This policy explains what personal data Aster collects, why we process it, who we share it with, how long we keep it, and the rights you and your candidates have.
Aster is an AI-assisted hiring platform. We help employers screen resumes, rank applicants, and run their interview pipeline. Protecting the personal data that passes through Aster is central to what we do. This Privacy Policy describes how Oryx Digital Sdn Bhd, trading as Aster ("Aster", "we", "us"), a company incorporated in Malaysia, handles personal data across our marketing site, web and mobile apps, and related services (together, the "Service"). By using the Service you confirm you have read and understood this policy.
Aster processes personal data in two distinct capacities, and your rights differ depending on which applies:
Controller. For data about our customers and their users, such as the account, workspace, billing, and support information an employer gives us to open and run an account, Aster is the data controller and decides how that data is used.
Processor. For candidate data, meaning the resumes and applicant information an employer uploads or collects through Aster, the employer is the controller and Aster is the processor. We handle that data only on the employer's documented instructions and to provide the Service. If you are a candidate and want to exercise your rights, contact the employer you applied to first; we will support them in responding.
We collect the following categories of personal data:
We use personal data to:
Aster uses AI models to read resumes into structured data and to score and rank candidates against the role you define. These outputs are decision support, not automated decisions made without human involvement. Every hiring decision is made by your team, and we ask that you apply human judgement to each one.
We do not use candidate data to train foundation models, and our AI subprocessor is contractually bound not to train its models on the data we send it.
We process personal data in accordance with Malaysia's Personal Data Protection Act 2010 (PDPA) and, where our customers or their candidates are in those regions, the EU and UK GDPR. Depending on the framework, we rely on the following bases:
We do not sell personal data. We share it only where necessary to run the Service:
Subprocessors: the vendors that host, power, and support Aster, each bound by a data processing agreement and reviewed for security before we onboard them. The current list, what each does, and where they process data are on our Subprocessors page.
Integrations you enable: when you connect Google or Microsoft for scheduling, relevant data is shared with that provider to create bookings and invites.
Legal and safety: where we are required by law, or to protect the rights, safety, and security of Aster, our customers, or the public.
Business transfers: if Aster is involved in a merger, acquisition, or sale of assets, personal data may transfer as part of that transaction, subject to this policy.
Aster and our subprocessors may process personal data in regions outside your own, including the European Union and the United States. Where data moves across borders, we rely on appropriate safeguards such as the Standard Contractual Clauses approved by the European Commission and equivalent UK mechanisms.
We keep account and workspace data for as long as your workspace is active and as needed to provide the Service. Candidate data is retained on behalf of, and under the instructions of, the employer that controls it.
Deleting a candidate or closing your workspace removes the associated data from our live systems, and backups age out on a fixed cycle. We may retain limited information longer where required for legal, tax, security, or dispute-resolution purposes.
We apply technical and organisational measures appropriate to the sensitivity of the data, including encryption in transit and at rest, role-based access controls, workspace isolation, audit logging, and regular review of our security practices. No system is perfectly secure, but we work continuously to protect the data you trust us with.
Depending on where you live, you may have the right to access, correct, export, delete, or restrict the processing of your personal data, to object to certain processing, and to withdraw consent. Access, export, and deletion of workspace and candidate data are available directly in the app.
To exercise a right or ask a privacy question about data for which Aster is the controller, contact us using the details below. If your data was uploaded to Aster by an employer, we will refer your request to that employer as the controller. You also have the right to complain to your local data protection authority.
We use essential cookies to sign you in and keep the app working, and analytics and preference cookies to understand and improve the Service. You can control non-essential cookies through your browser or our cookie controls. See our Cookie Policy for detail.
The Service is intended for use by employers and working-age candidates. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
We may update this policy as the Service and the law evolve. When we make material changes we will update the date above and, where appropriate, notify you in-app or by email. Your continued use of the Service after an update means you accept the revised policy.
For privacy questions, data subject requests, or a copy of our Data Processing Agreement, email legal@hireaster.com. We aim to respond to every request within the timeframes required by applicable law.
Questions about this policy?
Email our team at legal@hireaster.com and we'll help.
Related documents