Data Protection & Records Policy
How we classify, hold, retain and dispose of the information customers give us — including drawings and specifications, which are usually the most valuable thing we hold.
1. Scope
This policy applies to all information Astratech Solutions holds in the course of quoting for and manufacturing customer assemblies, whether it is personal data, commercial information or engineering data.
It sits alongside our Privacy Policy. Where the Privacy Policy explains a person’s rights, this document explains our internal handling.
2. How we classify information
Not everything needs the same protection, so we grade what we hold and handle it accordingly.
| Class | Examples | Handling |
|---|---|---|
| Customer confidential | Drawings, wire lists, specifications, part numbers, pricing | Access limited to the people working the job. Never published, never reused for another customer, never shown as portfolio work without written permission. |
| Personal data | Names, business email addresses, telephone numbers | Held only while in use, then deleted. Processed under the DPDP Act. |
| Business records | Quotations, purchase orders, invoices, test records | Retained for the statutory period, then destroyed. |
| Internal | Process notes, fixture designs, methods | Our own information; not disclosed to customers or third parties. |
3. Collection
We collect the minimum needed to do the job. In practice that means a name, a company, an email address, and the technical detail of the assembly.
We do not ask for financial account details, government identifiers, or any category the SPDI Rules class as sensitive personal data, and we ask customers not to send them.
4. Access control
- Access is granted on need, by role, and removed when someone no longer needs it.
- Accounts that hold customer correspondence or drawings require multi-factor authentication.
- Devices used for work are protected by full-disk encryption and a screen lock.
- Customer drawings are not copied to personal accounts, personal devices or consumer file-sharing services.
- Where an outside process is needed for a job, we tell the customer who and obtain agreement before anything is shared.
5. Retention and disposal
Information is kept while it is doing a job and for as long as the law requires, then destroyed. We do not keep records indefinitely "in case".
| Record | Retention | Disposal |
|---|---|---|
| Enquiry that did not become an order | 24 months from last contact | Deleted |
| Quotation issued | 24 months from date of quotation | Deleted |
| Customer drawings and specifications | While the assembly may need rebuilding or supporting | Returned or securely destroyed on request |
| Test and inspection records | Minimum 3 years, or as the customer’s sector requires | Securely destroyed |
| Invoices and statutory accounting records | As required by applicable tax and company law | Securely destroyed at the end of the period |
| Material traceability records | Minimum 3 years from date of supply | Securely destroyed |
Digital records are deleted from live systems and from backups on their normal expiry cycle. Paper records carrying customer or personal information are shredded, not binned.
6. Customer instructions
A customer may at any time ask us to:
- return or destroy their drawings and specifications;
- confirm in writing what we hold for them;
- delete personal data we hold about their staff; or
- apply a longer retention period, where their own sector requires it.
Send any of these to contact@astratechsolutions.in. Where a statutory obligation prevents us acting on a deletion request, we say which record we are keeping and why, rather than simply declining.
7. Sub-processors
We use a small number of third-party services, chosen so that the list stays short enough to be honest about:
| Service | Purpose | What it handles |
|---|---|---|
| Web3Forms | Relays website enquiry forms to our inbox | Enquiry form contents |
| Email provider | Business email | Correspondence |
| Website host | Serves this site | Standard server request logs |
Typefaces are self-hosted rather than loaded from Google Fonts, so rendering a page contacts no third party at all.
Where a provider is outside the EEA or the UK and no adequacy decision covers it, we put the European Commission’s Standard Contractual Clauses in place, with the UK Addendum for UK data.
We will update this list when it changes. If you need a formal sub-processor list, a data processing agreement or a copy of the transfer clauses for your onboarding pack, ask and we will provide them.
8. Incidents
If information is lost, disclosed or accessed without authorisation, we:
- contain the incident and establish what was affected;
- notify affected customers without undue delay, with what we know and what we are doing;
- notify the Data Protection Board of India where the DPDP Act applies, and the relevant supervisory authority within 72 hours where the GDPR or UK GDPR applies; and
- record the cause and the corrective action taken.
We do not wait until an investigation is complete before telling an affected customer that something has happened.
9. Review
This policy is reviewed at least annually, and whenever we change a system or a provider that handles customer information.