Privacy Policy — Starkie Teams

Version 2 · Last updated 2026-09-05

This addendum explains how personal data is handled in Starkie Teams, the company headshots product. It sits on top of our privacy policy, which continues to apply; where the two differ for Teams, this document wins. It is written for two audiences: the employees and contractors invited to a shoot ("members"), and the administrators who run an organisation.

Who is responsible

The organisation that invited you decides that headshots are made and what happens to them, so it is the controller of your data; Starkie AI, [legal entity name, registered address, VAT number], operating from Italy, is its processor and handles your data on its instructions. For administrators' own account data we are the controller. The processor terms are published at /legal/dpa.

What we collect

From a member: the name, work email address and optional job title your organisation entered when inviting you; the three to eight selfies you upload; the images generated from them; a branded profile picture if your organisation uses one; and your consent record — which version of the consent text you accepted, when, a hashed IP address and your browser's user agent. From an administrator: account and sign-in details, the organisation's settings, and billing information.

Why we process it

To train a private image model of your face, generate your headshots, deliver them to you and to your organisation's administrators, package downloads, and send the emails that go with all of that: your invitation, reminders, the notice that your photos are ready, and deletion confirmations. We also keep an audit log of privacy-relevant actions and monitor errors so the service works.

Your images are never used to train models for anyone else, and they are never sold or used for advertising. You give explicit consent before you can upload anything, and you can withdraw it by deleting your data.

Who can see your photos

You can, through the private link in your emails. Your organisation's owners and admins can see the headshots generated for their members, and where the organisation has turned approval on, an administrator reviews a member's photos before they are delivered. Nobody else has access: photos are stored privately and served only through links that expire, so there is no public URL for them. Inside Starkie, access is limited to what is needed to run and support the service.

Where it goes

Starkie Teams is not an EU-only service. Model training and image generation happen at Astria in the United States, images are stored in Amazon S3 in us-west-1, and email is sent through Resend in the United States. These transfers are covered by the European Commission's Standard Contractual Clauses. The full list is at /legal/subprocessors.

How long we keep it

Your uploaded selfies are deleted a set number of days after your photos are ready — your organisation chooses between 7 and 90 days, 30 by default — and the model trained from them goes at the same time, unless your organisation has opted in to keeping it so you can retake without uploading again. The generated headshots stay available to you and your organisation until deleted.

Your rights

You have the rights of access, rectification, erasure, restriction, portability and objection. In practice:

  • Download your photos at any time from your gallery.
  • Delete everything — uploads, generated images, the trained model, any archive containing your photos — from the privacy page linked from your gallery. We confirm by email with a certificate of what was deleted and when.
  • Ask your organisation's administrator to remove you, which has the same effect.
  • Submit a request at /privacy/request or write to privacy@starkie.ai. If it concerns member data we pass it to your organisation and help them answer.

We keep a record of a data-subject request — its type, dates and outcome — for 24 months after it closes, to show we handled it; its personal content is redacted once the member it concerns is deleted.

You can complain to the supervisory authority where you live or work; in Italy, that is the Garante per la protezione dei dati personali.