Data Processing Addendum

Version 1 · Last updated 2026-09-05

This addendum applies whenever an organisation ("Customer") uses Starkie Teams to create headshots for its people. It forms part of the Starkie Teams terms and takes effect when the Customer creates an organisation. Starkie Teams is operated from Italy by Starkie AI, [legal entity name, registered address, VAT number].

Roles of the parties

For the personal data of the Customer's members — the employees, contractors and others it invites — the Customer is the controller and Starkie AI the processor, acting only on the Customer's documented instructions: this addendum, the terms, and the settings an administrator chooses in the admin app. For administrator account data (name, email address, sign-in records, billing) Starkie AI is the controller and our privacy policy applies.

Subject matter, duration, nature and purpose

The subject matter is the creation of AI-generated headshots from selfies uploaded by the Customer's members, for as long as the Customer has an organisation on Starkie Teams plus the retention periods below.

Each member uploads three to eight selfies. We use them to train a private image model of that person with our sub-processor Astria, generate around forty headshots, and make the results available to the member and the Customer's administrators. We also store the results, send transactional email (invitations, reminders, delivery and deletion notices), build download archives and, where the Customer has a brand template, composite a branded profile picture. Member images are never used to train models for anyone else.

Categories of data subject and of personal data

Data subjects are the Customer's members and administrators. The personal data: name, work email address, optional job title, uploaded selfies, the images generated from them, any branded profile picture, consent records (version, timestamp, hashed IP address, user agent) and technical logs.

These images are pictures of an identified person's face used to build a model of that face, so we treat them with the care Article 9 requires: a member cannot upload until they have given explicit, versioned consent, and we record which consent text they accepted and when.

Our obligations as processor

  • Process personal data only on the Customer's documented instructions, transfers included, and tell the Customer if we believe an instruction breaches data protection law.
  • Bind everyone authorised to process the data to confidentiality.
  • Apply the measures on our security page, summarised in Annex C.
  • Assist with data subject requests and with Articles 32 to 36. If a member contacts us directly we forward the request to the Customer and answer nothing ourselves beyond pointing them at their self-service options.
  • Delete or return personal data at the end of the service, as described below.
  • Make available the information needed to demonstrate Article 28 compliance, and allow an audit once in any twelve-month period on reasonable notice, subject to confidentiality.

Sub-processors

The Customer gives general written authorisation for the sub-processors listed at /legal/subprocessors, which forms Annex B. We impose equivalent data protection obligations on each of them and remain liable for their performance. Additions and replacements are announced by email to organisation administrators at least 30 days in advance; a Customer that objects on reasonable data protection grounds within that window may terminate the affected part of the service.

International transfers

Starkie Teams is not an EU-only service. Personal data, member photos included, is processed in the United States: model training and generation by Astria, storage in Amazon S3 us-west-1, transactional email by Resend. For transfers out of the EEA we rely on the European Commission's Standard Contractual Clauses agreed with each sub-processor, plus supplementary measures: encryption in transit and at rest, private storage prefixes, short-lived presigned access, data minimisation.

Personal data breaches

We notify the Customer without undue delay and within 72 hours of becoming aware of a breach affecting its data, with the detail we have at the time and more as we learn it, and we assist with the Customer's own notification duties. Report a suspected breach to security@starkie.ai.

Retention and deletion

Uploaded selfies are deleted a set number of days after a member's photos are ready — the Customer chooses between 7 and 90 days, 30 by default. The trained model goes at the same time unless the Customer has opted in to keeping it for retakes. Generated headshots stay available until deleted.

A member can delete everything themselves from their privacy page: the purge removes uploads, generated images, the trained model and any download archive holding their photos, is written to our audit log, and is confirmed by email with a deletion certificate. An administrator can remove a member with the same effect; a Customer can ask us to delete a whole organisation at privacy@starkie.ai or via /privacy/request.

Annex A — description of the processing

Nature and purpose: training a private image model per member, generating headshots from it, delivering and packaging them, and sending the related notices. Data subjects, data categories and duration: as set out above. Frequency: continuous for the term of the agreement.

Annex B — sub-processors

The current sub-processors, each with its purpose, processing region and own data processing terms, are published at /legal/subprocessors and incorporated here by reference.

Annex C — technical and organisational measures

Encryption in transit (TLS) and at rest; per-organisation and per-member storage isolation, with no public delivery of personal images; short-lived presigned reads; unguessable member links; role-based administrator access; least-privilege credentials; an audit log of privacy-relevant actions; managed backups; vulnerability management. Full description: our security page.