GetStars

Privacy

GetStars records what colleagues say about each other at work. That is personal data about identifiable people, so this page says plainly what is stored, who can see it, and what is not anonymous.

Who is responsible for what

Your employer decides to use GetStars, decides who is asked, and decides who reads the results. In data-protection terms your employer is the controller and Brightness AS is the processor: we run the service and hold the data on their instruction, and we do not decide what it is used for.

So if you want to know why your employer runs these rounds, what they do with the results, or what legal basis they rely on, ask them, those are their decisions, not ours. If you want to know what the software does, that is this page.

For customers: a data processing agreement should be in place with Brightness AS before real employee data is entered. If you do not have one, ask for it before you start.

What is stored

There is no tracking beyond that. No analytics, no advertising, no third-party scripts, and the fonts are served from this site rather than from anyone else's, so loading a page does not tell another company that you visited.

What is not anonymous

This is the part worth reading twice. Your answers are not anonymous. The database records which person gave which rating to which colleague. It has to, in order to weight ratings and to stop one person answering twice.

What the reports show is narrower than what is stored:

So: aggregated in the report, attributable in the database. Anyone with administrative access to the underlying system could in principle join the two. Do not treat GetStars as a confidential channel, and do not write anything in a free-text answer that you would not put in an e-mail.

Who can see it

Others who process data for us

Cookies

One cookie, called getstars_session. It holds your signed-in e-mail address in signed form, so the service knows who you are between pages. It expires after twelve hours, and signing out clears it. There are no analytics or advertising cookies, so there is no cookie banner to click away.

How long it is kept

Until your employer or Brightness AS deletes it. There is no automatic expiry: a round from two years ago is still in the report history unless somebody removes it. When an administrator removes a colleague, that person is deactivated rather than erased, so past answers remain consistent, they can no longer sign in, and they no longer appear in new questionnaires.

When a company is deleted from the platform, everything belonging to it goes with it: the roster, the rounds, the ratings and the answers.

Your rights

Under the GDPR you can ask for a copy of your personal data, ask for it to be corrected, ask for it to be deleted, and object to how it is used. Because your employer is the controller, start with them, whoever administers GetStars where you work. They can act on the roster directly, and we act on their instruction for anything else.

You can also complain to your national data protection authority. In Norway that is Datatilsynet.

Platform contact: ask your administrator for the current Brightness AS privacy contact. It is not published here rather than published wrongly.

Security, honestly

Sign-in is Google only, so there is no password here to leak. Pages are served over HTTPS, company data is separated in the database, and the platform's own actions inside a customer's company are logged. Two things are worth knowing rather than glossed over: an e-mail domain is verified by us before it can be used to join a company, and a company administrator can see the whole company's report by design. Nothing here is a substitute for your employer deciding carefully who administers it.

Changes

If this page changes materially, the change lands with a new version of the service, the version number in the footer tells you which build you are reading.

Back