Legal
What personal data we hold, why we hold it, who sees it, how long we keep it, and what you can ask us to do about it.
Last updated 25 July 2026 · Version 3.0
StellarStart Global Limited, registered in England and Wales, is the controller for personal data described in this policy. Where we process personal data contained in client files on a client’s instructions, we may act as a processor for that data, in which case the terms of our data processing agreement with that client govern.
Data protection contact: privacy@stellarstart.global.
| Purpose | Data used | Lawful basis (UK/EU GDPR) |
|---|---|---|
| Responding to enquiries and scoping a matter | Enquiry and contact data | Legitimate interests; steps prior to entering a contract |
| Providing services under an engagement | Client and engagement data | Performance of a contract |
| Identity, conflict, sanctions and AML checks | Verification data | Legal obligation; legitimate interests |
| Invoicing, accounting and tax records | Billing data | Legal obligation |
| Sending the newsletter | Email address | Consent |
| Analytics and site improvement | Technical and usage data | Consent (analytics cookies) |
| Site security and abuse prevention | Server log data | Legitimate interests |
| Establishing, exercising or defending claims | Any relevant data | Legitimate interests; legal claims |
Where we rely on legitimate interests, we have assessed that our interest in operating and protecting the practice does not override your rights and freedoms. You can ask us for that assessment.
Some matters, particularly employment and dispute work, involve special category data such as health information, or data about criminal allegations. We process it only where necessary for the matter and where an additional condition applies, most commonly that the processing is necessary for legal claims or advice. We do not ask for special category data at the enquiry stage and would prefer you did not include it in a first message.
We do not sell personal data and we do not share it for cross-context behavioural advertising.
We operate across more than 24 countries, so personal data may be transferred outside the UK and the EEA. Where it is, we rely on an adequacy decision where one exists, and otherwise on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the EU SCCs, supported by a transfer risk assessment and additional safeguards where the assessment calls for them. You can request details of the mechanism used for a specific transfer.
| Record type | Retention period |
|---|---|
| Enquiries that do not become engagements | 12 months from last contact |
| Client matter files | 7 years from closure of the matter, longer where a limitation period or registry requirement demands it |
| Identity and AML verification records | 5 years from the end of the business relationship |
| Accounting and tax records | 6 years from the end of the relevant financial year |
| Newsletter subscription records | Until you unsubscribe, plus 12 months to evidence consent |
| Server and security logs | 90 days |
| Unsuccessful job applications | 6 months, unless you agree to a longer period |
We apply access controls on a need-to-know basis, encryption in transit and at rest for hosted systems, multi-factor authentication on business accounts, device encryption, supplier due diligence, and staff confidentiality undertakings and training. No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours where required, and tell you where the risk to you is high.
Subject to the conditions in applicable law, you can ask us to:
We respond within one month, and will tell you if we need an extension for a complex request. We do not charge unless a request is excessive or repetitive. Some rights are limited where data is subject to legal professional privilege or a confidentiality obligation to another client, and we will explain the reason if we have to rely on an exemption.
To exercise a right, write to privacy@stellarstart.global.
Where India’s Digital Personal Data Protection Act, 2023 applies to our processing, we act as a Data Fiduciary. You have the right to access a summary of your personal data and our processing, to correction and erasure, to nominate another individual to exercise your rights in the event of death or incapacity, and to a readily available grievance redressal mechanism. Where we rely on consent, our notice sets out the purposes in plain language and you may withdraw consent at any time with the same ease as it was given. Grievances can be sent to privacy@stellarstart.global and will be acknowledged within seven days.
If you are a resident of California or another US state with a comprehensive privacy law, you may have the right to know what personal information we collect and disclose, to request deletion or correction, to obtain a portable copy, and to appeal a refusal. We do not sell personal information and do not share it for cross-context behavioural advertising, so no opt-out of sale or sharing is required. We will not discriminate against you for exercising a right. Requests can be made to privacy@stellarstart.global, and we will verify your identity before responding. An authorised agent may act for you with written permission.
Our services are directed at businesses and professionals. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.
Cookies and similar technologies are covered in our Cookie Policy, which explains what we set, what each one does, and how to change your choices.
We update this policy as our processing changes. The version in force is published here with its date. Where a change materially affects how we use data about you, we will take reasonable steps to tell you directly.
Contact us at privacy@stellarstart.global or through our contact page. We would like the chance to resolve a concern first, but you can complain to a supervisory authority at any time: the Information Commissioner’s Office in the UK, your local supervisory authority in the EEA, or the Data Protection Board of India, as applicable to you.