ASTRISS

Legal

Privacy Policy

This Privacy Policy explains how ASTRISS collects, uses, shares, and protects personal data, in compliance with the UK GDPR, EU GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

On this page

ASTRISS (“ASTRISS”, “we”, “us”, or “our”) respects your privacy and is committed to protecting personal data. This Privacy Policy applies to visitors to our website, trial users, prospective clients who submit enquiries, and paying B2B clients and their authorised users (collectively, “you”).

1. Data Controller Identification

For the purposes of UK GDPR and EU GDPR, ASTRISS is the Data Controllerin respect of personal data collected through our website, marketing activities, and client account administration. Where ASTRISS processes Client Data (i.e. a client’s own customer or prospect data) through the Astriss GEO, Velocity, ICP, or Core modules, ASTRISS acts as a Data Processoron that client’s behalf, as further described in Section 2.3 below and in our standard Data Processing Agreement (DPA).

Data Protection Contact

For any privacy or data protection enquiry, including exercising your rights under Section 6, please contact our Data Protection team at privacy@astriss.com.

2. Personal Data We Collect

2.1 Information You Provide Directly

We collect personal data that you voluntarily submit to us, including via our “Book Demo” and contact forms, when creating a Platform account, or when corresponding with our team. This may include:

  • full name, company name, and job title;
  • work email address and phone number;
  • meeting preferences and scheduling details submitted via our Calendly booking integration; and
  • billing details (processed directly by our payment processor, Stripe — see Section 4).

2.2 Information Collected Automatically

When you visit our website or use the Platform, we and our service providers automatically collect certain technical information, including:

  • IP address and approximate geo-location;
  • device and browser type, and device fingerprint data;
  • referral source, pages visited, and on-site interaction data (clicks, scroll depth, session duration); and
  • cookies and similar tracking technologies, as described in Section 7 (Cookie Policy).

2.3 Client Data Processed Through ASTRISS Modules

Where a client uses Astriss GEO, Velocity, ICP, or Core, the Platform may process that client’s own customer, prospect, or audience data (for example, CRM records synced for pipeline scoring, or intent signals ingested for audience targeting). This Client Data is processed solely on the documented instructions of the client and under the terms of a Data Processing Agreement (DPA), which forms part of the client’s Order Form. ASTRISS does not use Client Data processed in this capacity for its own marketing purposes.

3. Lawful Basis for Processing (UK GDPR)

We rely on the following lawful bases under Article 6 UK GDPR, depending on the purpose of processing:

Performance of a Contract
To create and administer your Platform account, deliver the Services set out in an Order Form, process payments, and provide client support.
Legitimate Interests
For business-to-business direct communications about our Services, to safeguard the Platform against fraud, abuse, and unauthorised access, to analyse and improve platform performance, and to maintain the security of our systems. We balance these interests against your rights and freedoms before relying on this basis.
Consent
For non-essential analytics and marketing cookies, and for newsletter or marketing email subscriptions where consent is legally required (in particular under PECR). You may withdraw consent at any time as described in Section 7.
Legal Obligation
Where we are required to retain or disclose data to comply with applicable tax, accounting, or regulatory obligations.

4. Data Sharing & Third-Party Processors

We share personal data only with trusted third-party processors who help us operate the Platform and our business, under appropriate contractual safeguards. These include:

  • Cloudflare — content delivery network (CDN), DNS, and web application security;
  • Vercel / AWS — application hosting and infrastructure;
  • Stripe — payment processing and subscription billing;
  • Calendly — demo and meeting scheduling;
  • analytics providers, for aggregated website and product usage analysis; and
  • CRM and email delivery tools used to manage client relationships and respond to enquiries.
We Never Sell Your Data

ASTRISS does not, and will not, sell, rent, or trade your personal data to third parties for their own marketing purposes. Personal data is shared only with processors acting on our instructions, or where required by law.

5. International Data Transfers & Retention

5.1 International Transfers

Some of our third-party processors operate infrastructure outside the UK and European Economic Area (EEA). Where personal data is transferred outside the UK/EEA, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Addendum, the EU Standard Contractual Clauses (SCCs), or reliance on an applicable adequacy regulation, so that your data continues to benefit from a level of protection equivalent to that provided in the UK.

5.2 Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy. As a general rule:

  • client account and Client Data is retained for the duration of the active subscription, plus a reasonable period thereafter to allow for account reactivation or export requests;
  • billing, invoicing, and financial records are retained for six (6) years, in line with standard UK statutory financial record-keeping requirements; and
  • website enquiry and marketing data is retained until you withdraw consent or object to further processing, or for a reasonable period of inactivity, whichever is sooner.

6. Your Individual Rights (UK GDPR)

Subject to certain exemptions and conditions, you have the following rights in relation to your personal data:

Your rights at a glance

Access— request a copy of the personal data we hold about you (a Subject Access Request, or “SAR”).
Rectification — ask us to correct inaccurate or incomplete data.
Erasure— request deletion of your data (the “right to be forgotten”), subject to legal retention requirements.
Restriction — ask us to limit how we use your data in certain circumstances.
Portability — receive your data in a structured, commonly used, machine-readable format.
Objection — object to processing based on legitimate interests or direct marketing at any time.

To exercise any of these rights, please contact privacy@astriss.com. We will respond within one month, as required by UK GDPR.

Right to Complain to the ICO

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner’s Office (ICO), at ico.org.uk. We would, however, appreciate the opportunity to address your concerns directly before you approach the ICO.

7. Cookie Policy & Tracking Declaration

In line with PECR and UK GDPR, we categorise the cookies and similar technologies used on our website as follows:

CategoryPurposeConsent required?
Strictly NecessaryEssential for the website and Platform to function, including session management, load balancing, and security. Cannot be disabled.No — legitimate interest
Performance / AnalyticsHelp us understand how visitors use our website and Platform, so we can measure and improve performance.Yes — consent
MarketingUsed to measure the effectiveness of our marketing and, where applicable, personalise content across sessions.Yes — consent

You can adjust or withdraw your cookie preferences at any time via the cookie preference link in our website footer, or by changing your browser settings to block or delete cookies. Please note that disabling strictly necessary cookies may affect the functionality of the website and Platform.

See also our Terms and Conditions for the commercial terms governing use of the ASTRISS Platform.

This document is a general template provided for informational purposes and does not constitute legal advice. ASTRISS recommends this page be reviewed by a qualified data protection specialist prior to publication.