Legal
Privacy policy
How Asterion Software s.r.o. collects, uses, stores and deletes personal data. Written to be read, not to be survived.
Last updated: 11 August 2026
The short version
We collect only what you type into a form on this site. We use it to answer you and for nothing else. We do not sell it, do not share it with advertisers, and set no advertising or analytics cookies. You can ask us to delete it at any time and we will.
One thing worth knowing up front: this website runs on a server in the United States, so what you submit is stored there under Standard Contractual Clauses. Section 5 explains it in full.
1. Who is responsible for your data
The data controller is Asterion Software s.r.o., a company registered in the Czech Commercial Register (Obchodní rejstřík) under IČO 10736697, VAT number CZ10736697, with its registered office at Bělehradská 858/23, Vinohrady, 120 00 Praha 2, Czech Republic.
For any question about this policy or about your personal data, write to privacy@asterionsoftwaresro.com or to the postal address above. We are not required to appoint a Data Protection Officer under Article 37 GDPR and have not appointed one; requests are handled by the company management.
2. The law we work under
Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”), Czech Act No. 110/2019 Sb. on personal data processing, and — for electronic communications and cookies — Czech Act No. 127/2005 Sb. on electronic communications and Act No. 480/2004 Sb. on certain information society services.
3. What we collect, why, and for how long
Every field below is a field you filled in yourself. We do not buy data, do not enrich it from third-party sources, and do not build profiles.
| What | Why (purpose) | Legal basis | Kept for |
|---|---|---|---|
| Estimate request: company name, contact person, business email, phone (optional), service category, project description and the estimator selections | To assess your request, prepare a written reply and, if it proceeds, a quotation | Art. 6(1)(b) — steps at your request prior to a contract; Art. 6(1)(f) — our legitimate interest in responding to business enquiries | 24 months from last contact, then deleted |
| Contact message: name, email, company (optional), subject, message | To answer your message | Art. 6(1)(f) — legitimate interest in answering enquiries addressed to us | 12 months from last contact, then deleted |
| Anti-abuse data: a salted hash of your IP address and the browser user-agent string submitted with a form | To rate-limit submissions and investigate spam or abuse | Art. 6(1)(f) — legitimate interest in keeping the service available | Rate-limit counters: 24 hours. Stored hash: with the message it belongs to |
| Web server logs: IP address, timestamp, requested URL, status code, user-agent | Security, fault diagnosis and abuse investigation | Art. 6(1)(f) — legitimate interest in operating a secure service | 30 days, then rotated out |
| Email correspondence you send us | To conduct the conversation and keep a record of what was agreed | Art. 6(1)(b) / 6(1)(f) | 24 months, or the term of a contract plus the statutory retention period |
We store the IP address that submits a form as a salted SHA-256 hash, not in the clear. That is enough to count submissions from one source and investigate abuse, and not enough to reconstruct who sent them.
Why there is no “I agree” tick-box on our forms
Because consent is not the legal basis we rely on, and a tick-box would misrepresent that. We answer an enquiry either because you asked us to take steps towards a contract (Article 6(1)(b)) or because a business that publishes a contact form has a legitimate interest in replying to it (Article 6(1)(f)). Neither needs your consent, and a checkbox you cannot submit the form without is not freely given — so it would not be valid consent even if we called it that.
What you get instead is this notice, plus a short summary next to the send button, before you submit anything. Because the basis is legitimate interest rather than consent, your lever is the right to object under Article 21 (see section 7) rather than withdrawal of consent — in practice, tell us and we delete it. If we ever ask for genuine consent for something separate, such as a mailing list, it will be a separate, optional, unticked box that you can withdraw at any time without affecting your enquiry.
4. What we do not do
- No advertising, analytics, profiling or cross-site tracking cookies. None at all — see the cookie policy.
- No sale, rent or exchange of personal data, in any circumstances.
- No marketing emails unless you ask us for them. Answering your enquiry is not consent to a newsletter.
- No automated decision-making or profiling with legal or similarly significant effects (Art. 22 GDPR). The project estimator on this site runs entirely in your browser and produces an indicative scope profile; a person reads every request.
- No third-party fonts, tag managers, embedded videos, social widgets or CDN requests. Every asset this site loads comes from our own domain.
5. Who else can see your data
We use as few processors as we can. As of the date above, they are:
| Recipient | Role | Where it processes the data |
|---|---|---|
| Namecheap, Inc. | Provides the virtual server that runs this website, its database and its logs. Everything you submit through a form is stored here. | Atlanta, Georgia, United States |
| Email provider | None engaged. Outbound notification mail from this website is switched off, so no third-party mail service currently receives anything you submit. If that changes, this table is updated before it does. | — |
| Accountancy and legal advisers | Only where a request becomes an invoiced engagement or a legal matter | Czech Republic |
| Public authorities | Only where we are legally obliged to disclose | Czech Republic / EU |
Transfers outside the European Economic Area
Yes — data you submit through this website is stored on a server in the United States, not in the EU. We would rather tell you that plainly than bury it. The virtual server is provided by Namecheap, Inc. and is located in Atlanta, Georgia, United States, so your form submission, and the database row it creates, rest there.
The transfer relies on Standard Contractual Clauses (Article 46(2)(c) GDPR), as stated in the provider’s published privacy policy. The provider states in its published privacy policy that customer data is held on United States servers and that transfers are subject to those clauses, and it has appointed the European Data Protection Office (EDPO) as its GDPR Article 27 representative in the European Union.
What this means in practice: the United States does not have an EU adequacy decision that applies automatically to every company, so the contractual clauses above are what protect the data instead. US authorities can in principle compel a US provider to disclose data held on its systems. The information this site collects is business-contact information and whatever you choose to write in a message — we deliberately collect nothing more — but you should know where it goes before you type it. If you would prefer not to send business information to a US-hosted system, email or telephone us instead, using the details on the contact page.
Accountancy, legal advisers and public authorities are in the Czech Republic and the EU. Each processor is bound by a written agreement under Article 28 GDPR or by its published terms.
6. Client data during an engagement
When we build or operate software for a client, we normally act as a processor rather than a controller for the personal data inside that system. In that role we process data only on the client’s documented instructions, under a data processing agreement signed before any access is granted. We prefer anonymised or synthetic data in development environments, keep production access to the minimum number of named people, and return or delete client data at the end of the engagement as the agreement requires.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased where the conditions apply (Art. 17);
- restrict processing while a dispute is resolved (Art. 18);
- receive your data in a portable, machine-readable format (Art. 20);
- object to processing based on our legitimate interests (Art. 21) — including the marketing-free correspondence described above;
- withdraw a consent you gave, at any time, without affecting processing already carried out — this one does not currently apply to anything, because we do not rely on consent for enquiries. It is listed so the picture is complete, and so it means something the day we ever do ask. For the processing described above, the right you want is the objection right immediately before this.
Write to privacy@asterionsoftwaresro.com. We answer within 30 days and do not charge for it. We may ask one question to confirm you are the person the data concerns — we will not demand a copy of an identity document for a routine request.
8. Complaints
If you are not satisfied with how we handled your request, you may lodge a complaint with the Czech supervisory authority:
Úřad pro ochranu osobních údajů (Office for Personal Data Protection)
Pplk. Sochora 27, 170 00 Praha 7, Czech Republic
https://uoou.gov.cz/
If you are resident in another EU member state, you may instead complain to your own national data protection authority.
9. How we protect the data
- HTTPS with a modern TLS configuration on every page and every API endpoint.
- Form submissions validated server-side, stored through parameterised queries, and rate-limited.
- Database credentials held outside the web root and never committed to version control.
- Access to the production database limited to named administrators.
- Application logs that deliberately never record message bodies or form contents.
- Dependencies patched on a schedule, with security advisories monitored.
These controls are modelled on ISO/IEC 27001 Annex A and the OWASP ASVS. Asterion Software s.r.o. is not certified against either standard and does not claim to be.
10. Children
This is a business-to-business website. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has sent us data, write to us and we will delete it.
11. Changes to this policy
If we change this policy we update the date at the top of the page. If a change materially affects how we handle data you have already given us, we will contact you directly rather than rely on you re-reading this page.