Privacy Policy
What information cloudDFN LLP collects through the Kervo AI platform and website, how we use and share it, and the choices and rights you have.
Personal information is never sold.
Customer environment data is processed only under our DPA.
Access controls and audit logging throughout.
Host in your country or region where required.
1. Who we are
cloudDFN LLP ("cloudDFN", "we", "us" or "our") operates the Kervo AI security platform and the website at https://kervo.ai (together, the "Platform"). cloudDFN LLP is the data controller responsible for your personal information under this policy.
- Legal entity: cloudDFN LLP
- Contact: support@clouddfn.com
Where cloudDFN processes personal data on behalf of a customer using the Kervo AI platform (for example, data within a customer's environment that the platform analyzes), cloudDFN acts as a data processor and the customer is the data controller. In those cases, our processing is governed by the Data Processing Agreement (DPA) between us and the customer.
2. Scope
This policy applies to personal information we collect through:
- our website and marketing pages;
- account registration, demos, and sales inquiries;
- use of the Kervo AI platform by authorized users; and
- communications with us (email, support, events).
It does not apply to third-party websites or services that we link to but do not control.
3. Information we collect
Information you provide to us
- Contact and account details: name, work email, company name, job title, phone number.
- Demo and sales information: company size, use case, current tooling, and anything you include in a message to us.
- Account credentials and profile settings for platform users.
- Billing and transaction details (processed through our payment provider; we do not store full card numbers).
- Any content you submit to support, surveys, or communications.
Information we collect automatically
- Usage and device data: IP address, browser type, operating system, pages viewed, referring URLs, timestamps, and interactions with the Platform.
- Cookies and similar technologies (see Section 7).
- Log and diagnostic data generated when you use the platform.
Information from third parties
- Enrichment and analytics providers, event partners, and referrals.
- Authentication providers (for example, single sign-on) when you choose to use them.
Customer environment data
When a customer connects their environment to the Kervo AI platform, the platform processes technical and security data (such as asset inventories, configurations, vulnerability findings, and logs) that may incidentally contain personal data. We process this data as a processor, only to provide the Platform, under our agreement with the customer.
4. How we use information
We use personal information to:
- provide, operate, maintain, and secure the Platform;
- create and manage accounts and authenticate users;
- respond to demo requests, inquiries, and support;
- process transactions and send related information;
- communicate about updates, security, and (where permitted) marketing;
- detect, prevent, and address fraud, abuse, and security incidents; and
- comply with legal obligations and enforce our terms.
We do not use personal information to analyse, improve or develop the Platform. We collect product usage telemetry, such as page views, sessions, feature usage and errors, only in de-identified form that does not identify you, and use it to operate and improve the Platform.
We do not sell your personal information.
5. Legal bases for processing
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Contract: to provide the Platform to you.
- Legitimate interests: to operate and secure the Platform and for limited marketing, balanced against your rights.
- Consent: for certain marketing communications and non-essential cookies, which you may withdraw at any time.
- Legal obligation: to comply with applicable law.
India (Digital Personal Data Protection Act, 2023). We process personal data from our website for website analytics, advertising measurement and embedded services only with your consent, given through our cookie banner for the specific purposes it lists. You can withdraw consent at any time, as easily as you gave it, from Cookie settings at the bottom of every page. Withdrawal does not affect processing that took place before it. Contact details you submit in our forms are processed to respond to your request.
8. Data retention
We retain personal information only as long as necessary for the purposes described in this policy, including to provide the Platform, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type and context. When no longer needed, we delete or anonymize the data.
9. Data security
We maintain administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit and at rest, access controls, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Data localization and international transfers
Data localization. We support data localization for customers who require it. Depending on the country in which a customer's headquarters is located, and based on the customer's requirements, we can host and store that customer's data in data centers and hosting providers located within that country or region. Where a customer selects a specific hosting region, their platform data is stored and processed in that region in accordance with the terms agreed with the customer.
International transfers. Where data is not subject to a localization arrangement, we may process and store information in countries other than where you live. Where we transfer personal data out of the EEA, UK, or other regulated regions, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.
11. Your rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you;
- correct inaccurate or incomplete information;
- delete your information;
- restrict or object to certain processing;
- data portability;
- withdraw consent at any time; and
- lodge a complaint with a supervisory authority.
EEA/UK residents may exercise these rights under the GDPR/UK GDPR. California residents have rights under the CCPA/CPRA, including to know, delete, correct, and opt out of "sale" or "sharing" of personal information (we do not sell personal information) and the right not to be discriminated against for exercising these rights.
To exercise any right, contact us at support@clouddfn.com. We will respond within the timeframe required by applicable law and may need to verify your identity. If your data is processed by cloudDFN as a processor on behalf of a customer, please direct your request to that customer (the controller); we will assist them as required.
12. Third-party links and services
The Platform may link to third-party sites and integrate with third-party tools. We are not responsible for their privacy practices. Review their policies before providing information.
13. Children's privacy
The Platform is intended for businesses and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date and, where required, provide additional notice. Your continued use of the Platform after changes take effect constitutes acceptance.
15. Contact us
If you have questions about this policy or our data practices, contact:
cloudDFN LLP Email: support@clouddfn.com
Have questions about this document?
We typically respond to privacy and legal requests within 24 hours.
