Legal
Privacy Policy
This policy describes how AstraSight ("we", "us"), operated by Adithya Ravindra, Bengaluru, Karnataka, India, collects, uses and protects information in connection with our Strategy Intelligence platform at www.astrasight.in.
It is written to align with the Digital Personal Data Protection Act 2023, the Information Technology Act 2000 and the rules made under them.
Who we are
AstraSight is a Strategy Intelligence platform operated by Adithya Ravindra, Bengaluru, Karnataka, India. We publish measured analysis of how events translate into profit and loss for Indian companies, and we keep a scored record of the calls we make.
This policy explains what we collect when you use www.astrasight.in or the AstraSight product, what we do with it, and what you can ask us to do about it.
Information we collect
- Contact details you send us when you email us or request a sealed readout: your name, work email, phone number, company and role.
- Account and session data for customers with product access: login timestamps, features used, sessions created, and audit records of actions taken inside the platform.
- Company inputs you choose to share for analysis: cost structure, segment disclosures, scenarios, and any documents you upload for a readout.
- Basic server logs (IP address, user agent, timestamp) generated when the site or product is served.
The website carries no advertising trackers, no third-party analytics pixels, and no cross-site tracking cookies.
Sources we analyse
The analytical base is built from public disclosure: exchange filings and annual reports, regulatory circulars and orders, public statistical releases, and published news of record. Where a figure appears in an AstraSight output, it carries a citation back to the source it came from, or it is refused.
We do not buy personal data, we do not scrape private accounts, and we do not process private communications.
How we use information
- Responding to enquiries and preparing sealed readouts.
- Providing, operating, securing and improving the AstraSight product.
- Running the analysis you ask for, including P&L bridges, scenario probabilities and move rankings against your inputs.
- Keeping the tamper-proof record of sealed sessions, and scoring outcomes against what was recorded.
- Meeting our legal, tax and audit obligations.
We do not sell, rent or trade personal information, and we do not use client inputs to train third-party models.
Confidentiality of client work
Method public, record private. We publish how the engine works; we do not publish who used it or what they asked. Client scenarios, cost structures and readouts are treated as confidential and are not shown to other clients or used in marketing without written permission.
Where we cite our own track record publicly, we cite aggregate figures: counts of episodes, tests, and scored scenarios. We never cite client identities.
Legal basis for processing
- Consent: for enquiries, marketing correspondence and any optional data you choose to send us.
- Contractual necessity: for delivering the product and services to a customer organisation.
- Legitimate uses under Section 4 of the Digital Personal Data Protection Act 2023, including processing publicly available information.
- Legal obligation: where Indian law, a court order or a competent authority requires disclosure or retention.
Retention
- Enquiry correspondence is retained for 24 months from last contact unless you ask us to delete it sooner.
- Customer account data is retained for the life of the account and for 90 days after termination.
- Sealed session records and their ledger entries are retained for the life of the customer relationship, because scoring our own past answers depends on them; they can be closed to further use on request, and the underlying client inputs deleted, while the tamper-proof record remains.
- Server logs are retained for 12 months.
To request deletion, email adithya.r@astrasight.in with the subject line "Data deletion request". We action verified requests within 30 days.
Sharing and processors
- Infrastructure and hosting providers used to serve the site and run the product.
- Model providers used for language processing inside the product. Models propose structure and language; measured numbers are produced by code over measured data. Client inputs are not used by us to train models.
- Professional advisers bound by confidentiality, where needed for legal, accounting or audit purposes.
- Authorities, where disclosure is required by Indian law.
Security
- Encrypted transport (HTTPS/TLS) for the site and product.
- Role-based access control, with access to client inputs limited to personnel who need it.
- Audit logging of actions taken inside the platform.
- Session records are chained together and time-stamped outside our own systems, so the order and content of sealed records can be checked independently.
Your rights under the DPDP Act 2023
- Access: request a summary of the personal data we hold about you and why we hold it.
- Correction: request that inaccurate or incomplete data be corrected.
- Erasure: request deletion, subject to records we are legally required to keep.
- Grievance redressal: raise a complaint with our grievance officer, named below.
- Nomination: nominate another individual to exercise your rights in the event of incapacity or death.
To exercise any of these, email adithya.r@astrasight.in with the subject line "DPDP data rights request".
Cookies
The public website sets no advertising or analytics cookies. The product uses strictly necessary cookies for authentication and session security. You can refuse cookies in your browser, but the product will not be able to keep you signed in.
Changes to this policy
We may update this policy as the product and the law change. Material changes are notified to customers by email, and the effective date at the top of this page is updated.