Astracia / Policies & information
Privacy policy
What account and public competitor data Astracia processes, why it is used, how long it is retained and how to exercise your rights.
1. Who processes your data
The data controller is UMS Solutions d.o.o., Belgrade 11050, Serbia, tax ID 114522183, company registration number 22034588, provider of Astracia at astracia.com and app.astracia.com.
Contact office@astracia.com with privacy questions. A data protection officer has not currently been appointed because an appointment is not currently required; if this changes, contact details will be published here.
This policy covers service users and website visitors. Section 6 also covers public competitor information collected by the service.
2. Information we collect
Account information
Email address, username, securely stored password that we cannot read, company and billing details for paid services, interface and report language, notification settings, any Slack, Teams or Discord webhook you provide, and hashed MCP keys.
Service usage
Idea and market descriptions, your domain if provided, research projects and results, accepted or rejected competitors, notes and statuses for partners, checklist tasks and mentions, sharing links, and service usage records.
Technical information
IP address, device and browser type, access time, application pages visited and errors. These records support security and troubleshooting.
Cookies
See our Cookies policy.
Communications
Messages you send us and our correspondence with you.
Information we do not request: special categories of personal data, including health, religion, political beliefs or biometrics. Do not enter these in free-text fields.
3. Purposes and legal bases
| Activity | Purpose | Legal basis |
|---|---|---|
| Account management and access | Provide the service | Contract performance |
| Research, competitor monitoring and mentions | Deliver requested functionality | Contract performance |
| Billing, invoices and accounting | Collect payment and meet tax duties | Contract and legal obligation |
| Support | Help with questions and issues | Contract / legitimate interest |
| Security, abuse prevention and access logs | Keep the service secure | Legitimate interest |
| Product improvement and aggregate usage statistics | Identify improvements | Legitimate interest |
| Weekly summaries and change notifications | Deliver notifications you enabled | Contract; you can disable them |
Where we rely on legitimate interest, we assess that it does not override your rights. You can request this assessment.
4. Retention periods
- Account information and content: while the account exists. After deletion, there is a 30-day recovery period followed by permanent deletion.
- Billing details and invoices: for the period required by tax rules, stated here as 10 years in Serbia.
- Research, monitoring and mentions: while the account exists; deleted with the relevant research or account.
- Technical logs: 14 days.
- Support correspondence: 24 months.
Backups are removed through routine rotation no later than 90 days after deletion from production.
5. Recipients and processors
We do not sell your data. We share only the minimum necessary information with processors that help operate the service:
- Hosting and infrastructure: servers and databases in Germany, in the European Union, with Hetzner.
- Email provider: transactional messages, verification, password resets and weekly summaries.
- Paddle: our Merchant of Record. We do not see or store card details; Paddle handles them under its terms at paddle.com/legal.
- AI providers: classification, relevance assessment and report generation. We send the idea description and public competitor information, not personal account details.
- Search data providers: keyword volumes, rankings, links and domain traffic.
- Public APIs: services such as YouTube, X, Hacker News, Bluesky, GitHub and Mastodon receive competitor names and search phrases for mentions, not your account data.
- Webhooks you connect: Slack, Microsoft Teams and Discord receive the notifications you enable.
We may disclose information to a competent authority when legally required. We request the legal basis and notify you where permitted.
Transfers outside the EU and EEA: hosting is in the EU. Some AI, search and API providers process data in the United States under standard contractual clauses or an adequacy decision. Account details are not sent to those providers.
6. Public competitor information
Astracia collects information about researched businesses and products exclusively from public sources: websites, sitemaps, RDAP/WHOIS domain registries, certificates, public search and social APIs, reviews, advertisements and directories.
- AstraciaBot respects robots.txt, does not bypass logins or paywalls and limits requests per site. See AstraciaBot for opt-out details.
- The research focuses on businesses and products, not individuals. Incidental personal information, such as a founder name or public post author, is displayed in the requesting user’s report with a source link. We do not create profiles of individuals.
- If you own or work for a company mentioned in a report and want a correction or removal, contact office@astracia.com. We respond within 30 days and can exclude a domain from future crawling.
7. Your rights
Under the GDPR and Serbian personal data protection law, you have rights to:
- access: find out what information we hold and receive a copy;
- rectification: correct inaccurate or incomplete information, including through account settings;
- erasure: request deletion except where retention is legally required;
- restriction: temporarily limit processing while an issue is clarified;
- portability: receive data in a machine-readable format; reports can also be exported in the app;
- objection: object to processing based on legitimate interest;
- withdrawal of consent: withdraw at any time without affecting prior processing;
- complaint: contact Serbia’s Commissioner for Information of Public Importance and Personal Data Protection, or your local EU supervisory authority.
Send requests to office@astracia.com. We respond within 30 days. Complex requests may require an extension, which we will explain. Requests are free unless manifestly unfounded or unnecessarily repetitive.
We do not make automated decisions about you that have legal effects.
8. Security
- HTTPS encryption for pages and requests, including MCP;
- passwords and MCP keys stored in a form that cannot be recovered as readable text;
- workspace separation so one account cannot view another account’s research;
- need-to-know data access with access records;
- regular backups separate from production;
- component updates and monitoring of security advisories.
No system is invulnerable. If a data breach may threaten your rights, we notify the supervisory authority within 72 hours and notify you without delay when the risk is high.
9. Children
The service is not intended for people under 18, and we do not knowingly collect their information. If we learn that a child created an account without parental consent, we delete it.
10. Policy updates
We update this policy when operations or applicable rules change. The latest revision date appears above. We communicate material changes by email and in the application at least 15 days in advance.
11. Privacy contact
Support and requests: office@astracia.com.
Serbian supervisory authority: Commissioner for Information of Public Importance and Personal Data Protection, Bulevar kralja Aleksandra 15, Belgrade.