Data Processing
Last Updated: June 25, 2026
This page summarizes how Starling AI processes personal data on behalf of its business customers and how to put a formal Data Processing Addendum (DPA) in place. It supplements our Terms of Service and Privacy Policy. Capitalized terms have the meanings given in the Terms of Service.
Roles of the parties
When a Client uses Starling AI to manage its own contacts and communications, the Client acts as the controller (or “business”) and Starling AI acts as the processor (or “service provider”) with respect to End-User Data processed on the Client’s behalf. Starling AI processes that data only to provide, secure, support, and improve the services in accordance with the Client’s instructions and the Terms of Service.
Scope and purpose of processing
Starling AI processes data to operate the platform — including engaging and qualifying leads, scheduling appointments, routing conversations, syncing with connected systems, and generating AI outputs — and to secure, maintain, and improve the services.
Categories of data and data subjects
- Categories of data: contact details (name, phone number, email), message and conversation content, lead and pipeline information, appointment data, and related records.
- Data subjects: a Client’s contacts, leads, prospects, customers, and other End Users, as well as the Client’s Authorized Users.
Subprocessors
We engage the following categories of subprocessors to deliver the services, each bound to protect data and use it only to provide their services to us:
| Category | Purpose |
|---|---|
| Cloud hosting & infrastructure | Application hosting and compute |
| Database & storage (e.g., Supabase) | Storing application data |
| Telephony & messaging (e.g., Twilio) | Sending and receiving SMS and voice |
| Large language model providers | Generating AI outputs |
| Payment processing (e.g., Stripe) | Billing and subscription payments |
| Authentication & integrations (e.g., Google) | Sign-in and connected services |
Security
We maintain commercially reasonable security measures to protect personal data, as described on our Security page.
Data subject rights
Because Clients control the End-User Data they process through the platform, requests from individuals to access, correct, or delete their information should be directed to the relevant Client (the controller). Starling AI will reasonably assist Clients in responding to such requests as required by applicable law.
International transfers
Starling AI is based in the United States, and data is processed in the United States and potentially other countries where our service providers operate.
Retention and deletion
We retain data for as long as needed to provide the services and as described in the Terms of Service. Following termination, Clients may request export of their data for a limited period, after which the data may be deleted or de-identified in the ordinary course.
Requesting a DPA
Customers who require a signed Data Processing Addendum — for example, to support obligations under the GDPR or similar laws — may request one by contacting admin@starlingagent.com. An executed DPA is incorporated into the Terms of Service.