Effective Date: June 2025
This Third-Party Data Sharing & Vendor Policy (“Policy”) describes how Astricks (“Astricks,” “we,” “us,” or “our”) shares personal and business information with vendors, service providers, and business partners (collectively, “Third Parties”), and the standards Third Parties must meet to receive, process, or use that information. This Policy supplements our Privacy Policy and applies to all Astricks personnel who engage or manage Third Parties on the company’s behalf.
1. Purpose and Scope
This Policy applies to any Third Party that receives, accesses, processes, or stores data belonging to Astricks, its customers, or its employees in connection with the Services. It governs the selection, onboarding, contracting, monitoring, and offboarding of such Third Parties.
2. Categories of Third Parties and Purposes
We may share data with the following categories of Third Parties for the purposes indicated:
| Category | Purpose | Safeguards |
| Cloud Hosting / Infrastructure | Host our Services, store data securely | Data hosting agreements, encryption standards |
| Payment Processors | Process transactions and billing | PCI-DSS compliance required |
| Analytics Providers | Understand usage and improve Services | Aggregated/pseudonymized where possible |
| Customer Support Tools | Manage support tickets and communications | Access limited to support purposes |
| Marketing/Advertising Partners | Deliver and measure marketing campaigns | Opt-out honored; no sale of data for money |
| Professional Services | Legal, accounting, audit support | Confidentiality obligations apply |
3. Permitted Use by Third Parties
Third Parties may use data shared by Astricks solely for the specific purpose(s) for which it was disclosed, as defined in the applicable agreement or statement of work. Third Parties are prohibited from:
- Using Astricks data for their own independent marketing or research purposes without explicit authorization
- Selling, renting, or otherwise disclosing Astricks data to any other party, except as required to deliver the contracted service or as required by law
- Combining Astricks data with other data sources in a way that re-identifies anonymized or aggregated data, unless expressly permitted
- Retaining data longer than necessary to fulfill the contracted purpose, or beyond contract termination, except as required by law
4. Vendor Due Diligence
Before engaging a new Third Party that will access personal or sensitive business data, Astricks will conduct due diligence proportionate to the risk involved, which may include:
- Review of the vendor’s security practices and certifications (e.g., SOC 2, ISO 27001)
- Assessment of the vendor’s data protection and privacy practices
- Review of the vendor’s subcontracting/sub-processor practices
- Reference checks or review of past performance, where applicable
5. Contractual Requirements
Where a Third Party will process personal information on Astricks’ behalf, we require a written agreement (such as a Data Processing Agreement or equivalent contractual terms) that includes, as applicable:
- A description of the data shared, purpose, and duration of processing
- Confidentiality obligations
- Appropriate technical and organizational security measures
- Restrictions on further disclosure or sub-processing without consent
- Data breach notification obligations
- Data return or deletion obligations upon termination
- Audit or inspection rights, where appropriate
- Compliance with applicable data protection laws (e.g., CCPA, GDPR, as relevant)
6. Sub-Processors
Third Parties that engage their own subcontractors (“sub-processors”) to assist in processing Astricks data must ensure such sub-processors are bound by data protection obligations no less protective than those imposed on the Third Party itself. Material changes to sub-processors should be disclosed to Astricks in advance where required by contract.
7. International Data Transfers
Where a Third Party processes data outside the country in which it was originally collected, appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) will be used to ensure the transfer complies with applicable law.
8. Security Requirements
Third Parties handling Astricks data must maintain reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including access controls, encryption in transit and at rest (where applicable), and incident response procedures.
9. Monitoring and Audits
Astricks reserves the right to periodically review Third Party compliance with this Policy and applicable contractual obligations, which may include requesting documentation, completing security questionnaires, or conducting audits, subject to the terms of the applicable agreement.
10. Incident Response
Third Parties must notify Astricks promptly, and in any event within the timeframe specified in the applicable agreement, upon becoming aware of any actual or suspected unauthorized access to, or disclosure of, Astricks data.
11. Termination and Data Return/Deletion
Upon termination or expiration of a Third Party engagement, the Third Party must, at Astricks’ direction, return or securely delete all Astricks data in its possession, except where retention is required by law, and must confirm such return or deletion in writing upon request.
12. Policy Owner and Contact
Questions about this Policy, or requests related to a specific Third Party engagement, should be directed to:
Astricks
Email: vendors@astricks.com
Address: [Insert Company Address]
Phone: [Insert Phone Number]
13. Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a revised “Last Updated” date.
This document is a general template and does not constitute legal advice. Please consult a qualified attorney to tailor this Policy to your vendor landscape and applicable data protection laws (e.g., GDPR, CCPA/CPRA) before publishing or relying on it.