
Privacy Policy
Last Updated: July 2026
Astrid IT Lab ("we", "our", or "us") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, and safeguard personal data when you visit our website or engage with our IT and Cyber Security consultancy services.
In accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Astrid IT Lab acts as the Data Controller for the personal information processed through this website.
1. Information We Collect
As a specialized IT and Cyber Security service provider, we operate on a principle of strict data minimization. We only collect information that is strictly necessary to fulfill your requests or maintain site security:
-
Identity & Contact Data: Name, corporate email address, and company name when voluntarily provided via our contact or consultation forms.
-
Technical Data: Internet Protocol (IP) addresses, browser type, traffic logs, and server-side telemetry metrics collected automatically for security monitoring and threat mitigation.
2. How We Use Your Data
We process your information under the following legal bases:
-
Performance of a Contract: To respond to your inquiries, provide project estimates, and deliver agreed-upon IT and security services.
-
Legitimate Interests: To maintain network security, monitor for malicious traffic (such as bot-scraping or brute-force vectors), and optimize server-side routing performance.
3. Data Protection & Security Architecture
As a cybersecurity practice, data security is our core operational baseline.
-
All data transmission via this website is strictly encrypted in transit using industry-standard protocols.
-
We deploy zero-trust internal access controls and rigid anti-scraping firewalls to ensure that any client communications or server logs are fully isolated and protected against unauthorized access.
-
We do not sell, rent, or lease your personal data to third parties.
4. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including the satisfaction of any legal, accounting, or institutional reporting requirements. Technical security logs are automatically purged or anonymized on a structured retention cycle.
5. Your Legal Rights
Under the UK GDPR, you possess specific rights regarding your personal data:
-
The right to access the personal data we hold about you.
-
The right to request rectification of inaccurate data.
-
The right to request erasure ("the right to be forgotten") under specific legal conditions.
-
The right to restrict or object to certain processing activities.
To exercise any of these rights, please contact us directly through the official secure channels provided on this platform.
6. Updates to this Policy
We reserve the right to update this Privacy Policy periodically to reflect operational, technological, or regulatory updates. Any changes will become effective immediately upon being published on this page.
