KERN trust center
Privacy policy
This is a transparency page for how KERN handles personal data in practice. It is not a promise that every workflow is fully automated in self-serve mode.
Quick links
Sections: 13
What this page does and does not promise
This page explains current operational privacy posture and request paths for KERN.
It does not promise completed certification, universal legal coverage in every jurisdiction, or fully automated rights handling for all request types.
What KERN processes
KERN processes account identifiers, workspace activity, user-provided material, and operational metadata needed to deliver verification and investigation workflows.
Processing is limited to service operation, abuse prevention, integrity controls, support, and legal obligations.
Account, contact, and support data
Account profile and support interaction data are used for authentication, service delivery, and support case handling.
Enterprise or public-sector onboarding may include organizational contact and billing-related details.
Usage and security telemetry
KERN stores operational telemetry and audit-oriented metadata to monitor integrity, detect abuse, and investigate incidents.
These records can be retained to preserve traceability and support lawful security response.
Uploaded and user-provided material
KERN processes user-provided documents, claims, notes, and evidence references to render workspace functions and keep source traceability.
Export and portability depth can differ by plan and rollout state, and some request outcomes require manual handling.
Retention and deletion reality
Data is retained only while needed for operations, legal obligations, dispute handling, and service integrity controls.
Deletion and export paths are not all self-serve. Some data handling actions require manual handling.
Access, correction, deletion, restriction, portability, and objection requests
Users can submit rights requests through support for access, correction, deletion, restriction, portability, and objection.
Request handling depends on legal scope, system boundaries, security constraints, and data-location context.
Identity verification and request handling limits
KERN requires identity verification and scope clarification before executing rights-impacting actions.
If identity cannot be verified or the request is overbroad, handling can be limited, deferred, or rejected with rationale.
Security and audit orientation
KERN uses access boundaries, logging, and traceability-oriented controls to support operational security.
Security controls reduce risk but do not guarantee that incidents are impossible.
Cross-border transfers, processors, and vendors
KERN may use third-party infrastructure and processing partners needed to operate the service.
Cross-border processing can occur based on deployment and vendor setup. This page provides high-level framing, not a full public processor register.
No fully automated significant decisions
KERN is positioned as decision support and does not present itself as making fully automated legal or similarly significant decisions about individuals.
Human review and accountable operation remain required for high-impact outcomes.
Children/minors policy and age position
KERN is not intended for use by individuals under 18.
KERN may enforce an 18+ eligibility rule as a product access policy.
This age rule is a KERN service policy and not a statement that all laws universally require age 18 for similar services.
Controller and contact
Controller: Oziro AB (559302-5363), Sweden.
Contact: support@kernbot.com for privacy and data-rights matters, including escalation requests.
Related policies