Privacy Policy

Technomate IT-Solution Private Limited · Effective 2026-08-27

Draft — pending legal review. This document has not yet been reviewed by counsel and must not be relied upon as final. Sections marked “to be completed by counsel” are intentionally unfinished.
This policy explains how Technomate IT-Solution Private Limited (“Technomate”, “we”, “us”) handles personal data. It covers three different situations, and our role is different in each — which is the most important thing to understand before reading the rest.

1. The three relationships

SituationOur role
You visit technomateai.com or contact usWe are the Data Fiduciary (controller). We decide why and how your data is used.
You are an administrator with an ASTRA accountWe are the Data Fiduciary for your account and billing details.
You are an employee of an ASTRA customer and the agent runs on your work deviceYour employer is the Data Fiduciary. We are their Data Processor and act only on their instructions. Direct your questions to your employer’s IT team first; we will support them in answering you.

2. What we collect

2.1 Marketing website

  • Contact and demo forms: your name, work email, phone number, company, area of interest and message.
  • Resource downloads: your email address.
  • Campaign attribution: the referring page and any UTM parameters on the link that brought you here.
  • Analytics and advertising cookies: see the Cookie Policy.
  • Website assistant: the questions you type. The assistant answers from published product information, creates no record of your conversation, and has no access to any customer’s data.

2.2 ASTRA accounts

  • Organisation name; administrator name, work email and hashed password.
  • Billing identity you enter: legal name, billing contact, address, and tax registration number where you provide one.
  • Authentication and session records, and your acceptance of these terms.

2.3 Data the ASTRA agent collects from managed devices

Collected on our customers’ instruction, from devices they own or control:

  • Device hostname, operating system version and hardware inventory.
  • The username signed in to the device — this identifies a person, and we treat it accordingly.
  • Performance telemetry — processor, memory and disk usage — sampled about once per minute.
  • Installed applications, running services, Windows Update status, and system/application event log entries.
  • Support conversations initiated from the device, and a record of every remediation action requested, approved and executed.
  • Asset assignment records, where an organisation uses that feature.

What the agent does not do: it does not capture keystrokes, record the screen, read the contents of documents or email, monitor browsing history, or access personal files.

3. Why we process it

  • To provide, secure, operate and support the ASTRA service.
  • To diagnose faults and — where the customer has approved the relevant tier — to remediate them.
  • To bill for the service and meet our accounting and tax obligations.
  • To respond to enquiries and, where you have asked us to, send you information about the product.
  • To detect and prevent abuse, and to keep an audit trail of what was done.

To be completed by counsel: State the lawful basis for each purpose in the form the applicable data-protection legislation requires, and confirm the position on consent versus legitimate use for the marketing communications described above.

4. Artificial intelligence

ASTRA uses a third-party large language model to reason about IT issues. When a support conversation or a diagnosis runs, the relevant conversation text and device telemetry are sent to that provider. Model providers are not permitted to train on data sent through the ASTRA service. Our providers are listed on the sub-processors page.

Actions that change a device are governed by approval tiers enforced in our backend, not by the model. The AI can propose a remediation; whether it may run without a human approving it is decided by the customer’s configuration and checked in code.

5. Where data is held

The ASTRA application and database are hosted in Singapore. Some sub-processors operate elsewhere, including the United States. Full detail, with locations, is on the sub-processors page.

To be completed by counsel: Confirm the cross-border transfer position under applicable Indian law and, if the company sells into the EEA or the UK, add the transfer mechanism and any additional required disclosures.

6. How long we keep it

DataRetention
Raw performance telemetry7 days, then automatically deleted
Daily aggregated telemetry (for trend charts)Retained for the life of the account
Device inventoryReplaced on each collection; deleted when the device is removed
Audit logs and remediation historyRetained for the life of the account
Account and billing recordsRetained while the account is active, then for the period our tax and company-law obligations require
Marketing enquiriesUntil you ask us to delete them

To be completed by counsel: Confirm the statutory retention period for books of account and invoices, and state it as a definite number of years here.

7. Security

  • Encryption in transit; encryption at rest for stored third-party credentials.
  • Role-based access control, with every organisation’s data isolated from every other.
  • Short-lived access tokens with rotating refresh tokens and reuse detection.
  • Remediation is restricted to a fixed catalogue of permitted actions, enforced independently by both the server and the agent. The agent executes action identifiers, never arbitrary commands.
  • Audit logging of every change and every command sent to a device.

To report a vulnerability, email security@technomateai.com.

8. Your rights

Subject to applicable law you may ask us to give you a copy of your personal data, correct it, delete it, or withdraw a consent you previously gave. Write to privacy@technomateai.com.

If the data concerns a device managed by your employer, we will refer your request to them, because it is their data and their decision.

9. Grievance Officer

In accordance with applicable Indian law, the following officer may be contacted with any complaint about how your personal data has been handled:

Adeel Ahamad
Grievance Officer, Technomate IT-Solution Private Limited
grievance@technomateai.com
Ayodhya Ganj, Dadri, Gautam Budh Nagar, Uttar Pradesh 203207, India

To be completed by counsel: Confirm the response timeline that must be committed to here.

10. Changes

We will post any change to this policy on this page and update the effective date. Material changes affecting customers will additionally be notified as the applicable agreement requires.