Astrium Insight

Privacy Policy

Effective Date: 27 March 2026 Version: 1.0

1. Introduction

Astrium Software Solutions CC (“Astrium”, “we”, “us”, or “our”) operates Astrium Insight, an Azure cost optimization and performance monitoring service. This Privacy Policy explains how we collect, use, process, store, and protect personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA) and applicable South African law.

This policy applies to all users of Astrium Insight, including customer contacts who receive cost optimization reports and administrators who interact with the service.

2. Responsible Party

Astrium Software Solutions CC is the responsible party as defined in POPIA for all personal information processed through Astrium Insight.

3. Personal Information We Collect

3.1 Customer Contact Information

3.2 Azure Tenant & Resource Data

3.3 Service Usage Data

3.4 Information We Do Not Collect

  • South African identity numbers
  • Financial account details (bank accounts, credit cards)
  • Customer application data or workload content
  • End-user personal information within customer Azure environments
  • Authentication credentials for customer Azure environments (we use delegated RBAC with read-only roles)

4. Purpose of Processing

Purpose Lawful Basis (POPIA) Data Categories
Generating Azure cost optimization reports Contractual obligation (s11(1)(b)) Contact info, Azure data
Delivering reports via email Contractual obligation (s11(1)(b)) Email addresses, names
Providing shareable web report access Contractual obligation (s11(1)(b)) Azure data, access logs
Admin review of reports before delivery Legitimate interest (s11(1)(f)) Admin actions, report data
Calculating realised savings for billing Contractual obligation (s11(1)(b)) Azure cost data
Service improvement and reliability Legitimate interest (s11(1)(f)) Aggregated usage data

5. How We Collect Personal Information

5.1 Directly from You

5.2 From Azure APIs (on Your Behalf)

All Azure API access is performed using a multi-tenant Entra ID App Registration with the minimum necessary read-only RBAC roles: Cost Management Reader, Reader, and Monitoring Reader.

Recommendation-only service: We do not request or use write permissions on customer Azure environments. No automatic actions are taken on customer infrastructure.

6. Data Sharing and Third Parties

6.1 We Do Not Sell Personal Information

We do not sell, rent, or trade personal information to any third party.

6.2 LLM Processing Safeguards

When using large language models (LLMs) to generate cost optimization recommendations:

  • No personal information (names, emails, identifiers) is sent to the LLM
  • Only anonymised, aggregated Azure resource data (costs, metrics, configurations) is submitted
  • Tenant identifiers are stripped before LLM processing
  • We maintain an LLM-agnostic architecture to enable provider switching

6.3 Cross-Border Transfers

Astrium Insight is designed and hosted for the South African market. If any cross-border transfer is required (e.g., LLM API calls), we ensure adequate data protection measures are in place per POPIA s72, and only non-personal, anonymised data is transferred.

7. Data Storage and Security

8. Data Retention

Data Category Retention Period
Customer contact details Duration of service agreement + 12 months
Azure cost/performance data 13 months rolling window
Generated reports 12 months from generation date
Shareable report links 90 days active, then expired
Admin review/audit logs 24 months
Billing/savings tracking data Duration of agreement + 36 months

Upon termination of a service agreement, we will provide a data export upon request (within 30 days) and delete all identifiable customer data within 90 days.

9. Your Rights Under POPIA

As a data subject, you have the following rights:

Exercising Your Rights

To exercise any of these rights, email privacy@astrium.co.za with subject line “POPIA Data Subject Request — [Your Name]”. We will respond within 30 days.

Information Regulator

You may also contact the Information Regulator directly:

10. Data Breach Notification

In the event of a data breach that compromises your personal information, we will notify the Information Regulator as soon as reasonably possible (within 72 hours) and notify affected data subjects, including details of the breach, the information affected, and measures taken.

11. Cookies and Tracking

Astrium Insight web reports:

12. Children’s Information

Astrium Insight is a business-to-business service and does not knowingly collect or process personal information of children (persons under the age of 18).

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date and notify affected customers via email.

14. Contact Us

For questions, concerns, or requests related to this Privacy Policy:


This Privacy Policy is published pursuant to the Protection of Personal Information Act (POPIA), Act 4 of 2013, and is effective from 27 March 2026.