Skip to main content

KERVALT / GDPR

Your GDPR rights, explained in plain language.

Kervalt processes personal data under the EU General Data Protection Regulation (GDPR). This page explains what data we process, why we process it, your rights, and how to use them.

01 / CONTROLLER

Data controller

The company responsible for personal data processed through the Kervalt platform.

Kervalt B.V.
Keizersgracht 123
1015 CJ Amsterdam
The Netherlands

Email: privacy@kervalt.com
Data Protection Officer: dpo@kervalt.com

02 / PROCESSING

What personal data we process and why

We collect and process only the personal data we need to deliver, secure, and improve our services.

Category Examples Purpose Legal basis
Account data Name, work email, company, role To provide the service and manage your account Contract (Art. 6(1)(b))
Usage data Service logs, queries, feature interactions To run the service, keep it secure, and support you Contract (Art. 6(1)(b)) / Legitimate interest (Art. 6(1)(f))
Customer content Documents, metadata, and inputs uploaded by users To index, search, and analyze the documents you upload inside the platform Contract (Art. 6(1)(b))
Marketing data Email address, company, preferences To send product updates and event invitations Consent (Art. 6(1)(a))

03 / RIGHTS

Your rights over your personal data

GDPR gives you the following rights in relation to your personal data.

Right of access

You can request a copy of the personal data we hold about you.

Right to rectification

You can ask us to correct inaccurate or incomplete personal data.

Right to erasure

You can request deletion of your personal data when there is no overriding legal reason to keep it.

Right to restrict processing

You can ask us to limit how we use your personal data.

Right to data portability

You can request your data in a structured, commonly used, machine-readable format.

Right to object

You can object to processing based on legitimate interests or direct marketing.

To exercise any of these rights, contact us at dpo@kervalt.com. We respond within 30 days and may ask you to verify your identity first.

04 / TRANSFERS

International data transfers

Kervalt keeps personal data within the European Economic Area by default.

EEA-only processing

All processing, storage, and backup infrastructure is hosted on servers in Germany, France, and the Netherlands. No customer personal data is sent to third countries for processing.

Adequacy and safeguards

If we ever need to transfer data outside the EEA for support or subprocessing, we use adequacy decisions or standard contractual clauses approved by the European Commission.

05 / RETENTION

Retention and deletion

We keep personal data only as long as necessary for the purposes described or as required by law.

Account data

Kept for as long as you have a subscription and up to 7 years after that for legal, tax, and accounting obligations.

Customer content

Kept according to your retention policy. Enterprise customers can request immediate deletion when the contract ends.

Marketing data

Kept until you withdraw consent or it is no longer needed for marketing.

06 / SECURITY

Security and breach notification

We use technical and organizational measures to protect personal data against unauthorized access, loss, or alteration.

Encryption

Locked with AES-256 when stored and TLS 1.3 when moving. Customer-managed keys available for enterprise deployments.

Access controls

Role-based access, least-privilege rules, multi-factor authentication, and full audit logging.

Breach response

In the event of a personal data breach, we notify affected customers and supervisory authorities within GDPR timelines.

07 / COOKIES

Cookies and tracking

We use only the cookies and tracking technologies necessary to operate and secure the service.

Type Purpose Legal basis
Essential Authentication, security, and service functionality Legitimate interest / Contract
Analytics Aggregated usage statistics to improve the service Consent

08 / COMPLAINTS

Complaints and supervisory authority

If you believe we have not handled your personal data correctly, you have the right to lodge a complaint.

Please contact us first at dpo@kervalt.com so we can address your concern. If you are not satisfied with our response, you may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the supervisory authority in your country of residence or workplace.

09 / CHANGES

Changes to this notice

We update this GDPR notice as our services and legal obligations evolve.

Material changes will be communicated via email or through the platform. The effective date at the top of this page reflects the most recent update. Continued use of the service after changes constitutes acceptance of the updated notice.

NEXT STEP

Need a Data Processing Addendum?

Our legal team can provide a GDPR-aligned DPA tailored to your jurisdiction and industry.