1. Who is responsible
Astro Digital SL, tax identification number B67340463, with its registered address at Passeig Flaugier 46, 2, 08041 Barcelona, Spain, is the controller for data relating to the website, user accounts, support, security and the commercial relationship. Contact: hola@somosastro.com.
When a client connects their Google Ads account, the client normally acts as the controller and Astro Digital as the processor for data processed under the client’s instructions. This processing is governed by the Data Processing Agreement (DPA).
2. Data we process
- Name, work email address, encrypted credentials and role.
- Projects, settings, onboarding responses and objectives.
- Aggregated metrics, advertising account names and structure, without importing personal lead or conversion records.
- Ask Far questions and answers when the client enables the feature.
- Security, access, administrative activity, support and feedback records.
Far is not designed to receive end-customer personal information, payment data, passwords, tokens or special categories of personal data. Do not include these in names, questions, files or support messages.
We receive this data directly from the user, their organisation and, when an account is connected, Google Ads. Data marked as required is necessary to create the account, provide the service or protect it. If it is not provided, the relevant feature cannot be completed.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Create the account and provide the platform | Performance of a contract or pre-contractual steps |
| Security, abuse prevention and auditing | Legitimate interests and legal obligations |
| Support, incident handling and requested product improvements | Contract and legitimate interests |
| Non-essential marketing communications | Consent, where required |
4. Retention
- Account, project, context and metrics: retained while the project is active or archived; removed from the active system when the owner requests permanent deletion.
- Ask Far conversations: 30 days.
- Product suggestions: 90 days.
- Administrative and security activity: 365 days.
- Google Ads OAuth credentials: disconnecting a source from a project stops future queries, but a reusable authorisation may be retained if it is linked to other projects. Only the holder of that authorisation may request its revocation. After confirming the affected projects, we delete the encrypted token and stored cache and attempt to revoke permission with the provider where it allows this.
- Encrypted backups: the approved retention policy is 30 days. Deleted data is removed when that cycle expires and is not selectively restored unless required for continuity or security.
5. Recipients and transfers
We use infrastructure and security providers and, when the client enables it, artificial intelligence providers. They receive only the data necessary for their role and are subject to a contract. The maintained subprocessor list identifies each service, its purpose and location. Where processing involves an international transfer, we use mechanisms provided for under the GDPR, such as adequacy decisions or standard contractual clauses. You can use the contact email to request information about the applicable safeguard and how to obtain a copy.
6. Your rights
You may request access, rectification, erasure, objection, restriction or portability, and withdraw consent without affecting earlier processing. Email hola@somosastro.com. We may ask for reasonable information to verify your identity. We will respond without undue delay and, as a general rule, within one month. If the complexity or number of requests requires a lawful extension, we will inform you within that first month. You may also lodge a complaint with the Spanish Data Protection Agency at aepd.es.
7. Automated decisions and children
Far does not make decisions about individuals that have legal or similarly significant effects. Its outputs provide informational support for professionals. The service is not intended for children.