01 // Overview & Zero-Trust Architecture
At AstroLinx Technologies ("AstroLinx", "we", "us", or "our"), we operate at the intersection of high-stakes software engineering and elite cybersecurity. We believe that privacy is not merely a regulatory checklist; it is an architectural foundation. Our systems are engineered under a Zero-Trust framework where verification is continuous, data access is strictly compartmentalized, and client confidentiality is uncompromising.
This Privacy Policy sets forth how we collect, process, store, protect, and disclose information when you visit our website (https://astrolinx.site), engage our software architecture and engineering services, commission penetration testing or cybersecurity audits, or communicate with our operations team.
Zero-Trust Privacy Core
We do not sell, rent, monetize, or trade client data or technical audit findings. Every piece of information entrusted to AstroLinx is governed by cryptographic isolation and least-privilege administrative access.
02 // Governance, Roles & Scope
Depending on the nature of your interaction with AstroLinx, our role is defined as follows:
- Data Controller: For visitors browsing our digital platforms, prospective clients submitting project inquiry forms, and individuals directly communicating with our team, AstroLinx acts as the Data Controller responsible for determining the purposes and means of processing personal data.
- Data Processor / Service Provider: When enterprise clients engage AstroLinx to build custom software, implement artificial intelligence pipelines, or perform technical penetration testing on their servers, APIs, or databases, AstroLinx acts strictly as a Data Processor. In this capacity, we process system data solely pursuant to the executed Master Services Agreement (MSA), Statement of Work (SOW), and Data Processing Addendum (DPA).
03 // Categories of Information Collected
We gather only the minimum data necessary to conduct business, deliver engineering excellence, and secure client infrastructure:
| Category | Data Points Collected | Collection Purpose |
|---|---|---|
| Direct Identification | Full Name, Corporate Email, Phone Number, Organization Name, Job Title. | Project consultations, contract execution, client onboarding, and billing. |
| Technical & Telemetry | IP Address, Browser Type & Version, Operating System, Time Zone, Referrer URLs, Device Identifiers. | DDoS mitigation, traffic anomaly analysis, infrastructure optimization, and security defense. |
| Engagement Specifications | Target hostnames, repository access tokens, cloud architecture diagrams, API specs, testing boundaries. | Fulfilling engineering deliverables, running penetration audits, and fortifying codebases. |
| Audit Artifacts & Logs | Penetration testing payloads, ephemeral vulnerability logs, memory snapshots, proof-of-concept exploits. | Compiling confidential vulnerability reports and remediation guidance. |
04 // Lawful Basis for Processing
We process personal and organizational data in accordance with applicable global regulations (including GDPR, CCPA/CPRA, and Pakistan PECA/Data Protection standards) under the following lawful bases:
- Contractual Performance: Processing required to initiate, execute, and deliver contracted engineering, design, and cybersecurity services.
- Legitimate Business Interests: Maintaining platform stability, safeguarding our digital perimeter against threat actors, optimizing system performance, and preventing fraudulent activities.
- Explicit Consent: Where you have provided unambiguous consent (e.g., subscribing to technical briefings or opting into non-essential telemetry).
- Legal Compliance: Complying with statutory reporting obligations, tax regulations, or lawful court orders from competent jurisdictions.
05 // How We Use & Process Data
AstroLinx employs collected data exclusively for the following defined operations:
- Engineering Architecture & Delivery: Provisioning environments, developing bespoke full-stack applications, and tuning enterprise AI integrations.
- Cybersecurity Operations: Executing controlled penetration tests, vulnerability scans, threat modeling, and defensive hardening.
- Client Communications: Transmitting project status reports, critical vulnerability advisories, invoices, and technical documentation.
- Infrastructure Resilience: Monitoring site health, mitigating automated bots and malicious brute-force attempts, and upholding uptime SLAs.
06 // Security Audits & System Isolation
During penetration testing and cybersecurity engagements, AstroLinx operators may gain temporary access to sensitive client infrastructure and synthetic or production databases. We apply the highest industry standards to safeguard this engagement data:
Air-Gapped Assessment Pods
Security testing tools run within dedicated, isolated sandboxes with ephemeral memory and strict network egress controls.
Zero Production Persistence
We do not store customer production records or raw PII on testing machines. Proofs of Concept (PoCs) utilize sanitized placeholders.
Encrypted Deliverables
Vulnerability reports containing findings and remediation steps are transmitted solely via PGP/GPG encrypted channels or secure client portals.
07 // Data Retention & Cryptographic Deletion
We adhere to strict data minimization timelines. We retain personal and technical data only for the duration required to achieve the stated purposes or fulfill statutory obligations:
- General Inquiries & Leads: Retained for 180 days post-last interaction, after which records are purged if no commercial engagement ensues.
- Active Client Records & Code Repositories: Retained for the active duration of the contract plus 90 days for warranty and handover support.
- Security Audit Evidence & Logs: Raw testing artifacts are cryptographically wiped 30 days following formal delivery and sign-off of the final remediation report.
- Financial & Invoicing Records: Retained for 7 years in accordance with applicable corporate tax and accounting statutes.
08 // Sub-processors & Third-Party Disclosure
AstroLinx never sells personal data or monetization telemetry to data brokers. We share data strictly with vetted infrastructure sub-processors bound by stringent confidentiality and Data Processing Agreements:
- Cloud Hosting & Compute: Vercel, Amazon Web Services (AWS), Google Cloud Platform (GCP) for secure deployment hosting and edge network delivery.
- Analytics & Performance: Vercel Speed Insights and Web Analytics (anonymized, privacy-first, cookie-free telemetry).
- Transactional Communications: Encrypted enterprise email gateways for direct client correspondence.
- Legal & Regulatory Authorities: We disclose data only if required by a legally binding subpoena, warrant, or statutory mandate issued by a court of competent jurisdiction.
09 // Technical Safeguards & Encryption
As a cybersecurity firm, our security controls exceed baseline commercial standards:
Defense-in-Depth Measures
- Encryption at Rest: All databases, storage volumes, and backups utilize AES-256-GCM encryption.
- Encryption in Transit: Mandatory TLS 1.3 encryption across all public and internal service communications with HSTS enforcement.
- Access Governance: Hardware-based Multi-Factor Authentication (FIDO2/WebAuthn), least-privilege RBAC, and automated session timeouts.
- Continuous Vulnerability Auditing: Continuous automated SAST/DAST pipeline scans and regular manual red-team assessments.
10 // Cross-Border Data Transfers
AstroLinx operates globally with physical offices in Pakistan and cloud infrastructure distributed worldwide. If personal data is transferred across international boundaries, we ensure adequate safeguards through standard mechanisms, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adherence to robust technical, contractual, and organizational safeguards ensuring equivalent data defense standards.
- Cryptographic shielding preventing unauthorized intercept during transit.
11 // Data Subject Rights & Controls
Regardless of your geographical jurisdiction, AstroLinx affords you comprehensive rights over your personal data:
- Right of Access: You may request a complete copy of the personal information we maintain regarding your account or identity.
- Right to Rectification: You may request immediate correction of inaccurate, obsolete, or incomplete personal data.
- Right to Erasure ("Right to be Forgotten"): You may request permanent deletion of your data where it is no longer required for contractual or statutory compliance.
- Right to Data Portability: You may request your data in a structured, machine-readable format (e.g., JSON or CSV).
- Right to Object & Restrict Processing: You may object to processing based on legitimate interests or withdraw previously given consent at any time.
To exercise any of these rights, submit a verified request to our privacy team at contact@astrolinx.site. We process and respond to all verified requests within 30 days without undue delay.
12 // Cookies & Telemetry Policy
We minimize the use of cookies and tracking mechanisms on our website:
- Essential Session Tokens: Strictly necessary for navigation, security token validation, and CSRF protection. These cannot be disabled.
- Aggregated Performance Metrics: We utilize privacy-preserving, cookieless telemetry to track page performance, core web vitals, and asset load latency. No persistent personal identifiers or cross-site tracking cookies are deployed.
13 // Children's Privacy Protection
Our services and website are targeted exclusively at commercial enterprises, founders, and professional software developers. We do not knowingly collect, solicit, or process personal information from individuals under the age of 18. If we discover that personal data of a minor has been inadvertently collected, we will immediately purge such data from our active servers and backups.
14 // Policy Revisions & Updates
We may periodically update this Privacy Policy to reflect advancements in our security architecture, legal requirements, or evolving service offerings. Material changes will be accompanied by an updated "Last Revised" date and, where appropriate, direct notification to our active enterprise clients via email or client portal advisories.
15 // Contact & Privacy Office
For questions, legal notices, or formal Data Subject Access Requests (DSAR), reach out to our Data Protection & Legal Operations Office:
AstroLinx Technologies — Legal & Compliance
Lead Official: Privacy Operations & Data Protection Officer
Email: contact@astrolinx.site
Direct Telephone: +92 304 4700442
Physical Address: Baldia Road, Rachna Town, Shadara, Lahore, Pakistan
Questions or Privacy Requests?
For inquiries regarding data access, vulnerability disclosures, custom master service agreements (MSA), or non-disclosure agreements (NDA), contact our legal operations team.
AstroLinx Technologies, Baldia Road, Rachna Town, Shadara, Lahore, Pakistan