Legal

Privacy Policy

Last updated: July 17, 2026

This Privacy Policy explains what data Astryón collects when you use our website at astryon.in and the Astryón software-as-a-service product, how we use and protect that data, who we share it with, and what your rights are. It applies to visitors of our website, users of our app, teammates you invite into a workspace, and clients you invite into a client portal.

1. Who we are

Astryón ("we", "us", "our") is the data controller for personal information collected through astryon.in and the Astryón product. You can reach our privacy contact at founder@astryon.in.

2. Data we collect

Account data

When you sign up we collect your name, email address, and a hashed password. If you sign in through a supported identity provider we collect the profile information that provider returns to us (typically name, email, and avatar URL).

Workspace and product data

When you use Astryón we store the information you and your teammates create in the app: the agency name, teammates and their roles, clients, onboarding records, templates, checklist items, requests, notes, activity, and any files uploaded to Astryón Storage. Client portal submissions from your clients are stored inside your workspace and are visible to teammates you have granted access to.

Billing data

Payments are processed by Paddle.com Market Limited ("Paddle"), our merchant of record. Paddle collects and processes the payment details you enter at checkout; Astryón only receives limited billing metadata such as your Paddle customer ID, subscription status, plan, country, invoice history, and the last four digits and brand of the card used. We never see or store your full card number.

Usage and technical data

We collect standard technical information such as IP address, browser, device, referring URL, pages visited, features used, and error logs. This helps us keep the Service secure, diagnose problems, and improve the product.

Support communications

When you contact us at support@astryon.in or founder@astryon.in, we keep your message and our response so we can help you and improve our support.

3. How we use your data

  • Provide, operate, secure, and improve the Service and the client portal;
  • Authenticate you, keep your session, and enforce role-based access inside your workspace;
  • Send transactional emails you need to use the Service (invites, password resets, receipts, security alerts, and important account notices);
  • Diagnose bugs, monitor performance, and prevent fraud and abuse;
  • Comply with legal, tax, and accounting obligations.

We do not sell your personal data and we do not use your workspace content to train third-party AI models.

4. Legal bases (GDPR)

Where the GDPR applies, we rely on the following legal bases: contract (to provide the Service you signed up for), legitimate interests (to keep the Service secure and improve it), legal obligation (to keep tax and accounting records), and consent where we ask for it (for example, for optional analytics cookies).

5. Sharing and sub-processors

We share personal data only with sub-processors we need to run the Service, under contracts that require them to protect your data and use it only for the purposes we authorize. Our current sub-processors include:

  • Supabase — database, authentication, and file storage;
  • Paddle — checkout, payment processing, tax, and invoicing (as merchant of record);
  • Our hosting and CDN provider — application hosting and content delivery;
  • Transactional email provider — sending invites, receipts, and other operational emails.

We may also disclose personal data when required by law, to protect our rights or the safety of users, or in connection with a business transfer such as a merger or acquisition, in which case we will notify you.

6. International transfers

Our sub-processors may host and process data outside your country, including in the European Economic Area and the United States. Where required, we rely on Standard Contractual Clauses and equivalent safeguards approved by the relevant data protection authorities.

7. Retention

We keep your account and workspace data for as long as your account is active. If you delete your account, we delete or anonymize workspace data within 30 days, except for records we are required to keep (for example invoices, tax records, or logs needed for fraud prevention). Backups are rotated and purged on a rolling basis.

8. Security

Personal data is encrypted in transit (TLS) and at rest by our infrastructure providers. Access to production systems is limited to a small number of authorized team members and protected by strong authentication. We monitor the Service for security events and will notify affected users of a personal data breach without undue delay where required by law.

9. Your rights

Depending on where you live, you may have the right to access, correct, export, restrict, object to, or delete your personal data, and to withdraw consent where processing is based on consent. To exercise these rights, email founder@astryon.in. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

If Astryón processes data on your behalf as part of running your agency's workspace, we act as a processor for that data and your workspace owner is the controller. Please direct requests about that data to your workspace owner first.

10. Children

Astryón is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

11. Cookies

Our use of cookies is described in our Cookie Policy.

12. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be announced in-app or by email at least 14 days before they take effect. The "Last updated" date at the top of this page always reflects the current version.

13. Contact

Privacy questions and requests: founder@astryon.in. General support: support@astryon.in.

Questions about this document? Email founder@astryon.in.