KERN trust center

v1.2Updated 2026-04-19

Privacy policy

Practical privacy notice for KERN data handling, rights requests, and operational limits.

This is a transparency page for how KERN handles personal data in practice. It is not a promise that every workflow is fully automated in self-serve mode.

Quick links

Sections: 13

What this page does and does not promise

This page explains current operational privacy posture and request paths for KERN.

It does not promise completed certification, universal legal coverage in every jurisdiction, or fully automated rights handling for all request types.

What KERN processes

KERN processes account identifiers, workspace activity, user-provided material, and operational metadata needed to deliver verification and investigation workflows.

Processing is limited to service operation, abuse prevention, integrity controls, support, and legal obligations.

Account, contact, and support data

Account profile and support interaction data are used for authentication, service delivery, and support case handling.

Enterprise or public-sector onboarding may include organizational contact and billing-related details.

Usage and security telemetry

KERN stores operational telemetry and audit-oriented metadata to monitor integrity, detect abuse, and investigate incidents.

These records can be retained to preserve traceability and support lawful security response.

Uploaded and user-provided material

KERN processes user-provided documents, claims, notes, and evidence references to render workspace functions and keep source traceability.

Export and portability depth can differ by plan and rollout state, and some request outcomes require manual handling.

Retention and deletion reality

Data is retained only while needed for operations, legal obligations, dispute handling, and service integrity controls.

Deletion and export paths are not all self-serve. Some data handling actions require manual handling.

Access, correction, deletion, restriction, portability, and objection requests

Users can submit rights requests through support for access, correction, deletion, restriction, portability, and objection.

Request handling depends on legal scope, system boundaries, security constraints, and data-location context.

Identity verification and request handling limits

KERN requires identity verification and scope clarification before executing rights-impacting actions.

If identity cannot be verified or the request is overbroad, handling can be limited, deferred, or rejected with rationale.

Security and audit orientation

KERN uses access boundaries, logging, and traceability-oriented controls to support operational security.

Security controls reduce risk but do not guarantee that incidents are impossible.

Cross-border transfers, processors, and vendors

KERN may use third-party infrastructure and processing partners needed to operate the service.

Cross-border processing can occur based on deployment and vendor setup. This page provides high-level framing, not a full public processor register.

No fully automated significant decisions

KERN is positioned as decision support and does not present itself as making fully automated legal or similarly significant decisions about individuals.

Human review and accountable operation remain required for high-impact outcomes.

Children/minors policy and age position

KERN is not intended for use by individuals under 18.

KERN may enforce an 18+ eligibility rule as a product access policy.

This age rule is a KERN service policy and not a statement that all laws universally require age 18 for similar services.

Controller and contact

Controller: Oziro AB (559302-5363), Sweden.

Contact: support@kernbot.com for privacy and data-rights matters, including escalation requests.

Related policies