• Products
    STARBRIX CORE
    Product OverviewPricingSecurity
    STARBRIX FLEX
    Product OverviewPricingSecurity
  • Contact Us
    About UsContact SalesContact Support
  • Log in
  • Start free

Starbrix legal documents

Terms of Service
Terms of Additional Services
Developer Terms
Acceptable Use Policy
Privacy Policy
Data Processing Addendum
Sub-processors
Open Source List

Updated: 01.09.2026

Terms of Service

These Terms of Service ("Terms"), together with referenced terms and policies, constitute a legally binding agreement ("Agreement") as of the Effective Date (as defined below), governing your access and use of Starbrix.app and any related websites owned or operated by StarBrix International Ltd ("Sites"), Starbrix Services, and Starbrix Additional Services, as may be amended from time to time.

These Terms are entered into between StarBrix International Ltd ("Starbrix", "Starbrix.app", "us", "we", or "our") and you, whether acting individually or representing your employer or another entity ("you" or "your"). If you represent your employer or another entity, you affirm that you possess the full legal authority to agree to these Terms on behalf of your employer or entity, and by accepting these Terms, you bind your employer or entity accordingly.

As delineated below, various user types exist within the services. Consequently, unless expressly stated otherwise, "you" shall encompass the customer and all categories of users. By clicking a button or checking a checkbox to accept these Terms, or by registering for, using, or accessing the services, additional services, or sites, whichever occurs first, you acknowledge the binding nature of these Terms. This act signifies your consent to these Terms, with the date of registration or acceptance constituting the "effective date."

Please be advised that if you register for the service using your company's or organization’s email address, or if you are an Organization Account owner (as defined below), you shall be deemed a representative of your company or organization.

If you do not agree to these Terms or lack the authority to bind your employer or any other relevant entity, kindly refrain from accepting these Terms or accessing/using the services or sites.

1. Our Services

1.1 Services Description: Our cloud-based Services provided on starbrix.app encompass platforms, products, applications, APIs, tools, and any related products and services accessible online or via a mobile app ("Services").

1.2 Modification of Services: We reserve the right to add, modify, or discontinue features within our Services or Sites without prior notice. However, significant changes affecting core functionality will be communicated through announcements on the Sites or via email.

1.3 Non-Contingent Utilization: Your decision to utilize Services or Third Party Services is not contingent upon future releases, including the sustained availability of certain services beyond the current scope or our public remarks concerning forthcoming features.

1.4 Support and Uptime: We uphold a commitment to providing high-quality support and ensuring uptime for all customers, thereby ensuring equal and valuable assistance to everyone.

1.5 Additional Services: You have the option to purchase or receive Additional Services as delineated in the Terms Of Additional Services ("Additional Services"), subject to updates.

2. Registration

2.1 Establishment of User Accounts:

Upon registration for the Services, individuals establish a personal user account ("User Account") for their individual use. By creating an organization ("Organization Account") within Starbrix.app, individual users ("User") can extend invitations to other individuals to join the Organization Account and engage in collaborative endeavors. The individual initiating the creation of an Organization Account is herein referred to as the "Organization owner" and acts as the representative of their respective company or organization. The ownership can be transferred to another User at any time, subject to the conditions outlined in the Terms of Service.

2.2 Obligation of Accuracy and Security:

You agree to furnish accurate registration particulars and maintain the security of your password. You bear responsibility for all activities conducted under your User Account or Organization Account and are obligated to promptly notify us of any unauthorized access.

2.3 Identity Verification Measures:

We reserve the right to request identity verification to fortify the security of your User Account. In the event of access loss, we may necessitate verification prior to reinstating access privileges.

2.4 Authority of Organization Owners:

Organization owners serve as representatives of the Customer and possess pivotal controls over the Organization Account, encompassing user management, service acquisitions, and data accessibility.

2.5 Responsibilities of the Organization Owner:

The Organization Owner assumes responsibility for the administration of user settings and permissions within the Organization Account. The Organization Owner bears liability for all user activities and actions undertaken within the purview of the Organization Account.

2.6 Diverse Privileges of Organization Account Users:

Various categories of Organization Account users exist, each endowed with distinct privileges commensurate with their allocated permissions.

3. Your Customer Data

3.1 Customer Data Ownership and Usage:

"Customer Data" encompasses any content, including text, images, and personal data, uploaded to the Services by you or any User within an Organization Account. The Customer retains control over this data. We are granted limited rights to access and utilize this data solely for the purpose of providing the Services, addressing issues, investigating complaints, complying with legal processes, or as explicitly permitted by you in writing.

3.2 Compliance and Responsibility for Customer Data:

You affirm that you possess the requisite rights and permissions for the Customer Data you submit. It must adhere to our Acceptable Use Policy  and refrain from infringing upon third-party rights or contravening any laws or policies. You bear sole responsibility for your Customer Data, and we assume no liability for its content.

3.3 Prohibited Data Submission:

You are prohibited from submitting any data to the Services that is protected under special legislation and necessitates unique treatment.

4. Intellectual Property Rights

4.1 Ownership and Rights to Starbrix Materials:

The Services and Sites, inclusive of materials such as software, APIs, app frameworks, designs, design systems, textual content, editorial materials, informational text, documentation, photographs, illustrations, audio clips, video clips, artwork, and other graphical materials, as well as names, logos, trademarks, and service marks (excluding Customer Data), along with any related or underlying know-how, technology, or intellectual property, and any modifications, enhancements, or derivative works thereof (collectively referred to as "Starbrix Materials"), are the exclusive property of Starbrix and its licensors. These materials may be safeguarded by applicable copyright or other intellectual property laws and treaties. In the relationship between you and Starbrix, Starbrix maintains all rights, titles, and interests, including all intellectual property rights, in and to the Starbrix Materials.

4.2 Use of Customer's Name and Logo:

We reserve the right to employ your name and logo for the purpose of identifying you as a customer of Starbrix.app or user of the Services in our marketing materials or announcements, unless you expressly request otherwise.

4.3 Grant of Limited Rights to Access and Utilize Services:

Subject to the terms and conditions outlined in these Terms, and your strict compliance therewith, notably in accordance with our Acceptable Use Policy, we hereby extend to you a limited, worldwide, non-exclusive, non-transferable right to access and utilize the Services and Sites.

4.4 Prohibited Activities:

Except as explicitly permitted in these Terms, you may not, and shall not permit any User or third party to:

  • Transfer, lease, sublicense, disclose, publish, assign, market, resell, display, transmit, broadcast, or distribute any portion of the Services or Sites to any third party, including your affiliates, or utilize the Services in any service bureau arrangement;
  • Utilize the Services or Sites for competitive purposes, including the development or enhancement of a competing service or product;
  • Interfere with security-related features of the Sites or Services, circumvent, disable, or otherwise disrupt features that prevent or restrict use or copying of any content, or enforce limitations on use of the Services or Sites;
  • Interfere with the integrity or proper functioning of the Services or Sites, or any related activities;
  • Engage in reverse engineering, decompiling, disassembling, decrypting, or attempting to derive the source code of the Services or Sites, or any components thereof;
  • Modify, translate, patch, improve, alter, change, or create any derivative works of the Services or Sites, or any part thereof;
  • Undertake any action that may impose an unreasonable or disproportionately large load on the Starbrix.app infrastructure or infrastructure supporting the Sites or Services;
  • Remove, deface, obscure, or alter Starbrix’s or any third party’s identification, attribution, or copyright notices, trademarks, or other proprietary rights affixed to or provided as part of the Services or Sites, or use or display logos of the Services or Sites without Starbrix’s prior written consent;
  • Encourage or assist any third party, including other Users, in engaging in any of the aforementioned activities.

4.5 Feedback Ownership:

Any feedback provided by you regarding the Services becomes our property and may be utilized without restriction. You waive any rights to such feedback.

4.6 Use of API and Developer Terms:

Should we offer an API, you may employ it for internal business purposes to integrate the Services with other systems. Compliance with our Developer Terms  is mandatory. We reserve the right to modify or discontinue the API at any time.

5. Privacy and Security

5.1 Implementation of Security Measures:

We employ reasonable security measures and procedures to safeguard your Customer Data. Please refer to our  Security Page  for comprehensive details.

5.2 Collection and Use of Personal Data:

Through your utilization of the Services, we may collect, access, and utilize certain Personal Data pertaining to you. Consult our  Privacy Policy  for a thorough delineation of data collection and usage practices.

5.3 Agreement to Data Processing Addendum:

Your usage of the Services also entails your agreement to our  Data Processing Addendum, which regulates the processing of Personal Data on your behalf.

5.4 Collection and Use of Anonymous Information:

We may gather and utilize "Anonymous Information" derived from your utilization of the Services. This data, devoid of personal identification, aids in the enhancement of our products and services. All Anonymous Information collected is the exclusive property of Starbrix.

6. Third Party Services

6.1 Integration of Third Party Services:

The Services facilitate your utilization of third-party services, products, applications, and tools ("Third Party Services") in conjunction with our Services. Integrating Third Party Services with your User Account or Organization Account enables data exchange between them. We serve as an intermediary between you and Third Party Services. It is important to note that we do not endorse these services and assume no responsibility for them. Your utilization of Third Party Services is undertaken at your own risk, and you bear sole responsibility for ensuring their suitability for your needs. The Sites and Services may feature links to third-party websites, for which we disclaim responsibility for their content or practices.

6.2 Governing Agreements with Third Party Services:

Your relationship with Third Party Services is governed by separate agreements. Your utilization of Third Party Services is subject to their respective terms, and we bear no responsibility for their actions or security. Both we and Third Party Services reserve the right to discontinue or suspend Third Party Services without prior notice.

6.3 Additional Conditions and Payment Terms:

Both we and Third Party Services may impose supplementary conditions or limitations on your utilization of Third Party Services. Third Party Services may be offered free of charge or entail payment obligations. Payment terms are delineated in separate agreements. Fees for Third Party Services may undergo alterations over time.

7. Fees and upgrades

7.1 Initiation of Payment for Services:

You have the option to commence payment for our Services by inputting your billing details within the Organization Account and consenting to our invoicing terms.

7.2 Billing Details and Invoicing Terms:

Customers are required to provide us with updated, accurate, and comprehensive billing details. Invoices for customers with Organization Accounts will be generated monthly in advance, corresponding to the number of users and selected services. You retain the discretion to terminate services and remove users at any time to cease future invoicing. It is noted that Fees are denominated in Euros unless otherwise specified and are non-refundable. We reserve the right to modify fees with prior notice. You bear responsibility for any taxes imposed and are required to notify us if tax deductions or withholdings are necessary.

7.3 Adjustments and Additional Fees:

In instances where we ascertain that you or your users have exceeded the anticipated standard usage of the services, we reserve the right to modify pricing, levy additional fees, or impose restrictions on upload, storage, download, and usage. This may encompass limitations on third-party services, network traffic, bandwidth, content size, format, sources, and download time. Furthermore, we retain the prerogative to impose fees on Free Organization Accounts that exhibit a significantly greater volume of data compared to typical Free Organization Accounts.

8. Free Services

8.1 Provision of Free Services:

We may offer some or all of our Services free of charge. We retain the right to alter or terminate Free Services at our discretion, without incurring liability or providing justification.

8.2 Terms Governing Free Services:

Free Services are subject to these Terms, albeit with certain distinctions: they are provided "As-Is," without warranties; our indemnity provision does not apply; and our liability is capped at 100 euros. The availability of Free Services cannot be guaranteed.

9. Term, Termination and Suspension

9.1 Duration and Termination:

These Terms shall be effective from the Effective Date and shall remain in force indefinitely unless terminated earlier in accordance with these Terms or by mutual agreement.

9.2 Termination Process:

An organizational customer may terminate their usage of the Services by deleting the Organization Account, while an individual customer may do so by deleting the User Account.

9.3 Consequences of Termination:

Upon termination, the Customer's Account and all rights granted herein shall cease. The Customer bears sole responsibility for exporting Customer Data prior to termination. The Customer acknowledges and accepts this responsibility and must export and/or delete Customer Data before termination, thereby absolving us from liability to the Customer, Users, or third parties. Unless expressly stated otherwise, termination does not relieve the Customer of the obligation to pay any unpaid Fees. Furthermore, the Customer is not entitled to a refund of any pre-paid Fees.

9.4 Survival of Certain Provisions:

Certain provisions of these Terms shall continue to be in effect even after termination, including those pertaining to customer responsibilities for users, customer data, privacy and security, third-party services and links, subscription fees (especially unpaid fees), terms governing free services, term and termination, confidentiality, warranty disclaimer, limitations of liability, indemnification, governing law and jurisdiction, arbitration, and general provisions. These surviving provisions shall remain valid and enforceable in accordance with their terms.

9.5 Termination by Us:

We may terminate these Terms and the Customer’s Account by providing written notice if:

  • The Customer has been declared bankrupt, placed in receivership, or has applied for debt restructuring,
  • The Customer fails to settle payments that have fallen due within six months of the due date despite written notification of late payment, or
  • Any free accounts have remained unused for the past six months.

In all other cases, we shall provide three (3) months' notice of termination.

9.6 Suspension of Account or Services:

We reserve the right to temporarily suspend the Account or Services if we believe there is a security risk, breach of Terms, overdue payments, or violation of the  Acceptable Use Policy . This is in addition to other remedies available under these Terms or the law.

10. Confidentiality

10.1 Confidential Information:

In relation to these Terms and the Services, each party ("Disclosing Party") may disclose to the other party ("Receiving Party") non-public business, product, technology, and marketing information, including but not limited to customer lists and information, know-how, software, and any other non-public information that is either explicitly identified or reasonably understood to be confidential considering the nature of the information and the circumstances of disclosure, whether disclosed before or after the Effective Date ("Confidential Information").

For clarity, Customer Data is considered the Customer's Confidential Information, and our Site, Services, including their underlying technology, and their respective performance information, as well as any data, reports, and materials provided to you in connection with your use of the Services, are considered our Confidential Information.

Confidential Information does not include information that:

  • becomes generally available to the public without breach of any obligation owed to the Disclosing Party;
  • was known to the Receiving Party prior to its disclosure by the Disclosing Party without breach of any obligation owed to the Disclosing Party;
  • is received from a third party without breach of any obligation owed to the Disclosing Party; or
  • was independently developed by the Receiving Party without use or reference to the Confidential Information.

10.2 Receiving Party's Responsibilities:

The Receiving Party shall undertake reasonable measures to prevent unauthorized disclosure or use of Confidential Information, restricting access to such information to employees, affiliates, service providers, and agents on a need-to-know basis, all of whom are bound by confidentiality obligations at least as stringent as those delineated herein. The Receiving Party shall refrain from using or disclosing any Confidential Information to third parties, except when necessary for performance under these Terms or as mandated for disclosure to legal or financial advisors of the Receiving Party, or as part of a due diligence process, ensuring that any such disclosure adheres to confidentiality obligations of similar or greater stringency as those outlined herein.

10.3 Compelled Disclosure:

Despite the foregoing provisions, Confidential Information may be revealed in response to a court order, administrative directive, or other governmental mandate; nonetheless, the Receiving Party shall endeavor, to the extent permitted by law, to promptly notify the Disclosing Party of such legal obligation, enabling the Disclosing Party to pursue a protective order or take measures to prevent or limit such disclosure.

11. Warranty Disclaimer

We provide no warranties except as explicitly stated in these Terms.

11.1 Representation of Site and Service:

The Sites and Services are provided "as is," "with all faults," and "as available." We, along with our affiliates, subcontractors, agents, and vendors (including third-party service providers), disclaim all representations and warranties, including those of merchantability, functionality, title, fitness for a particular purpose, and non-infringement, whether expressed, implied, or statutory.

11.2 Uninterrupted Service:

We and our vendors do not guarantee uninterrupted, timely, secure, or error-free access and use of the Services and Sites. We also cannot guarantee that data will not be lost, defects will be rectified, or that the Sites and Services are free of viruses or harmful code. We disclaim responsibility for delays, failures, interception, alteration, loss, or other damages beyond our control.

11.3 Completeness and Accuracy:

We do not guarantee that our Services and Sites, or any part of them, are complete, accurate, of any particular quality, reliable, suitable for your intended activities, compatible with your devices, operating systems, browsers, software, or tools, or compliant with applicable laws. We further disclaim any guarantee regarding the accuracy or quality of any content, information, reports, or results obtained through the Services and Sites.

11.4 Compliance with Local Laws:

We do not guarantee that using the Services complies with your local laws. You are responsible for ensuring compliance with applicable laws.

12. Limitation of Liability

Notwithstanding anything else in these terms or elsewhere, and to the maximum extent permitted by applicable law:

12.1 Exclusion of Certain Damages:

Neither party, its affiliates, subcontractors, agents, and vendors (including third-party service providers), shall be liable under or in connection with these terms for any:

  • Indirect, exemplary, special, consequential, incidental, or punitive damages.
  • Loss of profits, anticipated savings, data, use, business, reputation, revenue, or goodwill.
  • Failure of security measures and protections.

This applies regardless of whether such damages were advised in advance or not, and even if a remedy fails of its essential purpose.

12.2 Maximum Liability:

Except for indemnity obligations, payment obligations, or breach of  Acceptable Use Policy , the total liability of either party, its affiliates, subcontractors, agents, or vendors (including third-party service providers) under these terms shall not exceed the total amount of fees actually paid by you in the preceding 12 consecutive months. This limitation of liability is cumulative and not per incident.

12.3 Acknowledgment of Limitations:

You acknowledge and affirm that the limitations of liability and warranty disclaimers outlined in these Terms are mutually agreed upon by both parties, deemed commercially reasonable and appropriate for our contractual engagement. Both parties have relied on these limitations and risk allocations in their decision to enter into these Terms.

13. Indemnification.

13.1 Customer's Indemnification:

Customer hereby agrees to indemnify, defend, and hold harmless Starbrix and its affiliates, officers, directors, employees, and agents from and against any and all claims, damages, obligations, liabilities, losses, reasonable expenses, or costs (collectively referred to as "Losses") incurred as a result of any third-party claim arising from:

  • Customer's and/or any of its Users' violation of these Terms or applicable laws; and/or
  • Customer Data, including its use by Starbrix.app and/or any of its subcontractors, which infringes or violates any third party's rights, including but not limited to intellectual property, privacy, and publicity rights.

13.2 Starbrix's Defense Obligations:

Starbrix will defend Customer against any third-party claim that Customer's use of the Services infringes on copyrights, trademarks, or patents (“Claim”). Starbrix's indemnity obligations shall not apply if:

  • the Services (or any portion thereof) were modified by Customer, its Users, or any third party, but solely to the extent that the Claim would have been avoided without such modification;
  • the Services are used in combination with any other service, device, software, or products, including Third Party Services, but solely to the extent that the Claim would have been avoided without such combination; and/or
  • any Claim arises or is related to the Customer Data or to any events giving rise to Customer's indemnity obligations under Section 13.1 above.

13.3 Conditions of Defense and Indemnification:

The defense and indemnification obligations of the indemnifying party are subject to the following conditions:

  • The indemnified party must promptly provide written notice of the claim for which indemnification is sought; however, the failure to do so will not relieve the indemnifying party of its obligations, except to the extent that the indemnifying party's defense is materially prejudiced thereby.
  • The indemnifying party must be given immediate and exclusive control over the defense and/or settlement of the claim. However, the indemnifying party shall not enter into any compromise or settlement of any such claim that requires any monetary obligation, admission of liability, or any unreasonable responsibility or liability by the indemnitee without the prior written consent of the affected indemnitee. Such consent shall not be unreasonably withheld or delayed.
  • The indemnified party must provide reasonable cooperation and assistance, at the indemnifying party's expense, in the defense and/or settlement of such claim and refrain from taking any action that prejudices the indemnifying party's defense or response to such claim.

14. Third Party Components

Our Services may incorporate third-party code subject to open source licenses ("Open Source Code" and "Open Source Terms"). Certain Open Source Terms may supersede conflicting license terms, including those of ours. We make diligent efforts to identify such code and encourage you to review the applicable Open Source Terms. We strive to utilize Open Source Code that does not impose additional obligations on your data or intellectual property beyond those stipulated in the Open Source Terms and herein. Please note that we do not provide warranties or indemnification for Open Source Code. For copyright statements and licenses pertaining to Open Source Code utilized in our Services, please refer to our  Open Source List.

15. Export Controls

The Services may be subject to Finnish or EU foreign export controls, laws, and regulations ("Export Controls"). You acknowledge and confirm the following:

  • You will not use, export, re-export, or import the Services (or any portion thereof) in violation of the Export Controls to any person, entity, organization, jurisdiction, or otherwise where such actions are prohibited.
  • You are not organized under the laws of, operating from, or ordinarily resident in a country or territory subject to comprehensive Finnish economic or trade sanctions; identified on a list of prohibited or restricted persons; or otherwise targeted by Finnish or EU sanctions. Customer is solely responsible for complying with applicable Export Controls and sanctions, which may impose additional restrictions, prohibitions, or requirements on the use, export, re-export, or import of the Services and/or the Customer Data.
  • Customer Data does not require any special permission or license for its use, import, export, or re-export under these Terms.

16. Modifications

We reserve the right to update these Terms for various reasons, such as adding features or rectifying errors. In the event of significant changes, we will notify you, either within the Services or via email. Your continued use of the Services constitutes acceptance of the modified terms.

17. Governing Law and Dispute Resolution

To the fullest extent permitted by applicable law, you and Starbrix hereby irrevocably agree to the following provisions:

17.1. Arbitration: Any dispute, claim, or controversy between you and us arising in connection with or relating in any way to these Terms (whether based on contract, tort, statute, fraud, misrepresentation, or any other legal theory, and whether the claims arise during or after the termination or expiration of these Terms) shall be resolved solely by mandatory binding arbitration.

17.2. Injunctive Relief: Notwithstanding clause 17.1 above, you and Starbrix both agree that nothing herein shall waive, preclude, or otherwise limit either of our rights, at any time, to seek injunctive relief in a court of law. Additionally, notwithstanding clause 17.1 above, Starbrix reserves the right to file a lawsuit in a court of law against you to address intellectual property infringement claims.

17.3. Arbitration Proceedings: Either party may initiate arbitration proceedings. Any arbitration between the parties shall be conclusively resolved in accordance with the Rules of Arbitration of the International Chamber of Commerce ("ICC Rules") by a single arbitrator appointed in compliance with the ICC Rules. The arbitration shall take place in Helsinki, Finland, conducted in English, and, unless otherwise required by mandatory law in any jurisdiction, governed by the laws of Finland, without regard to its conflict of law principles. The arbitration process shall be expedited, with an award rendered within a maximum of 90 days. All arbitration proceedings shall be conducted confidentially. The arbitrator's decision shall be final and binding upon the parties. The arbitration award shall be enforceable in any court of competent jurisdiction. Any motion to enforce or challenge an arbitration award under this agreement shall be kept as confidential as possible.

17.4. Commencement of Arbitration: Any arbitration must be initiated by filing a demand for arbitration within one year after the date the party asserting the claim first becomes aware or reasonably should have become aware of the act, omission, or default giving rise to the claim. Failure to assert a claim within this time period shall result in the forfeiture of any remedy for such claim. If applicable law prohibits such a limitation period for asserting claims, any claim must be asserted within the shortest time period permitted by applicable law.

17.5. Dispute Resolution Procedure: Before initiating arbitration, a party must first send a written notice ("Dispute Notice") of the dispute to the other party and confirm receipt by the other party. The Dispute Notice must outline the nature and basis of the claim or dispute, and specify the relief sought. Both parties agree to exert good faith efforts to resolve the claim directly. If an agreement is not reached within 60 days after receipt of the Dispute Notice, either party may commence arbitration proceedings.

During arbitration, any settlement offers made by either party shall not be disclosed to the arbitrator until after a final decision and award, if any, has been made. In addition to the confidentiality protection outlined in clause 17.3 above, all documents and information revealed during arbitration must be kept strictly confidential by the recipient and used solely for arbitration purposes or enforcement of the arbitrator's decision and award. Disclosure is permitted only to individuals with a legitimate need to know for these purposes or as mandated by applicable law.

Except for purposes of enforcing the arbitrator's decision and award, neither party shall make any public announcement, public comment, or engage in any publicity regarding the arbitration, including but not limited to disclosing the fact that a dispute exists, the arbitration proceedings, or any decision or award rendered by the arbitrator.

18. General Provisions

18.1. Heading Clarification: Any heading, caption, or section title contained herein, and/or any explanatory or summary columns, are provided solely for convenience and do not alter or amend the provisions within these Terms, nor do they legally bind us in any way. These Terms are written in English and translated into other languages for your convenience. In the event of a conflict between the translated (non-English) version of these Terms and the English version, the provisions of the English version shall prevail.

18.2. Force Majeure: Neither party will be liable for any failure or delay in the performance of its obligations due to events beyond its reasonable control, including denial-of-service attacks, internet or utility service interruptions or failures, third-party hosting service failures, strikes, shortages, riots, fires, war, terrorism, or governmental actions.

18.3. Independent Contractor Relationship: The parties are independent contractors. These Terms and the Services provided do not create a partnership, franchise, joint venture, agency, fiduciary, or employment relationship between the parties. There are no third-party beneficiaries to these Terms.

18.4. Notice: We will use the contact details we have on record to provide you with notices. Notices may be delivered via various methods, including posting on our Sites or within your account, text, in-app notifications, email, phone, or mail. You acknowledge that electronic notifications satisfy legal notification requirements and will be considered in writing. Notices to you will be deemed given upon receipt or within 24 hours of delivery. Notices to us should be sent to StarBrix International Ltd at legal@starbrix.app.

18.5. Assignment: These Terms and any rights and obligations herein may not be transferred or assigned by you without our written approval, except in certain circumstances such as mergers, acquisitions, or asset sales, subject to conditions outlined herein. We may assign our rights and obligations without your consent. These Terms shall bind and benefit the parties, their successors, and permitted assigns.

18.6. Enforceability: These Terms shall be enforced to the fullest extent permitted by applicable law. If any provision is held to be contrary to law, it will be modified to accomplish the objectives of the original provision to the fullest extent permitted by law, and the remaining provisions will remain in effect.

18.7. Waiver: No failure or delay by either party in exercising any right under these Terms will constitute a waiver of that right. Waivers must be made in writing and signed by an authorized representative.

18.8. No Reliance: You acknowledge that you do not rely on any statements, warranties, or representations made by us or any other person on our behalf, except as expressly set out in these Terms.

‍

Updated: 01.09.2026

Terms of Additional Services

These Terms of Additional Services ("AS Terms") form an integral component of the Starbrix  Terms of service  ("Terms") or any other agreement governing the use of Starbrix’s services (collectively referred to as the "Agreement"), entered into by and between you, the Customer (as defined in the Agreement) (collectively referred to as "you", "your", or "Customer"), and Starbrix International Ltd ("Starbrix", "Starbrix.app", "us", "we", "our"), to specify the parties' understanding concerning the provision of additional services, which may include training services ("Training Services"), consulting services ("Consulting Services"), technical services ("Technical Services"), and/or other ancillary services as described herein (the Training Services, Consulting Services, Technical Services, and additional ancillary services collectively referred to as the "Additional Services").

Capitalized terms not defined herein shall have the meanings ascribed to them in the Agreement.

By procuring, receiving, and/or utilizing the Additional Services, Customer acknowledges acceptance of these AS Terms, and you affirm and warrant that you possess full authority to bind the Customer to these AS Terms.

In the event of any inconsistency between certain provisions of these AS Terms and those of the Agreement, the AS Terms shall take precedence over conflicting provisions of the Agreement solely concerning the provision of the Additional Services.

1. The Additional Services

1.1. Subject to these AS Terms, Starbrix may provide the following Additional Services, as specified in an Order Form or a mutually agreed statement of work ("SOW") between the parties:

  • Training Services: Provision of training to Customer on how to use the Services.
  • Consulting Services: Assisting Customer in optimizing its use of the Services.
  • Technical Services: Provision of specific Technical Services related to the Services, with the scope and services to be mutually agreed upon.
  • Other Additional Services: Furnishing Customer with any other ancillary services, such as implementation or professional services, to aid in managing, supporting, or implementing the Services, including service packages for such additional services.

1.2. Unless otherwise agreed in writing, the Additional Services will be remotely performed by Starbrix or third-party providers on our behalf, with such third parties considered sub-processors of Starbrix for this purpose.

1.3. The Additional Services will be available to Customer for the period specified in the Order Form or SOW ("AS Term").

1.4. Certain Additional Services may have additional supplemental terms as identified by Starbrix in an Order Form, SOW, or applicable service offering documentation, which shall govern the performance and use of such Additional Services.

2. Consideration

The fees for the Additional Services ("AS Fees") and the payment terms shall be outlined in the Order Form or SOW. The AS Fees are non-refundable and non-cancellable.

3. Intellectual Property

Starbrix retains full ownership of any work products resulting from the provision of Additional Services, including reports and training materials ("Work Products"). Upon payment of all AS Fees, the Customer is granted a limited, global, non-exclusive, non-sublicensable, and non-transferable license to utilize, reproduce, and exhibit the Work Products solely for internal business purposes for the duration of the agreement, excluding any Customer Data contained therein.

It's important to note that all Work Products are classified as Starbrix Materials and are derived from Starbrix's existing intellectual property. Starbrix reserves all rights not explicitly granted herein for the Work Products.

4. Term and Termination

These AS Terms shall terminate upon the termination or expiration of the Agreement.

5. General

5.1. The Terms, to the extent applicable, shall apply to the Additional Services and are incorporated herein by reference, including the specified sections as applicable to Customer.

5.2. For the purpose of these AS Terms, in the Agreement, references to the Agreement, "Services," and "Fees" shall include the Additional Services, AS Terms, and AS Fees, respectively.

5.3. Starbrix retains the right to develop, use, market, or sell services or products similar to the Work Products or Additional Services, or to use such Work Products to perform similar services for any other purposes, including without limitation in connection with other projects and customers but subject to Starbrix’s obligations with respect to the Customer Data and Customer’s Confidential Information.

‍

Updated: 01.09.2026

Developer Terms

These Terms, together with any other terms and policies referenced and incorporated by reference herein, constitute a legally binding agreement as of the Effective Date (as defined below). They govern your access to and use of our application program interfaces, software, or accompanying documentation or materials (collectively, the "API"). Please carefully read these Terms before accessing or using the API.

These Terms are entered into between Starbrix International Ltd ("Starbrix", "Starbrix.app", "us", "we", or "our") and you, either individually or on behalf of your employer or any other entity which you represent ("you" or "your"). If you represent your employer or another entity, you hereby represent that you have full legal authority to bind your employer or such entity (as applicable) to these Terms. After reading and understanding these Terms, you agree to them on behalf of your employer or the respective entity (as applicable), and they will bind your employer or such entity (as the case may be).

You acknowledge that these terms are binding, and you affirm and signify your consent to them by either clicking on a button or checking a checkbox for the acceptance of these terms or by accessing or using the API, whichever occurs earlier (the "Effective Date"). If you do not agree to comply with and be bound by these terms or do not have authority to bind your employer or any other entity (as applicable), please refrain from accepting these terms or using the API.

1. API Permissions

API License: Subject to your compliance with the Terms, Starbrix grants you a limited, non-transferable, nonexclusive, revocable, royalty-free license, without the right to sublicense, to use the API to develop, implement, integrate, and interface your application ("App") with the Starbrix.app Services as defined in our  Terms of Service  and distribute Your App to end users who are also customers of Starbrix.app Service.

License Restrictions. Except as expressly authorized under these Terms, you may not:

  • use, copy, modify, display, distribute, transfer, or sublicense any portion of the API;
  • make the functionality of the API available to any third party through any means, including, without limitation, any hosting, application services provider, service bureau, or other type of service; or
  • use the Starbrix name, trademarks, logos, or anything confusingly similar, or anything that may create a connotation of false endorsement by Starbrix, in connection with any App created by you, or in a manner that creates a sense of endorsement, sponsorship, or false association with Starbrix.

You acknowledge and agree that portions of the API, and Services, including, without limitation, the source code and the specific design and structure of individual modules or programs, constitute or contain trade secrets of Starbrix.app and its licensors.

Accordingly, you agree not to disassemble, decompile, or otherwise reverse engineer the API, or Services, in whole or in part, or to permit or authorize a third party to do so, except to the extent that such activities are expressly permitted by law notwithstanding this prohibition.

You agree to fully comply with all applicable export laws and regulations to ensure that neither the API, and Services, any technical data related thereto, nor any direct product thereof are exported or re-exported directly or indirectly in violation of, or used for any purposes prohibited by, such laws and regulations.

2. API Access Requirements

Every App must maintain absolute compatibility with the API to gain access to the API and Services. This entails:

  • applying all API updates provided by Starbrix,
  • implementing all functionalities identified as critical by Starbrix, and
  • supporting any standards (including encryption standards) required by Starbrix.

You agree to adhere to any limitations on access, calls, or use of the API or Services (referred to as "Service Limits") set by Starbrix and will not attempt to circumvent such Service Limits without separate prior written consent from Starbrix.

You may not use or access the API or Services to monitor the availability, performance, or functionality of the API or Services, or for any benchmarking or competitive purposes.

3. Updates and Support

At its discretion, Starbrix may maintain, support, update, or provide error corrections for the API. If Starbrix issues an update or maintenance release for the API, unless you receive a separate license from Starbrix expressly superseding these Terms, such update or release will be subject to the terms and conditions herein.

4. Your App

If you make your App available to individuals outside your organization, you agree to do so exclusively under the terms of a user agreement ("EULA") and privacy policy ("Privacy Policy") specific to your App. These agreements will be presented to users prior to downloading or accessing your App. You further agree that the EULA and Privacy Policy will comply with all relevant laws and regulations, and you will obtain and maintain all necessary consents and permissions related to the collection, use, storage, and sharing of data in clear, understandable, and accurate terms.

Each EULA and Privacy Policy must provide at least the same level of protection to Starbrix's proprietary rights in the API as outlined in these Terms. This includes provisions covering restrictions on reverse engineering (to the maximum extent permitted by law), disclaimer of warranties, and limitation of liability.

Explicit consent from the end user is required before collecting, using, posting, or sharing any Customer Data obtained through the API on behalf of an end user. Merely authorizing your application by the end user does not constitute consent. You and your App are prohibited from engaging in any transmission, storage, or other use of Customer Data beyond the scope of what the end user has consented to.

Regarding any third-party "Open Source" software or other third-party intellectual property in your App ("Third-Party Code"):

  • You must fully comply with the terms and conditions governing such Third-Party Code, including displaying any attributions, copyright information, and other notices required for end users based on your use of such Third-Party Code.
  • You shall only use Third-Party Code that does not impose any obligations on, or affect Starbrix.app, the end users, or any aspect of our Services and related intellectual property, in the ordinary use and exploitation of your App (as indicated in any applicable terms between you and Starbrix).

5. Services Data

The results, usage statistics, data, or information derived from your use of the API or Services ("Service Data") may only be employed for your internal business purposes.

6. Acceptable Use

You are prohibited from using or accessing the API, or Services for any unlawful purpose, any purpose not expressly authorized hereunder, or in any manner inconsistent with the Terms. Additionally, you acknowledge and agree that your Apps must not contain any content that

  • Infringes, misappropriates, or violates a third party’s patent, copyright, trademark, trade secret, moral rights, or other intellectual property rights, or rights of publicity or privacy.
  • Violates, or encourages conduct that would violate, any applicable law or regulation or would give rise to civil liability.
  • Is fraudulent, false, misleading, or deceptive.
  • Is defamatory, obscene, pornographic, vulgar, or offensive.
  • Is violent or threatening, or promotes violence or actions that are threatening to any person or entity.
  • Promotes discrimination, bigotry, racism, hatred, harassment, or harm against any individual or group.
  • Promotes illegal or harmful activities or substances.
  • Use, display, mirror, or frame the Services or any individual element within the Services without the express written consent of Starbrix.
  • Access, tamper with, or use non-public areas of the Services, Starbrix.app’s computer systems, or the technical delivery systems of Starbrix.app’s providers.
  • Attempt to probe, scan, or test the vulnerability of any Starbrix.app system or network or breach any security or authentication measures.
  • Avoid, bypass, remove, deactivate, impair, descramble, or otherwise circumvent any technological measure implemented by Starbrix.app or any of its providers or any other third party (including another user) to protect the Services.
  • Collect or store any personally identifiable information from other users of the Services without their express permission.
  • Violate any applicable law or regulation.
  • Utilize Third Party Code that imposes any obligation on or affects Starbrix.app, the end users, or any aspect of our Services, and related intellectual property, in the ordinary use or any exploitation of your App.

7. Protection of End User Data

7.1 Data Collection

During your utilization of the API, you may access data or information, including personal data, associated with your Apps. Additionally, you may gather information, content, Customer Data, or any other data from end users of your App for various purposes, such as App performance, activities, or lawful reasons. All data, content, Customer Data, or information collected is collectively referred to as "End User Data".

7.2 Use of End User Data

You agree to employ, process, share, and transfer End User Data only as authorized by the end user or as necessary for the functionality of your App, as detailed in your Privacy Policy or any other Data Protection Agreement. End User Data must be handled, stored, transmitted, and processed in accordance with this Agreement, your Privacy Policy, agreements with end users, and applicable laws. You must also uphold the data subject rights of end users, including the right to delete, revoke, and review their End User Data. Starbrix assumes no liability for End User Data processed by your App.

7.3 Security:

You are responsible for maintaining the confidentiality and security of End User Data in accordance with privacy laws and regulations. Implement appropriate technical and organizational measures to ensure the security of processing operations, consistent with industry standards and any additional requirements provided by Starbrix.

7.4 Incident Notification:

Promptly notify Starbrix of any unauthorized access, security vulnerabilities, or incidents affecting End User Data or Starbrix.app's systems. Provide necessary information and assistance to investigate and remediate incidents, complying with all legal and contractual obligations. You are liable for any costs or damages incurred by Starbrix due to such incidents.

7.5 Deletion of End User Data upon App Deactivation:

Upon deactivation or termination of an App, delete all End User Data within 30 days unless expressly permitted otherwise by the end user. If consent for data retention is obtained, continue to maintain End User Data in accordance with your Privacy Policy and end user agreements. Notify Starbrix of compliance with data deletion or obtainment of further consent from end users.

8. Ownership

The API is licensed to you and not sold, with Starbrix retaining full ownership, including all intellectual property rights. Starbrix.app reserves all rights not expressly granted in these Terms.

9. Feedback

As a developer, you are encouraged to offer suggestions, comments, feature requests, or any other feedback concerning Starbrix.app Materials, the Starbrix.app Service, or the API ("Feedback"). Such Feedback is deemed integral to Starbrix Materials and becomes the exclusive property of Starbrix without any restrictions or limitations on its utilization. Starbrix reserves the right to accept or decline Feedback without any obligation to implement it.

10. Term and Termination

These Terms remain in effect from the Effective Date until they are terminated. You have the right to terminate these Terms at any time by notifying Starbrix.

In the event of your breach of any term or condition of these Terms, Starbrix reserves the right, at its sole discretion and without prior notice, to:

  • Suspend your and your App’s access to the API or Services;
  • Terminate all licenses or permissions granted under these Terms; or
  • Terminate these Terms.

Additionally, Starbrix may terminate these Terms or any licenses or permissions granted herein, at its sole discretion, by providing you with three months’ notice. Upon termination:

  • All licenses or permissions granted to you will cease;
  • You must discontinue your App’s access to and use of the API; and
  • Within fifteen (14) days of termination, you must destroy all copies of the API, Services Data, and any confidential information of Starbrix.app.

Sections 1 (with respect to License Restrictions only), 6, 7, 8, 10, 11, 12, 13, 14, 16, and 17 will survive the termination of these Terms.

11. Warranty

The API is furnished on an "as is" and "as available" basis, with no warranty of any kind. Starbrix explicitly disclaims all warranties and conditions, whether express or implied, including but not limited to any implied warranties and conditions of merchantability, fitness for a particular purpose, and non-infringement, as well as any warranties and conditions arising from course of dealing or usage of trade pertaining to the API. No advice or information, whether conveyed orally or in writing, obtained from any source outside of these Terms, shall establish any warranty or condition not expressly articulated herein.

12. Liability

Starbrix's aggregate liability to you, arising from all causes of action and under all legal theories pursuant to these Terms, shall be limited to, and not exceed, one hundred euros.

Except in cases of breach of Section 12 and your indemnification obligations under Section 13, neither party shall be liable to the other for any special, incidental, exemplary, punitive, or consequential damages (including loss of use, data, business, or profits), or for the cost of procuring substitute products, arising out of or in connection with these Terms or the use or performance of the API. This limitation of liability applies regardless of whether such liability arises from a claim based on contract, warranty, tort (including negligence), strict liability, or any other legal theory, and irrespective of whether the party has been advised of the possibility of such loss or damage. These limitations shall persist and be enforceable even if any limited remedy set forth in these Terms is found to have failed of its essential purpose.

13. Indemnity

You undertake to defend, indemnify, and hold Starbrix harmless against any liabilities, losses, damages, judgments, fines, penalties, costs, and expenses (including reasonable attorneys’ fees and court costs) incurred as a result of any third-party claim, action, or proceeding brought against Starbrix (hereinafter referred to as a "Claim") arising from your App or your use of the API. This includes, but is not limited to, any alleged infringement, violation, or misappropriation of any third-party rights (such as intellectual property rights and privacy rights), or your breach of these Terms.

Upon receipt of a Claim, Starbrix shall promptly notify you in writing and afford you the opportunity to assume control over the defense and/or settlement of the claim. However, Starbrix reserves the right to retain legal counsel, at its own expense, to participate in the defense and settlement of the Claim.

14. Confidentiality

The API constitutes confidential information of Starbrix, and you agree to utilize it solely as expressly authorized herein and as necessary to exercise your rights under these Terms.

Unless explicitly authorized herein, you are prohibited from disclosing Starbrix’s confidential information to any third party. However, you may disclose Starbrix’s confidential information to your employees and subcontractors who require such information to fulfill their obligations under these Terms, provided that each such individual is bound by a written agreement containing usage and disclosure restrictions at least as protective as those delineated herein.

You undertake to exert all reasonable efforts to preserve the confidentiality of Starbrix’s confidential information, employing measures no less stringent than those typically applied to safeguard your own proprietary information of comparable significance.

15. Modification

Starbrix retains the authority to amend the provisions of these Terms at any time and at its sole discretion. Such alterations will be communicated to you in writing, which may encompass posting the updated terms on the Starbrix.app website.

Should any notified modifications to these Terms prove unacceptable to you, your exclusive recourse will be to terminate these Terms in accordance with Section 10 above. Your continued access and/or utilization of the API subsequent to receiving such notification will signify your acceptance of the informed modifications.

16. Governing Law and Jurisdiction

These Terms and any dispute arising therefrom shall be governed by and construed in accordance with the laws of Finland, without regard to its conflict of law principles. Any dispute, controversy, or claim arising out of or relating to these Terms shall be exclusively settled by the courts of competent jurisdiction located in Helsinki, Finland, following the procedures outlined in Section 17.1 of the  Terms of Service  regarding Arbitration.

17. General

These Terms are originally drafted in English and may be translated into other languages for your convenience. In the event of any conflict between the English version and a translated (non-English) version of these Terms, the provisions of the English version shall prevail.

Neither party shall be held liable for any failure or delay in the performance of its obligations due to events beyond its reasonable control, including but not limited to denial-of-service attacks, interruptions or failures of the Internet or any utility service, failures in third-party hosting services, strikes, shortages, riots, fires, war, pandemics, terrorism, or governmental actions.

The parties are independent contractors, and these Terms do not create a partnership, franchise, joint venture, agency, fiduciary, or employment relationship between them. There are no third-party beneficiaries to these Terms. We will use the contact details we have on record for you to provide notices as outlined herein. Notices to us shall be sent to Starbrix Limited Ltd at legal@starbrix.app. Notices provided to you in connection with these Terms, including those related to your use of the API, shall be deemed delivered upon the earlier of receipt or 24 hours after delivery.

These Terms, and all rights and obligations herein, may not be transferred or assigned by you without our written approval. We may assign our rights and/or obligations herein without your consent or prior notice to you. Subject to the foregoing conditions, these Terms shall bind and inure to the benefit of the parties, their respective successors, and permitted assigns. Any assignment not authorized herein shall be null and void.

These Terms shall be enforced to the fullest extent permitted by applicable law. If any provision of these Terms is held by a court of competent jurisdiction to be contrary to law, the provision shall be modified by the court to best accomplish the objectives of the original provision to the fullest extent permitted by law, and the remaining provisions of these Terms shall remain in effect.

No failure or delay by either party in exercising any right under these Terms shall constitute a waiver of that right. No waiver under these Terms shall be effective unless made in writing and signed by an authorized representative of the waiving party.

‍

Updated: 01.09.2026

Acceptable Use Policy

Our Acceptable Use Policy (“AUP”) is an integral component of the Terms of Service, delineating prohibited activities when utilizing the Services or any Starbrix Sites (collectively referred to as “Services”). All capitalized terms not defined herein are as defined in the Terms of Service.

1. You affirm and warrant that you will not, and will not facilitate or permit any third party to:

  • Attempt to access, manipulate, or reverse engineer any part of the Services or associated infrastructures, except through the provided interface.
  • Probe, scan, or test the vulnerability of the Services or the Systems or breach security measures.
  • Disrupt our infrastructure by imposing unreasonable requests or burdens.
  • Modify or derive works from the Services, or remove proprietary markings.
  • Use the Services for transmitting malware or engaging in phishing activities.
  • Upload content that may disrupt or harm the operation of the Services or third-party infrastructure.
  • Engage in illegal, fraudulent, or deceptive activities.
  • Attempt unauthorized access to the Services or the Systems.
  • Impersonate any individual, organization, or entity.
  • Violate the privacy of others or disclose private information without authorization.
  • Use the Services for defamatory, threatening, or harassing activities.
  • Transmit harmful components or technologies through the Services.
  • Misuse or excessively use the Services.
  • Send unlawful, unsolicited, or unauthorized communications.
  • Generate harmful or discriminatory content.
  • Infringe upon third-party rights.

2. You affirm and warrant that you shall not, and shall not permit, cause, or encourage others, to upload, submit, transmit, or make available any content that:

  • Exploits or abuses children.
  • Infringes upon intellectual property or other rights.
  • Violates privacy or publicity rights.
  • Is deceptive, fraudulent, illegal, or harmful.
  • Discriminates against others unlawfully.

3. While we do not actively monitor your activities, we reserve the right to screen any content uploaded, submitted, or transmitted through our Services or Systems.

4. You acknowledge our commitment to respecting copyright and other intellectual property rights and agree to respond promptly to infringement notices.

5. We reserve the right to take action if we suspect violations of this AUP or the Terms of Service, including removing content, suspending accounts, or restricting access.

6. We may update this AUP periodically, and your continued use after changes signifies acceptance. If there are material changes, we will provide notice within the Services or by email.

‍

Updated: 01.09.2026

Privacy Policy

This Privacy Policy delineates the procedures by which StarBrix International Ltd (alongside its affiliated entities - "Starbrix," "Starbrix.app," "we," "our," or "us") gathers, stores, utilizes, and disseminates the ensuing categories of personal data:

  • Customer Data: Personal data procured, processed, and managed on behalf of our corporate clients ("Customers"), submitted to the Starbrix.app cloud-based services, encompassing our platforms, products, applications, APIs, tools, and any ancillary or supplementary Starbrix.app products and services (including Upgrades, as delineated in the Terms of Service), proffered online (collectively, the "Platform"). We handle such Customer Data on behalf of and as per the directives of the respective Customer, serving as a "data processor," consistent with our  Data Processing Addendum  with them. Further details are outlined in Section 9 below.
  • This Privacy Policy delineates Starbrix.app's autonomous privacy and data processing methodologies as a "data controller" concerning the Platform, Sites (as defined below), and any additional services rendered to Customers by Starbrix.app ("Services"), and does not pertain to the processing of Customer Data. For queries or requests regarding Customer Data, kindly contact your account administrators ("Organization Account Owner") directly.
  • User Data: Personal data pertaining to the internal focal individuals of our Customers who engage directly with Starbrix.app regarding their Starbrix.app account (e.g., billing contacts and authorized signatories), Customers' Organization Account Owners, and authorized users of the Platform (collectively, "Users");
  • Prospect Data: Data concerning visitors of our websites (including but not limited to www.starbrix.app), participants at events, and any other potential customer, user, or partner (collectively, "Prospects") who visit or otherwise engage with our programs, marketing and social activities, websites, digital ads and content, emails, integrations, or communications under our jurisdiction ("Sites").
  • Technology Partner Data: Data pertaining to individuals participating and/or engaging as a participant, candidate, applicant, or any other potential or existing technology partners (including developers or technology ambassadors) (collectively, "Technology Partners") who interact with our Platform, Sites, events, and/or other platforms utilized by Starbrix.app.

If you are a Customer, User, Prospect, or Technology Partner, we urge you to meticulously peruse and comprehend this Privacy Policy.

You are under no legal obligation to furnish us with any of your personal data and may opt to do so (or abstain from doing so) voluntarily. Should you opt not to provide us with your personal data or have it processed by us or any of our service providers, simply refrain from visiting or interacting with our Sites or utilizing our Services.

You may also choose not to furnish us with "optional" personal data (i.e., "not required" fields on forms); however, please be advised that doing so may render us incapable of providing you with the complete spectrum of our Services or the optimal user experience when utilizing our Services.

Any capitalized term in this Privacy Policy that remains undefined shall assume the meaning ascribed to it in our  Terms of Services ("Terms").

1. Data Collection & Processing

In this Privacy Policy, when referencing "personal data," we denote information that can identify, relate to, describe, be reasonably associated with, or could reasonably be linked, directly or indirectly, to an individual. This excludes aggregated or anonymized information that cannot reasonably be associated with or linked to an individual.

We collect or generate the following categories of personal data concerning the Services:

  • Usage and device information about our Users, Prospects, and Technology Partners:
  • This encompasses connectivity, technical, and usage data, such as IP addresses, approximate general locations inferred from IP addresses, device and application data (e.g., type, operating system, mobile device or app ID, browser version, location, and language settings utilized), activity logs, pertinent cookies and pixels installed or utilized on devices, and recorded activity (sessions, clicks, feature usage, logged activities, and other interactions) of Prospects, Users, and Technology Partners concerning our Services. We automatically collect and generate this information, including through the utilization of analytics tools (including cookies and pixels), which collect data such as the frequency with which Prospects or Technology Partners visit or use the Sites, the pages they visit and when, the website, ad, or email message that led them there, and how Users interact with and utilize the Platform and its features.
  • Contact and profile information about our Customers, Users, Prospects, and Technology Partners:
  • This encompasses names, email addresses, phone numbers, positions, workplaces, profile pictures, login credentials, contractual and billing details, and any other information submitted by Organization Account Owners and Users or otherwise accessible to us when they sign up or log in to the Platform (either directly or through their social media or organizational Single-Sign-On account), when creating their individual account ("User Account"), or by updating their account. We directly collect this information from you or from other sources and third parties, such as our Customer (your employer), Users, and colleagues related to your Organization Account, organizers of events or promotions in which both you and us were involved, and through the utilization of tools and channels commonly employed for connecting between companies and individual professionals to explore potential business and employment opportunities, such as LinkedIn.
  • Communications with our Customers, Users, Prospects, and Technology Partners:
  • This encompasses personal data contained in any forms and inquiries that you submit to us, including support requests, interactions through social media channels and instant messaging apps, registrations for events that we host, organize or sponsor, and participation in our online and offline communities and activities; surveys, feedback, and testimonials received; expressed, presumed, or identified needs, preferences, attributes, and insights relevant to our potential or existing engagement; and sensory information, including phone call and video conference recordings (e.g., with our customer experience or product consultants), as well as written correspondences, screen recordings, screenshots, documentation, and related information that may be automatically recorded, tracked, transcribed, and analyzed, for purposes including analytics, quality control and improvements, training, and record-keeping purposes.

2. Data Uses & Legal Bases

We utilize personal data for various purposes outlined below, relying on specific legal bases for processing:

  • Performance of Contract: This involves using personal data as necessary to fulfill our contractual obligations to you or to perform the Services effectively.
  • Legal Obligations: We process personal data to comply with applicable laws and regulations, as well as contractual obligations.
  • Legitimate Interests: We engage in processing personal data to support our legitimate interests in maintaining and improving our Services, marketing and selling our Services, providing customer services and technical support, protecting and securing our Users, Customers, Prospects, and Technology Partners, as well as for other business purposes.
  • Consent: In certain cases, where required by privacy laws, we may rely on consent as the legal basis for processing personal data. Your acceptance of our Terms and this Privacy Policy constitutes consent to the processing of your personal data for the purposes detailed herein, unless otherwise required by applicable law. You may revoke your consent by contacting us at privacy@starbrix.app.

Below are specific purposes for which we use personal data, along with the legal bases for processing.

Customer and User personal data:

  • Facilitating, operating, enhancing, and securing our Services.
  • Invoicing and processing payments.
  • Personalizing our Services to provide a tailored experience.

Customer, User, Prospect, and Technology Partner personal data:

  • Providing assistance, support, and training.
  • Improving our Services based on user interactions and feedback.
  • Creating aggregated or anonymized data for business intelligence.
  • Optimizing marketing campaigns and advertisements.
  • Sending personalized messages and promotional content.
  • Enhancing data security measures.
  • Exploring growth opportunities and partnerships.
  • Hosting events, webinars, contests, and promotions.
  • Publishing feedback and submissions.
  • Ensuring compliance with contractual and legal obligations.
  • Pursuing other lawful purposes or those to which you consent.

3. Data Location & Retention

Data Location: We and our authorized Service Providers maintain, store, and process personal data in various locations globally. These locations are chosen as necessary for the proper performance and delivery of our Services or as required by applicable law. While privacy laws may differ across jurisdictions, Starbrix, its affiliates, and Service Providers are committed to protecting personal data in accordance with this Privacy Policy, industry standards, and appropriate lawful mechanisms and contractual terms ensuring adequate data protection, regardless of any varying legal requirements in the jurisdiction of transfer.

Starbrix International Ltd is headquartered in Finland, a jurisdiction considered by the European Commission, the UK Secretary of State, and the Swiss Federal Data Protection and Information Commissioner (FDPIC) to offer an adequate level of protection for personal data of individuals residing in EU Member States, the UK, and Switzerland. We transfer data from the European Economic Area (EEA), the UK, and Switzerland to Finland based on this adequacy determination.

For data transfers from the EEA, the UK, and Switzerland to countries without an adequate level of data protection, we and relevant data exporters/importers have entered into Standard Contractual Clauses approved by the European Commission, the UK Information Commissioner’s Office (ICO), and the Swiss FDPIC.

Please note that when Starbrix.app processes personal data on behalf of a Customer, such data (included in their Customer Data) is processed according to agreements such as our  Terms of Service  and  Data Processing Addendum.

Data Retention: We retain personal data for as long as necessary to maintain our relationship, provide Services, comply with legal and contractual obligations, and protect against potential disputes. Our data retention policy considers factors such as data nature, sensitivity, potential risks, processing purposes, and legal requirements. For inquiries about our data retention policy, please contact us at privacy@starbrix.app.

4. Data Disclosure

We may disclose personal data in various circumstances, including:

  • Service Providers: We engage third-party companies and individuals as "Service Providers" to perform services on our behalf or complementary to our own. These services encompass a range of functions, from hosting and server co-location to billing and payment processing, fraud detection, and cybersecurity. Our Service Providers may have access to personal data only as required for their specific roles and purposes in facilitating and enhancing our Services.
  • Business Partners: We collaborate with business partners, resellers, and distributors to explore growth opportunities and provide tailored experiences for our Customers and Users. In such cases, relevant contact and usage details may be disclosed to these Partners to enable engagement for mutual benefit. Please note that engagements beyond the scope of our Services may be governed by the Partner's terms and privacy policy.
  • Third-party Applications: With your permission, we may disclose personal data to providers of third-party applications integrated into your Account or event organizers and sponsors for relevant communication or promotional purposes.
  • Account Ownership: Your personal data, including User information and activity within the Services, may be disclosed to the Customer owning the Organization Account to which you are subscribed and other Users within that Organizaton Account.
  • Integration with Third-party Services: Integration of your Account with third-party Services may involve the disclosure of relevant data. We do not receive or store passwords for these Services, but require API keys for integration. If you prefer not to disclose data to third-party Services, please contact your Organization Account Owner.
  • Public Reviews and Feedback: Public reviews or feedback submitted may be stored and presented publicly on our Sites and Services. Invitations to use the Services may be sent using the contact information provided by you.
  • Public Forums: Information shared on public forums may be read and used by others accessing these Sites. Your posts and profile information may remain visible even after termination of your User Profile.
  • Legal Requirements and Investigations: We may disclose personal data in response to legal requirements, such as subpoenas or court orders, or to investigate and prevent illegal activity or fraud.
  • Protection of Rights and Safety: Disclosure may occur if we believe it will protect the rights, property, or safety of Starbrix, our Users or Customers, or the general public.
  • Internal and Control Changes: Personal data may be disclosed internally within our group of companies or in the event of a change in control, such as a merger or acquisition.

Additionally, we may disclose personal data with your explicit approval, if legally obligated, or if rendered non-personal and anonymous.

5. Cookies and Tracking Technologies

Our Sites and Services, including some of our Service Providers, utilize various technologies such as "cookies," anonymous identifiers, pixels, and container tags. These tools are employed to facilitate the delivery and monitoring of our Services, ensure their proper functioning, analyze performance and marketing activities, and personalize user experiences.

While certain cookies and similar files may temporarily reside on your device, we prioritize user privacy and data protection, and any personal data stored, such as IP addresses provided by Prospects, Users, or Technology Partners, is handled with care.

Most browsers offer settings to manage cookies, providing options to accept, notify, block, or remove them. You can configure your browser settings according to your preferences to control cookie behavior.

6. Communications

In our communication strategy, we utilize various channels such as email, phone, SMS, and notifications to engage with you.

  • Services Communications: You can expect to receive essential updates about our Services, including notifications about changes, billing matters, login attempts, or password resets. These communications are crucial for ensuring your seamless experience with our platform. Additionally, other Users within your Organization Account may also reach out to you regarding Service-related matters. Please note that certain communications integral to your Service usage, such as password resets or billing notices, cannot be opted out of.
  • Promotional Communications: We may inform you about new features, events, special opportunities, or other valuable information related to your role as a Customer, User, Prospect, or Technology Partner. These notifications may be delivered through various channels, including phone, mobile, email, or through our marketing campaigns on different platforms. If you prefer not to receive promotional communications, you can opt out at any time by contacting us at privacy@starbrix.app or by following the opt-out instructions provided in the promotional messages you receive.

7. Data Security

To ensure the security of the personal data entrusted to us, we implement industry-standard physical, procedural, and technical security measures, including encryption where appropriate. However, it is crucial to acknowledge that despite our diligent efforts, we cannot offer an absolute guarantee of protection for personal data stored with us or with any third parties, as detailed in the Data Disclosure section above.

8. Data Subject Rights

If you wish to exercise your privacy rights under applicable law, including the EU or UK GDPR or Swiss regulations, such as the right to access specific pieces of personal data collected, categories of personal data collected, categories of sources from whom the personal data was collected, purpose of collecting personal data, categories of third parties with whom we have shared personal data, to request rectification or erasure of your personal data held with Starbrix.app, or to restrict or object to the processing of such personal data (including the right to direct us not to sell your personal data to third parties now or in the future), or to obtain a copy or port such personal data, or the right to equal Services and prices (e.g., freedom from discrimination), please contact us via email at privacy@starbrix.app. If you are a GDPR-protected individual, you also have the right to lodge a complaint with the relevant supervisory authority in the EEA or the UK, as applicable.

You may appoint an authorized agent, either in writing or through a power of attorney, to request to exercise your privacy rights on your behalf. The authorized agent can submit a request to exercise these rights by emailing us. In such cases, we may request further information to verify such power of attorney and authorization.

Please note that when you request us to exercise any of your rights under this Privacy Policy or applicable law, we may provide instructions on how to fulfill your request independently through your User Account settings, refer you to your Organization Account Owner, or require additional information and documents, including certain personal data and credentials, to process your request properly (e.g., to authenticate and validate your identity so that we can identify the relevant data in our systems and, where necessary, better understand the nature and scope of your request). Such additional information will then be retained by us for legal purposes (e.g., as proof of the identity of the person submitting the request and how each request was handled), in accordance with the Data Location & Retention section above. We may redact any personal or confidential data related to others from the data we make available to you.

9. Data Controller/Processor

Certain data protection laws and regulations, such as the GDPR or the CCPA, typically distinguish between two main roles for parties processing personal data: the “data controller” (or under the CCPA, “business”), who determines the purposes and means of processing; and the “data processor” (or under the CCPA, “service provider”), who processes such data on behalf of the data controller (or business). Below we explain how these roles apply to our Services, to the extent that such laws and regulations apply.

Starbrix acts as the “data controller” for the personal data of its Prospects, Users, Technology Partners, and Customers, as detailed in Section Data Collection & Processing above. Accordingly, we assume the responsibilities of a data controller (solely to the extent applicable under law), as outlined in this Privacy Policy.

Starbrix serves as the “data processor” for personal data contained in Customer Data, as submitted by our Organization Customers and their Users to their Accounts documents. We process such data on behalf of our Customer (who is the “data controller” of such data) and in accordance with its reasonable instructions, subject to our Terms, our  Data Processing Addendum  (to the extent applicable), and  Terms of Service.

Our Customers are solely responsible for determining whether and how they wish to use our Services, and for ensuring that all individuals using the Services on the Customer’s behalf or at their request, as well as all individuals whose personal data may be included in Customer Data processed through the Services, have been provided with adequate notice and given informed consent to the processing of their personal data, where such consent is necessary or advised, and that all legal requirements applicable to the collection, use, or other processing of data through our Services are fully met by the Customer. Our Customers are also responsible for handling data subject rights requests under applicable law, by their Users and other individuals whose data they process through the Services.

If you would like to make any requests or queries regarding personal data we process as a data processor on our Customer’s behalf, including accessing, correcting, or deleting your data, please contact the Customer’s Organization Account Owner directly.

10. Additional Notices

Updates and Amendments: We reserve the right to update and amend this Privacy Policy periodically by posting an amended version on our Services. The revised version will take effect on the date of publication. When we make significant changes to this Privacy Policy, we will provide notice as appropriate under the circumstances, such as by prominently displaying a notice within the Services or sending an email. Your continued use of the Services after the changes have been implemented will signify your acceptance of the modifications.

Third Party Websites and Services: Our Services contain links to third-party websites and services, as well as integrations with Third Party Services (as defined in the Terms). These third-party websites, services, and Third Party Services, along with any information you process, submit, transmit, or otherwise use with or through them, are governed by their respective terms and privacy policies, not by this Privacy Policy. We advise you to carefully review the terms and privacy policies of such third-party websites, services, and Third Party Services.

Our Services are not directed to children under the age of 16: We do not knowingly collect personal data from children and do not intend to do so. If we become aware that a person under the age of 16 is using the Services, we will take steps to prohibit and block such usage and promptly delete any personal data associated with such a child. If you believe that we may have collected such data, please contact us at privacy@starbrix.app.

Questions, Concerns, or Complaints: If you have any comments or questions about our privacy policy or practices, concerns regarding your personal data held with us, or wish to lodge a complaint about the processing of your personal data by Starbrix, please reach out to Starbrix.app’s support at privacy@starbrix.app.

‍

Updated: 01.09.2026

Data Processing Addendum

This Data Processing Addendum ("DPA") constitutes an integral component of the agreement ("Agreement") between you, the Customer (referred to as "you", "your", or "Customer"), and StarBrix International Ltd ("Starbrix," "Starbrix.app," "us," "we," or "our"), governing the utilization of Starbrix's services. It is incorporated by reference into Starbrix's Terms of Service and Privacy Policy. This DPA delineates the terms governing the Processing of Personal Data by Starbrix solely on behalf of the Customer. The term "Parties" collectively refers to both you and Starbrix, with each being referred to as a "Party." Any capitalized terms not defined in this DPA shall carry the meanings ascribed to them in the Terms of Service. By availing yourself of the Services, the Customer acknowledges and accepts the terms set forth in this DPA. By doing so, you affirm that you possess the full authority to legally bind the Customer to this DPA. If you lack the authority to bind the Customer or any other entity, or if you cannot or do not agree to comply with and be bound by this DPA, please refrain from providing Personal Data to us. In the event of any conflict between specific provisions of this DPA and those of the Terms of Service, the provisions of this DPA shall take precedence over conflicting provisions of the Terms of Service, solely concerning the Processing of Personal Data.

1. Definitions

Affiliate: Refers to any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. For the purpose of this definition, “control” means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.

Authorized Affiliate: Denotes any of Customer's Affiliates explicitly permitted to use the Services as per the Agreement between Customer and Starbrix but has not signed its own Agreement with Starbrix and does not fall under the definition of “Customer” as outlined in the Agreement.

CCPA: Abbreviation for the California Consumer Privacy Act of 2018, along with its implementing regulations, subject to amendments from time to time.

The terms Controller, Member State, Processor, Processing, and Supervisory Authority shall hold the same meaning as defined in the GDPR. Similarly, the terms Business, Business Purpose, Consumer, and Service Provider shall retain the same meaning as outlined in the CCPA. For clarity within this DPA, “Controller” shall also encompass “Business,” and “Processor” shall also include “Service Provider,” to the extent that the CCPA applies. Likewise, Processor’s Sub-processor shall refer to the concept of Service Provider.

Data Protection Laws: Encompass all applicable and binding privacy and data protection laws and regulations, including those of the European Union, the European Economic Area and their Member States, Switzerland, the United Kingdom, Canada and the United States of America. This includes the GDPR, the UK GDPR, and the CCPA, applicable to, and in effect at the time of, the Processing of Personal Data under this agreement.

Data Subject: Refers to the individual to whom Personal Data pertains.

GDPR: Abbreviation for the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons concerning the Processing of Personal Data and on the free movement of such data.

Personal Data or Personal Information: Encompasses any information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, to or with an identified or identifiable natural person or Consumer. This data is processed by Starbrix solely on behalf of Customer under this DPA and the Agreement.

Services: Denotes the Starbrix cloud-based services, including platforms, products, services, applications, application programming interface (“API”), tools, and any ancillary or supplementary Starbrix products and services (including Upgrades as defined in the Agreement), offered online and via mobile application (“Platform”), and any other services provided to Customer by Starbrix under the Agreement.

Security Documentation: Refers to the security documentation, updated periodically, detailing the technical and organizational measures adopted by Starbrix applicable to the Processing of Personal Data under the Agreement and this DPA. This documentation is accessible via www.starbrix.app/security or as otherwise made reasonably available to Customer by Starbrix.

Sensitive Data: Indicates Personal Data protected under special legislation requiring unique treatment, such as “special categories of data,” “sensitive data,” or similar terms under applicable Data Protection Laws. This may include, but is not limited to:

  • Social security number, tax file number, passport number, driver’s license number, or similar identifiers;
  • Financial or credit information, credit or debit card number;
  • Information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, or biometric data for the purpose of uniquely identifying a natural person, data concerning a person’s health, sex life, or sexual orientation, or data relating to criminal convictions and offenses;
  • Personal Data relating to children; and/or
  • Account passwords in unhashed form.

Standard Contractual Clauses: Refers to:

  • In respect of transfers of Personal Data subject to the GDPR, the Standard Contractual Clauses between controllers and processors, and between processors and processors, as approved by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
  • In respect of transfers of Personal Data subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses of 21 March 2022 (“IDTA”); and
  • In respect of transfers subject to the Federal Act on Data Protection (as revised as of 25 September 2020), the terms set forth in Annex IV of the EU SCCs (“Switzerland Addendum”).

Sub-processor: Denotes any third party carrying out specific Processing activities of Personal Data under the instruction of Starbrix.

UK GDPR: Refers to the Data Protection Act 2018, as well as the GDPR as it forms part of the law of England and Wales, Scotland, and Northern Ireland. This includes amendments by the Data Protection, Privacy and Electronic Communications Amendments etc. (EU Exit) Regulations 2019 (SI 2019/419).

2. Processing of Personal Data

Roles of the Parties: The Parties acknowledge and agree that concerning the Processing of Personal Data solely by Starbrix on behalf of Customer:

  • Customer serves as the Controller of Personal Data, and
  • Starbrix acts as the Processor of such Personal Data.

The terms “Controller” and “Processor” below represent Customer and Starbrix, respectively.

Customer’s Obligations: Customer, in utilizing the Services, and in providing instructions to the Processor, shall adhere to Data Protection Laws, the Agreement, and this DPA. Customer shall establish and maintain all necessary legal bases to collect, Process, and transfer Personal Data to the Processor. This includes authorizing the Processing activities conducted by the Processor on Customer’s behalf in accordance with the Agreement and this DPA, including the pursuit of a Business Purpose.

Processor’s Processing of Personal Data: The Processor shall Process Personal Data for the following purposes:

  • in accordance with the Agreement and this DPA;
  • in connection with its provision of the Services;
  • to comply with Customer’s reasonable and documented instructions, consistent with the terms of the Agreement and this DPA;
  • to share or receive Personal Data from third parties as per Customer’s instructions and/or pursuant to Customer’s use of the Services;
  • rendering Personal Data into Anonymous Information; and
  • as required by applicable laws or competent authorities, provided Processor informs Customer promptly unless legally prohibited.

Processor shall promptly notify Customer if, in Processor’s reasonable opinion, an instruction by Customer for Personal Data Processing infringes Data Protection Laws, unless prohibited by such laws. Processor is not obligated to assess whether Customer's instructions breach any Data Protection Laws.

Details of Processing: The subject-matter of Processing Personal Data by Processor is the performance of Services pursuant to the Agreement and this DPA.

Sensitive Data: The Parties agree that the Services aren't intended for Processing Sensitive Data. If Customer intends to Process Sensitive Data using the Services, it must first obtain explicit prior written consent from Starbrix and fulfill any additional requirements.

CCPA Standard of Care; No Sale or Sharing of Personal Information: Processor acknowledges it doesn't receive or process Personal Information as consideration for services provided under the Agreement or this DPA. Processor confirms understanding of CCPA rules and agrees not to sell or share any Personal Information Processed hereunder without Customer’s consent or instruction. Processor shall process Personal Information only for specified purposes and in compliance with applicable CCPA sections, refraining from unauthorized use or combination of Personal Information. Processor shall notify Customer if it determines it can no longer meet its CCPA obligations.

3. Data Subject Requests

If the Processor receives a Data Subject Request from a Data Subject or Consumer to exercise their rights (to the extent available to them under applicable Data Protection Laws), including but not limited to access, rectification, restriction of Processing, erasure, data portability, objection to Processing, opting out of the sale of Personal Information, or not being subject to automated individual decision making, and not being discriminated against (“Data Subject Request”), the Processor shall promptly notify the Customer or direct the Data Subject or Consumer to the Customer.

Considering the nature of the Processing, the Processor shall assist the Customer, to the extent feasible and reasonable, in facilitating a response to a Data Subject Request. The Processor may direct Data Subjects or Consumers to the Customer’s Organization Account Owner for handling such requests or provide guidance on utilizing the self-exercising features available within the Starbrix.app.

4. Confidentiality

The Processor shall ensure that all its personnel and contractors involved in the Processing of Personal Data are bound by confidentiality agreements or are otherwise subject to statutory confidentiality obligations.

5. Sub-processors

Appointment of Sub-processors:

Customer acknowledges and agrees that:

  • Processor's Affiliates may serve as Sub-processors; and
  • Processor and its Affiliates may engage third-party Sub-processors in connection with the provision of the Services.

As of the Effective Date, Customer grants Processor general written authorization to engage the Sub-processors, listed on the Sub-processor's Page available at www.starbrix.app/legal#sub-processors ("Sub-processor's Page"), which are currently utilized by Processor for processing Personal Data.

The Sub-processor's Page provides a subscription mechanism for notifications regarding the engagement of new Sub-processors or the replacement of existing ones ("Sub-processor Notice"). Customer acknowledges and agrees to subscribe to this mechanism upon entering into this DPA. Notifications sent through this mechanism fulfill Processor's obligation to inform Customer of new or replacement Sub-processors.

Objection to Sub-processors:

Upon publication of a new Sub-processor Notice, Customer may reasonably object to Processor's use of a new or replacement Sub-processor for reasons concerning the protection of Personal Data intended to be Processed by such Sub-processor. Customer must promptly submit objections in writing to privacy@starbrix.app within seven (7) days following publication. If no objection is raised within this period, Customer is deemed to have accepted the new Sub-processor. If Customer objects, Processor will make reasonable efforts to provide alternative solutions to avoid Processing by the objected-to Sub-processor. If unable to provide a satisfactory resolution within thirty (30) days, Customer may terminate the Agreement and this DPA with respect to affected Services by providing written notice to Processor. Any outstanding amounts under the Agreement prior to termination shall be paid to Processor. During the objection process, Processor may temporarily halt Processing of affected Personal Data and/or suspend access to Services. Customer shall have no further claims against Processor arising from termination under this paragraph.

Agreements with Sub-processors:

Processor or its Affiliate has executed written agreements with existing Sub-processors and shall do the same for new Sub-processors. These agreements contain data protection obligations similar to those outlined in this DPA, particularly regarding the implementation of appropriate technical and organizational measures to meet GDPR requirements. If a Sub-processor fails to fulfill its data protection obligations, Processor remains accountable to Customer for the Sub-processor's performance.

6. Security And Audits

Controls for the Protection of Personal Data:

Processor shall maintain industry-standard technical and organizational measures to safeguard Personal Data processed under this agreement. These measures include protection against unauthorized or unlawful Processing, accidental destruction, loss, alteration, or damage, as well as unauthorized access to or disclosure of Personal Data, ensuring the confidentiality and integrity of Personal Data. Upon Customer’s reasonable request and at Customer’s expense, Processor will assist Customer in ensuring compliance with GDPR, considering the nature of the Processing and available information.

Audits and Inspections:

Upon Customer’s written request with a 14-day notice at reasonable intervals (but not exceeding once every 12 months), and subject to strict confidentiality agreements, Processor shall provide non-competing Customer or Customer’s independent third-party auditor with necessary information to demonstrate compliance with this DPA. Processor may fulfill this obligation through questionnaire-based audits, providing attestations, certifications, or summaries of audit reports from accredited third-party auditors. Information from audits shall be used solely by Customer to assess Processor’s compliance and shall not be disclosed to third parties without Processor’s consent. Customer shall transfer all relevant records to Processor upon request.

Conduct of Audits:

Customer and its auditors shall minimize any disruption to Processor’s operations, premises, equipment, personnel, and business during audits or inspections.

Limitation of Audit Rights:

The audit rights provided herein shall apply only if the Agreement does not grant Customer audit rights meeting Data Protection Laws requirements. If Standard Contractual Clauses apply, this section does not alter or modify them nor affect Supervisory Authority or Data Subject rights under them.

7. Data Incident Management And Notification

Incident Response:

Processor maintains internal security incident management policies and procedures. In compliance with applicable Data Protection Laws, Processor shall promptly notify Customer upon becoming aware of any accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to Personal Data Processed by Processor on behalf of the Customer (“Data Incident”). Processor shall endeavor to identify and take necessary and reasonable steps to remediate and/or mitigate the cause of such Data Incident within Processor’s reasonable control. These obligations do not apply to Data Incidents caused by Customer, its Users, or anyone using the Services on Customer’s behalf.

Communication and Disclosure:

Customer agrees not to disclose, release, or publish any findings, admission of liability, communication, notice, press release, or report regarding any Data Incident that directly or indirectly identifies Processor without prior written approval from Processor. This includes legal proceedings, notifications to regulatory or supervisory authorities, or affected individuals, unless compelled to do so by applicable Data Protection Laws. In such cases, Customer shall provide Processor with reasonable prior written notice to allow Processor to object to such disclosure. If disclosure is mandated by law, Customer shall limit the scope of disclosure to the minimum extent required.

8. Return and Deletion of Personal Data

Upon termination of the Agreement and discontinuation of the Services, Processor shall, at the Customer’s discretion (as indicated through the Platform or in written notification to Processor), either delete or return to the Customer all Personal Data Processed on behalf of the Customer, as outlined in the Agreement. This action shall be taken upon Customer's notice. However, Processor may be required or permitted by applicable laws to retain certain Personal Data.

9. Cross-border Data Transfers

9.1 Transfers to Countries with Adequate Data Protection:

Personal Data may be transferred from EU Member States, Norway, Iceland, Liechtenstein (collectively, “EEA”), Switzerland, and the United Kingdom (“UK”) to countries with an adequate level of data protection, as determined by Adequacy Decisions issued by relevant authorities. This includes mechanisms and frameworks similarly approved by the EEA, Switzerland, and/or the UK, without requiring additional safeguards. Notably, this encompasses the European Commission’s adequacy decision of 10 July 2023, establishing the EU-US Data Privacy Framework.

9.2 Direct Transfers from EEA, Switzerland, and UK:

If Processor directly transfers Personal Data from the EEA, Switzerland, or the UK to countries lacking Adequacy Decisions, and alternative compliance mechanisms are not utilized, the following terms apply:

  • For transfers from the EEA: EU Standard Contractual Clauses (SCCs) shall apply.
  • For transfers from the UK: UK Addendum terms shall apply.
  • For transfers from Switzerland: Switzerland Addendum terms shall apply.

Additional safeguards outlined in Annex V of the EU SCCs apply to these transfers.

Onward Transfers from EEA, Switzerland, and UK:

When Processor transfers Personal Data from the EEA, UK, or Switzerland to authorized Sub-processors in countries lacking Adequacy Decisions, the appropriate compliance mechanisms shall be employed. This includes EU SCCs, the International Data Transfer Addendum, and/or SCCs adjusted per the Swiss Federal Data Protection and Information Commissioner’s guidance.

9.3 Transfers from Other Jurisdictions:

If Processor receives Personal Data from jurisdictions requiring specific compliance mechanisms for lawful transfer, Customer shall notify Processor. The Parties may then amend this DPA accordingly.

10. Authorized Affiliates

Contractual Relationship: By executing this DPA, Customer acknowledges that it enters into the agreement not only on its own behalf but also, where applicable, on behalf of its Authorized Affiliates. In doing so, each Authorized Affiliate agrees to adhere to the obligations outlined in this DPA. If Processor processes Personal Data on behalf of these Authorized Affiliates, they are deemed Controllers of such data. Authorized Affiliates must comply with the terms and conditions of the Agreement and this DPA. Any violation of these terms by an Authorized Affiliate is considered a violation by the Customer.

Communication: Customer retains responsibility for coordinating all communication with Processor as outlined in the Agreement and this DPA. Customer is authorized to engage in all communications relating to this DPA on behalf of its Authorized Affiliates.

11. Other provisions

Data Protection Impact Assessment and Prior Consultation: Upon Customer’s reasonable request, Processor shall provide Customer with reasonable cooperation and assistance, at Customer’s expense, to fulfill Customer’s obligations under the GDPR or the UK GDPR regarding data protection impact assessments related to Customer’s use of the Services. Processor shall offer assistance to the extent that Customer does not have access to the relevant information and it is available to Processor. Additionally, Processor shall, at Customer’s expense, provide reasonable assistance to Customer in cooperating or consulting with the Supervisory Authority as required under the GDPR or the UK GDPR.

Modifications: Either Party may request variations to this DPA with at least forty-five (45) calendar days' prior written notice if necessitated by changes in applicable Data Protection Laws to ensure compliance. The Parties shall endeavor to accommodate such modifications and negotiate in good faith to address the requirements of the law promptly. Processor reserves the right to amend this DPA without notice for non-material changes. However, if any material adverse changes are made affecting Customer’s rights or Processor’s obligations, Processor will notify Customer via the site, Platform, and/or email.

‍

Updated: 01.09.2026

Sub-processors

Service Company Used for Homepage Processed data
Heroku runtime Heroku Inc. Cloud hosting provider (Server infrastructure) https://www.heroku.com All data
MongoDB Atlas MongoDB Inc. Cloud hosting provider (Database) https://www.mongodb.com All data
Cloudflare CDN Cloudflare Inc. Content delivery network provider https://www.cloudflare.com All data
Email SMTP service Sendgrid Inc. (Sendgrid) Email service provider https://sendgrid.com Data required to send email notifications to the user

Updated: 01.09.2026

Open source list

Package License Link
axios@^0.21.1MIThttps://axios-http.com
clsx@^1.1.1MIThttps://www.npmjs.com/package/clsx
compression@^1.7.4MIThttps://www.npmjs.com/package/compression
express@^4.17.1MIThttp://expressjs.com/
lodash@^4.17.21MIThttps://lodash.com/
react@^17.0.1MIThttps://reactjs.org/
react-dom@^17.0.1MIThttps://reactjs.org/
react-router-dom@^5.2.0MIThttps://github.com/remix-run/react-router
typescript@^4.0.3Apache-2.0https://www.typescriptlang.org/
@types/node@^12.0.0MIThttps://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/node
@types/react@^16.9.53MIThttps://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/react
@types/react-dom@^16.9.8MIThttps://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/react-dom
prettier@^2.2.1MIThttps://prettier.io
@sendgrid/mail@^7.4.5MIThttps://sendgrid.com
chalk@^4.1.0MIThttps://www.npmjs.com/package/chalk
compressible@^2.0.18MIThttps://www.npmjs.com/package/compressible
debug@^4.3.4MIThttps://www.npmjs.com/package/debug
dotenv@^8.2.0BSD-2-Clausehttps://www.npmjs.com/package/dotenv
nanoid@^3.1.20MIThttps://www.npmjs.com/package/nanoid
rimraf@^3.0.2ISChttps://www.npmjs.com/package/rimraf
typescript@^4.1.3Apache-2.0https://www.typescriptlang.org/
@types/debug@^4.1.8MIThttps://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/debug
@types/node@^14.14.16MIThttps://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/node
@typescript-eslint/eslint-plugin@^4.11.0MIThttps://github.com/typescript-eslint/typescript-eslint.git
@typescript-eslint/parser@^4.11.0BSD-2-Clausehttps://github.com/typescript-eslint/typescript-eslint.git
eslint@^7.16.0MIThttps://eslint.org
@emotion/react@^11.11.4MIThttps://github.com/emotion-js/emotion/tree/main/packages/react
@emotion/server@^11.11.0MIThttps://emotion.sh
@emotion/styled@^11.11.0MIThttps://github.com/emotion-js/emotion/tree/main/packages/styled
@mui/icons-material@^5.15.11MIThttps://mui.com/material-ui/material-icons/
@mui/material@^5.15.11MIThttps://mui.com/material-ui/
@remix-run/css-bundle@^2.8.0MIThttps://remix.run
@remix-run/node@^2.8.0MIThttps://github.com/remix-run/remix
@remix-run/react@^2.8.0MIThttps://github.com/remix-run/remix
@remix-run/serve@^2.8.0MIThttps://github.com/remix-run/remix
@sendgrid/mail@^8.1.1MIThttps://sendgrid.com
crypto-js@^4.2.0MIThttp://github.com/brix/crypto-js
dotenv@^16.4.5BSD-2-Clausehttps://www.npmjs.com/package/dotenv
flag-icons@^7.2.0MIThttps://github.com/lipis/flag-icons
isbot@^4.1.0Unlicensehttps://isbot.js.org
react@^18.2.0MIThttps://reactjs.org/
react-dom@^18.2.0MIThttps://reactjs.org/
remix-utils@^7.5.0MIThttps://github.com/sergiodxa/remix-utils
tiny-invariant@^1.3.3MIThttps://github.com/alexreardon/tiny-invariant.git
zod@^3.22.4MIThttps://zod.dev
@remix-run/dev@^2.8.0MIThttps://remix.run
@types/react@^18.2.20MIThttps://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/react
@types/react-dom@^18.2.7MIThttps://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/react-dom
@typescript-eslint/eslint-plugin@^6.7.4MIThttps://github.com/typescript-eslint/typescript-eslint.git
@typescript-eslint/parser@^6.7.4BSD-2-Clausehttps://github.com/typescript-eslint/typescript-eslint.git
eslint@^8.38.0MIThttps://eslint.org
eslint-import-resolver-typescript@^3.6.1ISChttps://www.npmjs.com/package/eslint-import-resolver-typescript
eslint-plugin-import@^2.28.1MIThttps://github.com/import-js/eslint-plugin-import
eslint-plugin-jsx-a11y@^6.7.1MIThttps://github.com/jsx-eslint/eslint-plugin-jsx-a11y
eslint-plugin-react@^7.33.2MIThttps://github.com/jsx-eslint/eslint-plugin-react
eslint-plugin-react-hooks@^4.6.0MIThttps://reactjs.org/
tsx@^4.7.2MIThttps://www.npmjs.com/package/tsx
typescript@^5.1.6Apache-2.0https://www.typescriptlang.org/
vite@^5.1.6MIThttps://vitejs.dev
vite-tsconfig-paths@^4.3.2MIThttps://www.npmjs.com/package/vite-tsconfig-paths
Company
About usPrivacy PolicyTerms of Service
PRODUCTS
Starbrix CoreStarbrix Flex
help
Contact supportContact salesBook a demo
Copyright © 2026 Starbrix International Ltd