ASTRELLLegal
  1. Home
  2. /
  3. Privacy Policy

ASTRELL Privacy Policy

ASTRELL Legal

Last updated: [Insert publication date]

1. Introduction

ASTRELL ("ASTRELL," "we," "us," or "our") is a digital creative agency providing branding, design, web, marketing, and related creative services to clients worldwide. ASTRELL is managed from the United Kingdom, with additional operational support based in Amman, Jordan.

ASTRELL is currently operated as an independent agency and is in the process of formalising its business structure. Where this Privacy Policy refers to "ASTRELL" as a data controller, this refers to the individual(s) currently responsible for operating ASTRELL. Once ASTRELL completes formal company registration, this Privacy Policy will be updated to reflect the registered legal entity, its company number, and its registered office address.

  • Registered company name: [To be added upon incorporation]
  • Company number: [To be added upon incorporation]
  • Registered office address: [To be added upon incorporation]
  • Privacy contact email: [Insert dedicated privacy/legal contact email]

This Privacy Policy explains how we collect, use, disclose, and protect personal data when you visit our website, contact us, request a quote, or engage us for services, regardless of where in the world you are located.

This Policy is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where you are located outside the UK, we also aim to honour recognised data protection principles applicable in your jurisdiction (such as the EU GDPR), to the extent relevant to our processing of your data.

2. Scope of This Policy

This Policy applies to personal data we collect through:

  • Our website and any associated landing pages;
  • Contact forms, quote requests, and newsletter sign-ups;
  • Communications via WhatsApp, Telegram, email, or other messaging channels we make available;
  • The course of delivering a project once you engage ASTRELL as a client;
  • Analytics and cookie technologies described in our [Cookie Policy].

This Policy does not apply to third-party websites or services we may link to, which have their own privacy practices.

3. Information We Collect

3.1 Information You Provide Directly

  • Contact details: name, email address, phone number, company name, and other contact information you give us.
  • Project communications: messages, briefs, feedback, and correspondence sent via our contact form, email, WhatsApp, Telegram, or other channels.
  • Uploaded files: images, logos, documents, design references, written content, brand assets, and other files you submit for a project.
  • Newsletter sign-up data: email address (and, if provided, name) when you subscribe to updates.
  • Payment-related information: billing name, billing address, and transaction details relating to invoices and quotations. We do not collect or store full payment card numbers or other sensitive card details. Where online payments are processed (currently or in future, via providers such as Stripe or PayPal), card details are entered directly with and held by the payment processor under its own security standards (e.g. PCI-DSS).
  • Identity verification documents: where reasonably necessary for fraud prevention, dispute resolution, or to verify the authority of a person acting on behalf of a company, we may request identity or authorisation documents.

3.2 Information Collected Automatically

  • Cookies and similar technologies: as described in our Cookie Policy.
  • Device and browser information: IP address, browser type and version, operating system, device identifiers, and general location inferred from IP address.
  • Analytics data: pages visited, time spent on pages, referral source, and interaction patterns, collected via tools such as Google Analytics.
  • Technical and security logs: server logs, error logs, and access records used to maintain and secure our systems (including logs generated by infrastructure providers such as Cloudflare, Vercel, and Supabase).

3.3 Information We Do Not Seek to Collect

We do not knowingly collect special category data (e.g. health, religious belief, political opinion) unless you voluntarily include it within project materials you submit, in which case we will handle it in accordance with this Policy and applicable law, using it only for the purpose for which it was submitted.

4. How We Use Your Information

We use personal data for the following purposes:

PurposeExamplesLegal Basis (UK GDPR)
Responding to enquiries and quote requestsReplying to contact form or WhatsApp/Telegram messagesLegitimate interests / steps prior to a contract
Delivering contracted servicesProducing designs, managing projects, communicating with you as a clientPerformance of a contract
Processing payments and invoicingIssuing quotes, invoices, processing payment via third-party processorsPerformance of a contract / legal obligation
Sending newsletters or updatesEmailing subscribers who opted inConsent
Improving our website and servicesAnalysing site usage via analytics toolsLegitimate interests
Fraud prevention and identity verificationVerifying identity for high-value or disputed transactionsLegitimate interests / legal obligation
Maintaining security of our systemsReviewing technical logs, preventing abuseLegitimate interests
Complying with legal obligationsResponding to lawful requests from authorities, tax and accounting recordsLegal obligation

Where we rely on legitimate interests, we have considered that this processing is proportionate and does not override your rights and freedoms. You may object to processing based on legitimate interests at any time (see Section 9).

We do not use your personal data for any purpose incompatible with the purposes above without notifying you and, where required, obtaining your consent.

5. Cookies

We use cookies and similar tracking technologies to operate our website, understand usage, and improve our services. Full details, including how to manage or disable cookies, are set out in our separate Cookie Policy.

6. Third-Party Service Providers

We work with trusted third-party providers who process personal data on our behalf or in connection with our services, including:

  • OpenAI and Anthropic — AI-assisted tools that may be used to support research, drafting, or creative workflows during project delivery (see our AI Usage & Disclosure Policy);
  • Google Analytics — website usage analytics;
  • Cloudflare — security, performance, and content delivery infrastructure;
  • Vercel — website hosting and deployment infrastructure;
  • Supabase — backend data storage and infrastructure services;
  • Payment processors (currently or in future, e.g. Stripe, PayPal) — processing of online payments.

These providers act as data processors or independent controllers depending on the service, and are bound by their own privacy and security terms. We select providers that maintain appropriate technical and organisational safeguards. Where a provider processes personal data outside the UK or European Economic Area (EEA), we take steps described in Section 7 to ensure an adequate level of protection.

We do not sell personal data to third parties, and we do not share client project materials with third parties except as necessary to deliver services (e.g. trusted independent contractors engaged by ASTRELL under confidentiality obligations, as described in our Terms of Service), to comply with law, or with your consent.

7. International Data Transfers

ASTRELL operates from the United Kingdom with operational support in Amman, Jordan, and serves clients worldwide. As a result, personal data may be transferred to, stored, or processed in countries outside the United Kingdom, including Jordan and countries where our third-party service providers operate (which may include the United States and other jurisdictions).

Where we transfer personal data outside the UK, we do so on the basis of one or more of the following safeguards, as applicable:

  • The receiving country benefits from a UK adequacy regulation; or
  • Appropriate contractual safeguards, such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses; or
  • Another lawful transfer mechanism recognised under UK data protection law.

You may contact us for further information about the safeguards applied to a specific transfer.

8. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy, including to:

  • Deliver and support ongoing or completed projects;
  • Meet accounting, tax, and legal record-keeping obligations (generally up to 6 years for financial records, in line with UK requirements);
  • Resolve disputes and enforce our agreements;
  • Maintain security logs for a limited, proportionate period.

Newsletter subscriber data is retained until you unsubscribe or request deletion. Project files and client communications are generally retained for a reasonable period after project completion to support any warranty, revision, or dispute-related needs, after which they are deleted or anonymised unless a longer retention period is required by law.

9. Your Rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erasure ("right to be forgotten"), subject to legal or contractual retention requirements;
  • Restrict processing in certain circumstances;
  • Data portability, where processing is based on consent or contract and carried out by automated means;
  • Object to processing based on legitimate interests, including for direct marketing;
  • Withdraw consent at any time, where processing is based on consent (e.g. newsletter subscription), without affecting the lawfulness of processing before withdrawal;
  • Lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, or with your local data protection authority if you are located outside the UK.

To exercise any of these rights, contact us at [Insert privacy contact email]. We may need to verify your identity before actioning a request.

10. Children's Privacy

ASTRELL's services are directed at businesses and individuals capable of entering into commercial agreements. We do not knowingly collect personal data from children under the age of 16. If we become aware that we have inadvertently collected personal data from a child, we will take reasonable steps to delete it. If you believe a child has provided us with personal data, please contact us.

11. Data Security

We implement reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or alteration, including access controls, secure hosting infrastructure, and reliance on reputable third-party providers with their own security safeguards (see Section 6). However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. Automated Decision-Making

We do not currently use personal data for automated decision-making, including profiling, that produces legal or similarly significant effects on individuals without human involvement.

13. Marketing Communications

If you subscribe to our newsletter, we will send you updates related to ASTRELL's services. You may unsubscribe at any time using the link provided in each communication or by contacting us directly. We will not send marketing communications to clients or contacts who have not opted in, except where permitted by law for similar existing-client services.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal requirements, or business structure (including upon formal company registration). Material changes will be indicated by updating the "Last updated" date at the top of this Policy. We encourage you to review this Policy periodically.

15. Contact Us

If you have questions about this Privacy Policy or how we handle your personal data, please contact us:

  • Email: [Insert privacy contact email]
  • Via our website contact form
  • Via WhatsApp or Telegram, where made available on our website

This Privacy Policy was prepared with AI-assisted drafting tools as part of a broader legal package for ASTRELL. It provides a general compliance framework and does not constitute legal advice. Given ASTRELL's worldwide client base and current unregistered status, we recommend this Policy be reviewed by a qualified solicitor before publication and again upon formal company registration.

Legal Documents

Privacy PolicyTerms of ServiceCookie PolicyRefund & Cancellation PolicyAI Usage & Disclosure PolicyAcceptable Use Policy

© 2026 ASTRELL. All rights reserved.

Back to astrells.com