Back to Home

    GDPR Compliance

    Last updated: April 30, 2026

    01Our Commitment

    Astrixy is fully compliant with the EU General Data Protection Regulation (GDPR). We process personal data lawfully, transparently, and with strict purpose limitation. All EU customer data is encrypted at rest (AES-256-GCM), masked in public views, and protected by row-level security policies.

    02Your Rights Under GDPR

    • Right to Access: Request a copy of all personal data we hold about you.
    • Right to Rectification: Correct inaccurate or incomplete personal data.
    • Right to Erasure: Request deletion of your data ("right to be forgotten").
    • Right to Portability: Receive your data in a structured, machine-readable format.
    • Right to Object: Object to processing of your data for marketing or profiling.
    • Right to Restrict: Limit how we process your data while disputes are resolved.

    03Lawful Basis for Processing

    • Contract: Processing necessary to deliver our service.
    • Consent: Marketing communications and optional cookies.
    • Legal obligation: Tax records, fraud prevention, KYC.
    • Legitimate interest: Security monitoring and product improvement.

    04Data Protection Measures

    • AES-256-GCM encryption for sensitive secrets
    • Row-level security on every database table
    • PII masked in all public-facing views
    • IP anonymization (last octet redacted)
    • Email and tokens redacted from analytics URLs
    • AI-powered fraud detection and anomaly monitoring
    • Audit logs for all data access (service-role only)

    05Exercise Your Rights

    To exercise any GDPR right, email our Data Protection Officer. We respond within 30 days as required by law.

    DPO Email: dpo@astrixy.app
    Privacy Email: privacy@astrixy.app

    06Data Transfers

    Cross-border data transfers use Standard Contractual Clauses (SCCs) approved by the European Commission. We do not transfer data to jurisdictions without adequate protection.