Astra IT

Official Privacy Statement

Privacy Policy

How Astra IT collects, handles, protects and manages personal information across our website, customer portal, booking systems, IT repair services, and the Astra IT Remote Support application.

Australian Privacy Principles (Privacy Act 1988 Cth)Last updated: 24 August 2026Entity: Astra IT

01About Astra IT and This Policy

Astra IT (“we”, “our”, or “us”) is an Australian technology services provider based on the Sunshine Coast, Queensland, providing on-site computer repairs, small business IT support, web design, and Australia-wide remote IT support.

We are committed to handling your personal information transparently, respectfully, and in accordance with the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth).

This Privacy Policy explains what personal and technical information we collect, why we collect it, how it is used and stored, who it may be shared with, and how you can access or correct your information.

02Astra IT Services Covered

This policy applies to all customer interactions, platforms, and services offered by Astra IT, including:

  • Main Website: The public website located at https://astrait.com.au.
  • Customer Portal: The authenticated client area (/portal) used to manage support requests, view job histories, review quotes, approve website milestones, and manage connected devices.
  • Online Booking System: The service wizard (/book) used to schedule on-site visits, drop-offs, device pickups, and remote sessions.
  • Customer Accounts: Secure accounts accessed via email verification tokens and salted authentication PINs.
  • IT Services & Repairs: Computer diagnostics, PC tune-ups, hardware upgrades, virus removal, data migrations, and small business IT management.
  • Remote IT Support Services: Live remote diagnostic and troubleshooting sessions delivered Australia-wide.
  • Astra IT Remote Support Desktop Application: The official Astra IT Windows support client (AstraRemoteSetup--<token>.exe and associated desktop service) used to facilitate customer-authorised remote support.
  • Project Review & Web Workspaces: Dedicated web design client portals (/project/[reference]/[token]) for reviewing website drafts, assets, and invoices.
  • Customer Communications: Enquiries, phone calls, SMS messages, support notes, and contact forms submitted across our site.
  • Invoicing & Payments: Quotes, invoices, accounting records, and payment confirmation receipts.

03Personal & Technical Information We Collect

We only collect information that is reasonably necessary for providing our services, communicating with you, and maintaining system reliability and security. Depending on how you interact with Astra IT, this may include:

A. Contact & Account Information

  • Customer name, business name, and job title (where applicable).
  • Australian Business Number (ABN) where provided for commercial invoicing.
  • Email address and telephone / mobile phone number.
  • Hashed and salted authentication PINs (used securely to verify portal access; plaintext PINs are never stored).

B. Service, Booking & Address Information

  • Service address, suburb, state, and postcode (collected when required for on-site support, hardware pickup, or delivery).
  • Requested service type, preferred appointment dates, and time windows.
  • Customer notes, description of technical problems, error messages, and support requirements.
  • Device details supplied by the customer (brand, model, operating system, specifications).

C. Remote Support & Device Identifiers

  • Computer hostname, device friendly name, operating system version (e.g. Windows 11 Pro build numbers), and Astra Remote client version.
  • Persistent client identifier (astraDeviceUuid) generated locally on first launch to track device presence and link the machine to your customer account.
  • Remote support identifiers, such as a temporary RustDesk peer ID or Support ID.
  • Short-lived, cryptographically secure enrollment tokens (single-use tokens expiring within 10 minutes used exclusively to link the desktop client to your account).
  • Device heartbeat timestamps (indicating whether a connected computer is online or offline).
  • Customer-controlled unattended access status (disabled by default).

D. Billing & Transaction Metadata

  • Invoiced line items, amounts, invoice dates, due dates, and payment status (e.g. “draft”, “sent”, “paid”, “overdue”).
  • Stripe payment session, customer and subscription identifiers, billing status, renewal period and payment confirmation timestamps.
  • Important note: Full credit or debit card numbers, expiration dates, and CVVs are handled directly by our external payment provider (Stripe) and are never collected, transmitted, or stored on Astra IT servers.

E. Technical & Security Information

  • IP address (hashed when processing public booking forms to mitigate spam and automated abuse).
  • Browser user-agent, screen resolution, and operating system type.
  • Aggregate website usage metrics (page views, visit duration, referral paths) collected via Google Analytics.

04How We Collect Personal Information

We collect information through direct interactions and automated technical processes:

  • Direct Submissions: When you complete a booking form, request a quote, submit a contact message, register for a customer portal account, or upload files to a project portal.
  • Direct Communications: When you speak with our technicians by phone, send an email, text message, or communicate in person during a service visit.
  • Desktop Application: When you download and run the Astra IT Remote Support application on your computer, the application communicates with our backend API (/api/remote/v1/*) to enroll your device and send periodic presence heartbeats.
  • Automated Website Technologies: Essential session cookies used to maintain your authenticated login state, and Google Analytics telemetry used to monitor aggregate website traffic.

05Purposes for Collecting, Holding, Using & Disclosing Information

Astra IT collects and uses personal information for legitimate business purposes, including:

  • Service Delivery: Diagnosing computer hardware/software issues, performing tune-ups, setting up devices, executing data transfers, building websites, and delivering on-site or remote IT support.
  • Booking & Job Management: Scheduling service appointments, dispatching technicians, tracking repair progress, and recording service history.
  • Account Administration: Creating and authenticating customer portal accounts, verifying customer identities, and facilitating self-service device management.
  • Customer Communications: Sending booking confirmations, job status updates, quote proposals, invoice receipts, and direct customer support replies.
  • Remote Support Facilitation: Authenticating remote sessions, establishing secure peer-to-peer or relay connections, and verifying customer authorisation.
  • Financial Administration: Generating quotes, issuing tax invoices, processing online card payments via Stripe, and maintaining required business accounts.
  • Security & Abuse Prevention: Protecting our systems against unauthorized access, malicious activity, automated spam, and fraudulent bookings.
  • Legal & Regulatory Compliance: Complying with Australian taxation, business record-keeping, and legal requirements.

Astra IT does not sell, rent, or trade your personal information to third parties for advertising or marketing purposes.

06Remote Support and Astra IT Remote Support

Astra IT provides secure remote computer support for customers across Australia. This section outlines how remote support operates and the privacy safeguards built into the process.

Official Application Notice

Astra IT Remote Support is an official, legitimate desktop application provided and operated exclusively by Astra IT to deliver customer-requested technical support on Windows computers.

A. Authorisation and User Consent

  • Customer Initiated: Remote support is only initiated at your request. You must actively download the software (or request a remote session) and grant Windows administrator permission (User Account Control / UAC) for the setup to install.
  • Authorised Technicians: You should only run the Astra IT Remote Support tool or share access identifiers when speaking with an authorised Astra IT technician.
  • No Covert Access: Astra IT does not install covert background monitoring tools or access computers without explicit customer knowledge and consent.

B. Session Credentials & Automatic Enrollment

  • When downloaded through your authenticated Customer Portal, the installer uses a single-use, 256-bit enrollment token encoded safely in the filename (AstraRemoteSetup--<token>.exe).
  • This token is valid for 10 minutes, can only be used once, and is securely validated against a cryptographic SHA-256 hash in our database before being consumed atomically.
  • The desktop client generates a unique device identifier (astraDeviceUuid) stored locally and receives an authenticated device token protected via Windows Data Protection API (DPAPI).

C. Unattended Access Controls

  • Disabled by Default: Unattended access is strictly turned off by default upon installation.
  • Customer Controlled: Unattended support access can only be enabled if you explicitly toggle the setting ON within your Customer Portal account (under Remote Support → My Devices).
  • Revocable at Any Time: You can toggle unattended access OFF or revoke device enrollment entirely at any time directly through your portal or by uninstalling the application.

D. Screen Visibility and Customer Privacy

  • During an active remote session, the technician can view your computer screen and perform mouse/keyboard actions required to diagnose and fix the requested problem.
  • Recommendation: We strongly advise that you close all private documents, personal email windows, banking websites, and sensitive personal files before initiating a remote support session.
  • You maintain visual oversight of actions taken on your screen during attended sessions and can disconnect the session at any moment.

E. Session Termination & Recording Policy

  • Session Closure: Standard remote support sessions end immediately when closed by either you or the technician. No active screen-viewing connection remains open once the session is terminated.
  • No Session Recording: Astra IT does not record video or audio of remote support sessions.

07Third-Party Service Providers

To provide reliable cloud infrastructure, transactional communications, and secure payment processing, Astra IT engages select third-party service providers. These providers process limited information solely to perform their contracted functions under strict confidentiality and security obligations:

Service ProviderFunction / RoleInformation ProcessedLocation / Privacy Standard
StripePayment gateway & checkout processingBilling details, card tokenization, payment verificationPCI-DSS Level 1 certified payment processor
Neon DatabaseManaged cloud PostgreSQL databaseCustomer records, job notes, quotes, invoices, device metadataEncrypted in transit (TLS) and at rest (AWS Asia-Pacific region)
VercelWeb application hosting & serverless computeHTTP request logs, IP addresses (technical telemetry)Global secure cloud edge network (ISO 27001 / SOC 2)
Resend & PurelymailTransactional email deliveryCustomer email address, customer name, message body, invoice linksEncrypted email delivery infrastructure
Google AnalyticsWebsite usage & performance telemetry (G-7VLL0ET9F3)Anonymised visitor metrics, device/browser type, pages viewedAggregate web analytics; no personal identifying records

08Payment Information and Security

When paying an invoice or starting a monthly Remote Care subscription through Astra IT, card transactions are handled securely by Stripe via encrypted, hosted Checkout sessions. Recurring billing can be managed or cancelled through Stripe's customer billing portal.

Credit Card Privacy Guarantee

Astra IT never collects, views, stores, or processes your full credit card number, expiration date, or CVV security code on our web servers or databases. All payment card details are transmitted directly to Stripe via end-to-end TLS encryption.

Astra IT only receives confirmation of payment success, transaction identifiers, payment amounts, and timestamps required for accounting, tax receipting, and service completion. Direct bank transfer (EFT) details may also be provided on invoices for manual bank deposits.

09Data Storage and Security Safeguards

Astra IT takes reasonable technical, administrative, and physical measures to protect your personal information against loss, misuse, unauthorised access, modification, or disclosure:

  • Encryption in Transit: All website traffic, customer portal sessions, and API communications are strictly encrypted using modern Transport Layer Security (TLS 1.3 / HTTPS).
  • Encryption at Rest: Customer records, jobs, and invoices are stored in encrypted cloud databases.
  • Cryptographic Authentication: Customer portal accounts use unique salt strings and one-way cryptographic hashing (PBKDF2/SHA-256) with server-side peppers to verify access PINs. Plaintext PINs are never stored.
  • Secure Cookie Architecture: Customer sessions use HttpOnly, Secure, SameSite=Lax cookies inaccessible to client-side scripts.
  • Endpoint Protection: The Astra IT Remote Support desktop client uses the Windows Data Protection API (DPAPI) to encrypt device tokens locally on the machine.
  • Database Isolation: Server-side boundaries (server-only code architecture) and parameterized queries prevent injection and restrict data access to authorized backend operations.

While we implement comprehensive security practices, please understand that no method of internet transmission or electronic data storage can be guaranteed 100% immune from security risks.

10Data Retention and Secure Disposal

We retain personal information only for as long as reasonably necessary to fulfill the purposes for which it was collected, including:

  • Providing ongoing technical support, service continuity, and device repair history.
  • Maintaining customer portal accounts and connected device profiles.
  • Satisfying legal, accounting, and tax compliance obligations under Australian law (including statutory financial record retention periods required by the Australian Taxation Office).
  • Resolving disputes, enforcing service agreements, and handling warranty matters.

When personal information is no longer required for legitimate business or legal purposes, it is securely deleted, anonymised, or permanently de-identified.

11Cookies and Analytics

Our website uses a limited set of essential and functional cookies to ensure smooth, secure operation:

  • Essential Authentication Cookies: astra_customer_session and astra_project_session_* cookies are strictly required to keep you securely logged into your Customer Portal or project workspace.
  • Website Analytics Cookies: Google Analytics cookies (_ga, _ga_*) collect aggregate, non-identifying telemetry about how visitors find and use our site, helping us improve speed and user experience.
  • No Advertising Trackers: We do not deploy third-party advertising cookies, cross-site trackers, or behavioral marketing pixels.

You can configure your web browser to reject cookies or alert you when cookies are sent; however, disabling essential session cookies will prevent login to the Customer Portal.

12Your Privacy Rights and Choices

Under the Australian Privacy Principles, you have rights regarding the personal information we hold about you:

  • Access: You may request a copy of the personal information Astra IT holds about you.
  • Correction: You may request corrections to any inaccurate, incomplete, or out-of-date personal information.
  • Account Deletion / Closure: You may request the closure of your Customer Portal account and the deletion of your personal information, subject to our statutory record-keeping and tax retention requirements.
  • Privacy Inquiries & Complaints: If you have questions or concerns about how your personal information is handled, you may contact us directly using the details provided below. We take all privacy concerns seriously and will respond promptly.

13Children's Privacy

Astra IT services, websites, and applications are designed for use by adults, businesses, and individuals capable of entering into service agreements. We do not knowingly collect personal information directly from children under 18 years of age without parental or guardian consent.

14Changes to This Privacy Policy

We may periodically update this Privacy Policy to reflect changes in our services, technological systems, operational practices, or applicable Australian privacy laws.

The latest version of this policy will always be published at https://astrait.com.au/privacy, with the effective date clearly displayed at the top of the page. Continued use of our website or services following any updates constitutes acceptance of the revised policy.

15Contact Us & Privacy Inquiries

If you have questions about this Privacy Policy, wish to access or correct your personal details, or need to raise a privacy concern, please contact Astra IT:

Email Supporthelp@astrait.com.au
Phone Support07 5221 5200
Service LocationSunshine Coast, Queensland