Star IT Services
Legal & Governance

UK GDPR & Privacy Policy

Our commitment to transparency, data integrity, and strict compliance under the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018.

Data Protection & Privacy Overview

Effective Date: Last revised September 2026

Star IT Services Ltd ("we", "us", "our") is committed to protecting the privacy and confidentiality of personal and enterprise information entrusted to us. As a provider of Managed IT, Cyber Security, Cloud Solutions, and Bespoke Software, we maintain rigorous technical and organisational measures aligned with ISO/IEC 27001 standards and the UK General Data Protection Regulation (UK GDPR).

01Who We Are & Data Controller Details

For the purposes of the UK GDPR and the Data Protection Act 2018, the data controller is:

Star IT Services Ltd

Registered Office: 2C, Pennine House, 28 Leman St, London E1 8ER, United Kingdom

Data Protection Officer / Inquiries: info@staritservices.net

Phone: +44 (0) 20 8095 4444

02Personal Data We Collect

We may collect, use, store, and transfer distinct categories of personal information:

  • Identity & Contact Data: First name, last name, job title, corporate employer, business email address, direct telephone number.
  • Technical & Support Ticket Data: IP addresses, browser specifications, diagnostic machine identifiers, and helpdesk communications generated when you request service desk or desktop assistance.
  • Transactional & Contractual Data: Billing addresses, purchase order details, bank details for invoicing, and service engagement history.

03Lawful Bases for Processing

Under UK GDPR Article 6, we process your personal data under the following legal bases:

Contractual Performance

To fulfill managed IT service agreements, meet service commitments, configure cloud environments, and deliver support.

Legitimate Business Interests

To secure client network endpoints, monitor cyber vulnerabilities, and prevent fraud.

Legal Obligation

To satisfy statutory tax, accounting, and compliance mandates required by UK regulatory authorities.

Consent

Where you have explicitly opted in to receive technical whitepapers or scheduled cybersecurity threat advisories.

04Information Security & ISO 27001 Controls

We employ defense-in-depth technical safeguards to protect all data in our custody against accidental loss, unauthorized destruction, alteration, or disclosure:

  • End-to-end cryptographic encryption in transit (TLS 1.3) and at rest (AES-256).
  • Strict Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) across all administration consoles.
  • Isolated client environments preventing cross-tenant data exposure.
  • Regular third-party vulnerability audits and internal incident simulation drills.

05Data Retention

We only retain personal information for as long as necessary to fulfill the purposes for which it was collected, including for satisfying legal, regulatory, tax, accounting, or reporting requirements. Helpdesk ticketing records and network access logs are typically retained for 6 years in accordance with standard UK corporate audit obligations.

06Your Legal Rights Under UK GDPR

As a data subject located in the UK, you possess statutory rights regarding your personal data:

Right to Access: Request a copy of your personal data held by us.Right to Rectification: Request correction of inaccurate information.Right to Erasure: Request deletion of data where no legal ground persists.Right to Restrict Processing: Suspend processing in specific scenarios.Right to Portability: Transfer data to another provider in machine-readable format.Right to Object: Object to processing based on legitimate interests or direct marketing.

To exercise any of these rights, please contact our Data Protection team at info@staritservices.net. We respond to all verified requests within 30 calendar days.

07Right to Lodge a Complaint

If you have concerns regarding our data handling, we invite you to reach out to us directly so we can resolve the matter promptly. You also maintain the right to lodge a formal complaint with the UK supervisory authority:

Information Commissioner's Office (ICO)

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Helpline: 0303 123 1113 | Website: ico.org.uk

Have Questions About Your Corporate Privacy?

Our compliance officers are based in our London headquarters.

Contact Legal Team