KERVALT / GDPR
Your GDPR rights, explained in plain language.
Kervalt processes personal data under the EU General Data Protection Regulation (GDPR). This page explains what data we process, why we process it, your rights, and how to use them.
01 / CONTROLLER
Data controller
The company responsible for personal data processed through the Kervalt platform.
Kervalt B.V.
Keizersgracht 123
1015 CJ Amsterdam
The Netherlands
Email: privacy@kervalt.com
Data Protection Officer: dpo@kervalt.com
02 / PROCESSING
What personal data we process and why
We collect and process only the personal data we need to deliver, secure, and improve our services.
| Category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Account data | Name, work email, company, role | To provide the service and manage your account | Contract (Art. 6(1)(b)) |
| Usage data | Service logs, queries, feature interactions | To run the service, keep it secure, and support you | Contract (Art. 6(1)(b)) / Legitimate interest (Art. 6(1)(f)) |
| Customer content | Documents, metadata, and inputs uploaded by users | To index, search, and analyze the documents you upload inside the platform | Contract (Art. 6(1)(b)) |
| Marketing data | Email address, company, preferences | To send product updates and event invitations | Consent (Art. 6(1)(a)) |
03 / RIGHTS
Your rights over your personal data
GDPR gives you the following rights in relation to your personal data.
Right of access
You can request a copy of the personal data we hold about you.
Right to rectification
You can ask us to correct inaccurate or incomplete personal data.
Right to erasure
You can request deletion of your personal data when there is no overriding legal reason to keep it.
Right to restrict processing
You can ask us to limit how we use your personal data.
Right to data portability
You can request your data in a structured, commonly used, machine-readable format.
Right to object
You can object to processing based on legitimate interests or direct marketing.
To exercise any of these rights, contact us at dpo@kervalt.com. We respond within 30 days and may ask you to verify your identity first.
04 / TRANSFERS
International data transfers
Kervalt keeps personal data within the European Economic Area by default.
EEA-only processing
All processing, storage, and backup infrastructure is hosted on servers in Germany, France, and the Netherlands. No customer personal data is sent to third countries for processing.
Adequacy and safeguards
If we ever need to transfer data outside the EEA for support or subprocessing, we use adequacy decisions or standard contractual clauses approved by the European Commission.
05 / RETENTION
Retention and deletion
We keep personal data only as long as necessary for the purposes described or as required by law.
Account data
Kept for as long as you have a subscription and up to 7 years after that for legal, tax, and accounting obligations.
Customer content
Kept according to your retention policy. Enterprise customers can request immediate deletion when the contract ends.
Marketing data
Kept until you withdraw consent or it is no longer needed for marketing.
06 / SECURITY
Security and breach notification
We use technical and organizational measures to protect personal data against unauthorized access, loss, or alteration.
Encryption
Locked with AES-256 when stored and TLS 1.3 when moving. Customer-managed keys available for enterprise deployments.
Access controls
Role-based access, least-privilege rules, multi-factor authentication, and full audit logging.
Breach response
In the event of a personal data breach, we notify affected customers and supervisory authorities within GDPR timelines.
07 / COOKIES
Cookies and tracking
We use only the cookies and tracking technologies necessary to operate and secure the service.
| Type | Purpose | Legal basis |
|---|---|---|
| Essential | Authentication, security, and service functionality | Legitimate interest / Contract |
| Analytics | Aggregated usage statistics to improve the service | Consent |
08 / COMPLAINTS
Complaints and supervisory authority
If you believe we have not handled your personal data correctly, you have the right to lodge a complaint.
Please contact us first at dpo@kervalt.com so we can address your concern. If you are not satisfied with our response, you may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the supervisory authority in your country of residence or workplace.
09 / CHANGES
Changes to this notice
We update this GDPR notice as our services and legal obligations evolve.
Material changes will be communicated via email or through the platform. The effective date at the top of this page reflects the most recent update. Continued use of the service after changes constitutes acceptance of the updated notice.
NEXT STEP
Need a Data Processing Addendum?
Our legal team can provide a GDPR-aligned DPA tailored to your jurisdiction and industry.