Legal
Privacy policy
How Asterion Software s.r.o. collects, uses, stores and deletes personal data. Written to be read, not to be survived.
Last updated: 11 August 2026
The short version
We collect only what you type into a form on this site. We use it to answer you and for nothing else. We do not sell it, do not share it with advertisers, and set no advertising or analytics cookies. You can ask us to delete it at any time and we will.
1. Who is responsible for your data
The data controller is Asterion Software s.r.o., a company registered in the Czech Commercial Register (Obchodní rejstřík) under IČO 10736697, VAT number CZ10736697, with its registered office at Bělehradská 858/23, Vinohrady, 120 00 Praha 2, Czech Republic.
For any question about this policy or about your personal data, write to privacy@asterionsoftwaresro.com or to the postal address above. We are not required to appoint a Data Protection Officer under Article 37 GDPR and have not appointed one; requests are handled by the company management.
2. The law we work under
Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”), Czech Act No. 110/2019 Sb. on personal data processing, and — for electronic communications and cookies — Czech Act No. 127/2005 Sb. on electronic communications and Act No. 480/2004 Sb. on certain information society services.
3. What we collect, why, and for how long
Every field below is a field you filled in yourself. We do not buy data, do not enrich it from third-party sources, and do not build profiles.
| What | Why (purpose) | Legal basis | Kept for |
|---|---|---|---|
| Estimate request: company name, contact person, business email, phone (optional), service category, project description and the estimator selections | To assess your request, prepare a written reply and, if it proceeds, a quotation | Art. 6(1)(b) — steps at your request prior to a contract; Art. 6(1)(f) — our legitimate interest in responding to business enquiries | 24 months from last contact, then deleted |
| Contact message: name, email, company (optional), subject, message | To answer your message | Art. 6(1)(f) — legitimate interest in answering enquiries addressed to us | 12 months from last contact, then deleted |
| Anti-abuse data: a salted hash of your IP address and the browser user-agent string submitted with a form | To rate-limit submissions and investigate spam or abuse | Art. 6(1)(f) — legitimate interest in keeping the service available | Rate-limit counters: 24 hours. Stored hash: with the message it belongs to |
| Web server logs: IP address, timestamp, requested URL, status code, user-agent | Security, fault diagnosis and abuse investigation | Art. 6(1)(f) — legitimate interest in operating a secure service | 30 days, then rotated out |
| Email correspondence you send us | To conduct the conversation and keep a record of what was agreed | Art. 6(1)(b) / 6(1)(f) | 24 months, or the term of a contract plus the statutory retention period |
We store the IP address that submits a form as a salted SHA-256 hash, not in the clear. That is enough to count submissions from one source and investigate abuse, and not enough to reconstruct who sent them.
4. What we do not do
- No advertising, analytics, profiling or cross-site tracking cookies. None at all — see the cookie policy.
- No sale, rent or exchange of personal data, in any circumstances.
- No marketing emails unless you ask us for them. Answering your enquiry is not consent to a newsletter.
- No automated decision-making or profiling with legal or similarly significant effects (Art. 22 GDPR). The project estimator on this site runs entirely in your browser and produces an indicative scope profile; a person reads every request.
- No third-party fonts, tag managers, embedded videos, social widgets or CDN requests. Every asset this site loads comes from our own domain.
5. Who else can see your data
We use as few processors as we can. As of the date above, they are:
| Recipient | Role | Location |
|---|---|---|
| Our hosting provider | Operates the servers running this website, its database and its mail relay | European Union |
| Our email provider | Delivers and stores business correspondence | European Union |
| Accountancy and legal advisers | Only where a request becomes an invoiced engagement or a legal matter | Czech Republic |
| Public authorities | Only where we are legally obliged to disclose | Czech Republic / EU |
Each processor is bound by a written agreement under Article 28 GDPR. We do not transfer personal data outside the European Economic Area. If that ever changes, this policy will name the country and the Article 46 safeguard before the transfer begins.
6. Client data during an engagement
When we build or operate software for a client, we normally act as a processor rather than a controller for the personal data inside that system. In that role we process data only on the client’s documented instructions, under a data processing agreement signed before any access is granted. We prefer anonymised or synthetic data in development environments, keep production access to the minimum number of named people, and return or delete client data at the end of the engagement as the agreement requires.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased where the conditions apply (Art. 17);
- restrict processing while a dispute is resolved (Art. 18);
- receive your data in a portable, machine-readable format (Art. 20);
- object to processing based on our legitimate interests (Art. 21) — including the marketing-free correspondence described above;
- withdraw a consent you gave, at any time, without affecting processing already carried out.
Write to privacy@asterionsoftwaresro.com. We answer within 30 days and do not charge for it. We may ask one question to confirm you are the person the data concerns — we will not demand a copy of an identity document for a routine request.
8. Complaints
If you are not satisfied with how we handled your request, you may lodge a complaint with the Czech supervisory authority:
Úřad pro ochranu osobních údajů (Office for Personal Data Protection)
Pplk. Sochora 27, 170 00 Praha 7, Czech Republic
https://uoou.gov.cz/
If you are resident in another EU member state, you may instead complain to your own national data protection authority.
9. How we protect the data
- HTTPS with a modern TLS configuration on every page and every API endpoint.
- Form submissions validated server-side, stored through parameterised queries, and rate-limited.
- Database credentials held outside the web root and never committed to version control.
- Access to the production database limited to named administrators.
- Application logs that deliberately never record message bodies or form contents.
- Dependencies patched on a schedule, with security advisories monitored.
These controls are modelled on ISO/IEC 27001 Annex A and the OWASP ASVS. Asterion Software s.r.o. is not certified against either standard and does not claim to be.
10. Children
This is a business-to-business website. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has sent us data, write to us and we will delete it.
11. Changes to this policy
If we change this policy we update the date at the top of the page. If a change materially affects how we handle data you have already given us, we will contact you directly rather than rely on you re-reading this page.