This notice explains how STARS S.R.L. processes the personal data of visitors to this website, pursuant to Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended.
1. Data Controller
The Data Controller is STARS S.R.L., Via Vinciguerra 75, 00128 Roma (RM), Italy, VAT / Tax ID 18548941006.
Email: info@stars.srl · Certified email (PEC): stars@namirialpec.it
The company has not appointed a Data Protection Officer (DPO), as it is not required to do so under Article 37 GDPR. Any request concerning personal data may be sent to the addresses above.
2. What data we collect
2.1 Data you provide via the contact form
When you submit the contact form we collect: full name, company name, work email address, and the content of your message. All fields are required in order to reply to you.
2.2 Self-diagnosis (Chaos Index)
The answers you enter in the self-diagnosis questionnaire are not stored: the score is computed on the spot and shown only to you. If, from the result page, you choose to send the contact form, then alongside the data in 2.1 we also receive a summary of your result (overall score, band and most critical area), so that we can reply with some context. If you use the form on the home page, this data does not exist.
2.3 Data collected automatically
Together with the form submission we record the IP address, the browser user agent, the interface language, and the timestamp of the request. These are collected for security purposes (abuse prevention and rate limiting) and to demonstrate the lawfulness of processing.
The web server also produces standard technical logs of connections. These logs are not used to profile users and are not cross-referenced with other data.
3. Purposes and legal basis
| Purpose | Legal basis | Retention |
|---|---|---|
| Replying to your enquiry and any preliminary steps prior to entering a contract | Art. 6(1)(b) GDPR: pre-contractual measures at the data subject’s request | 24 months from the last contact |
| Website security, abuse prevention, rate limiting | Art. 6(1)(f) GDPR: legitimate interest in protecting the service | 12 months |
| Storing your language preference | Art. 6(1)(f) GDPR: legitimate interest in providing a working interface | 12 months (cookie) |
| Fulfilling legal and accounting obligations, where a relationship begins | Art. 6(1)(c) GDPR: legal obligation | 10 years, as required by law |
We do not use your data for marketing, newsletters, profiling, or automated decision-making, and we do not sell or otherwise transfer it for commercial purposes.
4. Who can access the data
Data is accessible to authorised staff of STARS SRL who have been instructed on processing. It may also be processed by suppliers acting as data processors under Article 28 GDPR (the hosting provider and the email service provider), bound by contract to process data solely on our instructions.
Data is not disclosed to third parties or disseminated, except where disclosure is required by law or by a competent authority.
5. Where the data is processed
Data is processed on servers located within the European Economic Area. Should a transfer outside the EEA ever become necessary, it will only take place subject to the safeguards of Chapter V GDPR (adequacy decision or Standard Contractual Clauses), and this notice will be updated accordingly.
6. Your rights
Under Articles 15–22 GDPR you have the right to:
- obtain access to your personal data and a copy of it;
- obtain rectification of inaccurate or incomplete data;
- obtain erasure of your data (“right to be forgotten”), where the conditions are met;
- obtain restriction of processing;
- receive your data in a structured, machine-readable format (portability);
- object at any time to processing based on legitimate interest;
- lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).
To exercise any of these rights, write to info@stars.srl. We reply within one month of receiving the request, as provided by Article 12 GDPR.
7. Security measures
We apply technical and organisational measures appropriate to the risk: encrypted transport (HTTPS), access restricted to authorised personnel, anti-abuse controls on the contact form, and separation of personal data from the application source code.
8. Cookies
This website only uses a technical cookie to remember your language choice. Full details are in the Cookie Policy.
9. Changes to this notice
We may update this notice to reflect changes to the website or to applicable law. The current version is always the one published on this page, with the last-updated date shown at the top.
← Back to home