Privacy Policy

Last updated: July 21, 2026

This policy explains how Astral Datos collects, uses, stores and protects personal data when you visit our website, contact us or use our expense-management services.

1. Scope and responsible party

This policy applies to Astral Datos websites, applications and services. Astral Datos is responsible for the personal data described here, unless a customer uses the platform to process data under its own instructions. In that case, the customer is the controller and Astral Datos acts as its service provider or processor.

2. Data we collect

We may collect contact and account details; company, billing and support information; invoices, receipts and expense records uploaded to the platform; communications with us; and technical information such as device, browser, IP address, access time and usage logs. We collect only information reasonably necessary to provide and secure the service.

3. How we use data

We use personal data to provide and improve the service, authenticate users, process and classify documents, apply customer-configured rules, provide support, communicate about accounts, prevent fraud and abuse, meet legal obligations and protect our users, systems and rights. Where required, we rely on consent, performance of a contract, legitimate interests or compliance with law.

4. When we share data

We may share data with vetted cloud, security, analytics, communications and support providers that process it for us under contractual safeguards. We may also disclose information when required by law, to protect rights or safety, or as part of a merger, financing or business transfer. We do not sell personal data or use customer documents for third-party advertising.

5. Storage and retention

Data may be processed in countries where Astral Datos or its providers operate. We use appropriate contractual and technical safeguards for international transfers. We retain information only for as long as needed to provide the service, meet contractual and legal duties, resolve disputes and maintain security, after which it is deleted or anonymized.

6. Security

We use administrative, technical and organizational measures designed to protect data, including encryption in transit and at rest, role-based access, logging, backups and restricted production access. No system is completely secure, so customers must also protect credentials and promptly report suspected unauthorized access.

7. Your choices and rights

Depending on your location, you may request access, correction, deletion, portability or restriction of your personal data, object to certain processing, or withdraw consent. You may also complain to the relevant data-protection authority. We may need to verify your identity and may retain information where the law requires it.

8. Cookies and policy changes

We may use essential storage technologies needed for security, language and theme preferences, and service operation. Any non-essential analytics or marketing cookies will be subject to the choices required by applicable law. We may update this policy and will publish the revised date and provide additional notice when a material change requires it.

Contact us

Questions, requests or complaints about these terms or our privacy practices may be sent to:

[email protected]