Overview
Stark Assistant is built on Google Cloud Platform with enterprise-grade security controls. Stark Industries FZ-LLC is the data controller for customer contact data and the data processor for end-user content uploaded to the service.
Data We Process
- Account Data – administrative contact details, billing contacts, MFA secrets.
- Operational Data – conversational content, knowledge base files, AI prompts, audit logs.
- Telemetry – device metadata, performance analytics, error traces. IP addresses are truncated and anonymised for analytics within 30 days.
Lawful Basis & Usage
- Contractual necessity to provide and support Stark Assistant.
- Legitimate interest in improving service reliability, preventing abuse, and informing security response.
- Consent for optional communications such as Stark Insights newsletters (with opt-out at any time).
Retention
Customer data is retained for the subscription term. Backups replicate across GCP regions with 30-day retention; Customer Data is purged within 30 days of termination unless required by law.
Subprocessors
Core infrastructure, storage, and email delivery leverage Google Cloud, Twilio SendGrid, and Atlassian Opsgenie. The current list is available in the Trust Portal. Stark contractually binds subprocessors to security and confidentiality obligations equivalent to our own.
Security & Compliance
- SOC 2 Type II, ISO 27001, ISO 27701, and ISO 27018 alignment.
- Data encrypted with Google-managed AES-256 at rest and TLS 1.2+ in transit.
- Optional customer-managed encryption keys and dedicated VPC deployment on request.
Data Subject Rights
Data subjects may submit access, correction, deletion, or export requests to privacy@starkassistant.com. Stark responds within 30 days and cooperates with controllers to fulfil regional obligations (GDPR, CCPA, LGPD, PDPL).
Cross-Border Transfers
Stark uses EU Standard Contractual Clauses (2021 SCCs) and ensures equivalent safeguards for transfers to the United States and United Arab Emirates. Regional data residency options are available for Enterprise plans.
Contact
Privacy questions: privacy@starkassistant.com
Data Protection Officer: Stark Industries FZ-LLC, Dubai, UAE.