Data Protection Policy
Last updated: 19 June 2026
This policy describes how AsronsWorld Ltd (trading as Asronax) protects personal data we hold as a Data Controller and Data Processor under the UK GDPR and the Data Protection Act 2018.
1. Principles
We process personal data lawfully, fairly and transparently; for specified, explicit and legitimate purposes; ensuring it is adequate, relevant and limited to what is necessary; accurate and kept up to date; kept no longer than necessary; and processed securely.
2. Roles
For website visitors, newsletter subscribers and direct customers, AsronsWorld Ltd is the Data Controller. When we process data on behalf of business customers (e.g. running an AI workforce against their CRM), we act as a Data Processor under a written Data Processing Agreement (DPA).
3. Security measures
- Encryption in transit (TLS 1.2+) and at rest where supported by the underlying platform.
- Least‑privilege access, MFA on administrative accounts, audit logging.
- Segregated environments for development, staging and production.
- Vendor due diligence and signed DPAs with sub‑processors.
- Regular backups, restoration testing and incident response planning.
4. Sub‑processors
Current sub‑processors include Lovable.dev, Replit.com and Cloudflare. We maintain a list of sub‑processors and notify business customers of material changes.
5. Data subject rights
We support access, rectification, erasure, restriction, portability and objection requests. Requests are answered within one month (extendable by two months for complex cases).
6. Breach response
Suspected breaches are triaged within 24 hours. Notifiable breaches are reported to the ICO within 72 hours and to affected individuals where required.
7. Training & accountability
All team members complete data protection training. We keep records of processing activities (ROPA) and review this policy at least annually.
8. Contact
Data protection enquiries: dpo@asronax.com.