Legal & Assurance

Privacy Policy

At Starside Technologies, we build critical software for aerospace engineering teams. We treat your engineering models, requirements, telemetry, and personal data with the highest standards of security, privacy, and sovereignty.

Effective Date:January 15, 2026
Version:2.4 (Enterprise)
Compliant with GDPR & Indian DPDPA

01Overview & Scope

This Privacy Policy explains how STARSIDE TECHNOLOGIES Pvt. Ltd. (“Starside”, “we”, “us”, or “our”) collects, processes, stores, and protects information when you access or use our website (starsidetechnologies.com), our engineering platform (AssembleIT), and related enterprise services (collectively, the “Services”).

Because Starside serves space, defence, and commercial aerospace organisations, our data architecture is engineered to guarantee mathematical traceability, strict tenant isolation, and uncompromising confidentiality.

Key Principle: Zero Secondary Training

Starside never uses customer engineering models, requirement graphs, CAD files, verification logs, or proprietary programme data to train foundational or public AI models. Your intellectual property belongs strictly to you.

02Information We Collect

We collect and process the following categories of information:

  • Account & Profile Data: Full name, professional work email address, company affiliation, role/title, and authentication credentials (SSO/SAML tokens).
  • Customer Programme & Engineering Data: System requirements, MBSE nodes, engineering graphs, verification test results, certification artifacts, and documentation ingested into AssembleIT.
  • Usage & Telemetry Data: System interaction logs, feature utilization metrics, performance indicators, API latency, error diagnostics, and session telemetry required for maintaining high platform availability and fault recovery.
  • Communications & Support: Queries submitted through our contact forms, customer success communications, feedback, and enterprise support tickets.

03AI & Proprietary IP Protection

Our AI-assisted compliance and graph-intelligence tools operate inside strictly bounded tenant enclosures:

  • Tenant-Isolated Inference: AI queries and semantic embeddings generated for requirement verification are executed inside isolated virtual private compute clusters.
  • No Cross-Tenant Data Leakage: No customer data is shared between different enterprise tenants or used to build cross-customer recommendation heuristics.
  • Deterministic & Audit-Ready: AI-driven verification outputs provide traceable source citations linked directly to verified standard bodies (e.g., DO-178C, DO-254, ECSS, NASA-STD) and your engineering artifacts.

04How We Use Information

We process information strictly for the following purposes:

  • To provision, maintain, configure, and operate the AssembleIT platform and user workspaces.
  • To generate living engineering graph nodes, compliance verification traces, and audit logs.
  • To authenticate authorized personnel and enforce enterprise role-based and attribute-based access controls (RBAC/ABAC).
  • To detect, prevent, and respond to cybersecurity threats, anomalous activities, and unauthorized access attempts.
  • To communicate mission-critical platform notices, security updates, and service advisories.
  • To fulfill statutory, contractual, and regulatory compliance obligations.

05Data Isolation & Multi-Tenancy

Starside implements logical and physical segregation safeguards across all compute and storage infrastructure:

  • Encryption in Transit: TLS 1.3 enforced for all network traffic with modern cipher suites and Perfect Forward Secrecy (PFS).
  • Encryption at Rest: AES-256 encryption across all persistent block stores, object storage, and backups with automated key rotation.
  • BYOK & Air-Gapped Deployments: For eligible defence and prime contractor tiers, Starside supports Bring-Your-Own-Key (BYOK) and dedicated, air-gapped on-premises or sovereign cloud infrastructure.

06Data Sharing & Subprocessors

We do not sell, rent, or monetize your data. We disclose data only under strict contractual controls with vetted subprocessors (e.g., tier-4 ISO/IEC 27001 certified cloud infrastructure providers) who satisfy rigorous security and confidentiality audits.

We may also disclose information where required by law, subpoena, or competent regulatory authority, provided that we notify the affected enterprise customer in advance unless legally prohibited.

07Data Residency & Export Controls

We recognize that aerospace and defence programmes often subject technical data to export control regimes, including ITAR (International Traffic in Arms Regulations), EAR (Export Administration Regulations), and national security data sovereignty mandates.

Enterprise customers can designate regional hosting boundaries (including India, EU, and US Sovereign Cloud regions) to guarantee that data remains localized and governed by applicable jurisdictional laws.

08Retention & Cryptographic Deletion

We retain customer data for the duration of the active subscription agreement. Upon customer request or contract termination:

  • Engineering graphs and raw telemetry are rendered permanently inaccessible within 30 calendar days.
  • Cryptographic erasure procedures are executed across immutable backup archives within 90 days.
  • A verifiable certificate of data destruction is provided to enterprise compliance officers upon request.

09Your Privacy Rights

Depending on your location, you may have statutory rights under data protection laws such as the EU/UK GDPR or the Indian Digital Personal Data Protection Act (DPDPA 2023):

  • The right to access, inspect, and request a copy of personal data we hold about you.
  • The right to rectify inaccurate, out-of-date, or incomplete records.
  • The right to object to or restrict specific processing operations.
  • The right to data portability in structured, machine-readable formats.
  • The right to withdraw consent without affecting the lawfulness of prior processing.

10Contact & Data Protection Officer

If you have questions regarding this Privacy Policy, our data protection practices, or wish to exercise your statutory rights, please contact our Data Protection Office:

Data Protection & Privacy Office

STARSIDE TECHNOLOGIES Pvt. Ltd.
Executive / Compliance: ceo@vyomfix.com
Headquarters: Bangalore (Bengaluru), Karnataka, India
Direct response within 1 business day.