Skip to content
Astrocounts
HomeSign in

Privacy Notice

Version and last updated: 15 September 2026

This notice explains processing for which the Astrocounts provider is controller. When an organisation determines why personal data is entered into its books, that organisation is normally controller and the Provider is processor under the DPA. For personal use where no other controller exists, the Provider processes the submitted data to perform the requested service.

1. Controller and contact

Holger Bartel, Hauptstr. 17, 10827 Berlin, Germany. Email: support@astrocounts.com. You may also use the contact form. No data protection officer is identified because no appointment obligation has been established; contact the controller directly.

2. Account and contract data

We process name, email address, password hash, account roles, company memberships, legal acceptance versions and times, session and security data, and support communications. Purposes are account creation, authentication, contract performance, customer support, service security, abuse prevention and proof of agreements. Legal bases are GDPR Article 6(1)(b) for contract steps and performance, Article 6(1)(c) for legal duties, and Article 6(1)(f) for the legitimate interests in operating, securing and defending the service.

3. Technical data and cookies

Requests can contain IP address, date and time, route, response status, browser user agent and security identifiers. Essential session and CSRF cookies are used to sign users in and prevent forged requests; they are necessary for the requested service and are not advertising cookies. We do not describe analytics or marketing cookies because the current service does not deploy them. If that changes, this notice and any required consent mechanism must change first.

4. Customer content

Accounting records can contain names, business contact details, bank and payment information, invoice and receipt data, tax identifiers, correspondence and document metadata concerning the Customer's staff, suppliers and customers. The Customer decides why and what to enter and must give affected people its own privacy information. We process this content only on documented instructions, to provide and secure the service, subject to the DPA.

5. Recipients and subprocessors

Access is limited to authorised personnel and service providers that need it. Categories can include hosting and infrastructure providers, email delivery providers, and the configured AI document-extraction provider when a user submits a receipt while scanning is enabled. The current hosted deployment uses OpenAI for receipt extraction. Customer-specific or self-hosted deployments may configure different infrastructure; their operator must publish an accurate list. We do not sell personal data or use Customer documents for advertising.

6. International transfers

A recipient outside the EEA receives personal data only where Chapter V GDPR requirements are met, such as an adequacy decision or approved Standard Contractual Clauses with supplementary measures where necessary. AI processing may involve OpenAI entities and subprocessors outside the EEA under the applicable contractual transfer safeguards. See the AI Processing Notice before submitting a receipt.

7. Retention

Account and Customer data are kept while the service relationship requires them. After termination, data is deleted or returned subject to backups and legal retention. Agreement evidence, security records, claims evidence and commercial or tax documents are retained only for the applicable statutory limitation or retention period and access is restricted. German commercial and tax rules can require certain records for six, eight or ten years; the exact period depends on the record and whose legal duty it is. Backup copies expire through the normal protected backup cycle unless preservation is legally required.

8. Your rights

Subject to legal conditions, you may request access, rectification, erasure, restriction, portability, or object to processing based on Article 6(1)(e) or (f). Where processing genuinely relies on consent, consent may be withdrawn for the future. The separate company AI switch can be turned off at any time; disabling it does not affect prior lawful processing. You may complain to a data protection supervisory authority, including the authority for Berlin or the authority where you live or work.

9. Requirement to provide data and automated decisions

Required account and contract data is necessary to create and operate an account; without accepting the current service agreement the service cannot be used. AI receipt extraction is not necessary and manual entry remains available. Astrocounts does not make solely automated decisions about users that produce legal or similarly significant effects. Extraction suggestions may be automated but remain subject to review.

10. Changes

We will update this notice when processing changes. Material changes are presented to account holders. A privacy notice is an information document, not blanket consent; where law requires consent, it is requested separately.

Astrocounts
Legal NoticeTermsPrivacyDPAAI Processing