Privacy Policy
Last Updated: January 29, 2026
At Astervis, we take your privacy seriously. This Privacy Policy describes how we collect, use, store, and protect your personal information.
1. Information We Collect
1.1 Information You Provide
When using Astervis, we collect information you provide directly:
- Account credentials: name, email address, password
- Profile information: job title, company name, contact details
- Payment information: credit card data (through secure payment providers)
- Support requests: your inquiries and correspondence with our team
1.2 Automatically Collected Information
We automatically collect certain information when you use the service:
- Usage data: actions in the system, features, session times
- Technical data: IP address, browser type, operating system, device version
- Cookies and similar technologies: to improve user experience
- Logs: access records and actions for security and debugging
1.3 Call Data
As part of providing call center monitoring services, we process:
- Call audio recordings: for analysis and training
- Call metadata: date, time, duration, participants
- Transcriptions: text versions of conversations
- Analytics data: quality metrics, sentiment analysis, keywords
1.4 CRM Integration Data
When you connect Astervis to a CRM system (such as Kommo/amoCRM), we process the following data to provide integration services:
- CRM entity data: contacts, leads, companies, and pipelines synchronized between your PBX and CRM
- User mapping: association between CRM users and PBX operators
- OAuth tokens: securely stored authentication credentials for CRM API access (encrypted at rest)
- Webhook events: real-time notifications from the CRM about entity changes (lead status, contact updates)
- Call-to-CRM linking: mapping of call records to CRM contacts, leads, and companies
All CRM data is processed exclusively on your self-hosted Astervis instance. We do not transmit CRM data to any third-party servers. OAuth tokens are stored in your local database and Redis cache, and are refreshed automatically.
2. How We Use Your Information
We use collected information to:
2.1 Provide Services
- Process and fulfill your requests
- Provide access to platform features
- Analyze calls and generate reports
- Personalize your experience
2.2 Improve Service
- Develop new features and capabilities
- Analyze usage to optimize performance
- Train machine learning models (on anonymized data)
- Fix bugs and technical issues
2.3 Communication
- Send service notifications and updates
- Respond to your support requests
- Marketing messages (with your consent)
- Important changes to terms or policy
2.4 Security and Compliance
- Detect and prevent fraud
- Protect against unauthorized access
- Comply with legal requirements
- Protect user rights and security
3. Legal Basis for Processing (GDPR)
For EU users, we process personal data on the following grounds:
- Contract performance: to provide requested services
- Legitimate interest: to improve service and ensure security
- Consent: for marketing communications and optional features
- Legal compliance: to fulfill legal obligations
4. Sharing Data with Third Parties
We do not sell your personal information. We may share data with third parties in the following cases:
4.1 Service Providers
We work with trusted partners who help us provide the service:
- Cloud infrastructure: hosting and data storage (AWS, Google Cloud)
- Payment processors: payment processing (Stripe, Polar)
- Analytics: usage analysis (Google Analytics)
- Customer support: customer service tools
All providers are required to comply with strict data protection requirements.
4.2 Legal Requirements
We may disclose information if required:
- By court order or government authorities
- To protect our rights and security
- To prevent fraud or law violations
- With your explicit consent
4.3 Business Transactions
In case of merger, acquisition, or asset sale, your data may be transferred to the new owner with notification of changes.
5. Data Storage and Security
5.1 Security Measures
We employ modern security measures to protect your data:
- Encryption: SSL/TLS for data transmission, AES-256 for storage
- Access control: strict access policies, multi-factor authentication
- Monitoring: 24/7 security threat monitoring
- Backup: regular backups to prevent data loss
- Audit: regular security and compliance audits
5.2 Retention Periods
We retain your data only as long as necessary:
- Account data: while your account is active
- Call data: according to your settings (default 90 days)
- Payment information: according to tax law (typically 5-7 years)
- Logs and analytics: up to 12 months
After account deletion, we delete all personal data within 30 days.
6. Your Rights
Under applicable law, you have the following rights:
6.1 Access and Management Rights
- Access: request a copy of your personal data
- Correction: update or correct inaccurate information
- Deletion: request deletion of your data ("right to be forgotten")
- Restriction: limit processing in certain cases
- Portability: receive data in a structured format
- Objection: opt out of certain types of processing
6.2 How to Exercise Rights
To exercise your rights:
- Log into account settings for self-service management
- Contact us at privacy@astervis.com
- We will respond to your request within 30 days
7. International Data Transfers
Your data may be processed on servers located outside your country. We ensure adequate protection for international transfers through:
- EU Standard Contractual Clauses
- Compliance certifications (ISO 27001, SOC 2)
- User consent (when required)
8. Cookies and Tracking Technologies
8.1 Types of Cookies
We use the following types of cookies:
- Essential: for basic service functionality
- Functional: to remember your preferences
- Analytics: to understand service usage
- Marketing: to personalize advertising (with your consent)
8.2 Managing Cookies
You can manage cookies through:
- Your browser settings
- Our consent management tool
- Opt-out of analytics cookies in profile settings
9. Children's Privacy
Our service is not intended for persons under 18 years old. We do not knowingly collect information from children. If you learn that a child has provided us with personal data, contact us to delete it.
10. Changes to Policy
We may update this Privacy Policy:
- Notification of material changes sent 30 days in advance
- Current version always available on this page
- Last update date indicated at top of document
11. Contact Information
If you have questions or concerns about your privacy:
- Privacy inquiries: privacy@astervis.com
- General support: support@astervis.com
- Mailing address: [Your company address]
Data Protection Officer (DPO)
For EU users, you can contact our Data Protection Officer:
- Email: dpo@astervis.com
- Contact form: available in account settings
12. Additional Information for EU Users
12.1 Your Rights Under GDPR
In addition to the rights described above, you have the right to:
- File a complaint with a data protection supervisory authority
- Withdraw consent at any time (does not affect lawfulness of previous processing)
- Receive explanation of automated decision-making
12.2 Automated Decision-Making
We use automated processing for:
- Call quality analysis
- Speech recognition and transcription
- Emotion and sentiment detection
You have the right to request an explanation and challenge decisions made automatically.
By using Astervis, you acknowledge that you have read and understood this Privacy Policy. We are committed to protecting your privacy and ensuring transparency in data processing.
