Astrea IT Services Pvt. Ltd. — Privacy Policy

Last updated: Sep 2, 2026

Astrea IT Services Pvt. Ltd. ("Astrea IT," "we," "us," or "our") provides Salesforce consulting, implementation, and managed services, and develops and publishes applications ("Apps") on the Salesforce AppExchange. This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with:

  • Our corporate website (the "Site");
  • Our Salesforce consulting and delivery services; and
  • Our AppExchange Apps.

If a specific App, service, or engagement has its own privacy terms (e.g., a signed Master Services Agreement or Data Processing Agreement with a client), those terms govern for that App or engagement to the extent they conflict with this Policy.

1. Our AppExchange Apps Don't Access Your Salesforce Org Data

This is important, so we state it plainly: our AppExchange Apps are designed and built so that Astrea IT does not collect, store, transmit, or otherwise have access to any data residing in a customer's Salesforce org ("Client Org Data"), including records, fields, files, or metadata created or managed by the customer within their own Salesforce environment.

Our Apps operate entirely within the customer's own Salesforce org and infrastructure. We do not operate external servers that receive, process, or store Client Org Data as part of normal App functionality, and we do not use Client Org Data for analytics, product improvement, advertising, or any other secondary purpose, because we do not have access to it in the first place.

The only information we may collect in connection with an App relates to the App listing and purchase process itself (see Section 3 below) — not the data inside your org.

If a specific App's functionality ever changes such that it requires access to org data (for example, an integration feature you explicitly opt into), we will disclose this clearly in that App's AppExchange listing and require your affirmative consent before any such access begins.

2. Scope of This Policy

This Policy applies to:

  • Visitors to our website (astreait.com and related domains);
  • Prospective and current clients of our Salesforce consulting services;
  • Users and administrators who install or evaluate our AppExchange Apps; and
  • Job applicants and business contacts who interact with us (e.g., through BD outreach, events, or partner introductions).

This Policy does not apply to information we de-identify or aggregate such that it can no longer reasonably identify an individual, or to Client Org Data, which we do not access (see Section 1).

3. Information We Collect

3.1 Website Visitors

When you visit our Site, we may automatically collect technical and usage information, including your IP address, browser type, device type, referring pages, and pages visited, typically through cookies and similar technologies. You can control cookies through your browser settings; disabling them may limit some Site functionality.

If you submit a contact form, request a demo, or subscribe to updates, we collect the information you provide, such as your name, business email, company, job title, and phone number.

3.2 AppExchange Listing and Purchase Information

When you view, install, trial, or purchase one of our Apps via the Salesforce AppExchange, Salesforce may share limited account and contact information with us (such as your name, business email, company name, and org edition), consistent with the AppExchange Partner Program requirements and Salesforce's own privacy terms. We use this information solely to support the sales, licensing, billing, and support relationship for that App — never to access your org data (see Section 1).

3.3 Consulting Clients and Business Contacts

In the course of providing Salesforce consulting, implementation, and managed services, we may collect business contact information (name, email, phone, job title, company) from client stakeholders, prospective clients, and partners for purposes of engagement delivery, proposals, invoicing, and relationship management.

Where a consulting engagement requires our team to access a client's Salesforce org or other systems as part of delivery work (e.g., implementation, configuration, or support), that access is governed by the applicable Master Services Agreement, Statement of Work, and Non-Disclosure Agreement executed with that client — not by this general website Policy. For clients whose vendor requirements call for a separate Data Processing Agreement, we are happy to work with your legal or procurement team to put one in place.

3.4 Job Applicants

If you apply for a role with Astrea IT, we collect the information you submit (resume, contact details, work history) to evaluate your candidacy.

4. How We Use Information

We use the information described above to:

  • Operate, maintain, and improve our Site and Apps;
  • Process App purchases, licensing, and billing;
  • Provide customer and technical support for our Apps and services;
  • Respond to inquiries and provide requested information (e.g., demos, proposals);
  • Communicate with clients and prospects about our services;
  • Manage and deliver consulting engagements, in accordance with the relevant client agreement;
  • Evaluate job applications;
  • Comply with legal, tax, and regulatory obligations; and
  • Protect the security and integrity of our Site, Apps, and business.

We do not sell personal information, and we do not use Client Org Data for any purpose, because we do not have access to it.

5. How We Share Information

We may share the categories of information described in Section 3 (not Client Org Data) with:

  • Service providers who support our business operations (e.g., hosting, email, CRM, analytics, payment processing), under confidentiality and data protection obligations;
  • Salesforce, as required to operate our AppExchange listings and Partner Program obligations;
  • Affiliates, for internal business purposes;
  • Professional advisors (legal, accounting) as needed;
  • Regulators or courts, where required by law, subpoena, or legal process; and
  • A successor entity, in the event of a merger, acquisition, or sale of business assets.

We do not share information for third-party advertising purposes.

6. International Data Transfers

Astrea IT is headquartered in India, and personal information described in this Policy (website and App-listing data — not Client Org Data) is generally processed and stored in India. If you are located outside India, including in the United States or the European Economic Area, your information may be transferred to and processed in India.

We take steps to ensure that any such transfer is subject to appropriate safeguards consistent with applicable law. For enterprise clients whose vendor security or legal review requires a Data Processing Agreement, including Standard Contractual Clauses, we are glad to work with you to put the appropriate agreement in place alongside our standard Master Services Agreement and Non-Disclosure Agreement.

7. Your Privacy Rights

Depending on your location, you may have rights to access, correct, delete, or restrict the use of your personal information, or to opt out of certain processing.

California residents: Under the California Consumer Privacy Act (CCPA), as amended by the CPRA, you have the right to know what personal information we hold about you, request deletion, correct inaccurate information, and opt out of the "sale" or "sharing" of personal information (we do not sell or share personal information for cross-context behavioral advertising). To exercise these rights, contact us using the details in Section 11.

Other jurisdictions: If you are located in a jurisdiction with its own data protection law (e.g., the EU/UK GDPR), you may have similar rights, including the right to lodge a complaint with your local data protection authority.

We will respond to verified requests within the time required by applicable law.

8. Data Security

We maintain reasonable administrative, technical, and physical safeguards designed to protect personal information we hold from unauthorized access, loss, misuse, or alteration. Because our Apps do not access Client Org Data, that data remains subject to the security controls of the customer's own Salesforce org and Salesforce's platform-level security — not our infrastructure.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes described in this Policy, including to meet legal, accounting, or reporting obligations. When no longer needed, information is securely deleted or de-identified.

10. Children's Privacy

Our Site, Apps, and services are intended for business use and are not directed at individuals under 16. We do not knowingly collect personal information from children.

11. Contact Us

If you have questions about this Policy, our privacy practices, or wish to exercise a privacy right, please contact:
Astrea IT Services Pvt. Ltd.
Email: support@astreait.com
C52, Sector 65, Noida, UP, India 201301

12. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices or legal requirements. We will post the updated version on this page with a revised "Last updated" date, and where changes are material, we will provide additional notice as appropriate.