UK GDPR & Privacy Policy
Our commitment to transparency, data integrity, and strict compliance under the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018.
Data Protection & Privacy Overview
Effective Date: Last revised September 2026
Star IT Services Ltd ("we", "us", "our") is committed to protecting the privacy and confidentiality of personal and enterprise information entrusted to us. As a provider of Managed IT, Cyber Security, Cloud Solutions, and Bespoke Software, we maintain rigorous technical and organisational measures aligned with ISO/IEC 27001 standards and the UK General Data Protection Regulation (UK GDPR).
01Who We Are & Data Controller Details
For the purposes of the UK GDPR and the Data Protection Act 2018, the data controller is:
Star IT Services Ltd
Registered Office: 2C, Pennine House, 28 Leman St, London E1 8ER, United Kingdom
Data Protection Officer / Inquiries: info@staritservices.net
Phone: +44 (0) 20 8095 4444
02Personal Data We Collect
We may collect, use, store, and transfer distinct categories of personal information:
- Identity & Contact Data: First name, last name, job title, corporate employer, business email address, direct telephone number.
- Technical & Support Ticket Data: IP addresses, browser specifications, diagnostic machine identifiers, and helpdesk communications generated when you request service desk or desktop assistance.
- Transactional & Contractual Data: Billing addresses, purchase order details, bank details for invoicing, and service engagement history.
03Lawful Bases for Processing
Under UK GDPR Article 6, we process your personal data under the following legal bases:
Contractual Performance
To fulfill managed IT service agreements, meet service commitments, configure cloud environments, and deliver support.
Legitimate Business Interests
To secure client network endpoints, monitor cyber vulnerabilities, and prevent fraud.
Legal Obligation
To satisfy statutory tax, accounting, and compliance mandates required by UK regulatory authorities.
Consent
Where you have explicitly opted in to receive technical whitepapers or scheduled cybersecurity threat advisories.
04Information Security & ISO 27001 Controls
We employ defense-in-depth technical safeguards to protect all data in our custody against accidental loss, unauthorized destruction, alteration, or disclosure:
- End-to-end cryptographic encryption in transit (TLS 1.3) and at rest (AES-256).
- Strict Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) across all administration consoles.
- Isolated client environments preventing cross-tenant data exposure.
- Regular third-party vulnerability audits and internal incident simulation drills.
05Data Retention
We only retain personal information for as long as necessary to fulfill the purposes for which it was collected, including for satisfying legal, regulatory, tax, accounting, or reporting requirements. Helpdesk ticketing records and network access logs are typically retained for 6 years in accordance with standard UK corporate audit obligations.
06Your Legal Rights Under UK GDPR
As a data subject located in the UK, you possess statutory rights regarding your personal data:
To exercise any of these rights, please contact our Data Protection team at info@staritservices.net. We respond to all verified requests within 30 calendar days.
07Right to Lodge a Complaint
If you have concerns regarding our data handling, we invite you to reach out to us directly so we can resolve the matter promptly. You also maintain the right to lodge a formal complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113 | Website: ico.org.uk
Have Questions About Your Corporate Privacy?
Our compliance officers are based in our London headquarters.
