Version 1 · Last updated 2026-09-05
This page is written for the person at a company who has to answer "is this GDPR-compliant?" before rolling out Starkie Teams. It is a summary in plain language; the binding terms are in the Data Processing Addendum, the Teams privacy addendum and the Teams terms.
Your organisation decides that its people will have headshots made, who is invited and what happens to the results, so your organisation is the controller for your members' data. Starkie AI — operated from Italy, [legal entity name, registered address, VAT number] — is the processor, acting on your instructions. For your administrators' own account data (name, email address, sign-in records, billing) we are the controller.
For members, the basis for processing their facial images is their explicit consent, which we collect before they can upload anything. The consent text is versioned and we store which version each person accepted, with a timestamp. A member who does not consent simply never uploads, and nothing is generated for them. Because a face model is data about an identified person, we treat it with Article 9 care whether or not it is formally classified as biometric data in your jurisdiction.
For administrators, the basis is the contract between your organisation and us, plus our legitimate interest in keeping the service secure and running.
Names, work email addresses, optional job titles, the three to eight selfies a member uploads, the roughly forty images generated from them, any branded profile picture, the consent record, and technical logs. We do not use member images to train models for anyone else, and we do not sell them or use them for advertising.
Starkie Teams is not an EU-only service. Model training and image generation run at Astria in the United States, images are stored in Amazon S3 in us-west-1, and transactional email is sent through Resend in the United States. Hosting and error monitoring are provided by Vercel and Sentry. Transfers out of the EEA are covered by the European Commission's Standard Contractual Clauses with each provider; the full list with regions is at /legal/subprocessors.
Uploaded selfies are deleted a set number of days after a member's photos are ready — you choose between 7 and 90 days, and the default is 30. The private model trained from them is deleted at the same time unless you opt in to keeping it for retakes. Generated headshots remain available to your organisation and to the member until one of you deletes them, or until the organisation is closed.
Members and administrators have the rights to access, rectification, erasure, restriction of processing, data portability and objection. There are three routes:
A data subject can complain to the supervisory authority in their country of residence or workplace. For Starkie AI, and for controllers established in Italy, that authority is the Garante per la protezione dei dati personali.
The processor terms are at /legal/dpa, the current sub-processors at /legal/subprocessors, and our technical measures at /security. For anything else, or to sign the addendum as a countersigned document, write to privacy@starkie.ai.