Privacy Policy
Who we are
STAROASIA is a registered firm name and the primary identity represented by this website. The information, notices and policies published on this website also apply to STARO INDIA PRIVATE LIMITED where that company markets, contracts, invoices, processes enquiries or delivers services through this website or through a STARO-related domain redirected to it.
STARO INDIA PRIVATE LIMITED · CIN U72900GJ2021PTC123354 · Registered office: B-403, S.G. Business Hub, S.G. Highway, Ahmedabad, Gujarat 382470, India.
STARO is the collective abbreviation used on this website to present the organisation as a whole. It is not presented as a separate contracting entity. The entity named in a proposal, Statement of Work, invoice or other engagement document is the contracting entity for that engagement. For website enquiries and visitor data, STAROASIA and STARO INDIA PRIVATE LIMITED may each act as a controller or data fiduciary to the extent that it determines the purposes and means of the relevant processing. References to “STARO”, “we”, “us” or “our” in this policy include both where applicable.
Privacy and grievance contact: info@staro.in. This role-based contact is responsible for privacy requests and complaints concerning this website.
Scope
This policy covers personal data we process when you:
- Visit staro.in or a STARO-related domain that redirects to this website
- Submit our contact form or email us directly
- Apply to the STARO partner programme or submit a referral opportunity
- Book a call through our scheduling tools
- Engage us for a paid service (consultation, project, or retainer)
- Interact with us on third-party platforms (e.g. WhatsApp, LinkedIn) where the conversation relates to STAROASIA
When we process personal data solely on a client's documented instructions while delivering services, the client generally acts as controller/data fiduciary and we act as processor/data processor. That processing is governed by the engagement agreement and any applicable Data Processing Addendum (DPA).
Data we collect
You give us directly
- Identity & contact — name, email address, phone number, company name, role, and organisation-size range where provided.
- Enquiry content — the message you write, service category, indicative budget, preferred timeline, target market, source page and privacy acknowledgement.
- Partner and referral information — application role, country or region, proposed partnership path, network description, opportunity context, attribution records and agreed commercial administration where applicable.
- Engagement records — proposals, contracts, invoices, project communications.
- Client portal, employee response app and support records — authorised-user identity, organisation, authentication and security events, registered device and encrypted push-token data, support requests, project visibility, uploaded incident context, SOS activations, acknowledgement and response history.
We collect automatically
- Server logs — IP address, browser type, referrer URL, pages visited, timestamps. Retained briefly for security and abuse prevention.
- Cookies & analytics — see Section 10. We do not use analytics or marketing cookies without your consent.
- Campaign attribution — URL parameters such as UTM values and an advertising click identifier may be retained with an enquiry to measure its source and prevent duplicate or fraudulent attribution. These parameters are not used to override your analytics choice.
- Anti-bot signals — our contact form uses a honeypot field, a time-of-submission stamp, and Google reCAPTCHA to detect automated submissions.
Please do not submit passwords, payment-card details, government identifiers, health information or other highly sensitive personal data through a general enquiry form.
From third parties
- Information you make public on professional networks (e.g. LinkedIn) and choose to share with us.
- Referrals — if a client, applicant or accepted partner introduces you, we may receive your name, professional contact details and relevant opportunity context from them. Referrers are required to make lawful, transparent introductions and must not submit your information without an appropriate basis.
Why we process it
- To respond to your inquiry and follow up on the project you described.
- To provide our services if we enter an engagement together.
- To send transactional emails — proposals, invoices, project updates, acknowledgements.
- To operate, secure, and improve our website (rate-limiting, abuse detection, error monitoring).
- To comply with legal obligations — accounting, tax, anti-fraud, regulatory record-keeping.
- To defend legal claims if necessary.
- To measure enquiry sources and understand campaign performance when attribution parameters accompany a form submission.
- To assess partner applications and referrals, prevent duplicate or fraudulent attribution, administer accepted arrangements and maintain appropriate commercial records.
- To operate the client portal and emergency response workflow, authenticate authorised client users, route support requests, alert relevant STARO stakeholders and retain an accountable incident history.
We do not sell personal data, share it with data brokers, or make decisions about you based solely on automated processing. We do not use general enquiry data for unrelated marketing without a separate lawful basis and any consent required by law.
Legal bases (GDPR)
Where GDPR or UK-GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Responding to your inquiry; pre-contract steps | Performance of a contract / steps prior to entering a contract (Art. 6(1)(b)) |
| Delivering services under a signed engagement | Performance of a contract (Art. 6(1)(b)) |
| Sending transactional emails about your account or project | Performance of a contract (Art. 6(1)(b)) |
| Analytics cookies, marketing pixels | Consent (Art. 6(1)(a)) — granted via the cookie banner |
| Security logs, rate-limiting, anti-fraud | Legitimate interests (Art. 6(1)(f)) — protecting our systems and users |
| Campaign parameters retained with an enquiry | Legitimate interests (Art. 6(1)(f)) — measuring enquiry source, subject to your rights and applicable ePrivacy rules |
| Assessing partner applications, referrals and attribution | Steps requested before an agreement (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) — operating a transparent partner programme and preventing disputes or fraud |
| Accounting, tax, regulatory record-keeping | Legal obligation (Art. 6(1)(c)) |
Where India's Digital Personal Data Protection framework applies, we provide a clear notice of the personal data requested and the purpose for which it is used. Enquiry data is processed to take the steps you request, with the acknowledgement presented beside the form. You may withdraw consent where processing relies on consent, exercise applicable rights, nominate another individual where the law permits, or raise a grievance using the contact details below.
How long we keep it
- Inquiry data (form submissions that don't become engagements) — up to 24 months, then deleted.
- Unsuccessful partner applications and unaccepted referrals — generally up to 24 months so we can respond, manage duplicate attribution and address disputes, unless a shorter period is required or deletion is requested and no overriding basis applies.
- Accepted partner records — for the relationship and generally up to 8 years thereafter where needed for contracts, accounting, tax, fraud prevention or legal claims.
- Engagement records (contracts, invoices, project communications) — for the engagement and generally up to 8 years thereafter, or longer where a legal hold or applicable law requires.
- Server and security logs — typically up to 90 days; selected processing/security logs may be retained for up to 1 year where required for security investigation or applicable Indian rules.
- Rate-limit records — up to 1 hour (sliding window), stored as hashed identifiers.
- Consent preference — up to 180 days, after which we ask again.
- Analytics identifiers — only after consent and according to the configured analytics retention period, normally no longer than 14 months for event data.
Third-party processors
We use service providers only for defined operational purposes. Processor terms, confidentiality obligations and data-protection safeguards are applied where required and available for the service.
| Processor | Purpose | Location of processing |
|---|---|---|
| Resend | Transactional email (inquiry notifications, acknowledgements) | USA / EU |
| Google reCAPTCHA | Anti-bot protection, loaded after you interact with an enquiry form | Global, including USA / EU |
| Google Analytics 4 / Google Tag Manager | Optional website analytics and tag delivery — blocked unless you grant analytics consent | Global, including USA / EU |
| Calendly | Call scheduling — connected only after you choose “Load scheduler” | USA / global |
| WhatsApp / Meta | Communication only when you choose to open WhatsApp; form data is not transferred automatically | Global |
| Google Fonts and content-delivery networks | Delivery of fonts and front-end libraries needed to render the website | Global edge networks |
| Hosting provider | Serving the website | India / global edge |
International transfers
Some providers process data outside India, the EEA or the UK. Where European transfer rules apply, we rely on an adequacy decision or appropriate contractual safeguards, such as the European Commission's Standard Contractual Clauses and any required UK addendum, together with supplementary measures where appropriate. Indian transfers will be restricted where required by a notification or other applicable law.
If you'd like a copy of the safeguards in place for a specific processor, email info@staro.in.
Your rights
If you are in the EU, the UK, or India (or if GDPR / DPDP otherwise applies to you), you have the following rights, subject to limitations under the applicable law:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your personal data ("right to be forgotten"), subject to record-retention obligations.
- Restriction — ask us to limit how we process your data.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — for any processing that relies on your consent, at any time.
- Complain — lodge a complaint with your local supervisory authority (in the EU/UK) or with the Data Protection Board of India.
- Nomination — where the Indian DPDP framework applies, nominate another individual to exercise applicable rights in the event of death or incapacity.
To exercise a right, email info@staro.in with the subject “Privacy request” and identify the email address or telephone number used with us. Please do not send identity documents unless we specifically request a proportionate verification method. We aim to acknowledge requests promptly and respond within one month where GDPR applies, or within the period required by other applicable law. Privacy grievances will be addressed within a reasonable period and no later than 90 days where the Indian DPDP grievance framework applies.
Cookies & analytics
Necessary operational processing is active by default. This includes security controls, abuse prevention, server logging, form operation and storage of your privacy preference. Google Analytics and Google Tag Manager are not treated as essential and remain blocked until you give analytics consent. For EU and UK visitors, analytics is always presented as an optional, non-essential choice.
- Privacy preference — local storage entry
staroasia_consent_v2, retained for up to 180 days, records whether you accepted or rejected optional analytics. - Theme preference — the website follows your device's light or dark colour setting by default. If you choose an override, local storage entry
staro_themerememberslightordarkuntil you return to the system setting or clear browser storage. This is functional storage and is not used for analytics or advertising. - Analytics — if configured, Google Analytics 4 / Google Tag Manager helps measure site use, technical events and campaign attribution. It loads only after “Accept all”. Advertising storage and personalisation remain disabled.
- Security — Google reCAPTCHA may set or read security identifiers after you interact with a form. It is used to prevent automated abuse, not for our advertising.
- Scheduling — Calendly is not connected until you actively choose to load the scheduler. Calendly then applies its own privacy and cookie choices.
Any Tag Manager container used on this website must be configured so optional analytics tags respect the recorded choice and do not bypass consent. Advertising, ad-user-data and ad-personalisation storage remain disabled unless this policy and the consent interface are separately updated to describe a lawful new purpose.
to accept, reject or withdraw optional analytics at any time. Rejecting analytics does not affect access to the website. Withdrawing consent does not affect processing that took place lawfully before withdrawal.
Security
We protect personal data with reasonable and appropriate measures, including: HTTPS everywhere, encrypted secret storage, principle-of-least-privilege access controls, regular dependency patching, anti-bot protections, and IP-based rate limiting. If a personal data breach occurs that poses a risk to your rights, we will notify the relevant authority and affected individuals as required by law.
Children
Our website and services are intended for businesses and adult professionals. General enquiry forms are not intended for anyone under 18. We do not knowingly process children's personal data through this website; if you believe a child has submitted information, contact us so we can take appropriate action.
Changes
We may update this policy from time to time. The "Effective" date at the top of this page will be updated whenever we do. If the changes are material, we will give reasonable prominence to them on our site (and notify clients directly where required).
Contact
For privacy questions, requests, or complaints:
- Email — info@staro.in
- Phone / WhatsApp — +91 78350 01221
- Website identity — STAROASIA
- Applicable company — STARO INDIA PRIVATE LIMITED, CIN U72900GJ2021PTC123354
- Registered office — B-403, S.G. Business Hub, S.G. Highway, Ahmedabad, Gujarat 382470, India