This DPA governs the processing of personal data by KernelFlow on behalf of its customers, in compliance with GDPR and other applicable privacy l.
Last updated: July 07, 2026
This Data Processing Agreement (DPA) applies to all personal data processed by KernelFlow Infrastructure Labs on behalf of its customers. For the purposes of GDPR, KernelFlow acts as a Processor, and the customer acts as the Controller.
KernelFlow uses trusted subprocessors to deliver its services. A complete list is available in our Subprocessor List. We ensure all subprocessors are bound by data protection obligations at least as stringent as those in this DPA.
KernelFlow implements appropriate technical and organizational measures to ensure the security of personal data, including:
In the event of a data breach, KernelFlow will notify the Controller without undue delay (within 72 hours) and provide all necessary information to assist with regulatory reporting.
KernelFlow will assist the Controller in responding to data subject requests (access, rectification, erasure, restriction, portability) in accordance with GDPR and CCPA requirements.
Data may be processed in the United States and Sri Lanka. KernelFlow relies on Standard Contractual Clauses (SCCs) and other legally-approved mechanisms for international transfers.
For DPA-related questions, contact us at privacy@kernelflow.one.
📌 GDPR Compliant: This DPA is fully aligned with the General Data Protection Regulation (GDPR) requirements.