This agreement applies when a business ("the customer") uses Starlog for its own people. It is part of our terms of service and needs no signature; if you need a signed copy, write to admin@starlog.pro.
1. Roles and subject
The customer is the controller of the meetings, files and questions its people put into Starlog. Entity Investment AG is its processor and processes them only to provide Starlog for the duration of the customer's use.
2. What is processed
Audio, transcripts, speaker names, summaries, decisions, action items, files and questions; about the customer's staff, guests, business contacts and anyone else present in recorded meetings. Meetings can contain special categories of data when people speak about them.
3. Instructions
We process the data only on the customer's documented instructions, which are these terms and what the customer does in Starlog, unless the law requires otherwise; then we tell the customer first where allowed.
4. Confidentiality
Everyone who can reach the data for us is bound to confidentiality.
5. Security
We protect the data with measures fitting the risk: each company or team in its own separate space on our servers; access by role; sign-in by passkey; encryption in transit; AI keys held outside the customer spaces; daily backups.
6. Sub-processors
The customer authorises the sub-processors on this list. We bind each to the same duties, tell the customer in advance of changes, and the customer may object. We stay responsible for them.
7. Transfers
Switzerland is recognised as adequate by the EU, so no further safeguard is needed for data from the EU to us. Transfers to sub-processors outside the EU and Switzerland use the Data Privacy Framework where the provider is certified, else the EU standard contractual clauses (with the Swiss amendments for Swiss data).
8. Help to the customer
We help the customer answer people's requests to exercise their rights, and with security, breach notices and impact assessments, as far as our part allows.
9. Breaches
We tell the customer without undue delay, and within 48 hours of knowing, about a personal data breach affecting its data, with what we know.
10. End
When the customer's use ends, we delete its data from Starlog within 30 days, after giving it a chance to export it, unless the law requires us to keep it; copies in backups can remain for up to 30 days after that.
11. Audits
We give the customer the information needed to show we meet this agreement and allow reasonable audits, announced 30 days ahead, at the customer's cost.
12. Law
This agreement follows the GDPR and the Swiss Federal Act on Data Protection; for Swiss data, the Swiss FDPIC is the authority. Otherwise the terms' choice of law applies.