Privacy Policy
How Stargazer Dynamics protects personal data.
This Privacy Policy explains how Stargazer Dynamics, Inc. and its affiliates, if any, collect, use, disclose, retain, and protect personal data in connection with the Stargazer Dynamics website, marketing activities, and the Event Horizon SaaS customer delivery CRM platform.
1. Overview
We design Event Horizon for B2B customer delivery operations, where privacy, confidentiality, tenant isolation, and accountability are core trust requirements.
Stargazer Dynamics provides Event Horizon, a SaaS-based customer delivery CRM platform for managing customer accounts, contacts, sales-to-delivery handoffs, implementation projects, milestones, dependencies, readiness, customer commitments, risks, support impact, health signals, renewal readiness, activities, notes, tasks, and related operational records.
This Privacy Policy applies to personal data we process through:
- our public websites, landing pages, downloadable resources, forms, and online events;
- sales, marketing, customer support, implementation, and account-management activities;
- the Event Horizon SaaS platform, APIs, integrations, dashboards, administrative tools, and related services;
- security, compliance, audit, access-control, billing, and operational administration.
2. Our role: controller, processor, service provider, and business associate status
Our legal role depends on context.
2.1 Stargazer as controller or business
Stargazer Dynamics acts as an independent controller, or a “business” under certain U.S. privacy laws, when we decide how and why personal data is processed for our own purposes. This includes website analytics, sales inquiries, marketing communications, customer account administration, billing records, support interactions, security operations, hiring, vendor management, and legal compliance.
2.2 Stargazer as processor, service provider, or contractor
When a customer uses Event Horizon to store or process data about its own customers, employees, prospects, contacts, stakeholders, users, or business relationships, Stargazer Dynamics generally acts as a processor, service provider, or contractor on behalf of that customer. The customer controls the personal data placed into its Event Horizon tenant, subject to the customer agreement and any applicable Data Processing Addendum.
2.3 Customer responsibilities
Customers are responsible for configuring their tenants, obtaining required notices and consents, setting user permissions, determining lawful processing purposes, responding to requests from their own data subjects where they are the controller, and ensuring that the personal data they submit to Event Horizon may lawfully be processed by Stargazer Dynamics.
2.4 Regulated data and business associate status
Event Horizon is not intended to process protected health information, payment card primary account numbers, government-issued identity numbers, children’s data, special-category data, or other regulated sensitive data unless the applicable customer agreement expressly permits that processing and the required addendum is in place. Stargazer Dynamics is not a HIPAA Business Associate unless it signs a Business Associate Agreement.
3. Personal data we collect and process
The categories below describe the personal data we may process depending on how a person or customer interacts with Stargazer Dynamics.
| Category | Examples | Typical context |
|---|---|---|
| Identifiers and contact data | Name, business email, phone number, company, job title, mailing address, account name, user ID, username. | Website forms, sales conversations, account setup, platform user profiles, support requests. |
| Commercial and customer relationship data | Subscription plan, billing contact, invoices, contract dates, products or modules used, renewal context, account ownership, support plan. | Customer account administration, billing, sales, renewals, support, customer success. |
| Platform user and authentication data | Login identifiers, role, tenant, team, permission scope, MFA status, session metadata, IP address, device/browser details, audit events. | Authentication, authorization, security monitoring, access reviews, SOC 2-oriented evidence. |
| Customer Content in Event Horizon | Accounts, contacts, stakeholders, handoffs, implementation projects, work orders, milestones, dependencies, readiness items, commitments, risks, blockers, support-impact items, success goals, health signals, renewal readiness indicators, notes, activities, tasks, uploaded files, and related metadata. | Customer-controlled CRM and delivery operations inside a tenant workspace. |
| Communications | Emails, chat messages, support tickets, meeting notes, call summaries, demos, feedback, surveys, event registration information. | Sales, marketing, onboarding, support, customer success, product feedback. |
| Usage, telemetry, and diagnostic data | Feature usage, page views, click paths, browser type, device identifiers, log data, performance data, errors, API calls, integration health. | Service operation, troubleshooting, abuse prevention, analytics, product improvement. |
| Integration data | Data imported from connected systems such as CRM, help desk, project management, identity provider, calendar, communication, document, billing, or product analytics tools, where enabled by a customer. | Customer-enabled integrations, workflow automation, account context, support impact, handoffs, implementation tracking. |
| Payment and financial data | Billing address, payment status, tax information, invoice history, limited payment metadata. Payment card data is processed by our payment processor, where applicable. | Billing, collections, tax compliance, subscription administration. |
| Potentially sensitive data | Account credentials, security logs, access logs, precise business-context notes, commercial terms, executive notes, support escalations, API tokens, integration secrets, and sensitive information customers choose to submit. | Security operations, administrative functions, customer-controlled records, integrations, support. We do not use sensitive personal data to infer characteristics unless expressly permitted by law and contract. |
4. Sources of personal data
We may receive personal data directly, automatically, from customers, or from third-party sources.
- Directly from you when you complete a form, register for content, request a demo, subscribe to communications, create an account, submit a support request, or communicate with us.
- From customers and tenant administrators when they create user accounts, upload Customer Content, configure roles, invite users, connect integrations, or manage their Event Horizon workspace.
- Automatically through cookies, pixels, server logs, analytics tools, application telemetry, security monitoring, and diagnostic systems.
- From integrations that a customer authorizes, such as sales CRM, help desk, identity provider, project management, communication, document, billing, or analytics systems.
- From third parties such as business partners, event organizers, lead enrichment providers, public business sources, fraud-prevention services, or referrals, where permitted by law.
5. How we use personal data
We use personal data to operate, secure, support, improve, and lawfully administer our website and SaaS platform.
- create, configure, administer, and support customer accounts and users;
- process Customer Content according to customer instructions and product functionality;
- provide CRM, delivery, implementation, milestone, readiness, dependency, commitment, risk, support-impact, health, renewal, activity, and reporting workflows;
- manage subscriptions, billing, tax, contracts, procurement, and account communications;
- send service messages, product updates, security notices, administrative messages, and requested marketing communications;
- measure website and product performance, understand engagement, improve user experience, and develop new features;
- train staff, monitor support quality, and maintain internal business records;
- detect, investigate, and prevent security incidents, abuse, fraud, spam, policy violations, and unauthorized access;
- generate audit logs, access reviews, security evidence, and compliance artifacts;
- comply with law, enforce agreements, protect rights, and respond to lawful requests.
6. Legal bases for processing
Where GDPR, UK GDPR, Swiss data protection law, LGPD, or similar laws require a legal basis, we rely on the basis that fits the processing context.
| Processing purpose | Typical legal basis |
|---|---|
| Provide Event Horizon, administer accounts, process customer instructions, authenticate users, and deliver contractual services. | Performance of a contract; legitimate interests; legal obligation; processor activity under customer instructions. |
| Security monitoring, fraud prevention, audit logging, access reviews, incident response, abuse prevention, and service integrity. | Legitimate interests; legal obligation; performance of a contract. |
| Billing, tax, accounting, procurement, contract management, and legal compliance. | Performance of a contract; legal obligation; legitimate interests. |
| Website analytics, product improvement, service diagnostics, and aggregate reporting. | Legitimate interests; consent where required for non-essential cookies or analytics. |
| Marketing communications, event invitations, downloadable content, and outreach. | Consent; legitimate interests; compliance with direct-marketing laws and opt-out requirements. |
| Optional AI-assisted features, if enabled. | Performance of a contract; legitimate interests; consent or customer instruction where required; additional contractual terms where applicable. |
7. Customer Content and tenant data
Event Horizon is designed as a tenant-scoped system of record for customer delivery data.
Customer Content means data that a customer, user, administrator, integration, or authorized workflow submits to Event Horizon for processing within a customer tenant. Customer Content may include personal data about a customer’s employees, contractors, customers, contacts, prospects, stakeholders, implementation participants, support contacts, executive sponsors, account managers, and other business contacts.
We process Customer Content to provide the service, perform support, maintain security, comply with customer instructions, satisfy legal obligations, and exercise rights under the customer agreement. We do not sell Customer Content. We do not use Customer Content for third-party advertising. We do not disclose Customer Content except as described in this Policy, the customer agreement, the Data Processing Addendum, the subprocessor list, or as legally required.
7.1 Customer administrator access
Customer administrators may be able to access, export, modify, delete, or configure Customer Content and user data within their tenant, subject to the customer’s settings and permissions. Customers are responsible for choosing administrators carefully and maintaining internal governance around user access.
7.2 Support access
Stargazer personnel do not need default unrestricted access to Customer Content. Where support access is required, access should be time-bound, reasoned, limited to the purpose of support or security, and logged. For high-trust environments, customers may request enhanced support-access controls if available under their plan.
8. AI-assisted and automation features
Event Horizon may include optional AI-assisted capabilities to help users summarize, classify, extract, or draft customer-delivery records.
If enabled, AI-assisted features may process user prompts, selected records, uploaded documents, emails or electronic files, extracted contact data, summaries, generated outputs, feedback, and related metadata. These features may support workflows such as contact capture, handoff summaries, risk summaries, executive briefings, commitment extraction, customer status summaries, or renewal-readiness analysis.
- AI features should process only the data necessary for the enabled workflow.
- AI outputs may be inaccurate or incomplete and should be reviewed by authorized users before use in customer-facing or legally significant contexts.
- We will not use Customer Content to train general-purpose AI models unless the customer has expressly authorized that use in writing.
- AI subprocessors, if used, will be listed in our subprocessor documentation or customer agreement where required.
- Customers may configure or disable AI-assisted features where supported by the plan, tenant settings, or applicable agreement.
9. How we disclose personal data
We disclose personal data only for business, service, security, legal, or customer-authorized purposes.
9.1 Categories of recipients
- Service providers and subprocessors: cloud hosting, storage, identity, security, observability, email, customer support, payment processing, analytics, AI infrastructure, and other vendors that help operate our business and services.
- Customer-authorized integrations: applications, systems, and platforms a customer connects to Event Horizon.
- Customer administrators and users: authorized users within the customer’s tenant, based on roles, scopes, and settings.
- Professional advisers: lawyers, auditors, accountants, insurers, consultants, and compliance advisers.
- Authorities and legal process recipients: regulators, courts, law enforcement, or other parties when required by law, subpoena, court order, or valid legal process.
- Corporate transaction parties: counterparties and advisers in connection with a merger, acquisition, financing, reorganization, due diligence, bankruptcy, or sale of assets, subject to appropriate confidentiality protections.
9.2 No sale of Customer Content
We do not sell Customer Content, and we do not share Customer Content for cross-context behavioral advertising. If we use third-party advertising or analytics technologies on the public website, those activities may be considered “sale,” “sharing,” or targeted advertising under certain privacy laws. Where required, we provide opt-out choices.
9.3 Subprocessor list
Customers may request our then-current subprocessor list at privacy@stargazerdynamics.com. Before publication, replace this sentence with a public subprocessor page link, such as /subprocessors, and define the notice process for new subprocessors.
10. Cookies, analytics, and tracking choices
We use cookies and similar technologies for essential website operation, security, analytics, preferences, and, where enabled, marketing.
| Cookie category | Purpose | Choice |
|---|---|---|
| Strictly necessary | Security, session management, form submission, load balancing, authentication, fraud prevention. | Required for site and service operation. |
| Functional | Remember preferences, improve usability, support chat or support workflows. | Configurable where required. |
| Analytics and performance | Understand usage, diagnose problems, measure campaigns, improve product and website performance. | Consent or opt-out where required. |
| Advertising or retargeting | Measure ads or show relevant marketing on third-party sites, if used. | Opt-out required where applicable; do not enable unless the cookie banner and disclosures match actual practice. |
You can manage cookies through our cookie banner, your browser settings, and applicable opt-out tools. Where legally required, we honor recognized browser-based opt-out preference signals, such as Global Privacy Control, for applicable website processing.
Do Not Sell or Share My Personal Information: If our website uses technologies that constitute “sale,” “sharing,” or targeted advertising under applicable law, you may opt out by using our cookie preference tool at /privacy-preferences or by emailing privacy@stargazerdynamics.com with the subject line “Do Not Sell or Share.”
11. Security measures
We maintain administrative, technical, and organizational safeguards designed to protect personal data and Customer Content.
Security measures vary by system, data sensitivity, customer configuration, and service maturity, but may include:
No method of transmission or storage is completely secure. Customers and users are responsible for maintaining strong credentials, protecting devices, configuring access permissions, reviewing user access, and notifying us promptly of suspected unauthorized account use.
11.1 Security incidents
If we determine that a security incident has affected personal data or Customer Content, we will investigate, take appropriate containment and remediation steps, and provide notice to affected customers, individuals, or authorities as required by law and applicable agreements.
12. Data retention and deletion
We retain personal data only as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted by law.
| Data type | Typical retention approach |
|---|---|
| Website inquiries, demo requests, and marketing contacts | Retained while there is a business relationship or active interest, then deleted or archived according to marketing and legal-retention rules. Suggested default: up to 3 years after last meaningful interaction unless law or consent requires otherwise. |
| Customer account, billing, contract, and tax records | Retained during the subscription and for the legally required accounting, tax, contractual, and dispute-resolution period. Suggested default: 7 years after account closure where appropriate. |
| Customer Content in Event Horizon | Retained according to the customer agreement, Data Processing Addendum, tenant settings, and customer instructions. Upon termination, customers may export or request deletion subject to backup, legal hold, and security retention rules. |
| Security logs, audit logs, access reviews, and authentication records | Retained for security, compliance, audit, fraud-prevention, and incident-response purposes. Suggested default: 12 to 24 months, or longer where required by customer agreement or law. |
| Backups | Backups are overwritten on a rolling schedule. Deleted data may persist in backups until the backup expires, unless restored in accordance with backup and disaster-recovery procedures. |
We may retain de-identified, aggregated, or anonymized data that no longer identifies an individual, subject to applicable law and contractual commitments.
13. Your privacy rights and how to exercise them
Depending on where you live and how we process your data, you may have rights to access, correct, delete, restrict, object, opt out, or receive a copy of your personal data.
13.1 Request methods
To exercise privacy rights, contact us at privacy@stargazerdynamics.com or submit a request through /privacy-request once available. Please include your name, email address, country or state of residence, relationship to Stargazer Dynamics, and the right you want to exercise.
13.2 Verification
We may need to verify your identity and authority before fulfilling a request. If your request concerns data inside a customer-controlled Event Horizon tenant, we may direct the request to the relevant customer or assist that customer in responding.
13.3 Authorized agents
Where applicable law allows an authorized agent to submit a request on your behalf, we may require proof of authorization and may ask you to verify your identity directly with us.
13.4 Appeals
If we deny your request and applicable law gives you an appeal right, you may appeal by emailing privacy@stargazerdynamics.com with the subject line “Privacy Appeal.” We will respond within the time required by applicable law.
13.5 Non-discrimination
We will not unlawfully discriminate against you for exercising privacy rights. Some services may require certain data to function; if deletion or restriction prevents us from providing the service, we will explain the impact where required.
14. U.S. state privacy notices
This section is intended to cover U.S. residents with comprehensive state privacy rights, including California and other states with applicable privacy laws.
14.1 California Notice at Collection and privacy rights
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, may give you rights to know, access, correct, delete, and receive information about certain personal information we collect, use, disclose, sell, or share. You may also have the right to opt out of sale or sharing, limit certain uses of sensitive personal information, and be free from unlawful discrimination for exercising your rights.
| CCPA category | Examples we may process | Business or commercial purpose | Disclosed to |
|---|---|---|---|
| Identifiers | Name, email, phone, company, account ID, IP address, online identifiers. | Provide service, sales, support, security, communications. | Service providers, customer administrators, integrations, legal recipients. |
| Customer records / commercial information | Billing records, subscription information, products used, renewal context, customer relationship records. | Account administration, billing, contracts, support, renewals. | Payment processors, service providers, advisers, customer-authorized users. |
| Internet or network activity | Log data, usage telemetry, page views, browser/device information, API activity. | Security, analytics, diagnostics, service improvement. | Cloud, monitoring, analytics, security providers. |
| Geolocation | Approximate location inferred from IP address. | Security, localization, analytics, fraud prevention. | Security, analytics, infrastructure providers. |
| Professional or employment-related information | Job title, department, company, role, business contact details. | B2B communications, customer support, role-based access, sales and account management. | Service providers, customer administrators, business partners where authorized. |
| Inferences | Lead or account interest, product usage patterns, customer health or engagement indicators generated by the service. | Sales, support, customer success, analytics, product improvement, customer-controlled CRM workflows. | Service providers and authorized customer users. |
| Sensitive personal information | Account credentials, security logs, access tokens, or sensitive content customers choose to submit. | Security, authentication, customer-controlled processing, integrations, compliance. | Service providers and authorized users only as needed. |
We do not use or disclose sensitive personal information for purposes that require a right to limit under California law unless we provide the required notice and choice. We do not knowingly sell or share personal information of individuals under 16.
14.2 Other U.S. state privacy laws
Residents of states with applicable comprehensive privacy laws may have rights to access, correct, delete, obtain a portable copy of personal data, opt out of targeted advertising, opt out of sale, opt out of certain profiling, appeal a denial, and limit or revoke consent for sensitive-data processing where applicable. These states may include California, Colorado, Connecticut, Delaware, Iowa, Indiana, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other states as laws become effective or applicable to Stargazer Dynamics.
Consolidated state rights summary
- Access / confirmation: confirm whether we process your personal data and access that data.
- Correction: correct inaccuracies in personal data, considering the nature and purpose of processing.
- Deletion: delete personal data, subject to exceptions.
- Portability: obtain a copy of personal data in a portable format where required.
- Opt out: opt out of sale, sharing, targeted advertising, or certain profiling where applicable.
- Sensitive data: limit or withdraw consent for sensitive-data processing where applicable.
- Appeal: appeal our decision if we deny a rights request where applicable.
14.3 Nevada residents
Nevada residents may submit a request to opt out of the sale of certain covered information by emailing privacy@stargazerdynamics.com with the subject line “Nevada Opt-Out.”
15. International privacy notices
Additional notices may apply depending on your location.
15.1 European Economic Area, United Kingdom, and Switzerland
If you are in the EEA, UK, or Switzerland, you may have rights to access, rectify, erase, restrict, object to processing, data portability, withdraw consent, and lodge a complaint with your supervisory authority. When we act as processor, we assist our customer as required by our Data Processing Addendum.
15.2 Canada
If Canadian privacy law applies, you may request access to personal information, challenge accuracy, withdraw consent where applicable, and ask questions about our privacy practices. We process personal information for identified purposes and use contractual and technical safeguards for service providers.
15.3 Brazil
If Brazil’s LGPD applies, data subjects may have rights to confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary or excessive data, portability, information about sharing, withdrawal of consent, and review of certain automated decisions where applicable.
15.4 Australia and New Zealand
If Australian or New Zealand privacy law applies, you may have rights to know how personal information is handled, access and correct personal information, and complain about privacy practices. We use safeguards designed to protect personal information and manage cross-border disclosures as required.
15.5 South Africa
If South Africa’s Protection of Personal Information Act applies, you may have rights to access, correct, delete, object to processing, and complain to the Information Regulator, subject to lawful exceptions.
15.6 Singapore and other APAC jurisdictions
Where applicable, we process personal data according to consent, notification, purpose limitation, access, correction, protection, retention, transfer, and accountability requirements under local privacy laws.
16. International transfers
Stargazer Dynamics may process personal data in the United States and other countries where we, our affiliates, or our service providers operate.
These countries may have data protection laws different from those in your jurisdiction. Where required, we use appropriate safeguards such as contractual protections, data processing agreements, standard contractual clauses, transfer risk assessments, supplementary safeguards, and subprocessor due diligence.
If Stargazer Dynamics later certifies under a recognized cross-border transfer framework, such as the EU-U.S. Data Privacy Framework or its UK/Swiss extensions, this section should be updated to describe that certification, scope, enforcement mechanism, and recourse process.
17. Children’s privacy
Our website and services are designed for business users and are not directed to children.
We do not knowingly collect personal data from children under 13, or under the age required by applicable local law, without appropriate consent. If you believe a child has provided personal data to us, contact privacy@stargazerdynamics.com so we can take appropriate action.
18. Changes to this Privacy Policy
We may update this Privacy Policy as our services, data practices, laws, and compliance program evolve.
If changes are material, we will provide notice through the website, in-product notice, email, or another reasonable method. The “Last updated” date at the top of this page indicates when this Privacy Policy was last revised.
19. Contact us
Questions, requests, and notices can be directed to Stargazer Dynamics privacy contact.
Stargazer Dynamics, Inc.
Privacy Contact: privacy@stargazerdynamics.com
Security Contact: security@stargazerdynamics.com
Mailing Address: Stargazer Dynamics Corporation
2912 Valley View Terrace
Jefferson City, MO 65109
Data Protection Officer / EU Representative: [Insert if required]
UK Representative: [Insert if required]