The GDPR processor terms that apply when you put client records into AstraDesk.
Last updated: 14 September 2026
This Data Processing Addendum (“DPA”) is part of the contract between you (“Controller”) and Niall Darby, trading as Star-Tek IT Services, Ireland (“Processor”), for the AstraDesk workspace. Using AstraDesk to store or send invoices, contracts, contacts, or signing records that include personal data constitutes acceptance of this DPA. If you need a signed copy, email ltdstartek@gmail.com.
Your own AstraDesk account (email, sign-in, license) is described in the Privacy Policy. This DPA covers personal data of your clients and counterparties that you put into the workspace.
You decide why and how your client data is used (Controller). We process that data only to provide AstraDesk (Processor), on your documented instructions, which are: operate the workspace, sync across your devices, generate downloads, send signing links you create, and keep the audit trail those links produce.
We process that data only to run AstraDesk, to comply with law, or on your other written instructions. People who can access systems are bound to confidentiality. We do not sell invoices, contacts, or signature data, and we do not use them for advertising.
Workspace traffic uses HTTPS. Authentication, database, and file storage run on Supabase with encryption in transit and at rest on their infrastructure, and row-level security so other AstraDesk customers cannot read your rows. This is not a zero-knowledge vault: we can operate the service. We do not run a separate SOC 2, ISO 27001, or pentest for AstraDesk yet. We are a new product, so for now we inherit platform security from the providers we use: Supabase for the workspace (SOC 2 Type 2 and ISO 27001), Render for the website, Apple and Stripe for sign-in and checkout. Those reports cover their infrastructure. As we scale we will add our own.
On written request we will describe these measures. Do not treat AstraDesk as the only copy of contracts or invoices — export what you need to keep.
You authorise the providers below. We will post material changes on this page. If you object, you may export your data and close the account.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Sign-in, database, and file storage for the workspace | AWS eu-north-1 (Stockholm, Sweden — EU) |
| Google (Gemini) | Optional AI Draft Studio only — skipped if you do not use it | May be processed outside the EEA under Google’s API terms |
| Apple | Sign in with Apple, and App Store license purchases | Apple’s systems |
| Stripe | One-time web license checkout (not your clients’ invoice payments) | Stripe’s systems |
| Google (Gmail) | Support email if you write to us | Google’s systems |
Core workspace data is stored in the EU (Stockholm). Optional Gemini drafts and support email may leave the EEA. Those transfers rely on the provider’s GDPR terms (including standard contractual clauses where they use them).
We will help you respond to access, deletion, and similar requests that relate to data in AstraDesk, and we will notify you without undue delay if we become aware of a personal-data breach affecting your workspace. We do not give legal advice on whether you need a DPA with your own clients.
You can export invoices as PDF, CSV, or Excel from the app and download signed PDFs and audit trails at any time. For a full workspace copy or account deletion, email ltdstartek@gmail.com or use Support.
If we discontinue AstraDesk we will give reasonable notice where we can so you can export. After shutdown we delete data from active systems as in the Privacy Policy. Keep your own copies of signed files — we are not a long-term archive if the product stops.
On written request we will provide information reasonably needed to show we meet this DPA. We do not currently offer on-site audits or third-party certification reports.
Processor: Niall Darby / Star-Tek IT Services, Ireland. Company page. Privacy: Privacy Policy. Questions: ltdstartek@gmail.com.