Privacy Policy
Technomate IT-Solution Private Limited · Effective 2026-09-26
1. The three relationships
| Situation | Our role |
|---|---|
| You visit technomateai.com or contact us | We are the Data Fiduciary (controller). We decide why and how your data is used. |
| You are an administrator with an ASTRA account | We are the Data Fiduciary for your account and billing details. |
| You are an employee of an ASTRA customer and the agent runs on your work device | Your employer is the Data Fiduciary. We are their Data Processor and act only on their instructions. Direct your questions to your employer’s IT team first; we will support them in answering you. |
2. What we collect
2.1 Marketing website
- Contact and demo forms: your name, work email, phone number, company, area of interest and message.
- Resource downloads: your email address.
- Campaign attribution: the referring page and any UTM parameters on the link that brought you here.
- Analytics and advertising cookies: see the Cookie Policy.
- Website assistant: the questions you type. The assistant answers from published product information, creates no record of your conversation, and has no access to any customer’s data.
2.2 ASTRA accounts
- Organisation name; administrator name, work email and hashed password.
- Billing identity you enter: legal name, billing contact, address, and tax registration number where you provide one.
- Authentication and session records, and your acceptance of these terms.
2.3 Data the ASTRA agent collects from managed devices
Collected on our customers’ instruction, from devices they own or control:
- Device hostname, operating system version and hardware inventory.
- The username signed in to the device — this identifies a person, and we treat it accordingly.
- Performance telemetry — processor, memory and disk usage — sampled about once per minute.
- Installed applications, running services, Windows Update status, and system/application event log entries.
- Support conversations initiated from the device, and a record of every remediation action requested, approved and executed.
- Asset assignment records, where an organisation uses that feature.
What the agent does not do: it does not capture keystrokes, record the screen, read the contents of documents or email, monitor browsing history, or access personal files. The only way anyone sees a device’s screen is a live remote support session that the person at the device has agreed to (section 2.4).
2.4 Remote support sessions
Where an organisation’s plan includes remote support and it has been switched on for that organisation, one of its technicians can ask to view and control a managed device’s screen to help the person using it. When that happens:
- The person at the device is asked first. A prompt titled “ASTRA Remote Support” appears on their screen, naming the technician and the reason they gave. Nothing connects unless they click Allow. If they do not answer within about two minutes the request lapses; silence is never treated as a yes.
- While the session is open, the technician sees the screen live and can use the mouse and keyboard. The clipboard is shared both ways so text can be copied between the two machines. File transfer and command-line access are disabled for these sessions.
- The session is not recorded. The screen is streamed to the technician in real time through our relay server and is not stored by us.
- We keep a record about the session — who asked, for which device, the reason given, whether the person allowed or declined, and when it started and ended — in the organisation’s audit log.
- To make this possible a separate remote-support service is installed on the device, and only on devices of organisations that have the feature enabled. It is removed automatically when the feature is switched off.
- Remote support can only be started by a person. ASTRA’s AI cannot request, start or join a remote session.
3. Why we process it
- To provide, secure, operate and support the ASTRA service.
- To diagnose faults and — where the customer has approved the relevant tier — to remediate them.
- To bill for the service and meet our accounting and tax obligations.
- To respond to enquiries and, where you have asked us to, send you information about the product.
- To detect and prevent abuse, and to keep an audit trail of what was done.
3.1 Lawful basis
| Purpose | Basis |
|---|---|
| Providing, securing and supporting the ASTRA service | Our contract with the customer; for device data, the customer’s own lawful basis as Data Fiduciary, on whose instructions we act |
| Remote support sessions | The customer’s instruction, together with the live consent of the person at the device, given separately for each session |
| Billing, tax and accounting records | Compliance with legal obligations |
| Answering an enquiry you send us | Your request, and the details you chose to give us for it |
| Marketing email | Your consent. Every such email carries an unsubscribe link, and you may withdraw consent at any time |
| Analytics and advertising cookies | Your consent, given through the cookie banner — see the Cookie Policy |
| Security, abuse prevention and the audit trail | Legitimate uses permitted by law, and our contract with the customer |
3.2 Who we share it with
We do not sell personal data, and we do not share it for other companies’ advertising. We share it only with:
- the providers listed on the sub-processors page, under contract, and only as far as they need it to provide their service to us;
- systems the customer deliberately connects, such as their own helpdesk;
- a court, regulator or law-enforcement authority where the law requires it — where we are allowed to, we tell the affected customer first;
- a successor to our business, bound by this policy, if the company is merged or sold.
4. Artificial intelligence
ASTRA uses a third-party large language model to reason about IT issues. When a support conversation or a diagnosis runs, the relevant conversation text and device telemetry are sent to that provider. Model providers are not permitted to train on data sent through the ASTRA service. Our providers are listed on the sub-processors page.
Actions that change a device are governed by approval tiers enforced in our backend, not by the model. The AI can propose a remediation; whether it may run without a human approving it is decided by the customer’s configuration and checked in code.
5. Where data is held
The ASTRA application and database are hosted in Singapore. Some sub-processors operate elsewhere, including the United States. Full detail, with locations, is on the sub-processors page.
We transfer personal data outside India only to countries not restricted by the Government of India under the Digital Personal Data Protection Act, 2023, and only to providers contractually bound to protect it to the standard in this policy. Customers who need a signed commitment on transfers can have one through our Data Processing Agreement. If your organisation needs its data held in India, tell us before you sign.
6. How long we keep it
| Data | Retention |
|---|---|
| Raw performance telemetry | 7 days, then automatically deleted |
| Daily aggregated telemetry (for trend charts) | Retained for the life of the account |
| Device inventory | Replaced on each collection; deleted when the device is removed |
| Remote support screen video | Not stored — streamed live only |
| Audit logs, remediation and remote-session history | Retained for the life of the account |
| Account and billing records | Retained while the account is active, then for eight years from the end of the financial year they relate to, as Indian company and tax law requires for books of account |
| Customer data after the account closes | Available for export for 30 days, then deleted from the live system; backup copies expire within a further 30 days |
| Marketing enquiries | Until you ask us to delete them |
7. Security
- Encryption in transit; encryption at rest for stored third-party credentials.
- Role-based access control, with every organisation’s data isolated from every other.
- Short-lived access tokens with rotating refresh tokens and reuse detection.
- Remediation is restricted to a fixed catalogue of permitted actions, enforced independently by both the server and the agent. The agent executes action identifiers, never arbitrary commands.
- Audit logging of every change and every command sent to a device.
To report a vulnerability, email security@technomateai.com.
8. Your rights
Subject to applicable law you may ask us to give you a copy of your personal data, correct it, delete it, or withdraw a consent you previously gave. Write to privacy@technomateai.com.
You may also nominate someone to exercise these rights for you in the event of your death or incapacity. We answer requests within 30 days, may first need to confirm your identity, and do not charge for this.
If the data concerns a device managed by your employer, we will refer your request to them, because it is their data and their decision.
Children. ASTRA and this website are for businesses. We do not knowingly collect personal data from anyone under 18; if you believe we have, write to us and we will delete it.
Breaches. If a breach affects personal data we hold, we inform affected customers without undue delay and within 72 hours of confirming it, and notify the Data Protection Board of India and affected individuals as the law requires.
9. Grievance Officer
In accordance with applicable Indian law, the following officer may be contacted with any complaint about how your personal data has been handled:
Adeel Ahamad
Grievance Officer, Technomate IT-Solution Private Limited
grievance@technomateai.com
Ayodhya Ganj, Dadri, Gautam Budh Nagar, Uttar Pradesh 203207, India
We acknowledge a complaint within 48 hours and aim to resolve it within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
10. Changes
We will post any change to this policy on this page and update the effective date. Material changes affecting customers will additionally be notified as the applicable agreement requires.