Astrid Privacy Notice
This Astrid Privacy Notice explains how BillPortal Technologies Inc. processes prompts, conversations and permission-scoped workspace data when you use Astrid, our Beta AI assistant. It supplements our Privacy Policy and Data Processing Agreement.
Questions about this policy, a refund, or want to raise a dispute? Our team is happy to help.
Contact support1. Scope
This notice covers data processed specifically in connection with Astrid. It sits alongside, and is subject to, our Privacy Policy (for personal data we control) and our Data Processing Agreement (for customer data we process on your behalf). Where a term is not defined here, it has the meaning given in those documents.
2. What Astrid processes
- Prompts and messages you type into Astrid, and files or attachments you upload to a conversation or to Astrid Drive.
- Conversation context, including prior messages in the same conversation and Astrid-generated drafts, report cards and results.
- Permission-scoped BillPortal workspace data retrieved at answer time via approved tools, limited to the collections and fields your role and organization can access.
- Operational metadata such as the resolved user scope, tool activity, timestamps, row counts, latency and error information, and AI-credit usage metered to your organization.
3. Grounded at answer time — not trained on your data
Astrid is not custom-trained on your private company data. When you ask a question, BillPortal combines your prompt with a system prompt, current conversation context, an approved tool registry and permission-scoped live data so the answer can be grounded in your workspace. Your workspace data is used to answer your request — it is not used to train the underlying foundation models.
4. Model providers and sub-processors
Astrid is powered by third-party large language model providers acting as our sub-processors, together with the cloud infrastructure and operational tooling described in our DPA. We share with these providers only what is needed to process your request. Model providers are engaged under contractual protections consistent with our DPA, and are additional to the sub-processors already listed there.
5. Retention
Astrid conversations, generated outputs and associated tool activity are persisted so you can revisit and continue prior work, and for security, support, abuse-prevention and service-improvement purposes. Retention follows the periods and controls set out in our Privacy Policy and DPA, and customer data is returned or deleted on termination as described in the DPA, except where retention is required by law.
6. Security
We apply the technical and organisational measures described in our DPA and Security notice to Astrid, including encryption in transit and at rest, access controls, least-privilege access and audit trails. Sensitive credentials handled within guided onboarding workflows are managed in protected UI and are not repeated or displayed back in chat.
7. Your controls and rights
- You control what you submit to Astrid; avoid sharing data or credentials you are not authorised to process.
- Data-subject rights (access, correction, deletion, objection and others) are exercised as described in our Privacy Policy and, for customer data, the DPA.
- Because Astrid is designed for human-in-the-loop review, its processing does not, by itself, make decisions producing legal or similarly significant effects about individuals; where such rights apply, they are handled under the Privacy Policy and DPA.
8. Contact
Questions about how Astrid processes your data, or to exercise your rights, contact info@billportal.io.
