Draft. This document has been prepared from NorthStar’s actual engineering record and has not yet been reviewed by legal counsel. Highlighted values are placeholders. It is published for review and is not yet a binding agreement.

Privacy Policy

What personal data NorthStar collects, why we hold it, who else touches it, how long we keep it, and how to exercise your rights under the GDPR and Singapore's PDPA.

Effective date: [EFFECTIVE DATE] · Operator: [COMPANY LEGAL NAME], [POSTAL ADDRESS] · Contact: [SUPPORT_EMAIL]

1. Two kinds of people in this policy

NorthStar holds personal data about two distinct groups, and your rights depend on which one you are in.

  • Users — people who create a NorthStar account and sign in. For this data [COMPANY LEGAL NAME] is the controller (GDPR) / organisation (PDPA), and this policy is our notice to you.
  • Workers — the people a customer plans around. Workers do not have NorthStar accounts and cannot sign in. Here the customer organisation is the controller and we are its processor: we hold that data on their instructions, and requests about it are answered by them. If you are a worker who has been told your employer plans with NorthStar, contact your employer first; we will support them in responding.

2. What we collect

About users

  • Name and email address, given at sign-up.
  • A password, stored only as a salted hash — we never hold, and cannot recover, the password itself.
  • Session records: the fact that a session exists, when it was created, and the IP address and user-agent it was created from.
  • Security audit records: sign-ins, session expiry, organisation creation and deletion, data export, role changes, membership changes — with the acting account, the time, and the originating IP address and user-agent.
  • Which organisations you belong to, and your role in each.

About workers, on our customers’ behalf

  • Name, job role, an avatar or initials, and default daily capacity.
  • Availability and capacity periods — a date range and a type (for example out of office). NorthStar does not ask for a reason and provides no field for one.
  • Planning data: which worker is assigned to what, when, and for how long, plus the history of those decisions and any comments a planner writes.
  • Baselines: frozen snapshots of a committed plan, kept deliberately unmodifiable so a record of what was agreed survives later changes.

What we do not collect

No advertising or analytics identifiers. No behavioural tracking. No third-party scripts, fonts or content-delivery networks — the application loads only its own code, which is also why it works with a strict content-security policy. We do not sell personal data, and we do not use it to train machine-learning models.

3. Cookies

NorthStar sets one cookie, and only after you sign in: a session cookie named northstar.session_token. It is strictly necessary — it is what keeps you signed in — so no consent banner is required for it under the ePrivacy rules or PDPA.

  • It is HttpOnly, so no script can read it, SameSite=Lax, and Secure over HTTPS.
  • It carries an opaque reference to a session row in our database, not your data. We can revoke it server-side, and do — signing out, changing your password or resetting it deletes the session immediately.
  • There are no analytics, advertising or preference cookies of any kind. The application also stores a working copy of your plan in your browser’s local storage so it stays responsive; signing out clears it.

4. Why we process it, and on what basis

  • To provide the service — account data and planning data. GDPR Art. 6(1)(b), performance of a contract.
  • To keep the service secure — session records, audit records, rate limiting. GDPR Art. 6(1)(f), our legitimate interest in preventing unauthorised access to our customers’ data, and Art. 32 security obligations.
  • To communicate about your account — the confirmation and password-reset emails. Contract necessity; we send no marketing email.
  • Worker data — processed only on the customer organisation’s documented instructions (GDPR Art. 28). The lawful basis for holding it is the customer’s to establish.

Under Singapore’s PDPA, which is built around consent rather than a choice of six bases, the equivalent framing is that we collect user data to provide a service the user has asked for, and worker data on behalf of the customer organisation, which is responsible for its own consent or applicable exception in the employment relationship.

5. Where it is stored, and who else touches it

Your data is stored in a PostgreSQL database hosted by [HOSTING PROVIDER] in [HOSTING REGION]. Each organisation’s records are separated at the database level by row-level security keyed to the organisation, so a query made in one organisation’s context cannot return another’s rows. Transport is encrypted (TLS); the database is encrypted at rest by the host.

Our sub-processors:

  • [HOSTING PROVIDER] — application and database hosting, in [HOSTING REGION].
  • Resend — delivery of account emails (confirmation and password reset). It receives the recipient address and the message body, and no planning data.

We will publish an updated list before adding a sub-processor that handles personal data. If you need the current list in writing for a procurement review, ask at [SUPPORT_EMAIL].

International transfers

Where data is transferred outside the EEA or outside Singapore, we rely on the appropriate mechanism for that transfer — an adequacy decision or standard contractual clauses under the GDPR, and comparable-protection safeguards under the PDPA’s Transfer Limitation Obligation. Our intended posture is a single hosting region so that most customer data does not cross a border at all; the region is recorded above.

6. How long we keep it

  • Planning and worker data — for as long as the organisation exists. When an organisation is deleted, its projects, tasks, allocations, workers, availability, comments and baselines are deleted with it.
  • Account data — until you delete your account, at which point the account, its credential and every session are removed.
  • Sessions and expired links — sessions have both an idle timeout and an absolute maximum lifetime; confirmation, reset and invitation tokens are single-use and expire.
  • Security audit records — kept deliberately beyond the deletion of the organisation they describe, because a record that can be erased by the event it records is not an audit record. Target retention: [AUDIT RETENTION PERIOD].
  • Backups — encrypted backups are retained on a rolling schedule and overwritten in turn, so deleted data can persist in a backup for up to [BACKUP RETENTION PERIOD] after deletion.

Stated plainly: automated, per-record retention enforcement is still being built. Today, data is removed when you or your organisation removes it, or when we act on a request under section 7 — not on a timer.

7. Your rights

Under the GDPR you have rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where processing rests on it. Under the PDPA you have rights of access and correction, and may withdraw consent. We do not charge for exercising them, and we will respond within one month (GDPR) or as soon as reasonably possible (PDPA).

  • If you are a user: much of this is self-serve — the account page changes your password and deletes your account, and an administrator can export or delete an organisation. For anything else, write to [SUPPORT_EMAIL].
  • If you are a worker: contact the organisation that plans with NorthStar. They control that data; we act on their instructions, and we can remove or anonymise an individual worker’s record at their request.

You may also complain to a supervisory authority — in the EEA, your local data protection authority; in Singapore, the Personal Data Protection Commission. We would rather you told us first at [SUPPORT_EMAIL].

8. Security

  • Passwords are hashed; sessions are database-backed and revocable server-side.
  • Every organisation’s data is isolated at the database level, and the isolation is enforced even for our own application code.
  • Access to consequential actions requires both an appropriate role and, for the most destructive ones, a recently authenticated session.
  • A strict content-security policy, a full security-header set, no third-party scripts, and rate limiting on authentication endpoints.
  • An append-only security audit log that records who did what, and cannot be edited to hide it.

No system is perfectly secure. If we suffer a breach affecting your personal data we will notify the relevant supervisory authority and, where the risk to you is high, notify you — within 72 hours of becoming aware under the GDPR, and as soon as practicable under the PDPA.

9. Changes to this policy

We will post any update here and change the effective date. If a change materially affects your rights we will email the address on your account before it takes effect.

10. Contact

[COMPANY LEGAL NAME], [POSTAL ADDRESS] — [SUPPORT_EMAIL]. See also our Terms of Service.

Privacy Policy — NorthStar