Privacy policy
1. Who is responsible for this website
MP Star Personal, Albert Voglar
Sant Miquel 68 8A, 07002 Palma de Mallorca, Spain
Email: office@star-personal.com
Phone: +34 610 738 619
2. What we are here for
We place staff. To do that we need contact details — and as little else as possible. Whatever you give us is used solely to talk to you and to arrange a placement.
What we explicitly do not do:
- We do not pass your data to third parties — apart from the service providers who technically run this website and our mailbox (section 6), and there only as far as operation requires.
- We do not add you to any mailing list. There is no newsletter and there are no promotional emails.
- We do not sell data and we do not compile lists.
- We make no automated decisions about you. Every enquiry and every application is decided by a person.
- We build no profile of your behaviour on this website — we do not track which pages you open one after another. An enquiry does receive two automatically calculated figures: how complete it is and how urgent it is rated. Both only order our own work. Every enquiry is decided by a person.
3. Staff enquiries and applications
What we collect
In both forms, first name, surname, email address and phone number are required. The reason is practical: placement work happens on the phone. An enquiry we cannot reach is one we cannot act on.
Everything else — dates, location, number of guests, budget range, work experience, languages, availability — is optional in a staff enquiry. It helps us make a fitting proposal. Without it we can still work; it just takes longer.
An application asks for more. Besides your contact details you must state which positions you offer, since when you have worked in the trade, your year of birth, which languages you speak, from when you are available, in what form you want to work and in which region. Without those we cannot place you. We need the year of birth because statutory limits attach to age — for night work, for instance. We deliberately ask for the year rather than the age, so the entry does not quietly become wrong over time.
No CVs
For an application we ask for no CV and no files. You tick which positions you work in, since when, and when you are available. That is enough for a first conversation.
We ask for documents only when things get concrete — and then from you directly. That way we hold no application folders from people we have never spoken to.
Legal basis
Article 6(1)(b) GDPR — steps taken at your request prior to entering into a contract. You write to us because you want something from us; we process your details in order to do exactly that.
The consent you give when submitting documents your agreement to this processing.
Who sees your details
Only staff at MP Star Personal involved in placement. Access to the internal area is protected by a password and an additional code sent by email.
If a placement comes about, we pass on the details required for it to the other side — that is, to the client or to the professional. That is the purpose of a placement agency, and we do it only once both sides want it.
A profile in our register does not appear by itself. An application becomes a register entry only when we create one by hand — and it then sits as a draft, invisible to the public. Your email address and phone number are not carried over; they stay with the application. Your name appears abbreviated, for example “Marco S.”. Such a profile becomes publicly visible — with a photo, job title, availability and working area, with its own page and an entry in our index for search engines — only with your separate consent, which we obtain from you beforehand. The tick box in the application form does not cover this. You may withdraw consent once given at any time; we then take the profile off the website.
4. Your entries stay saved on your device
While you fill in the enquiry or application form, your browser saves what you have entered on your own device (localStorage). If you are interrupted or close the window, you can continue later without typing everything again.
- Nothing is transmitted. Your entries leave your device only when you press send.
- They expire after seven days on their own.
- After sending they are deleted.
- The consent box is never saved. You have to tick it each time.
- You can clear everything yourself at any time, using the “Discard entries” button below the form.
Why this needs no consent: under Article 22.2 LSSI-CE (Ley 34/2002) and the underlying European rule, storing information on a device is exempt from consent where it is strictly necessary to provide a service explicitly requested by the user. A form you started yourself and want to continue falls under that — the same case as a shopping basket in an online shop. Nothing is analysed and nobody but you sees this data.
If you are on a shared or public computer, please clear your entries using that button before you leave.
5. Cookies and statistics
This website sets no advertising cookies and embeds no social media components.
A session identifier is technically necessary as soon as someone signs in to the internal area. As a visitor to the website you do not receive one.
Statistics are collected only with your consent (Article 6(1)(a) GDPR). You give or withhold it in the notice on your first visit and can change your mind at any time via “Cookie settings” in the footer. Without consent, nothing is loaded.
The statistics service we intend to use is Google Analytics 4. The recipient is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; its parent company Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, is technically involved. As long as no measurement ID is entered in our administration, none of this happens — and then there is nothing for you to consent to either.
How it works. The Google script is not in the page. It is fetched from a Google server only once you have agreed to the “Statistics” category. Before that, Google is not contacted at all — not even with the anonymous signals otherwise common, because those would require the script to be loaded. The default in consent mode is denied, for statistics as well as for advertising and personalisation. Only statistics is released, and only by your agreement.
What is then collected. Pages opened and time spent, referring
page, browser, operating system, device type and screen size, language setting, an
approximate location at city and country level, and a random identifier by which
your device is recognised again. What is not collected is your name,
and nothing you type into a form. Your IP address is transmitted technically —
without it no connection would come about — but serves solely to derive the
approximate location; according to Google it is neither logged nor stored for visits
from the EU. Google sets two cookies in the process, _ga and
_ga_…, with a lifetime of two years.
Transfer to the United States. A transfer to servers in the United States cannot be ruled out. Google LLC is certified under the EU-US Data Privacy Framework; the transfer therefore rests on the European Commission’s adequacy decision of 10 July 2023 (Article 45(3) GDPR). In addition, the standard contractual clauses issued by the Commission (Article 46(2)(c) GDPR) apply; they form part of Google’s data processing terms and continue to serve as a basis should the adequacy decision fall away. A residual risk remains all the same: US authorities can access data under certain conditions, and legal protection equivalent to the European one is not guaranteed in every case. That is precisely why we ask first.
Legal basis and withdrawal. That anything is stored on your device and read from it at all happens solely on the basis of your consent (Article 22.2 LSSI-CE, Ley 34/2002); the subsequent processing rests on Article 6(1)(a) GDPR. You may withdraw at any time with effect for the future — via “Cookie settings” at the foot of the page. From the moment of withdrawal nothing further is transmitted to Google. Cookies already set do remain on your device until they expire, unless you delete them in your browser; its help explains how. Google also offers a browser add-on that prevents collection across all websites: tools.google.com/dlpage/gaoptout. How long Google keeps the collected data is set by us in our Google account; the choices there are two or fourteen months.
Your decision about statistics is not stored with us but in your
browser’s local storage, under the key mpsp_consent and together with
the time. After 180 days we ask again rather than quietly carrying an old agreement
forward.
The Instagram section on the home page is not an embedded widget. We fetch the images onto our own server and serve them from there. Your browser never connects to Instagram or Meta, no cookies are set, and no data is passed on.
The WhatsApp button is likewise just an ordinary link to
wa.me. Only when you click it do you leave this website and open a
connection to WhatsApp; from then on Meta’s privacy terms apply. Nothing is passed
there beforehand.
6. Technical service providers
To run this website we work with providers who process data on our behalf (processing under Article 28 GDPR). Corresponding agreements are in place.
- Hosting — operation of the server this website runs on.
- Email delivery — sending your confirmation and our internal notification.
The servers for hosting and email delivery are located in the European Union. A recipient outside the EU is added only if you consent to statistics (section 5).
7. Server logs
Like every web server, ours records which pages are requested: time, address requested, browser identification and IP address.
The legal basis is Article 6(1)(f) GDPR — our legitimate interest in secure and functioning operation. These logs are deleted after 14 days at the latest and are not combined with other data.
With each enquiry we additionally store a checksum of your IP address — not the address itself. It is produced by putting the address together with a secret addition through a one-way procedure; from the result we cannot restore your address. We nevertheless treat the checksum as personal data, because for the same address it always comes out the same. It serves solely to fend off bulk form submissions; when signing in to our administration it is used for the same purpose. The legal basis is Article 6(1)(f) GDPR.
We also store, along with the enquiry, which page you came to us from, whether the address you opened carried a campaign tag, which browser and device type you used, and which time zone your device is set to. The time zone is reported by your browser when you send the form. This helps us understand what an enquiry refers to — whether someone arrived from a particular job posting, for instance. Unlike the server logs above, these details are kept for as long as the enquiry itself. The legal basis is Article 6(1)(f) GDPR.
How we fend off form spam. Three rules apply on sending, none of which stores anything about you: a field invisible to humans must stay empty, at least three seconds must pass between opening and sending, and from the same IP checksum we accept at most five forms per hour. We do not score your enquiry and award no suspicion points. If one of the rules applies, the submission is discarded and nothing is stored.
What arises internally around a case. We additionally store your answers in searchable form: the features you ticked, such as languages, availability and region, and the positions sought or offered, with quantities. Added to that is a history recording when the enquiry arrived and who on our side changed its status, plus the two figures already mentioned for completeness and urgency. Staff can also add internal notes to a case. The legal basis is Article 6(1)(b) GDPR and, as regards ordering our own work, Article 6(1)(f) GDPR.
Change log in the internal area. Every sign-in and every change anyone makes in our administration is recorded: with the time, the user account, a checksum of the IP address and a short label of the item concerned — which may include a name. This serves to show who changed what, and to investigate unauthorised access. The legal basis is Article 6(1)(f) GDPR.
Sign-in with a second factor. Whoever signs in to the internal area receives a six-digit code by email. Only an irreversible checksum of it is stored, together with the expiry time — ten minutes — and a checksum of the IP address. Anyone having their device remembered additionally gets an entry with a rough device label such as “Chrome on macOS”, valid for 30 days from last use. The full browser identification is not stored. This concerns only our own accounts, not visitors to the website.
Error logs. When something goes wrong technically, the server writes a line with the time and the error message. If sending a confirmation fails, that line also contains the email address concerned. These logs serve solely for fault-finding; they are not analysed and not combined with other data (Article 6(1)(f) GDPR).
8. How long we keep your details
| Type of data | Retention |
|---|---|
| Enquiries that did not lead to a placement | 12 months after last contact |
| Applications that did not lead to a placement | 12 months — you may object earlier at any time |
| Details of placements that went ahead | for the duration of the business relationship, then according to statutory retention periods |
| Contact messages | 6 months after the matter is closed |
| Server logs | 14 days |
| Your entries in the browser | 7 days, on your device |
| Checksum of the IP address | together with the case it belongs to |
| Change log in the internal area | as long as the case or content it refers to |
| Sign-in code for the administration | 10 minutes |
| Remembered device for signing in | 30 days after last use |
| Your decision about statistics | 180 days, on your device |
| Statistics data at Google — only after consent | according to the period set in our Google account |
| Server error logs | until they are no longer needed for fault-finding |
We keep applications for a year because our business is seasonal: someone who did not fit in autumn may be exactly right in spring. If that is too long for you, write to us — we will delete straight away.
9. Your rights
You have the right at any time to
- access the data we hold about you (Article 15 GDPR),
- rectification of incorrect details (Article 16 GDPR),
- erasure (Article 17 GDPR),
- restriction of processing (Article 18 GDPR),
- data portability (Article 20 GDPR),
- object to processing based on legitimate interest (Article 21 GDPR),
- withdraw consent with effect for the future (Article 7(3) GDPR).
An informal email to office@star-personal.com is enough. We reply within one month. This costs you nothing.
10. Complaints
If you are unhappy with how we handle your data, you can complain to a supervisory authority. The competent one is the Spanish data protection authority:
Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan 6, 28001 Madrid, Spain
www.aepd.es
You may also contact the supervisory authority in your country of residence.