Astrium Software Solutions CC (“Astrium”, “we”, “us”, or “our”) operates Astrium Insight, an Azure cost optimization and performance monitoring service. This Privacy Policy explains how we collect, use, process, store, and protect personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA) and applicable South African law.
This policy applies to all users of Astrium Insight, including customer contacts who receive cost optimization reports and administrators who interact with the service.
Astrium Software Solutions CC is the responsible party as defined in POPIA for all personal information processed through Astrium Insight.
| Purpose | Lawful Basis (POPIA) | Data Categories |
|---|---|---|
| Generating Azure cost optimization reports | Contractual obligation (s11(1)(b)) | Contact info, Azure data |
| Delivering reports via email | Contractual obligation (s11(1)(b)) | Email addresses, names |
| Providing shareable web report access | Contractual obligation (s11(1)(b)) | Azure data, access logs |
| Admin review of reports before delivery | Legitimate interest (s11(1)(f)) | Admin actions, report data |
| Calculating realised savings for billing | Contractual obligation (s11(1)(b)) | Azure cost data |
| Service improvement and reliability | Legitimate interest (s11(1)(f)) | Aggregated usage data |
All Azure API access is performed using a multi-tenant Entra ID App Registration with the minimum necessary read-only RBAC roles: Cost Management Reader, Reader, and Monitoring Reader.
Recommendation-only service: We do not request or use write permissions on customer Azure environments. No automatic actions are taken on customer infrastructure.
We do not sell, rent, or trade personal information to any third party.
When using large language models (LLMs) to generate cost optimization recommendations:
Astrium Insight is designed and hosted for the South African market. If any cross-border transfer is required (e.g., LLM API calls), we ensure adequate data protection measures are in place per POPIA s72, and only non-personal, anonymised data is transferred.
tenant_id and Row-Level Security (RLS) policies| Data Category | Retention Period |
|---|---|
| Customer contact details | Duration of service agreement + 12 months |
| Azure cost/performance data | 13 months rolling window |
| Generated reports | 12 months from generation date |
| Shareable report links | 90 days active, then expired |
| Admin review/audit logs | 24 months |
| Billing/savings tracking data | Duration of agreement + 36 months |
Upon termination of a service agreement, we will provide a data export upon request (within 30 days) and delete all identifiable customer data within 90 days.
As a data subject, you have the following rights:
To exercise any of these rights, email privacy@astrium.co.za with subject line “POPIA Data Subject Request — [Your Name]”. We will respond within 30 days.
You may also contact the Information Regulator directly:
In the event of a data breach that compromises your personal information, we will notify the Information Regulator as soon as reasonably possible (within 72 hours) and notify affected data subjects, including details of the breach, the information affected, and measures taken.
Astrium Insight web reports:
Astrium Insight is a business-to-business service and does not knowingly collect or process personal information of children (persons under the age of 18).
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date and notify affected customers via email.
For questions, concerns, or requests related to this Privacy Policy:
This Privacy Policy is published pursuant to the Protection of Personal Information Act (POPIA), Act 4 of 2013, and is effective from 27 March 2026.