS does not make solely automated decisions that produce legal or similarly significant effects about account users.
Your rights
Subject to applicable law and verified identity, you may request access, correction, deletion, restriction, portability, or information about processing; object to legitimate-interest processing; and withdraw consent. EEA and UK individuals may complain to their competent supervisory authority, including the Bavarian State Office for Data Protection Supervision (BayLDA). Where applicable, California residents may request to know, correct, or delete covered information and exercise statutory rights without discrimination; because ChronOS does not sell or share personal information, there is no sale/sharing opt-out to exercise. Residents of Brazil, Canada, Australia, and other regions may exercise locally applicable access, correction, deletion, objection, or complaint rights through the same email address.
Required data, children, and changes
Account, security, and billing data marked as required is necessary to provide a paid subscription; without it we cannot create or maintain the service. The B2B service is not directed to children and must not be used to submit children’s personal data. Material notice changes will be posted here with a new version and, where appropriate, communicated to account holders.
Version, scope, and eligibility
chronos-terms-b2b-global-2026-07-16, effective July 16, 2026. These terms govern free and paid use of ChronOS Ephemeris by Neumann (a Nox Publishing Product). Self-service plans are offered only to entrepreneurs, companies, public-law entities, and persons acting predominantly for a business or professional purpose. By creating a workspace or ordering, you confirm authority to bind the named organization. Consumers must not use the self-service flow. The exact version can be saved or printed from the immutable legal bundle.
Provider and contract formation
The provider and contractual counterparty is Martin Neumann, trading as NOX Publishing, at the address in the imprint. Plan, currency, billing interval, usage limits, and taxes shown immediately before Checkout form part of the order. A paid contract is formed when Stripe confirms Checkout and ChronOS activates the subscription. The privacy notice, cancellation policy, and—where ChronOS processes customer personal data on the customer’s behalf—the Data Processing Addendum below form part of the agreement.
Service and documentation
ChronOS provides authenticated access to the documented ephemeris API and the functionality enabled for the selected plan. Supported bodies, time range, calculation profiles, precision declarations, rate and usage limits, and material compatibility changes are described in the service documentation. Preview or beta functionality may change or be withdrawn. Unless a separately signed service-level agreement states otherwise, no specific uninterrupted availability or response time is guaranteed.
Astronomical-output and high-risk-use notice
Results depend on the selected input, time standard, reference frame, ephemeris dataset, model, and documented uncertainty. Customers must validate input, select a suitable profile, and independently verify output before material reliance. ChronOS is an astrology and astronomical calculation product; it is not certified for spacecraft, aviation, maritime or terrestrial navigation, emergency response, medical devices, critical infrastructure, weapons, or other safety- or life-critical control. Output is not medical, legal, tax, investment, or other regulated professional advice.
Account and API-key security
Customers must provide accurate account and billing information, protect credentials, restrict keys to authorized systems, rotate exposed keys without delay, and notify the provider of suspected misuse. Activity performed with a valid customer credential is attributed to that customer unless the provider caused the compromise.
Acceptable use
Customers may integrate returned results into their products and internal workflows. They must not attack, probe, overload, scrape, or bypass service security or quotas; reverse engineer non-public service components; resell raw API access as an unmodified substitute; remove provenance or proprietary notices; use the service unlawfully; submit content they lack authority to process; or use results to deceive, discriminate unlawfully, or make prohibited high-impact automated decisions. The provider may apply reasonable technical safeguards to protect all customers.
International availability, export controls, and sanctions
The service is offered internationally only where lawful and may not be available in every territory, language, currency, or tax regime. Each party must comply with applicable export-control, embargo, and sanctions law. Customers may not access or use ChronOS for or on behalf of a prohibited person, entity, territory, or end use. The provider may reject, suspend, or terminate access where reasonably necessary for compliance.
Fees, taxes, renewal, and refunds
Recurring fees, billing interval, included capacity, currency, and taxes are disclosed before the binding order. Stripe processes payments, but the provider remains the seller of the ChronOS subscription. Subscriptions renew automatically for the selected interval until cancelled. Unless mandatory law, a duplicated charge, an incorrect charge, or an express written promise requires otherwise, paid B2B fees are non-refundable and unused capacity does not roll over. Failed payment may suspend paid entitlements after reasonable retry and notice. Customers are responsible for accurate billing and tax information and for taxes not collected at Checkout.
Customer data, data protection, and confidentiality
Customers control what they submit and remain responsible for lawful instructions, notices, permissions, data accuracy, and minimizing personal or sensitive data. The privacy notice explains processing for ChronOS’s own account and billing purposes; the Data Processing Addendum applies where ChronOS processes personal data on a customer’s behalf. Each party must protect the other party’s non-public business and technical information with reasonable care and use it only to perform or enforce the agreement. Confidentiality does not cover information that is public without breach, lawfully known, independently developed, or lawfully received from another source.
Intellectual property
ChronOS software, documentation, branding, and service design remain protected by applicable law. During the subscription, the customer receives a non-exclusive, non-transferable right to use the service for its business. The customer retains rights in its own applications and data.
Warranty, maintenance, and force majeure
The provider will operate the service with reasonable professional care and remedy reproducible material defects within a reasonable time. Documentation, third-party datasets, networks, and services may contain errors or become unavailable. Maintenance, security incidents, upstream outages, legal restrictions, and events beyond reasonable control may interrupt access. Statutory warranty rights are not excluded where exclusion would be invalid.
Liability
Liability is unlimited for intent, gross negligence, injury to life, body or health, fraudulent concealment, guarantees, and mandatory product or other statutory liability. For slightly negligent breach of an essential contractual duty, liability is limited to damage foreseeable and typical when the contract was formed. Otherwise, liability for slight negligence is excluded to the extent permitted by law. These limitations also protect employees, agents, and subcontractors and do not shift liability that cannot lawfully be limited.
Term, suspension, and termination
The contract runs for the selected billing interval. Ordinary cancellation takes effect at the end of the current paid period. The right to terminate for good cause remains. ChronOS may suspend access proportionately for material security risk, unlawful use, persistent payment default, or serious breach, and will give notice where reasonably possible.
Changes, notices, and assignment
Material changes will be announced in advance and will not retroactively reduce an already paid period without a valid reason. Operational, security, billing, and legal notices may be sent to the account email and are deemed received when delivered without an error notice. Customers may not assign the agreement without consent, except with an entire business transfer and written notice; the provider may assign it with the business while preserving customer rights.
Final provisions
The order, these terms, the cancellation policy, the applicable DPA, and any signed addendum form the complete agreement; a signed addendum prevails over conflicting standard terms. Failure to enforce a term is not a waiver. Invalid provisions are severed only to the extent necessary. German law applies, excluding conflict rules and the UN Convention on Contracts for the International Sale of Goods. For merchants, public-law entities, and customers without a general German venue, Nürnberg is the exclusive place of jurisdiction to the extent legally permitted. Mandatory law remains unaffected.
Version and scope
chronos-cancellation-b2b-global-2026-07-16, effective July 16, 2026. This policy applies to paid B2B self-service subscriptions purchased by eligible business customers in supported jurisdictions.
How to cancel
An organization owner or billing administrator can open “Manage billing” in the authenticated dashboard and cancel through the Stripe Customer Portal. If portal access is unavailable, send the organization name and billing email from an authorized account address to payment@chronos-ephemeris.com. A support request is not effective until it identifies the subscription and reaches this mailbox before renewal; we will confirm the effective date.
When cancellation takes effect
Ordinary cancellation stops renewal and takes effect at the end of the current paid billing period. Access and included capacity remain active until that date unless the subscription is terminated for cause or a refund is legally required.
Refunds, plan changes, and data
Cancellation does not by itself create a refund or credit for elapsed time, remaining days, or unused capacity. Refunds are provided only where mandatory law applies, a duplicated or incorrect charge occurred, or the provider expressly agrees in writing. Billing questions should be sent promptly to payment@chronos-ephemeris.com. Downgrades and cancellations may reduce quotas and paid features at the effective date. Account and workspace deletion is a separate request because billing, security, and acceptance records may remain subject to statutory retention duties.
Business customers only
Every ChronOS self-service plan, including the free evaluation tier, is intended only for customers acting in a business or professional capacity. Consumers must not create a workspace or complete paid Checkout.
Version and application
chronos-dpa-global-2026-07-16, effective July 16, 2026. This DPA is incorporated into the B2B Terms where the customer is a controller or processor and Martin Neumann, trading as NOX Publishing processes personal data contained in API inputs, workspace content, or support material on the customer’s documented instructions. It does not change processing for which the provider is an independent controller, such as account administration, security, or billing.
Instructions and details of processing
The subject matter is provision and support of the ChronOS service for the contract term; the nature is receipt, hosting, organization, calculation, transmission, logging, securing, deletion, and support access. The purpose is to return requested ephemeris calculations and operate the customer workspace. Data may include identifiers, dates, times, locations, chart inputs, account references, technical metadata, and other data chosen by the customer, relating to the customer’s users, clients, personnel, or other authorized individuals. The customer instructs processing through its configuration and API requests and must not submit prohibited or unnecessary sensitive data.
Processor duties
The provider will process covered data only on documented lawful instructions, including lawful transfers; ensure authorized personnel are bound by confidentiality; maintain appropriate technical and organizational measures; notify the customer if an instruction appears unlawful; and provide reasonable assistance with data-subject requests, security incidents, impact assessments, and regulator consultations, taking account of the nature of processing and information available.
Security
Measures include encrypted transport, secret separation, one-time API-key display with digest-only persistence, role and organization scoping, audit and security logging, backups, vulnerability and patch processes, access limitation, incident handling, and restoration procedures appropriate to the risk. Customers are responsible for endpoint security, credential rotation, access administration, lawful input, and their own backups of returned results.
Subprocessors
The customer gives general authorization for Hetzner Online GmbH (EEA hosting, database, logs, and local backup), Supabase, Inc. and its contracted infrastructure providers (authentication), ALL-INKL.COM – Neue Medien Münnich (transactional mail and encrypted offsite backup), and Stripe group companies and contracted infrastructure providers to the extent Stripe acts as a processor (billing technology). The provider remains responsible for processor duties it delegates and will publish or send notice at least 30 days before a material new subprocessor begins processing where feasible. A customer may raise a reasoned data-protection objection during that period; if no reasonable alternative is available, either party may terminate the affected service without penalty for future periods.
Transfers, incidents, deletion, and audits
Restricted transfers use the safeguards described in the privacy notice. The provider will notify the customer without undue delay after becoming aware of a personal-data breach affecting covered customer data and provide available information needed for the customer’s duties. At contract end, the provider will delete or return covered data within a reasonable operational period unless law requires retention; secured backups expire through normal rotation. On reasonable written request, the provider will supply information needed to demonstrate compliance and permit a proportionate audit no more than annually, subject to confidentiality, security, non-disruption, and the customer bearing its audit costs unless a material breach is found.
International transfers
A customer-to-provider transfer is assessed according to the parties’ actual locations and roles; an EEA customer’s transfer to the German provider is not described as a third-country transfer merely because a subprocessor has global operations. Restricted downstream transfers are governed by the transfer mechanism in the provider’s applicable agreement with that subprocessor. Where a direct customer transfer requires additional clauses or annex information, the parties will execute the appropriate current Standard Contractual Clauses, UK transfer terms, or other lawful instrument rather than treating this summary as a completed transfer annex. DPA and transfer requests must be sent to hello@chronos-ephemeris.com.