Why your privacy matters to us
At Emelari, we work with something deeply personal: your energy, your timing, your relationships, and the way you move through everyday life. When you share your birth details and your stories with us, we know you are trusting us with more than “just data” – you are trusting us with a part of your inner world.
This Privacy Policy is here to make that trust concrete. It explains which personal data we collect, why we collect it, how we protect it, and which rights you have under data protection rules (including the GDPR and the Danish Data Protection Act). We have tried to write it in clear, calm language so you can understand what is going on behind the scenes without needing a law degree.
This policy applies when you visit emelari.com, use our forms, receive our free or paid Human Design products, participate in any programs, and when we communicate with you in that context. The legal responsibility for your data sits with 20TWENTY ApS (Emelari), and the intention behind our choices sits with our founder, Celeste Elwood, and the team who build and run this space. If anything in this policy feels unclear or worrying, you are always welcome to reach out to us.
With care for your data and your inner world,
The Emelari team
on behalf of 20TWENTY ApS (Emelari)
1. Data controller and contact
1.1 The company that is the data controller for the processing of your personal data is 20TWENTY ApS, Sandkaj 21, ground floor, 2150 Nordhavn, Denmark, CVR no. 33262426. In this policy, we are referred to as “Emelari,” “we,” “us,” or “our.”
1.2 If you have any questions about this Privacy Policy or about our processing of your data, you can always contact us at hello@emelari.com.
2. Which personal data we process
2.1 When you use Emelari, we typically process identity and contact information such as your name and email address. You may also choose to provide us with additional information, for example how you are related to another person if you order a relationship report.
2.2 In order to generate Human Design reports, we ask for birth data. This includes your date of birth, your time of birth (as precisely as possible), and your place of birth (city and country). If you order a report that also involves other people, for example a partner or a child, we will typically receive the same types of birth data about them.
2.3 In connection with the purchase of paid products, we process information about the purchase itself, including which products you ordered, the time of the purchase, and basic transaction information. Our payment provider Stripe handles the actual payment and processes payment card data. We do not receive your full card details but may have access to information such as transaction ID, payment status, and in some cases masked card details (for example, the last digits of the card number).
2.4 When you visit our website, technical and usage-related information is also collected. This may include your IP address, information about the device and browser you use, and log information about how the site is used. In addition, cookies and similar online identifiers may be stored. More detailed information about cookies appears in our cookie information on the website.
3. Purposes and legal bases
3.1 When you order a free Human Design “light” product, we process your data in order to generate and deliver the free report to you and, where relevant, send you a few explanatory emails that make it easier to understand and use the report. The processing is based on your consent when you enter your information and ask to receive the report, cf. GDPR Article 6(1)(a).
3.2 When you purchase a paid product, for example a full blueprint report, we process your data in order to complete the purchase, generate the report, deliver it to you, and administer the purchase, including receipts and any subsequent support. Here, the legal basis is that the processing is necessary for the performance of the contract with you, cf. GDPR Article 6(1)(b). As regards storage of accounting materials, the processing is necessary for us to comply with our legal obligations under bookkeeping and accounting legislation, cf. GDPR Article 6(1)(c).
3.3 When you order a relationship or family report that also involves another person, we process information about that person (for example partner or child) in order to generate the requested report. For you as the customer, the processing is based on the same legal bases as mentioned above. For the other person, the legal basis is our legitimate interest in being able to deliver the product you have specifically ordered, cf. GDPR Article 6(1)(f). We limit the use of information about the partner or child to this purpose and do not use it for direct marketing directed at that person.
3.4 When we respond to your inquiries, assist you with issues, improve our services, or ensure stable operation and security of the website, we process information such as contact information, technical log data, and possibly the content of your inquiry. The legal basis is our legitimate interest in providing good service, improving our products, and ensuring a stable and secure platform, cf. GDPR Article 6(1)(f).
3.5 If you sign up to receive emails with inspiration, explanations, news, and offers from Emelari, we process your contact information and information about which products you have received or purchased. The legal basis for the marketing itself is your consent, cf. GDPR Article 6(1)(a), in conjunction with the Danish Marketing Practices Act. In certain cases, we may also rely on our legitimate interests in marketing our own similar products to existing customers, cf. GDPR Article 6(1)(f), and the rules in the Marketing Practices Act on “soft opt-in.” You can unsubscribe from marketing at any time, including via the unsubscribe link in our emails.
4. Where we get your data from
4.1 Most of the personal data we receive comes directly from you when you fill out our forms, order products, write to us, or sign up for emails. This applies both to your own information and to information about other people that you choose to include in a report.
4.2 When a report involves a partner, a child, or another person, it is you who chooses to share that person’s information with us. We normally do not obtain information about your close relations from other sources.
4.3 Technical data, for example IP address, device information, and cookie ID, is collected automatically through your use of the website. This happens through our own system, our hosting provider, and any analytics and cookie providers.
5. Profiling and automated processing
5.1 When we generate your Human Design reports, this is done using automated processing. Your birth data is used to calculate a Human Design chart, and texts and explanations are linked to the chart according to fixed systems and rules. The result is a personal report that describes patterns, potentials, and recommendations.
5.2 This type of processing can be considered profiling within the meaning of the GDPR. However, we do not make automated decisions that have legal effects or similarly significant impact on you within the meaning of GDPR Article 22. The reports are intended as a tool for inspiration and reflection and do not replace professional advice from, for example, a doctor, psychologist, lawyer, or financial advisor.
6. Recipients and processors
6.1 To operate Emelari, we use a number of external providers that process personal data on our behalf and under our instructions. This applies in particular to providers of hosting, email services, payment solutions, and analytics and statistics. We have entered into data processing agreements with these providers in accordance with the GDPR.
6.2 Our website and data are hosted by DuelHost, which is established in the EU. DuelHost processes personal data as a processor on our behalf and follows our instructions.
6.3 Payments are handled through Stripe. Stripe acts both as a data processor and as an independent data controller for certain processing activities, for example in connection with fraud prevention and chargebacks. Stripe receives payment information directly from you and stores it in accordance with its own terms. We refer to Stripe’s own privacy policy for more detailed information.
6.4 Where necessary, we may also disclose information to other recipients, for example our accountant, bank, authorities such as the Danish Tax Agency (Skattestyrelsen), or legal advisors, if required by law or necessary to handle specific matters or claims. We do not sell your personal data to third parties.
7. Transfers to third countries
7.1 Some of our providers or their sub-processors may be established outside the EU/EEA, for example in the United States. If we transfer personal data to countries outside the EU/EEA, this only occurs where there is a valid transfer basis under the GDPR.
7.2 A valid transfer basis may be the European Commission’s standard contractual clauses or another lawful mechanism designed to ensure an adequate level of protection for your data. You are welcome to contact us if you would like more information about any transfers to third countries and the specific safeguards we use.
8. Retention periods
8.1 We store your personal data for as long as necessary for the purposes for which it was collected and in accordance with the GDPR principles of data minimization and storage limitation.
8.2 Information used for free reports is stored for a period that allows you to access the report and allows us to maintain normal operations, error correction, and follow-up. As a rule, this will be in the order of 12–24 months, after which the information is anonymized or deleted, unless there is another legitimate purpose.
8.3 Information relating to paid products is stored for as long as necessary to deliver the product, handle any complaints, and provide support. In addition, accounting and transaction information is stored for the period required by bookkeeping and accounting legislation, typically up to 5 years after the end of the financial year to which the information relates.
8.4 Information used for email marketing is stored until you withdraw your consent or we assess that you are no longer active, for example after an extended period without opening or interacting. After this, the information is deleted or anonymized in the mailing list.
8.5 Technical data and log information are stored for a reasonable period for purposes such as error correction, security, and statistics, typically for months rather than years, unless specific security incidents make it necessary to store them longer.
9. Information about other people and children
9.1 When you enter information about other people, for example a partner or a child, in order to order a report, it is you who chooses to share their information with us. We use this information to generate the report you ordered and deliver the report to you. We do not use this information to create independent profiles for the other person or to send direct marketing to them, unless they later register with us themselves.
9.2 Emelari is fundamentally aimed at adult users. However, we are aware that some users wish to use Human Design to better understand their children. When we generate reports about children, we assume that you have parental responsibility or a similar legal basis, and we strive to provide descriptions that are resource-oriented and not stigmatizing.
9.3 If you believe that we have received information about a child or another person in a way that is not appropriate or lawful, we encourage you to contact us so that we can consider deletion or restriction of the processing.
10. Your rights
10.1 You have the right to obtain information about which personal data we process about you and to receive a copy of the data.
10.2 You have the right to have incorrect or incomplete information about you corrected.
10.3 In certain cases, you have the right to have information about you deleted before we would normally delete it, for example if we no longer have a legitimate purpose for storing it.
10.4 In certain situations, you may request that the processing of your personal data be restricted, for example if you contest the accuracy of the information or if you have objected to the processing.
10.5 In some cases, you have the right to data portability, which means that you can receive your information in a structured, commonly used, and machine-readable format and have it transmitted to another data controller, if technically feasible.
10.6 When we process your information on the basis of our legitimate interests, you have the right to object to the processing. If you object, we will make a specific assessment as to whether our legitimate interests outweigh your interests and rights. You always have the right to object to processing for direct marketing purposes, and if you do, we will cease such processing.
10.7 If we process your information on the basis of your consent, you may withdraw your consent at any time. This does not affect the lawfulness of the processing carried out before you withdrew your consent.
10.8 If you wish to exercise one or more of your rights, you can contact us at hello@emelari.com. In that context, we may ask you for additional information to ensure that we only provide access to data to the correct person.
11. Complaint to the Danish Data Protection Agency
11.1 If you are dissatisfied with the way we process your personal data, we would very much like to hear from you so that we can try to find a solution.
11.2 You also have the right to lodge a complaint with the Danish Data Protection Agency. The Agency can be contacted at:
Datatilsynet
Carl Jacobsens Vej 35
2500 Valby
12. Security
12.1 We take the security of your personal data seriously and have implemented appropriate technical and organizational measures to protect it against accidental or unlawful destruction, loss, or alteration and against unauthorized access or disclosure.
12.2 The measures include, among other things, limited access to personal data, the use of secure systems, and ongoing assessment and adjustment of our security measures.
13. Cookies and similar technologies
13.1 When you visit emelari.com, we may use cookies and similar technologies to make the website function technically, remember your choices and settings, compile statistics, and improve the user experience. In some cases, cookies may also be used to tailor content and marketing.
13.2 More detailed information about our use of cookies, including which types we use, for which purposes, and how long they are stored, appears in our cookie information on the website. There, you can also change or withdraw your cookie consent at any time.
14. Changes to this Privacy Policy
14.1 We may update this Privacy Policy from time to time, for example if we launch new products, change our processing activities, or if the rules change. The version in force at any time will always be available on emelari.com.
14.2 If there are material changes that significantly affect you, we may also choose to inform you directly, for example by email.
15. Contact
15.1 You are always welcome to contact us if you have questions about this Privacy Policy or about our processing of your personal data. You can write to hello@emelari.com or send a letter to:
20TWENTY ApS / Emelari
Sandkaj 21, ground floor
2150 Nordhavn
Denmark










