Privacy policy

How Kernova Technologies handles information when you browse the website, prepare a brief or contact us. This policy covers the current website; processing within an agreed client project is governed separately.

Who is responsible

Kernova Technologies SIA, registration number 40203786353. Registered address: Rēzeknes nov., Feimaņu pag., Feimaņi, "5" - 6, LV-4623, Latvia. For website, privacy and service enquiries: [email protected]; telephone: +371 12685080. The registered address is not a walk-in office.

What information we process

An enquiry contains your name, work email, selected service, starting budget and project description. Company and telephone are optional. A brief may also include scope choices. The server receives technical request information needed to validate submissions and prevent abuse. We do not request payment details, identity documents or sensitive personal information. Please describe the task without sharing passwords, confidential client records or information about other people unnecessarily.

Purposes and legal grounds

We use enquiry details to understand your requirements, reply and discuss a possible project. Steps requested before your own contract rely on GDPR Article 6(1)(b). Correspondence with an organisation’s representative and abuse prevention rely on legitimate interests in responding to business enquiries and protecting the website, subject to balancing those interests against your rights (Article 6(1)(f)). Legal obligations may require particular records (Article 6(1)(c)). Contacting us does not subscribe you to marketing.

Drafts, cookies and demonstrations

The multi-step brief keeps answers in this browser’s session storage to preserve them between steps and language changes. You can delete them with “Clear saved answers”. Portfolio navigation stores only its filter URL and scroll position. This version sets no tracking cookies and loads no analytics or advertising scripts; fonts and media are served locally. The nine project demonstrations use fictional data and transient browser memory. Their interactions do not send information to payment, booking or AI services. See the cookie policy for storage details.

Submission and service providers

The Cloudflare deployment serves static pages and processes enquiries in a Worker. Resend forwards validated enquiries to [email protected]; the visitor’s email is the Reply-To address. Only after the company notification is accepted by the email provider, we send an automatic English or Latvian acknowledgement from [email protected] to the entered client address. This is service correspondence, not a marketing subscription. Cloudflare, Resend and the company mailbox provider process the information necessary for hosting, abuse prevention and delivery. Sending remains unavailable without a configured API key and a verified sender. Provider regions, processor agreements and mailbox retention must be confirmed before public launch.

How long information is kept

Brief drafts are cleared after successful sending, manual deletion or the end of the browser session; drafts older than 24 hours are discarded on next access. In the direct Cloudflare Pages mode, request timestamps, salted connection hashes and request digests/statuses are kept only in temporary Worker memory for a 15-minute window, cleaned on subsequent requests or isolate disposal. This limit is per isolate, not a global persistent limit. Confirmation retries briefly hold the necessary contact details in memory after a response. Resend idempotency keys protect each email for 24 hours. If the optional durable backend is connected, its request metadata expires after 24 hours and acknowledgement contact details expire after a one-hour retry window, cleared by its alarms or on successful sending. The project description is not persisted in either retry store. Mailbox, hosting-log and backup retention must be confirmed with the providers.

Security and international transfers

The website validates input, limits repeated requests and restricts the enquiry endpoint to the configured origin. These controls do not make any internet channel risk-free. Before public deployment, provider identities, processing locations, access controls and processor agreements must be confirmed. Any transfer outside the EEA must have an applicable GDPR transfer basis and safeguards; the policy must identify the relevant arrangements once selected. This local delivery does not assert an overseas hosting or mail transfer.

Your rights and requests

Where the legal conditions apply, you may request access and a copy, correction, erasure, restriction or data portability, and object to processing based on legitimate interests. If processing relies on consent, you may withdraw it without affecting earlier lawful processing. Write to [email protected], explaining your request; we may ask only for proportionate information to verify identity. Requests are normally answered within one month. A lawful extension of up to two further months requires notice within the first month, with reasons. Restrictions or refusals must be explained. You may complain to Latvia’s Datu valsts inspekcija or another competent supervisory authority.

Your choice and policy updates

Providing information is voluntary. Without the required contact and project details we cannot process an online enquiry; you may contact us directly instead. The website does not use automated decisions with legal or similarly significant effects. Changes to the site’s data practices must be reflected here with a revised date. Where required, we will provide additional information or obtain consent before introducing a new purpose.

[email protected]

Cookie policy

Datu valsts inspekcija · GDPR / VDAR