Stardex Privacy Policy


Last Updated: Feb 20, 2026

1. Introduction


At Stardex (SedimentIQ Corp, "we," "us," "our"), we are committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and protect information about users ("you," "your") of our Stardex software-as-a-service (SaaS) platform, an AI-native ATS and CRM designed for recruiting and executive search firms. We understand the sensitive nature of the data you entrust to us, and we take our responsibility to safeguard it seriously.


Our Role in Data Processing


Stardex handles two distinct categories of data, and our role differs for each:

  • Data we control (Controller): We act as the data controller for information we collect directly from you to operate the platform, such as your account information (name, email, company), billing details, usage data, and device/log data. We determine the purposes and means of processing this data.

  • Data we process on your behalf (Processor/Service Provider): We act as a data processor (or "service provider" under California law) for the candidate data, client data, communications, notes, and other recruitment-related information that you and your team input into or manage through the Stardex platform ("Customer Data"). You, as our customer, are the controller of this data. We process it only on your instructions and solely to provide the Services. Our obligations as a processor are further detailed in our Data Processing Addendum.


The rights and choices described in this Privacy Policy (Sections 8 and 9) apply to the data we control. For Customer Data that we process on your behalf, data subject requests (such as access, correction, or deletion of candidate records) should be directed to you as the controller, and we will assist you in fulfilling those requests as described in our DPA.

2. Information We Collect

We collect information that you provide directly to us, information we automatically collect when you use our platform, and information from third-party sources.


a. Information You Provide Directly

  • Account Information: When you create an account, we collect your name, email address, company name, and other contact details.

  • Billing Information: We use Stripe, a third-party payment processor, to handle payment transactions. We do not store your full credit card details. Stripe collects and processes your payment information according to its own privacy policy.

  • Candidate and Client Information: As a CRM and ATS platform, you will input and manage information about candidates and clients, which may include names, contact information, resumes, employment history, communication records, and other data relevant to the recruitment process.

  • User Content: Any other information you choose to upload or input into the platform, such as notes, comments, documents, or other content.


b. Information We Collect Automatically

  • Usage Data: We collect information about how you use our platform, including features used, pages visited, actions taken, and frequency of use.

  • Device Information: We may collect information about the devices you use to access our platform, including IP address, operating system, browser type, and device identifiers.

  • Log Data: Our servers automatically record certain log information, such as your IP address, browser type, access times, pages viewed, and the page you visited before navigating to our platform.

  • Cookies and Similar Technologies: See Section 13 (Cookie Policy) for details.


c. Information from Third-Party Sources

  • Email Integration Data: If you choose to integrate your email account with Stardex using a supported email integration provider, and only if you explicitly opt in, we will access and collect data necessary to provide email automation and tracking features. This may include email headers, sender and recipient information, email content (for tracking and sync purposes), and email metadata. We access this data securely through OAuth 2.0 authorization and appropriate scopes, and we only collect and use data with your explicit consent.

  • Third-Party Integrations: If you connect Stardex with other third-party services (such as calendar, messaging, or productivity tools), we may receive data from those services as needed to provide the integration functionality you have enabled.

  • Browser Extension Data: The Stardex browser extension is an optional add-on to the platform. The extension does not passively collect, monitor, or transmit data about your browsing activity. Data is only collected when a user actively clicks to import or interact with information on a supported site (such as a candidate profile). The extension does not scrape pages, or send data to Stardex without an explicit user action. The extension only operates on sites that the recruiting firm's users have agreed to use in connection with Stardex.

3. How We Use Your Information

We use your information for the following purposes:

  • To Provide and Maintain the Stardex Platform: We use your information to operate, maintain, and improve the Stardex platform and its features, including providing customer support, troubleshooting issues, and developing new features.

  • To Process Payments: We use Stripe to process payments for your Stardex subscription.

  • To Communicate with You: We may use your information to send you important updates, security alerts, administrative messages, and respond to your inquiries and requests.

  • To Personalize Your Experience: We may use your information to personalize your experience on the Stardex platform, such as suggesting relevant features or content.

  • For Email Automation and Tracking (with Opt-In Consent): If you opt in and integrate your email, we will use your email data to enable you to send emails and track their delivery and engagement. This is done securely and only with your explicit consent.

  • To Power AI Features: We use your data within the platform to provide AI-powered features such as semantic search, candidate matching, and workflow automation. This processing happens in real-time to serve your queries and is not used for model training. See Section 7 for details.

  • For Security Purposes: We use your information to protect the security and integrity of our platform, investigate suspicious activity, and prevent fraud and abuse.

  • For Compliance with Legal Obligations: We may use your information to comply with applicable laws, regulations, legal processes, or governmental requests.

  • For Analytics and Improvement: We may use aggregated and anonymized data for analytical purposes to understand how our platform is used and to improve its performance and functionality.

4. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties. We may share your information in the following limited circumstances:

  • With Service Providers: We may share your information with trusted third-party service providers who assist us in operating our platform, such as hosting providers, payment processors, email service providers, and AI infrastructure providers. These providers are contractually obligated to protect your information and only use it for the specific purposes for which it is disclosed. A current list of our subprocessors is available upon request and is included in our Data Processing Addendum.

  • With Your Consent: We may share your information with third parties if you have given us your explicit consent to do so.

  • For Legal Reasons: We may disclose your information if required by law, such as to comply with a subpoena, court order, or other legal process, or to protect our rights, property, or safety, or the rights, property, or safety of others.

  • In Connection with a Business Transaction: In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred to the acquiring entity. We will notify you via email and/or a prominent notice on our platform of any change in ownership or uses of your personal information.

SMS consent is not shared with third parties.

5. Data Security

We take the security of your information seriously. We implement industry-standard security measures to protect your information from unauthorized access, use, disclosure, alteration, or destruction. These measures include:

  • Encryption: We use encryption to protect data both in transit (TLS 1.2+) and at rest (AES-256).

  • Access Controls: We restrict access to your information to authorized personnel only, using role-based access controls and multi-factor authentication.

  • Regular Security Audits: We conduct regular security audits and assessments to identify and address potential vulnerabilities. We maintain SOC 2 Type II compliance.

  • Data Breach Response Plan: We have a data breach response plan in place to address any potential security incidents promptly and effectively.

  • Secure Third-Party Providers: We use only reputable third-party providers that adhere to strict security standards.

While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. Therefore, we cannot guarantee absolute security.

6. Data Retention

We retain different categories of data for different periods based on their purpose:

  • Customer Data (candidate records, client records, notes, communications): Retained for the duration of your subscription. Upon termination, Customer Data is available for export for ninety (90) days, after which it is securely deleted.

  • Backups: Encrypted backups of Customer Data are retained for up to 30 days on a rolling basis for disaster recovery purposes. Backups are automatically purged after 30 days.

  • Audit Logs: Platform audit logs (such as user login events, record changes, and data access logs) are retained for 30 days.

  • Account Information (name, email, billing): Retained for the duration of your subscription and for a reasonable period after termination as needed for billing, legal, or compliance purposes.

  • Usage and Analytics Data: Retained in aggregated, anonymized form and may be kept indefinitely for product improvement purposes.

  • Subprocessor Retention: Our third-party AI providers (Anthropic, OpenAI, Microsoft Azure) operate on a zero-retention basis for Customer Data passed through their APIs. Data is processed in real-time and not stored after the API request completes. Other subprocessor retention periods are governed by our agreements with those providers and are detailed in our Data Processing Addendum.

7. No Training on Your Data

We are committed to your privacy. We do not use your data to train our AI models or any third-party AI models. AI features in Stardex process your data in real-time to serve your queries (such as search and matching), but this data is not retained for or used in model training. Where we use third-party AI providers to power certain features, we contractually require that those providers do not use your data for training purposes either. Your data remains yours.

8. Your Rights and Choices

You have certain rights regarding your personal information, including:

  • Access: You have the right to access the personal information we hold about you.

  • Correction: You have the right to request that we correct any inaccurate or incomplete information we hold about you.

  • Deletion: You have the right to request that we delete your personal information, subject to certain exceptions.

  • Restriction of Processing: You have the right to request that we restrict the processing of your personal information in certain circumstances.

  • Data Portability: You have the right to receive a copy of your personal information in a structured, commonly used, and machine-readable format.

  • Withdraw Consent: If we rely on your consent to process your personal information, you have the right to withdraw your consent at any time.

  • Object to Processing: You may have the right to object to the processing of your data.

  • Lodge a Complaint: If you believe that we have breached our obligations to you under this Privacy Policy or relevant privacy laws, please contact us at support@stardex.ai.

To exercise any of these rights, please contact us at support@stardex.ai.

9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act ("CCPA") and the California Privacy Rights Act ("CPRA"):

  • Right to Know: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which we collected it, our business purpose for collecting it, and the categories of third parties with whom we share it.

  • Right to Delete: You have the right to request that we delete personal information we have collected from you, subject to certain exceptions.

  • Right to Correct: You have the right to request that we correct inaccurate personal information we maintain about you.

  • Right to Opt-Out of Sale or Sharing: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising purposes.

  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.

To exercise your California privacy rights, please contact us at support@stardex.ai. We will verify your identity before processing your request.

Categories of Personal Information Collected: We collect identifiers (name, email, IP address), commercial information (billing records), internet or electronic network activity (usage data, log data), professional or employment-related information (to the extent included in candidate data you input), and inferences drawn from the above.

We do not sell personal information. We do not use or disclose sensitive personal information for purposes other than those permitted under the CCPA/CPRA.

10. Children's Privacy

Our platform is not intended for use by children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us, and we will take steps to delete such information.

11. International Data Transfers

We may transfer and process your information in countries other than your own, including the United States. These countries may have data protection laws that are different from the laws of your country. We will take appropriate measures to ensure that your information is protected in accordance with this Privacy Policy and applicable data protection laws, wherever it is processed. Such measures may include the use of Standard Contractual Clauses approved by the European Commission, or other appropriate safeguards. Where applicable, processing is governed by our Data Processing Addendum.

12. Third-Party Services and Subprocessors

Stardex integrates with and relies on third-party service providers to deliver the platform. These include hosting infrastructure, payment processing, email integration, AI model providers, analytics services, and other tools. All subprocessors are contractually bound to protect your data and process it only as instructed by us. A list of our current subprocessors is available in our Data Processing Addendum or upon request at support@stardex.ai.

13. Cookie Policy

Stardex uses cookies and similar tracking technologies to operate and improve the platform.

  • Essential Cookies: Required for the platform to function properly. These include session cookies and authentication cookies. You cannot opt out of essential cookies.

  • Analytics Cookies: Used to understand how users interact with the platform so we can improve it. These may include third-party analytics tools (such as Google Analytics or similar services).

  • Preference Cookies: Used to remember your settings and preferences within the platform.

We do not use cookies for third-party advertising or cross-site tracking. You can manage cookie preferences through your browser settings. Disabling certain cookies may affect platform functionality.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of any material changes by posting the updated Privacy Policy on our platform and updating the "Last Updated" date at the top of this page. For material changes, we will provide at least 30 days' notice via email or in-platform notification. We encourage you to review this Privacy Policy periodically.

15. Contact Us

If you have any questions or suggestions about our Privacy Policy or want to know more information about the personal information we hold, please contact us at support@stardex.ai or write to us at 169 Madison Ave #2089, New York, NY, 10016.

16. Complaints

If you believe that we have breached our obligations to you under this Privacy Policy or relevant privacy laws, please contact us at support@stardex.ai or write to us at 169 Madison Ave #2089, New York, NY, 10016. If you are not satisfied with our response, you have the right to lodge a complaint at any time to your relevant supervisory authority.