Privacy Policy
This Privacy Policy explains how ASTROX TECHNOLOGIES LTD collects, uses, and protects personal data in connection with the AstroX platform and website, in compliance with UK GDPR and the Data Protection Act 2018 and, where applicable to customers or end-customers in the European Economic Area, the EU GDPR.
1. Who we are
AstroX is a trading name of ASTROX TECHNOLOGIES LTD (Company No. 16584933), registered in England and Wales.
We are the data controller for personal data collected through our website and platform account management. For personal data your end-customers share through your AI agent (e.g., your shoppers' messages), we act as a data processor on your behalf — see our Data Processing Agreement.
Our processing of personal data is subject to the UK GDPR and the Data Protection Act 2018 and is supervised by the UK Information Commissioner's Office (ICO). We have not appointed a formal Data Protection Officer (DPO) but have designated support@astroxtech.com as our data protection contact for all privacy-related enquiries.
Contact our data team: support@astroxtech.com
2. What data we collect and why
We collect personal data in the following contexts:
a) Website enquiries and contact forms
- Data: Name, email address, company name, message content.
- Legal basis: Legitimate interests (responding to your enquiry and operating our business).
b) Account registration and management
- Data: Name, business email, company name, billing address, password (hashed).
- Legal basis: Performance of a contract (to provide you with access to the service).
c) Billing and payment
- Data: Billing name, email, company, country. Payment card details are handled directly by Stripe — we do not store full card numbers.
- Legal basis: Performance of a contract; legal obligation (financial record-keeping).
d) Service usage and platform activity
- Data: Login timestamps, feature usage, AI agent configuration, conversation logs, integration data (e.g., Shopify store data, WhatsApp contact identifiers).
- Legal basis: Performance of a contract; legitimate interests (maintaining service quality and security).
e) Technical and analytics data
- Data: IP address, browser type, pages visited, error logs.
- Legal basis: Legitimate interests (security, performance monitoring, fraud prevention).
3. Cookies
We currently use only strictly necessary cookies and storage: session authentication and CSRF protection in the platform, security cookies set by our CDN provider, and local storage for remembering your settings and choices (such as dismissing the cookie notice). These are required for the site and platform to function and cannot be disabled.
We do not currently set analytics, tracking, or marketing cookies on our website or platform. A notice banner is displayed on your first visit to our website; your acknowledgement is stored in your browser's local storage so you are not asked again. You can reset this at any time by clearing your browser's local storage or site data. Because only strictly necessary cookies are currently used, no consent choice is required under UK PECR. If we introduce any non-essential cookies or similar technologies (including those set by embedded third-party content), we will update this policy and present you with a consent choice before they are set, as required by UK PECR and equivalent laws.
4. How we share data
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share data with the following categories of service providers (“subprocessors”) solely to operate the service:
- Cloud hosting: Server infrastructure with vetted cloud providers. The platform is multi-tenant: each customer's data is logically separated by tenant identifiers and access controls on shared infrastructure. Specific hosting regions are confirmed on request; where infrastructure is located outside the UK/EEA, the transfer safeguards in Section 5 apply.
- Payment processing: Stripe, Inc. (PCI-DSS compliant).
- AI model services: OpenAI (for generating AI agent responses and for two-way conversation translation in the agent inbox). We use OpenAI's API under its business terms. OpenAI's published API data-usage policy states that API inputs and outputs are not used to train OpenAI's models and are retained only for a limited period for abuse monitoring and legal compliance (currently up to 30 days). We rely on OpenAI's published policy and our agreement with OpenAI; we do not control OpenAI's practices and will update this policy if they change materially. Your end-customers' conversation data remains your data.
- Messaging channels: Meta Platforms (WhatsApp Business Cloud API delivery, under your own Meta Business account).
- Email delivery: Transactional email providers for account notifications.
- eCommerce integrations: Shopify (data accessed under your authorisation).
- Website delivery & security: Cloudflare, Inc. (CDN, DDoS protection, DNS — USA/Global).
We require all subprocessors to maintain appropriate data protection and security standards. The list of subprocessors above may be updated from time to time as our infrastructure evolves. The latest version will always be available on this page.
5. International data transfers
Some of our subprocessors are based outside the UK and EEA, which means your personal data may be transferred internationally. The most significant transfer is described below:
- OpenAI (USA): When you or your end-customers interact with an AI agent on our platform, the message content (the text of the conversation) is sent to OpenAI's servers in the United States to generate a response. This is a core part of how the AI service works. Under OpenAI's published API data-usage policy, this data is used only to return the AI-generated reply, is not used to train OpenAI's models, and is retained only for a limited abuse-monitoring period (currently up to 30 days); we rely on that published policy and our agreement with OpenAI. We rely on Standard Contractual Clauses (SCCs) as the transfer mechanism for this transfer.
- Cloudflare (USA/Global): Web traffic to our website passes through Cloudflare's network for delivery and security purposes. Cloudflare may process limited request metadata (such as IP addresses) internationally. We rely on SCCs for this transfer.
- Stripe (USA): Payment card data is processed by Stripe in the USA. Stripe is PCI-DSS compliant and relies on UK IDTA / SCCs.
- Cloud hosting: Where our server infrastructure is located outside the UK/EEA, platform data is stored and processed in that region under UK IDTA / SCC safeguards. Current hosting regions are available on request at support@astroxtech.com.
For all international transfers, we have verified that appropriate safeguards are in place under UK GDPR, including the UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs) where applicable. You can request a copy of the relevant transfer mechanisms by contacting support@astroxtech.com.
6. Data retention
We retain personal data for as long as necessary to provide the service and meet our legal obligations:
- Account data: Retained while your account is active and for 12 months after closure, to handle any outstanding matters.
- Billing records: Retained for 6 years from the end of the relevant accounting period, as required by HMRC (VAT Notice 700/21 and Corporation Tax rules).
- Conversation and agent handoff logs: Retained for the life of your subscription so you and your team can access your own conversation history, then deleted after cancellation according to your subscription plan:
- Starter and Growth: within 30 days of cancellation
- Scale: within 90 days of cancellation
- Enterprise: within 365 days of cancellation, or as varied by written agreement in your Data Processing Agreement
- Order and customer history data: Synced from your connected store for the life of your subscription, then deleted on the same post-cancellation schedule as conversation logs above.
- Contact/enquiry data: Retained for 12 months from last contact.
On account closure, all conversation and end-customer data (which we hold as data processor on your behalf) is deleted within your plan's post-cancellation retention period set out above (30 days on Starter/Growth, 90 days on Scale, 365 days on Enterprise), except where a longer retention period is required by applicable law or an active dispute.
Important distinction: The post-closure deletion periods above apply to processor data (your end-customers' messages and contact details). It does not apply to controller data we hold in our own right — such as your account registration details, billing records, payment history, and security logs — which we retain for as long as required by law (e.g. 6 years for financial records under HMRC rules). Encrypted backup copies may also persist for up to 30 days after a deletion event before being fully purged.
7. Your rights under UK GDPR
You have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Ask us to correct inaccurate or incomplete data.
- Erasure: Request deletion of your personal data (subject to legal obligations).
- Restriction: Ask us to limit how we use your data in certain circumstances.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time.
To exercise any right, email support@astroxtech.com with the subject line Privacy Request. We will respond within one month of receiving a valid request. Where a request is complex or we receive several from you, we may extend this by up to two further months as permitted by UK GDPR, and we will tell you within the first month if an extension is needed. We may ask you to verify your identity before acting on a request.
8. Marketing communications
We will only send you marketing emails if you have opted in. You can unsubscribe at any time by clicking the “Unsubscribe” link in any marketing email or by emailing support@astroxtech.com. Opting out of marketing does not affect transactional and account-related communications.
9. Data deletion request
To request deletion of your account and associated data, email support@astroxtech.com with the subject line Data Deletion Request and include your account email or company name. We will action a verified deletion request within one month, subject to the retention periods in Section 6 and any legal retention obligations. Data we hold as processor on behalf of a business customer is deleted on that customer's instruction under our Data Processing Agreement.
10. Right to complain
If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with the UK's data protection authority:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113
We would appreciate the opportunity to address your concerns directly before you contact the ICO, so please reach out to us first.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and by updating the “Last updated” date at the top of this page. Continued use of the service after the effective date constitutes acceptance of the updated policy.
Language and governing law: This policy is drafted in English, and the English text is the sole binding version; any translation or summary is for convenience only. It forms part of, and is governed by the same law and jurisdiction as, our Terms of Service (the laws of England and Wales, exclusive jurisdiction of its courts), without prejudice to any mandatory data-protection rights you have under UK GDPR or the EU GDPR.
12. Contact
For any privacy-related questions: support@astroxtech.com
ASTROX TECHNOLOGIES LTD (Company No. 16584933), registered in England and Wales; registered office address as recorded at Companies House.
Document History
| Version | Effective Date | Summary of changes |
|---|---|---|
| 1.6 | 2 September 2026 | ICO statement reworded to a supervisory statement (s.1); cookie and no-sale statements made current-state rather than absolute (s.3, s.4); hosting described as logically separated multi-tenant (s.4); OpenAI training and retention described by reference to OpenAI's published policy in s.4 and s.5; data-subject request and deletion timings aligned with the UK GDPR one-month period and extension right (s.7, s.9); language and governing-law statement added (s.11); registered company details in contact (s.12). |
| 1.5 | 9 August 2026 | EU GDPR applicability statement added (intro); cookie section simplified to reflect strictly-necessary-only usage and notice banner (s.3); CookieYes removed from subprocessors — consent notice is provided natively (s.4); hosting-region wording aligned with DPA and hosting transfer safeguards added (s.4, s.5); OpenAI entry extended to cover inbox conversation translation (s.4); retention schedule aligned with the published post-cancellation periods — 30/30/90/365 days by plan (s.6). |
| 1.4 | 14 March 2026 | Added Cloudflare and CookieYes to subprocessor list (s.4); expanded s.5 with specific per-provider international transfer disclosure — OpenAI (USA), Cloudflare (USA/Global), Stripe (USA) — with transfer mechanisms named. |
| 1.3 | 14 March 2026 | Implemented cookie consent banner on all pages; updated s.3 to accurately describe banner behaviour. |
| 1.2 | 14 March 2026 | Updated cookie section to accurately reflect current status; added OpenAI no-training disclosure (s.4); added processor vs controller data retention split (s.6). |
| 1.1 | 14 March 2026 | Added ICO registration statement; DPO designation contact; cookie consent mechanism description (s.3); clarified data retention periods. |
| 1.0 | January 2026 | Initial release. |