Back to home

We respect your privacy

GDPR & SOC 2 Compliant

Privacy Policy

Last Updated: January 29, 2026

At Astervis, we take your privacy seriously. This Privacy Policy describes how we collect, use, store, and protect your personal information.


1. Information We Collect

1.1 Information You Provide

When using Astervis, we collect information you provide directly:

  • Account credentials: name, email address, password
  • Profile information: job title, company name, contact details
  • Payment information: credit card data (through secure payment providers)
  • Support requests: your inquiries and correspondence with our team

1.2 Automatically Collected Information

We automatically collect certain information when you use the service:

  • Usage data: actions in the system, features, session times
  • Technical data: IP address, browser type, operating system, device version
  • Cookies and similar technologies: to improve user experience
  • Logs: access records and actions for security and debugging

1.3 Call Data

As part of providing call center monitoring services, we process:

  • Call audio recordings: for analysis and training
  • Call metadata: date, time, duration, participants
  • Transcriptions: text versions of conversations
  • Analytics data: quality metrics, sentiment analysis, keywords

1.4 CRM Integration Data

When you connect Astervis to a CRM system (such as Kommo/amoCRM), we process the following data to provide integration services:

  • CRM entity data: contacts, leads, companies, and pipelines synchronized between your PBX and CRM
  • User mapping: association between CRM users and PBX operators
  • OAuth tokens: securely stored authentication credentials for CRM API access (encrypted at rest)
  • Webhook events: real-time notifications from the CRM about entity changes (lead status, contact updates)
  • Call-to-CRM linking: mapping of call records to CRM contacts, leads, and companies

All CRM data is processed exclusively on your self-hosted Astervis instance. We do not transmit CRM data to any third-party servers. OAuth tokens are stored in your local database and Redis cache, and are refreshed automatically.

2. How We Use Your Information

We use collected information to:

2.1 Provide Services

  • Process and fulfill your requests
  • Provide access to platform features
  • Analyze calls and generate reports
  • Personalize your experience

2.2 Improve Service

  • Develop new features and capabilities
  • Analyze usage to optimize performance
  • Train machine learning models (on anonymized data)
  • Fix bugs and technical issues

2.3 Communication

  • Send service notifications and updates
  • Respond to your support requests
  • Marketing messages (with your consent)
  • Important changes to terms or policy

2.4 Security and Compliance

  • Detect and prevent fraud
  • Protect against unauthorized access
  • Comply with legal requirements
  • Protect user rights and security

3. Legal Basis for Processing (GDPR)

For EU users, we process personal data on the following grounds:

  • Contract performance: to provide requested services
  • Legitimate interest: to improve service and ensure security
  • Consent: for marketing communications and optional features
  • Legal compliance: to fulfill legal obligations

4. Sharing Data with Third Parties

We do not sell your personal information. We may share data with third parties in the following cases:

4.1 Service Providers

We work with trusted partners who help us provide the service:

  • Cloud infrastructure: hosting and data storage (AWS, Google Cloud)
  • Payment processors: payment processing (Stripe, Polar)
  • Analytics: usage analysis (Google Analytics)
  • Customer support: customer service tools

All providers are required to comply with strict data protection requirements.

4.2 Legal Requirements

We may disclose information if required:

  • By court order or government authorities
  • To protect our rights and security
  • To prevent fraud or law violations
  • With your explicit consent

4.3 Business Transactions

In case of merger, acquisition, or asset sale, your data may be transferred to the new owner with notification of changes.

5. Data Storage and Security

5.1 Security Measures

We employ modern security measures to protect your data:

  • Encryption: SSL/TLS for data transmission, AES-256 for storage
  • Access control: strict access policies, multi-factor authentication
  • Monitoring: 24/7 security threat monitoring
  • Backup: regular backups to prevent data loss
  • Audit: regular security and compliance audits

5.2 Retention Periods

We retain your data only as long as necessary:

  • Account data: while your account is active
  • Call data: according to your settings (default 90 days)
  • Payment information: according to tax law (typically 5-7 years)
  • Logs and analytics: up to 12 months

After account deletion, we delete all personal data within 30 days.

6. Your Rights

Under applicable law, you have the following rights:

6.1 Access and Management Rights

  • Access: request a copy of your personal data
  • Correction: update or correct inaccurate information
  • Deletion: request deletion of your data ("right to be forgotten")
  • Restriction: limit processing in certain cases
  • Portability: receive data in a structured format
  • Objection: opt out of certain types of processing

6.2 How to Exercise Rights

To exercise your rights:

  1. Log into account settings for self-service management
  2. Contact us at privacy@astervis.com
  3. We will respond to your request within 30 days

7. International Data Transfers

Your data may be processed on servers located outside your country. We ensure adequate protection for international transfers through:

  • EU Standard Contractual Clauses
  • Compliance certifications (ISO 27001, SOC 2)
  • User consent (when required)

8. Cookies and Tracking Technologies

8.1 Types of Cookies

We use the following types of cookies:

  • Essential: for basic service functionality
  • Functional: to remember your preferences
  • Analytics: to understand service usage
  • Marketing: to personalize advertising (with your consent)

8.2 Managing Cookies

You can manage cookies through:

  • Your browser settings
  • Our consent management tool
  • Opt-out of analytics cookies in profile settings

9. Children's Privacy

Our service is not intended for persons under 18 years old. We do not knowingly collect information from children. If you learn that a child has provided us with personal data, contact us to delete it.

10. Changes to Policy

We may update this Privacy Policy:

  • Notification of material changes sent 30 days in advance
  • Current version always available on this page
  • Last update date indicated at top of document

11. Contact Information

If you have questions or concerns about your privacy:

  • Privacy inquiries: privacy@astervis.com
  • General support: support@astervis.com
  • Mailing address: [Your company address]

Data Protection Officer (DPO)

For EU users, you can contact our Data Protection Officer:

  • Email: dpo@astervis.com
  • Contact form: available in account settings

12. Additional Information for EU Users

12.1 Your Rights Under GDPR

In addition to the rights described above, you have the right to:

  • File a complaint with a data protection supervisory authority
  • Withdraw consent at any time (does not affect lawfulness of previous processing)
  • Receive explanation of automated decision-making

12.2 Automated Decision-Making

We use automated processing for:

  • Call quality analysis
  • Speech recognition and transcription
  • Emotion and sentiment detection

You have the right to request an explanation and challenge decisions made automatically.


By using Astervis, you acknowledge that you have read and understood this Privacy Policy. We are committed to protecting your privacy and ensuring transparency in data processing.

Questions about our privacy practices? Contact our Data Protection Officer at privacy@astervis.com

GDPR Compliant
ISO 27001
SOC 2 Type II