Astra Data Processing & Security Policy
Effective Date: June 1, 2026
Last Updated: June 1, 2026
This Data Processing & Security Policy ("Policy") describes how Launchpoint Dev, DBA Astra ("Astra," "Company," "we," "our," or "us") processes, stores, secures, and manages information submitted to, generated by, or otherwise processed through Astra's websites, software, applications, artificial intelligence systems, APIs, integrations, and related services (collectively, the "Services").
This Policy is incorporated into and forms part of Astra's Terms of Service and Privacy Policy.
By using the Services, you acknowledge and agree to the practices described herein.
Purpose
Astra is committed to maintaining commercially reasonable safeguards designed to protect the confidentiality, integrity, and availability of information processed through the Services.
This Policy outlines:
- Data processing practices
- Security measures
- User responsibilities
- Incident response procedures
- Data retention practices
- Third-party service provider requirements
Nothing in this Policy creates a guarantee of absolute security.
Definitions
Customer Data
"Customer Data" means all information, files, content, documents, records, prompts, communications, databases, and materials submitted to Astra by users.
Personal Information
"Personal Information" means information that identifies, relates to, describes, or can reasonably be associated with an individual person.
Processing
"Processing" means any operation performed on data including:
- Collection
- Storage
- Organization
- Analysis
- Transmission
- Retrieval
- Modification
- Deletion
- Use
Subprocessor
"Subprocessor" means a third-party service provider utilized by Astra to assist in delivering the Services.
Customer Data Ownership
Customers retain ownership of all Customer Data submitted to Astra.
Astra does not acquire ownership rights in Customer Data.
Customers grant Astra a limited, non-exclusive license to process Customer Data solely for purposes including:
- Providing Services
- Delivering requested functionality
- Generating AI outputs
- Supporting integrations
- Improving platform performance
- Maintaining system operations
- Monitoring security
- Complying with legal obligations
Except as permitted herein, Astra will not claim ownership of Customer Data.
Data Processing Purposes
Astra may process Customer Data for purposes including:
Service Delivery
- Account management
- Authentication
- AI-powered functionality
- Workflow execution
- Reporting
- Analytics
Customer Support
- Technical support
- Troubleshooting
- Issue resolution
- Service communications
Platform Operations
- System monitoring
- Performance optimization
- Capacity planning
- Reliability improvements
Security
- Fraud prevention
- Abuse prevention
- Threat detection
- Risk management
Legal Compliance
- Compliance obligations
- Law enforcement requests
- Regulatory requirements
- Enforcement of agreements
AI Data Processing
Astra utilizes artificial intelligence systems to process information submitted by users.
Such processing may include:
- Prompt analysis
- Content generation
- Strategic recommendations
- Marketing recommendations
- Data analysis
- Business intelligence
- Workflow recommendations
- Reporting generation
Users acknowledge that AI-powered processing may involve automated systems and third-party AI providers.
Users remain solely responsible for verifying the accuracy and suitability of AI-generated outputs.
Customer Responsibilities
Customers are responsible for:
- Obtaining necessary permissions
- Securing lawful rights to uploaded data
- Compliance with privacy laws
- Data accuracy
- Managing user access permissions
- Reviewing AI-generated outputs
Customers should not upload information they are not legally authorized to process.
Customers remain solely responsible for their own compliance obligations.
Security Program
Astra maintains a security program designed to protect information against unauthorized access, disclosure, alteration, and destruction.
Security measures may include:
- Access controls
- Authentication systems
- Encryption technologies
- Logging systems
- Monitoring tools
- Security reviews
- Vulnerability management
- Network protections
Security controls are reviewed and updated as business needs evolve.
Access Control
Access to systems and Customer Data is restricted to authorized personnel with a legitimate business need.
Access management practices may include:
- Role-based permissions
- Multi-factor authentication
- Least-privilege access principles
- Credential management
- Access reviews
Astra reserves the right to modify access controls at any time.
Encryption
Where commercially reasonable, Astra may utilize encryption technologies to protect information during:
Data Transmission
Information transmitted between systems may be protected through encrypted communication protocols.
Data Storage
Certain information may be encrypted while stored within Astra systems or those of authorized service providers.
Encryption methods may evolve over time as technologies and security standards change.
Subprocessors and Third-Party Providers
Astra may engage third-party providers to support:
- Hosting
- Cloud infrastructure
- Data storage
- Payment processing
- Artificial intelligence services
- Analytics
- Customer support
- Communications
Examples may include providers such as:
- Cloud hosting providers
- AI service providers
- Payment processors
- Analytics platforms
Subprocessors are selected based on business, operational, security, and service requirements.
Astra is not responsible for independent actions taken by third-party providers outside Astra's control.
International Data Transfers
Customer Data may be processed in the United States and other jurisdictions where Astra or its service providers operate.
By using the Services, customers consent to the transfer, storage, and processing of information in these jurisdictions.
Customers remain responsible for determining whether such transfers satisfy their own legal obligations.
Incident Response
Astra maintains procedures designed to identify, investigate, and respond to suspected security incidents.
When appropriate, Astra may:
- Investigate suspected incidents
- Contain security threats
- Mitigate impacts
- Notify affected parties where legally required
- Cooperate with authorities where appropriate
Not every system event constitutes a reportable security incident.
Astra reserves the right to determine notification obligations consistent with applicable law.
Data Retention
Customer Data is retained only as long as reasonably necessary to:
- Provide Services
- Maintain platform operations
- Resolve disputes
- Enforce agreements
- Comply with legal obligations
- Protect legitimate business interests
Retention periods may vary based upon:
- Data category
- Customer relationship status
- Legal requirements
- Operational needs
Upon expiration of retention requirements, data may be deleted, anonymized, aggregated, or otherwise rendered unusable.
Account Termination and Data Deletion
Customers may request account closure in accordance with Astra policies.
Following termination, Astra may retain certain information where necessary to:
- Comply with legal obligations
- Resolve disputes
- Prevent fraud
- Enforce agreements
- Maintain business records
Astra does not guarantee immediate deletion of all information upon account termination.
Backup systems and archival processes may require additional time for removal.
Security Limitations
No system can be guaranteed completely secure.
Users acknowledge and agree that:
- Internet transmissions carry inherent risks.
- Security breaches may occur despite safeguards.
- Third-party systems may experience failures.
- Sophisticated threats may evade detection.
Astra does not warrant that its systems will be immune from:
- Cyberattacks
- Unauthorized access
- Malware
- Data loss
- Service interruptions
Users assume these inherent risks when utilizing cloud-based services.
Audits and Assessments
Astra may periodically review, assess, or improve its security practices.
Such reviews may include:
- Internal evaluations
- Risk assessments
- Operational reviews
- Security testing
- Vendor assessments
Astra reserves discretion regarding the scope, timing, and publication of such activities.
Regulatory Compliance
Astra strives to operate in a manner consistent with applicable privacy and data protection laws.
However, customers remain solely responsible for ensuring their own compliance with laws governing:
- Personal information
- Consumer data
- Customer records
- Marketing communications
- Industry-specific regulations
Astra does not provide legal advice regarding compliance obligations.
Limitation of Liability
To the maximum extent permitted by law, Astra shall not be liable for:
- Data loss
- Unauthorized access
- Security breaches
- Service interruptions
- Third-party failures
- Cyberattacks
- Data corruption
- Customer misconfigurations
- User security failures
Astra's liability shall remain subject to the limitations set forth in the Terms of Service.
Confidentiality
Astra will use commercially reasonable efforts to protect Customer Data from unauthorized disclosure.
Nothing in this Policy prevents Astra from disclosing information when required by:
- Law
- Court order
- Government request
- Regulatory requirement
- Enforcement of legal rights
Modifications to This Policy
Astra may update this Policy from time to time.
Updated versions become effective upon posting.
Continued use of the Services after publication of changes constitutes acceptance of the revised Policy.
Contact Information
Questions regarding this Data Processing & Security Policy may be directed to:
- Launchpoint Dev, DBA Astra
- Email: security@askastra.dev
- Website: www.askastra.dev
- Address: [INSERT BUSINESS ADDRESS]
Policy Incorporation
This Data Processing & Security Policy is incorporated into and forms part of Astra's:
- Terms of Service
- Privacy Policy
- AI Use & Disclosure Policy
In the event of a conflict between this Policy and Astra's Terms of Service, the Terms of Service shall govern except where applicable law requires otherwise.
Acknowledgment
By using Astra, you acknowledge that:
- You have read this Policy.
- You understand Astra's data processing practices.
- You understand the limitations of information security.
- You accept the inherent risks associated with cloud-based and AI-powered technologies.
- You agree to the processing activities described herein.
By continuing to use the Services, you consent to Astra's processing and security practices as described in this Policy.