Privacy Policy
This policy describes how Asterolabs handles personal information in two distinct contexts: website and lead data (where Asterolabs acts as the controller) and client data accessed during engagements (where Asterolabs acts as the processor). Asterolabs serves U.S. clients remotely.
1. Roles: Controller and Processor
Asterolabs handles personal information in two different roles, depending on the context:
- As controller: for data collected on asterolabs.com, through the contact form, and in our relationship with leads and clients (contact, browsing, and communication data). In these cases, Asterolabs decides on the purposes and means of processing.
- As processor: for personal information we access in our clients' systems, databases, and environments while delivering Automation + AI and Cybersecurity services. In these cases, Asterolabs processes the data on the client's instructions (the client being the controller) and in line with the contract — we do not use it for our own purposes.
2. Data We Collect (Website and Leads)
As controller, we collect the following categories of data, depending on your interaction:
- Contact and account data: name, email, phone, company, and other information you provide in contact forms, proposals, and the commercial relationship.
- Technical data: IP address, browser type, operating system, pages visited, access time, device identifiers, and campaign parameters (UTM).
- Billing data: information needed to issue invoices and process payments, handled by a certified payment processor (PCI-DSS). We do not store full card details on our servers.
- Browsing data: session identifiers, cookies, and data from behavior and performance analytics tools, as described in the Cookies section.
- Client portal access logs: each time you log in to the portal, we record the IP address, device and browser information (user-agent), and the date and time of access. These logs support account security and help prevent misuse and credential sharing (the account is individual and non-transferable, per the Terms of Service).
3. How We Use Data
As controller, we use the data we collect for the following purposes:
- Respond to inquiries, prepare proposals, and deliver the services you engage us for.
- Process charges and issue invoices and receipts.
- Send operational and transactional communications (confirmations, service notices, and billing notices).
- Secure our systems and detect and prevent fraud and unauthorized access.
- Log client portal access and prevent misuse or sharing of credentials, based on our legitimate interest in service security and fraud prevention.
- Comply with legal, tax, and regulatory obligations.
- Measure and optimize Asterolabs' own marketing campaigns, based on legitimate interest and, where applicable, consent (see the Cookies section).
4. Client Data in Engagements (Processor)
While delivering Automation + AI and Cybersecurity services, Asterolabs may access clients' systems, code, databases, and data — which can contain personal information about the client's own people (their employees, users, or customers). In that context:
- Asterolabs acts as a processor, handling the data solely on the client's instructions (the client being the controller) and to perform the contracted service.
- Asterolabs does not use this data for its own purposes, for marketing, or to train general-purpose AI models.
- Access is restricted, credential-controlled, and ends when the engagement concludes, where applicable.
- The applicable confidentiality and security obligations are set out in the Terms of Service and the Security Policy, and may be detailed in a specific data processing agreement.
- Privacy requests from individuals about this data should be directed to the client (controller); Asterolabs supports the client in responding, as agreed in the contract.
6. Data Retention
Data is retained for as long as necessary for the purposes in this policy or as required by law. In general:
- Contact and relationship data: kept for the duration of the commercial relationship and for a reasonable period afterward, for recordkeeping and to defend our rights.
- Billing and tax data: retained for the period required by applicable tax law.
- Technical and access logs: stored for up to 12 months for security purposes.
- Data processed as processor: retained only as long as needed to deliver the service and returned or deleted when it ends, per the client's instructions and the contract, subject to any mandatory legal retention.
7. Data Security
Asterolabs adopts technical and organizational measures to protect personal information, including:
- Encryption of data in transit (TLS/SSL) and, where applicable, at rest.
- Strict access controls and the principle of least privilege.
- Careful management of credentials and access granted by clients.
- Monitoring and logging of access.
For more detail, see our Security Policy.
8. Your Privacy Rights
Depending on where you live and the applicable law — including U.S. state privacy laws such as the California Consumer Privacy Act, as amended by the CPRA — you may have the following rights regarding your personal information:
- The right to know what personal information we hold about you and how it is used.
- The right to access a copy of your personal information.
- The right to correct inaccurate or outdated information.
- The right to delete personal information, subject to legal exceptions.
- The right to data portability.
- The right to opt out of the "sale" or "sharing" of personal information for targeted advertising.
- The right to limit the use of sensitive personal information, where applicable.
- The right not to receive discriminatory treatment for exercising these rights.
To exercise your rights, contact us at support@asterolabs.com. We will respond within the timeframe required by applicable law. You may use an authorized agent to submit a request on your behalf. Where Asterolabs acts as processor, requests will be forwarded to the relevant client (controller).
10. Email Communications
When you interact with Asterolabs, you may receive the following types of communication:
- Transactional: replies to inquiries, payment confirmations, and invoices.
- Operational: notices about your service, maintenance, and alerts.
- Commercial: proposals, updates, and content, where there is interest or a legal basis to send them.
Transactional and operational communications are necessary to deliver the service. Commercial communications can be turned off at any time by emailing support@asterolabs.com or using the unsubscribe link.
11. International Data Transfers
Asterolabs operates from Brazil and serves U.S. clients remotely. Your data may therefore be transferred to and processed on servers located outside your country of residence — including in Brazil and the United States (for example, cloud infrastructure providers). In those cases, Asterolabs ensures that:
- Transfers rely on an appropriate legal mechanism where one is required.
- Contractual clauses are in place to protect the transferred data.
- Complementary technical measures, such as encryption, are applied.
12. Minors
Asterolabs' services are not directed to individuals under 18, and we do not knowingly collect personal information from minors. If we become aware of such collection, we will delete it. If you are a parent or guardian and believe a minor has provided data, please contact us.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or in the law. We will give reasonable advance notice of material changes. We recommend reviewing it periodically.
14. Contact
If you have questions about this Privacy Policy or how we handle your personal information, contact us: