Privacy Policy
Last updated: 11/09/2026
Draft under legal review
1. Data controller
The data controller is [[RAGIONE_SOCIALE]], registered office at Via Renato Serra 6, 20148 Milano, Italia, VAT number [[P_IVA]], entered in the Milan Company Register under REA no. [[REA]].
For any request concerning personal data you can write to privacy@starfinderai.com. No Data Protection Officer (DPO) has been appointed: the appointment is not mandatory for the activity carried out.
This policy covers the starfinderai.com website and the StarFinder platform available after registration (the "Service").
2. Data we process
Account data: first name, last name, email address, password (stored only as a hash), plus job title and phone number if you choose to add them to your profile.
Content you enter into the Service: notes, CRM lead records and activities, the text of the emails you write, search criteria, campaigns and sequences, documents you upload.
Usage and technical data: pages visited inside the platform, features used, IP address, browser and device type, application logs and error logs.
Company data in the database: information about Italian companies collected from public and publicly accessible sources (chamber-of-commerce registers and other public databases, company websites, public professional profiles). It may include data relating to natural persons as owners, shareholders or company contacts, such as name, role and business contact details.
Contact request data: name, company, email address and the text of the message you send through the forms on the site.
Integration data: if you connect a mailbox, we store the access tokens in encrypted form together with the metadata of the emails sent from the platform.
3. Purposes and legal bases
Providing the Service (account creation, search, CRM, sending email, AI features): performance of a contract, Art. 6(1)(b) GDPR.
Support and service communications (email verification, password reset, operational notices): performance of a contract, Art. 6(1)(b) GDPR.
Platform security, abuse prevention, technical logs and backups: legitimate interest, Art. 6(1)(f) GDPR.
Building and maintaining the database of Italian companies from public sources, and making it available to customers for B2B business development: legitimate interest, Art. 6(1)(f) GDPR. Data subjects may object at any time by writing to privacy@starfinderai.com.
Replying to requests sent through the contact forms: pre-contractual measures, Art. 6(1)(b) GDPR.
Tax, accounting and other legal obligations: legal obligation, Art. 6(1)(c) GDPR.
4. Artificial intelligence features
Some features of the Service — the conversational assistant, text generation and review, grant analysis, company assessment — work by sending the necessary data to a third-party large language model provider, currently OpenAI.
When you use these features, the text of your requests and the context data needed to answer are transmitted to the provider: for example the data of the selected company, the text of a grant notice, the notes or the emails you ask it to work on. We do not transmit your password or your integration tokens.
Data sent through the OpenAI API is not used by the provider to train its models. If you would rather certain content were not processed by a language model, do not put it into the AI features.
Text generated by the models may contain errors or statements that do not match reality, and must always be checked before use.
5. Email sent from the platform
The business development emails you send through StarFinder leave from your own mailbox: you connect your Microsoft Outlook account or an SMTP server of your choice, and the messages are delivered by that provider, not by a domain of ours.
Towards the recipients, you are the data controller: you are responsible for the legal basis of the sending, for the privacy notice to recipients and for handling objection and erasure requests.
The service emails we send ourselves (address verification, password reset, notifications) leave from our systems through Resend.
6. Providers that process data on our behalf
We use the following providers, appointed as processors under Art. 28 GDPR:
OpenAI (United States) — language models for the AI features. Transfer outside the EU based on the Standard Contractual Clauses.
Resend (United States) — delivery of service emails. Transfer outside the EU based on the Standard Contractual Clauses.
Vercel (European Union and United States) — hosting of the website and the web application. Transfer outside the EU based on the Standard Contractual Clauses.
Neon (European Union) — managed PostgreSQL database, hosted in a European region.
Google Cloud (European Union, europe-west1 region, Belgium) — running the application services and storing documents.
PostHog (European Union, EU cloud) — aggregate statistics on how the site is used. It runs in cookieless mode: it sets no cookies and no local storage entries, creates no persistent identifier, and the IP address is discarded rather than stored.
MillionVerifier (European Union) — technical validity checks on email addresses, when you use that feature.
Microsoft (European Union and United States) — only if you connect an Outlook mailbox, to send messages and to read the conversations the Service shows you.
The SMTP provider you choose yourself — only if you connect a mailbox over SMTP: in that case the relationship with the provider is yours and is governed by its own terms.
An up-to-date list of providers is available on request by writing to privacy@starfinderai.com.
7. Transfers outside the European Union
Some of the providers listed above are based in the United States. In those cases the transfer relies on the Standard Contractual Clauses adopted by the European Commission, supplemented by the technical measures described in section 9.
You can request a copy of the safeguards in place by writing to privacy@starfinderai.com.
8. Retention
Account data and the content you entered: for as long as the account exists and for 30 days after deletion, unless a different legal obligation applies. You can delete your account yourself from the profile page.
Requests sent through the contact forms: 24 months from the last exchange.
Application, technical and security logs: 12 months.
Tax and accounting records: 10 years, as required by law.
Company data collected from public sources: for as long as it remains relevant to the Service, with periodic updates and re-checks; it is removed at the data subject's request.
9. Security
Passwords are stored only as bcrypt hashes and are never readable in clear text, not even by us.
Sessions use signed tokens; the application's calls to the backend travel over HTTPS and carry a short-lived, cryptographically signed identity token that is verified on every request.
The tokens of connected mailboxes are encrypted at rest in the database.
Database queries use parameterised statements through an ORM.
Password reset and email verification use single-use tokens with an expiry and are subject to rate limits.
No system is absolutely secure. If you suspect unauthorised access to your account, write to us immediately at privacy@starfinderai.com.
10. Your rights
You can exercise the rights under Articles 15-22 GDPR at any time: access to your data, rectification, erasure, restriction of processing, portability, objection to processing based on legitimate interest, and withdrawal of consent where the processing is based on consent.
To exercise them, write to privacy@starfinderai.com. We reply within 30 days of the request.
If you believe the processing breaches the law, you can lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali), Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it — or with the supervisory authority of the country where you live.
11. Cookies
The site uses technical cookies, which require no consent, and — only with your prior consent — statistical and advertising cookies managed through Google Tag Manager. Until you consent, no cookie of that second kind is written. The full list, with purpose and duration, is in the Cookie Policy.
12. Changes to this policy
We may update this policy. The version in force is always published on this page, with the last-updated date at the top. If the changes are material we will tell you by email or inside the platform.
13. Contact
[[RAGIONE_SOCIALE]] — Via Renato Serra 6, 20148 Milano, Italia
VAT [[P_IVA]] — REA [[REA]]
Privacy requests: privacy@starfinderai.com
General enquiries: info@starfinderai.com