KernelFlow NVIDIA Partner
Home Product Trust Partners Docs Contact
KernelFlow · Data Processing Agreement

Data Processing Agreement

This DPA governs the processing of personal data by KernelFlow on behalf of its customers, in compliance with GDPR and other applicable privacy l.

Last updated: July 07, 2026

1. Scope and Roles

This Data Processing Agreement (DPA) applies to all personal data processed by KernelFlow Infrastructure Labs on behalf of its customers. For the purposes of GDPR, KernelFlow acts as a Processor, and the customer acts as the Controller.

2. Data Processing Details

  • Categories of Data Subjects: Employees, customers, and end-users of the Controller.
  • Types of Personal Data: Names, email addresses, IP addresses, usage logs, and inference request data.
  • Purpose of Processing: To provide, secure, and improve the KernelFlow platform.
  • Duration: For as long as the customer has an active account, plus any retention period required by law.

3. Subprocessors

KernelFlow uses trusted subprocessors to deliver its services. A complete list is available in our Subprocessor List. We ensure all subprocessors are bound by data protection obligations at least as stringent as those in this DPA.

4. Security Measures

KernelFlow implements appropriate technical and organizational measures to ensure the security of personal data, including:

  • Encryption at rest (AES-256-GCM) and in transit (TLS 1.3).
  • Role-based access control (RBAC) and least-privilege principles.
  • Regular security audits and penetration testing.
  • 24/7 monitoring and incident response.

5. Data Breach Notification

In the event of a data breach, KernelFlow will notify the Controller without undue delay (within 72 hours) and provide all necessary information to assist with regulatory reporting.

6. Data Subject Rights

KernelFlow will assist the Controller in responding to data subject requests (access, rectification, erasure, restriction, portability) in accordance with GDPR and CCPA requirements.

7. International Data Transfers

Data may be processed in the United States and Sri Lanka. KernelFlow relies on Standard Contractual Clauses (SCCs) and other legally-approved mechanisms for international transfers.

8. Contact

For DPA-related questions, contact us at privacy@kernelflow.one.

📌 GDPR Compliant: This DPA is fully aligned with the General Data Protection Regulation (GDPR) requirements.

KernelFlow Business Solutions
The intelligent execution layer for enterprise AI, optimizing inference performance, infrastructure efficiency, and operational control at scale — built for and certified with NVIDIA.
USA Sri Lanka

Product

  • Overview
  • Features
  • Pricing
  • Integration

Company

  • About
  • Blog
  • Contact
  • Partners

Trust

  • Security & Compliance
  • Privacy Policy
  • Terms & Conditions
  • Acceptable Use
  • Cookie Policy

Legal

  • Data Processing Agreement
  • Service Level Agreement
  • Bug Bounty

Resources

  • Documentation
  • System Status
  • Support Policy
  • Case Studies
© 2026 KernelFlow Infrastructure Labs · all rights reserved
all systems nominal · build 4.2.1