Skip to content
StarPresence
Sign In

Data Processing Agreement

Last updated: September 2026

This Data Processing Agreement (“DPA”) is concluded between the customer who accepts the Terms of Service of the StarPresence platform (operated under the names StarPresence and StarReview) (the “Customer”, “you”) and StarPresence LLC, a limited liability company organised under the laws of the State of Wyoming, United States of America, with its registered address at 30 N Gould St Ste N, Sheridan, WY 82801, USA (“StarPresence”). It forms part of the Terms of Service and governs the processing of personal data that StarPresence carries out on the Customer's behalf under Article 28 of the EU General Data Protection Regulation (“GDPR”) and the Swiss Federal Act on Data Protection (“FADP”). It applies from the moment the Customer connects an account of a third-party platform and StarPresence processes data that contains personal data of the Customer's own customers or of other third parties.

1. Roles

For the Customer Data defined in section 4, the Customer is the data controller and StarPresence is the data processor. StarPresence processes Customer Data only on the Customer's documented instructions and never for its own purposes.

For the data of the Customer's own account (registration and contact details, billing and payment records, usage data and support correspondence), Marlin Group LLC is the data controller, as described in the Privacy Policy. That data is not subject to this DPA.

2. Subject matter, nature and purpose of the processing

The subject matter of the processing is the import of reviews, comments and mentions from the accounts the Customer connects, the drafting of replies and posts with the AI processors named in section 9, the publication of that content on the Customer's instruction, and the statistics StarPresence shows the Customer about that content. The purpose is to provide the Platform to the Customer as described in the Terms of Service.

The following are excepted from the processing on instruction: (a) aggregated or anonymised statistics with no personal reference, and (b) security, abuse-prevention and logging data necessary to operate the Platform.

3. Duration

Processing takes place for the duration of the Terms of Service and ends when the Customer disconnects the account concerned, cancels the subscription or deletes the account, subject to the deletion-and-return provisions of section 12.

4. Categories of data subjects and of data

The data subjects are the authors of reviews, comments and mentions on the accounts the Customer connects (the Customer's own customers and other members of the public) and, for the Customer's own replies, posts and profile facts, the Customer and the persons acting for it.

The data processed (“Customer Data”) is: the author's public display name or handle and profile picture, the text of the review, comment or mention, the rating, the date and the platform identifiers of that content; the Customer's own replies, posts and profile facts.

Special categories of personal data are not the subject of this DPA; the Customer refrains from introducing any by way of instruction.

5. The Customer's instructions

The Customer's documented instructions are the Terms of Service, this DPA, the consent the Customer gives when connecting an account, the settings the Customer makes in the Platform (in particular the automatic-publishing settings and the per-rating approval rules), and the Customer's item-by-item approvals. StarPresence processes Customer Data only on these instructions, including with regard to transfers to third countries, unless a legal obligation requires otherwise; in that case StarPresence informs the Customer before processing, unless the law prohibits it.

If an instruction appears to StarPresence to infringe the GDPR, the FADP or other data-protection law, StarPresence informs the Customer without undue delay.

6. Obligations of the Customer

The Customer ensures that a valid legal basis exists for the processing it instructs, that its instructions are lawful, that it is authorised to connect the accounts it connects, and that data subjects are informed to the extent required. The Customer remains responsible for the lawfulness of the processing it instructs and for the content it approves or publishes automatically.

7. Confidentiality

StarPresence binds every person authorised to process Customer Data to confidentiality, to the extent they are not already under an appropriate statutory duty of confidentiality.

8. Security of processing and separation of customers

StarPresence implements appropriate technical and organisational measures under Article 32 GDPR and the FADP, in particular: encryption in transit and at rest; access control on a need-to-know basis; availability, resilience, regular backup and restore capability; logging and monitoring; environment segregation; secure development; and periodic review of the effectiveness of these measures.

StarPresence keeps each customer's Customer Data logically separated from every other customer's data. StarPresence does not pool, merge, share or cross-reference the Customer's Customer Data with the data of any other customer, and does not use it to provide the Platform to another customer.

9. Sub-processors and infrastructure delegation

9.1 Appointment of sub-processors. The Customer grants StarPresence general written authorisation to engage downstream sub-processors to perform hosting, technical development, maintenance and automated data-processing operations on the Customer's behalf.

9.2 Infrastructure mapping. The Customer acknowledges and authorises that the software, its codebase and the cloud environments in which the Platform, its data pipelines and its databases run are held, managed and maintained by StarPresence's corporate parent and downstream sub-processor:

  • Name of entity: Marlin Group LLC
  • Jurisdiction: Sharjah Media City (SHAMS), Sharjah, UAE
  • Operational function: core technology infrastructure provider and database management

Through that infrastructure the Platform relies on the following further sub-processors: hosting providers that operate the Platform and store Customer Data in EU data centres; an email-delivery service that sends notifications to the Customer; and OpenAI and Anthropic (United States) as AI processors that draft replies and posts from Customer Data.

OpenAI and Anthropic do not use our API inputs or outputs to train their models. They keep those inputs and outputs for a limited time to provide the service and to monitor for abuse and misuse. OpenAI retains API inputs and outputs for up to 30 days, unless longer retention is required by law or is reasonably necessary to protect its services or any third party from harm; its enterprise privacy page also states that after 30 days those inputs and outputs are removed unless the law requires retention. Anthropic automatically deletes API inputs and outputs within 30 days of receipt or generation, except where a longer-retention service under the customer's control is used, the parties have agreed otherwise, retention is needed to enforce the Usage Policy (up to 2 years for flagged inputs and outputs, and up to 7 years for trust and safety classification scores), or the law requires it.

The third-party platforms whose accounts the Customer connects (for example Google) act under their own terms as independent controllers and are not sub-processors of StarPresence. Payment processing does not concern Customer Data; the payment processor acts as an independent controller in that respect.

9.3 Contractual compliance. StarPresence has entered into a written intra-group data processing agreement with Marlin Group LLC that imposes data-protection obligations no less stringent than those imposed on StarPresence under this DPA, and binds every other sub-processor to equivalent obligations. StarPresence remains fully responsible to the Customer for the performance of its sub-processors. StarPresence informs the Customer of intended additions or replacements with reasonable notice so that the Customer may object; on a legitimate objection that cannot be resolved, either party may terminate the affected service. On request, StarPresence provides the Customer with a current list of sub-processors stating their name, processing location and transfer basis, and updates it when they change.

9.4 Operational execution and liability. The Customer acknowledges that operational execution, service levels and data management are performed through the downstream infrastructure described in 9.2. Commercial disputes, liability claims and indemnities arising out of a data incident are governed by the Terms of Service and, as between the parties, lie exclusively against and end at StarPresence LLC. Section 15 applies.

10. Requests from data subjects and assistance to the Customer

StarPresence does not respond on the merits to requests that data subjects address directly to it concerning Customer Data: access, rectification, erasure, restriction, objection or portability. It forwards every such request to the Customer without undue delay, does not act on it unless the Customer instructs it to, and assists the Customer, through appropriate technical and organisational measures and to a reasonable extent, in responding within the statutory deadlines. The Customer answers the data subject.

StarPresence likewise assists the Customer, to a reasonable extent, in complying with the obligations under Articles 32 to 36 GDPR and the corresponding provisions of the FADP (security, breach notification, data protection impact assessment and prior consultation), taking into account the nature of the processing and the information available to StarPresence.

11. Personal-data breaches

StarPresence notifies the Customer of a personal-data breach concerning Customer Data without undue delay after becoming aware of it, and provides the information available to it that the Customer needs for its own notification obligations, supplementing it as further information becomes available.

12. Deletion or return

On the end of the processing, StarPresence, at the Customer's choice, deletes the Customer Data or returns it to the Customer, and deletes existing copies within 30 days, unless a statutory retention obligation applies. Deletion or return applies to the Customer Data StarPresence holds. It does not retract, delete or alter content already published to a third-party platform on the Customer's instruction; that content remains on the platform as the Customer's published content.

13. Records and audits

StarPresence makes available to the Customer the information necessary to demonstrate compliance with the obligations under Article 28 GDPR and this DPA, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer and bound to confidentiality. An audit takes place no more than once per year, on 30 days' written notice, during business hours, at the Customer's expense and without unreasonable disruption to StarPresence's operations; where possible, StarPresence first satisfies the request with documentation.

14. International transfers

StarPresence is established in the United States of America. Customer Data is stored in EU data centres. Where Customer Data that is subject to the GDPR or the FADP is transferred to StarPresence or to a sub-processor in a country without an adequacy decision (including the United States and the UAE) the transfer relies, where the recipient holds a certification under the applicable Data Privacy Framework, on that certification, and otherwise on the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 (the “SCCs”), supplemented by a transfer impact assessment and, where necessary, by additional safeguards.

For transfers from the Customer to StarPresence the SCCs apply in Module Two (controller to processor); for onward transfers from StarPresence to its sub-processors, in Module Three (processor to processor). The SCCs are incorporated into this DPA by reference; their Annex I is completed by sections 1, 2, 4 and 9 of this DPA and their Annex II by section 8. For transfers subject to the FADP, the SCCs apply with the adaptations recognised by the Swiss Federal Data Protection and Information Commissioner, and references to the GDPR are read as references to the FADP. Onward transfers are subject to the same guarantees.

15. Liability

The limitation of liability in the Terms of Service applies to this DPA. The liability of the parties towards data subjects under Article 82 GDPR and the corresponding provisions of the FADP remains unaffected.

16. Governing law, precedence and language versions

This DPA is governed by the law and the dispute-resolution clause of the Terms of Service. The mandatory provisions of the GDPR and the FADP, the competence of the data-protection supervisory authorities, the rights of data subjects, and the governing-law and jurisdiction clauses of the SCCs remain reserved and prevail in the event of conflict.

In the event of discrepancies between this DPA and the Terms of Service, this DPA prevails for the processing of Customer Data. This DPA is provided in English, German, French and Italian; in the event of discrepancies between the language versions, the English version prevails.

17. Contact

For questions regarding this DPA, please contact us at:

StarPresence LLC
30 N Gould St Ste N, Sheridan, WY 82801, USA
legal@starpresence.ai