Third-Party Data Sharing & Vendor Policy

Effective Date: June 2025

This Third-Party Data Sharing & Vendor Policy (“Policy”) describes how Astricks (“Astricks,” “we,” “us,” or “our”) shares personal and business information with vendors, service providers, and business partners (collectively, “Third Parties”), and the standards Third Parties must meet to receive, process, or use that information. This Policy supplements our Privacy Policy and applies to all Astricks personnel who engage or manage Third Parties on the company’s behalf.

1. Purpose and Scope

This Policy applies to any Third Party that receives, accesses, processes, or stores data belonging to Astricks, its customers, or its employees in connection with the Services. It governs the selection, onboarding, contracting, monitoring, and offboarding of such Third Parties.

2. Categories of Third Parties and Purposes

We may share data with the following categories of Third Parties for the purposes indicated:

CategoryPurposeSafeguards
Cloud Hosting / InfrastructureHost our Services, store data securelyData hosting agreements, encryption standards
Payment ProcessorsProcess transactions and billingPCI-DSS compliance required
Analytics ProvidersUnderstand usage and improve ServicesAggregated/pseudonymized where possible
Customer Support ToolsManage support tickets and communicationsAccess limited to support purposes
Marketing/Advertising PartnersDeliver and measure marketing campaignsOpt-out honored; no sale of data for money
Professional ServicesLegal, accounting, audit supportConfidentiality obligations apply

3. Permitted Use by Third Parties

Third Parties may use data shared by Astricks solely for the specific purpose(s) for which it was disclosed, as defined in the applicable agreement or statement of work. Third Parties are prohibited from:

  • Using Astricks data for their own independent marketing or research purposes without explicit authorization
  • Selling, renting, or otherwise disclosing Astricks data to any other party, except as required to deliver the contracted service or as required by law
  • Combining Astricks data with other data sources in a way that re-identifies anonymized or aggregated data, unless expressly permitted
  • Retaining data longer than necessary to fulfill the contracted purpose, or beyond contract termination, except as required by law

4. Vendor Due Diligence

Before engaging a new Third Party that will access personal or sensitive business data, Astricks will conduct due diligence proportionate to the risk involved, which may include:

  • Review of the vendor’s security practices and certifications (e.g., SOC 2, ISO 27001)
  • Assessment of the vendor’s data protection and privacy practices
  • Review of the vendor’s subcontracting/sub-processor practices
  • Reference checks or review of past performance, where applicable

5. Contractual Requirements

Where a Third Party will process personal information on Astricks’ behalf, we require a written agreement (such as a Data Processing Agreement or equivalent contractual terms) that includes, as applicable:

  • A description of the data shared, purpose, and duration of processing
  • Confidentiality obligations
  • Appropriate technical and organizational security measures
  • Restrictions on further disclosure or sub-processing without consent
  • Data breach notification obligations
  • Data return or deletion obligations upon termination
  • Audit or inspection rights, where appropriate
  • Compliance with applicable data protection laws (e.g., CCPA, GDPR, as relevant)

6. Sub-Processors

Third Parties that engage their own subcontractors (“sub-processors”) to assist in processing Astricks data must ensure such sub-processors are bound by data protection obligations no less protective than those imposed on the Third Party itself. Material changes to sub-processors should be disclosed to Astricks in advance where required by contract.

7. International Data Transfers

Where a Third Party processes data outside the country in which it was originally collected, appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) will be used to ensure the transfer complies with applicable law.

8. Security Requirements

Third Parties handling Astricks data must maintain reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including access controls, encryption in transit and at rest (where applicable), and incident response procedures.

9. Monitoring and Audits

Astricks reserves the right to periodically review Third Party compliance with this Policy and applicable contractual obligations, which may include requesting documentation, completing security questionnaires, or conducting audits, subject to the terms of the applicable agreement.

10. Incident Response

Third Parties must notify Astricks promptly, and in any event within the timeframe specified in the applicable agreement, upon becoming aware of any actual or suspected unauthorized access to, or disclosure of, Astricks data.

11. Termination and Data Return/Deletion

Upon termination or expiration of a Third Party engagement, the Third Party must, at Astricks’ direction, return or securely delete all Astricks data in its possession, except where retention is required by law, and must confirm such return or deletion in writing upon request.

12. Policy Owner and Contact

Questions about this Policy, or requests related to a specific Third Party engagement, should be directed to:

Astricks

Email: vendors@astricks.com

Address: [Insert Company Address]

Phone: [Insert Phone Number]

13. Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a revised “Last Updated” date.

This document is a general template and does not constitute legal advice. Please consult a qualified attorney to tailor this Policy to your vendor landscape and applicable data protection laws (e.g., GDPR, CCPA/CPRA) before publishing or relying on it.