HomeServicesWorkAboutCareersContact
Get in Touch
AstroLinx

Navigation

01Home02Services03Work04About05Careers06Contact
Get in Touch→

Lahore · Remote-ready

Home/Legal/Privacy Policy
DATA GOVERNANCE & PRIVACY

Privacy Policy

How AstroLinx Technologies collects, fortifies, isolates, and governs personal data, telemetry, and security audit artifacts under strict zero-trust protocols.

Effective DateJanuary 15, 2026
Last RevisedAugust 22, 2026
Version2.4.0
ClassificationPublic Standard

TABLE OF CONTENTS

15 CLAUSES
  • 01 //Overview & Zero-Trust Architecture
  • 02 //Governance, Roles & Scope
  • 03 //Categories of Information Collected
  • 04 //Lawful Basis for Processing
  • 05 //How We Use & Process Data
  • 06 //Security Audits & System Isolation
  • 07 //Data Retention & Cryptographic Deletion
  • 08 //Sub-processors & Third-Party Disclosure
  • 09 //Technical Safeguards & Encryption
  • 10 //Cross-Border Data Transfers
  • 11 //Data Subject Rights & Controls
  • 12 //Cookies & Telemetry Policy
  • 13 //Children's Privacy Protection
  • 14 //Policy Revisions & Updates
  • 15 //Contact & Privacy Office
RELATED POLICIES
→ Privacy Policy→ Terms & Conditions

Zero-Trust Integrity

All customer systems, codebases, and security audit artifacts are governed by strict zero-knowledge controls.

01 // Overview & Zero-Trust Architecture

At AstroLinx Technologies ("AstroLinx", "we", "us", or "our"), we operate at the intersection of high-stakes software engineering and elite cybersecurity. We believe that privacy is not merely a regulatory checklist; it is an architectural foundation. Our systems are engineered under a Zero-Trust framework where verification is continuous, data access is strictly compartmentalized, and client confidentiality is uncompromising.

This Privacy Policy sets forth how we collect, process, store, protect, and disclose information when you visit our website (https://astrolinx.site), engage our software architecture and engineering services, commission penetration testing or cybersecurity audits, or communicate with our operations team.

Zero-Trust Privacy Core

We do not sell, rent, monetize, or trade client data or technical audit findings. Every piece of information entrusted to AstroLinx is governed by cryptographic isolation and least-privilege administrative access.

02 // Governance, Roles & Scope

Depending on the nature of your interaction with AstroLinx, our role is defined as follows:

  • Data Controller: For visitors browsing our digital platforms, prospective clients submitting project inquiry forms, and individuals directly communicating with our team, AstroLinx acts as the Data Controller responsible for determining the purposes and means of processing personal data.
  • Data Processor / Service Provider: When enterprise clients engage AstroLinx to build custom software, implement artificial intelligence pipelines, or perform technical penetration testing on their servers, APIs, or databases, AstroLinx acts strictly as a Data Processor. In this capacity, we process system data solely pursuant to the executed Master Services Agreement (MSA), Statement of Work (SOW), and Data Processing Addendum (DPA).

03 // Categories of Information Collected

We gather only the minimum data necessary to conduct business, deliver engineering excellence, and secure client infrastructure:

CategoryData Points CollectedCollection Purpose
Direct IdentificationFull Name, Corporate Email, Phone Number, Organization Name, Job Title.Project consultations, contract execution, client onboarding, and billing.
Technical & TelemetryIP Address, Browser Type & Version, Operating System, Time Zone, Referrer URLs, Device Identifiers.DDoS mitigation, traffic anomaly analysis, infrastructure optimization, and security defense.
Engagement SpecificationsTarget hostnames, repository access tokens, cloud architecture diagrams, API specs, testing boundaries.Fulfilling engineering deliverables, running penetration audits, and fortifying codebases.
Audit Artifacts & LogsPenetration testing payloads, ephemeral vulnerability logs, memory snapshots, proof-of-concept exploits.Compiling confidential vulnerability reports and remediation guidance.

04 // Lawful Basis for Processing

We process personal and organizational data in accordance with applicable global regulations (including GDPR, CCPA/CPRA, and Pakistan PECA/Data Protection standards) under the following lawful bases:

  • Contractual Performance: Processing required to initiate, execute, and deliver contracted engineering, design, and cybersecurity services.
  • Legitimate Business Interests: Maintaining platform stability, safeguarding our digital perimeter against threat actors, optimizing system performance, and preventing fraudulent activities.
  • Explicit Consent: Where you have provided unambiguous consent (e.g., subscribing to technical briefings or opting into non-essential telemetry).
  • Legal Compliance: Complying with statutory reporting obligations, tax regulations, or lawful court orders from competent jurisdictions.

05 // How We Use & Process Data

AstroLinx employs collected data exclusively for the following defined operations:

  • Engineering Architecture & Delivery: Provisioning environments, developing bespoke full-stack applications, and tuning enterprise AI integrations.
  • Cybersecurity Operations: Executing controlled penetration tests, vulnerability scans, threat modeling, and defensive hardening.
  • Client Communications: Transmitting project status reports, critical vulnerability advisories, invoices, and technical documentation.
  • Infrastructure Resilience: Monitoring site health, mitigating automated bots and malicious brute-force attempts, and upholding uptime SLAs.

06 // Security Audits & System Isolation

During penetration testing and cybersecurity engagements, AstroLinx operators may gain temporary access to sensitive client infrastructure and synthetic or production databases. We apply the highest industry standards to safeguard this engagement data:

Air-Gapped Assessment Pods

Security testing tools run within dedicated, isolated sandboxes with ephemeral memory and strict network egress controls.

Zero Production Persistence

We do not store customer production records or raw PII on testing machines. Proofs of Concept (PoCs) utilize sanitized placeholders.

Encrypted Deliverables

Vulnerability reports containing findings and remediation steps are transmitted solely via PGP/GPG encrypted channels or secure client portals.

07 // Data Retention & Cryptographic Deletion

We adhere to strict data minimization timelines. We retain personal and technical data only for the duration required to achieve the stated purposes or fulfill statutory obligations:

  • General Inquiries & Leads: Retained for 180 days post-last interaction, after which records are purged if no commercial engagement ensues.
  • Active Client Records & Code Repositories: Retained for the active duration of the contract plus 90 days for warranty and handover support.
  • Security Audit Evidence & Logs: Raw testing artifacts are cryptographically wiped 30 days following formal delivery and sign-off of the final remediation report.
  • Financial & Invoicing Records: Retained for 7 years in accordance with applicable corporate tax and accounting statutes.

08 // Sub-processors & Third-Party Disclosure

AstroLinx never sells personal data or monetization telemetry to data brokers. We share data strictly with vetted infrastructure sub-processors bound by stringent confidentiality and Data Processing Agreements:

  • Cloud Hosting & Compute: Vercel, Amazon Web Services (AWS), Google Cloud Platform (GCP) for secure deployment hosting and edge network delivery.
  • Analytics & Performance: Vercel Speed Insights and Web Analytics (anonymized, privacy-first, cookie-free telemetry).
  • Transactional Communications: Encrypted enterprise email gateways for direct client correspondence.
  • Legal & Regulatory Authorities: We disclose data only if required by a legally binding subpoena, warrant, or statutory mandate issued by a court of competent jurisdiction.

09 // Technical Safeguards & Encryption

As a cybersecurity firm, our security controls exceed baseline commercial standards:

Defense-in-Depth Measures

  • Encryption at Rest: All databases, storage volumes, and backups utilize AES-256-GCM encryption.
  • Encryption in Transit: Mandatory TLS 1.3 encryption across all public and internal service communications with HSTS enforcement.
  • Access Governance: Hardware-based Multi-Factor Authentication (FIDO2/WebAuthn), least-privilege RBAC, and automated session timeouts.
  • Continuous Vulnerability Auditing: Continuous automated SAST/DAST pipeline scans and regular manual red-team assessments.

10 // Cross-Border Data Transfers

AstroLinx operates globally with physical offices in Pakistan and cloud infrastructure distributed worldwide. If personal data is transferred across international boundaries, we ensure adequate safeguards through standard mechanisms, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Adherence to robust technical, contractual, and organizational safeguards ensuring equivalent data defense standards.
  • Cryptographic shielding preventing unauthorized intercept during transit.

11 // Data Subject Rights & Controls

Regardless of your geographical jurisdiction, AstroLinx affords you comprehensive rights over your personal data:

  • Right of Access: You may request a complete copy of the personal information we maintain regarding your account or identity.
  • Right to Rectification: You may request immediate correction of inaccurate, obsolete, or incomplete personal data.
  • Right to Erasure ("Right to be Forgotten"): You may request permanent deletion of your data where it is no longer required for contractual or statutory compliance.
  • Right to Data Portability: You may request your data in a structured, machine-readable format (e.g., JSON or CSV).
  • Right to Object & Restrict Processing: You may object to processing based on legitimate interests or withdraw previously given consent at any time.

To exercise any of these rights, submit a verified request to our privacy team at contact@astrolinx.site. We process and respond to all verified requests within 30 days without undue delay.

12 // Cookies & Telemetry Policy

We minimize the use of cookies and tracking mechanisms on our website:

  • Essential Session Tokens: Strictly necessary for navigation, security token validation, and CSRF protection. These cannot be disabled.
  • Aggregated Performance Metrics: We utilize privacy-preserving, cookieless telemetry to track page performance, core web vitals, and asset load latency. No persistent personal identifiers or cross-site tracking cookies are deployed.

13 // Children's Privacy Protection

Our services and website are targeted exclusively at commercial enterprises, founders, and professional software developers. We do not knowingly collect, solicit, or process personal information from individuals under the age of 18. If we discover that personal data of a minor has been inadvertently collected, we will immediately purge such data from our active servers and backups.

14 // Policy Revisions & Updates

We may periodically update this Privacy Policy to reflect advancements in our security architecture, legal requirements, or evolving service offerings. Material changes will be accompanied by an updated "Last Revised" date and, where appropriate, direct notification to our active enterprise clients via email or client portal advisories.

15 // Contact & Privacy Office

For questions, legal notices, or formal Data Subject Access Requests (DSAR), reach out to our Data Protection & Legal Operations Office:

AstroLinx Technologies — Legal & Compliance

Lead Official: Privacy Operations & Data Protection Officer

Email: contact@astrolinx.site

Direct Telephone: +92 304 4700442

Physical Address: Baldia Road, Rachna Town, Shadara, Lahore, Pakistan

LEGAL & COMPLIANCE DIRECTORY

Questions or Privacy Requests?

For inquiries regarding data access, vulnerability disclosures, custom master service agreements (MSA), or non-disclosure agreements (NDA), contact our legal operations team.

LEGAL EMAILcontact@astrolinx.site
PRIMARY PHONE+92 304 4700442
REGISTERED ADDRESS

AstroLinx Technologies, Baldia Road, Rachna Town, Shadara, Lahore, Pakistan

AstroLinx

Engineering secure digital ecosystems for teams who refuse to compromise on growth or defense.

Lahore, Pakistan · Remote-ready

Services

  • All Services
  • Our Craft
  • Engagement Models
  • Strategic Advisory
  • Capabilities

Company

  • About
  • Our Story
  • Team
  • Work
  • Careers
  • Our Process

Connect

  • Get in Touch
  • Email
  • LinkedIn
  • Instagram

© 2026 AstroLinx Technologies. All Rights Reserved.

Privacy PolicyTerms and ConditionsContact