Privacy Policy

Your privacy matters to us. Learn how we collect, use, and protect your information.

Last updated: January 11, 2025

Introduction

Welcome to Astric.ai (“we,” “our,” or “us”). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our business automation platform.

By using Astric.ai, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.

Information We Collect

1. Information You Provide

  • Account Information: Name, email address, phone number, company name
  • Profile Data: User preferences, settings, and customization choices
  • Payment Information: Billing address, payment method details (processed securely by our payment providers)
  • Customer Data: Information you input into our CRM and automation systems
  • Communications: Messages you send to our support team

2. Automatically Collected Information

  • Usage Data: How you interact with our platform, features used, time spent
  • Device Information: Browser type, operating system, IP address
  • Cookies: We use cookies to enhance your experience (see our Cookie Policy)
  • Log Data: Access times, pages viewed, errors encountered

3. Information from Third Parties

  • Integration Data: Data from services you connect (WhatsApp, email, etc.)
  • Authentication: If you sign in using Google or other OAuth providers

How We Use Your Information

We use the collected information for various purposes:

  • Provide Services: Deliver, maintain, and improve Astric.ai
  • Account Management: Create and manage your account
  • Customer Support: Respond to your requests and provide assistance
  • Communication: Send service updates, security alerts, and support messages
  • Marketing: Send promotional communications (you can opt out anytime)
  • Analytics: Understand usage patterns to improve our platform
  • Security: Detect, prevent, and address fraud and security issues
  • Legal Compliance: Comply with legal obligations and enforce our terms

Data Security

We take the security of your data seriously and implement industry-standard measures:

  • Encryption: All data is encrypted in transit (TLS/SSL) and at rest
  • Access Controls: Strict role-based access with multi-factor authentication
  • Infrastructure: Hosted on secure cloud infrastructure (Supabase/AWS)
  • Regular Audits: Periodic security assessments and penetration testing
  • Data Isolation: Multi-tenant architecture with Row Level Security (RLS)
  • Backup: Regular automated backups with disaster recovery procedures
  • Monitoring: 24/7 system monitoring and intrusion detection

Note: While we implement robust security measures, no method of transmission over the internet is 100% secure. We strive to use commercially acceptable means to protect your data.

Data Sharing and Disclosure

We may share your information in the following situations:

  • Service Providers: Third-party vendors who help us provide services (hosting, payment processing, email delivery)
  • Business Transfers: In connection with mergers, acquisitions, or asset sales
  • Legal Requirements: When required by law or to protect our rights
  • With Your Consent: When you explicitly agree to share information

We do NOT: Sell your personal information to third parties or use it for purposes unrelated to providing our services.

Your Privacy Rights

You have the following rights regarding your personal information:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your personal data (with some exceptions)
  • Portability: Export your data in a machine-readable format
  • Restriction: Request restriction of processing your data
  • Objection: Object to processing for marketing purposes
  • Withdraw Consent: Withdraw consent at any time where we rely on consent

To exercise these rights, please contact us at privacy@astric.ai

Data Retention

We retain your personal information only as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

  • Active Accounts: Data retained while your account is active
  • Deleted Accounts: Most data deleted within 30 days of account deletion
  • Backups: Backup copies may persist for up to 90 days
  • Legal Requirements: Some data retained longer for compliance purposes

International Data Transfers

Astric.ai is based in India. If you access our services from outside India, please be aware that your information may be transferred to, stored, and processed in India and other countries where our service providers operate.

We take appropriate measures to ensure that your personal information receives adequate protection wherever it is transferred, in accordance with applicable data protection laws.

Children's Privacy

Astric.ai is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you become aware that a child has provided us with personal information, please contact us immediately.

Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by:

  • Posting the new Privacy Policy on this page
  • Updating the “Last updated” date at the top
  • Sending you an email notification for material changes

We encourage you to review this Privacy Policy periodically for any changes. Changes are effective when posted on this page.

Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us:

Email: privacy@astric.ai

Support: support@astric.ai

Address: 2151/9b 3rd Floor, New Patel Nagar, Shadipur, New Delhi 110008, India