Legal
Privacy Policy
This Privacy Policy explains how ASTRISS collects, uses, shares, and protects personal data, in compliance with the UK GDPR, EU GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
On this page
ASTRISS (“ASTRISS”, “we”, “us”, or “our”) respects your privacy and is committed to protecting personal data. This Privacy Policy applies to visitors to our website, trial users, prospective clients who submit enquiries, and paying B2B clients and their authorised users (collectively, “you”).
1. Data Controller Identification
For the purposes of UK GDPR and EU GDPR, ASTRISS is the Data Controllerin respect of personal data collected through our website, marketing activities, and client account administration. Where ASTRISS processes Client Data (i.e. a client’s own customer or prospect data) through the Astriss GEO, Velocity, ICP, or Core modules, ASTRISS acts as a Data Processoron that client’s behalf, as further described in Section 2.3 below and in our standard Data Processing Agreement (DPA).
For any privacy or data protection enquiry, including exercising your rights under Section 6, please contact our Data Protection team at privacy@astriss.com.
2. Personal Data We Collect
2.1 Information You Provide Directly
We collect personal data that you voluntarily submit to us, including via our “Book Demo” and contact forms, when creating a Platform account, or when corresponding with our team. This may include:
- full name, company name, and job title;
- work email address and phone number;
- meeting preferences and scheduling details submitted via our Calendly booking integration; and
- billing details (processed directly by our payment processor, Stripe — see Section 4).
2.2 Information Collected Automatically
When you visit our website or use the Platform, we and our service providers automatically collect certain technical information, including:
- IP address and approximate geo-location;
- device and browser type, and device fingerprint data;
- referral source, pages visited, and on-site interaction data (clicks, scroll depth, session duration); and
- cookies and similar tracking technologies, as described in Section 7 (Cookie Policy).
2.3 Client Data Processed Through ASTRISS Modules
Where a client uses Astriss GEO, Velocity, ICP, or Core, the Platform may process that client’s own customer, prospect, or audience data (for example, CRM records synced for pipeline scoring, or intent signals ingested for audience targeting). This Client Data is processed solely on the documented instructions of the client and under the terms of a Data Processing Agreement (DPA), which forms part of the client’s Order Form. ASTRISS does not use Client Data processed in this capacity for its own marketing purposes.
3. Lawful Basis for Processing (UK GDPR)
We rely on the following lawful bases under Article 6 UK GDPR, depending on the purpose of processing:
4. Data Sharing & Third-Party Processors
We share personal data only with trusted third-party processors who help us operate the Platform and our business, under appropriate contractual safeguards. These include:
- Cloudflare — content delivery network (CDN), DNS, and web application security;
- Vercel / AWS — application hosting and infrastructure;
- Stripe — payment processing and subscription billing;
- Calendly — demo and meeting scheduling;
- analytics providers, for aggregated website and product usage analysis; and
- CRM and email delivery tools used to manage client relationships and respond to enquiries.
ASTRISS does not, and will not, sell, rent, or trade your personal data to third parties for their own marketing purposes. Personal data is shared only with processors acting on our instructions, or where required by law.
5. International Data Transfers & Retention
5.1 International Transfers
Some of our third-party processors operate infrastructure outside the UK and European Economic Area (EEA). Where personal data is transferred outside the UK/EEA, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Addendum, the EU Standard Contractual Clauses (SCCs), or reliance on an applicable adequacy regulation, so that your data continues to benefit from a level of protection equivalent to that provided in the UK.
5.2 Data Retention
We retain personal data only for as long as necessary for the purposes described in this Policy. As a general rule:
- client account and Client Data is retained for the duration of the active subscription, plus a reasonable period thereafter to allow for account reactivation or export requests;
- billing, invoicing, and financial records are retained for six (6) years, in line with standard UK statutory financial record-keeping requirements; and
- website enquiry and marketing data is retained until you withdraw consent or object to further processing, or for a reasonable period of inactivity, whichever is sooner.
6. Your Individual Rights (UK GDPR)
Subject to certain exemptions and conditions, you have the following rights in relation to your personal data:
Access— request a copy of the personal data we hold about you (a Subject Access Request, or “SAR”).
Rectification — ask us to correct inaccurate or incomplete data.
Erasure— request deletion of your data (the “right to be forgotten”), subject to legal retention requirements.
Restriction — ask us to limit how we use your data in certain circumstances.
Portability — receive your data in a structured, commonly used, machine-readable format.
Objection — object to processing based on legitimate interests or direct marketing at any time.
To exercise any of these rights, please contact privacy@astriss.com. We will respond within one month, as required by UK GDPR.
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner’s Office (ICO), at ico.org.uk. We would, however, appreciate the opportunity to address your concerns directly before you approach the ICO.
7. Cookie Policy & Tracking Declaration
In line with PECR and UK GDPR, we categorise the cookies and similar technologies used on our website as follows:
| Category | Purpose | Consent required? |
|---|---|---|
| Strictly Necessary | Essential for the website and Platform to function, including session management, load balancing, and security. Cannot be disabled. | No — legitimate interest |
| Performance / Analytics | Help us understand how visitors use our website and Platform, so we can measure and improve performance. | Yes — consent |
| Marketing | Used to measure the effectiveness of our marketing and, where applicable, personalise content across sessions. | Yes — consent |
You can adjust or withdraw your cookie preferences at any time via the cookie preference link in our website footer, or by changing your browser settings to block or delete cookies. Please note that disabling strictly necessary cookies may affect the functionality of the website and Platform.
See also our Terms and Conditions for the commercial terms governing use of the ASTRISS Platform.
This document is a general template provided for informational purposes and does not constitute legal advice. ASTRISS recommends this page be reviewed by a qualified data protection specialist prior to publication.