Legal & Privacy
Privacy Policy
Effective Date: September 3, 2026 · Last Updated: September 3, 2026
Starks Enterprise LLC (“Starks Enterprise,” “we,” “our,” or “us”) is an enterprise security engineering and advisory firm. We are committed to transparency and privacy in every engagement. This Privacy Policy details the types of information we collect, the purposes for which we use it, the third parties to whom it may be disclosed, the methods of disclosure, and our rigorous security safeguards.
1. Information Collected
We collect only the minimum personal, technical, and commercial information necessary to operate our website, respond to inquiries, execute security consultations, and provide AI agent build services.
A. Information You Voluntarily Provide
- Contact Information: When you submit a consultation request, questionnaire, or contact inquiry, we collect your full name, business email address, company or organization name, and optional details regarding your security project.
- Consultation & Project Requirements: Architecture notes, project scopes, technical requirements, and service questions you share to evaluate or initialize a consulting engagement.
- Customer Support Inquiries: Communications and records sent to our support channels ([email protected]).
B. Payment and Transaction Information
- Payment Card Data: All online payment processing is mediated directly by our third-party payment processor, Stripe, Inc. When you purchase consultation hours or services through Stripe Checkout, your cardholder data (card number, expiration date, CVV, and billing address) is submitted directly to Stripe via encrypted, hosted sessions. Starks Enterprise never stores, processes, or retains raw credit card numbers or security codes on our servers.
- Transaction Records: We receive and store transaction metadata from Stripe, including transaction ID, purchased service name, quantity/hours, payment status, timestamp, and customer email address to fulfill orders and issue invoices.
C. Automatically Collected Technical Data
- Server Logs & Telemetry: Standard network request logs including IP address, HTTP request method and path, browser user-agent, operating system, referring URL, and response status codes. These are used solely for rate limiting, system diagnostics, and defending against adversarial activity or denial-of-service attempts.
- Security Tokens & Session Identifiers: Minimal, cryptographically signed tokens stored locally in your browser (e.g. for administrative access or authentication) without cross-site tracking cookies.
2. Use of Information
We use the information we collect strictly for legitimate business, operational, and legal purposes, specifically:
- Service Delivery: To review, scope, schedule, and perform security engineering assessments, PAM/IAM implementations, cloud architecture evaluations, and custom AI agent engineering.
- Billing & Accounting: To process payments, verify transactions, deliver digital receipts, reconcile accounts, and maintain statutory financial records.
- Customer Support & Communication: To answer inquiries, provide project status updates, resolve technical issues, and deliver administrative notices.
- Platform Security & Fraud Prevention: To monitor system availability, detect unauthorized access, prevent abuse and automated attacks, and enforce service rate limits.
- Legal & Regulatory Compliance: To comply with applicable statutory, tax, commercial, and auditing obligations.
We do not engage in automated decision-making or profiling that produces legal or similarly significant effects concerning data subjects.
3. Parties to Whom Information Is Disclosed
Starks Enterprise LLC does not sell, rent, monetize, or trade your personal information to third parties, data brokers, or advertising networks under any circumstances.
We disclose information only to the following specific categories of recipients, subject to strict confidentiality and security commitments:
| Party / Category | Purpose | Nature of Data Disclosed |
|---|---|---|
| Stripe, Inc. (Payment Processor) |
Payment processing, payment fraud prevention, and billing receipts. | Payment details, transaction amounts, customer email, and billing contact data. |
| Microsoft Azure (Cloud Infrastructure) |
Application hosting, encrypted database and document storage, secret management. | System logs, customer contact records, and encrypted document storage. |
| Cloudflare, Inc. (Edge & CDN Provider) |
DNS routing, TLS termination, DDoS defense, and rate-limiting. | Network transit data, IP addresses, and HTTP headers in encrypted transit. |
| Purelymail (Corporate Email) |
Business email communication and customer support routing. | Inbound and outbound email messages, sender/recipient addresses, timestamps. |
| Legal Authorities & Regulators | Only when required by enforceable court order, subpoena, or applicable law. | Only data strictly demanded by valid legal process. |
4. Method of Disclosure
Whenever information is shared with authorized service providers, the disclosure is governed by the following technical and operational methods:
- Encrypted API Transmission: All data transmitted between our servers and third-party processors (such as Stripe and Azure services) is transmitted over authenticated connections secured with Transport Layer Security (TLS 1.2 or TLS 1.3).
- Direct Client-Side Tokenization: Financial payment details are collected through Stripe-hosted Checkout forms directly from your browser to Stripe’s PCI-DSS Level 1 certified environment, bypassing our application backend.
- Managed Identities and Role-Based Access: Server-side communication between our container applications, Azure Key Vault, and storage accounts uses Azure Managed Identities with least-privilege role assignments (RBAC), eliminating static API credentials in code or transit.
- Contractual Safeguards: All third-party infrastructure providers are bound by Data Processing Agreements (DPAs) or enterprise terms requiring enterprise-grade data protection, confidentiality, and restriction from secondary use.
5. Security Practices in Place to Safeguard Information
As a specialized cybersecurity engineering firm, security is our primary competency. We employ defense-in-depth safeguards across our entire architecture:
- Encryption in Transit: Strict HTTPS and TLS 1.3 encryption enforced across all public endpoints, with HSTS (HTTP Strict Transport Security) enabled to prevent downgrade attacks.
- Encryption at Rest: All stored documents, database state, and backups are encrypted at rest using industry-standard AES-256 encryption within Microsoft Azure.
- Secrets Management: Zero credentials, API keys, or private certificates exist in source code repositories. All keys and Price IDs are isolated in hardware-backed Azure Key Vault instances with audit logging enabled.
- Access Controls & Authentication: Administrative and document vault interfaces are gated by enterprise OAuth2 identity verification (Microsoft Entra ID) and an explicit email allowlist policy.
- Input Validation & Rate Limiting: All incoming requests are parsed against strict Pydantic schemas, sanitized against injection vulnerabilities, and bounded by sliding-window rate limiters.
- Data Minimization: We collect and retain only the data required to deliver your services. Log retention and session lifecycles are restricted to operational necessity.
- Vulnerability Management: Continuous automated security scanning via GitGuardian and secret detection workflows on every code commit and deployment.
6. Your Privacy Rights
Depending on your jurisdiction (including under GDPR, LGPD, and state privacy regulations), you may have rights regarding your personal information, including:
- The right to know what personal data we maintain about you.
- The right to request access to or a copy of your personal data.
- The right to rectify inaccurate or incomplete information.
- The right to request erasure (“right to be forgotten”) of your personal data, subject to legal and financial retention requirements.
- The right to restrict or object to the processing of your data.
To exercise any of these rights, please contact us using the details below. We verify all requests before taking action to protect your security.
7. Customer Support & Privacy Contact
If you have any questions, concerns, or requests regarding this Privacy Policy or our security practices, please contact our team directly:
- Customer Support Portal: starksenterprise.com/support
- Customer Support Email: [email protected]
- Consultation & Sales Inquiries: [email protected]
- Organization: Starks Enterprise LLC
- Mailing Address: Starks Enterprise LLC, Attn: Privacy & Compliance Office