01 / Operator and contact
Architecture Confrontation is an Astrynn Holdings application. Contracting legal entity: [LEGAL ENTITY NAME]. Registered address: [REGISTERED ADDRESS]. These particulars have not been verified for this application.
Product, privacy and rights requests can be directed to the confirmed Astrynn corporate contact: javier@astrynn-holdings.com. No separate DPO appointment or DPO contact is asserted.
02 / Data lifecycle
Account and contact details → engagement intake → bounded object, claims and evidence → analysis → findings → report and readout → clarification → closeout → retention or deletion under the agreed arrangements.
Personal data identifies or relates to people. Confidential business information may include non-public architectures, technical diagrams, claims, policies, risk assessments and governance artefacts even when it contains no personal data. An item may fall into both categories. Customer submissions remain customer-provided materials; uploading them does not transfer ownership or make them public.
03 / Data collected
The application receives a site-specific account identifier and email through ChatGPT sign-in; a display name may also be provided. Astrynn does not collect your ChatGPT password. Authentication is operated by the hosting platform.
The engagement record contains organisation and contact details, object and question, available-evidence descriptions, agreed scope, acceptance records, status history, messages, clarification and closeout information. Uploaded evidence and its filename, size and submission time are stored for the engagement.
Customer findings, internal analysis notes, conclusions, limitations and report/readout arrangements form part of delivery. Billing records contain invoice references, instructions, tax/amount details and payment receipt references entered by Astrynn. The application does not collect card details or operate a connected payment gateway.
Hosting infrastructure may process connection and security data. Exact platform-log categories and duration: [TECHNICAL LOG INVENTORY TO BE CONFIRMED]. Optional analytics and marketing technologies are not configured. A necessary browser-local record remembers your privacy preference.
04 / Purposes and legal bases
Information is used to identify the client, scope and administer the engagement, receive relevant evidence, carry out the agreed technical confrontation, deliver and clarify findings, maintain commercial records, protect access and respond to support or privacy requests.
The applicable legal basis must be established for each purpose and jurisdiction: [LEGAL BASIS BY PURPOSE TO BE CONFIRMED]. This may require distinguishing steps requested before a contract, contract administration, applicable legal duties and assessed legitimate interests. Acknowledging this notice is not consent to every processing activity. No optional analytics consent is bundled into engagement acceptance.
The platform does not make an automated decision that approves an architecture. Its operating workflow is human-assisted. Any external analytical service proposed for a particular engagement must be evaluated and disclosed as appropriate before customer material is shared with it.
05 / Access and security
The offer and legal pages are public. Engagement records and file downloads require authentication and server-side checks for the owning customer or configured Astrynn operator. Customer views omit Astrynn internal notes and withhold findings until report release.
Files are stored separately from engagement metadata. The application limits accepted upload types and sizes and serves evidence as downloads rather than executing it inline. Scope and payment gates control workflow progress. These are implemented application controls, not claims of certification, zero risk, a particular storage region or a guaranteed security outcome.
Only submit relevant materials you are authorised to provide. Do not send passwords or unrelated personal data. Discuss additional confidentiality or processing requirements before submission.
06 / Infrastructure, recipients and transfers
The deployed application uses Sites / ChatGPT for hosting access and authentication, with Cloudflare D1 for records and R2 for uploaded files. This identifies implemented infrastructure; it is not a complete approved contractual subprocessor schedule.
Contracting provider entities, their roles, authorised access, processing locations and any additional engagement-specific services: [SERVICE PROVIDER / SUBPROCESSOR SCHEDULE TO BE CONFIRMED]. International-transfer applicability and safeguards: [TRANSFER ASSESSMENT AND SAFEGUARDS TO BE CONFIRMED]. No particular jurisdiction, adequacy decision or transfer mechanism is asserted.
Customer materials are used for the agreed engagement. Submission grants no automatic permission to publish customer names, logos, architectures, case studies or findings. Any public-reference permission must be separate, explicit and opt-in.
07 / Retention, return and deletion
Closing an engagement does not automatically delete its records or files. The application currently retains them for access; no automatic retention-expiry job is configured. Retention schedule by data type, applicable record-keeping duties and backup handling: [RETENTION PERIOD TO BE CONFIRMED].
Request return, correction or deletion through Contact or the engagement conversation. Astrynn must verify authority, determine the applicable duties and agree the action and timing. This interface does not promise instant deletion or a specific backup-erasure period. Applicable DPA instructions and legally required retention must be addressed in the agreed schedule.
08 / Individual rights
Depending on the applicable law and processing basis, individuals may have rights of access, correction, erasure, restriction, portability, objection and withdrawal of consent where processing relies on it. These rights are not unconditional in every situation. You may also have the right to complain to the competent supervisory authority; none is designated here without confirming jurisdiction.
Contact Astrynn with enough context to locate the relevant record. Avoid sending sensitive evidence in an initial email. Reasonable identity or authority checks may be needed. Requests will be assessed under the applicable legal requirements; the relevant procedure and response obligations must be confirmed.
09 / Changes to this notice
This notice is versioned. Material changes should be communicated to affected clients through the engagement or confirmed contact channel, with any new agreement or consent obtained where required. Updating this page does not itself amend an already agreed scope or DPA.
