Skip to main content
On this page

Astra Data Processing & Security Policy

Effective Date: June 1, 2026
Last Updated: June 1, 2026

This Data Processing & Security Policy ("Policy") describes how Launchpoint Dev, DBA Astra ("Astra," "Company," "we," "our," or "us") processes, stores, secures, and manages information submitted to, generated by, or otherwise processed through Astra's websites, software, applications, artificial intelligence systems, APIs, integrations, and related services (collectively, the "Services").

This Policy is incorporated into and forms part of Astra's Terms of Service and Privacy Policy.

By using the Services, you acknowledge and agree to the practices described herein.

Purpose

Astra is committed to maintaining commercially reasonable safeguards designed to protect the confidentiality, integrity, and availability of information processed through the Services.

This Policy outlines:

  • Data processing practices
  • Security measures
  • User responsibilities
  • Incident response procedures
  • Data retention practices
  • Third-party service provider requirements

Nothing in this Policy creates a guarantee of absolute security.

Definitions

Customer Data

"Customer Data" means all information, files, content, documents, records, prompts, communications, databases, and materials submitted to Astra by users.

Personal Information

"Personal Information" means information that identifies, relates to, describes, or can reasonably be associated with an individual person.

Processing

"Processing" means any operation performed on data including:

  • Collection
  • Storage
  • Organization
  • Analysis
  • Transmission
  • Retrieval
  • Modification
  • Deletion
  • Use

Subprocessor

"Subprocessor" means a third-party service provider utilized by Astra to assist in delivering the Services.

Customer Data Ownership

Customers retain ownership of all Customer Data submitted to Astra.

Astra does not acquire ownership rights in Customer Data.

Customers grant Astra a limited, non-exclusive license to process Customer Data solely for purposes including:

  • Providing Services
  • Delivering requested functionality
  • Generating AI outputs
  • Supporting integrations
  • Improving platform performance
  • Maintaining system operations
  • Monitoring security
  • Complying with legal obligations

Except as permitted herein, Astra will not claim ownership of Customer Data.

Data Processing Purposes

Astra may process Customer Data for purposes including:

Service Delivery

  • Account management
  • Authentication
  • AI-powered functionality
  • Workflow execution
  • Reporting
  • Analytics

Customer Support

  • Technical support
  • Troubleshooting
  • Issue resolution
  • Service communications

Platform Operations

  • System monitoring
  • Performance optimization
  • Capacity planning
  • Reliability improvements

Security

  • Fraud prevention
  • Abuse prevention
  • Threat detection
  • Risk management
  • Compliance obligations
  • Law enforcement requests
  • Regulatory requirements
  • Enforcement of agreements

AI Data Processing

Astra utilizes artificial intelligence systems to process information submitted by users.

Such processing may include:

  • Prompt analysis
  • Content generation
  • Strategic recommendations
  • Marketing recommendations
  • Data analysis
  • Business intelligence
  • Workflow recommendations
  • Reporting generation

Users acknowledge that AI-powered processing may involve automated systems and third-party AI providers.

Users remain solely responsible for verifying the accuracy and suitability of AI-generated outputs.

Customer Responsibilities

Customers are responsible for:

  • Obtaining necessary permissions
  • Securing lawful rights to uploaded data
  • Compliance with privacy laws
  • Data accuracy
  • Managing user access permissions
  • Reviewing AI-generated outputs

Customers should not upload information they are not legally authorized to process.

Customers remain solely responsible for their own compliance obligations.

Security Program

Astra maintains a security program designed to protect information against unauthorized access, disclosure, alteration, and destruction.

Security measures may include:

  • Access controls
  • Authentication systems
  • Encryption technologies
  • Logging systems
  • Monitoring tools
  • Security reviews
  • Vulnerability management
  • Network protections

Security controls are reviewed and updated as business needs evolve.

Access Control

Access to systems and Customer Data is restricted to authorized personnel with a legitimate business need.

Access management practices may include:

  • Role-based permissions
  • Multi-factor authentication
  • Least-privilege access principles
  • Credential management
  • Access reviews

Astra reserves the right to modify access controls at any time.

Encryption

Where commercially reasonable, Astra may utilize encryption technologies to protect information during:

Data Transmission

Information transmitted between systems may be protected through encrypted communication protocols.

Data Storage

Certain information may be encrypted while stored within Astra systems or those of authorized service providers.

Encryption methods may evolve over time as technologies and security standards change.

Subprocessors and Third-Party Providers

Astra may engage third-party providers to support:

  • Hosting
  • Cloud infrastructure
  • Data storage
  • Payment processing
  • Artificial intelligence services
  • Analytics
  • Customer support
  • Communications

Examples may include providers such as:

  • Cloud hosting providers
  • AI service providers
  • Payment processors
  • Analytics platforms

Subprocessors are selected based on business, operational, security, and service requirements.

Astra is not responsible for independent actions taken by third-party providers outside Astra's control.

International Data Transfers

Customer Data may be processed in the United States and other jurisdictions where Astra or its service providers operate.

By using the Services, customers consent to the transfer, storage, and processing of information in these jurisdictions.

Customers remain responsible for determining whether such transfers satisfy their own legal obligations.

Incident Response

Astra maintains procedures designed to identify, investigate, and respond to suspected security incidents.

When appropriate, Astra may:

  • Investigate suspected incidents
  • Contain security threats
  • Mitigate impacts
  • Notify affected parties where legally required
  • Cooperate with authorities where appropriate

Not every system event constitutes a reportable security incident.

Astra reserves the right to determine notification obligations consistent with applicable law.

Data Retention

Customer Data is retained only as long as reasonably necessary to:

  • Provide Services
  • Maintain platform operations
  • Resolve disputes
  • Enforce agreements
  • Comply with legal obligations
  • Protect legitimate business interests

Retention periods may vary based upon:

  • Data category
  • Customer relationship status
  • Legal requirements
  • Operational needs

Upon expiration of retention requirements, data may be deleted, anonymized, aggregated, or otherwise rendered unusable.

Account Termination and Data Deletion

Customers may request account closure in accordance with Astra policies.

Following termination, Astra may retain certain information where necessary to:

  • Comply with legal obligations
  • Resolve disputes
  • Prevent fraud
  • Enforce agreements
  • Maintain business records

Astra does not guarantee immediate deletion of all information upon account termination.

Backup systems and archival processes may require additional time for removal.

Security Limitations

No system can be guaranteed completely secure.

Users acknowledge and agree that:

  • Internet transmissions carry inherent risks.
  • Security breaches may occur despite safeguards.
  • Third-party systems may experience failures.
  • Sophisticated threats may evade detection.

Astra does not warrant that its systems will be immune from:

  • Cyberattacks
  • Unauthorized access
  • Malware
  • Data loss
  • Service interruptions

Users assume these inherent risks when utilizing cloud-based services.

Audits and Assessments

Astra may periodically review, assess, or improve its security practices.

Such reviews may include:

  • Internal evaluations
  • Risk assessments
  • Operational reviews
  • Security testing
  • Vendor assessments

Astra reserves discretion regarding the scope, timing, and publication of such activities.

Regulatory Compliance

Astra strives to operate in a manner consistent with applicable privacy and data protection laws.

However, customers remain solely responsible for ensuring their own compliance with laws governing:

  • Personal information
  • Consumer data
  • Customer records
  • Marketing communications
  • Industry-specific regulations

Astra does not provide legal advice regarding compliance obligations.

Limitation of Liability

To the maximum extent permitted by law, Astra shall not be liable for:

  • Data loss
  • Unauthorized access
  • Security breaches
  • Service interruptions
  • Third-party failures
  • Cyberattacks
  • Data corruption
  • Customer misconfigurations
  • User security failures

Astra's liability shall remain subject to the limitations set forth in the Terms of Service.

Confidentiality

Astra will use commercially reasonable efforts to protect Customer Data from unauthorized disclosure.

Nothing in this Policy prevents Astra from disclosing information when required by:

  • Law
  • Court order
  • Government request
  • Regulatory requirement
  • Enforcement of legal rights

Modifications to This Policy

Astra may update this Policy from time to time.

Updated versions become effective upon posting.

Continued use of the Services after publication of changes constitutes acceptance of the revised Policy.

Contact Information

Questions regarding this Data Processing & Security Policy may be directed to:

  • Launchpoint Dev, DBA Astra
  • Email: security@askastra.dev
  • Website: www.askastra.dev
  • Address: [INSERT BUSINESS ADDRESS]

Policy Incorporation

This Data Processing & Security Policy is incorporated into and forms part of Astra's:

  • Terms of Service
  • Privacy Policy
  • AI Use & Disclosure Policy

In the event of a conflict between this Policy and Astra's Terms of Service, the Terms of Service shall govern except where applicable law requires otherwise.

Acknowledgment

By using Astra, you acknowledge that:

  • You have read this Policy.
  • You understand Astra's data processing practices.
  • You understand the limitations of information security.
  • You accept the inherent risks associated with cloud-based and AI-powered technologies.
  • You agree to the processing activities described herein.

By continuing to use the Services, you consent to Astra's processing and security practices as described in this Policy.