Kervo AI
[ Legal ]Privacy Policy
Your privacy matters

Privacy Policy

What information cloudDFN LLP collects through the Kervo AI platform and website, how we use and share it, and the choices and rights you have.

Last updated: October 5, 2026Effective: September 1, 2026
We don't sell your data

Personal information is never sold.

Processor for your environment

Customer environment data is processed only under our DPA.

Encrypted in transit and at rest

Access controls and audit logging throughout.

Data localization available

Host in your country or region where required.

1. Who we are

cloudDFN LLP ("cloudDFN", "we", "us" or "our") operates the Kervo AI security platform and the website at https://kervo.ai (together, the "Platform"). cloudDFN LLP is the data controller responsible for your personal information under this policy.

  • Legal entity: cloudDFN LLP
  • Contact: support@clouddfn.com

Where cloudDFN processes personal data on behalf of a customer using the Kervo AI platform (for example, data within a customer's environment that the platform analyzes), cloudDFN acts as a data processor and the customer is the data controller. In those cases, our processing is governed by the Data Processing Agreement (DPA) between us and the customer.

2. Scope

This policy applies to personal information we collect through:

  • our website and marketing pages;
  • account registration, demos, and sales inquiries;
  • use of the Kervo AI platform by authorized users; and
  • communications with us (email, support, events).

It does not apply to third-party websites or services that we link to but do not control.

3. Information we collect

Information you provide to us

  • Contact and account details: name, work email, company name, job title, phone number.
  • Demo and sales information: company size, use case, current tooling, and anything you include in a message to us.
  • Account credentials and profile settings for platform users.
  • Billing and transaction details (processed through our payment provider; we do not store full card numbers).
  • Any content you submit to support, surveys, or communications.

Information we collect automatically

  • Usage and device data: IP address, browser type, operating system, pages viewed, referring URLs, timestamps, and interactions with the Platform.
  • Cookies and similar technologies (see Section 7).
  • Log and diagnostic data generated when you use the platform.

Information from third parties

  • Enrichment and analytics providers, event partners, and referrals.
  • Authentication providers (for example, single sign-on) when you choose to use them.

Customer environment data

When a customer connects their environment to the Kervo AI platform, the platform processes technical and security data (such as asset inventories, configurations, vulnerability findings, and logs) that may incidentally contain personal data. We process this data as a processor, only to provide the Platform, under our agreement with the customer.

4. How we use information

We use personal information to:

  • provide, operate, maintain, and secure the Platform;
  • create and manage accounts and authenticate users;
  • respond to demo requests, inquiries, and support;
  • process transactions and send related information;
  • communicate about updates, security, and (where permitted) marketing;
  • detect, prevent, and address fraud, abuse, and security incidents; and
  • comply with legal obligations and enforce our terms.

We do not use personal information to analyse, improve or develop the Platform. We collect product usage telemetry, such as page views, sessions, feature usage and errors, only in de-identified form that does not identify you, and use it to operate and improve the Platform.

We do not sell your personal information.

6. How we share information

We share personal information only as described here:

  • Service providers / sub-processors: hosting, analytics, payment processing, email, and support vendors who process data on our behalf under contract. A current sub-processor list is available on request.
  • Professional advisors: lawyers, auditors, and accountants where necessary.
  • Legal and safety: to comply with law, respond to lawful requests, or protect the rights, property, and safety of cloudDFN, our users, or others.
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
  • With your direction or consent.

7. Cookies, analytics and advertising

Our website asks for consent before it uses anything beyond strictly necessary technologies, wherever the law requires it, including India, the EEA, the UK and Switzerland.

  • Always on: a record of your consent choice, and Vercel Web Analytics, which counts visits in aggregate without cookies.
  • With analytics consent: we keep our own visitor log, stored on our servers in India: the pages you view, time on each page, how far you scroll, how you reached us, your approximate location (city level), language, device type, and the organisation that owns the network you browse from. To identify that organisation we send your IP address once to IPinfo, which returns the network owner; we never store your IP address. A summary of each visit is emailed to our sales team through our Microsoft 365 business email. If you later send us a form or book a meeting, your earlier visits are linked to the details you give us so our team can follow up.
  • With marketing consent: the Google Ads tag and the LinkedIn Insight Tag measure our advertising and enable ads to past visitors. Data is shared with Google and LinkedIn.
  • With consent for embedded services: the Calendly booking calendar.

Consent records are stored in India. You can change or withdraw consent at any time from Cookie settings at the bottom of every page. See our Cookie Policy for the full list.

8. Data retention

We retain personal information only as long as necessary for the purposes described in this policy, including to provide the Platform, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type and context. When no longer needed, we delete or anonymize the data.

9. Data security

We maintain administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit and at rest, access controls, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Data localization and international transfers

Data localization. We support data localization for customers who require it. Depending on the country in which a customer's headquarters is located, and based on the customer's requirements, we can host and store that customer's data in data centers and hosting providers located within that country or region. Where a customer selects a specific hosting region, their platform data is stored and processed in that region in accordance with the terms agreed with the customer.

International transfers. Where data is not subject to a localization arrangement, we may process and store information in countries other than where you live. Where we transfer personal data out of the EEA, UK, or other regulated regions, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.

11. Your rights

Depending on where you live, you may have the right to:

  • access the personal information we hold about you;
  • correct inaccurate or incomplete information;
  • delete your information;
  • restrict or object to certain processing;
  • data portability;
  • withdraw consent at any time; and
  • lodge a complaint with a supervisory authority.

EEA/UK residents may exercise these rights under the GDPR/UK GDPR. California residents have rights under the CCPA/CPRA, including to know, delete, correct, and opt out of "sale" or "sharing" of personal information (we do not sell personal information) and the right not to be discriminated against for exercising these rights.

To exercise any right, contact us at support@clouddfn.com. We will respond within the timeframe required by applicable law and may need to verify your identity. If your data is processed by cloudDFN as a processor on behalf of a customer, please direct your request to that customer (the controller); we will assist them as required.

12. Third-party links and services

The Platform may link to third-party sites and integrate with third-party tools. We are not responsible for their privacy practices. Review their policies before providing information.

13. Children's privacy

The Platform is intended for businesses and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date and, where required, provide additional notice. Your continued use of the Platform after changes take effect constitutes acceptance.

15. Contact us

If you have questions about this policy or our data practices, contact:

cloudDFN LLP Email: support@clouddfn.com

Have questions about this document?

We typically respond to privacy and legal requests within 24 hours.