Privacy Policy
Who controls your data
1.1This privacy policy is issued by STARECOM ("we", "us"), the operator of starecom.net and the provider of the services described on it.
1.2For the personal data described in this policy, the operator is the data controller. The operator's identity, registered address and contact details are set out in the block at the top of this page and in the footer of every page on this site.
1.3Where we process personal data on behalf of a client — for example inside a system we build or host for them — that client is the controller and we act as a processor under a separate written data processing agreement. This policy does not govern that processing.
1.4Data protection enquiries go to .
What we collect
2.1Enquiries. When you submit the contact form we collect your name, email address, company name (if given), the type of work and budget range you select, your message, and the time of submission. We also record the browser user-agent string sent with the request.
2.2Correspondence. If you email us, we hold that correspondence and anything you choose to put in it.
2.3Client records. If you become a client we hold the contract, scope documents, invoices, and the business contact details of the people we work with.
2.4Server logs. Our web server records the request URL, timestamp, HTTP status, bytes served, referrer, user-agent and the IP address the request came from. This is standard web-server logging and is used for security and diagnostics.
2.5Consent records. When you make a cookie choice we store a record containing a random identifier, a timestamp and the decision itself. No IP address and no personal identifier is stored in that record.
2.6Traffic measurement. Baseline measurement of site traffic is aggregate, anonymous and cookieless, and cannot be linked back to you. See the Cookie Policy.
2.7We do not collect special category data, and we ask you not to send it. We do not collect payment card details on this website at all — see clause 8.
Why we process it, and on what lawful basis
| Data | Purpose | Lawful basis |
|---|---|---|
| Contact form submission | To answer your enquiry and, if relevant, prepare a scope document and quote | Steps at your request prior to entering a contract (Art. 6(1)(b) GDPR) |
| Correspondence | To manage the relationship and keep a record of what was agreed | Legitimate interests (Art. 6(1)(f)) — running a business and keeping accurate records |
| Client and contract records | To perform the contract and to meet accounting and tax obligations | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Server logs | Security, abuse prevention, fault diagnosis | Legitimate interests (Art. 6(1)(f)) — keeping the service secure and available |
| Consent record | To evidence that a cookie choice was made and honoured | Legal obligation (Art. 6(1)(c)) |
| Analytics storage, if introduced | Measuring how the site is used | Consent (Art. 6(1)(a)) — never set before you accept |
3.1Where we rely on legitimate interests we have considered your rights and concluded that the processing is limited, expected, and does not override them. You may object at any time — see clause 6.
3.2We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
3.3We do not sell personal data, and we do not share it for anyone else's marketing.
How long we keep it
4.1Enquiries that do not become clients: 24 months from the last contact, then deleted.
4.2Server logs: 90 days, then rotated and deleted.
4.3Consent records: 12 months from the decision, matching how long the choice itself is valid.
4.4Client and contract records: for the life of the engagement and then for as long as accounting, tax and limitation law requires — typically six to ten years depending on jurisdiction.
4.5Due diligence records collected under the AML / CTF Policy: 5 years after the relationship ends, as that policy requires.
4.6When a retention period ends the data is deleted, or irreversibly anonymised where we need to keep an aggregate count.
Who else sees it
5.1We keep the number of recipients small and name them by category:
- Hosting and infrastructure — the provider of the server this site runs on, which necessarily processes traffic to it.
- Transactional email delivery — the provider that delivers enquiry notifications to our inbox.
- Professional advisers — accountants and lawyers, where they need the information to advise us.
- Authorities — where we are required by law to disclose, including under the AML / CTF Policy.
5.2Each processor acts only on our written instructions under a data processing agreement, and may not use your data for its own purposes. The identity of the current providers is available on request.
5.3If our business is transferred, personal data may transfer with it. You would be told before that happened and this policy would continue to apply.
Transfers outside the EEA
6.1We prefer processors inside the EEA. Where a processor is outside it, the transfer is made under an adequacy decision of the European Commission or under the European Commission's Standard Contractual Clauses, together with supplementary technical measures where they are needed.
6.2You can ask us which safeguard applies to a particular transfer, and we will tell you.
Your rights
7.1Under the GDPR you have the right to: be informed; obtain a copy of your data (access); have inaccurate data corrected; have data erased where the conditions are met; restrict processing; receive your data in a portable format; object to processing based on legitimate interests; and withdraw consent at any time where consent is the basis.
7.2Withdrawing consent does not affect processing carried out before you withdrew it.
7.3To exercise any right, write to with enough detail to identify the data. We do not charge for this. We may ask for proof of identity where we cannot otherwise be confident who is asking.
7.4We respond within 30 days. If a request is complex we may extend by up to two further months, and will tell you within the first month if we do.
7.5If you are unhappy with how we have handled your data, please tell us first through the Complaints procedure. You also have the right to complain to the Commission for Personal Data Protection (CPDP) of the Republic of Bulgaria, and you may do so without contacting us first.
Payments and card data
8.1This website does not take payments and does not collect, transmit or store card numbers. There is no checkout on this site.
8.2Where a client pays us by card, the card details are entered directly with a regulated payment service provider and are handled by them. We receive a confirmation and a masked reference only. Full detail is in the Payment & Billing Disclosures.
Security
9.1The site is served over TLS. Enquiry data is stored on the server with filesystem permissions restricting it to the web service account, and the directories holding it are not reachable over HTTP.
9.2Access to systems is limited to the people who need it, secrets are held in the server environment rather than in code, and dependencies and server configuration are reviewed as part of our standard practice.
9.3The contact form is protected against automated abuse by a rate limit, a timing check and a hidden field, and against cross-site request forgery by a per-session token.
9.4No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours of becoming aware of it, and will tell you directly where the law requires.
Children's data
10.1Our services are sold to businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18 through this website.
10.2If you believe a child has given us personal data, tell us at and we will delete it.
Changes to this policy
11.1The current version, its number and its last-updated date are always shown at the top of this page. Superseded versions are available on request.
11.2Where a change materially affects how we use data we already hold, we will take reasonable steps to tell affected people directly before it takes effect.
Questions about this document go to . We aim to reply within one business day, and in any case within 2 business days. Post is accepted at the registered office shown above where one is listed.
This document is version 1.0, last updated 2026-09-07. Superseded versions are available on request.