Astravizia AI Agency legal
Privacy Policy
Last updated: September 12, 2026
This policy explains how Astravizia handles personal data when you visit this website, submit a project request, or communicate with us. It is intended to provide the information required by Articles 12, 13, and 14 of the General Data Protection Regulation (GDPR) where that law applies.
1. Data controller
Astravizia is the controller for personal data collected through this website and direct enquiries. Privacy questions and data-rights requests can be sent to astravizia@gmail.com.
2. Personal data we collect
- Identity and business details, including your name or business name and business type.
- Contact details, currently your email address.
- Enquiry information, including the product or service selected and your message.
- Technical information normally produced by hosting infrastructure, such as IP address, request time, browser information, page path, and security logs.
- Correspondence and project records if you continue discussions or become a client.
Please do not submit health information, payment-card data, government identifiers, or other sensitive personal data through the enquiry form.
3. Sources of personal data
We normally obtain data directly from you through the contact form or email. If another person introduces your business or contacts us on your behalf, we may receive basic business contact details from that person and will provide privacy information when required.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Responding to enquiries, recommending packages, and preparing proposals. | Steps requested before entering a contract and our legitimate interest in responding to prospective clients. |
| Delivering agreed services, support, hosting, and maintenance. | Performance of a contract. |
| Keeping accounting, contractual, and compliance records. | Legal obligations and legitimate interests in establishing or defending legal claims. |
| Protecting the website, preventing misuse, and troubleshooting. | Legitimate interests in maintaining secure and reliable services. |
We do not use enquiry data for unrelated marketing without an appropriate legal basis.
5. Recipients and processors
Personal data may be processed by service providers that support the website and our operations, such as hosting and deployment providers, Supabase for database storage, email providers, and professional advisers where necessary. These providers receive only the data needed for their role and are required to protect it. We do not sell personal data.
6. International transfers
Some providers may process data outside your country or outside the European Economic Area. Where GDPR transfer rules apply, we rely on an adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with supplementary measures where required.
7. Retention
Enquiry records are normally retained for up to 24 months after the last meaningful contact so we can respond, follow up, and understand prior discussions. Client, invoice, and contractual records may be kept longer where required by tax, accounting, contractual, or legal-claims obligations. Security logs are retained for shorter operational periods unless needed to investigate an incident. Data is deleted or anonymised when it is no longer needed.
8. Security
We use proportionate technical and organisational safeguards, including restricted server-side access, encrypted HTTPS transport, access controls, protected environment variables, database row-level security, updates, and service health monitoring. No online service can guarantee absolute security.
9. Your data-protection rights
- Access the personal data we hold about you and receive a copy.
- Correct inaccurate or incomplete personal data.
- Request deletion where there is no overriding legal reason to keep the data.
- Restrict processing in the circumstances provided by law.
- Object to processing based on legitimate interests.
- Receive data you provided in a structured, commonly used format where portability applies.
- Withdraw consent at any time where consent is the legal basis.
Rights depend on the processing context and may be subject to legal exceptions. Access and portability are separate rights. We may ask for reasonable information to verify your identity before acting.
10. Exercising your rights
Email astravizia@gmail.com with the subject “Privacy request”. We aim to respond without undue delay and within one month where GDPR applies. If a request is complex or numerous, the legally permitted extension may apply and we will explain this.
11. Cookies, analytics, and automated decisions
This version of the website does not intentionally use non-essential advertising cookies or behavioural analytics. Hosting providers may use essential technical storage and logs required to deliver and secure the website. We do not make decisions producing legal or similarly significant effects solely through automated processing, and we do not conduct profiling through the enquiry form.
12. Children
The website and services are directed to business owners and professionals, not children. We do not knowingly collect personal data from children through this form.
13. Changes and contact
We may update this policy when our services, providers, or legal obligations change. The current version and update date will remain available on this page. Contact astravizia@gmail.com with questions.