GDPR

Version 1 · Last updated 2026-09-05

This page is written for the person at a company who has to answer "is this GDPR-compliant?" before rolling out Starkie Teams. It is a summary in plain language; the binding terms are in the Data Processing Addendum, the Teams privacy addendum and the Teams terms.

Who is responsible for what

Your organisation decides that its people will have headshots made, who is invited and what happens to the results, so your organisation is the controller for your members' data. Starkie AI — operated from Italy, [legal entity name, registered address, VAT number] — is the processor, acting on your instructions. For your administrators' own account data (name, email address, sign-in records, billing) we are the controller.

Lawful basis

For members, the basis for processing their facial images is their explicit consent, which we collect before they can upload anything. The consent text is versioned and we store which version each person accepted, with a timestamp. A member who does not consent simply never uploads, and nothing is generated for them. Because a face model is data about an identified person, we treat it with Article 9 care whether or not it is formally classified as biometric data in your jurisdiction.

For administrators, the basis is the contract between your organisation and us, plus our legitimate interest in keeping the service secure and running.

What we process

Names, work email addresses, optional job titles, the three to eight selfies a member uploads, the roughly forty images generated from them, any branded profile picture, the consent record, and technical logs. We do not use member images to train models for anyone else, and we do not sell them or use them for advertising.

Where it is processed

Starkie Teams is not an EU-only service. Model training and image generation run at Astria in the United States, images are stored in Amazon S3 in us-west-1, and transactional email is sent through Resend in the United States. Hosting and error monitoring are provided by Vercel and Sentry. Transfers out of the EEA are covered by the European Commission's Standard Contractual Clauses with each provider; the full list with regions is at /legal/subprocessors.

How long data is kept

Uploaded selfies are deleted a set number of days after a member's photos are ready — you choose between 7 and 90 days, and the default is 30. The private model trained from them is deleted at the same time unless you opt in to keeping it for retakes. Generated headshots remain available to your organisation and to the member until one of you deletes them, or until the organisation is closed.

Rights, and how people exercise them

Members and administrators have the rights to access, rectification, erasure, restriction of processing, data portability and objection. There are three routes:

  • A member can download their own photos and delete all of their data themselves, from the privacy page linked from their gallery. Deletion is confirmed by email with a certificate of what was deleted and when.
  • An administrator can remove a member from the organisation, which triggers the same purge.
  • Anyone can submit a request at /privacy/request or by writing to privacy@starkie.ai. Requests that reach us about member data are passed to the controlling organisation, and we help them answer within the statutory deadline.

Supervisory authority

A data subject can complain to the supervisory authority in their country of residence or workplace. For Starkie AI, and for controllers established in Italy, that authority is the Garante per la protezione dei dati personali.

Documents and contact

The processor terms are at /legal/dpa, the current sub-processors at /legal/subprocessors, and our technical measures at /security. For anything else, or to sign the addendum as a countersigned document, write to privacy@starkie.ai.