Compliance & Data Governance
Privacy Policy
Last updated: September 2026. This policy outlines our commitment to safeguarding customer, client, and visitor information across all Astraiv Technologies systems.
1. Information We Collect
Astraiv Technologies collects information to provide higher-quality enterprise software, architectural consultations, and platform performance. This includes:
- **Direct Submissions**: Information you voluntarily provide when requesting a software architecture quote, submitting project requirements, applying for an open engineering role, or submitting client feedback (e.g. name, work email address, company name, telephone number, resume files, and project scope).
- **Technical Telemetry**: Information automatically generated through your interaction with our website and client portal, such as IP address, browser type, device identifiers, referring URLs, operating system, and pages visited, captured via privacy-focused telemetry.
- **Client Engagement Data**: For contracted enterprise clients, project specifications, architectural repositories, ticket communications, and billing metrics managed through encrypted database connections.
2. How We Use Your Information
We utilize gathered information exclusively for legitimate business, architectural, and contractual purposes:
- Delivering, operating, testing, and optimizing custom software engineering platforms.
- Responding to project inquiries, preparing commercial proposals, and scheduling technical discovery sessions.
- Administering client portal accounts, support tickets, and role-based access controls.
- Complying with regulatory, tax, accounting, and institutional security mandates.
- Evaluating engineering job applicants and scheduling founder interviews.
- Protecting our systems against unauthorized access, credential stuffing, DDoS attacks, and security vulnerabilities.
3. Data Security & Storage Standards
Astraiv adheres to strict institutional security benchmarks:
- **Encryption**: All data in transit is encrypted using modern TLS 1.3 cryptographic suites. Persistent data at rest is encrypted using AES-256 standards across PostgreSQL clusters and Cloudflare R2 object storage.
- **Access Control**: Strict principle of least privilege (PoLP) and multi-factor authentication (MFA) govern developer and system access to production databases.
- **Tenant Isolation**: Client data in multi-tenant environments is segregated through Row-Level Security (RLS) policies and dedicated tenant partitions.
- **Data Retention**: We retain commercial records and communication logs only as long as necessary to satisfy contractual obligations or statutory requirements.
4. Third-Party Sub-Processors
We partner with world-class, SOC-2 compliant cloud infrastructure providers to host and secure our platforms:
- **Cloud Infrastructure**: Amazon Web Services (AWS) and Cloudflare for global edge delivery, caching, and CDN routing.
- **Database & Persistence**: Managed PostgreSQL via Supabase and dedicated VPC database clusters.
- **Analytics & Telemetry**: Google Analytics 4 (configured with IP anonymization) to monitor Core Web Vitals and site usability.
We do not sell, rent, or monetize client or visitor data to third-party data brokers or marketing conglomerates.
5. Your Rights (GDPR & CCPA Compliance)
Depending on your jurisdiction, you have statutory privacy rights regarding your personal information:
- **Access & Portability**: Request a copy of the personal information we maintain concerning you in a structured, machine-readable format.
- **Correction & Rectification**: Request correction of any incomplete or inaccurate data.
- **Erasure ("Right to be Forgotten")**: Request deletion of your personal records, subject to ongoing legal or contractual record-retention requirements.
- **Objection & Restriction**: Object to our processing of your personal data or request restricted processing.
To exercise any of these rights, contact our Data Governance team at privacy@astraivtechnologies.com.
6. Contact & Data Governance Officer
If you have questions, concerns, or requests regarding this Privacy Policy or our security posture, please reach out directly:
- **Email**: privacy@astraivtechnologies.com / info@astraivtechnologies.com
- **Mailing Address**: Astraiv Technologies, Ashoknagar, Kolkata, West Bengal, India
- **Response SLA**: Inquiries are reviewed and answered within 48 business hours.
Have security compliance questions or need an Enterprise Data Processing Agreement (DPA)?Contact Legal & Security