Privacy Policy
How Asytra Limited handles personal data across our website and cloud products.
This Privacy Policy explains how Asytra Limited ("Asytra", "we", "us", or "our") collects, uses, discloses, and protects personal data when you visit https://www.asytra.com, use our cloud software products, or otherwise interact with us.
Our products include Asytra Trace (assembly instructions and traceability), which is generally available with self-serve signup and billing, Asytra Quote (CNC quoting and embeddable widgets), and Asytra Measure (dimensional inspection). Quote and Measure may be in development or available by invitation only. This policy describes our practices across the platform.
1. Who we are
Data controller (for account, website, and platform operations):
Asytra Limited
Unit 2, 23/F, Carnival Commercial Building, 18 Java Road, North Point, Hong Kong
Email: support@asytra.com
Customer content: If your employer or another organization gives you access to Asytra through a company account, that organization is usually the data controller for operational data you enter into the products (for example assembly records, serial numbers, measurements, CAD files, and quotes). Asytra acts as a data processor for that content under the organization's instructions, except where we use such data for security, billing, or service improvement as described below.
2. Scope
This policy applies to:
- the Asytra marketing website at https://www.asytra.com;
- platform authentication at auth.asytra.com;
- billing at billing.asytra.com;
- product applications such as trace.asytra.com, quote.asytra.com, and measure.asytra.com; and
- embedded Quote widgets that our customers place on their own websites.
Third-party websites that embed our widget are controlled by our customers. Their privacy practices are separate from this policy.
3. Personal data we collect
We collect personal data in the following categories, depending on how you use Asytra.
3.1 Account and identity data
- Email address, account name, display name, and password (stored in hashed form).
- Company name and optional VAT or tax identification number provided at registration.
- Email verification and two-factor authentication records.
- Role, permissions, and product access settings assigned by your organization.
3.2 Billing and subscription data
- Subscription plan, trial status, billing interval, and licensing entitlements.
- Billing contact email and invoice-related metadata.
- Payment method and transaction data processed by Stripe. We do not store full payment card numbers on our servers.
3.3 Customer content and operational data
When you use our products on behalf of an organization, we process content you or your colleagues upload or generate, which may include:
- Trace: assembly instructions, images, videos, serial unit records, shop-floor execution data, issues, remarks, quality checks, measurements, operator identifiers, timestamps, and exported reports.
- Quote: CAD files (for example STEP or IGES), drawings, pricing configuration, quote outputs, customer contact details for quote requests, and widget visitor interactions.
- Measure: engineering drawings, inspection templates, dimensional results, and pass or fail records.
This content may relate to your colleagues, end customers, or manufacturing parts. Your organization decides what is uploaded and who may access it.
3.4 Website, support, and communications
- Information you submit through contact forms (name, email, company, message).
- Messages you send to our website chat assistant ("Asa") and related conversation identifiers.
- Support correspondence and administrative audit records where applicable.
3.5 Technical and usage data
- Session identifiers, authentication cookies, and security tokens.
- IP address, browser type, device information, and request logs.
- Product usage events needed to operate, secure, meter, and improve the service (for example storage consumption, AI credit usage, and widget quote counts).
- Approximate country derived from IP address for fraud prevention and captcha routing.
3.6 Widget and public-link visitors
If you use a customer's embedded Quote widget or a password-protected shared assembly link, we may process:
- files you upload for analysis;
- contact details you provide when a widget gate or quote request form requires them;
- feedback you submit about pricing or analysis results;
- technical data such as IP address, browser data, and API request metadata for security and rate limiting.
For widget visitor data, the manufacturing customer that operates the widget is typically the data controller. Asytra processes that data to provide the service to that customer.
4. How we use personal data
We use personal data to:
- create and manage accounts and company tenants;
- authenticate users and maintain sessions across Asytra subdomains;
- provide, host, maintain, and secure the products;
- process subscriptions, trials, invoices, and payments;
- send transactional emails (verification codes, security alerts, billing notices, quote delivery, and trial or payment reminders);
- scan uploaded files for malware where enabled;
- run optional AI-assisted features (for example content enhancement or chat responses) and meter AI credit usage;
- respond to support requests and improve reliability;
- comply with law and enforce our Terms of Service.
We do not sell your personal data. We do not use customer content to train public third-party AI models unless we clearly disclose that in the product and you opt in.
5. Legal bases (EEA, UK, Hong Kong, and similar jurisdictions)
Where applicable data protection law requires a legal basis, we rely on:
| Purpose | Typical legal basis |
|---|---|
| Providing the service under a subscription or trial | Performance of a contract |
| Security, fraud prevention, and abuse detection | Legitimate interests / legal obligation |
| Billing and tax compliance | Performance of a contract / legal obligation |
| Product analytics and service improvement | Legitimate interests |
| Marketing communications where permitted | Consent or legitimate interests |
| Processing on behalf of a business customer | Contract with the customer (processor role) |
In Hong Kong, we handle personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) where it applies to our activities.
6. Cookies and similar technologies
We use cookies and similar technologies for authentication, security, and basic functionality.
6.1 Platform authentication cookies
When you sign in on auth.asytra.com, we set httpOnly cookies shared across *.asytra.com product subdomains. These may include:
asytraSessionId(unified platform session);accountSessionId,companySessionId, andsessionId(legacy session layers during migration); and- optional "Remember me" persistence for up to 30 days, or shorter idle expiry when not selected.
Logging out clears platform session cookies. You can also clear cookies in your browser, which will sign you out.
6.2 Marketing website (www.asytra.com)
On our public marketing site we use a cookie preference banner. You can accept all cookies, reject non-essential cookies, or choose categories individually. Your choices are stored in localStorage under asytra_cookie_consent_v1 so we can remember them on future visits.
| Category | What we use it for | Examples |
|---|---|---|
| Strictly necessary | Core site operation and remembering your cookie choices | Cookie preference storage |
| Analytics (optional) | Understanding how visitors use pages so we can improve content and navigation | Microsoft Clarity (_clck, _clsk, and related session identifiers) |
| Functional (optional) | Interactive site features you choose to use | Website chat conversation ID in sessionStorage (asytra_chat_conversation_id); live Quote widget demo loaded from quote.asytra.com |
On the contact page, captcha providers may set their own cookies or tokens (hCaptcha, Google reCAPTCHA, or Tencent Cloud Captcha depending on region) when you submit the form. These help prevent spam and abuse.
6.3 Product apps and other cookies
- Guest access cookies for password-protected shared assembly links.
- Stripe may use cookies or similar technologies during checkout on the billing app.
7. How we share personal data
We share personal data only as needed to operate the service:
| Recipient | Why |
|---|---|
| Infrastructure and hosting providers (for example DigitalOcean) | Application hosting, databases, and object storage |
| Stripe | Payment processing, subscriptions, and invoicing |
| Resend | Transactional email delivery |
| OpenRouter and connected model providers | AI-assisted features when enabled |
| Captcha and fraud-prevention providers | Login and registration protection |
| Frankfurter or other exchange-rate APIs | Currency display conversions |
| Your organization and its authorized users | Normal product operation within a tenant |
| Professional advisers and authorities | Where required by law or to protect rights and safety |
We require service providers to handle personal data under contractual obligations appropriate to their role. Payment card data is handled directly by Stripe under its own privacy policy.
8. International transfers
Asytra is based in Hong Kong. Our service providers may process data in Hong Kong, Singapore, the United States, the European Union, or other countries where they or their subprocessors operate. Where required by law, we implement appropriate safeguards for cross-border transfers.
9. Retention
We keep personal data only as long as necessary for the purposes described in this policy, including:
- Account data: for the life of the account and a reasonable period afterward for backups, billing records, and legal compliance.
- Customer content: until deleted by authorized users or the customer organization, or until the company tenant is deleted.
- Billing records: as required for tax, accounting, and dispute resolution.
- Security and audit logs: for a limited period appropriate to investigation and compliance needs.
- Website chat conversations: according to our chat retention settings.
When a company tenant is deleted, we remove associated databases and durable file storage, subject to backup rotation and legal hold requirements.
10. Security
We use administrative, technical, and organizational measures designed to protect personal data, including encryption in transit (HTTPS), access controls, tenant isolation, httpOnly session cookies, upload malware scanning where enabled, and restricted production access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing of your personal data, and to data portability or withdrawal of consent where processing is consent-based.
If you use Asytra through a company account, contact your organization administrator first for operational data held in that tenant. We may direct you to the controller where appropriate.
For account, billing, or platform requests, email support@asytra.com. We may need to verify your identity before responding.
You may also have the right to lodge a complaint with a supervisory authority in your country of residence or workplace. In Hong Kong, you may contact the Office of the Privacy Commissioner for Personal Data (PCPD).
12. Children's privacy
Asytra is a business-to-business service and is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal data from children. Contact us if you believe a child has provided personal data and we will take appropriate steps to delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. For material changes, we may provide additional notice (for example by email or in-product notice) where appropriate.
14. Contact us
Questions about this Privacy Policy or our data practices:
Asytra Limited
Unit 2, 23/F, Carnival Commercial Building, 18 Java Road, North Point, Hong Kong
Email: support@asytra.com
Web: Contact form
