Astrabotix
Privacy Policy · Terms · Disclaimer Back to sign in

Legal

Privacy Policy

How Broomerr Media Ltd handles personal information across Astrabotix accounts, AI experiences, Launchpads and support.

Effective and last updated: 6 August 2026

On this page

  1. Who we are and scope
  2. Our data-protection roles
  3. Information we collect
  4. How and why we use it
  5. AI and tool processing
  6. Who receives information
  7. International transfers
  8. Retention
  9. Security
  10. Cookies and browser storage
  11. Your rights
  12. Children
  13. Changes and contact

1. Who we are and what this policy covers

Astrabotix is a sub-brand of Broomerr Media Ltd (Broomerr, we, us or our). We are registered in England and Wales under company number 14908738.

This policy covers personal information handled through the Astrabotix marketing website, application, account administration, support, public embeds and Launchpads. It also explains the different roles that apply when an Astrabotix customer builds an experience used by its own clients, prospects or end users.

Astrabotix is intended for people using it for business or professional purposes. It is not directed at children.

2. Our data-protection roles

Where Broomerr is the controller

We act as controller when we decide why and how to use information for account creation, licence administration, service communications, support, security, abuse prevention, legal compliance and running our business. We also act as controller for limited technical records needed to secure public embeds and Launchpads.

Where a customer is the controller

An Astrabotix customer decides what its AI Apps, AI Bots and Launchpads ask for, which knowledge and prompts they use, who can access them, and how resulting data is used. For that customer-controlled information, the customer is normally the controller and Broomerr acts as its processor.

If you use an experience created by one of our customers, you should also read that customer’s privacy notice. Direct questions about its purpose, lawful basis or use of your submission to the customer. We will assist the customer with rights requests where required.

3. Information we collect

The information involved depends on how you use Astrabotix.

Category Examples
Account information Name, business email address, password hash, account status, settings and licence information.
Provider credentials OpenAI or Anthropic API keys you choose to connect and limited verification metadata. Keys are encrypted at rest.
Customer Content Prompts, instructions, input definitions, templates, branding, uploaded documents, extracted text, embeddings, AI Apps, AI Bots, Knowledge Hubs and Launchpad configuration.
Experience and end-user data Form answers, prompts, conversations, generated responses, names and email addresses entered for Launchpad access, member and access-grant records.
Usage and technical data IP address, browser and device information, user agent, login history, timestamps, requested pages, domain or referrer checks, run counts, token counts, event and security logs.
Support and communications Your email address, messages, attachments and information supplied to diagnose or resolve an issue.
Order and transaction data Product, price, payment status, transaction reference and accounting records received from an external checkout provider. Full card details are handled by that provider and are not stored in the Astrabotix application.

We collect information from you, from people who use customer-created experiences, automatically from browsers and servers, and from providers involved in account activation, payment or support.

4. How and why we use personal information

Purpose Typical lawful basis
Create and administer accounts, provide purchased features, save configurations and deliver support. Performance of our contract and steps requested before entering a contract.
Run customer-configured Apps, Bots, Knowledge Hubs, embeds and Launchpads. Performance of our contract; for customer-controlled end-user data, processing on the customer’s documented instructions.
Authenticate users, verify providers, enforce access and usage controls, detect abuse and protect the service. Our legitimate interests in operating a secure, reliable service and, where applicable, performance of our contract.
Send password resets, welcome messages, security notices, service updates and responses to support requests. Performance of our contract and our legitimate interests in communicating about the service.
Keep transaction, tax, complaint and legal records. Compliance with legal obligations and our legitimate interests in establishing or defending legal claims.
Improve reliability, usability and feature performance using service-level and aggregated information. Our legitimate interests in maintaining and improving Astrabotix.
Send optional marketing communications. Consent where required, or legitimate interests where the law permits. You may opt out at any time.

We do not sell personal information. We do not use Customer Content to train a general-purpose AI model of our own.

5. AI providers, knowledge and optional tools

When an account owner runs an AI App or AI Bot, relevant instructions, form inputs, conversation content, selected knowledge context and tool results are sent to the supported AI provider chosen by that account owner. The provider processes that information under the provider account and settings connected by the owner.

Uploaded knowledge files are stored and processed to extract text. Relevant text is sent to OpenAI to generate embeddings where the Knowledge Hub feature requires it, and selected knowledge context may later be sent to the configured conversation provider to answer a request.

If an optional web-search or URL-fetch tool is enabled, the search query or requested URL and information needed to perform the request may be shared with the search provider or the destination website. The destination may receive ordinary request information such as an IP address and user agent.

AI providers and external websites have their own terms and privacy practices. Account owners should not submit personal or confidential information unless its use with the selected provider and tools is lawful and appropriate.

Astrabotix does not make decisions about people that have legal or similarly significant effects for our own purposes. Customers are responsible for deciding how they use output and must put appropriate human review and safeguards around any high-impact use.

6. Who receives personal information

We disclose information only where reasonably necessary for the purposes described above, including to:

  • the United States hosting infrastructure that runs the Astrabotix application, database, file storage and outbound email;
  • OpenAI or Anthropic when the account owner connects that provider and requests processing;
  • search providers and requested websites when optional web tools are enabled;
  • an external checkout or payment provider used for an order;
  • professional advisers, insurers and auditors under appropriate confidentiality duties;
  • courts, regulators, law enforcement or other authorities where required by law or reasonably necessary to protect rights and safety; and
  • a buyer or successor involved in a genuine sale, merger or reorganisation, subject to appropriate safeguards.

Customers and their authorised users can see information associated with the experiences and Launchpads they control. End users should not assume that a submission is private from the owner of that experience.

7. International transfers

The Astrabotix application, database and outbound email service are hosted on a server in the United States. Supported AI providers and other service providers may also process information outside the United Kingdom.

Where UK data-protection law treats this as a restricted transfer, we use an applicable lawful mechanism and require appropriate protection. Depending on the recipient, this may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, and an appropriate transfer-risk assessment.

Customers that enable a provider or external tool are responsible for checking whether their own disclosure to that service is lawful and for giving end users appropriate information about it.

8. How long we keep information

We keep information only for as long as reasonably needed for the relevant purpose. Our normal retention approach is:

  • Account and Customer Content: while the account is active.
  • Deleted Apps, Bots, Launchpads and Knowledge Hubs: removed from the active system when deleted, subject to temporary backups and records we must retain.
  • Closed accounts: operational data deleted or anonymised within 30 days, unless a legal obligation, dispute, security concern or agreed return period requires longer.
  • Backups: normally overwritten within 90 days and not restored except for continuity, security or disaster recovery.
  • Security and access logs: normally retained for up to 90 days, with a longer period where needed to investigate an incident.
  • Support correspondence: normally retained for up to two years after the issue is resolved.
  • Purchase, tax and accounting records: retained for up to six years where required for legal, tax or accounting purposes.

Some records may be retained longer where reasonably necessary to establish, exercise or defend legal claims, comply with law, investigate fraud or enforce our agreements. You can ask for account deletion by emailing support@astrabotix.com.

9. Security

We use technical and organisational measures designed to protect information against unauthorised access, alteration, loss or disclosure. These include access controls, password hashing, encryption of stored AI provider credentials, secure transport in production, domain and usage controls, backups and security logging.

No internet service is completely secure. You are responsible for using a strong unique password, protecting provider keys, limiting who can access your account, configuring public experiences carefully and contacting us promptly about suspected misuse.

10. Cookies and browser storage

Astrabotix currently uses cookies and local browser storage needed to provide requested features and remember user choices. These may include:

  • a session cookie for authentication, security and form handling, normally expiring after 120 minutes of inactivity;
  • a longer-lived login cookie if an account user chooses a remember-me option;
  • local browser storage for the light, dark or system theme preference;
  • random browser identifiers used by embedded Apps and Bots to continue a conversation and enforce owner-configured lifetime run limits; and
  • short-lived session information used to provide gated Launchpad access.

The application does not currently intentionally set non-essential advertising or analytics cookies. Because the current storage is used for requested functionality, security or user-interface preferences, we do not currently display a non-essential cookie-consent banner. We will update this policy and introduce appropriate consent controls before intentionally activating non-essential tracking.

Blocking essential storage may prevent login, saved preferences, conversation continuity, run-limit controls or gated access from working correctly.

11. Your data-protection rights

Depending on the circumstances, UK data-protection law may give you rights to:

  • receive information about how your personal information is used;
  • request access to a copy;
  • correct inaccurate or incomplete information;
  • request deletion or restriction;
  • object to processing based on legitimate interests or to direct marketing;
  • receive certain information in a portable format; and
  • withdraw consent where processing relies on consent.

These rights are not absolute and legal exceptions may apply. We may need to verify your identity. We normally respond within one month.

For information controlled by an Astrabotix customer, contact that customer first. You may also email support@astrabotix.com and we will route or assist with the request as appropriate.

You may complain to the UK Information Commissioner’s Office. We would appreciate the opportunity to address your concern first.

12. Children

Astrabotix accounts are only available to people aged 18 or over using the service for business or professional purposes. Customers must not knowingly design or operate an experience directed at children in a way that would cause us to process children’s personal information without first establishing all required notices, consents, safeguards and an appropriate written arrangement with us.

13. Changes, company details and contact

We may update this policy when the service, providers or law changes. We will post the revised version here and change the effective date. We will provide additional notice where a change materially affects how we use personal information.

Broomerr Media Ltd
Henleaze House Business Centre, 13 Harbury Road, Henleaze, Bristol, United Kingdom, BS9 4PN
Company number: 14908738
Privacy and support email: support@astrabotix.com
Broomerr Media Ltd Astrabotix is a sub-brand.
Company 14908738, registered in England and Wales.
Registered office: Henleaze House Business Centre, 13 Harbury Road, Henleaze, Bristol, United Kingdom, BS9 4PN
Privacy Policy · Terms · Disclaimer