Astry - On-Call Management Platform

Privacy Policy

Last updated: September 4, 2026

1. Introduction

This Privacy Policy explains how 5SOFT ("we", "us", "our"), the publisher of the Astry platform, collects, uses, discloses and protects personal data when you visit our website or use our SaaS application, available via web and mobile app (together, the "Services").

This Policy applies to website visitors, prospective and current customers, and any individual whose personal data is processed in connection with the Services — including Users and Alert Recipients as defined in our Terms of Service. If your personal data was added to the Services by an organization you belong to (your employer, for example), that organization acts as the data controller for that data, and 5SOFT acts as its data processor, as further described in our Data Processing Addendum.

2. Who We Are

5SOFT SAS — France

Headquarters: 5 rue Marie de Lorraine, 37700 La Ville-aux-Dames, France

SIRET: 991 029 042 00017

Contact / Data Protection: contact@astry.fr

3. Personal Data We Collect

  • Account and profile data: name, email address, phone number, job title / position, organization name.
  • Contact and alert data: phone numbers, email addresses, and notification preferences of Users and Alert Recipients, as configured by your organization.
  • Technical and usage data: IP address, browser and device information, log data, and cookies (see Section 6).
  • Billing data: billing address and invoicing details. Payment card details are processed directly by our payment processor; we do not store full card numbers.
  • Support communications: any information you provide when contacting us for support or sales inquiries.
  • Vault content: documents you choose to store in the Astry Vault are encrypted end-to-end; 5SOFT cannot access this content in clear text (see our Terms of Service and Data Processing Addendum for details).

4. How We Use Personal Data

We use personal data for the following purposes:

  • Providing and operating the Services, including account management and authentication.
  • Sending alerts and notifications configured by you or your organization, via SMS, voice call, email, push notification, or Microsoft Teams.
  • Billing, invoicing, and payment processing.
  • Customer support and responding to your requests.
  • Maintaining the security, integrity, and proper functioning of the Services.
  • Improving our Services through aggregated, non-identifying analytics.
  • Complying with legal obligations (accounting, tax, regulatory requests).
  • Sending marketing communications, only where you have opted in or where permitted by applicable law — you may opt out at any time.

5. SMS & Text Messaging Notifications

As part of the Services, Astry can send SMS text messages to Users and Alert Recipients as part of on-call, incident, and crisis alerting, based on the notification strategies configured by you or your organization.

By providing a mobile phone number and enabling SMS notifications, you consent to receive text messages from Astry related to the alerts, incidents, and crises you or your organization have configured. Message frequency varies depending on your organization's activity. Message and data rates may apply.

You can opt out of SMS notifications at any time by replying STOP, by updating your notification preferences in the Astry application, or by contacting your organization's administrator. Reply HELP for help.

No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

6. Cookies & Similar Technologies

We use strictly necessary cookies to operate our website and application (e.g., authentication, session management), as well as optional cookies for analytics, subject to your consent where required by applicable law. You can manage your cookie preferences at any time through your browser settings.

7. How We Share Personal Data

We do not sell personal data. We share personal data only in the following circumstances:

  • Within your organization: data you configure (contact details, notification preferences) is visible to authorized members of your organization, as intended by the Services.
  • Service providers (Sub-processors): we share data with providers who help us deliver the Services (hosting, SMS/voice/email delivery, payment processing), bound by contractual data protection obligations. The current list of Sub-processors is available on our Data Processing Addendum page.
  • Legal requirements: when required to comply with applicable law, regulation, legal process, or governmental request.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, subject to the same protections described in this Policy.

8. International Data Transfers

Astry is hosted on data centers located in the European Union. Where personal data must be transferred outside the European Economic Area (for example, to a Sub-processor), we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, as detailed in our Data Processing Addendum.

9. Data Retention

We retain personal data for as long as necessary to provide the Services and for legitimate business purposes (e.g., legal, accounting, or security reporting requirements). User action logs are retained for 1 year by default, and this duration can be reduced by your organization. When an account, incident, or alert is deleted, associated data is deleted, except where we are required to retain it for legal or security purposes, in which case it is securely archived and access-restricted.

10. Data Security

We implement technical and organizational measures to protect personal data, including TLS encryption in transit, AES-256 encryption at rest, and the SRP protocol so that passwords are never stored on our servers. Documents stored in the Vault are encrypted end-to-end. Further detail is available in our Data Processing Addendum.

11. Your Rights

If you are located in the European Economic Area or the United Kingdom, you have the right to access, rectify, erase, or restrict the processing of your personal data, to object to processing, to data portability, and to withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with your local data protection authority (the CNIL in France).

If you are located in the United States, depending on your state of residence you may have similar rights, including the right to know what personal data we collect, the right to request deletion, and the right to opt out of the sale or sharing of personal data — we do not sell personal data.

To exercise any of these rights, contact us at contact@astry.fr.

12. Children's Privacy

The Services are intended for professional use and are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated Policy on this page with a new "Last updated" date, and, where appropriate, by additional notice (e.g., email).

Questions about your data?

Contact us to exercise your rights or learn more.

Contact Us