Privacy Policy

Last updated: 5 September 2026

Who we are

AstraHR is operated by 38SHIFT LTD, a company registered in England and Wales, company number 17335669, registered office 128 City Road, London, EC1V 2NX, United Kingdom. 38SHIFT LTD is the controller for the personal data described in “Data about you as our customer” below.

For the employee records your organisation stores in AstraHR, your organisation is the controller and we are the processor. We process that data only on your instructions. If you are an employee whose data is in AstraHR, your employer is the right first point of contact for access, correction or erasure.

Privacy questions: privacy@astrahr.com.

Data about you as our customer

  • Account data: your name, work email address and role.
  • Billing data: billing contact, billing address and VAT identification number, collected at checkout and held by Stripe.
  • Usage data: sign-in events and application logs, used to operate and secure the service.

Legal basis: performance of our contract with you (Art. 6(1)(b)) for account and billing data, and our legitimate interest in operating and securing the service (Art. 6(1)(f)) for usage data. Where we are required to keep billing records, the basis is legal obligation (Art. 6(1)(c)).

Data your organisation stores in AstraHR

Employee records, documents, absence, time, payroll preparation, reviews, goals, meetings and feedback. We hold this as processor on your organisation’s behalf. Every table is scoped to an organisation and isolated by database-level Row Level Security, so one customer cannot read another’s rows.

Sub-processors

We use the following sub-processors. We will tell you before adding or replacing one.

Sub-processorWhat it doesWhereTransfer basis
SupabaseDatabase, authentication and file storage. All customer records live here.Ireland (eu-west-1)Within the EEA. No transfer mechanism required.
VercelApplication hosting. Processes requests in transit; stores no customer records.Frankfurt (fra1)Within the EEA for processing. Vercel Inc is US-headquartered; SCCs apply.
AnthropicThe AI assistant and insights. Sends the employee and organisation data needed to answer a question you ask.United StatesStandard Contractual Clauses.
Stripe Payments Europe, Ltd.Subscription billing. Receives your billing contact, email, address and VAT identification number. It does not receive employee records.Ireland, with onward transfer to Stripe, Inc. in the United StatesEU-US Data Privacy Framework and Standard Contractual Clauses.
ResendTransactional email: sign-in links and team invitations.United States (sending infrastructure in eu-west-1)Standard Contractual Clauses.

Artificial intelligence

The AI assistant answers questions about your own data. To do that it sends the relevant employee and organisation records to Anthropic. Your data is not used to train any model. If you would rather it were never sent, an owner can disable the AI modules for your workspace, and the rest of AstraHR is unaffected.

Retention

We keep your data for as long as your workspace exists. If you stop paying, your data remains readable and exportable: we do not withhold access to records you have already entered, because you may need them to answer your own obligations.

Deleting an employee record deletes it. Where you must retain a record to satisfy a legal obligation, for example commercial or tax retention periods, you can pseudonymise it instead. A record for someone who has left is not billed, so retention costs you nothing.

Your rights

You have the right to access, correct, erase, restrict and port your personal data, and to object to processing based on legitimate interests. Write to privacy@astrahr.com and we will respond within one month.

Portability is self-service. An owner or admin can download their whole workspace as structured JSON at any time from /api/export. It works in every billing state, including after cancellation, because you may need your own records to answer a request made to you.

If you are in the UK you may complain to the Information Commissioner’s Office. If you are in the EEA you may complain to your local supervisory authority.

Security

Data is encrypted in transit and at rest. Access is passwordless, by emailed sign-in link, so there is no password to guess or reuse. Tenant isolation is enforced by the database rather than by application code. We do not hold any security certification, and we say so rather than implying one.

Changes

We will post changes here and, for anything that materially affects you, tell you before it takes effect.