Privacy policy
Last Updated:
Privacy Policy
This Privacy Policy explains what personal data Astrix Tech Ltd (“Astrix”, “we”, “us”, “our”) collects when you use our website and our training and assessment products, why we collect it, how we use and protect it, and the rights and choices you have. It covers our two products, the Simulations App and the Live Meeting App, both of which process voice, video and other data to generate skills and communication assessments.
In short: To provide our assessments we record and analyse your voice, and (where you enable it) your video and screen share. We generate transcripts and scores from that content, and we store them. Some of this analysis relies on biometric data. We only use it to provide the service to you and the organisation you belong to, we do not sell it, and you can ask us to delete it at any time by emailing security@astrix.ai.
Contents
Who we are and scope
Our role: controller and processor
Key terms
Data we collect
Voice, video and biometric data
How and why we use your data
Automated analysis, profiling and AI
Consent and how to withdraw it
How we share data
International transfers
Retention
Deleting your data
Your rights
Security
Children
Changes to this policy
Contact and EU representative
1. Who we are and scope
Astrix Tech Ltd is a company registered in the Dubai International Financial Centre (DIFC), United Arab Emirates, at Gate Avenue at DIFC, Zone D, Level 1, Offices 208-215, Dubai, AE. We provide AI-powered training and assessment software.
This Policy applies to personal data we process through:
our website at astrix.ai (the “Site”);
the Simulations App, our web application in which users take part in AI-driven voice or video role-play scenarios and receive assessments against competency frameworks; and
the Live Meeting App, our native desktop application which records real-world meetings and produces assessments comparable to those of the Simulations App.
We refer to these together as the “Services”. Where the Services are provided to you through your employer, training provider or another organisation (the “Organisation”), please read section 2, which explains who is responsible for your data.
2. Our role: controller and processor
Our responsibilities under data protection law depend on why data is being processed:
When we act as a “controller”. We decide the purposes and means of processing for our Site, our own account administration, direct communications with you, billing, security and product improvement. For these activities Astrix is the controller.
When we act as a “processor”. When an Organisation uses the Services to train or assess its people, that Organisation generally decides who is assessed, against which frameworks, and for what purpose. In that case the Organisation is the controller of the assessment data (recordings, transcripts and scores) and Astrix processes it on the Organisation’s documented instructions under a data processing agreement. If you access the Services through an Organisation, that Organisation’s own privacy notice governs how it uses your assessment results, and you should direct requests about that use to them. We will support the Organisation in responding to your requests, and you can also contact us directly.
3. Key terms
Assessment Data: the audio, video and screen-share recordings you generate through the Services, the transcripts derived from them, and the scores, metrics and analytics we produce from them.
Scores and metrics: competency and evaluation results, communication-competency scores (for example confidence, warmth and captivation), expression metrics, speech and voice analytics, and related outputs.
Biometric data: data resulting from technical processing of a person’s physical, physiological or behavioural characteristics, such as characteristics of the voice or face. See section 5.
Special category data: data that receives extra protection under the GDPR, including biometric data used to uniquely identify a person and data revealing health or similar sensitive matters.
4. Data we collect
4.1 Information you provide
Category | Examples |
|---|---|
Account information | Name, surname, username, email address, password, and where applicable a personal or employee identifier and the Organisation you belong to. |
Profile and framework settings | Role, team, and the competency frameworks or scenarios assigned to you. |
Communications | Messages, support requests and any information you choose to share when you contact us. |
Billing information | Where you or your Organisation purchase directly, billing contact and payment details (card details are handled by our payment processor, not stored by us). |
4.2 Assessment Data you generate through the Services
This is the core of what the Services do, and the most sensitive data we handle. Depending on the product and the settings enabled by you or your Organisation, we collect and store:
Audio / voice recordings of your speech during scenarios (Simulations App) and meetings (Live Meeting Assessment).
Video recordings, where a scenario or meeting has video enabled.
Screen-share recordings, where screen share is enabled.
Transcripts generated from your audio.
Scores, metrics and analytics, including competency and evaluation results, communication-competency scores (e.g. confidence, warmth, captivation), expression metrics, and speech and voice analytics.
Metadata about each session, such as timestamps, duration, scenario or meeting identifiers, and (for the Live Meeting Assessment) information needed to associate a recording with a meeting.
For the Live Meeting Assessment, recordings may also capture the voices and, if video is enabled, the images of other meeting participants. Responsibility for obtaining those participants’ consent to being recorded rests with you and your Organisation. See our Terms and Conditions and section 8 below.
4.3 Information we collect automatically
Log and device data: IP address, browser type, operating system, device identifiers, referring/exit pages, date/time stamps and clickstream data.
Approximate location: derived from your IP address.
Usage analytics: how you interact with the Site and Services, collected using analytics tools (see section 9). Non-essential cookies and similar technologies are used only with your consent; see our Cookie Notice.
5. Voice, video and biometric data
We want to be clear and specific about this, because it is central to how the Services work and it was not adequately disclosed in our previous policy.
The Services analyse characteristics of your voice and, where enabled, your face and expression in order to produce speech analytics, expression metrics and communication-competency scores. This analysis of physiological and behavioural characteristics constitutes processing of biometric data.
Under the GDPR, biometric data becomes special category data, attracting the highest level of protection, where it is used for the purpose of uniquely identifying a person (for example, matching a voice or face to confirm identity). Where our processing crosses that threshold, we rely on your explicit consent (or another Article 9 condition where one applies) and we carry out a Data Protection Impact Assessment. Where our analysis produces communication and expression metrics without being used to uniquely identify you, the underlying recordings and derived data remain personal data that we protect with the same care described in this Policy.
Expression and emotion metrics, important. Some outputs (voice tone or facial expression indicators, and any state derived from them) are estimates of how communication may be perceived. Inferring a person’s emotions from biometric data in workplace or education contexts is restricted under the EU AI Act. Where required, we make these particular outputs configurable and may disable them for users in the EU/EEA. Your Organisation controls which metrics are enabled for your deployment; contact us or your Organisation for details of what is active for you.
We do not use your identifiable voice, video or biometric data to train general-purpose AI models, and we do not sell it. Any use of your content to improve the Services is described in section 7.
6. How and why we use your data
We only process personal data where we have a lawful basis to do so. The table below sets out our main purposes and the basis we rely on (where Astrix is the controller). Where Astrix acts as a processor for an Organisation, the lawful basis is determined by that Organisation.
Purpose | Data used | Lawful basis (GDPR Art. 6 / 9) |
|---|---|---|
Create and administer your account; authenticate you | Account information | Performance of a contract; legitimate interests |
Deliver scenarios and meetings, generate transcripts, scores and analytics | Assessment Data | Performance of a contract; where directed by an Organisation, that Organisation’s basis; explicit consent for special-category biometric processing |
Enable comparison of results across scenarios and meetings | Scores and metrics | Performance of a contract; legitimate interests |
Provide support and respond to you | Account and communications | Legitimate interests; performance of a contract |
Billing and administration | Billing information | Performance of a contract; legal obligation |
Secure the Services; prevent fraud and abuse | Log/device data; account data | Legitimate interests; legal obligation |
Improve and develop the Services | Aggregated / de-identified data; limited diagnostic data | Legitimate interests (see section 7) |
Marketing communications | Contact details, preferences | Consent; legitimate interests (existing customers, with opt-out) |
Comply with legal obligations | As required | Legal obligation |
7. Automated analysis, profiling and AI
The Services are, by their nature, automated. We use AI and algorithmic models to generate transcripts, scores, expression metrics and speech analytics. This involves profiling, the automated evaluation of aspects of your performance and communication.
Assessments are estimates, not verdicts. Outputs are indicative and may contain errors or biases. They are intended to support learning, coaching and human judgement, not to be the sole basis of decisions that produce legal or similarly significant effects for you (such as hiring, promotion, discipline or dismissal).
Decisions rest with your Organisation. Where an Organisation uses the Services, it decides how to use the results. Where a decision producing legal or similarly significant effects would be based solely on automated processing, you have rights under Article 22 GDPR, including to obtain human review; contact your Organisation or us to exercise them.
Improving the Services. We may use aggregated or de-identified data to evaluate and improve model quality. We do not use your identifiable recordings or biometric data to train models without an appropriate lawful basis and, where required, your explicit consent.
See the flagged note in section 5 regarding emotion-related outputs and the EU AI Act.
8. Consent and how to withdraw it
Where we rely on your consent, including explicit consent for special-category biometric processing, non-essential cookies, or marketing, you can withdraw it at any time. Withdrawing consent does not affect processing that took place before withdrawal, and it may mean we can no longer provide some or all of the Services to you.
Recording others (Live Meeting App). If you use the Live Meeting App to record meetings, you are responsible for informing other participants and obtaining any consent required by law in your jurisdiction before recording. Do not record where doing so would be unlawful.
To withdraw consent or change your choices, adjust the relevant setting in the Services or email security@astrix.ai.
9. How we share data
We do not sell your personal data. We share it only as follows:
Your Organisation. Where you use the Services through an Organisation, your account and assessment results are available to that Organisation’s authorised administrators.
Service providers (processors / sub-processors). We use trusted vendors to run the Services, under contracts that require them to protect your data and process it only on our instructions. These include categories such as cloud hosting and storage, AI/large-language-model and speech-analysis providers, transcription, analytics, email delivery and customer support. A current list of key sub-processors is available on request.
Professional advisers and authorities. Where required by law, court order or lawful request, or to establish, exercise or defend legal claims, and in connection with a merger, acquisition or reorganisation.
10. International transfers
We are based in the UAE and use service providers that may be located in other countries, so your data may be transferred across borders. Where we transfer personal data of individuals in the EU/EEA or UK to a country that has not been recognised as providing adequate protection, we put appropriate safeguards in place, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant), together with additional measures where needed. You can request details of the safeguards we use by emailing security@astrix.ai.
11. Retention
We keep personal data only for as long as we need it for the purposes described in this Policy:
Account information: for as long as your account is active, and for a reasonable period afterwards.
Assessment Data (recordings, transcripts, scores): for as long as needed to provide the Services and to enable comparison of results, in line with your Organisation’s instructions and retention settings, unless you ask us to delete it sooner.
Billing and legal records: for as long as required to meet legal, tax and accounting obligations.
When data is no longer required, we delete it or irreversibly anonymise it.
12. Deleting your data
You can ask us to delete your personal data, including your recordings, transcripts and scores. To make a request, email security@astrix.ai from the address associated with your account, or ask your Organisation’s administrator to submit the request on your behalf.
Deletion is currently handled manually on request. We aim to action verified requests without undue delay and in any event within one month, as required by the GDPR (this period may be extended by up to two further months for complex requests, in which case we will tell you). Where you access the Services through an Organisation, we may need to consult that Organisation before deleting assessment data, and some data may be retained where we have a legal obligation or overriding legitimate ground to keep it; we will explain if that is the case.
13. Your rights
Subject to applicable law, you have the right to:
access the personal data we hold about you;
have inaccurate data corrected;
have your data erased (“right to be forgotten”);
restrict or object to certain processing, including profiling and direct marketing;
receive your data in a portable format and, where feasible, have it transmitted to another controller;
withdraw consent at any time where we rely on it;
not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and to obtain human review of such a decision; and
lodge a complaint with a supervisory authority in your country of residence or work.
To exercise any of these rights, email security@astrix.ai. We will not discriminate against you for exercising them. If you access the Services through an Organisation acting as controller, we may direct your request to them or act on their instructions.
14. Security
We handle personal data in a manner designed to comply with the GDPR, and our security programme is aligned with the ISO/IEC 27001 framework. We implement technical and organisational measures designed to protect personal data, including encryption in transit and at rest, access controls (including multi-factor authentication and single sign-on for organisations), monitoring and vendor due diligence. More detail is set out in our Security Overview. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; please avoid sharing sensitive information that is not necessary for the Services.
15. Children
The Services are intended for use by adults (18 years or older) in a professional, training or educational context arranged through an Organisation. They are not directed to children, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
16. Changes to this policy
We may update this Policy from time to time. We will post changes on the Site and update the “Last updated” date above. Where changes are significant, we will provide a more prominent notice and, where appropriate, seek your consent.
17. Contact and EU representative
For any question about this Policy, or to exercise your rights, contact:
Astrix Tech Ltd Gate Avenue at DIFC, Zone D, Level 1, Offices 208-215, Dubai, AE Privacy and data requests: security@astrix.ai
EU representative (GDPR Article 27). For individuals in the EU/EEA, our representative can be contacted at: Jason Valenti, jason@astrix.ai, +31 6 27367370 (Netherlands).
