Last updated · 2026-10-01
This page says what we do with personal data, in plain words. It describes what our code does today, not what we plan.
The short version
- We are Starwright Studios, a small software studio in South Africa. The company is STARWRIGHT (Pty) Ltd, number 2026/778390/07.
- Our website sets no cookies and uses no analytics. It remembers two choices on your own device: light or dark, and the currency you picked.
- If you message us, we use your details only to reply and, if you want, to set up your service. There is no mailing list.
- If we contacted you first, your business details came from open map data, a public register or your own public pages. Tell us to stop and we never contact you again.
- We do not sell personal data.
- Questions, requests or complaints: privacy@starwrightstudios.com.
The notice in full
1. Who we are
Starwright Studios is the trading name of STARWRIGHT (Pty) Ltd, a company registered in South Africa, number 2026/778390/07. Registered address: Erf 2530, R365, Porterville, Western Cape, 6810, South Africa. Email: privacy@starwrightstudios.com or hello@starwrightstudios.com.
We build websites, an AI receptionist and paperless tools for small businesses in the United Kingdom, the United States and Europe. For the personal data described on this page we are the controller (under South Africa's POPIA, the responsible party).
Our Information Officer under POPIA is the company's director, Janno. His registration with the Information Regulator is being lodged in October 2026; this line will carry the date once it is.
We have not yet appointed a representative in the United Kingdom under UK GDPR Article 27. We will name them here when we do. Until then, write to privacy@starwrightstudios.com and we answer within five working days.
2. Who this page is for
- Visitors to starwrightstudios.com and to the preview websites we host.
- People who get in touch with us.
- Business owners we contact first, whose details we found in open data (section 5).
- Customers.
When we host a customer's website, forms or bookings, or run their AI receptionist, we handle their visitors' and callers' data for the customer, under a written data processing agreement. The customer's own privacy notice covers that.
3. If you visit our website
- Cookies: none. No analytics, no advertising, no tracking. We do not know who visits.
- Your choices stay on your device. When you pick light or dark, or a currency, the site saves that one word in your browser's local storage (the keys theme and currency) so it remembers next time. It is never sent to us or to anyone. To show prices in pounds, euros or dollars the page also reads the time zone your device is set to. That happens on your device and is not sent anywhere. A currency you pick yourself always wins. Clear this site's data in your browser to remove both.
- Nothing loads from other companies. Fonts, scripts and the globe's weather figures all come from our own server. (We fetch the weather once when we build the site; your browser does not.)
- What your browser sends. To deliver a page, your browser sends our server your IP address and the page you asked for. The web server that serves this site and the preview sites keeps no log of visits.
- Links to WhatsApp, email and phone open your own app. WhatsApp is run by Meta under its own privacy policy.
- Preview sites. Before a business pays us anything we build it a preview website. A preview shows that business's public details (name, trade, address, phone, hours). It is marked as a preview, hidden from search engines, at an address that is not listed anywhere, and it makes no request to any other company's server. We take it down 30 days after we first tell the business about it, or at once if they ask. The same no-cookie rules apply.
- Why we may do this: our legitimate interest in running and securing the site. Saving your theme and currency choice is storage used only to adapt how the site appears to you, which UK law allows without consent.
4. If you get in touch
- What we receive: what you send us. On WhatsApp, your number and profile name. By email, your address. Your name, your business and your message. If you ask us to call you, the number and time you give.
- Why: to reply; to give you a quote or set up your website or other service; to keep a record of what was agreed.
- Our lawful basis: the steps you ask us to take before a contract (UK GDPR and EU GDPR Article 6(1)(b); POPIA section 11(1)(b)); our legitimate interest in keeping a record of what was said.
- Who sees it: Janno. The services that carry your message also handle it: Meta if you use WhatsApp; Cloudflare, which receives email to our addresses and forwards it; Google, where our mailbox is; Resend, which sends our replies (section 7).
- We reply on the channel you used. We do not add you to any list. We send no automatic emails and no newsletter. We only write about what you asked about. If you become a customer, section 6 applies.
- How long: if nothing comes of it, we delete your enquiry from our records 12 months after your last message. We delete the email or WhatsApp thread when you ask us to.
5. If we contacted you first: where your details came from
This section is for a business owner who got an email, a postcard or a call from us before they had heard of us. It is the information UK GDPR and EU GDPR Article 14 and POPIA section 18 say we must give you.
- What we hold about your business: its name; its trade; its address or postcode; its phone number; its email address where one is published; whether it has a website and how good that site is; whether it is a registered company and, if so, its number, status, incorporation date and the first names and roles of its officers from the public register; notes from its public pages (for example that a review or a post is recent, recorded as a link and a date, never copied); the preview website we built for it; what we sent you and when, and whether the preview link was opened.
- Where it came from:
- Overture Maps Places, an open dataset of places published monthly by the Overture Maps Foundation with data from Meta, Microsoft, Foursquare and others, under open licences (CDLA-Permissive-2.0, Apache-2.0, CC0). We record which release each record came from.
- OpenStreetMap (© OpenStreetMap contributors, Open Database Licence).
- Companies House, the UK public register of companies.
- Your business's own public pages on the web and on social sites.
- Google Maps: we may look at your listing live while we work, but we store only Google's place ID. We never take or store phone numbers or any other content from Google.
- You, when you reply, write or speak to us.
- Why: to offer your business a website and the services on this site, and to build a preview so you can see it before you decide anything.
- Our lawful basis: our legitimate interest in telling businesses about a relevant service (UK GDPR and EU GDPR Article 6(1)(f); POPIA section 11(1)(f)).
- How we contact you:
- Email. In the UK we email companies and generic business addresses (such as info@); we email a sole trader or partnership only after they have agreed. In Ireland and the USA we email businesses. Every email says who we are, carries our postal address, and has a one-click link to stop. Our emails contain no tracking images.
- Post. A UK business we cannot confirm is a company gets one postcard instead of an email. The card says where your address came from and how to stop.
- Calls. Rarely. Before we call a UK number we check it against the Telephone Preference Service and the Corporate TPS; before a US number, the National Do Not Call Registry. On the call we say who we are, that we are calling from South Africa, and where we found your number. We do not record calls.
- WhatsApp. Never first. Only if you message us.
- The preview link. The link to your preview in an email or on a postcard is unique to you. When it is opened we record the date and time, so we know the card or email reached you. Our records hold no IP address and nothing about your device.
- Your right to stop us, at any time: click the stop link in any email, reply STOP, write to privacy@starwrightstudios.com, or say so on the call. We stop at once, take your preview down and delete your record. We keep only what we need to make sure we never contact you again: the number, address or listing ID, the channel, the date and the reason. That do-not-contact list is permanent.
- How long: we review prospect records at least every 12 months and delete those that led nowhere. We keep a record of what we sent, when, and of our register checks for five years, as evidence that we followed marketing law.
6. If you become a customer
- What: your name, business and contact details; your order form; what you ordered; invoices and payments (through our payment provider, named on your order form; we never see full card numbers); your messages and change requests; the content of your site.
- Why and on what basis: to perform our contract with you; to keep accounting and tax records (a legal duty in South Africa); our legitimate interest in running, securing and improving the service; and to tell you about similar services of ours, which you can refuse at any time, in every message.
- Your website, forms, bookings and AI receptionist: we process your customers' and callers' data for you under our data processing agreement. The AI receptionist is not yet live; before it launches we will describe it and name its providers here.
- Reviews and case studies: we show your business or your words as an example of our work only with your written permission, and remove them within 7 days if you withdraw it.
- How long: accounting records for as long as South African company and tax law requires; your site's content for 30 days after cancellation, then deleted; server backups for 14 days.
7. Who we share data with
We do not sell personal data. We use these providers, each under their own terms that limit what they may do with it:
| Provider | What it does for us | Where |
|---|---|---|
| Oracle Cloud Infrastructure | Hosts our website, the preview sites, our records and our tools | Johannesburg, South Africa |
| Cloudflare | Holds our domain names and DNS, and receives email sent to our addresses and forwards it to our mailbox | USA, global network |
| Google (Gmail) | The mailbox where email to us is kept | USA, global |
| Resend | Sends our emails | USA |
| Stannp | Prints and posts our postcards. It receives the business name, the name on the listing if there is one, the address, and the card itself | United Kingdom |
| Anthropic (Claude) | Helps us research a business from its public pages, write text and design previews. It receives the business details listed in section 5 | USA |
| WhatsApp (Meta) | Carries the messages you choose to send us on WhatsApp, under Meta's own terms | Meta's network |
| Our payment provider | Takes payments once you are a customer. It is named on your order form | Named on your order form |
| Companies House, Overture Maps, OpenStreetMap | Sources we read. We send them nothing about you beyond a search by business name | UK; open data |
We may also share data with our professional advisers, and with authorities where the law requires it.
8. Where your data is kept, and transfers between countries
We are in South Africa and our server is in Johannesburg. The United Kingdom and the European Union have not decided that South African law gives the same protection as theirs, and some of our providers are in the United States. South African law (POPIA section 72) lets us send personal data abroad to a provider bound by an agreement that gives adequate protection, or where it is needed to carry out your contract. Where UK or EU law needs a safeguard for a transfer, we rely on our providers' standard contractual clauses and the UK addendum, and on encryption and limited access. Ask us for details.
9. How long we keep data
| What | How long |
|---|---|
| Visitor data | None in our records |
| Your theme and currency choice | On your device, until you clear the site's data |
| An enquiry that leads nowhere | 12 months after your last message |
| A prospect record we found in open data | Reviewed at least every 12 months; deleted if it led nowhere |
| A preview website | 30 days after we first tell the business, or on request |
| Evidence of what we sent and of register checks | 5 years |
| The do-not-contact list | Permanent, minimum data |
| Customer accounting records | As South African company and tax law requires |
| A customer's site after cancellation | 30 days, then deleted |
| Server backups | 14 days |
10. Your rights
Wherever you are, you can ask us what we hold about you, have it corrected or deleted, ask us to limit or stop using it, and get a copy in a usable format. You can always object to direct marketing, and we always stop. Write to privacy@starwrightstudios.com. We reply within one month. If you are in the USA: we do not sell or share personal information for advertising, and the same requests are open to you.
You can also complain to a regulator:
- United Kingdom: the Information Commissioner's Office, ico.org.uk/make-a-complaint.
- Ireland: the Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963, dataprotection.ie.
- South Africa: the Information Regulator, Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191; POPIAComplaints@inforegulator.org.za; 010 023 5200.
11. Security
Every connection is encrypted. Only the founder and the named tools can reach our records, behind two-factor sign-in. Secrets are kept out of the code. Backups are kept for 14 days. If a breach puts your data at risk we tell you and the regulator as the law requires.
12. Children
Our services are for businesses. We do not knowingly collect data about anyone under 18.
13. Changes
We update this page when our tools or practices change and show the date at the top.