This Privacy Policy explains how personal data is collected, used, shared, and protected in connection with Astrosia CRM, the public website and checkout at crm.astrosia.com, related billing, and the CRM application at labs.astrosia.tech (together, the “Service”).
It should be read with the Terms of Service, Cookie Policy, Cancellation & Refund Policy, and Shipping & Delivery Policy. It includes information for visitors and customers in the EEA, UK, and Switzerland (GDPR / UK GDPR). By using the Service, you acknowledge this Policy. Capitalised terms not defined here have the meaning given in the Terms.
The Service is commercially provided by Astrosia Technologies LLP (“the LLP”). Your contract for the CRM, including subscriptions and billing, is with the LLP, as set out in the Terms of Service.
Personal data is handled by the LLP. The LLP is the Data Fiduciary / controller for account, billing, website, and support-administration data we collect about customers and site visitors. The LLP may share that data, and Customer Data processed as your processor, with ASTROSIA (Prop) (Astrosia Technologies, a sole proprietorship), a related entity, for the purposes in Section 6.
For Indian data-protection purposes:
Registered address (shared by Astrosia Technologies LLP and ASTROSIA (Prop)): Mazna Up Road, Contai-721401, West Bengal, India.
Corporate address of Astrosia Technologies LLP (support and public enquiries; not a change of registered office): Tech37, 1st Floor, Plot No. 2A, Electronic City 2nd Phase, Sy-No 37, Bangalore-560100, India.
Public contact (email, phone, Corporate Center) is on the Contact page. The registered address above is stated here for legal identification and is not published elsewhere on the marketing site.
India: +91-8069645402 · US: +1-415-417-1659 · support@astrosia.com
This Policy covers:
It does not govern third-party websites or apps you connect (Meta, WhatsApp, Razorpay, carriers, Voiceplix, AI providers, and similar), which have their own policies.
When you use the CRM, you and your Users may upload or generate leads, contact details, notes, files, WhatsApp and email threads, call metadata or recordings (where enabled), automation logs, and similar business records. We process this to provide the Service on your instructions. We do not use Customer Data to sell advertising.
Payment status and tokens from Razorpay; identity details from Google if you sign in with Google; delivery and quality events from email, SMS, WhatsApp, or telephony providers you connect.
We use personal data to:
We do not sell personal data. We do not use Customer Data for third-party advertising profiles.
Depending on applicable law (including India’s Digital Personal Data Protection Act, 2023, and other rules that may apply):
We share personal data only as needed:
We do not share Customer Data with unaffiliated third parties for their independent marketing.
Unless a separate written enterprise arrangement says otherwise, all Service data is stored on servers located in India. This is the default for every standard Subscription, including account, billing, and Customer Data we host as processor.
If you require hosting in a different country or a dedicated regional environment, you must ask our enterprise team. Allocation of a separate-location server is subject to enterprise cost: a minimum of USD 5,000 in addition to your Subscription charges, plus any ongoing regional hosting or compliance fees quoted in writing. Standard plans are not moved off Indian servers without that agreement.
Even when data is stored in India, some subprocessors or channel providers you enable (Meta / WhatsApp, email, telephony, Razorpay, AI or MCP endpoints) may process data in other countries under their own terms. Those transfers are described in Section 8.
We are established in India. If you access the Service from outside India, your data is transferred to India for hosting and support. Where we transfer personal data from the EEA, UK, or Switzerland to India or another third country, we rely on appropriate safeguards where required (including Standard Contractual Clauses or UK addenda), a valid derogation, or your instructions as controller of Customer Data.
Enterprise customers who purchase a separate-location server (Section 7) will have the hosting region stated in their enterprise order; residual transfers (support, billing, channel APIs, related-entity sharing) may still involve India or provider regions.
This section applies where the EU General Data Protection Regulation (GDPR), UK GDPR, or Swiss FADP applies to our processing — for example if you are in those territories, or you use the Service to process personal data of people in those territories.
Where we are controller, we process personal data under GDPR Article 6 on these bases as applicable:
When we host Customer Data we: (a) process only on documented instructions (these Terms, your in-product settings, and written enterprise orders); (b) require confidentiality of authorised staff and of ASTROSIA (Prop) as a related entity; (c) implement appropriate security measures; (d) use subprocessors as listed in spirit in Section 6 (hosting, payments, email, channels you enable, related entity) and will flow down equivalent obligations; (e) assist with data-subject requests and DPIAs where reasonably feasible at your cost if the effort is material; (f) delete or return Customer Data after the Service ends, subject to legal retention and backup cycles; (g) make available information reasonably needed to demonstrate these commitments.
You authorise us to use subprocessors required to run the Service, and to share with ASTROSIA (Prop) as described in Section 6. Connecting a third-party channel is your instruction to transfer relevant Customer Data to that provider.
Where GDPR applies to data we hold as controller, you may request: access; rectification; erasure; restriction; portability; objection to processing based on legitimate interests; and withdrawal of consent. You may also lodge a complaint with your local supervisory authority (for example a national DPA in the EU, or the ICO in the UK). We ask that you contact support@astrosia.com first so we can try to resolve the issue.
We do not use automated decision-making that produces legal or similarly significant effects about you as a customer without human involvement, other than routine fraud/payment checks by Razorpay.
For Customer Data, end users should contact you as controller. We will assist you as processor where reasonably required.
We do not maintain an Article 27 representative in the Union or the UK unless an enterprise agreement requires one. GDPR enquiries: support@astrosia.com, with postal identification at the registered address in Section 1.1.
We retain account and billing records for as long as the Account is active and thereafter as needed for tax, accounting, dispute resolution, and legal obligation (typically several years for financial records). Support correspondence is kept for a reasonable period to handle follow-up and quality.
Customer Data is retained for the life of the workspace and according to settings you control. After cancellation or a verified deletion request, we delete or de-identify Customer Data within a reasonable period, except where retention is required by law, dispute, or backup cycles. Backups are overwritten on a rolling schedule.
We use reasonable technical and organisational measures, including TLS in transit, access controls, and least-privilege practices for staff and related-entity personnel who receive data. No method of transmission or storage is completely secure. You are responsible for User access rights inside your workspace, for exporting data you need, and for the security of credentials you issue.
Subject to applicable law, you may request access, correction, completion, or erasure of personal data we hold as Data Fiduciary, or withdraw consent where processing is consent-based. You may also nominate (where the law provides) a person to exercise rights in the event of death or incapacity. EEA/UK/Swiss rights are set out in Section 9.
To exercise rights, email support@astrosia.com. We may need to verify identity and may decline or limit requests where an exception applies (for example legal retention, another person’s rights, or disproportionate effort).
End customers whose data sits in your CRM should contact you first. We will assist you as processor where reasonably required. A public deletion form is also available at labs.astrosia.tech/crm/public/data-deletion for requests we receive directly (for example Play Store / user-data requests); we will review those in line with law and your role as fiduciary of Customer Data.
If you are in a jurisdiction with a statutory grievance process, you may also contact the Data Protection Board of India or another competent authority after first raising the issue with us.
The Service is intended for businesses and adults. It is not directed to children under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided data, contact us and we will delete it where required.
We use cookies as described in the Cookie Policy. Essential cookies are used for authentication, session continuity, checkout, CSRF protection, and remembering site preferences. Analytics and attribution cookies run only after you choose Accept all on the cookie banner. Disabling essential cookies may prevent login or purchase. We do not run third-party ad networks on the core CRM or checkout pages.
Change your choice any time using Cookie settings in the site footer.
If you enable AI Agents, MCP connections, or similar features, prompts and the Customer Data you choose to send may be processed by those models or endpoints to generate drafts, summaries, or actions. You control whether those features are on. Do not submit data to AI features that you are not permitted to process. MCP privacy controls in the CRM (including redaction toggles) are additional product safeguards; they do not replace your legal obligations to your end customers.
We may update this Policy by posting a revised version on this page with a new “Last updated” date. Material changes may also be notified by email or in-product notice. Continued use after the effective date constitutes acknowledgement where permitted by law.
Privacy, GDPR, and support requests: support@astrosia.com
Postal identification for legal purposes: registered address in Section 1.1. Public / support enquiries: LLP Corporate Center on the Contact page.