Skip to content
Back to site

Data Protection & Records Policy

How we classify, hold, retain and dispose of the information customers give us — including drawings and specifications, which are usually the most valuable thing we hold.

Last updated
9 September 2026
Applies to
Astratech Solutions
Written against
Digital Personal Data Protection Act, 2023 · Information Technology Act, 2000, s.43A & SPDI Rules, 2011 · EU & UK GDPR

1. Scope

This policy applies to all information Astratech Solutions holds in the course of quoting for and manufacturing customer assemblies, whether it is personal data, commercial information or engineering data.

It sits alongside our Privacy Policy. Where the Privacy Policy explains a person’s rights, this document explains our internal handling.

2. How we classify information

Not everything needs the same protection, so we grade what we hold and handle it accordingly.

ClassExamplesHandling
Customer confidentialDrawings, wire lists, specifications, part numbers, pricingAccess limited to the people working the job. Never published, never reused for another customer, never shown as portfolio work without written permission.
Personal dataNames, business email addresses, telephone numbersHeld only while in use, then deleted. Processed under the DPDP Act.
Business recordsQuotations, purchase orders, invoices, test recordsRetained for the statutory period, then destroyed.
InternalProcess notes, fixture designs, methodsOur own information; not disclosed to customers or third parties.

3. Collection

We collect the minimum needed to do the job. In practice that means a name, a company, an email address, and the technical detail of the assembly.

We do not ask for financial account details, government identifiers, or any category the SPDI Rules class as sensitive personal data, and we ask customers not to send them.

4. Access control

  • Access is granted on need, by role, and removed when someone no longer needs it.
  • Accounts that hold customer correspondence or drawings require multi-factor authentication.
  • Devices used for work are protected by full-disk encryption and a screen lock.
  • Customer drawings are not copied to personal accounts, personal devices or consumer file-sharing services.
  • Where an outside process is needed for a job, we tell the customer who and obtain agreement before anything is shared.

5. Retention and disposal

Information is kept while it is doing a job and for as long as the law requires, then destroyed. We do not keep records indefinitely "in case".

RecordRetentionDisposal
Enquiry that did not become an order24 months from last contactDeleted
Quotation issued24 months from date of quotationDeleted
Customer drawings and specificationsWhile the assembly may need rebuilding or supportingReturned or securely destroyed on request
Test and inspection recordsMinimum 3 years, or as the customer’s sector requiresSecurely destroyed
Invoices and statutory accounting recordsAs required by applicable tax and company lawSecurely destroyed at the end of the period
Material traceability recordsMinimum 3 years from date of supplySecurely destroyed

Digital records are deleted from live systems and from backups on their normal expiry cycle. Paper records carrying customer or personal information are shredded, not binned.

6. Customer instructions

A customer may at any time ask us to:

  • return or destroy their drawings and specifications;
  • confirm in writing what we hold for them;
  • delete personal data we hold about their staff; or
  • apply a longer retention period, where their own sector requires it.

Send any of these to contact@astratechsolutions.in. Where a statutory obligation prevents us acting on a deletion request, we say which record we are keeping and why, rather than simply declining.

7. Sub-processors

We use a small number of third-party services, chosen so that the list stays short enough to be honest about:

ServicePurposeWhat it handles
Web3FormsRelays website enquiry forms to our inboxEnquiry form contents
Email providerBusiness emailCorrespondence
Website hostServes this siteStandard server request logs

Typefaces are self-hosted rather than loaded from Google Fonts, so rendering a page contacts no third party at all.

Where a provider is outside the EEA or the UK and no adequacy decision covers it, we put the European Commission’s Standard Contractual Clauses in place, with the UK Addendum for UK data.

We will update this list when it changes. If you need a formal sub-processor list, a data processing agreement or a copy of the transfer clauses for your onboarding pack, ask and we will provide them.

8. Incidents

If information is lost, disclosed or accessed without authorisation, we:

  1. contain the incident and establish what was affected;
  2. notify affected customers without undue delay, with what we know and what we are doing;
  3. notify the Data Protection Board of India where the DPDP Act applies, and the relevant supervisory authority within 72 hours where the GDPR or UK GDPR applies; and
  4. record the cause and the corrective action taken.

We do not wait until an investigation is complete before telling an affected customer that something has happened.

9. Review

This policy is reviewed at least annually, and whenever we change a system or a provider that handles customer information.