Legal

GDPR Statement

Last modified: February 18th, 2025

At StarlixAI, we are committed to safeguarding the privacy and personal data of our customers and users of the StarlixAI application. We recognize the importance of complying with the General Data Protection Regulation ("GDPR") and take appropriate measures to ensure the security and confidentiality of the data we collect, process, store, and transmit.

Back to Legal documents

Section 1

Data Collection and Processing

The company obtains information directly from clients or application users to provide services. Data is obtained on a daily basis, ensuring the smooth functioning of our services.

Section 2

Data Processing Procedures

We perform various processes against the data, including collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

Section 3

Data Retention and Deletion

Retention lasts until withdrawal of consent or the expiry of the limitation period for claims arising from contractual agreements. The company maintains procedures for secure deletion per GDPR standards.

Section 4

Data Storage and Security

Enterprise clients can select server geographic locations. We implement appropriate network perimeter IT security protection measures, such as firewalls, intrusion prevention systems (IPS), email/web filtering, DMZ, VLANs, and electronic backups using Google Cloud infrastructure. Internal protections include antivirus software and restricted access.

Section 5

Vendor Compliance and Policies

Vendor procedures comply with GDPR. The vendor maintains formal Data Privacy and Information Security Policies and executes compliant data processing agreements.

Section 6

Data Subject Rights and Data Breach Management

We have established procedures for handling data subject rights requests in accordance with GDPR provisions. Breach procedures ensure notification to controllers within 24 hours. There were no incidents reported in the last 12 months.

Section 7

Data Transfer and Privacy Measures

Transfer occurs via email or via a dedicated API connection, with regulated electronic transfer and control mechanisms.

Section 8

Data Protection Management and Compliance

The organization implements regular security testing, defined responsibilities, and data protection by design and default by implementing privacy-friendly pre-settings and processing only necessary personal data.

StarlixAI's commitment to GDPR compliance and protecting personal data is of utmost importance. We regularly review and update our practices to align with changes in legislation, industry best practices, and our commitment to data protection and privacy.